Blog
September 2026

There is a date in December that will apply to most care providers in Australia, and almost nothing in the sector press has mentioned it.
From 10 December 2026, the Privacy Act requires an organisation to disclose in its privacy policy where it uses personal information in automated decision-making that affects an individual's rights or interests. The obligation sits in Australian Privacy Principle 1.7.
It is a transparency duty, not a ban. It does not care whether you call the system AI. It cares whether a computer took part in a decision about a person.
Care operators run more automated decisioning than they think. The obligation is written around the decision, not the technology, so the question is not "do we use AI" but "does software take part in decisions about people".
Almost every provider running a modern case-management platform is doing at least one of these. The obligation does not require the decision to be fully automated, and it does not require the system to be sophisticated. A rules engine counts.

The OAIC opened its consultation on guidance for this obligation on 18 May 2026 and closed submissions on 15 June. Four independent legal analyses of that consultation reach the same conclusion: the regulator is reading the obligation broadly rather than narrowly.
That matters more than it sounds, because of how it gets enforced.
A reportable incident happens. A complaint is made. An audit falls due. There is an event, and the event triggers scrutiny.
A privacy policy is a public document. Checking whether it discloses automated decision-making costs the regulator nothing, scales perfectly, and requires no cooperation from you. The OAIC is already running a compliance sweep of privacy policies.
You do not need an AI incident to be found non-compliant. You need somebody to read your website.
It is worth being precise about the limits, because the surrounding commentary is not.
The obligation is disclosure. It does not require you to stop using automated decision-making, to obtain consent for it, or to offer human review of every decision. It does not import the EU's risk categories.
It is also not an Australian AI Act, because there isn't one. The ten mandatory guardrails proposed in September 2024 were shelved in the December 2025 National AI Plan in favour of existing technology-neutral law.
That absence is exactly why this date matters. Australian care providers have no AI-specific statute, so their obligations around automated systems arrive through privacy law, the aged care standards and the NDIS instruments instead. They are harder to see, they are spread across three regulators, and they are already here.


The disclosure duty sits with the entity that holds the personal information. It does not transfer to the software vendor.
If your platform cannot tell you which of its features take part in decisions about people, you cannot write an accurate privacy policy, and the gap is yours rather than theirs. Very few vendor contracts say this out loud.
Ask, in writing, and keep the answer. Two questions do most of the work:
A vendor who cannot answer the second question has told you something useful about the first.
The OAIC's final guidance is expected around September. Waiting for it is defensible. Waiting for it and then starting in December is not.
Sources. OAIC, consultation on guidance for transparency in automated decision-making, opened 18 May 2026, submissions closed 15 June 2026 (`V`). Privacy Act, Australian Privacy Principle 1.7, commencing 10 December 2026 (`V`). Australia's National AI Plan, December 2025, shelving the proposed mandatory guardrails (`C`, corroborated across independent analyses). The breadth of the OAIC's reading is `C`: four independent law-firm analyses agree, and the regulator's final guidance is not published yet.
We’ll show you a certification done in ten hours.
You decide whether it holds up.