New resources on transparency for use of AI and automated decision-making
Authored by: Lily McCormick and James Pratt
On 30 September 2026, the Office of the Australian Information Commissioner (OAIC) published new guidance to assist agencies and organisations prepare for changes regarding the Privacy Act 1988 (Cth) (Privacy Act) concerning automated decision-making, including decisions involving the use of AI.
From 10 December 2026, agencies and organisations regulated by the Privacy Act will be required to include information in their privacy policies about the utilisation of certain computer programs to inform, or make decision that significantly affect, individuals’ rights or interests. The requirements were introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and are contained in new APPs 1.7-1.9.
The changes are broader than the utilisation of artificial intelligence alone, as OAIC guidance makes clear that a “computer program” can include traditional rule-based systems, machine learning systems and generative AI. Importantly, the obligation can apply where a computer program does not make the final decision but plays a direct role in the decision-making process.
To ensure compliance with the new requirements, entities should therefore consider the full range of automated tools across their operations, rather than exclusively focusing on AI systems.
Key takeaways for APP entities
Where APP 1.7 applies, an entity will be required to include information about its use of automated decision-making in its APP Privacy Policy.
Under APP 1.8, the privacy policy must describe:
The kinds of personal information used in the operation of relevant computer programs
The kinds of decisions made solely by those programs
The kinds of decisions where a computer program does something directly related to making the decision
For example, an organisation may use a computer program to assess an individual’s information, generate a recommendation or score, and provide that information to an employee who will make the final decision. Depending on the significance of the program’s role, this may still fall within the new requirements.
APP 1.9 also makes clear that a decision includes refusing or failing to make a decision that can affect an individual negatively or positively.
Some examples of these decisions that may affect an individual’s rights or interests include decisions around:
Access to significant services or support, including healthcare
Employment, renumeration or recruitment decisions
Rights under a contract or agreement
Other significant services where automated systems influence the outcome
The question will ultimately depend on whether the decision could be reasonably expected to significantly affect the individual’s interests or rights. This in turn means that human involvement does not necessarily avoid the requirements.
What should entities do now?
With the new requirements commencing on 10 December 2026, entities should review their use of automated systems now.
Organisations and agencies should:
identify relevant systems through conducting a broad mapping exercise of all computer programs, algorithms and AI tools involved in decision-making processes.
This may require a review of third-party technology used by your entity.
Assess the decisions involved and determine whether those decisions could significantly affect an individual.
If any decisions meet the threshold, include relevant details in your Privacy Policy by 10 December 2026.
Establish new governance processes to ensure that new automated systems are identified and included in your Privacy Policy as they are introduced.
Overall, these changes reflect an increased regulatory focus on transparency.
If your entity requires assistance assessing whether or not any of your automated decision-making processes or tools are captured, or want any other advice on managing compliance with the Privacy Act, please reach out to help@adaptbl.com.au and our privacy law experts will be in touch.