
This is a practical overview for product teams, not legal advice. Your obligations depend on your organisation and your data, so check the detail with your privacy adviser.
If your product uses AI with personal information, a date is coming up that is worth planning for. From 10 December 2026, organisations covered by the Privacy Act must explain certain automated decisions in their privacy policies. The change came in through the Privacy and Other Legislation Amendment Act 2024, which added APPs 1.7 to 1.9.
It is a transparency obligation, not a ban. But preparing for it forces useful questions about where AI sits in your product, and the design decisions that make disclosure simple are the same ones that make the product safer.
The obligation applies where all of these are true:
Where it applies, your privacy policy needs to describe the kinds of personal information used and the kinds of decisions made. You are not expected to publish commercially confidential detail about how your system works.
The OAIC consulted on guidance through May and June 2026 and said it intended to publish that guidance ahead of the start date. Check the OAIC website for the current version before you finalise anything.
Many teams will assume they are outside the rule because a person makes the final call. Be careful with that. The obligation covers programs that do something substantially and directly related to a decision, not only programs that make it. Several law firms reading the OAIC's issues paper have noted it points to a broad interpretation, where AI that materially shapes what a decision maker sees may still bring the workflow in scope.
Context matters too. The OAIC has indicated that whether an effect is significant can depend on who is affected, and a decision affecting a child or a vulnerable person may be significant where the same decision for someone else would not be. If you build for health, disability, education or community services, assume closer scrutiny.
The December change sits on top of principles that already apply whenever personal information passes through an AI feature:
The OAIC's guidance on commercially available AI products also recommends, as best practice, that organisations don't enter personal information, and particularly sensitive information, into publicly available generative AI tools.
On coverage: many small businesses with annual turnover under $3 million are exempt from the Privacy Act, but not all. Health service providers are covered regardless of size, and so are some other organisations. Don't assume the exemption applies without checking.
The cheapest compliance work is done in the architecture, before launch. These are the decisions we made on Nooma, the AI practice companion we designed and built with O-HR, where the data is workplace investigation records about real people:
Not every product needs all of these. But each one is far cheaper to decide before the build than to retrofit after a customer, a board or a regulator asks.
If you want an independent view of where AI touches personal information in your product, Strategy & Audit covers it as part of a fixed-scope review. Or see how we build AI into products that handle sensitive data.
Book a free 30-minute call. We'll talk through what you're working on, what we'd do, and whether we should partner. No pitch deck, no PDF brochure.