DEV Community

Sheila
Sheila

Posted on Originally published at oioioi.ai

Your privacy policy now has to describe your AI

From 10 December 2026, Australian Privacy Principles 1.7 to 1.9 require APP entities to disclose automated decision-making in their privacy policy. If a computer program uses personal information to make, or substantially and directly contribute to, decisions that could significantly affect someone's rights or interests, the policy must state the kinds of information and decisions involved.

**What changes on 10 December 2026?
**Privacy policies have to start describing automated decisions. The obligation comes from the Privacy and Other Legislation Amendment Act 2024, which added APP 1.7 to 1.9 to the Australian Privacy Principles, and it applies to every APP entity. On 30 September the OAIC published its guidance: a fact sheet and a flowchart for working out whether you're caught. Government agencies get their own supplementary sheet. The OAIC says the material reflects 90 written submissions from academia, civil society, government and industry.

A program is in scope when it makes a decision, or does something substantially and directly related to making one, using personal information about a person, and that decision could reasonably be expected to significantly affect the person's rights or interests. APP 1.9 widens the net. Refusing or failing to decide counts as a decision, and the effect counts whether it helps the person or hurts them.

**Does the rule only apply to AI?
**No. The OAIC's APP 1 guidelines say a computer program covers "pre-programmed rule-based processes, artificial intelligence and machine learning". An eligibility check a developer hard-coded into an online application form in 2017 sits on the same footing as this year's LLM agent, as long as it meets the test.

I think this is the part most teams will miss. The conversation about the rule is happening under the AI heading, so the inventory will start with the chatbot and the copilot and stop there. The scoring macro in the finance team's spreadsheet won't make the list until someone asks what actually decides who gets declined.

**What has to go in the privacy policy?
**Two things: the kinds of personal information your programs use, and the kinds of decisions they're involved in. APP 1.8 splits the decisions in two. Some are made solely by the program. In others, the program does something substantially and directly related to the decision and a person makes the final call.

That second category matters more than it looks. A human signing off at the end doesn't take a system out of scope. If a model ranks rental applicants and a property manager picks from the top five, the ranking belongs in the disclosure.

Why won't a carefully worded paragraph keep you compliant?
Because the paragraph describes your systems on the day it was written, and AI systems don't stay put. Publishing the disclosure is the easy bit. You've made a public claim about which data your programs read and which calls they make on their own, and that claim has to stay true every day after.

Systems drift in boring ways. A model gets swapped for a cheaper one in the June budget review. An agent picks up a new tool and a wider scope. Someone connects the CRM export to a screening workflow at 4:45 on a Friday because the backlog has to clear by Monday. Each change is reasonable on the day. None of them touch the privacy policy, which gets reviewed whenever legal next has a quiet week.

The gap opens slowly and in good faith. Nobody sees it until someone asks what the system actually did, and by then the privacy policy has been wrong for months.

How do you keep the disclosure accurate after the next model swap?
Enforce the rule where the AI runs, not in the document that describes it. In practice that means a governed context layer: one shared place for your organisation's rules and approved connections, connected once over MCP and used by whichever model you're running this quarter.

Each half of the APP 1.8 disclosure maps to a control. The kinds of personal information become a connection scope, so the screening workflow can read rental history and income but never sees the applicant's date of birth. The kinds of decisions become a guardrail: the program can rank applicants, and anything that looks like a final decline goes to a named person. Oi's connections are credential-brokered, so the agent's runtime never holds the provider keys it would need to reach around its scope.

Audit logging covers what happened. Actions through the layer are logged, so when someone asks in March what the screening agent did in January, you can answer from the log.

Now the December disclosure describes a system that can't act outside it. You can write the privacy policy from the layer's configuration and know it's still accurate after the next model swap, because the rules were never stored in the model. It's the same shared layer that multiplayer AI depends on, applied to a regulator's question.

What should you do before 10 December?
Start by listing every program that touches a decision about a person, including the rule-based ones nobody calls AI. Run each one through the OAIC flowchart. Write the disclosure from that list.

Then move the rules for the programs that are in scope out of documents and into the layer they run through, so the next model or agent inherits them on its first day. Agents that keep pushing after a system says no aren't hypothetical: in June, an internal OpenAI agent got past repeated refusals on a Medicare portal. A rule that only lives in a document can't stop an agent like that.

If you want to see an automated-decision rule enforced at the layer, book a demo.

FAQ

When do the Privacy Act automated decision-making rules start?
APP 1.7 to 1.9 commence on 10 December 2026. They were added by the Privacy and Other Legislation Amendment Act 2024. The OAIC published its guidance and a flowchart on 30 September 2026.

**Do the rules apply to systems that aren't AI?
**Yes. The OAIC's guidelines say a computer program includes pre-programmed rule-based processes as well as AI and machine learning. A simple scoring rule can be in scope if it meets the APP 1.7 test.

**Does a human reviewer take a system out of scope?
**Not on its own. APP 1.8 covers decisions made solely by a program and decisions where a program does something substantially and directly related to the decision. A program that ranks or recommends before a person decides can still need disclosing.

**What counts as a decision under APP 1.9?
**Refusing or failing to make a decision counts as making one. A decision can affect someone's rights or interests whether the effect is good or bad for them.

**Who has to comply with APP 1.7 to 1.9?
**APP entities, meaning the organisations and Australian Government agencies covered by the Privacy Act. The OAIC's flowchart walks through whether a particular program is caught.

Sources: OAIC, "New resources on transparency for use of AI and automated decision-making", 30 September 2026; OAIC, APP Guidelines Chapter 1: APP 1; Privacy and Other Legislation Amendment Act 2024.

Top comments (0)