Skip to main content

MyMoney® is reviewing its service model in light of evolving ASIC regulatory guidance. Some features are temporarily unavailable.

AFSL 222640 · Global Mutual Funds Pty Ltd
AI Engineer
Privacy Act
automated decision-making
ADM transparency

Privacy Act ADM Transparency Obligations in Australia: An AI Engineer Guide for December 2026

From December 2026, Australian businesses must disclose automated decision-making in privacy policies. Learn what AI engineers must do to ensure compliance.

MyMoney® Editorial4 September 2026 7 min read

A landmark deadline is approaching for Australian businesses that use artificial intelligence in their operations. From 10 December 2026, organisations covered by the Privacy Act 1988 (Cth) must disclose in their privacy policies whether they use automated decision-making (ADM) systems that significantly affect individuals. For AI engineers building, deploying, or maintaining these systems, this regulatory shift demands immediate technical and governance action.

Understanding the December 2026 ADM Transparency Obligation

The Privacy and Other Legislation Amendment Act 2024 introduced a new transparency requirement for automated decision-making. From 10 December 2026, any entity covered by the Privacy Act must explicitly state in its privacy policy whether it uses computer programs or automated processes to make — or substantially assist in making — decisions that significantly affect individuals.

The obligation is broader than many businesses initially assume. It applies not only to fully automated systems but also to AI tools that materially contribute to or substantially influence decisions about an individual's rights, entitlements, or legal interests. Examples include credit assessments, job application screening, insurance underwriting, loan approvals, and content moderation decisions.

The privacy policy disclosure must specify the types of personal information used in the automated process and the categories of decisions being made. Vague or generic statements will not satisfy the requirement — the Office of the Australian Information Commissioner (OAIC) expects meaningful, specific disclosures that allow individuals to understand how their data is being used.

Who Is Affected: The End of the Small Business Exemption

A critical change accompanying the ADM transparency obligation is the effective removal of the small business exemption. Previously, businesses with an annual turnover of less than $3 million were exempt from most Privacy Act obligations. The Privacy and Other Legislation Amendment Act 2024 has progressively wound back this exemption, bringing the vast majority of Australian businesses — including startups, professional services firms, and technology companies — within the scope of the Australian Privacy Principles (APPs).

This means that even small technology companies and AI startups that build or deploy automated decision-making systems must now comply with the ADM transparency requirements. AI engineers working for or advising these businesses need to understand the full scope of their clients' obligations.

What AI Engineers Must Do Before December 2026

The December 2026 deadline requires a structured technical and governance response. AI engineers are central to this effort, as they are best placed to identify, document, and remediate the automated systems that trigger the disclosure obligation.

Step 1: Conduct an AI System Inventory

The first step is a comprehensive audit of every software tool, model, and automated process that uses personal information to influence decisions. This includes not only bespoke machine learning models but also third-party SaaS tools, CRM automation, document processing pipelines, and any system that applies rules or scoring to individual data.

For each system identified, AI engineers should document the type of personal information processed, the nature of the decision being influenced, the degree of human oversight in the process, and whether the decision significantly affects individuals' rights or entitlements.

Step 2: Conduct Privacy Impact Assessments

For systems that trigger the ADM transparency obligation, a Privacy Impact Assessment (PIA) should be conducted. A PIA maps data flows, identifies privacy risks, and documents the controls in place to mitigate those risks. The OAIC's PIA guide provides a structured methodology that AI engineers can adapt for technical system assessments.

Step 3: Build Human Review Pathways

For significant automated decisions, the regulatory expectation — and best practice — is that there is a clear, accessible mechanism for a human to review and potentially overturn the algorithmic output. AI engineers must design and implement these human-in-the-loop pathways, ensuring they are technically robust and operationally practical.

Common Mistakes and Red Flags

As the December 2026 deadline approaches, several common errors are emerging in how businesses are approaching ADM compliance. AI engineers should be alert to the following:

  • Scope underestimation: Assuming only bespoke ML models are covered, while ignoring automated rules engines, scoring systems, and third-party AI tools that also process personal information
  • Generic privacy policy updates: Adding boilerplate ADM language to a privacy policy without conducting the underlying system audit — this will not satisfy the OAIC's expectation of meaningful disclosure
  • Ignoring third-party AI services: Many businesses use offshore AI platforms (such as large language model APIs) that process personal data on foreign servers — these arrangements require careful assessment of cross-border data flow obligations
  • No human review mechanism: Deploying automated decision systems without any pathway for human review or appeal, which creates both regulatory and reputational risk
  • Failure to update disclosures: Treating the December 2026 update as a one-time exercise rather than an ongoing obligation that must be reviewed whenever the underlying AI system changes

Australian Regulatory Context

The ADM transparency obligation sits within a broader and rapidly evolving Australian AI regulatory landscape. The key regulatory bodies and frameworks AI engineers must understand include:

  • Office of the Australian Information Commissioner (OAIC): The primary regulator for Privacy Act compliance, including ADM transparency. The OAIC has enforcement powers including civil penalties of up to $50 million or 30% of adjusted turnover for serious or repeated breaches.
  • Australian Government's Voluntary AI Safety Guardrails: Ten guardrails published by the Department of Industry, Science and Resources that provide a governance framework for responsible AI deployment, covering accountability, risk management, transparency, and human oversight.
  • ISO/IEC 42001:2023: The international standard for AI management systems, which provides a structured framework for documenting AI inventory, risk assessments, and human review pathways — directly aligned with the ADM transparency requirements.
  • Australian Consumer Law (ACL): Automated systems that make misleading representations or engage in unfair conduct may also attract scrutiny from the Australian Competition and Consumer Commission (ACCC).

Australia does not yet have a dedicated AI Act equivalent to the EU's framework, but the combination of Privacy Act obligations, voluntary guardrails, and existing consumer protection law creates a substantive compliance environment that AI engineers must navigate carefully.

Questions to Ask an AI Engineer About ADM Compliance

If you are a business seeking to engage an AI engineer to assist with December 2026 ADM compliance, the following questions will help you assess their expertise:

  • Can you conduct a comprehensive audit of our automated systems to identify those that trigger the ADM transparency obligation?
  • Do you have experience conducting Privacy Impact Assessments for AI and automated decision-making systems?
  • How will you design human review pathways for our automated decision processes?
  • Can you help us draft the specific ADM disclosures required for our privacy policy?
  • How do you assess cross-border data flow risks when we use offshore AI platforms?
  • What ongoing monitoring do you recommend to ensure our disclosures remain accurate as our AI systems evolve?
  • Are you familiar with ISO/IEC 42001 and can you help us align our AI governance with this standard?

How MyMoney® Can Help

Meeting the December 2026 ADM transparency deadline requires technical expertise that goes beyond updating a privacy policy. It demands a systematic audit of automated systems, careful assessment of data flows, and the design of governance structures that will satisfy the OAIC's expectations.

MyMoney® connects Australian businesses with qualified AI engineers who specialise in privacy compliance, responsible AI deployment, and regulatory governance. Post a brief describing your business's automated systems and compliance needs, and receive tailored proposals from experienced AI engineers. You can also browse our AI engineer directory to compare credentials, specialisations, and client reviews.

With the December 2026 deadline now imminent, acting early is essential. The businesses that engage qualified AI engineers now will be best positioned to meet their obligations, avoid enforcement action, and build the trust of their customers and stakeholders.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.