← All posts

Australia's Automated Decision-Making Law: What It Requires

Australia's Automated Decision-Making Law: What It Requires
TL;DR

From 10 December 2026, Australian Privacy Act entities must disclose automated decision-making in their privacy policies under a new transparency obligation. The trigger is a three-part test: a computer program makes, or substantially and directly guides, a decision that could significantly affect an individual, using their personal information. Generative AI and recommendation engines are in scope, not just fully automated decisions.

On 10 December 2026, a quiet change to Australia's Privacy Act 1988 comes into force that will force thousands of organisations to rewrite their privacy policies. The automated decision-making transparency obligation, tucked inside Australian Privacy Principle 1, requires any APP entity that uses personal information in automated decisions to say so publicly.

Most coverage of Australia's privacy reform has focused on the statutory tort for serious invasions of privacy and the new children's privacy code. The automated decision-making obligation got a fraction of the attention. That's a mistake, because it's the part of the reform that reaches AI vendors directly.

The regulation: new disclosure duties inside APP 1

The obligation was introduced by the Privacy and Other Legislation Amendment Act 2024. It doesn't create a standalone rule. It slots new disclosure requirements into APP 1, the principle that already requires APP entities to maintain a clearly expressed and up to date privacy policy.

From 10 December 2026, that policy must also explain how the entity uses personal information in automated decision-making. The OAIC set out the scope and timing in its consultation on guidance for transparency in automated decision-making, which opened 18 May 2026 and closed 15 June 2026. Final guidance is due by September 2026.

What changed, and when it bites

The date that matters is 10 December 2026. That's when the obligation commences. The OAIC has said it will publish its ADM transparency guidance in September 2026, leaving organisations roughly three months to align their privacy policies before the obligation is enforceable.

This is a disclosure obligation, not an individual access right. Australia deliberately chose a lighter touch than Europe. Under Article 22 of the GDPR, individuals get a right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Australia's APP 1.8 instead requires transparency at the privacy policy level. No right to contest the decision, no obligation to notify people individually, no mandated human review. The compliance burden is concentrated in how you write and publish your privacy policy.

The three-part test that decides if you're caught

The OAIC's ADM Issues Paper sets out the trigger precisely. APP 1.7 captures automated decision-making where three things are all true:

  • The entity has arranged for a computer program to make, or do a thing substantially and directly related to making, a decision.
  • The decision could reasonably be expected to significantly affect the rights or interests of an individual.
  • Personal information about the individual is used in the operation of that computer program.

Two parts of that test deserve close reading, because both are broader than most people assume.

First, computer program is defined to mean almost any software. The Explanatory Memorandum states the term takes its ordinary meaning and covers pre-programmed rule-based processes, artificial intelligence, and machine learning. The OAIC has confirmed that generative AI tools, including chatbots, fall inside the definition. This isn't only about a black-box credit scoring engine. A spreadsheet formula, a rules-based triage tool, or a chatbot that drafts recommendations can all qualify.

Second, the phrase substantially and directly related is what pulls recommendation engines into scope. The Explanatory Memorandum says substantially means a key factor in facilitating a human's decision-making, and directly means a direct connection with the decision. You don't need a fully automated decision. If an AI system recommends an outcome to a human who then decides, and that recommendation is a key factor, you're captured. The OAIC's own example is a generative AI chatbot that summarises candidate profiles and recommends eligibility while a human always makes the final call. That's squarely in scope.

What you actually have to disclose

APP 1.8 lists three things your privacy policy must state:

  • The kinds of personal information used in the operation of the computer programs.
  • The kinds of decisions made solely by the operation of those programs.
  • The kinds of decisions for which a thing substantially and directly related to making the decision is done by those programs.

Notice the word kinds. The obligation isn't a per-model, per-decision technical log. It's a categorised disclosure. But it must be specific enough to be meaningful. A policy that says we may use automated decision-making without naming the kinds of personal information or the kinds of decisions won't survive scrutiny.

Note too that significant effect cuts both ways. APP 1.9 makes clear a decision can affect rights or interests whether the effect is adverse or beneficial. The OAIC's examples include admission to a country, entitlement to a housing benefit, a life insurance contract, and access to healthcare. It also flags that targeting individuals with content or ads can qualify where it results in differential pricing for significant goods or services, or limits access to employment opportunities.

Who's affected

APP entities are the Australian Government and organisations with annual turnover above $3 million, plus a set of entities covered regardless of turnover such as health service providers and credit reporting bodies. Small businesses under the threshold are generally exempt.

