EU AI Act GPAI obligations are now in force. Is your documentation ready? See GRC Toolkits →
Blog

Regulatory insight, plain-English guidance.

AI governance, compliance and finance, explained without the jargon — timed to the deadlines that actually matter.

Most Australian businesses have spent the past fortnight watching the EU AI Act’s 2 August deadline. Fewer are watching the reform that will actually affect them more directly: AU Privacy Act reform introduces new automated decision-making (ADM) transparency obligations that commence on 10 December 2026, reaching straight into how businesses use AI on customer and staff data.

What’s actually changing

The 2024 tranche of reforms introduced a “fair and reasonable” test for handling personal information and strengthened enforcement powers for the OAIC. The next tranche of AU Privacy Act reform builds on that foundation with a new APP 1.7 transparency obligation, specifically targeting automated decision-making (ADM) — any process where AI makes, or substantially assists, a decision that affects an individual: credit assessments, employment screening, insurance pricing, eligibility checks, and similar.

The OAIC’s own consultation materials set out the test in three parts, all of which have to be present: a computer program made the decision, or did something substantially and directly related to making it; the decision could reasonably be expected to significantly affect an individual’s rights or interests; and personal information was used in that process. Where all three apply, businesses will need to disclose in their privacy policy that automated decision-making is occurring, and explain the kinds of personal information and decisions involved.

Why this matters more than it looks like it does

Unlike the EU AI Act, there’s no jurisdictional question here — if you’re an Australian business handling Australian customer or staff data, this applies to you directly, on top of obligations you already carry under the existing Australian Privacy Principles. And because AI tools are usually adopted tool-by-tool, team-by-team, most businesses don’t actually have a clear answer to the question a regulator or an enterprise customer will eventually ask: which of our systems make or assist decisions about people, and what data goes into them?

That gap — not knowing what you don’t know — is the real exposure. It’s also, conveniently, the easiest part to fix before the reform lands rather than after.

Who is most exposed

Some sectors will feel AU Privacy Act reform sooner and harder than others. Financial services and insurance businesses running any kind of automated credit or pricing assessment sit squarely inside the definition. Recruitment and HR platforms using AI to screen or shortlist candidates are another clear fit — “employment screening” is named explicitly in how the obligation is being framed. Healthcare and NDIS providers using AI-assisted eligibility or triage tools carry a double exposure, since they’re often also handling sensitive information, which the Privacy Act treats with a stricter standard than ordinary personal information.

But the obligation isn’t sector-specific by design — any business using an AI tool that substantially assists a decision about a customer, applicant, or employee needs to work through the same three-part test. A retail business using AI to flag high-risk returns, a professional services firm using AI to screen job applicants, and an NDIS provider using AI to support intake decisions are all, in principle, in scope.

What non-compliance actually costs

This isn’t a soft disclosure norm — it’s an enforceable Australian Privacy Principle, and the OAIC’s expanded enforcement powers (in effect since December 2024) already apply to it. A privacy policy that fails to meet the APP 1.7 transparency requirements once the obligation commences exposes a business to compliance notices, infringement notices, and civil penalties, on top of the reputational cost of a regulator or journalist finding the gap before you’ve closed it.

The OAIC has also signalled it’s reading the obligation broadly — its Issues Paper flags an expansive interpretation of what counts as automated decision-making, which means businesses that assume “we have a human in the loop, so we’re exempt” are likely to find that assumption doesn’t hold once final guidance lands, expected around September 2026.

What a proportionate response looks like

You don’t need a privacy counsel on retainer to get ahead of this. Three things matter most:

This is exactly the gap Madalent’s Data Classification for AI Policy is built to close first — a plain-English framework for classifying what data can and can’t go into AI tools, ready to adapt to your business in under a day, not a six-week engagement.

Get the Data Classification for AI Policy — $49 AUD →

Seeing the whole picture

If you’re already juggling EU AI Act, ISO 42001, and now AU Privacy Act reform in your head, a document-by-document approach starts to feel like whack-a-mole. The Regulatory Compliance Matrix maps your obligations across all three in one place, so you can see exactly where the gaps are before a regulator, insurer, or enterprise customer points them out for you.

Get the Regulatory Compliance Matrix →

Not sure where your business actually sits? Start with the free AI Governance Readiness Checklist — a plain-English self-assessment covering data use, automated decision-making, and where you stand against ISO 42001, the EU AI Act, and Australian privacy law. If your business also has EU exposure, our related piece covers the EU AI Act’s GPAI obligations starting August 2026 in more detail.

Frequently Asked Questions

When does AU Privacy Act reform’s automated decision-making obligation start?

10 December 2026. The Privacy and Other Legislation Amendment Act 2024 introduced the obligation, with a two-year grace period ending on that date. Final OAIC guidance is expected around September 2026.

Does the AU Privacy Act reform only apply to fully automated decisions?

No. The obligation applies where a computer program made the decision, or did something substantially and directly related to making it — human sign-off does not automatically exempt a business if the software did the heavy lifting.

What happens if a business doesn’t update its privacy policy in time?

The OAIC’s enforcement powers, in effect since December 2024, already extend to this obligation — non-compliance can expose a business to compliance notices, infringement notices, and civil penalties.

How is this different from the EU AI Act?

There’s no jurisdictional question with AU Privacy Act reform — it applies directly to any Australian business handling Australian customer or staff data, on top of existing Australian Privacy Principles obligations, regardless of EU exposure.

One Response

Leave a Reply

Your email address will not be published. Required fields are marked *