What Australia’s Privacy Act Means for Businesses Using AI

Artificial intelligence is no longer a future consideration for Australian businesses — it is already embedded in how many organisations hire staff, serve customers, process applications, manage logistics, and make decisions that affect people’s lives. But as AI adoption accelerates, so does the regulatory framework governing how it can be used — and the deadline for compliance is closer than many business owners realise.

The 10 December 2026 deadline requires all businesses to disclose the use of automated decision-making in their privacy policies. For businesses that have been quietly deploying AI tools without reviewing their privacy obligations, the clock is running — and the consequences of getting this wrong are significant.

This guide explains what the reforms actually require, which businesses are affected, and what practical steps you need to take before the deadline.

The Regulatory Landscape in 2026 — What Has Changed

Australia’s approach to AI regulation has taken a deliberate path. Australia rejected a standalone AI Act in December 2025, opting instead for a voluntary framework that leans on existing laws. This means there is no single “AI law” to comply with — instead, most Australian businesses will face AI obligations through existing laws rather than through new AI-specific legislation, which places the compliance burden on internal governance rather than waiting for a regulator to prescribe controls.

The primary legislative vehicle is the Privacy Act 1988 and its recent amendments. The Privacy and Other Legislation Amendment Bill 2024 (Cth) introduces significant amendments to the Privacy Act 1988 (Cth) that will strengthen transparency obligations under the Australian Privacy Principles, including the introduction of mandatory disclosures about automated decision-making systems.

The Privacy and Other Legislation Amendment Act 2024, passed in November 2024, introduced a range of new requirements — and the Australian Government has committed to further reforms addressing AI transparency and automated decision-making as a second tranche of changes.

Alongside the Privacy Act, other binding obligations include the Digital Transformation Agency Policy for Responsible Use of AI in Government for federal contractors, the Cyber Security Act 2024 for critical infrastructure entities, and the Australian Consumer Law for misleading AI capability claims.

The December 2026 Deadline — What It Actually Requires

The most immediate and concrete obligation for businesses using AI is the automated decision-making disclosure requirement under Australian Privacy Principle 1.

From 10 December 2026, the Privacy Act requires businesses to tell people, in their privacy policy, when personal information is used in automated decisions that significantly affect those people, and to explain what kinds of information and decisions are involved.

New APP 1.7–1.9 obligations require disclosure when computer programs use personal information to make decisions significantly affecting individuals.

In plain terms: if your business uses any AI system, algorithm, or automated process to make or significantly influence decisions about individuals — in hiring, lending, customer service, pricing, insurance, or any other context — you need to disclose this clearly in your privacy policy before December 10, 2026.

The obligation applies to any qualifying automated decision from that date, even if the system was built or the data collected earlier. There is no grandfather clause for AI tools already deployed — if they are still in use after the deadline, disclosure is required.

Who Is Affected?

This is one of the most important questions for Australian businesses to get right, because the answer is broader than many assume.

Historically, businesses with an annual turnover of less than $3 million were largely exempt from the Privacy Act. In 2026, the Attorney-General concluded that information is the new currency, and even a micro-business collecting email addresses or using website cookies is processing valuable personal data.

The practical implication is that the small business exemption that previously shielded many operators from Privacy Act obligations is being significantly narrowed. Any business using AI that touches personal data — which includes customer data, employee data, and any information that can identify an individual — needs to assess its compliance position.

These reforms will affect most institutional operators of student management systems, human resource platforms, and AI-enabled administration tools. But the scope extends well beyond these categories. Any business using AI-powered customer service chatbots, automated email systems, recommendation engines, credit assessment tools, or candidate screening platforms is likely within scope.

In early 2026, the Office of the Australian Information Commissioner (OAIC) launched a nationwide compliance sweep targeting high-risk sectors including property, pharmacy, retail, and digital services, signalling a move toward proactive audits rather than reactive complaint handling.

What Counts as an Automated Decision?

Understanding what triggers the disclosure obligation requires understanding what regulators mean by “automated decision-making.” This is broader than most business owners initially assume.

