Is your business ready for Australia’s AI transparency deadline?

Artificial intelligence is now embedded in how many businesses hire, manage, and serve people. If yours is one of them, a significant compliance deadline is coming that you need to act on.
Is your business ready for Australia’s AI transparency deadline?

What changed and when

In December 2024, the Australian Government passed the Privacy and Other Legislation Amendment Act 2024, the most substantial overhaul of Australia’s privacy laws in almost 40 years. After four years of proposals, discussions, and drafts, the Act received Royal Assent on 10 December 2024, with most changes taking effect immediately.

One set of obligations was given a two-year grace period: the rules governing transparency in automated decision-making. Those provisions come into force on 10 December 2026.

 

What this means for employers

If software, an algorithm, or an AI tool plays a role in decisions about employees, job candidates, or customers, your business must clearly and specifically disclose that in your privacy policy.

The phrase “computer program” is intentionally wide-ranging. It captures not just sophisticated AI platforms but also everyday HR tools such as your applicant tracking system, performance management software, and automated rostering platform, if they use personal data to inform a significant decision.

If you’re using HR software, an ATS, or performance management tools, the chances are you’re already caught by these rules. Citation HR’s Advice Line can help you understand what that means for your people processes and the next steps to take.

 

What employers need to disclose

From 10 December 2026, APP entities must include the following in their privacy policies:

  • The types of personal information used in substantially automated decisions.
  • The nature of decisions made solely or significantly by computer programs.
  • Decisions where significant effect on individual rights or interests could reasonably be expected.

Disclosures must reflect your organisation’s actual systems and processes – not generic or standardised language.

 

What happens if you don’t comply

Failure to comply will expose your organisation to:

  • Significant penalties under the Privacy Act, including substantial fines for serious or repeated breaches.
  • Reputational damage and heightened regulatory scrutiny.

The OAIC’s 2026 compliance sweep signals a move from education and guidance towards active enforcement. That means your window for self-correction is closing.

 

What to do next

The December 2026 deadline may feel distant, but the work required to meet it is not trivial. Organisations need to audit every tool that handles personal data, assess whether automated decisions are made, update privacy policies with specific, accurate disclosures, and ensure humans remain meaningfully in the loop.

The businesses that act now will be compliant and protected. Those that don’t act now risk being in the regulator’s sights first.

Citation Legal can review your current privacy policies and AI tools to identify where your exposure lies and confirm your documents are legally sound before the deadline arrives.

Curious to learn more about how AI is reshaping workplace risk in Australia? Download our free AI in the workplace guide to understand the risks and what your business needs to do about them.