Insights · AI Consulting
AI agents and the 10 December privacy rule.
From 10 December 2026, Australian organisations must say in their privacy policy when a computer program makes, or substantially contributes to, decisions about people. Many AI agents are in scope, including ones a person signs off. What the rule asks, and the inventory to build first.
Most of the AI agents now running in Australian organisations were switched on without anyone asking a privacy question about them. They triage enquiries, flag claims, score applications and rank waiting lists. Many of them do something the law is about to care about: they make, or help make, decisions about people.
From 10 December 2026, an organisation covered by the Privacy Act that uses a computer program in that way has to say so in its privacy policy. That is nine weeks away. This piece sets out what the rule asks for, why a person approving the output does not take an agent outside it, and the inventory work that has to happen before the policy can be written. It is also a fair test of any AI consulting firm you are working with.
What the rule says.
The change came in the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024 and gave organisations two years to prepare. It adds three new paragraphs to Australian Privacy Principle 1, the principle that governs your privacy policy. The rule is triggered when three things are all true.
- A computer program makes a decision, or does something substantially and directly related to making one. The second half matters more than the first, and we come back to it below.
- The decision could reasonably be expected to significantly affect a person's rights or interests. The Act gives examples: granting or refusing a benefit under a law, a decision that affects a person's rights under a contract or arrangement, and a decision that affects their access to a significant service or support.
- Personal information about that person is used by the program. An agent that reads a customer record, a case note or a claim history meets this almost by definition.
Where all three hold, the privacy policy must describe the kinds of personal information those programs use, the kinds of decisions made solely by a program, and the kinds of decisions where a program does something substantially and directly related to the decision. It is a disclosure rule. It does not ban automated decisions, and it does not require consent for each one. It does require you to know where they are.
A person in the loop does not take you out of it.
The most common assumption we hear is that an agent which only recommends, with a person approving every output, is not making decisions and so is not covered. The text does not support that. A program that scores, ranks, flags or drafts the recommendation a person then signs off is doing a thing substantially and directly related to the decision. The human approval moves the decision from one category in the privacy policy to the other. It does not remove it.
That puts a lot of ordinary AI agent work in scope. A few patterns we see often:
- Triage and prioritisation. An agent that decides which enquiry, referral or complaint is handled first is shaping access to a service.
- Eligibility and claims checks. An agent that flags a claim as out of policy, or a request as ineligible, is affecting rights under a contract or arrangement, even if a person makes the final call.
- Pricing and limits. Credit limits, hardship assessments, discounts and fee waivers set or suggested by a model.
- Built-in agents you did not build. Features switched on inside software you already license count as well. If the vendor's agent scores your customers, the disclosure is still yours. Our piece on choosing between an agent platform or an AI consulting firm covers what those platforms leave to you.
Not every agent is caught. One that summarises a meeting, drafts marketing copy or searches your policy library usually decides nothing about a person. The point of the exercise is to know which is which, in writing, rather than to assume.
What this looks like in a care provider.
Care providers sit closer to this rule than most. The decisions their systems support are about access to a significant service or support almost by definition, and the small business exemption generally does not apply to an organisation that provides a health service, which takes in many NDIS and home care providers whatever their size.
Consider the agents a provider is likely to be running or planning: one that prioritises the intake list, one that checks claims against a participant's plan and the current price limits, one that suggests which support worker fills a shift for a particular client. Each uses personal information, and each can affect what support a person receives and when. Each belongs in the inventory. Our pieces on AI for NDIS providers, AI for home care providers and AI and the NDIA describe the work these agents do and the rules around it.
The inventory comes before the policy.
The privacy policy is the last step. You cannot describe the kinds of automated decisions you make until you know what they are, and in most organisations nobody has a complete list. Nine weeks is enough time to build one if it starts now.
- List every program that touches a decision about a person. Include vendor features, spreadsheets with scoring logic and anything a team built for itself. Ask the people who do the work, not only IT; they know which screens tell them what to do.
- Test each one against the three conditions. Does it make or substantially contribute to a decision? Could that decision significantly affect someone? Does it use their personal information? Write down the answer and the reason.
- Record the personal information each one reads. At the level of kinds of information, which is what the policy asks for, but traced to the actual fields so the answer can be checked.
- Classify each decision. Made solely by the program, or made by a person with the program doing something substantially and directly related to it.
- Draft the policy wording with your lawyer. Plain language, organised by the kinds of decisions, not by system name.
- Make it stay true. Add a check to the process for switching on any new agent or AI feature, so the inventory and the policy are updated before it goes live, not after.
The last step is the one most often skipped, and it is where the risk sits after December. Agent features arrive in licensed software every quarter. A policy that was accurate on 10 December can be wrong by March. The same inventory also tells you where personal information flows, which is the starting point for the residency questions in our piece on where your AI data can live.
What to ask your AI consulting firm.
If a firm is building or configuring agents for you, this work should be part of the engagement, not something you discover afterwards. These questions tell you quickly whether it is.
- Which decisions about people will this agent make or contribute to? A good answer is specific and comes before the build, not at handover.
- What personal information will it read, and from which systems? Ask for the list, not a diagram.
- Is the decision made solely by the agent, or by a person it informs? And how would you show which, if asked?
- Who updates the inventory when the agent changes? The answer should be a named role on your side, with the firm handing over the means to do it.
- Can you log what the agent recommended and what the person decided? That record is what lets you answer a complaint or a regulator's question about a specific decision.
Put the answers in the brief. Our guide on how to write an AI consulting brief covers where they belong.
Why RUBIX.
RUBIX is an independent Australian data and AI consultancy, founded in 2011. For 15 years our work has been finding out where an organisation's data actually goes, which systems read it and who relies on the result. That is the same work this rule asks for, applied to AI agents. Three things follow for how we approach it.
- Governance is a practice, not an add-on. Our data governance and AI governance work catalogues where personal information lives and which processes use it, which is most of the inventory before you start.
- We have joined the systems in care. For a leading NDIS provider we joined six disconnected systems into one governed data foundation, with a live role-based dashboard and security from support worker to director, inside eight weeks. Read the NDIS provider case study.
- We build agents that can show their working. When we put AI agents to work, what each one reads and what it recommended is logged as part of the build, so the disclosure can be checked against what the system actually does.
We are not lawyers, and the policy wording is a job for yours. If you need to know what your agents are actually doing with personal information before 10 December, start with a conversation about the decisions they touch.
Frequently asked questions.
What changes on 10 December 2026 for organisations using AI?
From 10 December 2026, an organisation covered by the Privacy Act that uses a computer program to make, or do something substantially and directly related to making, a decision that could significantly affect a person's rights or interests, using their personal information, must say so in its privacy policy. The policy must describe the kinds of personal information used and the kinds of decisions involved.
Does an AI agent that only makes recommendations need to be disclosed?
Often, yes. An agent that scores, ranks, flags or drafts a recommendation that a person then approves is doing something substantially and directly related to the decision. Human approval changes which kind of decision it is in the privacy policy. It does not take the agent outside the rule.
How should an organisation prepare for the automated decision rule?
Build an inventory first: list every program that touches a decision about a person, including vendor features, test each against the rule's three conditions, record the personal information it reads, classify the decision, then draft the policy wording with a lawyer. Add a check so the inventory is updated before any new agent goes live.
General information only, not legal advice. Check how the Privacy Act applies to your organisation with your lawyer. Current as at October 2026.