Australian AI Governance Briefing: Week Ending 9 August 2026
The Privacy Commissioner put surveillance wearables on the regulatory agenda, disclosing that the OAIC has already engaged one entity twice this year on the technical specifications of devices now reaching the Australian market.
A quiet week. Parliament remained in winter recess until 11 August, National Cabinet did not meet, and the Australian Standards for AI flagged for consideration this month had not reached it by Sunday. The OAIC was the only regulator to publish anything of consequence, and it published twice on the same day.
The more significant of the two was a blog post from Privacy Commissioner Carly Kind on surveillance wearables — smart glasses and the ambient-capture devices being built to feed AI assistants. It reads as the successor to the facial recognition work: the OAIC says it is giving serious consideration to the issues these devices raise and monitoring their market presence to determine whether scrutiny or intervention is warranted. Notably, the Commissioner disclosed that the office has already engaged one entity on at least two occasions this year to understand the technical specifications of the products on offer. This is a signal rather than a regulatory action, but it is a specific one, and it arrives with the Privacy Act’s coverage gaps openly acknowledged.
The OAIC also published its 2026 disclosure log desktop review, finding that two-thirds of the agencies examined had failed to publish all their freedom of information disclosure log entries within the statutory timeframe. Separately, the Prime Minister announced a new Secretary for the department that houses the National AI Centre and the Australian AI Safety Institute.
The week in review
The regulator’s next frontier: always-on wearables
On 7 August the OAIC published a blog post by Privacy Commissioner Carly Kind titled “Surveillance wearables — are we through the looking glass(es)?”, opening with Dave Eggers’ novel The Circle and closing with an unambiguous statement of regulatory interest: the office is giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence to understand if scrutiny and intervention is required or warranted. For anyone tracking what follows facial recognition in the OAIC’s technology pipeline, this is the answer.
The Commissioner sets out the market she is watching. Meta’s glasses lead the category. Google’s Android XR smart glasses are slated for launch later this year, Apple’s product for 2027, and cut-price versions are already appearing at mainstream retailers including Kmart and Amazon. OpenAI’s plans for a wearable — described as enabling the ambient collection of data to power AI assistants — are noted as secretive but real. The framing is deliberate: these are not enterprise pilots or niche devices but consumer hardware arriving at scale, with capture as the point rather than a side effect.
The analytical move that matters for compliance teams is the distinction Kind draws between two kinds of surveillance. Place-based surveillance in an airport or a retail shopfront can, on the right facts, be justified against a necessity and proportionality test — the analysis the OAIC set out for facial recognition. Roving individual surveillance carried on a person’s face, in devices designed for discretion or even concealment, does not sit comfortably within that framework at all. The practical questions the blog poses are the ones nobody has answered: how will an entity notify an individual that their image or voice has been recorded, and how will it obtain consent where a facial recognition feature is switched on? The harms flagged run from the use of these devices against children and victims of domestic violence to corporate espionage, data theft, extortion and bribery.
What makes the post unusually candid is its treatment of the Privacy Act’s limits. The Act binds businesses and agencies, not individuals, and it bites only where personal information is collected — which means processing that stays on the device may sit outside it entirely. The Commissioner does not paper over that. She instead points to three levers, none of which is in force in the form required. Tranche 2 of the privacy reforms would introduce a fair and reasonable test — expressly including for the training of AI models — alongside higher consent standards, geolocation protections and an expanded definition of personal information. The statutory tort of serious invasion of privacy is already available against an individual wearer who intentionally invades privacy and causes serious harm, which is the only current avenue that reaches the person actually doing the recording. And the forthcoming Digital Duty of Care would apply to hardware providers, requiring reasonable steps to prevent illegal activity and harm to children. Each of those is a different regulatory instrument aimed at a different actor in the same supply chain.
The disclosure about engagement is the part worth acting on. An office that has met a supplier twice this year to interrogate technical specifications is building a factual foundation, and that is what preliminary inquiries look like before they become something else. Organisations should read the trust context alongside it: the Commissioner cites survey findings that more than 85 per cent of Australians say their privacy concerns have increased over the last five years, and that Australians have almost no trust in social media and AI companies. Her conclusion is that the bar for establishing a social licence for rolling out new technology will be high.
For compliance functions the immediate work is not speculative. Any organisation issuing, permitting or procuring smart glasses — for field service, warehousing, clinical settings, retail loss prevention or executive convenience — is now deploying a technology the privacy regulator has named as a candidate for intervention. The defensible position is the familiar one: a documented assessment of whether the function can be performed without ambient capture, a notification design that works in practice rather than on paper, an explicit decision about whether facial recognition features are enabled, and a clear record of where processing occurs. Organisations that treated the facial recognition guidance as applying only to shopfront cameras should reconsider the scope.
Primary sources: OAIC — Surveillance wearables: are we through the looking glass(es)?
