Google analytics are off.

Promptective journal / Article

Australia’s APP 1 automated decision deadline: a practical AI governance guide

What the 10 December 2026 APP 1 changes mean, which organisations are covered, how to map AI-supported decisions, and where Shadow AI discovery fits.

A human hand places a cobalt review tile among routed case records and an automated decision unit
Map the records, automated routes and human review points behind decisions that significantly affect people.

From 10 December 2026, covered Australian entities must add information to privacy policies when computer programs use personal information in decisions that can significantly affect people.

The date comes from the Privacy and Other Legislation Amendment Act 2024. The Office of the Australian Information Commissioner (OAIC) confirms the commencement date in its APP 1 guidance.

The technology-neutral term is computer program, so rules engines and automated workflows can qualify. Generative AI without a substantial role in a significant decision may sit outside this particular disclosure rule. Other privacy obligations can still apply.

This article provides general information. Organisations should obtain legal advice about their coverage, exemptions and decision processes.

What changes

New APP 1.7 applies where:

  1. an entity arranges for a computer program to make a decision, or do something substantially and directly related to making it;
  2. the decision could reasonably be expected to significantly affect an individual's rights or interests; and
  3. the program uses that individual's personal information in making or supporting the decision.

APP 1.8 then requires the privacy policy to describe the kinds of personal information used, kinds of qualifying decisions made solely by programs, and kinds substantially and directly supported by programs. It does not require publication of source code, model weights, prompts or thresholds. Qualifying post-commencement decisions can be covered even when the system or data predates the reform.

APP 1.7 qualification test

Three facts must connect.

Software has a decision role

It makes the decision or substantially and directly supports it.

Personal information is used

The program uses information about the person affected.

The effect could be significant

The decision can materially affect that person’s rights or interests.

When all three connect, assess the workflow for APP 1.8 privacy-policy disclosure.


Coverage and decisions

The general federal rule covers Australian Government agencies and organisations above $3 million annual turnover, subject to exceptions. The OAIC's Rights and responsibilities and Small business guidance covers special inclusions and exemptions.

Some entities at or below the threshold are covered, including certain health service providers, personal-information traders, Commonwealth contracted service providers, credit reporting bodies, tenancy database operators and Consumer Data Right businesses. Entity type and practice matter. State bodies, political parties, journalism and some employee records receive separate treatment; applicants are not necessarily employees.

Keep a coverage record for each legal entity: turnover, any special inclusion or exemption, reviewer, evidence and review date.

Assess decisions involving credit, insurance, fraud restrictions, recruitment, tenancy, healthcare, education, government benefits, licensing, essential services or material financial recommendations. A decision includes refusing or failing to decide and may affect someone beneficially or adversely.

Generic drafting, meeting notes and internal summarisation may sit outside APP 1.7 when they do not materially support a significant decision, although other APP obligations may still apply.

The OAIC's commercial AI guidance says personal information can include inferred, incorrect or artificially generated information about an identified or reasonably identifiable person.

Human review may remain in scope

The law separately addresses decisions made solely by software and those substantially and directly supported by it. Assess whether the reviewer independently examines evidence, can depart from a score, actually uses that authority, sees people filtered out earlier and could realistically change the outcome.

Look past “human in the loop”

Software output

A score, shortlist, recommendation, extracted fact or generated summary.

Reviewer’s real authority

Can they inspect the source, see excluded cases and genuinely change the outcome?

The evidence of how review works matters more than the workflow label.


Map decisions before tools

For each decision about a person:

  1. Trace software involvement: decision, filter, ranking, score, recommendation, extraction or administration.
  2. Map personal information: inputs, inferences, sensitive information, vendor access, overseas disclosures and retention.
  3. Assess significance: nature, duration and reversibility of effects on rights or interests.
  4. Record evidence: workflow, configuration, owner confirmation, model or rules version and review date.
  5. Classify authority: sole decision, substantial support, minor support or administration.

This works for deterministic rules, statistical models, generative assistance and agentic workflows.

Find Shadow AI, then review it

Procurement records miss browser tools, embedded features, personal accounts, local models, scripts and departmental automation. Shadow AI discovery can identify observed domains, applications, devices, providers, timing and whether a path was protected, blocked or only observed.

A connection proves activity at that connection alone. Combine technical discovery with manual registration for offline and unmonitored systems. Owners must classify the use case, data and decision role.

From Shadow AI signal to reviewed disclosure

Discover

Observed AI activity, procurement records and staff registrations

Verify

A system owner confirms purpose, data and actual use

Map

Each decision use case gets its own role, effect and evidence

Review

Privacy and legal teams assess candidate disclosures

Monitoring supplies leads. People confirm what the system does and decide what the organisation can accurately publish.


Build a use-case register

Record system and version, owner, purpose, affected people, decision type, automation degree, information categories, affected rights or interests, reviewer authority, vendor and overseas access, privacy impact assessment, notices, dates and supporting evidence.

Privacy and legal teams can use this record to review APP 1.8 disclosure categories while preserving the distinction between observation, human assessment and published wording. Platforms should support several use cases per product, potential-gap review, evidence exports and periodic owner attestation without claiming legal certification.

Readiness plan

  • Scope: confirm covered entities and practices; assign privacy, legal, security and business owners.
  • Discover: combine approved lists, technical evidence, interviews and manual registration.
  • Classify: map decisions, people, information and software involvement; assess other APP duties.
  • Publish: review APP 1.8 categories against workflows and collection notices before commencement.
  • Maintain: require attestation and reassess changes to purpose, personal information, model, automation level or integration.

A repeatable readiness cycle

Scope

Confirm covered entities and owners

Discover

Find approved, observed and unregistered systems

Classify

Map data, decision roles and effects

Publish

Review and approve accurate policy wording

Maintain

Reassess new tools and material changes

Publication is not the finish line. The inventory and evidence need to change as systems and uses change.


Avoid common mistakes

Treat the reform as a computer-program rule, apply the three statutory conditions to each use case and examine real human authority. Include legacy systems. Privacy-policy wording does not replace lawful collection, permitted use and disclosure, quality, security or notices. Technical monitoring also needs manual registration and owner review.

The durable outcome is a reviewed map connecting software, personal information, decisions and effects on people. It supports the 10 December 2026 update and ongoing governance.

For the broader framework, read our Australian workplace AI policy guide and review Shadow AI discovery with content-minimised governance evidence.

Security review

Map policy to the AI paths your team uses.

See where Promptective can apply organisation policy and record content-minimised evidence.

Map your AI workflows