Under a new Privacy Act obligation, Australian government agencies must start disclosing when computer programs help decide people’s rights and entitlements – just as the same agencies are being pushed to build more such programs through a government-wide AI platform and training mandate.

Compliance officers are drafting privacy policy disclosures to satisfy a new legal requirement about automated decision-making, while the same agency’s staff are being trained – through a new platform called GovAI – to build more of the very systems they are scrambling to disclose.

From 10 December 2026, any Australian organisation, including government agencies, that uses personal information in a computer program to make or substantially help make decisions significantly affecting a person’s rights or interests must say so in its privacy policy. The obligation stems from the Privacy and Other Legislation Amendment Act 2024, and it lands on Services Australia, tax administrators, licensing regulators, and any agency running a decision engine or triage tool.

The irony sits at the level of policy design. The government mandating AI literacy and internal tool-building across the public service is also the government now required to tell the public, in plain language, when it lets software make decisions about them. Transparency and expansion share a calendar and a target: the same agencies, arriving within months of each other.

What the new law requires

The obligation sits in new Australian Privacy Principles 1.7 to 1.9. An entity must comply where it has arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision, and that decision could reasonably be expected to significantly affect an individual’s rights or interests, and personal information is used in the process. 

Where those conditions are met, the entity’s privacy policy must disclose three things: the kinds of personal information used, the kinds of decisions made solely by computer programs, and the kinds of decisions in which an automated step substantially contributes to a decision a human ultimately makes.

The definition of ‘computer program’ is deliberately broad… a spreadsheet formula that scores and triages calls to a crisis hotline counts; a formula that simply calculates someone’s age from a date of birth does not.

The definition of “computer program” is deliberately broad, according to the OAIC’s Issues Paper on the new obligation. It captures pre-programmed rule-based processes as readily as machine-learning systems – a spreadsheet formula that scores and triages calls to a crisis hotline counts; a formula that simply calculates someone’s age from a date of birth does not. That breadth means agencies cannot assume their older, low-tech scoring tools sit outside the new regime just because nobody thinks of them as “AI”.

The law creates no individual right to demand an explanation of a specific decision, and no right to insist a human redo an automated assessment. Non-compliance carries genuine penalties – serious or repeated breaches of the Privacy Act 1988 can attract fines up to the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover – but the underlying obligation is limited to naming, in general terms, what an agency’s systems do.

The shadow of Robodebt

The reform exists because of Robodebt, the automated debt-recovery scheme that wrongly pursued welfare recipients for money they did not owe. The Royal Commission into the Robodebt Scheme, led by Commissioner Catherine Holmes, found the scheme was “a crude and cruel mechanism, neither fair nor legal, and it made many people feel like criminals,” adding that “people were traumatised on the off-chance they might owe money. It was a costly failure of public administration, in both human and economic terms.”

Among its 57 recommendations, the Commission called for departmental websites to disclose, in plain language, when automated decision-making is used and how the process works, and for business rules and algorithms to be made available for independent scrutiny. The December 2026 deadline delivers a version of that recommendation – narrower, and years later than the scandal that prompted it.

The other half of the irony: GovAI and the training mandate

While agencies prepare disclosures, the same government is accelerating internal AI adoption. Finance Minister Katy Gallagher’s AI Plan for the Australian Public Service mandated foundational AI training for around 200,000 public servants and required every Commonwealth agency to appoint a chief AI officer by July 2026. It also rolled out GovAI, a secure, sovereign, whole-of-government platform offering AI training, an application catalogue and a sandbox for building tools, with GovAI Chat trials beginning from April 2026.

TMR’s own reporting on the training mandate has characterised the plan’s use-case ambitions as spanning compliance monitoring, risk analysis, case triage and fraud detection – a synthesis of the GovAI use-case language rather than a direct quotation from the plan itself. Whatever the precise wording, agencies are being equipped to build more automated tools of exactly the kind that shape decisions about individuals, at the same time as they are being asked to disclose the tools they already have.

A readiness gap – but a different disclosure regime

The Office of the Australian Information Commissioner (OAIC) has already tested how well agencies disclose the automated decision-making they use today, and the results are not encouraging. A desktop review of 23 Commonwealth agencies authorised to use automated decision-making found that only 17% (four agencies) disclosed that use through their published Information Publication Scheme material. A further 9% (two agencies) were identifiable as likely users of automated decision-making through other public sources but had made no disclosure at all, and 74% (17 agencies) could not be confirmed as using it through any public material whatsoever.

