Automated decision-making transparency requirements—new obligations for businesses with AI systems

This article was first published in the LexisNexis Internet Law Bulletin, Volume 28, Issue 1, 2026. Copyright © 2026 LexisNexis. All Rights reserved.

Introduction

With the increasing prevalence of businesses adopting artificial intelligence (‘AI’) in recent years,[1] the Australian Government is undertaking reforms to support the safe and responsible development and deployment of automated decision making (‘ADM’). As part of this initiative, from 10 December 2026 the Privacy and Other Legislation Amendment Act 2024 (Cth) will amend the Privacy Act 1988 (Cth) (‘Privacy Act’) to include ADM explainability and transparency requirements which provide individuals with greater transparency about the use of their personal information in automated decisions which significantly affect their rights or interests (‘ADM reform’).[2] As this article explores, the ADM reform has major implications for entities bound by the Privacy Act (‘APP entities’)[3] that use AI-driven ADM systems involving personal information.

Key concepts

An ADM system refers to a computerised process (which may or may not involve AI) that can automatically act without human intervention or control to varying degrees.[4] As such, ADM systems are capable of either assisting or replacing the judgement of human decision makers in reaching a result or conclusion about a matter (i.e. a ‘decision’).[5] Generally speaking, the more automated a system is, the less human involvement there will be. Where a human is involved in a process prior to a decision or action being taken, this is known as ‘human-in-the-loop’.[6] If an AI process or system is not well-designed, decisions can be unfairly biased, inaccurate or unreliable and may cause social, physical or economic harm to people on an individual or collective basis.[7]

From a privacy standpoint, the main concerns about ADM systems include arbitrary or unlawful interferences with privacy,[8] an infringed right to equality and discrimination.[9] Other concerns include unfair bias, reduced autonomy, accountability and authenticity.[10] These concerns may eventuate in harm when an APP entity is not transparent about ADM systems which use personal information in ways which can have significant impacts on an individual’s rights or interests.[11] Personal information broadly means information or an opinion about an identified or a reasonably identifiable individual, whether or not the information or opinion is true or recorded in a material form.[12] The way in which the ADM reform aims to reduce the abovementioned harms is by strengthening transparency and explainability obligations in the Privacy Act.

Transparency and explainability are both universally recognised AI ethical principles. Transparency is the notion that individuals who are subjected to ADM systems should have general information about the system and are able to enquire about the input, decision making process or output of a system.[13] Explainability complements transparency because while people may know about a system, this does not mean they understand how it works or why a decision was made.[14] If an ADM system is both transparent and explainable, this helps ensure that:

  • people are aware of the process by which decisions are made and the degree of automation involved;
  • people can understand why certain inferences or decisions were made with their personal information;
  • people can request entities correct information held or take legal action if there has been an interference with their privacy or unlawful discrimination; and decisions are accountable (in other words, explanations or answers for decisions are provided to persons with a legitimate claim to demand an account with consequences).[15]

The ADM reform

The ADM reform introduces additional obligations for privacy policies in APP 1 (‘open and transparent management of personal information’) in the form of APPs 1.7, 1.8 and 1.9. The new APPs require that entities who use an ADM system which makes decisions involving personal information which could significantly affect the rights or interests of individuals must contain specific information in their privacy policies. This is broken down below.

APP 1.7

Under APP 1.7, an APP entity’s privacy policy must contain the information outlined in APP 1.8 if:

  1. the entity arranged for a computer program to make, or do a thing that is substantially and directly related to making a decision (APP 1.7(a));
  2. the decision could reasonably be expected to significantly affect the rights or interests of an individual (APP 1.7(b)); and
  3. personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision (APP 1.7(c)).[16]

The Explanatory Memorandum to the amending act clarifies various aspects of APP 1.7. First, it is the entity who is responsible for arranging the computer to do the things described above which must meet the privacy policy requirements under APP 1.7.[17] Second, a ‘computer program’ takes on its ordinary meaning to encompass a broad range of computer processes, including pre-programmed rule-based processes, artificial intelligence and machine learning processes to make a computer execute a task.[18] Third, the words ‘substantially’ and ‘directly’ are two separate requirements which must be satisfied.  ‘Substantially’ means that the automated aspect must be a key factor in facilitating the human’s decision making. ‘Directly’ means the automated aspect must have a direct connection with making the decision.

