In August we reported that a privacy rule starting on 10 December 2026 would require organisations to disclose automated decisions, and that the regulator had not yet said what counts. On 30 September the Office of the Australian Information Commissioner said. Its new fact sheet, a supplement for government agencies, a flowchart and an update to its APP 1 Guidelines answer the open question, and the answer is wide. The OAIC says the resources reflect the feedback received from 90 written submissions.

What counts as a computer program: nearly everything

The fact sheet's list of what a computer program includes runs from pre-programmed rule-based processes to artificial intelligence and machine learning processes, software, apps or word-processing tools, and generative AI used to generate text, images, videos, code or synthesis, including chatbots. There is no carve-out for old-fashioned software. A spreadsheet rule that sorts applicants is in the same category as a large language model.

A human in the loop does not take you out of it

The point most organisations will need to hear: A decision may be within scope of the transparency obligation even where a computer program output does not replace the entire decision-making process or is subject to human review. The OAIC goes further for machine learning and generative AI. It considers their outputs, when used to make decisions that significantly affect people, would generally fall within scope of the transparency obligation unless subject to extensive human oversight and control.

It also defines the two words the test turns on. Substantially means where it is a key factor in facilitating the human's decision making, and Directly means where the thing has a direct connection with making the decision.

The phrase that decides scope, now defined

Our August piece said everything turned on whether a decision could reasonably be expected to significantly affect the rights or interests of an individual. The fact sheet now says significantly means the impact of the decision or thing must be more than trivial and must have the potential to considerably influence the circumstances or outcomes for the individual concerned, and that vulnerability matters: a decision may have a greater impact on people experiencing vulnerability than on the general population.

It also lists decisions it would generally consider in scope. Among them: facial recognition for watchlist matching in a shop or stadium, recruitment software that sorts candidates, personalised pricing for significant goods, programs that prioritise health or disability services, eligibility for government benefits, housing, education places, loans, credit and insurance, AI reports used to rank staff or set bonuses, and immigration and border processing.

And where an organisation is unsure, the regulator's instruction is to disclose: entities in doubt should take a cautious approach and include information in their APP privacy policy.

Who carries it, and what can be withheld

The obligation stays with the organisation making the decision, not the software vendor, though the OAIC says vendors should provide clear, high-level information about how their products can be used so customers can comply. Commercially sensitive information and trade secrets are out of scope, with a limit the fact sheet states plainly: information about using a program for significant decisions is not shielded just because it results in exposure to ridicule, embarrassment or public criticism.

Government agencies get a supplement linking the rule to their existing Freedom of Information publishing duties. It says agencies should publish the types of automated decision-making they use, not just that AI is being used by the agency.

Our view

This is broader than a reading limited to AI would suggest, and clearer than the rule's own words. The two exits people tend to reach for, "a human signs off" and "it is just software", are both closed by the regulator's own words. With just under ten weeks to go, an organisation that has not inventoried its decision tools is behind. And the list of in-scope decisions reads like a map of where automated decisions already touch people most: hiring, pricing, credit, insurance, benefits and borders.

How we did this

We read the OAIC's announcement and both fact sheets in full and quote them directly; the flowchart and the updated APP 1 Guidelines were released alongside them and are not quoted here. The list of in-scope decisions is the OAIC's, summarised in our words with every item kept. Fact sheets are the regulator's view of the law, not the law, and a court could read the obligation differently. "Just under ten weeks" is our count from 3 October to 10 December. This follows our 18 August story on the same obligation. We did not contact the OAIC. The “our view” paragraph is opinion based on the documents quoted.

Sources

  1. OAIC, New resources on transparency for use of AI and automated decision-making (published 30 September 2026, read 3 October 2026): the commencement date, the resources released and the 90 submissions.
  2. OAIC, APP 1.7-1.9 Transparency Obligation Fact Sheet (PDF, 11 pages, September 2026, read 3 October 2026): what counts as a computer program, human review, substantially and directly, significantly, vulnerability, the in-scope decisions list, the in-doubt instruction, vendors, and the commercial-in-confidence limits.
  3. OAIC, Supplementary Fact Sheet for Government Agencies (PDF, 5 pages, read 3 October 2026): the link to Information Publication Scheme duties and what agencies should publish.

Spotted an error? Tell us and we will check it against the sources and log the outcome here.