Skip to content
← Back to Insights
Privacy Act AI Governance Compliance Australian SMB

The AI Disclosure Deadline Most Australian Businesses Haven't Heard Of

From 10 December 2026, the Privacy Act requires businesses to disclose automated decision-making in their privacy policies. Here's what the rule actually says, whether it applies to you, what happens if you ignore it, and the five-step preparation that costs an afternoon.

Vinay Tripathi

On 10 December 2026, a new Privacy Act rule takes effect, and it has barely registered with the small businesses it applies to.

From that date, if a computer program uses personal information to make a decision that could reasonably be expected to significantly affect someone’s rights or interests, your privacy policy has to say so. Specifically, it must describe the kinds of personal information the program uses and the kinds of decisions it makes. That’s the whole obligation. This is not an AI ban; it is a disclosure rule, and five months out it is a task rather than a problem.

The requirement comes from the Privacy and Other Legislation Amendment Act 2024, which added new paragraphs to Australian Privacy Principle 1. The OAIC is still developing its detailed guidance: consultation closed in June 2026 and the office has said it intends to publish before the obligation starts, which should leave a few months to act on it. The start date is not waiting for the guidance.

Does it apply to your business?

The rule applies to organisations already covered by the Privacy Act. For most businesses that means annual turnover above $3 million.

One group grew this year. From 1 July 2026, accountants, lawyers, conveyancers, real estate professionals and dealers in high-value goods took on anti-money-laundering obligations, and small businesses that are AML/CTF reporting entities must now comply with the Privacy Act for the personal information they handle in connection with those obligations, whatever their turnover. Read that scope carefully, because it is narrower than the headline suggests. The OAIC is explicit that these businesses are still not covered by the Privacy Act for their non-AML/CTF activities, unless something else brings them in.

The practical effect for a small firm: your customer due diligence is now Privacy Act territory, while your hiring and marketing are not. Industry estimates put more than 100,000 small businesses inside the new anti-money-laundering net, and for most of them the question worth asking is whether any part of that verification work is automated. Identity matching and customer risk scoring are where to look first.

If your turnover is under $3 million and none of the special categories apply, this rule doesn’t bind you yet. I’d prepare anyway: the government has agreed in principle to remove the small business exemption entirely in a future round of reform, and the businesses that treat this as a dry run will find that round boring instead of painful.

What counts as an automated decision

The test is whether the decision could reasonably be expected to significantly affect a person’s rights or interests, and whether the computer makes it solely or substantially. Worked examples make the line clearer than definitions do.

Software that screens job applications and rejects candidates before a human looks at them: yes. A system that scores loan or credit applications: yes. An automated tool that shortlists tenants for a rental property: very likely. Marketing software that segments customers by behaviour and decides who gets which offer: possibly, depending on the stakes of what’s being offered. The spell-checker and the chatbot answering opening hours: no. The grey zone in between is real, and it is exactly what the OAIC’s coming guidance is for.

The regulator’s own research shows where public expectation sits. In the 2026 Australian Community Attitudes to Privacy Survey, 79% of Australians said they expect to be told when their personal information is used in AI systems, up from 71% in 2023. A further 81% said decisions made by AI should carry a right to human review.

What happens if you don’t

The 2024 Act rebuilt the enforcement structure underneath all of this. Alongside the existing penalty for serious interferences with privacy, it added a mid-tier civil penalty and a lower tier aimed at administrative breaches of the Australian Privacy Principles, with infringement notice powers attached. Infringement notices run to a maximum of 200 penalty units, currently $66,000, and let the OAIC act without going to court. The office can also issue a compliance notice setting out what you got wrong and how long you have to fix it.

A privacy policy missing its automated-decision paragraph is an administrative breach, which puts it at the bottom of that structure rather than the top. The honest answer on first-year enforcement is that nobody knows yet: the OAIC has not published its posture for this obligation, and the guidance is still being written. What the design tells you is that the cheap end of the toolkit now exists, and using it no longer requires a court.

The five-step preparation

For most small businesses, the work here fits in an afternoon.

  1. Inventory your automated decisions. Walk through every tool that touches customer, applicant or staff data and ask whether it decides something about a person or merely assists someone who does.
  2. Map the personal information each one uses. For every real decision-maker on that list, write down the kinds of information that feed it.
  3. Update your privacy policy to describe both, in the plainest language you can manage.
  4. Decide your human-review path. Who does a person contact when they question an automated outcome, and who has authority to override it?
  5. Brief whoever answers your phones, because disclosure creates questions.

Step four is not strictly required by this amendment, but 81% of Australians already expect it, and it is cheap to set up before someone asks. Regulation rarely announces itself twice: the businesses that hear the first announcement get to prepare on their own schedule.

The paragraph most businesses will need

Step three is the one people stall on, so here is a plain-language starting point to adapt. A small recruitment-adjacent business might write:

Automated decision-making. We use software that helps assess job applications. This software uses information you give us in your application, including your work history, qualifications and answers to screening questions, to rank and shortlist candidates. It may exclude an application from the shortlist without a person reviewing it first. If you would like a person to review a decision made this way, contact us at [address] and we will arrange it.

It names the two things the rule actually asks for, the kinds of personal information and the kinds of decisions, then tells the reader what to do next. Swap the specifics for your own and the structure holds. If your software only assists a human decision-maker, say that instead, because it is a materially different claim.

The quiet advantage

Here is the part I find genuinely useful for the businesses I work with. A privacy policy is the one document every regulator, and an increasing number of customers, reads first. A policy that plainly says “here is where software makes decisions about you, here is the information it uses, and here is who to call if you disagree” reads as confidence. Most of your competitors won’t have one until someone makes them.

We run our own operations on a governed team of AI agents, so disclosure and human-review paths are questions we’ve had to answer for ourselves, not just advise on. If you’re working through where automated decisions sit in your own business, happy to compare notes — no pitch, just a conversation.

This article is general information, not legal advice. The sample wording above is a starting point for discussion, not a compliant policy for your business. For advice on your specific obligations, talk to a privacy lawyer.

Ready to put this into practice?

VN Media Solutions works with Australian businesses to implement AI agents, automate manual processes, and build the systems that make it all work.

Start a Conversation