orangeAI
Discover · phase 1
AI Readiness Scorecard FreeA three-minute self-check.AI Opportunity Call FreeA straight steer on your best next step.AI Activation $2,499Switched on as a client, map in hand.AI Discovery & Roadmap AnchorKnow exactly where AI earns its place.Process CaptureHow the work happens, documented as an asset.Reasoning CaptureKey-person judgement, made an asset.
Design & Ignite · phases 2–3
Design & BuildThe engine that constructs it all, including skill design.
Amplify · phase 4
Chief AI OfficerAn accountable AI executive on retainer.Managed AgentsHigh-stakes work, run as a governed service.Business IntelligenceLive cockpits, assembled and analysed overnight.Governed AI RolloutYour whole workforce, switched on safely.
One methodology: Discover → Design → Ignite → Amplify. Every product sits on it.How I work →The Client Portal →Full map →
MethodologyCase studiesInsightsAboutClient Portal ↗
Free AI Scorecard
Home
Discover
AI Readiness Scorecard · FreeAI Opportunity Call · FreeAI Activation · $2,499AI Discovery & RoadmapProcess CaptureReasoning Capture
Design & Ignite
Design & Build
Amplify
Chief AI OfficerManaged AgentsBusiness IntelligenceGoverned AI Rollout
Company
MethodologyHow I workCase studiesThe Client PortalInsightsAboutClient Portal loginContact us · hello@orangeai.com.auStart here: free AI Scorecard or a call
orangeAI

We map how your business actually runs, then put AI where it earns its place. Brisbane, Australia.

What we do
What we doMethodologyCase studiesInsights
Company
AboutContactPortal login
Follow

Content lands on LinkedIn first.

The Lens, weekly
PartnersMicrosoft PartnerAnthropic · Claude Partner Network
Orange AI Pty Ltd (ABN 55 697 856 447) · Privacy · Terms · Contact© 2026 Orange AI Pty Ltd
BlogPrivacy And ComplianceAutomated Decision MakingAI Implementation

Your Privacy Policy Now Has to Describe Your AI

By Brad Ferris · 3 October 2026

5 min read

On 30 September the Office of the Australian Information Commissioner released new resources on transparency for use of AI and automated decision-making: a fact sheet, a flowchart, a supplementary sheet for government agencies and an update to the APP 1 guidelines. They support an obligation that commences on 10 December 2026. From that date, any business covered by the Privacy Act that has arranged for a computer program to make or inform decisions significantly affecting individuals must say so in its privacy policy.

That is 68 days from today. The OAIC says the material reflects 90 written submissions to the consultation it ran earlier this year, so the regulator has now set out how it reads the law. Most mid-sized businesses are covered by the Privacy Act, and most of their privacy policies say nothing about automated decisions.

What the obligation asks for

The test has three parts, and all three have to be met.

First, the business has arranged for a computer program to make a decision, or to do something "substantially and directly related" to making one. Second, the decision could reasonably be expected to significantly affect an individual's rights or interests. Third, personal information about that individual is used when the program runs.

Where all three apply, the privacy policy has to describe three things: the kinds of personal information the program uses, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially related to the decision while a person makes the final call.

Two points follow from that wording. The obligation is not limited to AI in the sense most people use the word. A rules engine, a scoring spreadsheet with macros or a configured workflow in your ERP can all qualify. And it is not limited to fully automated decisions. A tool that ranks, filters or recommends, with a person signing off at the end, sits inside the second category.

Where these decisions hide in a mid-sized business

Very few operators would say their business runs automated decisions about people. Ask a different question, which systems sort, score or rank customers, applicants or staff, and the list usually gets longer.

Credit and trade terms are the obvious place to start. Any tool that sets a credit limit, approves an account or flags a customer as high risk from their payment history is a candidate. So is dynamic pricing or discounting that varies by customer profile.

Recruitment is the second. Many applicant tracking systems screen or rank candidates before a person reads a résumé. The business may never have switched that feature on deliberately, but if it is running, it is in scope.

Then there is the long tail: fraud and claims triage, collections prioritisation, tenancy or membership approvals, rostering tools that allocate shifts based on performance data, and customer service platforms that decide who gets escalated and who gets a bot. Some of these will fall below the "significantly affect" threshold. That judgement has to be made one decision at a time, and written down.

A growing share of these features arrive inside software you already pay for. A vendor update can switch on an AI scoring feature in a platform your team has used for years. The obligation attaches to your business, because you arranged for the program to be used, whoever wrote the code.

Why the inventory is the real job

Drafting the privacy policy clause takes an afternoon once you know what to put in it. Knowing what to put in it is where the time goes, because in most businesses nobody holds a complete list of where software is making or shaping decisions about people.

That list tends to be spread across whoever administers each system. Finance knows how credit limits are set. HR knows what the recruitment platform does, roughly. Operations knows the rostering rules. The IT provider knows which features are licensed but often not which are switched on. Pulling those threads together is a few weeks of steady work rather than a heroic effort, but it has to start soon to finish before December.

There is a commercial upside to doing it properly. The same inventory tells you where software is already shaping outcomes for customers and staff, which of those decisions nobody is reviewing, and where an automated process could be extended or should be pulled back. Most businesses have never had that view in one place.

A sensible order of work

Start with a register. One row per system that touches decisions about individuals: what the decision is, what personal information feeds it, whether a person reviews the result, and who in the business owns it. Use the OAIC flowchart to test each row against the three conditions.

Next, sort the in-scope rows into the two categories the policy has to describe: decisions made solely by a program, and decisions where a program does something substantially related while a person decides. The policy describes kinds of decisions, so the wording can be grouped and plain.

Then draft the clause and have it reviewed by whoever advises the business on privacy. Keep the register as the working record behind it, and give it an owner. New software, new features and vendor updates will keep adding rows, and the policy has to stay accurate after 10 December as well as on it.

None of this needs a new platform or a large project. It needs someone with enough authority to ask every system owner the same questions, and enough time between now and early December to get the answers.


Where does your business stand? The free AI Scorecard takes three minutes and shows you. If you want a straight steer from a person, book an AI Opportunity Call.

Sources
  • New resources on transparency for use of AI and automated decision-making · Office of the Australian Information Commissioner
  • Consultation on Guidance for Transparency in Automated Decision Making · Office of the Australian Information Commissioner
What's your next move?

Find out where your business sits on the AI maturity curve.

Take the free AI ScorecardBack to insights