Automated Decision-Making Privacy Act: What Changes 10 Dec

Woman in a black blazer reviewing printed documents in a binder beside a laptop at a white desk.

The automated decision-making Privacy Act rules start on 10 December 2026, and the regulator has now spelled out what it expects. Last week the Office of the Australian Information Commissioner (OAIC) published new guidance on when businesses must tell people, in their privacy policy, that software or AI makes or informs decisions about them. This week, the AI debate has moved from Canberra to boardrooms: Medibank’s chief executive has called for health AI regulation, federal agencies are finishing their AI use registers, and the parliamentary AI inquiry is hearing about mandatory incident reporting. If your business uses AI, a scoring rule or a SaaS feature to decide anything that matters to customers or staff, now is the time to map it.

Here is what the rule requires, which uses are likely to be caught, and a checklist to get ready.

What the automated decision-making rule requires

The obligation was introduced by the Privacy and Other Legislation Amendment Act 2024 and sits in Australian Privacy Principle 1, which already requires an up-to-date privacy policy. According to the OAIC’s 30 September announcement, from 10 December 2026 an organisation covered by the APPs must add information to its privacy policy when all three of these apply:

  • it has arranged for a computer program to make a decision, or to do something substantially and directly related to making one;
  • the decision could reasonably be expected to significantly affect an individual’s rights or interests; and
  • personal information about that individual is used by the program.

Where the test is met, the privacy policy must describe the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions the program substantially and directly informs. The OAIC released a fact sheet, a flowchart and updated APP 1 guidelines, shaped by 90 written submissions.

“Computer program” is wider than AI

The OAIC fact sheet says a computer program includes pre-programmed rule-based processes, AI and machine learning, ordinary software and apps, and generative AI, including chatbots. Three points stand out for business owners:

  • Human review is not an automatic exit. A decision can be in scope even when a person reviews the output. The OAIC says machine learning or generative AI outputs used for significant decisions would generally be in scope unless subject to extensive human oversight and control.
  • Bought software counts. Procuring a third-party tool, or configuring an off-the-shelf product, can mean you have “arranged for” the program. The obligation generally stays with you, not the vendor, although vendors are expected to give you clear, high-level information.
  • Even a spreadsheet can be caught. One OAIC example is a health and aged care provider whose spreadsheet formula ranks clients to decide who gets contacted for support. That is in scope, and so is using the same ranking to decide who not to contact.

If you are unsure, the OAIC’s advice is to take a cautious approach and include the information.

Which decisions are likely to be in scope

The fact sheet lists examples the OAIC would generally consider in scope. Several map directly to common business AI projects:

  • facial recognition used in a retail store or stadium for watchlist matching, which is relevant to any computer vision system that identifies people;
  • recruitment software that sorts candidate profiles and informs hiring decisions, a growing area of AI in HR;
  • programs that prioritise the provision of health or disability services;
  • programs that approve or reject loan or credit applications, or assess eligibility for insurance, both core to finance AI and insurance software;
  • personalised pricing for significant goods, and AI reports that rank employee performance or set bonuses.

You do not have to reveal trade secrets. Commercially sensitive details, such as how a fraud model weights each data point, are excluded. But the fact that you use personal information to power such tools is not confidential, and sensitive inputs such as health information or biometric templates should be clearly identified.

Why this week makes it urgent

Three stories this week show AI decision-making becoming a governance issue.

Health. Medibank chief executive David Koczkar told news.com.au that AI is the “next big shift in health” but needs proper governance and regulation so vulnerable people are not exploited. He said about 73% of Medibank workers use AI in their everyday work, and 80% of clinicians in its virtual GP network use AI scribing, saving about four minutes per consultation. Documentation tools like scribes are different from tools that prioritise or refuse care, and knowing exactly where that line sits in your systems is the point of the new rule. For more on that line, see our healthcare AI page.

Government. The Canberra Times reported that freedom of information requests to 18 departments and agencies revealed hundreds of AI deployments, from summarising documents to assessing grant eligibility. Every agency must keep an internal AI use register under the Digital Transformation Authority’s responsible use of AI policy, with a final deadline in December. Businesses that sell to government should expect the same questions from their clients.

Incidents. At the Joint Select Committee on AI, Information Age reported that the government is considering a mandatory reporting regime for AI-related cybersecurity incidents, which both OpenAI and Anthropic said they would welcome. Labor is also developing national AI standards.

A practical checklist before 10 December

  1. Build an AI and automation register. List every tool that uses personal information to score, rank, approve, price, route or flag people. Include SaaS features, chatbots, AI agents and spreadsheets, not just projects labelled “AI”.
  2. Apply the three-part test to each one. Does it make or substantially inform a decision? Could that decision significantly affect someone? Does it use their personal information? Record your reasoning.
  3. Ask your vendors for decision information. Request plain-language descriptions of the inputs their software uses and the decisions it supports, so you can describe them accurately.
  4. Decide how much human oversight is real. The OAIC’s examples suggest that interrogating outputs, checking the underlying evidence and documenting why staff departed from a recommendation all matter. A rubber stamp is not oversight.
  5. Update your privacy policy. Add a clear section on decisions made or informed by computer programs, grouped sensibly, with sensitive information called out.
  6. Train the people who use the tools. Staff need to know which outputs are advisory and when to escalate. Short, role-based AI training helps the policy stick. Our free AI assistant course covers approvals and guardrails in four short lessons.

Not sure what a structured review looks like? Our guide to what an AI audit includes walks through the inventory, risk and data-flow steps.

This is general information, not legal advice. Read the OAIC guidance in full and get advice from a privacy lawyer about your own circumstances.

What to watch next

Watch for the remaining inquiry hearings this week, any detail on the proposed incident reporting regime, and further OAIC resources as 10 December approaches. Expect customers, insurers and government buyers to start asking for your AI register well before the regulator does.

Get your AI decisions mapped before December

Not sure which of your tools make or inform decisions about people? An AI business audit builds your AI register, maps personal information flows and flags what belongs in your privacy policy. Aideveloper builds compliance-first AI systems for Australian organisations. Talk to us about getting ready for 10 December.

Featured image: Photo by Karolina Grabowska on Pexels.