But a vendor selling into a covered enterprise isn't off the hook. Your customer is the APP entity. They carry the disclosure obligation, and they'll push that burden upstream to you. When a bank, insurer, or government agency realises it must disclose automated decision-making in its privacy policy, it needs to know what its AI vendors do with personal information. The procurement questionnaire is about to gain a new question: does your product use personal information in automated decisions that could significantly affect individuals, and if so, what kinds of decisions and what kinds of data?

The regulatory context is already pointing this way. The OAIC's regulatory action priorities for 2025-26 name the application of artificial intelligence, and the preservation of privacy and information access rights in government use of AI and automated decision making, as explicit focus areas. That's the enforcement signal. Western Australia has also gone further than the Commonwealth. Its Privacy and Responsible Information Sharing Act 2024, in force from 1 July 2026, requires regulated entities to notify individuals, provide information about the ADM on request, and enable requests for human intervention. National vendors with WA customers are already facing the stricter regime.

A compliance roadmap before 10 December 2026

For adopters and vendors alike, the work breaks into five steps.

  1. Inventory your automated decisions. Map every workflow where a computer program makes, or materially guides, a decision about an individual. Include recommendation engines, not just fully automated pipelines.
  2. Tag the personal information each workflow uses. The disclosure obligation is about kinds of data and kinds of decisions, so you need the categorisation before you can write it.
  3. Assess significance. Ask whether each decision could reasonably be expected to significantly affect rights or interests. Use the OAIC's examples as a floor, not a ceiling.
  4. Draft the APP 1.8 disclosure. State the kinds of personal information, the kinds of fully automated decisions, and the kinds of decisions where a program does a thing substantially and directly related to the decision.
  5. Update vendor due diligence. If you're a buyer, add automated decision-making disclosure to your procurement checklist. If you're a vendor, prepare the answer before you're asked.

This maps cleanly onto frameworks you may already be using. ISO 42001 requires AI systems to be documented and their impact assessed, which makes the inventory step far easier for organisations that have done the work. The EU AI Act's transparency obligations for high-risk systems overlap in spirit, and enterprises subject to both should build one disclosure pipeline rather than two. Financial services entities will also need to square this with APRA's CPS 230 operational risk standard, which requires regulated entities to manage risks from new technologies and material service providers.

The vendor angle: your buyers will ask first

This is where the commercial pressure lands. Australian enterprise procurement teams don't wait for a law to be enforced before writing it into their security reviews. We already see security questionnaires expanding from SOC 2 and ISO 27001 into AI-specific questions about training data, model governance, and automated decision-making. The 10 December 2026 commencement gives every Australian enterprise a concrete reason to ask vendors a hard question this quarter.

For vendors, the asymmetry is the point. The enterprise carries the legal obligation, but it can only comply if its vendors tell it what their software does with personal information. The vendor that can hand over a clean, documented map of its automated decisions removes friction from the sale. The vendor that can't adds weeks to it. If you're already doing DPA and vendor due diligence, this is the next question to bolt onto that checklist.

The BizThriveAI take

The ADM obligation is easy to misread as a paperwork exercise. It's actually the first Australian privacy rule that requires organisations to publicly admit what their algorithms do with people's data. That's a meaningful shift, and it will surface in procurement long before the OAIC issues its first enforcement action on this provision.

If you build or deploy AI in Australia, don't wait for September's guidance. Start the inventory now. The disclosure is only as good as the map underneath it, and the map takes longer to build than the policy takes to write. If you want help documenting your automated decision-making against APP 1.8 and ISO 42001, talk to us, see what a verification report looks like, or check how pricing works.

Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.

Frequently asked questions

When does Australia's automated decision-making transparency obligation commence?

10 December 2026. From that date, APP entities using personal information in automated decision-making must include the required disclosures in their privacy policies.

What does APP 1.8 require entities to disclose?

Three things: the kinds of personal information used in the computer programs, the kinds of decisions made solely by the programs, and the kinds of decisions for which a program does something substantially and directly related to making the decision.

Does the obligation cover AI that only recommends decisions to a human?

Yes. The phrase substantially and directly related captures recommendation engines where the program is a key factor in a human's decision. You don't need a fully automated decision to be in scope.

Who is an APP entity that must comply?

The Australian Government and organisations with annual turnover above $3 million, plus entities covered regardless of turnover such as health service providers and credit reporting bodies.

Is Australia's rule the same as GDPR Article 22?

No. GDPR Article 22 gives individuals a right not to be subject to solely automated decisions with legal or similarly significant effects. Australia's APP 1.8 is a lighter disclosure-only obligation at the privacy policy level.

What happens if an entity doesn't update its privacy policy?

A failure to comply with the Australian Privacy Principles is an interference with privacy and can attract civil penalties for serious or repeated breaches under section 13G of the Privacy Act.