What does the December 2026 Privacy Act change mean for AI in Australia?
From 10 December 2026, Australian organizations (APP entities) must disclose in their privacy policies when they use automated decision-making, including AI, to make or substantially support decisions that could significantly affect a person's rights or interests.
The obligation comes from the Privacy and Other Legislation Amendment Act 2024, which amends the Privacy Act 1988 (Cth). It sets transparency rules for how computer programs, from AI models to rule-based engines, shape decisions about people.
This is the first time Australian privacy law formally treats automated decision-making as a disclosure obligation. For compliance, legal, IT, and risk teams, it means mapping where automation touches consequential decisions and updating privacy policies before the deadline.
What does the December 2026 Privacy Act change require?
From 10 December 2026, the Privacy and Other Legislation Amendment Act 2024 amends the Privacy Act 1988 (Cth). APP entities must then disclose in their privacy policies when they use a computer program to make decisions about people. The rule applies when that program makes a decision, or does something substantially and directly related to making one, that could significantly affect an individual's rights or interests using their personal information.
The reform adds three new sub-principles to Australian Privacy Principle 1 (APP 1):
- APP 1.7 sets the threshold for when disclosure is required.
- APP 1.8 specifies what you must disclose: the kinds of personal information used, the kinds of decisions made solely by automated systems, and the kinds of decisions where automated systems play a substantial and direct role.
- APP 1.9 clarifies the definitions and gives examples, including that "making a decision" covers refusing or failing to make one, and that effects can be adverse or beneficial.
The obligation applies broadly. The Explanatory Memorandum to the Privacy and Other Legislation Amendment Bill 2024, quoted in the Office of the Australian Information Commissioner (OAIC) guidance, treats "computer program" as covering AI systems, machine learning, and pre-programmed rule-based engines, not just tools labeled as AI. If a model does the heavy lifting and a person simply clicks "approve," the decision is likely in scope.
Consider a lender that uses a machine learning model to score home loan applications. Even when a staff member gives the final sign-off, the model is a key factor in the outcome, so the lender must describe that use in its privacy policy. The same logic reaches decisions about insurance, employment, housing, and access to significant services or supports.
What types of AI decisions are in scope?
The rules capture automated decisions that could reasonably be expected to significantly affect a person's rights or interests. Insurance underwriting that sets someone's premium, tenancy screening that ranks rental applicants, employment shortlisting, and decisions about access to significant services or supports all sit squarely inside scope.
Scope reaches past fully automated decisions. It also covers decision-support tools where a computer program is a key factor with a direct connection to the outcome, even when a person signs off at the end. Algorithmic pricing, automated intake triage, candidate screening engines, scheduling tools, and service-routing assistants can all qualify.
The OAIC is developing guidance to clarify terms like "substantially and directly related" and "significantly affect rights or interests," targeted for release by September 2026. Because that guidance lands close to the deadline, organizations should assess scope now rather than wait for the final wording.
Why transparency in AI decisions matters under these reforms
Transparency in AI decisions is the enforcement mechanism behind the Australian Privacy Act 2026 changes. People deserve to know when a machine shapes decisions about them, and disclosure is what makes that knowledge possible.
Without disclosure, individuals cannot understand, question, or challenge a decision that affects their job application, their insurance, or a financial product. Transparency turns an opaque process into one a person can actually respond to.
Transparency also works as an organizational forcing function. Disclosing automated decision-making in a privacy policy requires you to know where those systems run in the first place. Many AI tools already sit inside HR screening, customer service triage, and dynamic pricing, often without central oversight, so honest disclosure starts with finding them.
How to identify automated decision-making across your organization
Start by mapping every system that ingests personal information and contributes to a decision about a customer, employee, or user. That includes AI models, rules engines, scoring algorithms, assistants, and any tool that triages, ranks, filters, or recommends. AI compliance in Australia depends on this inventory being complete.
Pay close attention to "shadow AI": tools adopted outside central IT and risk processes, where no one tracks which models touch personal data. These are the systems most likely to surface after the deadline, when discovery is expensive.
For each system, document the kinds of personal information it uses, the decision it supports or makes, and whether the outcome could significantly affect rights or interests. Involve legal, IT, risk, and business-unit stakeholders, since no single team sees every deployment. A permission-aware enterprise search and knowledge platform such as Glean can help teams see which tools and data sources connect across the organization through the Enterprise Graph, which maps relationships across documents, tools, and people, supporting this inventory work.
What compliance measures businesses need to implement by December 2026
Compliance with the December 2026 Privacy Act changes for AI in Australia rests on three moves: fix your privacy policy, stand up governance, and prepare for enforcement. The subsections below cover each in turn.
Update your privacy policy
Your privacy policy must state the kinds of personal information that feed automated decision-making systems, the kinds of decisions made solely by those systems, and the kinds of decisions where automated tools play a substantial and direct role. These three disclosures map directly to the new APP 1.8 requirements.
