Five months before the law requires it, most Australian privacy policies say nothing about automated decisions
Aicura scanned more than 500 Australian privacy policies in July 2026. 55% do not yet contain the automated decision disclosures APP 1.7 requires from 10 December.
By Scott Goldie · 15 July 2026
From 10 December 2026, organisations covered by the Privacy Act must disclose in their privacy policies the kinds of automated decisions that significantly affect people and the kinds of personal information used to make them. Aicura scanned the published privacy policies of more than 500 Australian commercial organisations in early July and found that 55 per cent do not yet contain the disclosures the new provisions describe, with 65 per cent saying nothing about the use of AI at all. The findings were most concentrated in financial services and insurance, and even the strongest policies fell short of the specific disclosures required. The work between now and December starts with knowing which systems make automated decisions. From there it is deciding which of them the provisions capture, updating the privacy policy to say so and keeping it updated as systems change.
The obligation
The Privacy and Other Legislation Amendment Act 2024 added new transparency requirements to the Australian Privacy Principles. From 10 December 2026, APP 1.7 requires an APP entity’s privacy policy to set out the kinds of decisions made using automated systems that significantly affect the rights or interests of individuals, and the kinds of personal information used in those decisions. The requirement sits in a document every organisation already publishes, so whether a policy meets it can be read from the outside. The OAIC will publish its guidance on the obligation by September, and under the expanded penalty regime a privacy policy missing its required content can draw an infringement notice of up to $66,000 without any court proceeding.
The study
We built a panel of more than 500 Australian commercial organisations covered by the Privacy Act, spread across ten industries, then we scanned each organisation’s published privacy policy using the same scan technology that runs inside Aicura. Our technology is powered by AI, and as such has some variance, as a consultant’s reading would. Every policy was read in three separate runs, and a finding only counts if it appeared in at least two of them. Where our verification found error, the scanner was missing issues rather than inventing them, so the figures below are more likely understated than overstated. To get the best results, a scan relies on a company’s AI register of systems and agents, and as this information is not public, a policy that says nothing about automated decisions can belong to an organisation with nothing to disclose, or to one that has not yet disclosed. From the outside, those two look identical, and that is the problem the new provisions exist to fix. From December, the privacy policy is where the difference is supposed to become visible.
The findings
Of the policies we analysed, 68 per cent carried at least one finding that held up across scan runs. Within that, 55 per cent do not yet contain the disclosures APP 1.7 will require from December and a wider 65 per cent say nothing about the use of AI at all. 42 per cent give individuals no path to have an automated decision reviewed by a person, and 38 per cent are silent on how the accuracy of automated outputs is assured. The findings clustered where automated decisions carry the most weight. Every financial services policy in the panel carried at least one finding, with insurance at 84 per cent, healthcare at 54 and retail at 48. This is to be expected, as banks, lenders and insurers make more automated decisions about individuals than any other sector so they have the most to disclose and the most ground to cover before December. The strongest policies in the panel promise that if an automated decision significantly affects you, the organisation will tell you about it at the time. It is a careful drafting instinct, but it is not what the new provisions ask for, which is a present description in the policy itself of the kinds of decisions and the kinds of information involved. Below those policies the range runs through genuine sections that stop short of the required specifics, down to a single boilerplate line, down to silence, which remains the most common state of all. Not one policy in the panel paired substantive automated decision-making disclosure with a scan that raised nothing.
What to do
Preparing for the December obligation is work most organisations can run inside the time remaining. First, know which of your systems make or substantially contribute to decisions about people, which for most organisations means building an AI system register, as nobody can disclose what nobody has listed. Second, work out which of those systems the provisions actually capture, the ones making decisions that significantly affect rights or interests, which is a judgement exercise, not a technical one. Third, write the disclosures into the privacy policy, the kinds of decisions and the kinds of personal information involved, in language a member of the public can follow. Then keep it true, because the register and the policy drift apart the moment systems change, and December is the start of the obligation, not the end of it. We have written guides for each step, covering building an AI system register, working out which systems make automated decisions and writing an ADM transparency statement.
How Aicura can help
The steps above are exactly what Aicura is built for, doing the listing, the drafting and the rescanning so your people only refine and decide. It is the register of your AI systems, with prefilled records for hundreds of commercial AI products and a helper that gathers the details of custom-built systems from the people who know them. It scans your privacy policy against the ADM provisions, drafts the fixes for your review and runs the scan again when systems change so that the policy keeps pace with what the organisation actually runs. The people who own the work refine what Aicura drafts, and the decisions stay with you. When you are ready to go further, the same register carries the rest of the governance work including risk assessments, incidents and the records behind them.
A note on this page. This study reports aggregate results only, and nothing in it is a compliance finding about any organisation. The obligation described is not yet in force. APP 1.7 to 1.9 and the OAIC’s guidance are the primary sources, and this page is not legal advice.
See where your privacy policy stands
Aicura scans your own privacy policy against the ADM provisions, surfaces the automated-decision systems it does not yet disclose and drafts the fixes for your review. The decisions stay with you.