AI Compliance · 14 min read

AI and the Privacy Act: How Australian Businesses Stay Compliant

There is no AI Act in Australia, which is why so many businesses assume they are fine. The Privacy Act already covers everything you put into an AI tool. Here is what it actually requires, the seven places businesses get caught, and what changes in December 2026.

Published 19 Aug 2026
By Automatrix
Topic Privacy Act · AI Governance · Compliance
Applies to Australian businesses
0 Australian Privacy Principles that apply to AI
0 AI-specific Acts in force in Australia
0 Days you get to assess a suspected breach
0 Million dollar maximum penalty, or 30% of turnover

SECTION 01The short answer

Australia has no AI Act. There is no separate law telling you how your business may use artificial intelligence, and as at August 2026 there is no date set for one.

That is not the relief it sounds like. The laws you already had apply in full, and the Privacy Act 1988 is the one that does the most work. Putting a customer's details into an AI tool is a use, and often a disclosure, of personal information. It has to meet the same tests as any other use. The difference is that a spreadsheet does not quietly send your customer list to a server in Oregon, and an AI chatbot might.

If you only do four things

1. Write down which AI tools your team is allowed to use, and which are banned. 2. Move anything touching customer data onto business or API plans with training switched off, and keep it off the free consumer tiers. 3. Update your privacy policy so it actually describes your AI use, including where the data goes. 4. Put a human in front of every decision that affects a person.

The rest of this guide explains why each of those matters, what the regulator has already said, and what changes in December 2026.

SECTION 02What actually governs AI use in Australia

Five things, in descending order of how likely they are to cause you a problem.

InstrumentStatusWhy it matters to you
Privacy Act 1988 (Cth) and the 13 Australian Privacy PrinciplesLaw, in forceGoverns every use and disclosure of personal information, including anything typed into an AI tool
OAIC AI guidance, published 21 October 2024Regulator guidanceTwo guides: one on using commercially available AI products, one on training generative models. Sets the standard you will be measured against
Australian Consumer LawLaw, in forceMisleading or deceptive conduct covers AI output you publish and claims you make about your own AI
Voluntary AI Safety Standard, 10 guardrailsVoluntaryNot enforceable, but it is the template a regulator or a large client will use to judge whether you were reasonable
Mandatory guardrails for high-risk AIConsulted on, not legislatedAimed at high-risk settings such as employment, credit and health. Watch it if you are in one of those

Sector rules sit on top. If you are in health, finance, legal or education you have professional obligations that are stricter than the Privacy Act, and they do not pause because a tool is new.

The small business trap

Businesses turning over $3 million or less are currently exempt from the Privacy Act. Do not build a strategy on that. The exemption has been under review for years and the 2024 amendments were explicitly the first tranche of more. You also lose it the moment you provide a health service, trade in personal information, or contract to the Commonwealth. And it does you no good commercially: every enterprise procurement form asks how you handle data, and "we are exempt" is not an answer that wins work.

SECTION 03What counts as personal information once AI is involved

Personal information is information about an identified individual, or one who is reasonably identifiable. That second limb is where AI causes trouble, because AI is very good at re-identifying people from fragments.

The practical test we use with clients: if the output of this AI task could be traced back to a specific human being, treat the input as personal information and handle it accordingly.

SECTION 04The six obligations that actually bite

There are 13 Australian Privacy Principles. Six of them do almost all the work when AI is in the picture.

