From 10 December 2026, Australian privacy policies have to say where AI makes or shapes decisions about people.
New Australian Privacy Principles (APP 1.7–1.9) take effect on 10 December 2026. If your organisation is covered by the Privacy Act and uses AI or automated systems to make or influence decisions about customers, staff or applicants, your privacy policy will need to disclose it. Here's what the rule actually requires, and how to get ready.
If AI helped decide it, you have to be able to say so.
Not the algorithm. Not your vendor's trade secrets. Just: what kind of personal information, what kind of decision, and whether a person was in the loop.
Three things your privacy policy has to cover
Confirmed against the OAIC's own guidance material and independent legal analysis. Commercial-in-confidence system detail is explicitly exempt — this is about the kind of data and decision, not the model behind it.
- ✓ The kinds of personal information used in automated decision-making.
- ✓ Decisions made solely by a computer program, with no person reviewing the outcome.
- ✓ Decisions where a computer program does something substantially and directly related to a decision a person then makes — scoring, prioritising and recommending count here, not only fully autonomous decisions.
Any APP entity, if AI touches a decision about a person
The obligation follows the standard Privacy Act coverage — generally businesses over $3M annual turnover, plus health, education and financial services providers regardless of turnover. In practice, it catches far more organisations than "we built an AI product":
- ✓ Hiring tools that screen or rank candidates before a recruiter sees them.
- ✓ Credit, insurance or risk scoring that feeds a person's final call.
- ✓ Customer service triage or prioritisation that routes who gets seen first.
- ✓ Any recommendation engine influencing what a staff member decides or approves.
The disclosure is only hard if you don't already know where AI operates
Every decision on an AI Operating Map already has an accountable owner and an operating mode — fully automated, or AI-assisted with a person deciding. That split is exactly what this disclosure asks for. We're building a personal-information flag straight into the Decision Register, so getting ready for this stays the same work as keeping your Map current, not a separate compliance project.
- ✓ Every AI-driven decision in one register, not scattered across teams and memory.
- ✓ An accountable owner already attached to each one.
- ✓ Solely-automated vs. AI-assisted already captured per decision, the exact line this rule draws.
Get set up before December 10
That's the deadline, not a marketing date. Organisation Access is $1,995 instead of $2,495 with the code below, plus Map Foundations: three live onboarding sessions to get your Decision Register built in time.
The same code also gets you Own the Loop free on release, the book behind the methodology.
Australia is first with a fixed date, not the only one thinking about this. The EU and UK already regulate automated decision-making under GDPR Article 22. AI Operating Map's Decision Register is built to extend to other jurisdictions as their own disclosure rules land, not just this one.
About the disclosure rule
Does this apply to a small business?
Only if your business is already covered by the Privacy Act -- generally organisations with over $3M annual turnover, plus health, education and financial services providers regardless of turnover. If the Privacy Act doesn't apply to you today, this new rule doesn't create fresh coverage on its own.
What if we're only testing AI internally, not using it on customers?
The disclosure requirement is about decisions that could significantly affect an individual's rights or interests. Internal testing that never reaches a real decision about a real person isn't what this catches, but the moment a tool moves from testing into actually shaping a decision about a customer, staff member or applicant, it's in scope.
What happens if we don't comply?
The OAIC has new infringement-notice and compliance-notice powers under this amendment, on top of the Privacy Act's existing civil penalty regime. This isn't a guidance-only change.
How is this different from GDPR?
The idea is similar to GDPR Article 22 (automated decision-making), but the mechanism here is narrower and more specific: a plain disclosure in your privacy policy, split into solely-automated and AI-assisted categories, rather than a standalone right to contest an automated decision. Commercial-in-confidence system detail is explicitly exempt either way.
Do we need to disclose exactly how our AI model works?
No. The requirement is about what kind of personal information is used and what kind of decision it feeds, not the algorithm or model itself. Commercial-in-confidence system detail doesn't need to be disclosed.
Has the OAIC published final guidance yet?
The OAIC ran a public consultation on guidance for this requirement, which closed in mid 2026. The commencement date and the three-part disclosure requirement are fixed by the legislation itself and won't change; check the OAIC's published guidance for interpretive detail before finalising your own privacy policy wording.
This isn't legal advice. It explains the regulation as published and how AI Operating Map helps you get organised for it. Whether APP 1.7–1.9 applies to your organisation, and what exactly to write in your own privacy policy, is a call for you and your own privacy counsel.
The commencement date and the three-part disclosure requirement above are fixed in the legislation itself. The OAIC's own guidance on how to interpret it is still being finalised, so specific wording and edge cases may sharpen over time — check their published guidance before finalising your own privacy policy.
AI Operating Map