As such, if a computer program is used to calculate a sum this may be ‘directly related’ to a decision but not ‘substantially related to’ (unless that sum was a key factor in a human decision maker making a decision).[19]

Finally, for a decision to ‘significantly affect’ the rights or interests of an individual, it must be more than trivial and have the potential to significantly influence the relevant individual’s circumstances.[20] The significance of the effect will depend on the circumstances, such as if the individual is vulnerable (e.g. a child or person with a disability).[21]

APP 1.8

The responsible APP entity must include the following information in its privacy policy:

  1. the kinds of personal information used in the operation of such computer programs, such as name, date of birth, sex, address and so on (APP 1.8(a));
  2. the kinds of such decisions made solely by the operation of such computer programs, such as a fully automated computerised process determining a credit score or denying access to credit (APP 1.8(b)); and
  3. the kinds of such decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs (APP 1.8(c)).  An example of this requirement may be a decision by an ADM system to shortlist job applicants and a human decision maker, upon review, chooses the successful applicant.

APP 1.9

APP 1.9 sets out a non-exhaustive list of the types of decisions this reform applies to. This principle explains that ‘making a decision’ includes refusing or failing to make a decision, and that a decision may affect the rights or interests of an individual in an adverse or beneficial manner. Further, a decision might relate to: (1) a decision made under an Act or legislative instrument to refuse or grant a benefit (e.g. eligibility for community social housing or welfare support); (2) a decision that affects an individual’s rights under a contract, agreement or arrangement (e.g. under an insurance policy); or (3) an individual’s access to a significant service or support (e.g. access to healthcare services or targeted advertising which impacts access to significant goods or services).[22]

Australia’s evolving AI regulatory landscape

The Australian Government stated in its National AI Plan that it will reform existing legal and regulatory frameworks in a way which balances ethical considerations with AI opportunity.[23] Businesses now have certainty that:

  1. ethical principles and guidelines will remain non-binding but will set sector-specific standards for best practice approaches to AI compliance and governance;
  2. existing regulatory frameworks are technology-neutral and already apply to AI development and deployment; and
  3. upcoming reforms will take the form of clarifying and expanding existing legal and regulatory frameworks.  

In relation to points (2) and (3), reforms to existing frameworks will likely introduce proactive, risk-based duties and obligations for businesses.[24] This is to ensure AI is adopted responsibly and people are protected from emerging AI risks and harms. Examples of laws which will be updated include the Competition and Consumer Act 2010 (Cth), the Privacy Act, the Online Safety Act 2021 (Cth), andthe Corporations Act 2001 (Cth).[25] The Australian Government has also confirmed that agencies and regulators, such as the OAIC, the Australian Competition and Consumer Commission and the Australian Securities and Investments Commission (‘ASIC’), will retain responsibility for identifying, assessing, and addressing potential AI-related harms within their respective policy and regulatory domains.[26]

As mentioned, Australia’s existing AI ethical principles and guidelines will remain a key reference point for effective AI adoption practices by businesses.[27] This means the previous proposal to implement mandatory guardrails for AI in high risk settings will no longer proceed.[28] Rather, businesses are encouraged to adopt best practices by complying with sector-specific guidance and standards being developed by relevant regulators including ASIC,[29] as well as the new Guidance for AI Adoption published by the National Artificial Intelligence Centre on 21 October 2025.[30] By adopting the Guidance for AI Adoption and other sector-specific guidelines, businesses can have confidence they will position themselves to be compliant with existing laws and regulations, international standards and subsequent reforms regarding AI and ADM.

Comparative global approaches

As Australia moves toward embedding transparency and explainability obligations into its privacy framework, it is useful to consider the approach of other jurisdictions. Globally, regulatory responses to ADM and AI vary significantly, reflecting different policy priorities, legal traditions and levels of technological adoption.

OECD Principles – the foundation for global norms

The Organisation for Economic Co-operation and Development (‘OECD’) released its Principles on Artificial Intelligence in 2019, later updated in 2024.[31] The OECD Principles advocate for values-based governance of AI systems, emphasising transparency and explainability as essential to fostering trust and accountability. Other principles include human-centred values and fairness, robustness and safety, and accountability.

Transparency under the OECD framework is not just about disclosure; it requires that individuals interacting with AI systems have meaningful information about how those systems operate and the degree of automation involved. Explainability complements this by ensuring that decisions made by AI can be understood and, where necessary, challenged. These principles have influenced the approach taken in many jurisdictions (including Australia’s Guidance for AI Adoption),[32] and underpin the legislative shift toward mandatory transparency obligations in privacy policies.

European Union – the EU AI Act

The European Union has taken the most comprehensive legislative approach to date with the EU AI Act, which came into force in June 2024.[33] The EU AI Act adopts a risk-based framework, categorising AI systems into prohibited, high-risk, and limited-risk tiers. High-risk systems (such as those used in credit scoring, recruitment or biometric identification) are subject to stringent requirements, including transparency, documentation and human oversight.

Transparency obligations under the EU AI Act extend beyond privacy policies. Providers of high-risk AI systems must ensure that users understand the system’s capabilities and limitations, and that individuals affected by ADM can access meaningful information about the logic involved. The EU AI Act also intersects with the General Data Protection Regulation (‘GDPR’), particularly Article 22, which restricts decisions based solely on automated processing that significantly affect individuals, unless specific safeguards are in place.

