By Brad Ferris · 3 October 2026
On 30 September the Office of the Australian Information Commissioner released new resources on transparency for use of AI and automated decision-making: a fact sheet, a flowchart, a supplementary sheet for government agencies and an update to the APP 1 guidelines. They support an obligation that commences on 10 December 2026. From that date, any business covered by the Privacy Act that has arranged for a computer program to make or inform decisions significantly affecting individuals must say so in its privacy policy.
That is 68 days from today. The OAIC says the material reflects 90 written submissions to the consultation it ran earlier this year, so the regulator has now set out how it reads the law. Most mid-sized businesses are covered by the Privacy Act, and most of their privacy policies say nothing about automated decisions.
The test has three parts, and all three have to be met.
First, the business has arranged for a computer program to make a decision, or to do something "substantially and directly related" to making one. Second, the decision could reasonably be expected to significantly affect an individual's rights or interests. Third, personal information about that individual is used when the program runs.
Where all three apply, the privacy policy has to describe three things: the kinds of personal information the program uses, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially related to the decision while a person makes the final call.
Two points follow from that wording. The obligation is not limited to AI in the sense most people use the word. A rules engine, a scoring spreadsheet with macros or a configured workflow in your ERP can all qualify. And it is not limited to fully automated decisions. A tool that ranks, filters or recommends, with a person signing off at the end, sits inside the second category.
Very few operators would say their business runs automated decisions about people. Ask a different question, which systems sort, score or rank customers, applicants or staff, and the list usually gets longer.
Credit and trade terms are the obvious place to start. Any tool that sets a credit limit, approves an account or flags a customer as high risk from their payment history is a candidate. So is dynamic pricing or discounting that varies by customer profile.
Recruitment is the second. Many applicant tracking systems screen or rank candidates before a person reads a résumé. The business may never have switched that feature on deliberately, but if it is running, it is in scope.
Then there is the long tail: fraud and claims triage, collections prioritisation, tenancy or membership approvals, rostering tools that allocate shifts based on performance data, and customer service platforms that decide who gets escalated and who gets a bot. Some of these will fall below the "significantly affect" threshold. That judgement has to be made one decision at a time, and written down.
A growing share of these features arrive inside software you already pay for. A vendor update can switch on an AI scoring feature in a platform your team has used for years. The obligation attaches to your business, because you arranged for the program to be used, whoever wrote the code.
Drafting the privacy policy clause takes an afternoon once you know what to put in it. Knowing what to put in it is where the time goes, because in most businesses nobody holds a complete list of where software is making or shaping decisions about people.
That list tends to be spread across whoever administers each system. Finance knows how credit limits are set. HR knows what the recruitment platform does, roughly. Operations knows the rostering rules. The IT provider knows which features are licensed but often not which are switched on. Pulling those threads together is a few weeks of steady work rather than a heroic effort, but it has to start soon to finish before December.
There is a commercial upside to doing it properly. The same inventory tells you where software is already shaping outcomes for customers and staff, which of those decisions nobody is reviewing, and where an automated process could be extended or should be pulled back. Most businesses have never had that view in one place.
Start with a register. One row per system that touches decisions about individuals: what the decision is, what personal information feeds it, whether a person reviews the result, and who in the business owns it. Use the OAIC flowchart to test each row against the three conditions.
Next, sort the in-scope rows into the two categories the policy has to describe: decisions made solely by a program, and decisions where a program does something substantially related while a person decides. The policy describes kinds of decisions, so the wording can be grouped and plain.
Then draft the clause and have it reviewed by whoever advises the business on privacy. Keep the register as the working record behind it, and give it an owner. New software, new features and vendor updates will keep adding rows, and the policy has to stay accurate after 10 December as well as on it.
None of this needs a new platform or a large project. It needs someone with enough authority to ask every system owner the same questions, and enough time between now and early December to get the answers.
Where does your business stand? The free AI Scorecard takes three minutes and shows you. If you want a straight steer from a person, book an AI Opportunity Call.