What is automated decision-making under Australian law?
Automated decision-making, usually shortened to ADM, is the use of a computer program to make a decision about a person, or to do something substantially and directly related to making that decision. The term is now anchored in the Privacy Act 1988 by a transparency obligation introduced through the Privacy and Other Legislation Amendment Act 2024.
The obligation is built as a three-part test. It is engaged where the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; the decision could reasonably be expected to significantly affect the rights or interests of an individual; and personal information about the individual is used in the operation of that computer program.
The Act then defines the edges of the test deliberately widely. Making a decision includes refusing or failing to make a decision. Doing a thing includes refusing or failing to do a thing. A decision may affect rights or interests whether the individual is affected adversely or beneficially, so a system that automatically approves is in scope alongside one that automatically declines.
The Act also gives worked examples of decisions that may affect rights or interests: a decision made under a provision of an Act or legislative instrument to grant or refuse to grant a benefit; a decision that affects the individual's rights under a contract, agreement or arrangement; and a decision that affects the individual's access to a significant service or support.
Note what the obligation is and is not. It is a transparency duty attached to the privacy policy. It is not a prohibition on automated decisions, a right to human review, or a right to an individual explanation of a particular decision.
Who does the automated decision-making obligation apply to?
It applies to APP entities, which covers most Australian Government agencies and private sector organisations with annual turnover above three million dollars, along with the smaller operators the Act specifically captures.
The reach inside those organisations is wider than most registers assume. The trigger is a computer program, not artificial intelligence, so a deterministic rules engine, an eligibility calculator, a scoring spreadsheet and a machine learning model can each engage the obligation on identical terms. Long-standing systems that predate any AI programme are squarely within scope.
The word arranged also matters. An entity that has arranged for a computer program to make or support the decision is covered, which reaches decisions supported by a vendor platform or an outsourced service rather than only by software the entity built. The meaning of arranged for is one of the questions the OAIC put out for feedback in its May 2026 issues paper, alongside the meaning of computer program, of substantially and directly related, of significantly affect rights or interests, and of the extent of disclosure required.
From 10 December 2026, entities in scope must set out in their privacy policy the kinds of personal information used in the operation of such programs, the kinds of decisions made solely by them, and the kinds of decisions for which a program does something substantially and directly related to making the decision.
Where does AI fit in automated decision-making?
AI is the reason the obligation is now urgent, but it is not the boundary of it. The sharper question for most organisations is the reverse of the one they expect: whether keeping a human in the loop takes the system out of scope. On the face of the provision, it often will not.
APP 1.7 reaches a program that does a thing substantially and directly related to making a decision, not only a program that makes the decision. A model that ranks, scores, screens, summarises or recommends can sit within that language while a person signs the outcome. The OAIC's issues paper tests precisely this scenario, describing an agency whose staff use a generative AI chatbot to summarise applicant profiles and recommend eligibility, with a human always making the final call, and asking consultation participants whether that use is substantially and directly related to making the decision.
That framing aligns with the OAIC's separate AI guidance, which treats the use of AI for decisions that may have a legal or similarly significant effect on an individual's rights as likely to be a high privacy risk activity, warranting particular care about accuracy and about whether the product suits the intended purpose.
Two AI-specific risks compound the exposure. Accuracy obligations under APP 10 apply to information used in the decision, and generative systems produce confident output regardless of correctness. And where the model's contribution is summarisation, the summary itself shapes the decision even though no score is ever recorded.
What should practitioners do about automated decision-making?
Build the inventory first, and build it against the statutory test rather than against the label AI. Every system that makes or materially supports a decision about a person needs to be assessed for whether the decision could reasonably be expected to significantly affect rights or interests, and whether personal information is used in the program's operation.
Classify each system by which limb of APP 1.8 it falls under, because the disclosure differs. Decisions made solely by a program and decisions where a program does something substantially and directly related to making them are described separately in the privacy policy.
Do not treat human sign-off as a scope exemption. Record what the model actually contributes, how much weight the decision-maker gives it, and whether the human has the information and the time to depart from it. That record is the evidence for the classification, and it is the same evidence an administrative law or Administrative Review Tribunal challenge would probe.
Draft the privacy policy change early rather than in December 2026, and align it with collection notices so the two do not contradict each other. Related material sits under the privacy topic hub, the AI governance hub and across the GRC section.
Bottom line
The automated decision-making obligation is a transparency duty, not a ban, and it commences on 10 December 2026. Its reach is wider than the AI label suggests, because the trigger is a computer program, and because it captures programs that do something substantially and directly related to making a decision rather than only programs that decide. That is why human sign-off does not reliably remove a system from scope, and why the OAIC put the human-oversight scenario out for consultation. Practitioners who inventory decisions rather than technologies, and who record what the model actually contributes, will find the privacy policy update straightforward.
TheAICommand. Intelligence, At Your Command.*
TheAICommand. Intelligence, At Your Command.
