Hub
Analysis
Ten weeks to 10 December: Australia's automated-decision rule
AI Governance & RegulationAnalysis

Ten weeks to 10 December: Australia's automated-decision rule

From 10 December 2026, privacy policies must say when a computer program makes, or substantially helps make, decisions that significantly affect people.

ArchitectDarryl S Astin2 October 20267 min read

Key Insight: If an AI agent or any other program makes, or substantially helps make, a decision that could significantly affect someone, the privacy policy must say so from 10 December 2026. The rule applies to decisions made from that date, including decisions that use information collected earlier.

The date to circle

On 10 December 2026, three new Australian Privacy Principles start to apply: APP 1.7, 1.8 and 1.9. They were added by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024 with a two-year runway. That runway now has about ten weeks left.

The rule is short. If an organisation covered by the Privacy Act has arranged for a computer program to use personal information to make a decision, or to do something substantially and directly related to making a decision, and that decision could reasonably be expected to significantly affect an individual's rights or interests, its privacy policy must say so.

What the privacy policy must contain

Under APP 1.8, the policy must describe:

  • the kinds of personal information used by the program;
  • the kinds of decisions made solely by the operation of the program; and
  • the kinds of decisions where the program does something substantially and directly related to making the decision.

The word "kinds" matters. The rule asks for categories that a reader can understand, not source code, model weights or a list of every individual decision.

The question is no longer whether you use AI. It is whether people can find out which decisions a program makes about them.

Who is covered

The obligation sits on APP entities: Australian Government agencies and most private organisations with annual turnover above the small-business threshold, plus some smaller businesses that the Act brings in, such as health service providers. If you are not sure whether the Privacy Act applies to you, start with the OAIC's guidance rather than assuming you are exempt.

Solely, or substantially and directly related

Two kinds of automation are in scope.

Solely automated decisions are made by the program with no meaningful human involvement. An agent that approves or declines an application on its own is the obvious example.

Substantially and directly related covers the much larger middle ground: a program that scores, ranks, filters, flags or recommends, where a person then makes the formal decision. A human signing off at the end does not, by itself, take the decision out of the rule if the program's output shaped it in a substantial and direct way.

For teams running AI agents, this second category is where most work will land. Triage agents, eligibility screeners, fraud flags and "next best action" tools all deserve a look.

Solely automated and substantially assisted decisions are both in scope. A human signing off at the end does not take a decision out of the rule.

The significant-effect test

The rule only bites where the decision could reasonably be expected to significantly affect an individual's rights or interests. Decisions about access to services, credit, insurance, employment, housing, government benefits or health care are the clearest candidates. Personalising the colour of a button is not. The OAIC's guidance gives the regulator's view of where the line sits, and it is worth reading directly.

Timing: data collected before 10 December still counts

The obligation applies to decisions made on or after 10 December 2026. It does not matter that the personal information was collected earlier. An agent deployed in 2025 that keeps making significant decisions after 10 December needs to be described in the privacy policy from that date.

A practical ten-week checklist

  1. Inventory. List every program and agent that uses personal information and touches a decision about a person.
  2. Classify. For each one, note whether it decides solely, or does something substantially and directly related to a decision.
  3. Test the effect. Ask whether the decision could reasonably be expected to significantly affect someone's rights or interests. Record your reasoning.
  4. Describe the kinds. Write plain-language categories of personal information and decisions.
  5. Update the privacy policy. Publish the new section before 10 December, and make it easy to find.
  6. Keep it current. New agents, new data sources and new decision types should trigger a review.

How this compares with EU Article 50

A transparency field is a pointer to your disclosure, not a substitute for it.

The EU AI Act takes a different angle. Article 50 is about telling people when they are dealing with AI: providers must design systems that interact directly with people so that people are informed they are interacting with an AI system, unless that is obvious from the context, and certain AI-generated or manipulated content must be marked or disclosed. Those obligations apply from 2 August 2026, although organisations should check the latest EU timelines and guidance, which continue to evolve.

