01 / 20AI governance

Is Australia about to make every business put an “AI used here” sticker on its work? No. The important rule is narrower, and a good deal more consequential than a sticker.

24 September 20264 min read3 research sources

Is Australia about to make every business put an “AI used here” sticker on its work? No. The important rule is narrower, and a good deal more consequential than a sticker.

The change arriving in December concerns significant automated decisions involving personal information.

From 10 December 2026, APP entities that arrange for a computer program to use personal information in certain decisions that could significantly affect an individual’s rights or interests must include specified information in their privacy policies. The rule also covers a program doing something substantially and directly related to making such a decision.

That is not an “AI declaration law” for every chatbot, image generator or copywriting tool. It is a transparency obligation around significant automated decision-making involving personal information.

01For Australian businesses, that distinction matters.

For Australian businesses, that distinction matters.

A marketing team using generative AI to draft campaign concepts is not the same risk category as a system that uses personal information to determine whether someone receives finance, employment, insurance, access to a service, or another outcome that materially affects them.

That distinction matters because the new disclosure obligation has a defined legal trigger. A general concern about AI is not itself the test.

Under the new APP 1 requirements, affected privacy policies will need to explain the kinds of personal information used in these computer programs, the kinds of decisions made solely by them, and the kinds of decisions where a computer program performs something substantially and directly related to making the decision.

02This should change how companies think about “AI readiness”.

This should change how companies think about “AI readiness”.

AI readiness is not simply whether staff have access to Copilot, ChatGPT or Gemini. It is whether the organisation knows where automated systems are operating, what data they use, what decisions they influence, who is accountable, and whether those uses are documented clearly enough to explain to a customer, employee or regulator.

That means the practical preparation work should start before December.

A sensible organisation should already be building an internal inventory of AI and automated systems, identifying which systems touch personal information, separating low-risk productivity uses from higher-impact decision processes, and reviewing whether its privacy policy reflects how technology is actually used.

03This is particularly important because the Privacy Act is only one part of the picture

This is particularly important because the Privacy Act is only one part of the picture. Australian organisations using AI may also intersect with consumer law, workplace law, discrimination law, online safety requirements, intellectual property, confidentiality and sector-specific obligations.

The Australian Government’s broader direction is also clear. Its Guidance for AI Adoption emphasises accountability, risk management, data governance, testing, human oversight, transparency and record keeping. Separate guidance encourages businesses to be clear when digital content has been generated or materially modified by AI.

The lesson for agencies, developers and product teams is that transparency is becoming part of product architecture.

A privacy statement written at the end of a project is not enough if nobody inside the organisation can explain what the software actually does.

04The better model is to make governance part of the build itself: document the data flo

The better model is to make governance part of the build itself: document the data flows, map significant decisions, record human intervention points, and design explanations into the service.

Doing this early should make a privacy policy more accurate and a service easier to explain. Whether it earns trust depends on how the system actually behaves.

Australia is not requiring every business to put an “AI used here” badge on everything.

But it is moving toward a world where significant automated decisions cannot remain invisible.

SourcesResearch trail

References used for this article

  1. 01OAIC, APP 1 guidance and automated decision-making obligations
  2. 02Privacy and Other Legislation Amendment Act 2024
  3. 03Australian Government Guidance for AI Adoption legal landscape

If you can relate, feel free to reach out.


Share your thoughts?