Quick verdict
From 10 December 2026, APP entities that meet the automated-decision trigger must add prescribed information to their privacy policy. The duty is to describe kinds of personal information and kinds of decisions. It is not a workshop rewrite of the whole policy. It is not a certificate. It is not “prove the model in court.”
Counsel cannot draft that paragraph until someone hands them a list of what the organisation already runs, who owns it, what personal information it touches, and where the gaps are. The teams that miss December book a “privacy policy update” in November and discover in week one that nobody has a system list.
Best for: privacy officers, GCs and CIOs at APP entities who will own the December wording. Honest limit: Cipher Projects is not a law firm. We build the evidence layer. Sign-off stays with your counsel. We do not claim you are compliant at the end of a workshop.
Last updated: 4 September 2026. The three-limb legal test lives on the December ADM post. The dated map of 2026–2027 lives here. This page is the pack counsel actually needs.
What does counsel need before they can write APP 1.8?
Five artefacts, in this order: an inventory of what you already run (including default vendor features nobody bought as an “AI project”); a named owner for each row; what personal information each program uses; a gap list with who is fixing what, by when; and an export counsel can read without sitting through the upload.
What the December rule actually asks for
Instrument: Privacy and Other Legislation Amendment Act 2024 (Cth). Effect: APP 1 subclauses 1.7, 1.8 and 1.9 commence 10 December 2026. Who: APP entities. Small-business exemptions under the Privacy Act still matter. Not every Australian business using a chatbot is in.
OAIC paraphrase of the trigger: the APP entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual; and personal information about the individual is used in the operation of that program. Primary page: OAIC APP 1 guidelines.
APP 1.8 then requires the policy to state:
- the kinds of personal information used in the operation of those programs
- the kinds of decisions made solely by those programs
- the kinds of decisions where a thing substantially and directly related to making the decision is done by such programs
Making a decision includes refusing or failing to make one. The duty applies whether the outcome is beneficial or adverse. OAIC also notes the amendments apply to decisions from that date regardless of when the arrangement or the personal information was created. You cannot wait until you “start using AI.” You already are.
What the rule does not do: ban automated decisions, force a human in the loop, or create an individual right to an explanation. Other laws can still require more. The three-limb table: 10 December 2026 ADM rule.
Four questions that sort any AI use
Every row on the inventory, including the ones nobody bought as AI, gets these in the room:
| Question | Why it exists | If yes |
|---|---|---|
| Does it process personal information? | Privacy Act. Prompts, logs, retrieved documents and vendor training opt-ins count. OAIC enforces this today. | It is already a privacy row, December or not. |
| Does it decide things about people, or help decide? | Starts 10 December 2026 for in-scope ADM at APP entities. | It is a candidate for APP 1.8 kinds-of-decisions text. |
| Is the organisation APRA-regulated? | CPS 230 and CPS 234. Skip if you are not. | Material third-party technology is already an operational-risk file. |
| Does it affect customers, staff, applicants, or vulnerable people? | Privacy, employment and consumer law already apply. The Federal Court ordered a $44.7 million penalty on the ACCC’s Trivago case over a misleading recommendation engine. No AI Act was required. | Existing law, not a 2027 standard, is the first constraint. |
Engineering must not self-exempt “it’s only a recommendation.” Rubber-stamp review is the fact pattern OAIC discussion keeps returning to. Counsel marks in / out / needs facts after the rows exist.
Who should be in the room
Two people minimum. Three is ideal. More than that and the day turns into a meeting.
- A sponsor with authority: someone who can say yes to the list and the owners, without a committee.
- One operator: the person who can show logins, software spend, and the vendor list. They find the AI nobody calls AI.
- Legal as a user of the export, not an observer of the whole upload. Your lawyer reads the pack and owns the privacy-policy wording. They do not need to sit through every SSO hunt.
If legal sends an observer and IT sends a contractor, the register will be polite and wrong. Field list we actually fill: AI inventory for shadow AI.
What you walk out with, and what you do not
| Walk out with | Walk out without |
|---|---|
| Inventory started, including tools nobody bought as an AI project | A badge, or anything “certified” |
| A named owner for every system on the list | A rewritten privacy policy |
| Existing documents in one place | A claim that you are compliant |
| A gap list: what is missing, who is fixing it, by when | Legal opinions. Those stay with counsel. |
| An export your lawyer can use for the December privacy-policy work | ISO 42001. That is an assessor’s job after months of an AIMS. |
Cipher Projects sits on Alan Murphy’s Tipcan evidence software (ai-compliance.app) for that living register. The public offer is a compliance workshop under Australian law, especially the December duty. In the room or remote. We build the evidence layer. We do not certify you.
Unique insight from the rooms we run: the valuable artefact is the gap list. Boards relax when they see forty rows. They should read the eight marked “unknown data / no owner / rights-affecting” first. Those eight are the December problem.
FAQ
We are under the small-business exemption. Do we still need this pack? The December duty sits on APP entities. Ask counsel whether you are one. The pack is still useful when a customer, insurer or tender asks you to show AI governance. The Voluntary AI Safety Standard is the usual checklist for that request. It is not law.
Does a human clicking “accept” take a system out of APP 1.8? Not automatically. A program that does a thing substantially and directly related to the decision can still trigger the rule.
Is ChatGPT in scope? Only if personal information about an individual is used and the output is used to make or support a decision that significantly affects them. A writer using ChatGPT on public copy is a different row from a case officer pasting a customer file into ChatGPT to decide a hardship request. Both rows belong on the inventory. Only the second is likely APP 1.8.
Will OAIC guidance change the test? Guidance interprets the Act. It does not move 10 December. Start the inventory before the final PDF lands. The OAIC ADM issues paper is the working document until then.
Does this replace the 2027 standards work? No. December and 2027 are different layers. Calendar argument: December 2026 vs 2027.
Not legal advice. Regulatory mapping is general. Verify against official sources before you act. Sign-off on privacy policy and ADM disclosures stays with your counsel. We do not claim Australia has an AI Act. We do not claim a workshop makes you compliant.
Related: 10 December 2026 ADM rule · December vs 2027 · AI inventory · Prove it · Clear Direction AI workshops
