
Is your business ready for December 2026?
Artificial intelligence is already changing how Australian organisations communicate, analyse information, support customers and make decisions. As adoption grows, so does the responsibility to protect personal information and use AI in a secure, transparent and considered way.
A confirmed change to Australia’s privacy framework will take effect on 10 December 2026. It introduces additional transparency requirements for certain organisations that use personal information in automated decision-making.
This does not mean every business using an AI assistant, chatbot or automation platform will suddenly be subject to a new set of AI-specific rules. However, it does mean organisations should understand where automated systems are being used, what information those systems access and whether they contribute to decisions that significantly affect people.
Cyber Security Awareness Month is a timely opportunity to begin that work. It is not only about protecting systems from external threats. It is also about building the policies, knowledge and accountability needed to use emerging technology responsibly.
The short answer
From 10 December 2026, an organisation covered by the Australian Privacy Principles may need to include additional information in its privacy policy if it has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual’s rights or interests.
Where the requirement applies, the privacy policy will need to explain:
- the kinds of personal information used by the computer program
- the kinds of decisions made by the computer program
This obligation forms part of Australian Privacy Principle 1, which focuses on the open and transparent management of personal information.
Importantly, this is an automated decision-making transparency requirement. It is not a general ban on AI and it does not automatically apply to every AI-supported activity.
Why this matters now
December 2026 may sound some distance away, but many organisations do not yet have a complete view of where AI and automation are being used.
AI features can now be embedded within customer relationship management platforms, recruitment systems, productivity tools, service workflows, marketing platforms and third-party applications. In some cases, teams may adopt a feature without realising that information is being processed or analysed by an AI-enabled system.
The first step towards readiness is therefore visibility.
Businesses need to be able to answer some straightforward questions:
- Which AI and automated tools are we currently using?
- What information is entered into or accessed by those tools?
- Does that information identify an individual?
- Does the tool support or make decisions about customers, employees, applicants or partners?
- Could those decisions significantly affect a person’s rights or interests?
- Who remains accountable for the outcome?
- Can we explain our use of the system clearly?
The Office of the Australian Information Commissioner, or OAIC, was developing more detailed guidance on the scope of the new automated decision-making obligation during 2026. This means businesses should monitor final regulator guidance and avoid relying only on general articles or vendor summaries when determining their legal obligations.
This is about more than generative AI
When people hear “AI”, they often think of tools that generate text, images or summaries. The December requirement is potentially broader because it refers to a computer program using personal information to make certain decisions.
Depending on the circumstances, relevant systems could include:
- automated eligibility assessments
- recruitment screening applications
- customer risk or service prioritisation models
- credit, insurance or pricing systems
- employee management workflows
- personalised decision engines
- rules-based applications
- machine learning systems
Not every automated workflow will meet the legal threshold. A system that helps draft an email or summarises information is different from one that makes a decision with a significant effect on an identifiable person.
The purpose of the system, the personal information involved, the nature of the decision and its effect on the individual will all be important.
Existing privacy obligations already apply to AI
Businesses should not wait until December 2026 before considering privacy.
The OAIC has stated that existing privacy obligations apply to personal information entered into a commercially available AI product. They can also apply to information produced by an AI tool where the output contains personal information.
The OAIC recommends that organisations:
- conduct appropriate due diligence before adopting commercially available AI products
- consider privacy and security risks
- understand who may access information entered into or generated by a system
- establish policies and procedures for AI use
- provide clear and transparent information about relevant AI use
- consider appropriate oversight within AI-supported processes
As a matter of best practice, the OAIC also recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools because of the privacy risks involved.
These expectations make AI governance an immediate business issue, not simply a future compliance activity.
The connection between AI, privacy and cyber security
AI privacy and cyber security are closely connected.
An AI system may process customer records, employee information, commercial data or other sensitive material. If access controls are weak, users enter inappropriate information, or a third-party service handles data in an unexpected way, the organisation may face privacy, security and reputational risks.
AI can also change the threat environment. The Australian Signals Directorate’s guidance for Cyber Action Year 2026 encourages Australian organisations to prepare for AI-enabled cyber threats, alongside actions such as using secure-by-design products and services, improving event logging and addressing legacy technology.
Cyber Security Awareness Month takes place every October and is intended to encourage action to improve cyber security. In 2026, it sits within the Australian Signals Directorate’s broader Cyber Action Year, which calls on organisations to move from awareness towards practical, year-round action.
For business leaders, this creates a clear message: responsible AI adoption should be part of the organisation’s wider cyber security and information-management approach.
Seven practical actions businesses can take
The following steps are good foundations for AI readiness. They are practical governance recommendations and should be adapted to each organisation’s legal obligations, risk profile and operating environment.
1. Build an AI and automation register
Create a central record of approved AI tools, automation systems and AI-enabled features.
Include:
- the business purpose
- the internal owner
- the vendor or provider
- the information accessed
- whether personal or sensitive information is involved
- whether the system supports decisions about individuals
- the intended users
- the review date
Do not limit the register to standalone generative AI services. Include AI capabilities built into existing business applications.
