Specialist Compliance Solutions for AML/CTF Tranche 2, ISO 9001 & ISO 42001.

  0437 801 021    1/457-459 Elizabeth Street, Surry Hills, NSW 2010

Privacy Act AI Disclosure Requirements: What Australian Businesses Must Do by December 2026

Privacy Act AI Disclosure Requirements: What Australian Businesses Must Do by December 2026

Australian businesses that use artificial intelligence to make or influence decisions about individuals are facing a new wave of compliance obligations under the Privacy Act reforms. The requirements for transparency, disclosure, and accountability around automated decision-making are not theoretical — they are arriving. This guide explains what is required, which businesses are affected, and what preparing now looks like in practice.

Australia’s Privacy Act 1988 is undergoing its most significant reform in decades. The Privacy and Other Legislation Amendment Act 2024, passed in November 2024, introduced a range of new requirements — and the Australian Government has committed to further reforms addressing AI transparency and automated decision-making as a second tranche of changes. The December 2026 timeline reflects the expected implementation of these AI-specific obligations.

For Australian SMEs, the timing creates a double pressure. The ISO 42001 AI Governance standard has been available since December 2023 as the international framework for responsible AI management. The Privacy Act reforms are now establishing the legal obligations that make that framework directly relevant to any Australian business using AI in its operations. The two developments are converging on the same deadline window.

This article explains the Privacy Act AI disclosure requirements, which businesses they apply to, what compliance looks like in practice, and how Lead Comply’s ISO 42001 AI governance practice supports Australian businesses through both the voluntary standard and the mandatory legal requirements. For the most current status of the Privacy Act reforms, refer to the Office of the Australian Information Commissioner at oaic.gov.au and the Attorney-General’s Department at ag.gov.au.

Important note on timing and legislative status:

This article is published in June 2026. The Privacy Act AI disclosure requirements described here reflect the reform trajectory as of that date. Some requirements are already in force following the 2024 amendments. Others are anticipated as part of the second tranche of reforms expected through 2026. The final legislative requirements may differ in specific detail from what is described here. Businesses should monitor oaic.gov.au and ag.gov.au for current guidance and consult with Lead Comply for advice specific to their operations and AI use cases.

The Privacy Act Reform Landscape — What Has Changed and What Is Coming

The Privacy and Other Legislation Amendment Act 2024 was the first tranche of Privacy Act reforms following the comprehensive Privacy Act Review Report released in 2023. The 2024 Act introduced several changes relevant to AI and automated decision-making:

  • New transparency requirements for entities to disclose what personal information they collect and how it is used in decision-making processes
  • Strengthened individual rights to access information about decisions that significantly affect them, including decisions influenced by automated processes
  • New children’s privacy protections with implications for AI systems that process the personal information of minors
  • Foundations for a statutory tort for serious privacy invasions that are now available where AI systems cause harm through misuse of personal information
  • New enforcement powers for the Office of the Australian Information Commissioner, including the ability to conduct investigations into AI-related privacy breaches

The second tranche of reforms — expected to be implemented through 2026 — is anticipated to include more specific requirements for automated decision-making disclosure, AI transparency notices, and accountability frameworks for AI systems that make or significantly influence decisions about individuals. The December 2026 date marks the expected implementation horizon for these obligations.

🎓  FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE

The Privacy Act reforms are creating a compliance dynamic that Lead Comply identifies consistently when working with Australian SMEs on AI governance: businesses are using AI tools extensively in their operations — for customer communications, lead qualification, document processing, credit assessment, staff performance evaluation — but have no framework for managing the privacy and accountability obligations those uses create. The typical SME AI toolkit in 2026 includes: an AI-powered CRM that scores leads and recommends next actions, a document processing tool that extracts and stores personal information from uploaded files, a customer service chatbot that handles complaint triage, and a productivity tool that summarises communications and generates responses. Each of these involves automated processing of personal information. Under the Privacy Act reforms, each creates disclosure and transparency obligations. Most Australian SMEs have not yet considered any of them through a privacy compliance lens.

