Your AI Risk Register Maps the Regulator. It Misses the Plaintiff., practitioner guidance from TheAICommand
← GRC
Regulatory analysis

Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

Australia's statutory tort for serious invasions of privacy gives individuals a direct cause of action that runs on different rules to the Australian Privacy Principles. Most AI risk registers do not carry it.

·monthly

GRC content. Written for compliance, risk, and audit professionals in Australian financial services. General information. Not legal or compliance advice.

Quick answer

Schedule 2 of the Privacy Act 1988 gives individuals a direct cause of action for serious invasions of privacy, in force since 10 June 2025. It is actionable without proof of damage, the fault test is intentional or reckless, truth is immaterial, and the small business and employee records exemptions do not travel. Own it as its own risk line.

Your privacy risk register is built around a regulator. The tort is not.

Since 10 June 2025 an individual in Australia has been able to sue directly for a serious invasion of privacy under Schedule 2 of the Privacy Act 1988. No complaint to the Office of the Australian Information Commissioner, no investigation, no determination. The OAIC states plainly that it "does not have a direct role in administering the tort" (OAIC, statutory tort guidance). A person who believes your AI system intruded on them or misused information about them can file in a court and put the question to a judge.

Most AI risk registers in Australian financial services do not carry a line for this. They carry APP obligations, notifiable data breach timeframes, APRA prudential standards and ASIC guidance. Those are the surfaces a compliance function is built to watch. The tort is a different surface with different rules, and the gap matters most precisely where AI is doing the most work.

What Schedule 2 actually requires

Clause 7(1) sets out five elements. The defendant invaded the plaintiff's privacy by intruding upon their seclusion or misusing information relating to them. A person in the plaintiff's position would have had a reasonable expectation of privacy in all the circumstances. The invasion was intentional or reckless. It was serious. And the public interest in the plaintiff's privacy outweighed any countervailing public interest.

Four features of that drafting should change how a GRC function reads it.

First, clause 7(2): "The invasion of privacy is actionable without proof of damage." A plaintiff does not need to show financial loss, or any loss. The cause of action is complete on the elements.

Second, the fault threshold is intentional or reckless, and clause 6 provides that "reckless" has the same meaning as in the Criminal Code. That is a defined concept, not a loose one. It turns on awareness of a substantial risk and whether taking that risk was unjustifiable. An organisation that identified a privacy risk in an AI system during design review, recorded it, and shipped anyway is in a very different evidentiary position to one that never saw it.

Third, clause 6 defines misusing information as including, but not limited to, "collecting, using or disclosing information about the individual". Collection alone can qualify. That is a wider entry point than most practitioners assume from the word misuse.

Fourth, clause 7(7): where the invasion involved misusing information, "it is immaterial whether the information was true". An AI system that generates a confident and wrong inference about a customer is not saved by the fact that it was wrong. If anything, untruth is expressly taken off the table as a defence.

Diagram of the five elements a plaintiff must prove under clause 7 of Schedule 2
The five elements of the statutory tort, clause 7(1)

The exemptions you rely on do not travel

This is the point most likely to be missed, and it is on the face of the statute.

Clause 6(2) provides that in determining the meaning of an expression used in Schedule 2, "an expression used in the rest of this Act is to be disregarded (unless a provision of this Schedule expressly provides otherwise)". Clause 6(3) goes further: "In determining the meaning of a provision of this Schedule, the rest of this Act is to be disregarded."

Schedule 2 is drafted to be read on its own. The exemptions that shape day to day privacy compliance sit in the rest of the Act. They are not carried into the Schedule. Schedule 2 has its own exemption regime in Part 3, and it covers journalists, agencies and State and Territory authorities, intelligence agencies and persons under 18. There is no small business exemption in Part 3. There is no employee records exemption in Part 3. Clause 3 also provides that the Schedule binds the Crown in each of its capacities.

For an organisation that has built its privacy position on one of those exemptions, the tort is a second front that the first position does not defend.

Why does AI concentrate the exposure?

Clause 7(5) lists what a court may consider when deciding whether a person in the plaintiff's position had a reasonable expectation of privacy. Paragraph (a) is "the means, including the use of any device or technology, used to invade the plaintiff's privacy". The technology is expressly relevant to the test.

