INSIGHT · AI GOVERNANCE & COMPLIANCE
Australian Privacy Principle 1.7 (APP 1.7) takes effect on 10 December 2026. Where its trigger is met, a covered organisation's privacy policy must state three things: the kinds of personal information used, the kinds of decisions a computer program makes on its own, and the kinds of decisions it does something substantially and directly related to making. The obligation sits with the business that arranged the deployment, not the vendor — and a human sign-off changes which disclosure applies, not whether you can answer it.

Analysed 21 August 2026 · APP 1.7–1.9 commence 10 December 2026, 111 days from the date of analysis.
KEY TAKEAWAYS
WHAT CHANGED
Most of Australia's AI governance activity in 2025–26 has been direction-setting: offices established, priorities announced, voluntary guidance issued. One item is different in kind, because it carries a commencement date fixed in legislation. The Privacy and Other Legislation Amendment Act 2024 inserted APP 1.7, 1.8 and 1.9, and from 10 December 2026 an APP entity's privacy policy must contain specific information about automated decision-making whenever three conditions are all met.
When triggered, APP 1.8 requires three disclosures — not two, and the distinction between (b) and (c) is the whole argument of this article. APP 1.9 closes the escape routes: "making a decision" includes refusing or failing to make one, the effect counts whether adverse or beneficial, and "computer program" covers pre-programmed rule-based processes, AI and machine learning — a spreadsheet formula can qualify, so can an AI agent.
| APP 1.8 item | What must be disclosed |
|---|---|
| (a) | The kinds of personal information used in the operation of such computer programs |
| (b) | The kinds of decisions made solely by the operation of such computer programs |
| (c) | The kinds of decisions for which the program does a thing substantially and directly related to making the decision |
THE PREPARATION WINDOW
The sequence from assent to commencement — and where the regulator's guidance is meant to land.
Read the sequence, not the countdown alone. On the OAIC's own timetable, guidance arrives about a month from now and three months before the obligation bites — enough to inform how a privacy policy is worded, not enough to build a record structure that does not yet exist.
| Date | Event |
|---|---|
| 10 December 2024 | Royal Assent, Privacy and Other Legislation Amendment Act 2024 |
| 18 May – 15 June 2026 | OAIC consultation on ADM transparency guidance |
| By September 2026 | OAIC's stated intention to release final guidance |
| 21 August 2026 | Date of this analysis — 111 days to commencement; guidance not yet published |
| 10 December 2026 | APP 1.7–1.9 commence |
THE CORE ARGUMENT
The most consequential words in APP 1.7 are not about automation — they are about assistance: "substantially and directly related to making" a decision. The Explanatory Memorandum defines both limbs: "substantially" means the program's contribution "is a key factor in facilitating the human's decision making"; "directly" means it "has a direct connection with making the decision". A program that recommends or guides a human decision-maker is still captured where both limbs are satisfied.
We would be misleading you if we said a "Draft → human confirmation" pattern automatically sits outside APP 1.7.
WHO CARRIES IT
APP 1.7 attaches to the entity that has "arranged for" the computer program to make, or do the related thing to, a decision. The OAIC is explicit that a program "may be operated by one entity, but another entity is responsible for arranging for" its use. Two of its own examples read as if written for this market.
The nearest construction equivalents are a quoting agent whose draft is a key factor in what gets sent to a client, a scheduling system that assigns and dispatches labour, and a claims process that escalates variation or payment matters. The OAIC also anticipates the procurement consequence: during and after procurement, entities should monitor third-party ADM usage.
COVERAGE
Businesses with annual turnover of $3 million or less are generally not APP entities. The exemption carries exceptions, and one — for small businesses related to a larger body corporate covered by the Privacy Act — points directly at group structures. A group consolidating several operating entities is more likely to fall within coverage than a standalone business under the threshold, but coverage must be established entity by entity against the exemption and its exceptions.
What disclosure does not require: "commercial-in-confidence information about automated decision-making systems is excluded". The obligation is to state categories — kinds of information, kinds of decisions — not to publish how your systems work.
THE WIDER MAP
Australia's AI governance map in mid-2026 is easily misread as one undifferentiated wave of regulation. The parts separate cleanly — and APP 1.7 is the odd one out, because it is already legislated with a commencement date. None of these federal privacy measures asks a construction business whether it may use AI; they ask whether you can say, in your privacy policy, what your programs decide and what they substantially and directly contribute to.
WA already leads on this: Western Australia's Privacy and Responsible Information Sharing Act 2024 (WA) Principle 10 commenced 1 July 2026, and by the OAIC's own comparison the federal obligation is lighter — it "only requires information to be provided in an entity's privacy policy". OAIC research cited in its issues paper found 89% of Australians believe they should have a right to know when personal information is used in ADM that could affect them, and 86% believe government should publicly report the technologies it uses to assist decisions. That tracks an expectation; it does not show the expectation produced the legislation.
WHAT IT MEANS
One decision changes: whether to add an AI agent to an operating system, and on what data boundary. That was a technology preference; for covered entities whose deployments meet the trigger, it now carries a written obligation with a statutory date.
We found no reliable public data on what preparation costs in dollars or hours; any vendor quoting a figure is estimating.
CUSTOMER QUESTIONS
Not solely by the program. Whether the draft's contribution reaches the statutory test — and so whether it needs describing under APP 1.8(c) — is a legal determination. Knowing which outputs are confirmed, and by whom, is operational, and it is yours.
If the entity is covered and the trigger is met: the kinds of personal information used, the kinds of decisions made solely by programs, and the kinds of decisions programs do something substantially and directly related to making — the last two stated separately, not merged.
The only question here entirely within your control, whatever the guidance says.
Where one entity operates a system another entity's staff rely on, the obligation follows the arranger — so a group running one agent across several entities needs the answer per entity.
WHAT TO WATCH
WHERE THE RECORD LIVES
The systems a builder already runs are where the "who confirmed what, when" record either exists or doesn't.
THE POSITION
The structural response is to deploy agents so the boundary between "drafted by a program, confirmed by a person" and "produced by a program" is recorded as it happens. That is how we deploy: every Cyberate agent runs inside an accountable workflow defining what it may read, what it may produce, who confirms it, what gets logged and where exceptions go, with commercial, legal, site-critical and externally issued outputs always requiring human confirmation.
This is a design choice, not a compliance answer, and we do not present it as one. Whether any deployment triggers APP 1.7 — and which disclosure category applies — is a question for your legal advisers.
SOURCES
This article is general information, not legal advice. It does not determine whether any specific deployment triggers APP 1.7, or which APP 1.8 category applies — that assessment belongs with your legal advisers. Statutory text and quotations are drawn from the OAIC's Automated Decision Making Issues Paper (May 2026) and its ADM transparency consultation page, with commencement details from legislation.gov.au (C2024A00128). Current as at 21 August 2026; the OAIC's final guidance was unpublished at that date.