The obligation is not limited to fully autonomous AI systems making decisions without any human involvement. It extends to systems that significantly influence decisions — where an AI tool provides a recommendation, a score, a ranking, or an assessment that a human then acts on in a meaningful way.

Practical examples of AI uses that are likely to trigger the disclosure requirement include:

Customer-facing applications — AI chatbots that assess eligibility for services, recommend products, or triage complaints. If the AI’s output meaningfully shapes the outcome for the customer, it is likely within scope.

HR and recruitment tools — Resume screening algorithms, candidate scoring tools, and automated interview assessment platforms. These are among the highest-risk applications because decisions about employment significantly affect individuals.

Credit and financial assessment — Any automated system that assesses creditworthiness, insurance risk, or financial eligibility using personal data.

Pricing and access decisions — Dynamic pricing systems that use personal data to set prices, or platforms that use AI to determine what content or services an individual can access.

Healthcare and aged care — AI diagnostic tools, risk stratification systems, or care allocation platforms that use patient data to influence clinical or administrative decisions.

If your business uses any of these — or anything functionally similar — the December 2026 disclosure requirement applies.

What the Disclosure Actually Needs to Say

Understanding that disclosure is required is only the first step. Understanding what the disclosure must contain is equally important.

The core of the Privacy Act AI disclosure obligations is transparency: individuals have the right to know when an automated system is making or influencing a decision that significantly affects them.

At a minimum, a compliant disclosure should cover:

What AI or automated systems are used — a description of the system or systems involved, at a level of detail sufficient for a reader to understand their general nature and purpose.

What personal information is used — the categories of data the system processes when making or influencing decisions.

What kinds of decisions are involved — a plain-language description of the decision types the automated system contributes to, and how significantly it influences the outcome.

What rights individuals have — including any right to request human review of a decision made or influenced by an automated system.

In the age of AI, a generic privacy template is no longer a legal shield. Regulators now require policies to be tailored, specific, and readable. If your policy has not been updated since 2024, it is likely non-compliant with the new Statutory Tort for Serious Invasions of Privacy and updated APP 1.7 requirements.

The Penalties for Non-Compliance

The consequences of failing to meet Privacy Act obligations in 2026 are not trivial. Since 2022 reforms, serious or repeated breaches can attract penalties of up to the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover.

Stricter data quality obligations under APP 10 will be enforced with a heavier hand against AI systems that rely on probabilistic inferences. If your model hallucinates personal information, you have likely breached data quality obligations.

Beyond the direct financial penalties, the reputational consequences of a privacy breach involving AI are increasingly severe. Consumer trust in how businesses use AI is fragile — a publicised breach or enforcement action can damage customer relationships in ways that are difficult to recover from, particularly for businesses whose competitive advantage depends on handling customer data.

What Practical Compliance Looks Like

Businesses that stand up basic AI governance now — a use-case register, an impact assessment process, clear approval and incident-reporting steps — will be in a materially better position when the Australian Standards for AI move from announcement to enforceable rules.

Here is what a practical compliance programme looks like for a business that is currently using or planning to deploy AI:

Step 1: Conduct an AI use-case inventory. Document every AI tool, algorithm, or automated system your business currently uses or is planning to use. Include third-party tools — off-the-shelf AI features embedded in software platforms you use — not just custom-built systems.

Step 2: Assess which use cases involve personal information. For each AI use case identified, determine whether it processes personal information and whether it makes or significantly influences decisions affecting individuals.

Step 3: Conduct a Privacy Impact Assessment (PIA) for high-risk use cases. For AI systems that process sensitive personal information or make consequential decisions, a formal PIA documents the risks identified and the controls put in place to mitigate them.

Step 4: Update your privacy policy. Before December 10, 2026, your privacy policy must be updated to disclose all qualifying automated decision-making. The disclosure should be specific, readable, and accurate — not a generic reference to “automated tools.”

Step 5: Establish ongoing governance. Compliance is not a one-time exercise. Appoint a person responsible for AI governance, establish a process for reviewing new AI deployments before they go live, and implement a monitoring process to identify when existing systems change in ways that trigger new obligations.