Set that against what AI systems now do routinely in a regulated business. They ingest volumes of customer interaction data that no human process would have touched. They infer sensitive characteristics from non sensitive inputs. They join data that was collected for separate purposes into a single profile. They produce assessments of individuals, at speed, that read as authoritative and are sometimes wrong.

Clause 7(6) then lists seriousness factors, including "the degree of any offence, distress or harm to dignity" the invasion was likely to cause, and whether "the defendant knew or ought to have known" that it was likely to cause that harm. Ought to have known is an objective standard. A risk assessment that flagged the harm, or an industry practice that recognised it, feeds directly into that limb.

The remedy set is also broader than damages. Clause 12(2) allows an account of profits, an injunction, an apology order, a correction order and, at paragraph (e), an order that material "obtained or made as a result of the invasion of privacy" be destroyed or delivered up. In an AI context, material made as a result of an invasion is not just a record. It can reach derived datasets, embeddings, inference outputs and anything downstream that was built from the contested data. That is an operational problem, not just a legal one, and it is worth knowing whether your architecture could comply with such an order at all.

Damages are capped. Clause 11(5) provides that non economic loss damages plus any exemplary or punitive damages must not exceed the greater of $478,550 and the maximum available for non economic loss in defamation proceedings under an Australian law. The court must not award aggravated damages (clause 11(2)) but may award damages for emotional distress (clause 11(3)). The cap is meaningful but it is per plaintiff, and it sits alongside the reputational cost of a published judgment describing your AI system.

The vendor question, and the injunction risk

Two operational points follow that are easy to miss when the tort is read as a legal abstraction.

The first is who the defendant is. Clause 7(1) frames the action against "another person" who invaded the plaintiff's privacy. Where an AI capability is supplied by a vendor and deployed by you against your customers or staff, the conduct that a plaintiff points to is usually yours: your decision to deploy, your choice of data, your configuration, your purpose. A contractual indemnity may move the money afterwards. It does not move the conduct, and it does not stop you being named. Contract review should be asking whether the vendor is obliged to support you in defending a claim about how the system behaved, and whether they can produce the technical evidence you would need to run the reasonable expectation and seriousness arguments.

The second is timing. Clause 9(1) allows the court to grant an injunction restraining the defendant from invading the plaintiff's privacy "at any stage of the proceedings". That is not a final remedy after a trial. It is available while the matter is on foot. For a GRC function used to regulatory timeframes measured in months, an application that could restrain a live system within weeks is a materially different risk profile, and it belongs in the operational resilience conversation rather than only the legal one.

Clause 10 provides the counterweight. The court may give judgment for the defendant where it is satisfied the plaintiff has no reasonable prospect of success, and clause 8A allows the court to determine at any stage whether a Part 3 exemption applies. Weak claims can be disposed of early. That is genuine protection, and it is worth more to an organisation that can produce a clean contemporaneous record of its reasoning than to one that cannot.

Do this Monday

Add the tort as its own risk line. Not a sub item under Privacy Act compliance. It has a different trigger, a different decision maker and a different remedy set. If your register maps controls to APP obligations only, the tort has no row and therefore no owner.

Make the recklessness question part of design review. The fault element rewards organisations that identify, assess and resolve privacy risk before deployment, and punishes those that identify it and proceed. That is an evidentiary point as much as a legal one. Keep the record of what was considered and what was decided.

Test whether your consent is really consent. Clause 8(1)(b) makes it a defence that the plaintiff, or someone with lawful authority, "expressly or impliedly consented to the invasion of privacy". Consent buried in terms that never mentioned the AI use is a weak foundation for that defence. So is consent obtained for a different purpose.

Check the destruction order is technically possible. Before you need it. If material derived from a contested dataset cannot be located and removed from your AI stack, work out now what your answer to clause 12(2)(e) would be, and put the requirement into vendor contracts where a third party holds the derivatives.

Know your clock. Clause 14 requires proceedings to be commenced before the earlier of one year after the plaintiff became aware of the invasion and three years after it occurred, with a court able to extend to no later than six years. Records retention settings that assume a longer or shorter window should be checked against that.

