From 10 December 2026, a new Privacy Act obligation requires many organisations to disclose how they use AI in decisions affecting customers and staff. Here is what changes and where to start.
AI & Technology
Artificial intelligence is now a Privacy Act problem, not just a technology one.
From 10 December 2026, a new transparency obligation under the Privacy Act comes into effect. Organisations that use AI or other automated systems to make decisions affecting customers, employees or other stakeholders will need to say so, clearly, in their privacy policy.
Privacy and Other Legislation Amendment Bill 2024
https://www.aph.gov.au/Parliamentary_Business/Bills_LEGislation/Bills_Search_Results/Result?bId=r7249
What is actually changing
The Privacy and Other Legislation Amendment Act 2024 inserts new provisions into Australian Privacy Principle 1.
Where an organisation arranges for a computer program to make, or do something substantially and directly related to making a decision, and that decision could reasonably be expected to significantly affect an individual's rights or interests, and personal information is used to make it, the organisation must disclose in its privacy policy the kinds of personal information used and the kinds of decisions made this way.
A "computer program" in this context is not limited to a dedicated AI product. It covers any software that follows rules or logic to produce an output, from a simple scoring spreadsheet to a machine learning model.
AI systems fall squarely within it, but so does older automation such as an eligibility calculator or a rules-based approval engine. The obligation is not about the technology being new or intelligent. It is about a program standing in for, or feeding into, a human decision.
The obligation reaches further than most businesses expect:
It applies to decisions made after commencement, even where the underlying data was collected, or the AI tool was already in use, well before December.
It covers decisions supported by AI, not only decisions made entirely by a machine. A staff member accepting an AI-generated recommendation without meaningful independent review can still trigger it.
It applies regardless of whether the organisation built the AI system itself or is using a third-party tool.
Why this affects more than the technology team
Sending information to an external AI provider through an application programming interface is generally treated as a disclosure of personal information, not merely an internal use.
That distinction matters under the existing cross-border rules in Australian Privacy Principle 8 and section 16C of the Privacy Act. It means the organisation stays accountable for how the vendor stores, processes and potentially trains on that information, wherever in the world it happens.
For a business that has not mapped where AI touches personal information, this is a genuine blind spot. It is not only the AI product chosen deliberately. It includes AI features embedded in everyday software, and tools staff have adopted on their own initiative.
Three things that separate the organisations that are ready
Know where AI is actually used. Identify every tool that processes personal information, understand what it does with that information, and ask honestly whether it influences a decision affecting a customer, employee or other stakeholder.
Understand where the data goes. Where a vendor is based, what its contract says about retention and training, and whether sub-processors are involved, all shape the organisation's exposure and its ability to give an accurate account in its privacy policy.
Be able to explain the decision. A privacy policy cannot describe an automated decision the organisation itself cannot explain. Governance, a properly conducted privacy impact assessment, and clear internal ownership of AI tools earn their keep well before a regulator or a customer asks the question.
Processing, Use and Disclosure
"Processing" simply means anything done with information once it is collected: storing it, looking at it, analysing it, or feeding it into a system such as an AI tool.
"Use" and "disclosure" describe two different things that can happen to that information, and the law treats them differently.
Use means the information stays within the organisation's own control, an employee reading a file, or a system searching records.
Disclosure means the information is handed to someone outside the organisation who can then access or act on it independently, whether that is another company, a contractor, or an AI provider.
Sending information to an external AI provider through an application programming interface is generally treated as a disclosure of personal information, not merely an internal use.
That distinction matters under the existing cross-border rules in Australian Privacy Principle 8 and section 16C of the Privacy Act.
It means the organisation stays accountable for how the vendor stores, processes and potentially trains on that information, wherever in the world it happens.
Where to start
Organisations do not need to wait for the Office of the Australian Information Commissioner's final guidance to begin.
A practical starting point is a short inventory of AI tools in use, a review of the contracts behind them, and an honest assessment of which decisions they touch.
From there, updating privacy policies and collection notices, and building a simple approval process for new AI tools, closes most of the gap before December.
If your organisation needs to map its AI use, review vendor arrangements or update its privacy disclosures before the deadline, our Technology, Data and Privacy service can help you get ahead of it.




