Know your ADM: New rules put automated decisions under scrutiny

Published on the 11/08/2026 | Written by Heather Wright


Know your ADM: New rules put automated decisions under scrutiny

Your company wants AI. Regulators want details…

Australian companies rushing to adopt AI will soon face a more basic challenge: Identifying every system making automated decisions which affect people.

From 10 December 2026, new disclosure requirements under the Privacy and Other Legislation Amendment Act will require organisations to disclose when automated decision-making systems use personal information to make, or substantially assist in making, decisions that significantly affect an individual’s rights or interests.

“The obligations will extend beyond high-risk AI systems to capture commonly deployed enterprise and customer-facing technologies.”

The change comes as financial industry regulator APRA (the Australian Prudential Regulation Authority) warns banks, insurers and superannuation funds that governance and assurance practices are not keeping pace with the scale and speed of AI adoption. It’s calling for a ‘step-change’ in how AI-related risks are managed.

The combined message from privacy and financial regulators is straightforward: Organisations required to follow the Australian Privacy Principles will need to know where AI is being used, what personal information it relies on, and the types of decisions made.

The Privacy and Other Legislation Amendment Act introduced a range of privacy reforms, including clarifying ‘reasonable steps’ to protect the security of personal information, introducing the offence of doxxing and providing ministerial powers to ‘whitelist’ countries that provide substantially similar privacy protections. Many of the changes kicked in in 2024.

What the new rules require

Law firm Macpherson Kelley says businesses that use personal information in automated or semi-automated decision-making that could reasonably be expected to have a significant effect on an individual’s rights or interests will need to update their privacy policies by December 2026. The policies will need to describe the types of personal information used and the types of decisions being made.

The requirement extends beyond generative AI tools. Mark Metzeling, principal lawyer commercial for Macpherson Kelly notes the rules apply where a computer program either makes a decision itself or performs a task that is ‘substantially and directly related’ to making that decision. An automated decision could include outcomes affecting contractual rights, access to services, eligibility determinations and other decisions that significantly affect individuals.

Among the examples of those most likely to be caught by the new requirements are financial services companies relying on credit-scoring, fraud detection and algorithmic trading, ecommerce and digital platforms using recommender systems or dynamic pricing, telcos harnessing automated customer identity checks and service provisioning, and insurers, healthtech and medtech companies using predictive analytics.

Areas including insurance eligibility assessments, recruitment screening, automated billing, hardship assessments and disconnections, and other AI-driven decisioning systems are also likely to be impacted.

The Office of the Australian Information Commissioner (OAIC) says the new transparency requirements are intended to give individuals greater visibility into how automated decision-making systems use their personal information – reducing AI’s ‘black box’ challenge. In a May consultation paper, the regulator said greater transparency would help people understand how their information is being handled and enable them to take further action where appropriate.

Veronica Scott, partner at Pinsent Masons, and Gagan Singh, associate at the law firm, say the OAIC has taken a broad, technology-neutral approach to the meaning of a ‘computer program’ that is used for ADM.

“This may include commonly used software; apps; word-processing tools; AI systems; generative AI tools; chatbots and virtual assistants; and tools that analyse, classify, summarise or generate content,” they warn.

“This signals that the obligations will extend beyond high-risk AI systems to capture commonly deployed enterprise and customer-facing technologies. This has the potential in practice to result in lengthy disclosures.”

They note many common digital business practices such as targeted advertising and content delivery, may fall within scope particularly where algorithmic curation may limit access to employment opportunities or personalised or differential pricing for significant good or services is provided.

Ashurst Perkins Coie also cautions that organisations should prepare for targeted advertising and algorithmic pricing to come under scrutiny.

The tech challenge

For tech leaders, the challenge may not be interpreting the legislation, but instead ensuring they can trace what all the systems are doing in practice, the decisions they influence and the personal information sitting behind it – and provide the plain English disclosures required.

A January review by the OAIC into how Australian government agencies use ADM in decision making and communicate that information on their websites found just 17 percent disclosed that they were using ADM and none had published guidelines or policies explaining how those systems were used.

Meanwhile an APRA review in April of large financial institutions found AI adoption accelerating across regulated industries, with organisations moving from experimentation to customer-facing use cases including claims triage, loan processing, fraud detection, customer interactions, insight generation and software engineering.

Governance, however, has not kept pace APRA warned.

The regulator says while boards showed a strong interest in AI’s strategic potential, many were still developing the technical literacy needed to effectively challenge AI-related risks and provide oversight. APRA also noted an ‘over-reliance on vendor presentations and summaries without sufficient examination of key AI risks such as unpredictable model behaviour and the impact on critical operations.”

Among APRA’s expectations is that organisations maintain an inventory of AI tooling and AI use cases, alongside clear accountability, human involvement in high-risk decisions and governance arrangements covering the full AI lifecycle.

Mapping and disclosures required

Macpherson Kelley’s Metzeling warns the ADM requirements apply to any qualifying decision made on or after 10 December 2026, regardless of when the algorithm or system was originally implemented.

He’s urged organisations to prepare early, mapping algorithms and evaluating whether – and where – automated decisions involving personal information are occurring within the organisation.

Ashurst Perkins Coie echoes that, saying organisations need to close the loop on governance and ensure they can trace what systems are actually doing in practice – and keep disclosures aligned with reality.

Post a comment or question...

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

MORE NEWS:

Processing...
Thank you! Your subscription has been confirmed. You'll hear from us soon.
Follow iStart to keep up to date with the latest news and views...
ErrorHere