Canada – Artificial Intelligence and Data Act (‘AIDA’)

The AIDA, which has yet to be enacted, adopts a similar risk-based philosophy but with a narrower scope than the EU AI Act.[34] The AIDA focuses on ‘high-impact’ AI systems and imposes obligations on organisations to assess and mitigate risks of harm or biased outcomes. Transparency is central: businesses must publish plain-language explanations of how their AI systems function, including the types of data used and the potential impacts on individuals.

Unlike the EU AI Act, AIDA places significant emphasis on organisational accountability rather than prescriptive technical standards.

United States of America

The US has not enacted a federal AI law, but regulatory activity is accelerating at both state and sectoral levels. The White House’s Blueprint for an AI Bill of Rights, released in late 2024, sets out aspirational principles, including notice and explanation for automated decisions. Several states, such as Colorado and California, have introduced laws requiring businesses to disclose the use of AI in consumer-facing contexts and to provide mechanisms for human review.

While the approach taken in the US remains fragmented, transparency and accountability are recurring themes.  

Cross-border compliance considerations

For Australian organisations deploying ADM systems globally, the divergence in regulatory models presents practical challenges. Transparency obligations may differ in scope, format and enforcement across jurisdictions. For example, an EU-compliant disclosure may exceed what is required under Australian law but still fall short of U.S. state-specific mandates. Businesses should adopt a harmonised compliance strategy that prioritises the highest common denominator (typically the EU AI Act) while remaining agile to local variations.

Governance, risk and compliance implications

The ADM reform highlights several governance, risk and compliance implications for APP entities. The ADM reform ultimately means businesses will need to ensure their privacy policies accurately include, and adequately explain, the required information set out in APP 1.8. As mentioned, the required information depends on various contextual matters. This includes: the vulnerability of certain individuals, their rights or interests, the sensitivity and types of personal information concerned, and what types of actions are ‘substantially’ and ‘directly’ related to the decision.

Due to the highly contextual nature of the ADM reform, businesses in practice may face challenges in interpreting and implementing the ADM transparency and explainability requirements. As a starting point, a privacy policy will likely be adequately transparent and explainable if it discusses the matters in APPs 1.7 and 1.8 in a way which meaningfully provides general information sufficient to enable a stakeholder to enquire about the input, decision making process or output of a system and seek recourse.

Importantly, to be able to do this, it will be necessary to understand in detail the data flows within their own organisation, to be able to adequately assess whether personal information is being used in connection with an ADM tool, and to assess the significance of the impact on individuals. This involves an often complex and time consuming project of work that needs to be commenced soon in order to be able to comply by December 2026.

There will also be judgements about how much detail to provide about the ADM system. It is unlikely that businesses would be required to explain aspects of an ADM system which are confidential, trade secret, pose a security risk if disclosed, are prohibited from disclosure by law, or are overly technical. For example, training data may contain the personal information of third parties which are protected by the Privacy Act. Source code or methods may be confidential or trade secret. If complex or technical aspects of an ADM system are explained, this explanation may be meaningless to a lay person which undermines transparency, explainability and accountability, and could ultimately lead to opacity rather than transparency. Overall, businesses need to carefully determine how to update their privacy policies to comply with the ADM reform.

If an APP entity fails to comply with APP 1.7, it will have committed a civil offence under s 13K(1)(b)(ii) of the Privacy Act. This civil provision provides that an APP entity is liable for up to a maximum of 200 penalty units if they fail to comply with the requirement in APP 1.4 to include the required information in an APP privacy policy. Entities who breach these provisions may be issued an infringement notice or compliance notice by the Office of the Australian Information Commissioner (‘OAIC’).

Practical recommendations

Businesses can take the following proactive steps now to prepare for the ADM transparency and explainability requirements:

Update Contracts

  • Review existing contracts and risk allocation clauses to ensure they address AI-related risks, noting that Australia’s technology-neutral laws already apply to AI systems.
  • Incorporate provisions for transparency, explainability, and human oversight in vendor agreements and procurement processes.
  • Monitor sector-specific guidance from regulators (e.g. ASIC, OAIC) and leverage templates and frameworks from industry bodies like the IAPP.

Compliance and Internal Governance

  • Conduct data mapping and assessment in order to be able to understand data flows, ADM impacts and ultimately to be able to update privacy policies to include the disclosures required under APPs 1.7 to 1.9.
  • Establish internal AI governance frameworks, including:
    • dedicated AI compliance champions;
    • regular audits and risk assessments of ADM systems; and
    • mechanisms for human review of significant automated decisions.
  • Update internal operations, workflows and policies to implement the best practices outlined in the Guidance for AI Adoption.
  • When considering cross-border compliance, adopt a strategy that complies with the highest common denominator (typically the EU AI Act).