What the AI Disclosure Requirements Mean in Practice

The core of the Privacy Act AI disclosure obligations is transparency: individuals have the right to know when an automated system is making or influencing a decision that significantly affects them. For Australian businesses, this translates into four practical obligations.

ObligationWhat It Requires in Practice
AI System DisclosureBusinesses must disclose in their privacy notice or policy that automated decision-making systems are used, the types of decisions those systems influence, and the categories of personal information involved. This is not a technical disclosure — it must be written in plain English accessible to the individuals affected.
Significant Decision NotificationWhere an automated system makes or substantially influences a decision that significantly affects an individual — loan assessment, insurance pricing, job application screening, tenancy approval, content moderation — the individual must be notified that an automated process was involved.
Human Review RightsIndividuals affected by significant automated decisions must have access to a human review process. A business that makes a decision using an AI system and has no human review pathway does not meet this requirement, regardless of how accurate or fair the AI system is believed to be.
Algorithmic AccountabilityBusinesses must be able to explain, in general terms, how their automated decision-making systems work and how personal information is used within them. This does not require technical disclosure of proprietary algorithms — it requires a sufficient description for individuals to understand why a decision was reached.

Which Australian Businesses Are Affected

The Privacy Act applies to any organisation with an annual turnover above AUD $3 million, and to many organisations below that threshold if they handle sensitive information, provide health services, or are contracted to provide services to the Australian Government. Under the reforms, any business within scope that uses AI systems to process personal information or make decisions affecting individuals is subject to the AI disclosure requirements.

Business TypeTypical AI Use CasesPrivacy Act AI Scope
Professional services firms (accountants, lawyers, consultants)AI-assisted document review, client communication drafting, research and summarisationYes — where AI influences advice, reporting, or client-facing communications involving personal information
Real estate agenciesAI-powered CRM, lead scoring, automated property matching, document extractionYes — where AI processes personal information in client communications, tenant assessments, or property recommendations
Financial services and credit providersAutomated credit assessment, fraud detection, customer risk scoringYes — these are high-significance automated decisions requiring both notification and human review pathways
Healthcare providersClinical decision support, appointment scheduling, patient communicationYes — health information is sensitive information under the Privacy Act, attracting the highest obligations
Retailers and e-commerce businessesProduct recommendation engines, customer behaviour profiling, pricing personalisationConditional — depends on whether the AI use significantly affects individuals or involves sensitive information
Recruitment and HR software usersAI resume screening, candidate scoring, performance assessment toolsYes — automated employment decisions are among the highest-significance decisions under the reform framework
⚠️  THE MOST COMMON MISCONCEPTION ABOUT SCOPE

Many Australian SMEs assume the Privacy Act AI obligations do not apply to them because they are not an AI company and do not build AI systems. The obligation applies to any organisation that USES AI systems to process personal information or make decisions affecting individuals — not only to organisations that build them. If your business uses an AI-powered CRM, a document processing tool, a customer service chatbot, or any software that applies automated logic to personal information, you are using an AI system for Privacy Act purposes. The disclosure obligations attach to the use, not the creation, of the system.

The Connection to ISO 42001 — Why AI Governance and Privacy Compliance Are the Same Conversation

ISO/IEC 42001:2023 is the international standard for Artificial Intelligence Management Systems. It was published in December 2023 and provides a framework for organisations to establish, implement, maintain, and continuously improve the governance of AI systems. The full standard is available at iso.org.

Lead Comply has written a detailed guide on ISO 42001 for Australian businesses: ISO 42001: The AI Governance Standard Australian Businesses Need to Know About. That guide explains the standard’s structure and scope. This section focuses specifically on how ISO 42001 supports Privacy Act AI compliance — because the two frameworks address the same underlying challenge from different directions.

