Promptective journal / Article
Australia’s APP 1 automated decision deadline: a practical AI governance guide
What the 10 December 2026 APP 1 changes mean, which organisations are covered, how to map AI-supported decisions, and where Shadow AI discovery fits.

From 10 December 2026, covered Australian entities must add information to privacy policies when computer programs use personal information in decisions that can significantly affect people.
The date comes from the Privacy and Other Legislation Amendment Act 2024. The Office of the Australian Information Commissioner (OAIC) confirms the commencement date in its APP 1 guidance.
The technology-neutral term is computer program, so rules engines and automated workflows can qualify. Generative AI without a substantial role in a significant decision may sit outside this particular disclosure rule. Other privacy obligations can still apply.
This article provides general information. Organisations should obtain legal advice about their coverage, exemptions and decision processes.
What changes
New APP 1.7 applies where:
- an entity arranges for a computer program to make a decision, or do something substantially and directly related to making it;
- the decision could reasonably be expected to significantly affect an individual's rights or interests; and
- the program uses that individual's personal information in making or supporting the decision.
APP 1.8 then requires the privacy policy to describe the kinds of personal information used, kinds of qualifying decisions made solely by programs, and kinds substantially and directly supported by programs. It does not require publication of source code, model weights, prompts or thresholds. Qualifying post-commencement decisions can be covered even when the system or data predates the reform.
APP 1.7 qualification test
Three facts must connect.
Software has a decision role
It makes the decision or substantially and directly supports it.
Personal information is used
The program uses information about the person affected.
The effect could be significant
The decision can materially affect that person’s rights or interests.
Coverage and decisions
The general federal rule covers Australian Government agencies and organisations above $3 million annual turnover, subject to exceptions. The OAIC's Rights and responsibilities and Small business guidance covers special inclusions and exemptions.
Some entities at or below the threshold are covered, including certain health service providers, personal-information traders, Commonwealth contracted service providers, credit reporting bodies, tenancy database operators and Consumer Data Right businesses. Entity type and practice matter. State bodies, political parties, journalism and some employee records receive separate treatment; applicants are not necessarily employees.
Keep a coverage record for each legal entity: turnover, any special inclusion or exemption, reviewer, evidence and review date.
Assess decisions involving credit, insurance, fraud restrictions, recruitment, tenancy, healthcare, education, government benefits, licensing, essential services or material financial recommendations. A decision includes refusing or failing to decide and may affect someone beneficially or adversely.
Generic drafting, meeting notes and internal summarisation may sit outside APP 1.7 when they do not materially support a significant decision, although other APP obligations may still apply.
The OAIC's commercial AI guidance says personal information can include inferred, incorrect or artificially generated information about an identified or reasonably identifiable person.
Human review may remain in scope
The law separately addresses decisions made solely by software and those substantially and directly supported by it. Assess whether the reviewer independently examines evidence, can depart from a score, actually uses that authority, sees people filtered out earlier and could realistically change the outcome.
Look past “human in the loop”
Software output
A score, shortlist, recommendation, extracted fact or generated summary.
Reviewer’s real authority
Can they inspect the source, see excluded cases and genuinely change the outcome?
Map decisions before tools
For each decision about a person:
- Trace software involvement: decision, filter, ranking, score, recommendation, extraction or administration.
- Map personal information: inputs, inferences, sensitive information, vendor access, overseas disclosures and retention.
- Assess significance: nature, duration and reversibility of effects on rights or interests.
- Record evidence: workflow, configuration, owner confirmation, model or rules version and review date.
- Classify authority: sole decision, substantial support, minor support or administration.
This works for deterministic rules, statistical models, generative assistance and agentic workflows.
Find Shadow AI, then review it
Procurement records miss browser tools, embedded features, personal accounts, local models, scripts and departmental automation. Shadow AI discovery can identify observed domains, applications, devices, providers, timing and whether a path was protected, blocked or only observed.
A connection proves activity at that connection alone. Combine technical discovery with manual registration for offline and unmonitored systems. Owners must classify the use case, data and decision role.
From Shadow AI signal to reviewed disclosure
Discover
Observed AI activity, procurement records and staff registrations
Verify
A system owner confirms purpose, data and actual use
Map
Each decision use case gets its own role, effect and evidence
Review
Privacy and legal teams assess candidate disclosures
Build a use-case register
Record system and version, owner, purpose, affected people, decision type, automation degree, information categories, affected rights or interests, reviewer authority, vendor and overseas access, privacy impact assessment, notices, dates and supporting evidence.
Privacy and legal teams can use this record to review APP 1.8 disclosure categories while preserving the distinction between observation, human assessment and published wording. Platforms should support several use cases per product, potential-gap review, evidence exports and periodic owner attestation without claiming legal certification.
Readiness plan
- Scope: confirm covered entities and practices; assign privacy, legal, security and business owners.
- Discover: combine approved lists, technical evidence, interviews and manual registration.
- Classify: map decisions, people, information and software involvement; assess other APP duties.
- Publish: review APP 1.8 categories against workflows and collection notices before commencement.
- Maintain: require attestation and reassess changes to purpose, personal information, model, automation level or integration.
A repeatable readiness cycle
Scope
Confirm covered entities and owners
Discover
Find approved, observed and unregistered systems
Classify
Map data, decision roles and effects
Publish
Review and approve accurate policy wording
Maintain
Reassess new tools and material changes
Avoid common mistakes
Treat the reform as a computer-program rule, apply the three statutory conditions to each use case and examine real human authority. Include legacy systems. Privacy-policy wording does not replace lawful collection, permitted use and disclosure, quality, security or notices. Technical monitoring also needs manual registration and owner review.
The durable outcome is a reviewed map connecting software, personal information, decisions and effects on people. It supports the 10 December 2026 update and ongoing governance.
For the broader framework, read our Australian workplace AI policy guide and review Shadow AI discovery with content-minimised governance evidence.
Security review
Map policy to the AI paths your team uses.
See where Promptective can apply organisation policy and record content-minimised evidence.
Map your AI workflows