The OAIC has published its final guidance on automated decisions. Here is what it says

Flowchart of the OAIC's seven questions for deciding whether the 10 December 2026 automated decision-making disclosure applies: APP entity, computer program arranged, personal information used, rights or interests affected, significant effect, substantially related, directly related. A yes to all seven means the privacy policy must disclose it.

On 30 September 2026 the Office of the Australian Information Commissioner published the guidance everyone had been waiting for on the new automated decision-making disclosure. The obligation starts on 10 December. That left ten weeks from publication, and the guidance confirms the broad reading rather than softening it.

If you have not read the earlier piece on what the obligation is, start with From 10 December, your privacy policy has to name the decisions your software makes. This article is about what the final guidance adds, and what it means for a disability, aged care or community services provider deciding what to do between now and December.

What was released

Four things: a fact sheet on the APP 1.7 to 1.9 transparency obligation, a supplementary fact sheet for government agencies, a one-page flowchart, and a revised Chapter 1 of the APP Guidelines. The OAIC says the package reflects 90 submissions on its issues paper. Having read both, the final position is the issues paper with examples attached. Nothing in the consultation narrowed it.

The flowchart

The OAIC’s flowchart is seven yes or no questions. I have redrawn it below with the plain-English from the fact sheet beside each step. Run every system that touches a decision about a client, participant, resident, applicant or staff member through it.

A seven-step flowchart. Each question flows down on YES and out to the left on NO, where it is marked out of scope. The questions: is your organisation an APP entity; have you arranged for a computer program to make or inform a decision; does it use personal information; does the decision affect a person's rights or interests; is that effect significant; is the program substantially related to the decision; is it directly related. A final yellow box reads IN SCOPE and states what the privacy policy must disclose.

Three of those questions do the real work, and the guidance has something to say about each.

“Computer program” means almost anything

The fact sheet lists what counts: pre-programmed rule-based processes, AI and machine learning, software, apps and word-processing tools, and generative AI including chatbots. The first worked example is a spreadsheet. An aged care provider scores clients for triage using a formula and ranks them, and staff use the ranking to decide who gets contacted. That is in scope. The OAIC adds that using the same ranking to decide who not to contact is also in scope, because refusing or failing to make a decision is still a decision.

So the question is not “do we use AI”. It is “which of our systems produce an output that someone acts on”.

The guidance also settles who carries the obligation when the software belongs to someone else. “Arranged for” covers buying a SaaS product, configuring off-the-shelf software, authorising a tool to decide something, and simply relying on its recommendations. The worked example is a housing provider that buys a vendor’s AI matching tool; it is in scope whether or not it can adjust the parameters. Vendors are expected to tell you enough to write your disclosure, but the disclosure is yours.

Human review does not get you out

This is the point most organisations were hoping would go the other way. A program is “substantially and directly related” to a decision if its output is a key factor with a direct connection to what the human decides, whether the output is advisory or determinative. The OAIC says plainly that machine learning or generative AI outputs feeding significant decisions will generally be in scope unless subject to extensive human oversight and control.

The worked example is a firm using a generative AI tool to draft performance reviews and suggest bonuses. HR oversees it. A director signs off every decision in writing. Still in scope, because the recommendation is what gets relied on to document the reasoning. The guidance does describe what genuine oversight looks like: interrogating the output, going back to the underlying evidence, setting the tool’s parameters narrowly, using other sources, and writing down why you diverged from the recommendation. If your people do all of that, the tool may fall outside. If they read the recommendation and click approve, it does not.

A human in the loop is not a defence. A human doing the work is.

“Significant” is a low bar, measured from the person’s side

Significant means more than trivial, with the potential to considerably influence the individual’s circumstances. Rights are legal or moral entitlements. Interests include health, housing, finance, employment and access to services. Where a decision would land harder on a vulnerable cohort than on the general population, that counts toward significance.

Two examples set the tone. An online grocer varies prices by postcode. Each difference is a dollar or two, but the OAIC says it is significant regardless, because small differences compound and the goods are essential. And a recruitment platform that targets job ads by age and gender, then screens video interviews using voice and facial analysis, is in scope at both steps: one limits access to employment, the other decides who gets the next interview.

The fact sheet also publishes a list of decisions it considers in scope without further argument. For this sector the ones that matter are prioritising health or disability services, determining eligibility for a government benefit or housing, recruitment screening, and AI-generated reports used for performance, promotion or pay.

What you can leave out

Commercial-in-confidence information is excluded, but the exclusion is narrow. It covers trade secrets and information whose disclosure would detract from its commercial value or hand a competitor an advantage. It does not cover information that would merely cause embarrassment or public criticism. The worked example is a lender with a proprietary fraud model: how the model weights its inputs can be withheld, but the fact that personal information feeds fraud detection and credit decisions cannot.

How much to write

Less than you fear. No technical detail is required. You can group categories of decisions and types of personal information, provided the result is meaningful to a reasonable person and specific to your organisation. Where sensitive information is used, health information or biometric templates in particular, say so clearly. The fact sheet gives two model disclosures, and each is a short section headed “Decisions made by computer programs”, listing the kinds of information used and then the kinds of decisions made, split by business function where the processes differ.

The disclosure is a few paragraphs. It is the only part of this that is quick.

What the guidance changes about the next ten weeks

Nothing about the inventory. Everything about the excuse.

Before 30 September an organisation could reasonably say it was waiting for the regulator. That is gone. The guidance tells you a spreadsheet counts, a vendor’s tool counts, sign-off by a director does not take a tool out, and when in doubt you should include it. The remaining work is the same as it was: find every system that shapes a decision about a person, record what data it uses and whether a human really does the work, decide which decisions are significant, and write the three statements.

In a mid-sized provider that takes three to four weeks of interviews and analysis. Counting back from 10 December, the last comfortable start is the middle of November. The organisations that will be compliant on the day are the ones that start the inventory now and hand their lawyer a list rather than a question.

What Governance Works does about it

The 10 December Privacy Changes AI Systems Audit is a fixed-price engagement that produces that list: a day of interviews with up to eight key staff, a risk-rated register of every system influencing a client decision across 15 risk domains, draft disclosure wording mapped to the register, a 30-minute CEO briefing, a Board summary, a three-hour working session with your compliance lead, and a full report. Three to four weeks.

The information is at governanceworks.com.au/10-december

Questions to hello@governanceworks.com.au.


This article is general information, not legal advice. The OAIC’s fact sheet, flowchart and revised APP 1 Guidelines are at oaic.gov.au. Confirm your obligations against the Privacy Act 1988 (Cth) and the OAIC’s guidance, or with your lawyer.

Governance Works · Liability limited by a scheme approved under Professional Standards Legislation.


.

The OAIC has published its final guidance on automated decisions. Here is what it says

On 30 September 2026, the Office of the Australian Information Commissioner unveiled crucial guidance on automated decision-making, set to take effect on 10 December. This new obligation requires organizations to disclose the decisions made by their software, impacting sectors like disability, aged care, and community services. The guidance clarifies what constitutes a “computer program,” emphasizes the significance of human oversight, and outlines what information can be excluded. With only weeks left to prepare, organizations must act swiftly to ensure compliance. Discover how to navigate these changes and protect your clients’ rights in our detailed analysis.

Read More »