AI Regulation Tracker / Privacy and automated decisions
Australia ADM Transparency Duty Set to Start December 10, 2026
The Privacy and Other Legislation Amendment Act 2024 added a transparency obligation to Australian Privacy Principle 1. From 10 December 2026, an APP entity that uses personal information in automated decision-making capable of significantly affecting an individual must say so in its privacy policy. On 18 May 2026 the Office of the Australian Information Commissioner opened an Issues Paper consultation to shape the guidance that will sit under that statutory duty.
The obligation did not appear out of nowhere. It came in through the Privacy and Other Legislation Amendment Act 2024, which the Issues Paper describes as the instrument that introduced a transparency obligation within Australian Privacy Principle 1 to include information about automated decision-making in an APP entity's privacy policy. That is the law. The OAIC's own words are plain about the timing: the obligation commences on 10 December 2026, and the paper repeats it. As the executive summary puts it, the amendment act "introduced a transparency obligation within Australian Privacy Principle 1," and "the ADM obligation commences on 10 December 2026."
What the obligation actually requires
The Privacy Act sets three tests. An automated decision falls inside the obligation when a computer program is arranged to make, or to do a thing substantially and directly related to making, a decision; when that decision could reasonably be expected to significantly affect the rights or interests of an individual; and when personal information about the individual is used in the operation of the program. The paper adds that failing or refusing to make a decision counts as making one, and that a person can be affected whether the outcome helps them or hurts them.
Once an entity runs that kind of system, its privacy policy has to spell out the kinds of personal information the program uses, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making the decision. This is a disclosure duty tied to APP 1.7 and APP 1.8. It is not a ban on automated decisions and not a right to a human review. It is about telling people, in the policy they can read, that these systems are in the loop.
Why the Issues Paper is not the rule
This is the distinction most coverage blurs. The 18 May 2026 Issues Paper is a consultation, not a legal instrument. The OAIC says so directly: "this consultation is not a statutory requirement. The OAIC has chosen to seek views to help inform the development of the guidance by identifying key implementation issues." Submissions closed on 15 June 2026. The regulator intends to release guidance by September 2026, before the December commencement.
So the sequence is the statute first, the guidance second. Reading the paper tells you how the OAIC is thinking about hard questions, such as what "significantly affect" means, how third-party systems are treated, and what form the disclosure should take. It does not change your obligation. Even if the guidance shifts between draft and final, the commencement date and the statutory text are already fixed.
Why this reaches US and other foreign firms
The Privacy Act reaches organisations that carry on business in Australia and handle Australians' personal information, which pulls in plenty of companies headquartered elsewhere. If you run credit scoring, insurance pricing, hiring screens, fraud flags, eligibility checks, or any model that uses personal data to reach or shape a decision about an Australian, and that decision could significantly affect the person, you are the audience for this. The obligation does not care whether the model is a large language model, a simpler machine-learning system, or a set of hard-coded rules. What matters is that a program is deciding, personal information is feeding it, and the stakes for the individual are real.
Here is my read as someone who has sat on the compliance side of these calls. The hard work is not writing the paragraph for the privacy policy. It is the inventory. Most organisations do not have a clean list of every place an automated or semi-automated decision touches a customer, and many of those systems were bought from vendors or bolted on by a team that never thought of them as "automated decision-making." Building that map takes longer than lawyers expect, and you cannot disclose what you have not found.
What to do before December
Start the inventory now. Walk each customer-facing and employment-facing process and ask whether a computer program makes or materially shapes a decision, whether personal information goes into it, and whether the outcome could significantly affect the person. For every yes, note the kinds of personal information used and the kinds of decisions produced, because that is the exact shape of what the privacy policy has to describe. Draft the disclosure language against the statutory tests, then refine it when the OAIC guidance lands. Waiting for final guidance to begin the mapping is the trap, because the commencement date does not move with the guidance.
Questions professionals are asking
Is the OAIC Issues Paper a new AI law?
No. The binding rule is a statute. The Privacy and Other Legislation Amendment Act 2024 added the automated decision-making transparency obligation to Australian Privacy Principle 1, and it commences on 10 December 2026. The 18 May 2026 Issues Paper is a consultation to help the OAIC write guidance. The OAIC states that the consultation is not a statutory requirement.
What exactly must be disclosed, and when?
From 10 December 2026, an APP entity's privacy policy must describe the kinds of personal information used in qualifying automated decision programs, the kinds of decisions made solely by those programs, and the kinds of decisions where the program does something substantially and directly related to making the decision. The obligation applies where a computer program makes or materially shapes a decision that could reasonably be expected to significantly affect an individual's rights or interests, using their personal information.
Does this apply to businesses based outside Australia?
It can. The Privacy Act reaches organisations that carry on business in Australia and handle Australians' personal information. A US or other foreign company running credit, insurance, hiring, or eligibility decisions that use Australian customers' personal data and could significantly affect them should treat the December 2026 commencement as its own deadline.
When will the OAIC guidance be final?
The OAIC states it intends to release guidance by September 2026, before the obligation commences. Consultation submissions closed on 15 June 2026. As of this writing the guidance is in development and should not be treated as final. The statutory obligation and its commencement date do not depend on the guidance being finished.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any statute, obligation, or guidance applies to your situation with qualified professionals in the relevant jurisdiction.