New Privacy Laws and AI: What Australian Businesses Must Do Before 10th December

Australia’s Privacy Act reforms are set to reshape how mid-market organisations use, govern, and disclose artificial intelligence (AI). At the centre of these changes is a clear shift: from broad privacy commitments to specific, transparent disclosures about automated decision-making and privacy compliance. For organisations already using AI-powered tools (or planning to) this isn’t just a policy update. It’s an operational challenge.

What is automated decision-making?

Automated decision-making is the use of AI and software-based systems to make or influence decisions that affect individuals. Common examples include fraud detection, client onboarding, insurance claims assessments, patient triage, contract reviews, customer support interactions, and personalised recommendations.

As AI adoption accelerates across Australian businesses, regulators are placing greater emphasis on transparency and accountability. This increased focus comes at a time when data privacy concerns and cyber attacks are also rising. The Office of the Australian Information Commissioner (OAIC) reported that they received 1205 data breach notifications in 2025, an 8% increase over 2024 and the highest number since the Notifiable Data Breaches scheme began in 2018.

With increased scrutiny from regulators and growing expectations from customers around data privacy, businesses need to take a closer look at how AI is embedded in their systems and whether current risk governance, risk and compliance (GRC) frameworks are fit for purpose.

What are the Privacy Act reforms for AI and Automated Decision-Making?

The upcoming Privacy Act reforms place a stronger emphasis on transparency around automated decision-making, particularly where it has a material impact on individuals.

Come 10th December 2026, there will be mandatory reporting obligations under the Privacy Act. In practice, this means organisations may need to clearly disclose:

  • Whether AI is used in decision-making
  • The types of decisions being automated (e.g. hiring, credit scoring, customer interactions etc.)
  • What personal information is used
  • How those decisions affect individuals

This marks a significant step beyond traditional privacy language, which often focuses on data collection and storage rather than how decisions are actually made.

For many organisations, the gap isn’t just documenting how they collect, store and process information, it’s understanding AI systems well enough to explain them transparently to customers, employees, regulators, and other stakeholders.

How Privacy Policies Must Change Under Australia’s AI Disclosure Rules

Generic privacy statements won’t cut it anymore.

Under the new requirements, privacy policies need to accurately reflect real-world practices, particularly when AI is involved. This means organisations must move beyond high-level descriptions and provide meaningful insight into:

  • The logic or intent behind automated decisions
  • Whether there is human oversight
  • How individuals can challenge or seek review of decisions

AI systems, especially those sourced from third-party vendors, can act as “black boxes”, making it difficult to articulate exactly how outcomes are determined. Businesses will need to work more closely with technology providers to bridge this gap.

How the OAIC Will Enforce AI Compliance Requirements

The OAIC is also evolving its approach.

Historically, enforcement has been reactive: responding to complaints and breaches. But with these reforms, expect a more proactive and investigative stance, particularly when it comes to high-risk technologies like AI.

In response to the growing number of entities dealing with notifiable breaches, the OAIC has also released a new breach response guide, highlighting the increasing focus on organisational readiness and accountability.

This means:

  • Increased likelihood of audits or compliance reviews
  • Greater expectation of evidence, not just statements
  • More accountability for demonstrating that systems are fair, accurate, and secure

In other words, it’s not enough to say you’re compliant. You need to prove it and be ready to show how.

Where AI Use Creates Real Compliance Challenges

AI transparency sounds simple in theory, but in practice it introduces a range of challenges, especially when balanced against commercial realities.

One of the biggest tensions is between disclosure and intellectual property. Organisations are being asked to explain how their systems work without exposing proprietary information or competitive advantages.

The organisations facing the greatest compliance pressure are often those handling large volumes of personal and sensitive information. As AI becomes more deeply embedded in these environments, visibility over how personal information is used and processed becomes increasingly important.

The following industries and are most impacted by AI Compliance with their common AI use cases:

Healthcare: Patient triage, claims processing, clinical decision support and appointment management. The OAIC has reported that health service providers accounted for 225 data breach notifications in 2025 (19% of the national total).

Financial services: Credit scoring, fraud detection and risk profiling and insurance underwriting. Financial services accounted for 157 notifications of data breaches reported in 2025.

Professional Services: client onboarding, recruitment screening, contract review, compliance monitoring.

In many cases, these systems have been implemented quickly to drive efficiency without the level of AI governance now required.

This creates blind spots. And those blind spots are exactly where compliance risks tend to sit.

AI Compliance Gaps Australian Businesses Should Address Before 2026 

For most organisations, the issue isn’t whether AI is being used, it’s how well that use is understood and documented.

Some of the most common gaps include:

  • No central visibility of where AI tools are deployed across the business
  • Limited understanding of what data is being used by those tools
  • Lack of documented decision-making processes
  • Privacy policies that don’t reflect actual system behaviour
  • No formal review or audit mechanisms for AI-driven decisions

Practical steps include:

  • Conducting an internal audit of AI and automated decision-making systems
  • Mapping data flows and inputs into those systems
  • Updating privacy policies to align with real usage
  • Establishing governance frameworks for ongoing oversight
  • Engaging vendors to clarify system functionality and transparency

From Policy to Practice: The Real Shift

The biggest takeaway from these reforms is this: privacy compliance is moving beyond documentation and into day-to-day operations. 

It’s no longer enough to have a well-written policy sitting on your website. Regulators and customers want to understand what’s actually happening behind the scenes.

Australians are paying closer attention to privacy than ever before. The OAIC found that 82% of Australians are concerned about data breaches, a significant increase from 74% just three years ago. In that environment, organisations that can clearly explain how they use AI and personal information will be far better positioned to build customer trust. In contrast, a lack of transparency can create uncertainty, damage brand reputation, and increase regulatory scrutiny.

For organisations using AI, that means building the capability to explain, justify, and evidence how decisions are made.

Those who act early will be in a far stronger position, not just to meet compliance requirements, but to build trust in how they use technology.

Because in this new environment, transparency isn’t just a legal obligation. It’s a competitive advantage.

Is Your Organisation Ready for the 2026 Privacy Act Reforms?

If your organisations is already using AI across customer service, operations, recruitment, and business workflows? VITG can help assess your AI-related risks, strengthen governance, and prepare for the upcoming Privacy Act reforms in Australia.

Book an AI Readiness & Compliance Assessment
Identify AI, privacy, and security gaps before they become compliance risks.

Speak with Our AI Governance & Cybersecurity Experts
Get practical guidance on AI transparency, data protection, and regulatory readiness.

Other recent articles

Great IT
starts here

Ready to take the next step? Talk to our
team about how we can support your
business objectives with award-winning
IT support and services.