If your organisation uses AI to help make decisions about people, Australia’s privacy law is about to change the rules, with the new obligations commencing on 10 December 2026.
This article sets out what the new obligations require, where other jurisdictions are heading, and the steps your organisation could be taking now.
December 2026: What the Australian Law Requires
The Privacy and Other Legislation Amendment Act 2024 introduces a transparency obligation for automated decision-making. It sits inside the Australian Privacy Principles and applies to any APP entity, which covers most businesses handling personal information.
The obligation is triggered when three conditions are met at the same time:
- Your organisation has arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision.
- That decision could reasonably be expected to significantly affect the rights or interests of an individual.
- Personal information about that individual is used in the operation of the program.
When all three conditions are met, your privacy policy must disclose what kinds of personal information the program uses, what types of decisions the program makes on its own, and what types of decisions the program substantially assists a human to make.
Two details in that test widen its scope considerably.
First, the obligation covers assisted decision-making as well as fully automated decisions, so a computer program that materially steers a human decision-maker brings the obligation into play. A loan officer who reviews an AI-generated credit score before approving or declining an application is making an assisted decision that falls within scope.
Second, the term “computer program” is interpreted broadly enough to cover generative AI tools, rule-based engines, and sophisticated spreadsheets that score or rank individuals. If your team has quietly introduced automation into a workflow over time, that automation is likely in scope.
Decisions that could significantly affect rights or interests include home loan approvals, insurance assessments, job application screening, housing allocation, and access to healthcare services. The Office of the Australian Information Commissioner (OAIC) is developing guidance expected by September 2026, though waiting for that guidance before acting carries real risk, as the months between September and December leave little room for the audit work that needs to happen first.
Regulators Worldwide Are Moving in the Same Direction
Australia’s December deadline reflects a global shift rather than an isolated local initiative, and regulators in multiple jurisdictions have reached similar conclusions about AI accountability.
The EU AI Act Ties Obligations to Risk Level
The EU AI Act classifies AI systems by risk level and attaches progressively stricter obligations to higher-risk applications. Providers of high-risk AI systems must design for transparency so users can understand what the system does and use it correctly. Providers of AI systems that generate or alter content must disclose that the output is AI-generated, with narrow exceptions for legal purposes or clearly artistic contexts. Impact assessments and documentation of decision-making processes are mandatory for high-risk applications.
United States Regulation Is Emerging State by State
The US has no single federal AI law, but individual states are filling that gap. California’s AB 3030, effective 1 January 2025, requires licensed healthcare providers to disclose when generative AI was used to create patient-facing content. Connecticut has established frameworks for automated employment decision tools that include mandatory consumer disclosures. This state-by-state patchwork creates real complexity for organisations operating across multiple US states, and it continues to grow.
Canada’s Proposed AIDA Signals the Same Intent
Canada’s Bill C-27 includes the Artificial Intelligence and Data Act (AIDA), which would create a regulatory framework for the design, development, and deployment of AI systems. The bill’s future depends on legislative processes still in progress, but the drafting shows a clear intent to regulate AI systems that could materially affect individuals.
The through-line across all three jurisdictions is consistent, in that any AI system making or influencing consequential decisions about people is likely to attract a requirement to disclose and explain.
Five Steps Your Organisation Can Take Before the Deadline
Compliance with the December 2026 deadline calls for preparation that starts well before the OAIC publishes its final guidance, and the following sequence offers a workable approach.
1. Map Every AI System That Touches Decisions About Individuals
Start with a complete inventory, since most organisations have more automated decision-support than they realise. Automation tends to arrive incrementally, so a workflow that began as a manual spreadsheet review may now include scoring logic that materially influences outcomes. Third-party tools, vendor platforms, and SaaS applications frequently contain embedded AI functionality that the organisation never explicitly chose.
For each system you identify, document what personal information it uses and how that information flows through the process, as this mapping forms the foundation the remaining steps build on.
2. Apply the Three-Condition Test to Each System
For each identified system, work through the three conditions in order, asking whether a computer program is making or substantially contributing to a decision, whether that decision could significantly affect someone’s rights or interests, and whether personal information is used in the process.
This analysis calls for both legal and operational judgement, since the same system may trigger the disclosure obligation in one use case and not another. Document your reasoning for every conclusion, including the cases where you determine the obligation does not apply, as that record demonstrates a considered approach if the OAIC reviews your compliance.
3. Rewrite Your Privacy Policy with Specificity
Generic statements about using technology to assist decisions are unlikely to satisfy the new requirements. Your privacy policy needs to identify the kinds of personal information used in your automated systems, the categories of decisions made solely by those systems, and the categories of decisions where those systems substantially assist human decision-makers.
For that reason, the policy is best written after the audit rather than before, since policies drafted from assumptions about what your systems do tend to be inaccurate, and inaccurate disclosure creates a compliance problem of its own.
Alongside the public-facing policy, maintain internal documentation of each system’s design, the testing conducted, and the risk assessment process, as this record supports both regulatory compliance and sound governance.
4. Build AI Review Into Procurement and Change Management
The compliance obligation does not stop at the systems you have today, as vendors update their tools, new AI functionality arrives inside products your team already uses, and new systems join the estate over time.
Integrating an AI disclosure assessment into your procurement process for any new tool or material software update gives your team a repeatable way to evaluate whether new capabilities bring the organisation into scope.
5. Establish Human Oversight Protocols for Assisted Decisions
Where AI assists human decision-makers, clear protocols for human review serve as both a legal expectation and sound risk management. Individuals should have a meaningful avenue to understand and challenge AI-influenced decisions, and for high-impact categories such as credit, employment, or healthcare access, that avenue should be accessible and substantive rather than a formality.
Train the people who work inside these systems on what the regulation requires and on their specific role in maintaining compliance, since regulatory obligations met at the policy level but not understood at the operational level tend to fail when tested.
The Cost of Waiting Is Higher Than It Appears
Organisations planning to start compliance work after the OAIC guidance arrives in September 2026 face a narrow window. The audit alone can take months in organisations with complex or distributed technology environments, and rewriting privacy policies, updating vendor contracts, establishing governance protocols, and training staff all compound that timeline.
The difficulty here lies less in the regulation, which is reasonably clear, than in the operational reality of understanding what your AI systems do at a level of detail sufficient to make accurate public disclosures.
Organisations approaching this work systematically from now should be positioned to comply with confidence and to use their privacy policies as a genuine communication tool with customers. The regulation exists in response to AI systems making consequential decisions about people who have a legitimate interest in knowing. Building your compliance programme from that principle, rather than from the minimum required to avoid scrutiny, tends to produce better outcomes for the organisation and for the individuals affected.