2. Map personal information
Identify what personal information is collected, entered, generated, inferred or shared when each system is used.
This may include information about customers, employees, job applicants, suppliers or community members. Pay close attention to sensitive information and to outputs that create new observations or inferences about an identifiable person.
3. Identify significant decisions
Determine whether a system makes or supports decisions that could have a significant effect on an individual.
This assessment may require privacy or legal advice. It should not be based solely on how the vendor describes the product.
4. Review your privacy policy and notices
Assess whether your current privacy policy accurately explains how personal information is managed.
Where the December 2026 automated decision-making requirement applies, the policy will need to contain the required additional information. Changes should be clear, specific and easy for customers and employees to understand.
5. Review AI suppliers
Ask suppliers how they collect, store, process and protect your information.
Topics to consider include:
- data retention
- access permissions
- model training
- information location
- subcontractors
- security controls
- incident notification
- deletion arrangements
- changes to AI features
Supplier assurances should be supported by appropriate documentation and contractual terms.
6. Protect the value of personal service
Automation can improve speed and consistency, but customers continue to value the human touch, particularly when an issue is complex, sensitive or personally significant.
Define when a person should review an AI-supported outcome, who is accountable and how a customer or employee can ask a question or raise a concern. Technology should support people to deliver better service, not remove care, judgement or accountability from important interactions.
7. Educate your people
Clear guidance helps employees use AI with confidence.
Training should explain:
- which tools are approved
- what information can and cannot be entered
- how to check AI-generated content
- how to identify unreliable or inappropriate output
- how to report a potential privacy or security issue
- when to seek expert assistance
AI education should be relevant to the work people perform. A short policy alone is unlikely to build the understanding required for safe and useful adoption.
Responsible AI adoption can build trust
Good AI governance should not be approached only as a compliance exercise.
When people understand how AI is being used, what information is involved and who is responsible, they are more likely to trust the service. Transparency can also help organisations identify weak processes before they become larger privacy, security or customer-experience issues.
The Australian Government’s National AI Centre provides practical guidance intended to help Australian organisations adopt AI safely and responsibly. It focuses on helping organisations understand where AI can add value, consider its benefits and risks, support their people through change and apply responsible practices in real business settings.
For many businesses, the goal is not to adopt the most AI. It is to adopt the right solutions, for the right reasons, with appropriate protection and accountability.
Are you ready for December 2026?
Consider whether your organisation can confidently answer “yes” to these questions:
- We know which AI and automated systems are being used.
- We know which systems handle personal information.
- We understand whether automated systems contribute to significant decisions.
- We have clear owners for our AI systems.
- We evaluate privacy and cyber security risks before adoption.
- We review our third-party AI providers.
- Our employees understand the boundaries for safe AI use.
- People remain accountable for important outcomes.
- Customers can understand relevant uses of their information.
- Our privacy documentation reflects what we actually do.
If several answers are “no” or “not sure”, now is the right time to begin.
Move from AI awareness to AI readiness
AI has significant potential to improve productivity, service delivery and decision-making. Realising that potential requires more than selecting a tool. It requires clear goals, suitable technology, informed people, secure information practices and a commitment to transparency.
Entag helps organisations make AI practical and manageable. Through AI education, enablement and secure technology solutions, we can help your organisation identify valuable use cases, build capability and introduce AI in a considered way that supports both your people and your customers.
This Cyber Security Awareness Month, take the next step from AI awareness to AI readiness. Speak with Entag about preparing your organisation for secure, responsible and people-focused AI adoption.
Ready to make AI work for your organisation?
Entag helps organisations turn AI opportunities into practical, secure solutions. From education and readiness planning to implementation and ongoing enablement, our experts can help your people use AI confidently while keeping trusted human service at the centre of the customer experience.
Speak with Entag about your AI goals and discover the right next step for your organisation.
This article provides general information only and should not be relied upon as legal or regulatory advice. Organisations should obtain advice appropriate to their circumstances.
Frequently asked questions
Are new AI privacy rules starting in Australia on 10 December 2026?
A specific automated decision-making transparency obligation commences on 10 December 2026. It requires certain organisations covered by the Australian Privacy Principles to include additional information in their privacy policies where they arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests.
Do the changes apply to every business using AI?
Not necessarily. The obligation applies to APP entities and depends on how personal information and automated decision-making are used. Businesses should assess their own activities and seek appropriate privacy or legal advice.
Does using an AI assistant automatically trigger the new requirement?
No. Using AI to draft, summarise or assist with routine work does not automatically trigger this particular obligation. The relevant circumstances include whether a computer program uses personal information to make a decision that could reasonably be expected to significantly affect an individual’s rights or interests.
Do privacy obligations already apply to AI?
Yes. Existing Australian privacy obligations can apply when personal information is entered into an AI system or appears in AI-generated output. The OAIC recommends due diligence, clear governance and careful consideration of privacy and security risks when adopting commercial AI products.
What should businesses do first?
A sensible first step is to create an inventory of AI and automated systems. Record what each system does, what information it uses, who owns it and whether it contributes to decisions about identifiable individuals.