RequirementPrivacy Act ObligationISO 42001 Framework Element
Understanding what AI systems do with personal informationBusinesses must disclose how AI uses personal information in decisionsClause 6.1 requires organisations to identify and document the AI systems in use and their intended purposes
Transparency about automated decision-makingBusinesses must notify individuals when automated systems influence significant decisionsClause 8.4 requires transparency and explainability controls for AI systems
Human review pathwaysSignificant automated decisions must have a human review optionClause 6.1.2 requires risk assessment including human oversight of AI decisions
Accountability for AI system outcomesBusinesses must be able to explain how their AI systems work in general termsClause 5.2 requires top management to take accountability for the organisation’s AI governance
Ongoing monitoring of AI system performanceBusinesses must manage privacy risks as AI systems evolveClause 9.1 requires continual performance evaluation of AI systems and their impacts

The practical implication: an Australian business that implements ISO 42001 as its AI governance framework will already have the documentation, processes, and accountability structures needed to satisfy the Privacy Act AI disclosure requirements. ISO 42001 is not a workaround or a shortcut — it is a genuinely better way to govern AI than ad-hoc compliance measures. But for businesses facing a December 2026 deadline, it serves both purposes simultaneously.

🎓  FROM LEAD COMPLY’S COMPLIANCE EXPERIENCE

The question Lead Comply hears most often from SMEs encountering the Privacy Act AI requirements for the first time is:

Do we actually use AI? We just use software.
The answer, in almost every case, is yes — and more extensively than the business realises. A CRM that scores leads and prioritises follow-up actions is an AI system. A document processing tool that extracts names, dates, and financial figures from uploaded PDFs is an AI system. A customer service tool that categorises complaints and routes them to the appropriate team is an AI system. An email tool that suggests responses is an AI system. The Privacy Act AI disclosure requirements apply to all of these. The starting point for every Lead Comply AI governance engagement is an AI system inventory — a structured process of identifying what AI tools the business actually uses, what personal information each one processes, and what decisions each one influences or makes. That inventory is the foundation of both the ISO 42001 framework and the Privacy Act disclosure requirements. For most SMEs, completing it produces two simultaneous surprises: how many AI systems they are already using, and how many personal information flows they were unaware of.

What Australian Businesses Need to Do Before December 2026

Preparing for the Privacy Act AI disclosure requirements involves five practical steps. The steps are sequential — each builds on the previous one — but they can be started now, before the full legislative requirements are finalised.

FIVE STEPS TO PRIVACY ACT AI COMPLIANCE

Step 1 — Complete an AI System Inventory
Identify every AI system or AI-assisted tool your business uses. For each system, document: what personal information it processes, what decisions it influences or makes, who the affected individuals are (customers, employees, contractors, or others), and what the consequence of an AI-influenced decision is for those individuals.

Step 2 — Assess the Significance of Automated Decisions
For each AI system identified, assess whether the decisions it influences are “significant” under the Privacy Act framework. Significant decisions are those that materially affect an individual’s rights, finances, access to services, or opportunities — credit assessment, employment screening, tenancy approval, insurance pricing, and service eligibility are all clearly significant.

Step 3 — Update Your Privacy Notice and Policy
Your privacy notice must disclose that automated decision-making systems are used, the types of decisions they influence, and the categories of personal information involved. This update is required before the December 2026 deadline and should be written in plain English accessible to affected individuals.

Step 4 — Design or Document Human Review Pathways
For each significant automated decision, establish a clear human review process. The process must be accessible to affected individuals — not just documented internally. If your current process relies entirely on an AI system with no human override, a human review pathway must be designed and implemented.

Step 5 — Implement an AI Governance Framework
The most efficient path to ongoing compliance is implementing ISO 42001 as the governance framework for your AI systems. ISO 42001 provides a structured, auditable approach to AI risk management, transparency, accountability, and continual improvement. A business with an operational ISO 42001 framework is not just prepared for the December 2026 deadline — it is positioned for the ongoing compliance obligations that will follow as AI regulation continues to develop.

How Lead Comply Supports Privacy Act AI Compliance

Lead Comply’s ISO 42001 AI Governance practice is designed specifically for the position most Australian SMEs are in: using AI tools extensively, facing new legal obligations around those tools, and needing a structured approach that satisfies both the international standard and the evolving Australian regulatory requirements.

