The definition that does the AI work

Privacy tranche two is one of the government’s five AI safety priorities, and we noted on 4 October that it now has draft legislation. Having read the draft and its 42-page consultation paper in full, the answer to what it does about AI is narrower and more useful than a new AI law. The Attorney-General’s Department says on the consultation page that the reforms will help tackle emerging risks from new technologies, including artificial intelligence and wearable devices such as smart glasses. The bill does that almost entirely through definitions.

The key one is new section 6AAA. An entity collects personal information only if the entity collects the personal information for inclusion in a record or generally available publication (regardless of the source from which or means by which the information is collected). The note under it gives the examples that matter for AI: means of collection include generating the information itself using its own processes, systems, observations or measurements, or deriving it from other information.

The consultation paper spells out the intent twice. On page 7 it says personal information may be generated or derived through means such as data analysis, artificial intelligence or other technological processes. On page 41, under emerging technologies, it says: This reform will ensure that inferences drawn by AI-enabled technology about an individual would be considered collection of information for the purpose of the Act. The paper calls this clarifying the definition, and it rests on a second change: personal information becomes information that relates to an identified or reasonably identifiable person, with a note listing characteristics, behaviours, traits, preferences or patterns of activity as information that can make someone identifiable. A profile is squarely in that list.

What being a “collection” would trigger

Calling an inference a collection matters because of what the draft attaches to collection.

What the exposure draft would require of an inference, once it counts as a collection
If the inference isThe draft requiresWhere
Any personal informationThe collection must be fair and reasonable in the circumstances and lawful. Factors include whether a reasonable person would expect it, whether the purpose could be met with less information, whether the person has genuine choice, whether any risk of harm is proportionate, and, for a child, the child’s best interests as a primary considerationNew APP 3.1 and 3.2
Sensitive information (racial or ethnic origin, political opinions, religious beliefs, sexual orientation, health, criminal record and others)An APP entity must not collect sensitive information that relates to an individual unless the individual has consented to the collection of the information, subject to exceptionsNew APP 4.1, 4.3
Sensitive, and for direct marketingThe strictly necessary exception can never apply: such a collection is never strictly necessaryNew APP 4.5

The draft is careful about when a sensitive inference is collected. Holding ordinary data from which something sensitive could be worked out is not enough: An entity is not taken to collect sensitive information only because the entity collects personal information from which the sensitive information can be derived. The sensitive information is collected when the entity derives it for a record, uses or discloses it, or at the start if that was the purpose all along. The paper’s example is a halal meal order: not sensitive information when it is used to deliver a meal, but a collection of religious belief once the entity uses it to send marketing about a religious festival.

The exceptions an AI builder would look at first

The consent rule for sensitive information does not apply when the information is collected from a publicly available document. The paper says that definition is intended to be broad and that a publicly available document may also include other publicly accessible material, such as social media posts. The fair and reasonable test still applies in that case: its own exceptions, in APP 3.3, cover only collections required or authorised by law and the permitted general and health situations.

The draft also gives a right to erasure, a new APP 14, but only against a large digital platform: a provider of a social media service, relevant electronic service or designated internet service under the Online Safety Act whose business group had gross revenue of at least $500 million in the previous financial year, or whose service averaged at least 2.5 million monthly end users in Australia, or which is prescribed by regulation. eSafety’s 2024 industry standard defines a high impact generative AI service as a designated internet service that uses machine learning models to enable an end-user to produce material, and we have explained why generative AI services generally fall in that class. On our reading, a large enough chatbot provider would be inside the erasure right. The platform would have to destroy the information on request unless an exception applies, one of which is that, despite reasonable steps, destruction is unreasonable or impracticable due to technical impossibility or infeasibility.

Neither document says how any of this applies to information inside a trained model. The words model, training and trained do not appear in the exposure draft or the consultation paper.

When, and what it is not

This is an exposure draft, not law and not yet a bill. The department’s page says The Bill remains subject to further consideration by government. The consultation opened on 31 August and closed on 18 September. The draft’s commencement table has no entries, and its transitional item says the new definition of collects would apply in relation to collections made on or after the commencement of this item, so an inference made before then would not be caught by the new collection rules. A ParlInfo title search for the bill on 7 October returned no results.

It is also separate from the automated decision-making rule that starts on 10 December. That obligation, to say in a privacy policy when a computer program makes decisions that significantly affect people, is already law from the 2024 amendments; we covered what counts as an automated decision under it. The 10 December rule is about decisions. This draft is about the information, and the inference is where it starts.

Our view

Handling AI through the definition of collection is the right design. The paper says the Privacy Act is intentionally technology neutral and principles based, and a rule that turns on whether you generated information about a person will not date the way a list of AI techniques would. It also closes the most obvious gap in practice: a business that never asked for your health status but has a system that works it out would, under this draft, have collected it, and would need your consent unless an exception applied.

Two things weaken it. The publicly available document exception is broad by design, and the draft does not say whether a sensitive inference drawn from public posts is collected from a publicly available document or derived by the entity, which is the whole question for anyone building on scraped data. And the erasure right, the one place a person could make an AI company delete what it holds, says nothing about models. If government means inferences and models to be covered, the introduced bill or its explanatory memorandum should say so in those words.

Sources

  1. Exposure Draft, Privacy Amendment (Personal Data Protection) Bill 2026, Attorney-General’s Department, 58 pages (PDF downloaded and read in full 7 October 2026): the blank commencement table (p 2); section 6AAA and its note (pp 4-5); section 6FD and note 1, section 6FE, and Schedule 1 transitional item 13 (pp 6-8); APP 3.1 to 3.4 (pp 12-13); APP 4.1 to 4.5 (pp 14-15); section 6EB and its end-user method statement (pp 43-45); APP 14.1 to 14.3 (p 46). Absence of the AI terms checked against the DOCX version from the same page.
  2. Privacy Reform, Consultation Paper, Attorney-General’s Department, 42 pages (PDF downloaded and read 7 October 2026): roughly 40 proposals (p 1); the definition of collects and the halal meal example (p 7); the publicly available document exception (pp 16-17); large digital platforms and the right to erasure (pp 33-35); addressing emerging technologies (pp 41-42).
  3. Privacy Reform, Consultation on Exposure Draft legislation, Attorney-General’s Department, Citizen Space (read 7 October 2026): opened 31 August 2026, closed 18 September 2026; the AI and smart glasses framing; the Bill remains subject to further consideration by government.
  4. ParlInfo bills search, title “Personal Data Protection”, Parliament of Australia (run 7 October 2026): no results found.
  5. Online Safety (Designated Internet Services, Class 1A and Class 1B Material) Industry Standard 2024, eSafety Commissioner (PDF, read in full 4 August 2026; definition re-read 7 October 2026): the definition of a high impact generative AI DIS, section 6, printed page 8.

How we checked this. Both documents were downloaded from the department’s consultation page and read in full; every quotation is verbatim. The absence of the words artificial intelligence from the draft, and of model, training and trained from both documents, comes from a full-text search of the PDF and DOCX text on 7 October; the draft’s only use of “automated” is in the sensitive information definition, about biometric verification. Whether a generative AI service is a large digital platform is our reading of section 6EB with the eSafety definition, not a statement by the department. We have not compared the new definition of collects with how the courts or the regulator read the current one. The ParlInfo absence is about that search on 7 October; a bill introduced since may not yet be indexed. We have not asked the department about the points in “Our view”, which is opinion based on the documents cited.

Made a submission on the draft, or read section 6AAA differently? Tell us and we will check it against the document and log the outcome here.