Briefings

Australian AI Governance Briefing: Week Ending 14 June 2026

The Privacy Commissioner's Optus White Pages determination set a fresh APP 11.1 benchmark in a week dominated by the looming close of the OAIC's automated decision-making consultation.

3 stories

A quiet week on the parliamentary calendar put the focus squarely on the regulator. The Privacy Commissioner’s determination against Optus over the White Pages publication of unlisted numbers was the week’s only substantive enforcement output, and it lands as a pointed reminder that the size and sophistication of an organisation raise, rather than excuse, what counts as reasonable security under the Australian Privacy Principles.

Beneath that, the dominant compliance story was a deadline rather than an event. Submissions to the OAIC’s Issues Paper on the incoming automated decision-making transparency obligation close on Monday 15 June, and the closing week brought a concentrated wave of law firm guidance urging organisations to lodge submissions and, more importantly, to start mapping where automated decisions sit in their operations — including in third-party and embedded tools.

For compliance teams the practical message is continuity, not novelty. No new binding AI obligations commenced this week, but the same December 2026 cliff looms: the ADM transparency rules under APP 1.7–1.9 commence on 10 December, with OAIC guidance expected in September. The window to influence that guidance closes Monday; the window to be ready for the obligation itself is the next six months.

The week in review

Privacy Commissioner finds Optus breached APP 11.1 over White Pages listings

The week’s headline enforcement development came on Thursday 11 June, when Australian Privacy Commissioner Carly Kind issued a determination finding that Optus interfered with the privacy of 41,728 porting customers whose details were published in the White Pages despite requests for unlisted numbers. The conduct spanned 1 October 2015 to 27 September 2019, and the determination finalises an investigation first announced in August 2021. The Commissioner found Optus breached Australian Privacy Principle 11.1 by failing to take reasonable steps to protect the affected customers’ personal information from unauthorised disclosure.

The reasoning is the part compliance teams should sit with. The customers in question were porting customers whom Optus had specifically asked whether they wanted a listed or unlisted number, creating a clear expectation the request would be honoured. Optus retained control of the directory details and was aware of the risk, but the steps it took — including attempts to reconcile records with directory provider Thryv — were found not to be commensurate with the ongoing risk given the company’s size, resources and sophistication. The Commissioner identified measures Optus could have taken but did not, including promoting a culture of privacy awareness, performing periodic system reconciliations, and putting in place processes to ensure directory details were accurate, current and complete with unlisting requests promptly implemented.

Two points carry forward. First, the framing that a large, sophisticated entity is held to a higher reasonable-steps standard, and that the difficulty of upgrading legacy systems is no defence, is squarely transferable to AI and data governance: an organisation that knows of a risk in a legacy or third-party system and defers remediation is exposed. Second, this is not the end of the matter for Optus — the Commissioner intends to apply the findings to a representative complaint and to consider reasonable and proportionate compensation for affected individuals in a future determination, which keeps the financial consequences live.

Primary sources: OAIC — media centre | Mirage News — Optus faulted in White Pages privacy breach

Automated decision-making consultation closes Monday as firms press for submissions

The substantive compliance current this week was the approaching close of the OAIC’s consultation on guidance for the automated decision-making transparency obligation. Submissions to the Issues Paper — released 18 May — close on Monday 15 June, with the OAIC intending to publish guidance by September 2026 ahead of the obligation’s commencement on 10 December 2026. The obligation, introduced as APP 1.7–1.9 by the Privacy and Other Legislation Amendment Act 2024, requires APP entities to disclose in their privacy policies the kinds of personal information used in automated decisions and the kinds of decisions made solely, or substantially and directly, by a computer program where those decisions could reasonably be expected to significantly affect an individual’s rights or interests.

The closing week produced a notable concentration of professional commentary, with major firms publishing client guidance to coincide with the deadline. The consistent theme is that the OAIC has signalled an expansive reading: “computer program” is taken to extend beyond AI and machine learning to rule-based systems and even spreadsheets, and a human sign-off does not necessarily take a decision outside the obligation where an automated output is a key factor. The firms also converge on the same practical advice — that organisations should not wait for the September guidance, but should now map where automated decision-making sits across their operations, including in third-party and embedded tools, assess vendor arrangements and contracts for visibility and audit rights, and begin drafting plain-language disclosures. The Issues Paper flags third-party ADM as a focus, distinguishing entities that have “arranged for” automated decision-making from those that merely “operate” it, with examples including procuring an AI system to screen job applicants or contracting software to approve or decline refunds.

For compliance teams the deadline matters in two ways. The narrow point is that Monday is the last opportunity to shape how the OAIC resolves the open definitional questions — what counts as “significantly affect,” what is “substantially and directly related,” and where the line between arranging for and operating ADM falls — and entities with significant automated decision-making activity in financial services, insurance, healthcare, employment and government have the clearest interest in doing so. The broader point is that the consultation is a prompt, not a precondition: the obligation commences regardless, and the readiness work of inventory, vendor due diligence and policy drafting should be underway now.

Primary sources: OAIC — Consultation on guidance for transparency in automated decision making | OAIC — APP 1 chapter (automated decisions guidance)

Stories

Privacy Commissioner finds Optus breached APP 11.1 over White Pages listings

On 11 June the Australian Privacy Commissioner determined that Optus interfered with the privacy of 41,728 porting customers whose details were published in the White Pages despite requests for unlisted numbers between 2015 and 2019, breaching APP 11.1. The determination found Optus’s mitigation steps were not commensurate with the risk given its size and sophistication, and that the difficulty of upgrading legacy systems was no defence. The Commissioner will apply the findings to a representative complaint and consider compensation for affected individuals in a future determination.

Source: miragenews.com

OAIC automated decision-making consultation closes 15 June

Submissions to the OAIC’s Issues Paper on guidance for the automated decision-making transparency obligation close on Monday 15 June, with final guidance expected by September 2026 ahead of the obligation’s 10 December 2026 commencement. The paper signals an expansive reading of what counts as a substantially automated decision, including third-party and embedded tools, and flags the distinction between entities that “arrange for” and those that “operate” automated decision-making. Entities with significant ADM activity in financial services, insurance, healthcare, employment and government have the clearest interest in lodging a submission before the deadline.

Source: oaic.gov.au

Law firms press organisations to map ADM use before the deadline

The closing week of the OAIC’s automated decision-making consultation brought a concentrated wave of law firm guidance, including a detailed Allens analysis of the APP 1 amendments. The consistent advice is that organisations should not wait for the September guidance but should now map where automated decision-making sits across their operations — including third-party and embedded tools — conduct vendor due diligence on contracts for audit and disclosure rights, and begin drafting plain-language privacy-policy disclosures. The firms stress that human sign-off does not automatically remove a decision from the obligation where an automated output is a key factor.

Source: allens.com.au


This briefing was researched and written with AI assistance.

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.