  • AI system inventory: a structured process for identifying every AI tool the business uses and documenting its personal information processing and decision-making scope

Privacy Act AI compliance gap assessment: reviewing existing privacy notices, policies, and procedures against the anticipated disclosure requirements and identifying specific gaps

  • Privacy notice and policy update: plain-English disclosure of AI system use and automated decision-making, written to satisfy the OAIC transparency standard
  • Human review process design: documenting and implementing accessible human review pathways for significant automated decisions

·  ISO 42001 AI Management System implementation: full framework design covering AI system identification, risk assessment, transparency controls, accountability structure, and continual improvement program

  • Ongoing compliance monitoring: regular review of AI system inventory and privacy obligations as the regulatory landscape develops through 2026 and beyond
📋  WHAT GOES WRONG IN PRACTICE — WHAT LEAD COMPLY SEES
Three AI privacy compliance failures Lead Comply identifies consistently with Australian SMEs:

1 — The business does not know what AI systems it uses. When Lead Comply begins an AI system inventory with a new client, it consistently identifies AI-assisted tools the business did not know were AI. The CRM with a lead scoring engine. The email platform with a reply-suggestion feature. The accounting software with an anomaly-detection module. None of these were considered “AI” by the business — but all process personal information using automated logic. Under the Privacy    Act, all create disclosure obligations.

2 — The privacy policy has not been reviewed since AI tools were adopted. Most Australian SMEs have a privacy policy that was drafted before they began using  AI tools. The policy discloses how personal information is collected and used — but says nothing about automated processing or decision-making. Under the Privacy Act AI requirements, this disclosure gap is a compliance failure regardless of how otherwise well-maintained the privacy framework is.

3 — There is no human review process for automated decisions. Businesses that use AI systems to screen job applications, assess tenant applications, or approve service requests — and have no documented pathway for an affected individual to request human review — will not satisfy the reform requirements. The human review pathway does not need to be complicated. It does need to exist and be accessible.
✓  WHAT A PRIVACY ACT AI COMPLIANT AUSTRALIAN BUSINESS LOOKS LIKE

– AI system inventory completed: every AI tool documented with its personal information processing scope and decision-making function·  Significant automated decisions identified and documented.
– Privacy notice updated to disclose AI system use and automated decision-making in plain English.
– Human review pathways documented and accessible for all significant automated decisions.
– AI governance framework in place — either ISO 42001 or an equivalent documented approach.
– Staff who operate AI systems understand the Privacy Act obligations attached to those systems.
– Privacy policy, AI governance documentation, and human review records maintained and accessible for OAIC review.
– Ongoing monitoring in place: AI system inventory reviewed annually and when new AI tools are adopted.
Frequently asked questions on Privacy Act AI requirements:

Does the Privacy Act apply to AI tools provided by third parties?
— Yes. If your business uses a third-party AI system to process personal information, you are responsible for that processing under the Privacy Act. Using a third-party tool does not transfer the privacy obligation to the provider.

Do we need to tell customers which specific AI tool we use?
— Not at the level of naming products. You must disclose the type of decision the automated system influences and the category of personal information involved. General disclosure — “we use automated systems to assist with lead qualification using publicly available and client-provided information” — is typically sufficient.

What is the penalty for non-compliance with the Privacy Act AI requirements?
— The 2024 Act increased penalties significantly. Serious or repeated privacy breaches can attract penalties of up to AUD $50 million or three times the benefit derived from the breach, whichever is higher. The OAIC also has enhanced investigation and enforcement powers.

Do we need ISO 42001 to comply, or just update our privacy policy?
— ISO 42001 is not mandated by law. However, it provides a governance framework that makes ongoing compliance significantly more manageable — especially as AI regulation continues to develop. Lead Comply can advise on whether ISO 42001 is the right approach for your business.
Not sure how your AI tool use maps to the Privacy Act requirements?

Book a free 30-minute Clarity Call with Lead Comply. In 30 minutes you will know which of your AI systems create Privacy Act obligations, what your disclosure gaps are, and what a compliance plan looks like before December 2026.

📅 Book a Clarity Call
C L
Ask Dan — Privacy Act AI Compliance for Australian Businesses Not sure how the Privacy Act reforms affect your AI tool use? Ask Dan directly.
AI may make mistakes. See our Privacy Policy. · info@leadcomply.com.au


Leave a Reply

Your email address will not be published. Required fields are marked *