AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·AI Compliance11 min read

Australia's Automated Decision Disclosure Rule Starts With an Inventory

From 10 December 2026, an Australian privacy policy must list the kinds of personal information and the kinds of decisions involved wherever a computer program makes, or substantially shapes, a decision that could significantly affect a person. The OAIC's guidance of 30 September 2026 counts generative AI as a computer program and says advisory outputs can be in scope. You cannot disclose decisions you have not found, so the work starts with an inventory.

S
Sofia Reyes
Head of Compliance
Oct 4, 2026

On 10 December 2026, Australia's Privacy Act starts asking a question most privacy policies never had to answer: which decisions about people does a computer program make, or substantially shape? New subclauses 1.7 to 1.9 of Australian Privacy Principle 1, inserted by Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024, require an APP entity to state in its privacy policy the kinds of personal information those programs use and the kinds of decisions they are used for, wherever a decision could reasonably be expected to significantly affect someone's rights or interests.

It is a disclosure duty, and a narrow one. The rule does not make you explain a model's logic, offer human review or switch anything off. The regulator reads its scope broadly, though. Guidance the Office of the Australian Information Commissioner (OAIC) published on 30 September 2026 counts generative AI and chatbots as computer programs, says advisory outputs can be in scope, and gives, as an example of a program an entity has "arranged for", an employer permitting staff to use an AI chat tool to draft performance assessments that determine promotions.

So writing the paragraph is the easy part. Knowing what belongs in it is harder, because you cannot list kinds of decisions you have not found.

Last verified: 8 October 2026, against the Federal Register of Legislation, the OAIC's APP 1 Guidelines (version 2.0) and fact sheet, APRA, and the New Zealand Privacy Commissioner.

What does the new rule actually say?

Item 88 of the amending Act adds three subclauses to the end of APP 1. The first two carry the obligation:

"1.7 Without limiting subclause 1.3, the APP privacy policy of an APP entity must contain the information covered by subclause 1.8 if: (a) the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and (b) the decision could reasonably be expected to significantly affect the rights or interests of an individual; and (c) personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision.

1.8 The information covered by this subclause is: (a) the kinds of personal information used in the operation of such computer programs; and (b) the kinds of such decisions made solely by the operation of such computer programs; and (c) the kinds of such decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs."

APP 1.9 adds that refusing or failing to decide counts, and that beneficial effects count as well as adverse ones.

Read 1.8 slowly. It asks for two lists of decisions, not one.

One covers decisions a program makes on its own. The other covers decisions a person makes while a program does something substantially and directly related to them. Sorting each use into the right list means knowing how a tool is used, not merely that it is installed.

The date is fixed. Part 15 commences "the day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent", which was given on 10 December 2024, and the Federal Register of Legislation shows the amended text taking effect on 10 December 2026. Item 89 applies the rule to decisions made after commencement even where the arrangement for the program, or the personal information it uses, predates that day, so a credit model built years earlier can be in scope for its later decisions.

Who has to comply?

Every APP entity, meaning an agency or an organization in the Act's terms. That takes in Australian Government agencies and, broadly, private sector entities other than small business operators, and under section 6D a business is small if its annual turnover for the previous financial year was $3,000,000 or less.

The carve-out has exceptions. A business under the threshold is still covered if it provides a health service and holds health information, trades in personal information for a benefit, is a contracted service provider for a Commonwealth contract, or is a credit reporting body. A small company is also covered when a related body corporate runs a business that is not small.

No volume threshold applies. One kind of in-scope decision is enough.

Take one exemption to counsel. Section 7B(3) exempts a private sector employer's acts directly related to a current or former employment relationship and an employee record, and the OAIC's APP 1.7 material does not say how that bears on its own performance-review and promotion examples. On its text the exemption needs an employment relationship, so it does not reach an outside job applicant, and recruitment screening is on the OAIC's list of uses generally in scope.