Two-thirds of agencies late to their own disclosure logs
Also on 7 August, the OAIC released its Disclosure Log Desktop Review 2026, examining the disclosure logs of 30 agencies against the requirements of section 11C of the Freedom of Information Act 1982. The headline finding is that while overall compliance was strong, 20 of the 30 agencies — roughly two-thirds — had not published all their disclosure log entries within the legislatively required timeframe during the 2024-25 financial year. A further four could not be assessed. FOI Commissioner Alice Linacre noted that agencies can improve the timeliness, accessibility and usability of information published on their logs, and the review recommends better searchability, keeping logs current including after review processes, and strengthening reporting and governance arrangements.
This is not an AI matter and should not be dressed as one. It earns a place in an AI governance briefing for a narrower reason. The obligation at issue is about as simple as a transparency duty gets: publish a list of what you released, within a fixed period, on a webpage. Two-thirds of the agencies reviewed did not do it on time. The automated decision-making transparency obligations commencing on 10 December 2026 require something considerably harder — identifying where substantially automated decisions sit across an organisation and describing them accurately in a privacy policy. The disclosure log result is a useful calibration of how much lead time a routine publication duty actually needs inside a large entity, and the answer appears to be more than most allowed.
Primary sources: OAIC — Review highlights opportunities to strengthen transparency | OAIC — Disclosure Log Desktop Review 2026
A new secretary for the AI portfolio
On 6 August the Prime Minister announced that the Governor-General had appointed Simon Draper PSM as Secretary of the Department of Industry, Science and Resources, on a five-year term commencing 6 October 2026. Draper moves from the New South Wales Premier’s Department, where he has been Secretary since 2023, and previously led Infrastructure NSW, the NSW Reconstruction Authority and the NSW Department of Industry. He fills the vacancy created when Meghan Quinn was appointed Secretary of Defence in May, a position held on an acting basis by Julia Pickworth.
The appointment is not an AI policy development, but the portfolio matters. DISR houses the National AI Centre and the Australian AI Safety Institute, and owns the Voluntary AI Safety Standard and the Guidance for AI Adoption — the instruments that would most plausibly be converted into or sit alongside mandatory obligations if legislation arrives on the flagged early 2027 timetable. Departmental leadership across that transition is now settled, though the policy centre of gravity for the mandatory framework sits with the Office of AI in the Department of the Prime Minister and Cabinet rather than with DISR. Draper’s background is infrastructure and delivery rather than technology regulation, which is a reasonable signal about where the department’s emphasis is expected to fall.
Primary sources: Prime Minister of Australia — Appointment of Secretary of the Department of Industry, Science and Resources | Capital Brief — Simon Draper appointed federal Industry Department secretary
Stories
OAIC signals regulatory scrutiny of surveillance wearables and smart glasses
In a blog post published on 7 August 2026, Privacy Commissioner Carly Kind said the OAIC is giving serious consideration to the issues raised by surveillance wearables and is monitoring their market presence to determine whether scrutiny or intervention is warranted, naming Meta’s glasses, Google’s Android XR launch later in 2026, Apple’s 2027 product, cut-price devices at Kmart and Amazon, and OpenAI’s planned ambient-capture wearable. The Commissioner disclosed that the office has engaged one entity on at least two occasions this year to understand the technical specifications of the products on offer, and acknowledged the Privacy Act’s limits — it does not bind individuals, and on-device processing may fall outside it. She pointed instead to Tranche 2 privacy reforms, the statutory tort of serious invasion of privacy and the forthcoming Digital Duty of Care as the available levers. Organisations issuing or permitting smart glasses should expect notification and consent design, and the decision to enable facial recognition features, to be the focus of any future scrutiny.
OAIC review finds two-thirds of agencies missed FOI disclosure log deadlines
The OAIC published its Disclosure Log Desktop Review 2026 on 7 August 2026, assessing 30 agencies against section 11C of the Freedom of Information Act 1982. It found that 20 agencies had not published all disclosure log entries within the legislatively required timeframe during 2024-25, with a further four unable to be assessed, and recommended improvements to accessibility, currency, reporting and governance arrangements. FOI Commissioner Alice Linacre said overall compliance was strong but that timeliness, accessibility and usability could improve. The finding is a useful benchmark for public sector entities preparing for the automated decision-making transparency obligations commencing 10 December 2026, which demand considerably more organisational awareness than a routine publication duty.
Simon Draper appointed Secretary of the Department of Industry, Science and Resources
The Prime Minister announced on 6 August 2026 that the Governor-General had appointed Simon Draper PSM as Secretary of the Department of Industry, Science and Resources for a five-year term commencing 6 October 2026. Draper moves from the NSW Premier’s Department and has previously led Infrastructure NSW, the NSW Reconstruction Authority and the NSW Department of Industry, filling the vacancy left when Meghan Quinn became Secretary of Defence in May. The appointment is not an AI policy announcement, but DISR houses the National AI Centre and the Australian AI Safety Institute and owns the Voluntary AI Safety Standard and Guidance for AI Adoption, so departmental leadership is now settled ahead of the mandatory AI framework legislation flagged for early 2027.
This briefing was researched and written with AI assistance.
Stay across Australian AI governance
Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.