If your AI product handles personal information about people in Australia, the Privacy Act 1988 applies, and a significant new transparency requirement for automated decision-making takes effect on 10 December 2026. This is a plain-language walk through what the Act and its Australian Privacy Principles actually require, why they exist, and specifically what an AI product needs to get right, including the new rule that will affect almost any AI-enabled system making or shaping decisions about people.
What the Privacy Act and the APPs actually are
The Privacy Act 1988 (Cth) is Australia's federal privacy law, enforced by the OAIC, the Office of the Australian Information Commissioner. Its core operative content is the 13 Australian Privacy Principles, usually called the APPs, which set out how personal information has to be collected, used, stored, and disclosed. The Act applies to an APP entity, meaning an organization or agency covered by the Act and bound by the APPs, which in practice covers most private sector businesses above a certain size, along with government agencies. If you are building an AI product for the Australian market, you or your customer are very likely an APP entity, and the APPs apply to how that product handles personal information.
Why the Privacy Act exists
Personal information, once collected by an organization, can be used, shared, or exposed in ways the person never intended or was told about. The Privacy Act exists to give people basic, enforceable expectations about how their information will be handled: that it will be collected for a stated reason, used only for that reason or a genuinely related one, kept reasonably secure, and that the person can find out what is held about them and correct it if it is wrong. These expectations matter more, not less, as AI systems increasingly make decisions using that information rather than just storing it.
Why a company follows it
The OAIC can investigate complaints and take regulatory action for a breach of the APPs, so there is real legal exposure to mishandling personal information. Beyond that, for a company selling into Australian businesses or serving Australian consumers, trust is the more immediate driver: a buyer will ask how an AI feature handles customer data, whether it is used to train or fine-tune anything beyond the immediate task, and increasingly, starting in December 2026, whether the privacy policy actually discloses what the new automated decision-making rule requires it to.
The APPs that matter most for AI products
APP 1: open and transparent management of personal information
An APP entity needs an accessible, accurate, up-to-date privacy policy describing how it manages personal information. For an AI product, this means the privacy policy has to actually reflect what the AI system does with personal information, not a generic template written before the AI feature existed.
APP 3: collection
An entity should only collect personal information that is reasonably necessary for its functions. For an AI agent, this means being deliberate about what data it is allowed to collect or retrieve for a given task, not defaulting to broad access because it might improve the model's answers.
APP 6: use or disclosure
Personal information should be used or disclosed only for the purpose it was collected for, unless a specific exception applies. Consider a small logistics company building an AI agent that answers customer delivery queries using their order history: that history was collected to fulfil orders, and using it to answer support queries is a closely related purpose, but sending the same data to a separate marketing AI tool without disclosure would not be, unless the privacy policy and collection notice already cover that use.
APP 11: security
An entity must take reasonable steps to protect personal information from misuse, interference, loss, unauthorized access, modification, or disclosure. For an AI system, this extends to prompt logs, retrieval indexes, and any fine-tuning data that contains personal information, not just the primary customer database.
APP 12 and APP 13: access and correction
A person can ask what personal information an entity holds about them and ask for it to be corrected if it is wrong. For an AI product, this means being able to actually locate and correct a person's data across every place it lives, including logs and any derived data an AI system has generated about them, not just the primary record.
The centerpiece 2026 development: automated decision-making transparency
This is the most significant AI-specific change to the Privacy Act, and it deserves full attention because it will affect a very wide range of AI products, not just obviously high-stakes ones.
The Privacy and Other Legislation Amendment Act 2024 (Cth) amended the Privacy Act to add new automated decision-making transparency obligations under a new APP 1.7. From 10 December 2026, an APP entity that uses personal information in automated decision-making (ADM) with the potential to affect a person's rights or interests must include specific information in its privacy policy: the kinds of personal information used in that automated decision-making, and the kinds of decisions made using it.
The scope here is important to understand correctly: this is broadly cast to capture AI-enabled systems, rule-based tools, and other automated assessment technologies, not a narrow category of "AI" alone. A traditional rules engine that automatically approves or declines an application based on fixed criteria can fall under this just as much as a machine learning model does, if it is using personal information to make a decision affecting someone's rights or interests. This means the obligation reaches further into a typical product's feature set than a team might assume if they are only thinking about their most obviously AI-branded features.
The OAIC intends to release further guidance before the 10 December 2026 commencement date, with guidance expected by around September 2026. Teams that have not yet audited which of their systems make automated decisions about personal information affecting rights or interests should treat that audit as the first practical step, since the disclosure obligation cannot be met without first knowing what needs to be disclosed.
The OAIC has new powers to issue infringement notices and compliance notices for a privacy policy that fails to meet this specific requirement, and civil penalties can apply for that failure. It is worth being precise here: the Privacy Act's general maximum civil penalty is a separate figure that applies to the Act broadly, not a number specific to this one disclosure rule, so this piece will not attach an unverified dollar figure to the APP 1.7 requirement specifically.
What GreyScript AI does, and does not, do here
GreyScript AI designs for the Privacy Act 1988 and the Australian Privacy Principles: scoping what an AI agent can collect and use, keeping personal information handling deliberate rather than incidental, and helping identify where a build falls under the automated decision-making disclosure requirement before it needs to, so the privacy policy work is not a last-minute scramble in November 2026. We are not a certified compliance vendor, and we do not give a legal opinion. A formal compliance determination, or the actual privacy policy language a specific product needs, stays yours to commission, typically through counsel. See our AI governance and security service for how this fits into a build.