A new transparency obligation is coming for businesses that use AI to make decisions about people. It's worth being aware of, because working out whether it applies to you means knowing exactly what your systems touch and how they use the information

There's a date worth putting in the diary if you run AI or automation anywhere near customer or staff data. From 10 December 2026, a new transparency obligation under the Privacy Act 1988 starts to bite, and it's aimed at automated decision-making

The rule is narrower than the commentary suggests. A lot of what's being written makes it sound like every business will have to publish a full account of its AI. That's not what it says

What's changing

The change came in through the Privacy and Other Legislation Amendment Act 2024, which added automated decision-making provisions to Australian Privacy Principle 1, the principle that governs your privacy policy. From 10 December 2026, affected organisations have to include information in that policy about how they use computer programs to make certain decisions about people

The trigger is a three-part test. The obligation applies where an entity has arranged for a computer program to make, or do something substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect the rights or interests of an individual; and personal information about that individual is used in the program. All three have to be true. A "decision" here also covers a refusal or failure to decide, and the effect counts whether it's good or bad for the person

Who it applies to

The most important limit is who it applies to. The obligation only binds APP entities, which broadly means Australian Government agencies and businesses with annual turnover above $3 million. Below that threshold the Privacy Act has a small-business exemption, so the first question for a smaller operator is whether the Act reaches you at all

The complication is the exceptions to that small-business exemption. A small business is subject to the Privacy Act regardless of size if it's a health service provider, trades in personal information for a benefit, or provides services under a Commonwealth contract, among a handful of other categories. Handling tax file numbers or consumer credit information brings its own obligations, the Tax File Number Rule and the credit reporting provisions, but those are separate regimes that don't by themselves make a small business subject to this one. Plenty of otherwise-small operators sit in one of these categories without realising it. So "we turn over less than $3 million" is the start of the question, not the end of it

What you'd have to disclose

Where the obligation applies, it's a privacy-policy disclosure, not a line-by-line explanation of your models. The policy has to set out the kinds of personal information your programs use, the kinds of decisions made solely by those programs, and the kinds of decisions where the program does something substantially and directly related to the decision while a person stays in the loop

The operative phrase is "kinds of." The OAIC has been clear that the disclosure is about categories, not a public inventory of every rule and algorithm you run. In practice that's closer to a clear, plain-English paragraph in your privacy policy than a technical white paper

The practitioner view: you can't disclose what you can't see

For anyone running a business, the practical core of this is simple. You can't describe how your systems use personal information if you don't know what they touch. That mapping is the genuinely useful work hiding inside this obligation, whether or not it strictly applies to you

We run this exercise on our own stack, because we're an outsourced finance team handling payroll, tax file numbers and bank data for our clients every day. Each tool touches personal information differently. The document capture reads invoices and receipts and pulls data off them. Xero holds the financial and payroll records. The AI features inside those platforms suggest, sort and flag. Knowing which tool sees what, where that data travels, and whether any of it feeds a decision about a person is the same AI governance discipline the Privacy Act is now nudging everyone toward

For most businesses, today's automation processes data rather than makes decisions about people. Reading an invoice isn't a decision that significantly affects anyone's rights. But the moment a system is screening job applicants, interpreting an award to set someone's pay, approving or declining an application, or scoring a person, you're in different territory, and you want to know that's happening before a regulator or a customer asks

What to do before December 2026

A sensible order of operations, whatever your size:

  • Map your systems, and write down what personal information each one can access and what it does with it
  • Work out whether any of them make or materially shape decisions about individuals, rather than just process their data
  • If they do, and you're an APP entity, that's the point to get your privacy policy reviewed

That last step is a legal one. This is general information rather than legal advice, and whether the obligation applies to your specific situation, and what your policy needs to say, is a question for a privacy lawyer. The OAIC is also developing detailed guidance, expected around September 2026 ahead of the commencement date, so the picture should sharpen well before the deadline

If you're using AI inside your bookkeeping or payroll, the exposure depends on what the tool is actually doing. Calculating a payrun against rules a person has already set is processing, and the risk is low. Interpreting an award, classifying a worker or deciding an entitlement is making the decision itself, and Xero won't interpret an award for you, so that judgement falls to whoever runs the payroll. Automate that step and you take on two risks at once: getting the interpretation wrong under Fair Work, and running an automated decision that affects someone's pay. Mapping your tools shows which side of that line each one sits on, which is plain good governance whatever the Privacy Act ends up asking of you

Something to watch as agents take on bigger decisions

Most of what's automated today executes a decision a person already made. The direction of travel is different. Tools like XeroForce, Xero's no-code agent builder released in alpha in May 2026, let people assemble agents in plain language that string together rules, data and actions across the systems they already use. As that capability spreads, agents will shift from processing the inputs to a decision toward making the decision itself, and for more layered calls than approving a payrun

That's the thing worth holding as you automate. The Privacy Act's test turns on what a program does, not what it's called, so it applies to the function as it arrives: a program that makes, or substantially shapes, a decision that significantly affects someone. The more of a decision you hand to an agent, the closer you move to that line. An agent that flags an unusual timesheet for a person to check is well clear of it. An agent that decides whether to approve the leave, classify the worker or set the rate is not

The no-code part is the sharp edge. Someone can build a decision-making agent in an afternoon without being the person who thinks about privacy obligations, and the obligation attaches whether or not anyone noticed it was created. So the habit worth forming before this gets complicated is to treat one question as a checkpoint whenever you build or buy an agent: does this make or materially shape a decision about a person, or does it just do the work around one? When it's the former, that's when a human in the loop and the disclosure start to matter

For a practice automating across many clients at once, there's a second layer. Building agents at that scale can make you the one who has arranged for the program to operate, which is the trigger the whole obligation hangs on. So the question isn't only what your clients do with AI, it's what you've built on their behalf