The two rules overlap but are not the same. Australia's APP 1.7 is about decisions and the privacy policy. Article 50 is about interactions and content at the point of contact. An organisation operating in both markets may need to satisfy both, in different places.

Where open records fit

The OCC Agent Record, the open record format published at Open Conformance, now includes optional fields that let an operator point to these disclosures: the kinds of decisions an agent makes solely, the kinds it substantially assists, the kinds of personal information it uses, a link to the privacy policy, and how AI interaction is disclosed under Article 50. The field definitions and an example are at openconformance.org/occ/adm-transparency.

Those fields are a pointer, not a substitute. Publishing them does not make a privacy policy lawful, and OCC does not assess or certify legal compliance. What they do is make the disclosure findable in a consistent, machine-readable place, next to the rest of what an operator says about its agent.

The bottom line

Ten weeks is enough time to find your automated decisions and describe them honestly. It is not enough time to start in December.

Sources & Further Reading

  1. 1.Privacy and Other Legislation Amendment Act 2024 (Cth)
  2. 2.OAIC, APP Guidelines Chapter 1: open and transparent management of personal information
  3. 3.OAIC guidance for organisations and government agencies
  4. 4.EU AI Act, Article 50: transparency obligations for providers and deployers of certain AI systems
  5. 5.Open Conformance: automated decisions and transparency fields in the OCC Agent Record
automated decisionsPrivacy ActAPP 1.7OAICEU AI ActArticle 50AI agentstransparency
The engine behind the Signal

Where this connects to Society OS

The Sovereign Intelligence Hub is the free, open front door of Society OS — the sovereign operating system that turns the ideas you just read into working governance. Where this piece names a problem, Society OS is building the machinery to solve it: AI agents that act with your authority, trust you can verify, and compliance that runs as code.

The 42-Protocol Stack

The governance engine beneath every article — led by the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank trust, and WISE Contracts that execute law, not just code.

F-ACT — the open agent standard

The vendor-neutral framework for governing AI agents before they act: Grant, Usage, Audit, Revocation, Data — free to read, cite and implement.

The Sovereign Platform

Put it to work: govern a fleet of AI agents with verifiable authority, tamper-evident evidence, and compliance-as-code across your whole operation.

Explore membershipRead the F-ACT standard

Continue Reading

More from the Sovereign Intelligence Hub

The EU AI Act Enters Full Enforcement: What the August 2026 Milestone Actually Means
AI Governance & Regulation

The EU AI Act Enters Full Enforcement: What the August 2026 Milestone Actually Means

16 min read
The Enforcement Moment: How the EU AI Act's August 2026 Deadline Is Reshaping Global AI Compliance
AI Governance & Regulation

The Enforcement Moment: How the EU AI Act's August 2026 Deadline Is Reshaping Global AI Compliance

11 min read
The Enforcement Inflection: A Definitive Timeline of Global AI Governance, 2024–2028
AI Governance & Regulation

The Enforcement Inflection: A Definitive Timeline of Global AI Governance, 2024–2028

18 min read
The Governance Inflection: A Complete Timeline of Global AI Regulation, 2025–2026
AI Governance & Regulation

The Governance Inflection: A Complete Timeline of Global AI Regulation, 2025–2026

16 min read
The Governance Gap: Why Regulation Can't Keep Pace with AI
AI Governance & Regulation

The Governance Gap: Why Regulation Can't Keep Pace with AI

18 min
The EU AI Act: What Actually Changes on 2 August 2026
AI Governance & Regulation

The EU AI Act: What Actually Changes on 2 August 2026

12 min

Never miss a signal

Weekly intelligence, no noise

Governance Toolkit

The Evidence
92 % ungoverned
The Framework
GUARD chain
Your Risk
Sourced model
Self-Assess
No login required

The Sovereign Intelligence Hub — Society OS

© 1989–2026 Society OS Pty Ltd. All rights reserved.