Does an AI tool that only recommends count?

Often, yes. The updated APP 1 Guidelines say that "Generative AI tools used to generate text, images, videos, code or synthesis, including chatbots and other types of AI all fall within the definition of computer program for the purpose of the APP 1.7-1.9 transparency obligation." Rule-based processes count too: one OAIC example puts a spreadsheet formula that ranks people for health and aged care services in scope.

Recommending can be enough. A program is substantially related to a decision when it is "a key factor in facilitating the human's decision making", and the guidelines state that a program "may be substantially and directly related to making a decision regardless of whether the nature of the output is advisory or determinative." The fact sheet is blunter: the OAIC "considers machine learning or generative AI outputs used to make decisions that significantly affect the rights or interests of individuals would generally fall within scope of the transparency obligation unless subject to extensive human oversight and control."

Human review does not take you out by default.

What falls outside? A program used only to write up a decision a person already made, such as a word processor. The fact sheet's harder case is a sales team whose managers use a generative AI tool to suggest bonuses and salary changes: in scope despite written director approval of every final decision, though interrogating outputs, checking the underlying indicators, narrowing the tool's parameters, weighing other evidence and documenting departures from the recommendation "could indicate" otherwise. Those are controls. They help only if you can show they ran.

Significance has a floor too. The impact "must be more than trivial", and vulnerability raises the stakes.

What does this require of an enterprise using AI tools?

Clause by clause, the obligation becomes six pieces of work. Only one of them is drafting.

What the rule asksWhat it means for AI toolsWhat to do before 10 December 2026
Programs the entity has "arranged for" (APP 1.7(a))In-house builds, procured or configured software and, in an OAIC example, an AI chat tool staff are permitted to use for promotion assessmentsInventory every AI tool in use, including those adopted without procurement, and record which team uses each one
Substantially and directly related (APP 1.7(a))Advisory output can count, depending on reliance and override in practiceFor every tool that touches decisions about people, record how the decision-maker uses its output
Significant effect on rights or interests (APP 1.7(b))More than trivial. Employment, housing, credit, insurance and healthcare recur in the OAIC's examples, as does personalized pricing of significant goodsTriage by decision type, and count a heavier effect on vulnerable groups toward inclusion
Personal information used in operation (APP 1.7(c))What the program uses when it runs: prompts, uploaded files, connected recordsList the kinds of personal information each in-scope tool receives, naming health information and biometric templates clearly
Two lists of decision kinds (APP 1.8(b) and (c))Solely automated decisions are listed apart from substantially assisted onesClassify each use, then draft. Grouping is fine if the result is meaningful to a reasonable person
A clearly expressed and up-to-date policy (APP 1.3)New tools and new uses change the answerReopen the policy whenever a new AI tool or a new decision use appears

Why is this an inventory problem, not a drafting problem?

The regulator frames it that way. Paragraph 1.45 of the guidelines: "APP entities should actively identify, assess and keep oversight over the third-party computer programs that they use to make a decision, both during and after procurement."

Three features push the work upstream of the privacy policy's owner. First, "arranged for". The OAIC's example is an employer that "permits or directs employees to use an AI chat tool to draft performance assessments that determine promotion decisions." Permission is enough. The guidance does not address a tool adopted with nobody's permission, but the fact sheet tells entities in doubt that they "should take a cautious approach and include information in their APP privacy policy". Not knowing what your own staff use is a weak reason to leave a decision type out, and a tool bought on a corporate card may never pass through procurement.

Second, vendors. The OAIC "generally expects" the obligation to stay with the entity using the personal information, while software providers "should provide clear, high-level information about how their software can be used to make decisions". Get that statement in writing before you draft.

Third, currency. APP 1.3 already demands an "up-to-date" policy, and a one-off survey starts aging the day it ends.