Step 6: Review vendor contracts and data sharing agreements. If third-party AI tools process personal data on your behalf, your contracts with those vendors should reflect your Privacy Act obligations — including data processing agreements, breach notification requirements, and the right to audit.

What This Means for Businesses Building Custom AI

For businesses investing in custom AI development — rather than simply using off-the-shelf tools — the compliance picture is more nuanced, but the obligations are the same. A custom AI system built specifically for your business is still subject to the Privacy Act’s transparency requirements if it processes personal information and makes or influences decisions about individuals.

This is one of the strongest arguments for working with experienced providers of AI Development Services in Adelaide or anywhere in Australia who understand not just how to build AI systems, but how to build them in a way that supports compliance from the ground up. Privacy-by-design — embedding data minimisation, transparency mechanisms, and access controls into the system architecture rather than retrofitting them later — is far more effective and far less expensive than trying to make a non-compliant system compliant after it has already been deployed.

Custom AI solutions in Adelaide built with compliance in mind will include features such as audit logging of automated decisions, user-facing transparency notices at the point of decision, the ability to generate reports on how the system used personal data in a given decision, and clearly defined data retention and deletion policies. These are not bureaucratic additions — they are the functional requirements of a compliant system, and they are far easier to build in than to retrofit.

The Broader Picture — AI Governance Beyond the Privacy Act

While the Privacy Act’s December 2026 deadline is the most immediate obligation for most businesses, it sits within a broader governance context that forward-thinking organisations are already addressing.

The Australian Consumer Law prohibits misleading conduct — which extends to misleading claims about AI capabilities, including overstating what an AI system can do or failing to disclose material limitations. If your business markets AI-powered services to customers, the accuracy of those claims is a consumer law issue as well as a privacy one.

Copyright law is also in flux — Parliament rejected a text-and-data-mining exemption for AI training in April 2026 and is exploring a paid licensing model instead. Businesses that have been training AI models on publicly available data should be aware that the legal status of this practice is actively being reconsidered.

And for businesses in healthcare, finance, and other regulated industries, sector-specific obligations — from APRA’s prudential standards to the Therapeutic Goods Administration’s guidance on AI in medical devices — layer additional requirements on top of the Privacy Act baseline.

Why Acting Now Is Better Than Waiting

The “wait for guidance” strategy is no longer viable. The December 2026 deadline is fixed, the OAIC is already conducting proactive compliance sweeps, and the volume of work involved in achieving compliance — particularly for businesses with multiple AI use cases or complex data environments — means that leaving it until the last quarter of 2026 creates genuine risk of not making the deadline.

For businesses in the early stages of AI adoption, starting with compliance in mind is significantly easier than deploying first and retrofitting later. For businesses already using AI tools, the time to conduct your use-case inventory and update your privacy documentation is now — not in November.

Working with a software development firm in Adelaide that understands both the technical requirements of building compliant AI systems and the regulatory framework those systems need to operate within gives you the best chance of deploying AI confidently — in a way that serves your customers well, manages your legal risk, and positions your business for the next stage of the AI regulation journey in Australia.

Final Thoughts

Australia’s Privacy Act reforms represent the most significant change to the country’s data protection framework in decades, and the AI-specific obligations coming into force in December 2026 have real, practical consequences for businesses across every industry.

The core message is straightforward: if your business uses AI or automated systems that make or influence decisions affecting individuals, you have a legal obligation to disclose this in your privacy policy by December 10, 2026 — and broader obligations around data quality, security, and accountability apply regardless of that deadline.

The businesses that will navigate this transition most successfully are those that treat Privacy Act compliance not as a legal burden to be managed but as an opportunity to build genuine trust with their customers around how AI is used in their business. In a market where consumer confidence in AI is hard-won and easily lost, that trust is worth more than the cost of getting compliance right.

Get Free Expert Advice

Request a call

Your Name*
Your Email*
Your Phone Number
Select date and time*
Your Message (optional)*