APP 1: have a governance position, and publish it
You need practices and procedures that keep you compliant, and a privacy policy that describes what you actually do. If you use AI on personal information and your privacy policy does not mention it, your policy is wrong. The OAIC has said plainly that entities should update their policies to reflect AI use. This is the cheapest fix on the list and the one most often skipped.
APP 3: only collect what you need
An AI tool that ingests your entire email history to answer one question has collected far more than it needed. Scope the connection. Most integrations default to the widest permission set on offer, because that is easiest for the vendor.
APP 6: using old data for a new AI purpose is a new purpose
This is the one businesses get wrong most often. You collected customer records to deliver a service. Feeding them into an AI system to build a model, train a chatbot or score leads is a secondary use. It is only allowed if the person would reasonably expect it and it is related to the original purpose, or you have their consent. The OAIC has said a person is unlikely to reasonably expect their information to be used to train a generative AI model. Assume you need consent, and that silence is not consent.
APP 8: sending data overseas keeps you on the hook
Almost every AI tool processes offshore. APP 8 does not ban it, but you stay accountable for what the overseas recipient does, unless you took reasonable steps to ensure APP-equivalent handling or got informed consent. Reasonable steps means contract terms you have actually read, not a hope that the vendor is fine.
APP 10: accuracy is your problem, not the model's
You must take reasonable steps to ensure the personal information you use is accurate, complete and up to date. AI systems produce confident, fluent, wrong output. If you act on a hallucinated fact about a customer, "the AI said so" is not a defence, and it is exactly the fact pattern a regulator finds easy to understand.
APP 11: security, including in the vendor's hands
You must protect personal information from misuse, interference, loss and unauthorised access. That extends to data sitting in an AI vendor's systems. Check retention, check who at the vendor can read it, check whether prompts are logged, and check what happens on account deletion.

Consent under Australian privacy law has four requirements. It must be voluntary, informed, current and specific, and the person must have capacity. That knocks out most of what businesses treat as consent.

Not consent

Will not survive a complaint
  • A line buried in terms and conditions nobody read
  • A pre-ticked box, or continued use of your website
  • Consent obtained in 2019 for a purpose that did not exist then
  • "We may use your data to improve our services", which is too vague to be specific
  • Bundled consent, where agreeing to AI use is the price of getting the service at all

Consent

Defensible
  • A clear, separate statement of what AI does with the data and who receives it
  • An affirmative action to agree, with a real option to decline
  • Naming the categories of recipient and the countries involved
  • A withdrawal mechanism that works and that you honour
  • A record of when and how it was given

If getting consent is impractical, the answer is usually not to press on regardless. It is to de-identify properly, or to use a tool where the data never leaves your control, or to not run that use case. Those are cheaper than the alternative.

SECTION 06Where businesses actually get caught

These are the patterns we find on nearly every audit, in rough order of how common they are.

What we findThe exposureThe fix
Staff using free consumer AI accounts for workConsumer tiers commonly reserve rights to use your inputs for training and human review. Every paste is a disclosure you did not authoriseProvide a paid business account. People use the free one because you did not give them anything else
An AI notetaker joining meetings nobody approvedRecording without all-party consent is an offence in NSW. The transcript then sits offshoreControl it at the identity provider, restrict app consent, and announce recording every time
A chatbot on the website with no privacy noticeCollection without notice under APP 5, and often an overseas disclosure with no mention of itA notice at the point of collection, not just in the policy, plus a real retention setting
Customer records exported to build an AI toolSecondary use under APP 6, almost certainly without valid consentDe-identify to a standard that survives scrutiny, or get specific consent, or use synthetic data
A privacy policy that never mentions AIAPP 1 failure, and it undermines any claim that use was within reasonable expectationsAn AI section naming providers, purposes, training position and processing locations
Resumes screened by an AI toolSensitive inferences, discrimination risk, and a decision that significantly affects a personHuman decision maker on every outcome, documented, with the AI only ever ranking or summarising
No record of which tools are connected to whatYou cannot assess a breach you cannot see, and the 30 day assessment clock does not careAn AI register. A spreadsheet is fine. Nothing is not

SECTION 07Ten questions to ask before approving any AI tool

Ask the vendor in writing. Keep the answers. If they will not answer in writing, that is the answer.

AI vendor assessment
Do you use our inputs or outputs to train your models, on this plan, by default?
In which countries is our data processed and stored, and can we choose an Australian region?
How long do you retain prompts, outputs and logs, and can we shorten it?
Who inside your organisation can read our content, and under what circumstances?
Which sub-processors do you use, and will you notify us before adding one?
Do you hold ISO 27001, SOC 2 Type II, or an equivalent independent audit?
What are your breach notification commitments and timeframes to us?
Can we export and permanently delete our data, and how is deletion verified?
What contractual terms bind you to APP-equivalent handling?
Will you tell us before you change any of the above?
The plan tier is the whole game

The same vendor often has completely different data terms across free, personal, team and API plans. Free tiers frequently train on your input. Business and API tiers usually do not, by default. When someone tells you a tool is safe, ask which plan they are on, because the brand name tells you nothing.