Context

Australia resisted a general privacy tort for two decades. The Australian Law Reform Commission recommended a statutory cause of action in 2014, and it took the 2024 reform package to legislate one. The design choice that matters most is the one in clause 6: Schedule 2 is deliberately insulated from the rest of the Act. Comparable jurisdictions arrived by a different route, with the United Kingdom developing misuse of private information through the courts rather than by statute. Australia has legislated the elements, which means the argument in an Australian case will be about application rather than existence.

The AI angle

The uncomfortable reading is that the tort catches the systems a compliance map often treats as low risk. A model that scores customers, a monitoring tool that watches sessions, an assistant that reads correspondence, a profiling layer that joins previously separate records. Each is defensible under an APP analysis with the right notice and purpose. Each also collects and uses information about identifiable people in ways those people did not expect, using technology the statute expressly invites a court to consider, producing outputs whose truth is legally beside the point.

The practical governance response is not to stop building. It is to run a second read over the AI inventory asking a different question. Not "which obligation does this touch" but "would an individual reasonably expect this, and could we show a court that we thought about that before we shipped".

Bottom line

The tort is a second surface with its own decision maker, fault test, remedy set and clock, and it is deliberately insulated from the APP regime your register already maps. It is actionable without proof of damage, truth is not a defence, and the exemptions you rely on elsewhere do not travel. Give it its own risk line, its own owner and a design-review record that shows the privacy question was asked before the system shipped.

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.

Primary sources

  1. Privacy Act 1988 (Cth), Schedule 2, Statutory Tort for Serious Invasions of Privacy, Compilation C104, in force from 4 June 2026. Clauses 3, 6, 7, 8, 11, 12 and 14 and Part 3. https://www.legislation.gov.au/C2004A03712/latest/text
  2. Office of the Australian Information Commissioner, Statutory tort for serious invasions of privacy, commencement 10 June 2025, including the statement that the OAIC does not have a direct role in administering the tort. https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What is the statutory tort for serious invasions of privacy?
A direct cause of action in Schedule 2 of the Privacy Act 1988, commenced 10 June 2025. A plaintiff must prove five elements under clause 7(1): an invasion by intrusion upon seclusion or misuse of information, a reasonable expectation of privacy, intentional or reckless fault, seriousness, and that the plaintiff's privacy interest outweighed any countervailing public interest. The OAIC states it does not have a direct role in administering the tort.
Do the small business and employee records exemptions apply?
No. Schedule 2 is drafted to be read on its own, and clause 6 provides that the rest of the Act is disregarded when interpreting it. Part 3 contains the Schedule's own exemption regime, covering journalists, agencies and State and Territory authorities, intelligence agencies and persons under 18. There is no small business exemption and no employee records exemption in Part 3.
Why does AI concentrate exposure to the tort?
Clause 7(5) expressly makes the means, including the use of any device or technology, relevant to the reasonable-expectation test. AI systems collect and join data at a scale people do not expect and produce confident inferences about individuals that may be wrong, and clause 7(7) makes it immaterial whether the information was true. Remedies can also reach derived material through destruction or delivery-up orders.
What damages are available under the tort?
Damages are capped. Non-economic loss damages plus any exemplary or punitive damages must not exceed the greater of $478,550 and the defamation non-economic loss maximum. Aggravated damages must not be awarded, emotional distress damages are available, and the remedy set also includes an account of profits, injunctions, apology and correction orders, and destruction or delivery up of material.
How long does a plaintiff have to sue?
Proceedings must generally be commenced before the earlier of one year after the plaintiff became aware of the invasion and three years after the invasion occurred. A court may extend the period, but not later than six years after the invasion. Records retention settings should be checked against that window.

Context

Australia resisted a general privacy tort for two decades. The Australian Law Reform Commission recommended one in 2014, and it took the 2024 Privacy Act reform package to legislate it. Schedule 2 is drafted to stand apart from the rest of the Act, which is why it behaves so differently to the compliance regime practitioners already know.

AI angle

AI systems generate the two things the tort is built to catch: collection and use at a scale a person would not expect, and confident inferences about individuals that may be entirely untrue.

Primary sources

privacylitigation-riskai-governanceprivacy-actrisk-register
← Back to GRC

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.