This is the part we built for. AccuroAI's shadow AI discovery correlates browser, SaaS, network and desktop signals to find the AI tools in use, matches them against a catalog of 1,400+ AI tools, and attributes each one to a user, team and business unit. Attribution matters here, since a credit team's tool raises a different question from marketing's. Whether a given use is substantially and directly related to a significant decision remains a judgment for your privacy and legal teams. It should simply start from the full list rather than the procured one.

Without tooling, start with the OAuth grants employees have given AI apps. Our OAuth grant walkthrough covers Microsoft 365 and Google Workspace, and the shadow AI hub collects other methods.

What happens if the privacy policy gets it wrong?

Item 87 adds APP 1.7 to section 13K of the Privacy Act, the civil penalty provision for which infringement notices and compliance notices can be issued, and which already covers APP 1.3 and 1.4. Its maximum civil penalty is 200 penalty units. For a listed corporation, an infringement notice is set at 200 penalty units per alleged contravention. The Commissioner can instead issue a compliance notice requiring specified action within a reasonable period, and failing to comply with one is a civil penalty provision in its own right. The note to section 13K adds that the same conduct may also contravene sections 13G or 13H, which carry higher maximums.

Keep that in proportion. The practical exposure is that a privacy policy is public, and an incomplete list can be tested by anyone on the receiving end of one of your decisions.

What else already applies to AI in Australia?

The OAIC's Guidance on privacy and the use of commercially available AI products, published on 21 October 2024 and updated on 17 January 2025, starts from the position that "The Privacy Act applies to all uses of AI involving personal information". As best practice it recommends keeping personal information, especially sensitive information, out of publicly available generative AI tools, and it already asked businesses to update their privacy policies with clear information about their use of AI. APP 1.7 turns part of that request into a requirement with a date.

For ADIs, insurers and superannuation trustees, APRA's CPS 230 Operational Risk Management has applied since 1 July 2025, with targeted amendments in force from 1 July 2026. It requires a register of material service providers, submitted to APRA annually, and makes an ADI treat a provider of credit assessment as material, and an insurer a provider of underwriting or claims management, unless it can justify otherwise. Credit and insurance decisions also appear in the OAIC's in-scope examples, so where an AI vendor sits inside those processes, one inventory serves both regimes.

What about New Zealand?

Information privacy principle 3A, added to the Privacy Act 2020 by the Privacy Amendment Act 2025, came into force on 1 May 2026, and it concerns indirect collection rather than automated decisions. An agency, businesses included, that collects someone's personal information from another source must take reasonable steps, as soon as reasonably practicable, to make the person aware of the collection, its purpose, the intended recipients, the name and address of the collecting and holding agencies, any law authorizing or requiring it, and their rights of access and correction. Exceptions apply, including for publicly available information.

The AI link sits upstream of any decision. Enrichment data, background-screening reports and information an AI agent gathers from third parties all arrive indirectly, and the Privacy Commissioner's guidance says IPP 3A "applies to all personal information agencies collect indirectly, from any source." Same question, other side of the Tasman: which tools bring personal information in, and from where?

Where should you start?

With the list: every AI tool in use, sanctioned or not, attributed to the team that uses it. Then work outward from the teams that decide things about people (recruitment and HR, credit, claims, pricing, fraud and account access, customer eligibility), apply the OAIC's reliance and significance tests, collect vendor statements and draft the two lists. Commercial-in-confidence detail can stay out of the policy, the OAIC says. The decision types cannot.

To check your starting point, our free AI governance maturity assessment takes about 12 minutes across 30 questions, including whether you can produce a current AI inventory and keep it refreshed. For the US comparison, see our US state AI law tracker; the AI compliance hub collects the rest.

This is not legal advice. The statutory text is quoted from the Act as made, and the interpretation is the OAIC's rather than ours. Where that guidance is silent, as it is on tools nobody approved and on the employee records exemption, ask counsel.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoRun the free assessment

15 enterprises secured · under 38ms p99 · live on your own estate in 72 hours