Lesson 2 of 5 · 9 min

By James Durkin, JDCS · Updated 6 August 2026

What you're actually allowed to do.

Most people approach this backwards. They ask whether a tool is safe, get a vague answer, and either ban it or shrug. The more useful question is about you, not the tool: given the obligations your business already carries, what are you permitted to do with client, patient or customer information? Answer that once and the tool questions mostly answer themselves. Before we start, the standing caveat: this is general information, not legal advice, and your own position needs your own adviser.

The change with a date on it

A new Australian Privacy Principle, APP 1.7, commences on 10 December 2026. In plain terms, if you are an APP entity and you use personal information in automated decisions that could significantly affect a person's rights, your privacy policy has to disclose two things: the kinds of personal information used, and the kinds of decisions being made with it.

It is a transparency obligation. Nothing gets banned, and nobody has to approve your systems. The work is mostly knowing where automated processing sits in your decisions and writing a few honest lines about it.

The scope is where it gets interesting. The OAIC has signalled a broad reading. Reported analysis of its position has "computer program" extending across commonly used software, apps, word-processing tools, AI systems, generative AI tools, chatbots and virtual assistants, and, importantly, has systems that materially assist human decision-making potentially captured, not only decisions made entirely by a machine.

Sit with that for a second. A firm using an AI tool to triage job applicants, score inbound leads, draft advice or set pricing may land inside this, even with a person signing off at the end. Most businesses in that position have no idea the obligation exists. If that might be you, the useful move now is an inventory: list the decisions in your business where software materially shapes the outcome for a person. That list is the work. The privacy policy wording is the easy part, and it's the part your lawyer can do quickly once the list exists.

The correction most Australian coverage gets wrong

Now for the claim you will read on plenty of Australian IT and consulting blogs: that the small business exemption is being removed from 10 December 2026, sweeping millions of extra businesses into the Privacy Act.

That is not right. Removing the small business exemption is a tranche 2 proposal. The government supports it in principle and the OAIC supports it. No bill has passed. There is no commencement date. The exemption is still there.

Why bother making the correction? Two reasons, and both are practical. First, if you budget and plan around a law that has not been made, you will either spend money you didn't need to spend or lose faith in the advice when December arrives and nothing happens to you. Second, it tells you something about the quality of what you're reading elsewhere. Plan hard around the change that has a date. Watch the one that doesn't, because it may well arrive eventually, and preparing calmly beats scrambling.

The obligations that never expire

December is a date. Your professional duties are permanent, and for a lot of firms they bite harder.

  • Tax practitioners. TPB(GS) 55/2026 sets out that tax practitioners must obtain client permission before disclosing client information to a third party, and that this can include entering client information into AI models and tools. Practitioners should also tell the client where data will be stored and whether AI tools may be used. Permission comes through a signed engagement letter or a signed consent. The consequences under section 30-15 of the Tax Agent Services Act 2009 run from a written caution up to termination of registration. The question to ask yourself is uncomfortable and clarifying: do my current client permissions match what my firm actually does with AI today?
  • AML/CTF tranche 2, commenced 1 July 2026. Lawyers, accountants, conveyancers, real estate agents, precious metals dealers and trust and company service providers became AUSTRAC reporting entities, with obligations including customer due diligence, sanctions screening, suspicious matter reporting, seven-year record keeping and staff training. Notice the compound effect: those firms now hold more identity documents and source-of-funds evidence than they used to, they must keep it for seven years, and they are precisely the firms tempted to point AI at the new paperwork.
  • Everything you already carried. Legal professional privilege, health records legislation, your duty of confidentiality, consumer law, and your professional body's code. None of them contain an exception for software that happens to be clever.

The framework to follow, and the one to stop quoting

Australia has no single sweeping AI act. What it has is guidance, and the current guidance is the National AI Centre's Guidance for AI Adoption, published on 17 October 2025 and often shortened to AI6. It replaced the Voluntary AI Safety Standard and condensed that standard's ten guardrails into six essential practices:

  • Decide who is accountable.
  • Understand impacts and plan accordingly.
  • Measure and manage risks.
  • Share essential information.
  • Test and monitor.
  • Maintain human control.

Two things follow. If an article or a vendor deck is still talking about "the ten guardrails", it predates October 2025, which tells you how carefully it was written. And mandatory guardrails, which were under discussion for a while, were dropped in the December 2025 National AI Plan. So the compliance posture for an Australian small or medium business right now is voluntary guidance plus your existing legal duties, and the six practices above are a genuinely sensible skeleton for a policy. Our free AI policy course turns them into a one-page document if that's your next job.

What the regulator says about keeping it in the building

One more line worth knowing, because it comes from the OAIC rather than from anyone selling hardware. In its guidance on commercially available AI products, the OAIC notes that deploying AI systems locally is "likely to be more privacy-preserving as it limits the risks of third party access to the data". It also recommends against entering personal information, and especially sensitive information, into publicly available generative AI tools.

Read the wording precisely, because precision is the whole point of this course. Likely to be more privacy-preserving. It's a comparison, not an absolution, and it doesn't say local is always right or always required. What it does mean is that if you end up recommending a local deployment for your most sensitive material, you are not out on a limb. You're aligned with how the privacy regulator describes the architecture. Lesson three looks at what actually runs on your own hardware, and lesson four at what it costs.

The bottom line: APP 1.7 commences 10 December 2026 and requires disclosure of the kinds of personal information used in significant automated decisions and the kinds of decisions made, with the OAIC signalling a broad reading that may capture systems which materially assist human decisions. The small business exemption has not been removed; that is an unpassed tranche 2 proposal with no commencement date. Tax practitioners need client permission before client information goes into AI tools under TPB(GS) 55/2026, and AML/CTF tranche 2 has been live since 1 July 2026. The current framework is the National AI Centre's six essential practices, not the old ten guardrails. General information only, so take your own position to your own adviser. Next up: what open models genuinely do well on hardware you own.
Quick check

A few quick questions to lock it in. No marks recorded, just for you.

Q1.What commences on 10 December 2026?

APP 1.7 requires you to disclose the kinds of personal information used in significant automated decisions and the kinds of decisions made. It's transparency rather than prohibition.

Q2.Has the small business exemption been removed from the Privacy Act?

Plenty of Australian coverage says otherwise and it's wrong. Plan hard around the change that has a date, and keep an eye on the one that doesn't.

Q3.What is the current Australian framework for AI adoption?

Guidance for AI Adoption replaced the Voluntary AI Safety Standard and condensed ten guardrails into six practices. Mandatory guardrails were dropped in the December 2025 National AI Plan.

Pick up anywhere

Save your progress

Pop your email in and we'll send you a link to pick up where you left off, on any device. No account needed.

Just for the link to your progress. No spam, and I never share your details.