Training Staff

  • Upskill staff in AI literacy and responsible AI practices.[35]
  • Encourage ongoing professional development through current and incoming resources from the National Artificial Intelligence Centre and the Being Clear About AI-Generated Content guide.[36]

Conclusion

With AI becoming deeply entrenched in all facets of society, ADM transparency and explainability obligations have become a key compliance priority in Australia. Accordingly, we encourage businesses to urgently prepare for the ADM reform to manage AI risks and harms, mitigate against liability and promote AI ethical leadership. We also urgently encourage businesses to adopt the above practical recommendations so that they can proactively meet increased ethical obligations from future reforms, improve competitiveness, and keep pace with innovation and opportunity as the economy transitions to widespread AI adoption.  

  1. Department of Industry, Science and Resources, AI adoption in Australian businesses for 2021 Q1, August 2025, accessed 6 February 2025 www.industry.gov.au/news/ai-adoption-australian-businesses-2025-q1.
  2. Explanatory Memorandum, Privacy and Other Legislation Amendment Bill 2024 (Cth) [50].
  3. Privacy Act 1988 (Cth), ss 6 (meaning of “APP entity”), 6C (meaning of “organisation”).
  4. Select Committee on Adopting Artificial Intelligence, Chapter 5 —Automated Decision Making Report (2024) 113 at [5.2] www.aph.gov.au/Parliamentary_Business/Committees/Senate/Adopting_Artificial_Intelligence_AI/AdoptingAI/Report/Chapter_5_-_Automated_decision-making; Information and Privacy Commission of New South Wales, Fact Sheet — Automated decision-making, digital government preserving information access rights — for agencies, (2024) www.ipc.nsw.gov.au/resources/fact-sheet-automated-decision-making-digital-government-and-preserving-information-access-rights-agencies#_ftn1.
  5. Above n 2, at [49].
  6. M Guihot and L Bennett Moses Artificial Intelligence, Robots and the Law 2nd edn, LexisNexis Butterworths, 2025, p 12 at [1.24].
  7. Above, at [1.2].
  8. Above n 2, at [13], citing International Covenant on Civil and Political Rights, opened for signature 16 December 1966, 999 UNTS 171 (entered into force 23 March 1976) (ICCPR), Art 17(1) (right to not be subjected to arbitrary or unlawful interference with privacy); Convention on the Rights of the Child, opened for signature 20 November 1989, 1577 UNTS 3 (entered into force 2 September 1990) (CRC), Art 16(1).
  9. Above n 2, at [13], [50] and [110]; ICCPR, above, Arts 2(1), 16 and 26 (the right to equality and non-discrimination); International Covenant on Economic, Social and Cultural Rights, opened for signature 16 December 1966, 999 UNTS 3 (entered into force 3 January 1976), Art 2.
  10. Above n 6, at [4.3].
  11. Above n 2, at [50] and [110].
  12. Privacy Act 1988 (Cth), s 6 (meaning of “personal information”).
  13. Above n 6, at [2.85], citing M C Buiten “Towards Intelligent Regulation of Artificial Intelligence” (2019) 10(1) European Journal of Risk Regulation 41 at 54–55.
  14. Above n 6, at [2.86].
  15. Above n 6, at [2.82] and [6.58]–[6.60].
  16. Above n 2, at [334].
  17. Above n 2, at [340]. The Explanatory Memorandum explains it is possible that a computer program may be operated by one entity, but another entity is responsible for arranging the computer to make or do a thing that is substantially and directly related to making, the decision.
  18. Above n 2, at [336].
  19. Above n 2, at [338].
  20. Above n 2, at [340].
  21. See above.
  22. Above n 2, at [343].
  23. Department of Industry, Science and Resources National AI Plan Publication (2025) 28 www.industry.gov.au/publications/national-ai-plan.
  24. See above.
  25. Above n 23, at 29–30.
  26. Above n 23, at 28.
  27. Above n 23, at 19.
  28. Department of Industry, Science and Resources, Introducing mandatory guardrails for AI in high risk settings: proposals paper, accessed 6 February 2026 https://consult.industry.gov.au/ai-mandatory-guardrails.
  29. Above n 23, at 33.
  30. Department of Industry, Science and Resources, Guidance for AI Adoption, accessed 6 February 2026 www.industry.gov.au/publications/guidance-for-ai-adoption.
  31. Organisation for Economic Co-operation and Development, OECD Principles on Artificial Intelligence, (2019, updated 2024, accessed 6 February 20026 https://oecd.ai/en/principles.
  32. Above n 30.
  33. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (EU AI Act).
  34. Digital Charter Implementation Act 2022 (Canada) Bill C-27, Pt 3 (Artificial Intelligence and Data Act).
  35. Above n 23, at 22.
  36. Above n 23, at 32.