Australia Sets December Deadline for Transparency on AI-Assisted Decisions
Key Takeaways
- New Rules Take Effect December 10: Australian Privacy Principle entities will face new privacy policy disclosure requirements covering certain uses of computer programs in decisions that significantly affect individuals.
- Human Involvement Does Not Necessarily Exclude a System: The requirements can cover programs that substantially and directly contribute to a decision, not only decisions made entirely by automated systems.
- Organizations Must Explain What Is Happening: Privacy policies must identify the kinds of personal information used and the kinds of decisions made or materially informed by relevant computer programs.
- Third-Party Systems Can Be in Scope: Contracting with an outside provider does not necessarily remove an entity's obligations when its technology is used in consequential decision-making.
- OAIC Publishes Compliance Resources: The regulator released updated guidance, fact sheets and a flowchart ahead of the December deadline following 90 written consultation submissions.
Deep Dive
On December 10, a privacy policy in Australia will have to say something it has never been required to say before: whether a computer program is being used to make, or materially help make, decisions that significantly affect people.
The Office of the Australian Information Commissioner is now telling organizations what that means in practice. On September 30, the regulator published new guidance ahead of the deadline, including an updated version of its Australian Privacy Principle 1 Guidelines, a fact sheet, separate guidance for government agencies and a flowchart for determining when the new requirements apply.
There is an important detail in the rule that could easily be missed. This is not confined to decisions made entirely by artificial intelligence. A person can still be sitting at the end of the process making the final call. If a computer program does something substantially and directly related to that decision, and personal information about the individual is used in the program, the transparency requirement can apply.
That makes the December deadline considerably more relevant to organizations already using software to screen applicants, assess customers, recommend outcomes or otherwise narrow the choices presented to a human decision-maker.
The requirements come from amendments made by the Privacy and Other Legislation Amendment Act 2024 and added to APP 1 of the Australian Privacy Principles. APP 1.7 sets out 3 conditions. An entity must have arranged for a computer program to make a decision or do something substantially and directly related to making one. The decision must reasonably be expected to significantly affect an individual's rights or interests. And personal information about that individual must be used in the operation of the program.
When all 3 conditions are met, APP 1.8 requires the organization's privacy policy to disclose the kinds of personal information used by those programs. It must also describe the kinds of decisions made solely by the programs and the kinds of decisions where a program performs something substantially and directly related to reaching the decision.
The wording matters. A disclosure saying simply that an organization “uses AI” would tell a person very little about what is actually happening to their information. The OAIC's updated guidance instead points organizations toward something more concrete. People should be able to understand what kinds of decisions are involved and what kinds of their personal information are being fed into the systems that make or influence them.
The regulator's interpretation of “computer program” is broad as well. Its guidance encompasses rule-based systems, artificial intelligence and machine learning, along with software and applications more generally. Generative AI tools can also qualify.
Nor does adding a human to the process necessarily solve the problem. Where a program recommends or guides an outcome, the OAIC says organizations should consider where it sits in the decision-making process, what information is used to generate its output, what parameters it operates under and how much influence that output has over the eventual decision.
That is where the rule starts to reach beyond the obvious cases. A program does not have to issue the final yes or no. A system that ranks candidates before a hiring decision, produces material used in a performance assessment or otherwise shapes what a human decision-maker sees can matter under the new requirements if its role is substantial and directly related to the decision.
The decisions themselves can reach deeply into ordinary life. The OAIC's guidance identifies areas including healthcare, employment, housing, education, financial assistance, banking and credit, telecommunications and essential utilities. Contractual rights can count too, including a person's eligibility for a life insurance policy.
And “significantly affect” does not mean “harm.” APP 1.9 makes clear that a decision can significantly affect someone's rights or interests even when the effect is beneficial.
Knowing Where the System Sits
For organizations preparing for December 10, one of the harder questions may be deceptively basic: where are these programs actually being used? Buying the technology from somebody else does not necessarily put the answer outside an entity's responsibility. The OAIC says an organization can have arranged for a computer program to be used when it contracts with a third party to provide one.
Its examples make the point plainly. An employer might procure an AI system that screens and ranks job candidates. Employees might be permitted to use an AI chat tool to draft performance assessments that determine promotions. A business might contract with a software provider whose system automatically approves or rejects refund requests.
Different systems, different decisions, same underlying problem. The organization needs to understand what role the program is playing. The OAIC says entities should maintain oversight of third-party systems during procurement and after they have been deployed. That includes understanding how the program contributes to decisions and making clear through contractual arrangements where ultimate decision-making capability or judgment rests.
The privacy policy comes later. An organization cannot meaningfully disclose its automated decision-making practices if it has not first established what software its people are using, what information those systems consume and what happens to their outputs.
The OAIC is not asking organizations to publish their source code or bury people in technical descriptions. Its guidance says disclosures should provide meaningful information in clear and accessible language. Similar decisions and categories of personal information can be grouped where that still leaves a reasonable person with a useful understanding of what is happening.
There is also an exclusion for commercial-in-confidence information, though the regulator cautions against treating that as a general shelter for anything commercially valuable.
The September guidance is the product of a consultation that received 90 written submissions from academia, civil society, government, industry, industry bodies and other interested parties. It gives organizations a fact sheet on APP 1.7 through APP 1.9, supplementary material for government agencies and a flowchart to help determine whether a particular use of a computer program triggers the requirements.
December 10 is the date on the calendar. The more difficult work comes before it. Organizations have to find the systems that matter, including the less conspicuous ones already sitting inside ordinary workflows. They have to determine what personal information those systems use, what decisions they make or influence and whether those decisions significantly affect individuals. Only then can the privacy policy describe something the organization itself properly understands.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