Only 17% (four agencies) disclosed that use through their published Information Publication Scheme material… 74% (17 agencies) could not be confirmed as using it through any public material whatsoever.

That review was conducted under the Freedom of Information Act’s Information Publication Scheme – an existing transparency obligation that predates the Privacy Act disclosure duty commencing in December. The two regimes are related in spirit, and the review is a reasonable proxy for institutional readiness, but they rest on different legal bases and a like-for-like compliance comparison would overstate the connection. What the review does establish cleanly is a baseline: agencies without a track record of disclosing automated decision-making under one regime are now being asked to do so, more precisely, under another. OAIC guidance to help them interpret the new obligation is not due until September 2026, roughly ten weeks before the law commences.

A second, slower-moving framework

Adding to the complexity, the government has separately signalled a broader plan for government AI decision-making. In a joint statement on 20 July 2026, six ministers – Attorney-General Michelle Rowland, Minister for Industry and Innovation Tim Ayres, Minister for Communications Anika Wells, Minister for Employment and Workplace Relations Amanda Rishworth, Assistant Minister Andrew Leigh and Assistant Minister Andrew Charlton – announced a set of AI consumer-safety priorities, including a commitment, led by Rowland, to “develop a framework to better regulate the use of automated decision-making within federal agencies, recognising the importance of ensuring fair, accurate and transparent government decision-making, including in the context of emerging technologies such as AI.”

That framework is a policy commitment: unlegislated, with no confirmed timetable. It is easy to conflate with the December disclosure deadline, but the two are distinct workstreams moving at different speeds – one a legislated obligation with a fixed commencement date, the other an announced intention still to be designed. Rowland’s framework is intended to address governance – fairness, accuracy, review rights – in a way the disclosure law does not.

The critics: why disclosure isn’t enough

Independent Curtin MP Kate Chaney has argued the reform stops short of what Robodebt exposed as necessary. Her March 2026 policy paper, Fairer and Faster Government Decisions, states that Australia does not currently have a legislated or mandatory framework governing the use of automated decision-making across government, and that existing protections are fragmented, limited and often voluntary.

“Neither assessors nor reviewers can override the automated decision.”

– Kate Chaney MP,
Fairer and Faster Government Decisions

She points to aged care and the National Disability Insurance Scheme (NDIS) as case studies in what a framework needs to fix. In both areas, a human assessor conducts a clinical assessment that is then entered into a program determining the support outcome, but, as her paper puts it, “neither assessors nor reviewers can override the automated decision.” A review can take up to 90 days, and even where an NDIS decision is appealed to the Administrative Review Tribunal, the tribunal can only direct the department to re-assess and re-enter the same information into the same tool – a human cannot manually change the program’s decision at any point. Notably, Chaney’s paper suggests the tools in both case studies may rely on fixed rules rather than AI, an ambiguity that complicates any assumption that automated decision-making risk in government is chiefly an AI problem.

The paper proposes a legislated, mandatory framework built on three pillars: transparency requirements so Australians can understand decisions that affect them, decision-level controls so government gets decisions right, and review and oversight provisions so Australians can be confident government is following the rules. 

“Legislating a mandatory framework will send a clear message to government departments and agencies that compliance is essential,” she writes. The paper draws on a survey of 761 Curtin constituents, more than 80% of whom said they were “very uncomfortable” or “somewhat uncomfortable” with government use of automated systems to help make decisions, and close to 80% of whom supported legislated, mandatory rules on automated decision-making.

The sequencing problem

Underneath the individual deadlines sits a sequencing problem. Agencies are expanding their use of automated tools through GovAI and mandatory training before the disclosure rules that will eventually cover those same tools have even been finalised in guidance. A related but distinct disclosure regime shows most agencies have a poor track record of volunteering this information at all. And the more ambitious governance framework – the one meant to guarantee fairness and accuracy, not just visibility – exists so far only as a ministerial commitment with no date attached, while Chaney’s own case studies show that even where a human is nominally in the loop, the automated tool’s decision often cannot be overridden at all.

Canberra is building the tools well ahead of finishing the rules for disclosing them, and the guidance meant to bridge the two arrives ten weeks before the deadline it’s supposed to explain.