The OAIC is running its first-ever privacy policy compliance sweep, reviewing about 60 organizations across six sectors against APP 1.4. That sweep targets existing privacy-policy content obligations rather than the December 2026 ADM rules specifically, but it is a clear signal that the regulator is checking policies actively.
Establish AI governance and accountability structures
Define who owns automated decision-making in your organization, maintain an inventory of the tools in use, run regular audits for bias and inaccuracy, and keep records of AI-driven decisions. Clear ownership is what keeps the inventory current as new tools appear.
Align these safeguards with the strengthened APP 11 requirement to take technical and organizational measures to protect personal information. Governance and data protection regulations in Australia now reinforce each other, so treat them as one program.
Prepare for enforcement consequences
Penalties are tiered. Serious interferences with privacy by corporations carry civil penalties of up to $50 million. Less severe breaches sit at up to $3.3 million for corporations, and administrative failures, including a non-compliant privacy policy, reach up to $330,000 for corporations.
A separate statutory tort for serious invasions of privacy took effect on June 10, 2025. It lets individuals, including employees, sue directly, which adds a litigation risk that runs alongside regulator action.
How Australia's Privacy Act compares to international AI transparency laws
Australia's regime shares DNA with the European Union's GDPR. Under Articles 13 to 15 and 22, GDPR requires controllers to disclose automated decision-making, gives people a right to meaningful information about the logic involved, and grants a right not to be subject to solely automated decisions that produce legal or similarly significant effects.
The key distinction is scope. Australia's December 2026 rules are narrower. They mandate transparency through disclosure in privacy policies, but they do not yet grant individuals a right to opt out of automated decisions or request human review. Those broader rights were agreed in principle but not legislated in 2024.
For organizations that operate across jurisdictions, this gap is a planning opportunity. Building governance and documentation now positions you for both the current Australian requirements and the broader reforms that international precedent suggests are coming.
What the OAIC expects and what comes next
The OAIC targeted publishing its automated decision-making guidance by September 2026. The OAIC guidelines 2026 are expected to clarify key terms, give examples of captured uses, and set out how much disclosure detail a privacy policy needs.
More reform is scheduled. A Children's Online Privacy Code must be registered by December 10, 2026, though its commencement date and transition period are not yet confirmed, so it is not enforceable from that date. Read it as a signal of the direction of privacy law changes in Australia rather than a fixed obligation.
A second tranche of legislation is also expected. The current exposure draft does not remove the small business exemption for organizations under $3 million in turnover, and it does not remove the employee records exemption. Treat December 2026 as the start of a longer compliance trajectory, not the finish line.
How to prepare your organization now
Preparing for the impact of privacy reforms on AI comes down to a repeatable sequence you can start today. Work through these steps in order.
- Inventory all AI and automated decision-making tools that affect decisions about customers, employees, or users, including shadow AI adopted outside central IT.
- Review and update your privacy policy against the new APP 1.7, APP 1.8, and APP 1.9 requirements.
- Introduce privacy compliance training so staff can recognize and flag new in-scope tools as they are adopted.
- Build a repeatable review process rather than a one-time audit, because in-scope systems change as AI adoption grows.
- Get legal and risk sign-off well before the deadline, since the gap between the OAIC's targeted September 2026 guidance and the December 2026 deadline is narrow.
Frequently asked questions
Does the December 2026 change apply to small businesses?
The small business exemption for organizations under $3 million in annual turnover still applies, and the current second-tranche exposure draft does not remove it. That position could change in future reform. Small businesses that use AI to make decisions about individuals should monitor the OAIC's guidance closely and prepare early.
What happens if my organization doesn't comply by 10 December 2026?
The OAIC can issue compliance notices, issue infringement notices, or pursue civil penalties reaching up to $50 million for serious interferences by corporations. The regulator's current privacy policy compliance sweep, reviewing about 60 organizations, signals that enforcement is active rather than theoretical. Treat the deadline as firm and document your readiness.
Do internal HR decisions made with AI fall under these rules?
Yes, if the decision could significantly affect a person's rights or interests and personal information feeds the system. Candidate screening engines, performance evaluation algorithms, and automated scheduling tools are all potentially in scope. Map these HR systems now, since many were adopted without central IT or risk oversight in the first place.
Will the OAIC provide specific examples of what must be disclosed?
Yes. The OAIC guidance, targeted for September 2026, will include examples of captured uses and the level of disclosure detail expected in privacy policies. Begin your assessment now against the draft principles, then refine your privacy policy once the final guidance publishes, because the window before the deadline is short.
Does this law require organizations to stop using AI for decision-making?
No. It is a transparency obligation, not a prohibition. Organizations can keep using automated decision-making, but they must disclose that use clearly in their privacy policies. AI ethics and privacy expectations are rising, yet the December 2026 rules focus on disclosure rather than banning any particular system.
The December 2026 deadline rewards teams that start mapping their automated decisions now, while the window before the OAIC's final guidance is still open. We help you connect and understand your company's knowledge, with permission-aware results that show where personal information and automated tools shape decisions across your organization. Request a demo to see how we can support your AI governance and privacy compliance work.









.webp)
.jpg)