SECTION 08The 30 day compliance build

This is the sequence we run for clients. It fits around normal work and does not require a consultant living in your office.

Days 1 to 5: find out what is already connected
List every AI tool in use, including the ones nobody approved. Check third-party app consents in Microsoft Entra ID or Google Workspace admin, look at expense claims for AI subscriptions, and ask your team directly with an amnesty. You will find more than you expect. That is normal, and it is better found by you than by a regulator.
Days 6 to 10: classify your data
Three tiers is enough. Public, which anything can touch. Internal, which approved business tools can touch. Restricted, meaning customer personal information, health, financial, legal and HR records, which only named tools under contract can touch, and some never leave your systems at all. Everything after this depends on this step.
Days 11 to 15: fix the tooling
Move approved use onto business or API plans with training off. Kill the shadow accounts by making the sanctioned option genuinely better, not just mandatory. Revoke app consents you cannot justify. Set retention to the shortest period the work allows.
Days 16 to 20: write the AI use policy
Two pages. Approved tools, what data may go into each, what is banned outright, the human review rule, and who to ask. If it is longer than two pages nobody will read it, and an unread policy protects nobody.
Days 21 to 25: update the privacy policy and notices
Add an AI section covering what you use it for, which providers receive data, where they process it, your training position, and how human oversight works. Add a collection notice wherever AI touches the public, such as a website chatbot or a call summariser.
Days 26 to 30: train the team and set a review date
One session, 30 minutes, with real examples of what is and is not acceptable. Then diarise a quarterly review, because vendor terms change and your register goes stale faster than you think.

SECTION 09What changes from December 2026

The Privacy and Other Legislation Amendment Act 2024 passed in December 2024 and rolls out in stages. Two dates matter.

ChangeWhenWhat you have to do
Statutory tort for serious invasions of privacyCommenced 10 June 2025Individuals can sue directly for serious invasions of privacy, including misuse of information. This applies whether or not you are covered by the Privacy Act, which quietly removes the comfort of the small business exemption
Automated decision-making transparencyFrom 10 December 2026If a computer program makes, or substantially helps make, a decision that significantly affects someone's rights or interests, your privacy policy must say so, what kinds of information are used, and what kinds of decisions are made
Children's Online Privacy CodeBeing developed, due by 10 December 2026If your service is likely to be accessed by under 18s, expect specific design obligations
Tiered civil penaltiesIn forceSerious or repeated interference attracts penalties up to the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Mid and low tier penalties now cover less severe breaches, which makes enforcement far more likely for ordinary businesses
The December 2026 one needs work now

Automated decision-making transparency is not a paragraph you add on the day. You first need to know which of your systems make or substantially assist decisions about people, and most businesses have never mapped that. Lead scoring, application triage, pricing, fraud flags and rostering all qualify depending on how they are used. Start the mapping in 2026 and the policy update writes itself.

SECTION 10Compliance is worth money, not just safety

The framing that gets ignored: this is a sales asset. Every enterprise, government and health procurement now asks where data goes and whether AI touches it. Businesses that can answer in one page win work that businesses who need three weeks to find out do not.

Being able to answer "no, your data is not used for training, here is the contract clause" converts. It is the same answer we now put in front of our own clients, and it closes the conversation in one email instead of four.

The build above costs a few days of attention. A notifiable breach costs the assessment, the notification, the remediation, the client calls and the reputation, and none of those are optional once it happens.

SECTION 11The compliance checklist

AI and Privacy Act readiness
A written register of every AI tool in use, who uses it, and what data it touches
Data classified into public, internal and restricted, with rules for each
All work use on business or API plans with model training confirmed off
No free consumer AI accounts touching customer information
Privacy policy updated with an AI section, naming providers and locations
Collection notices anywhere AI meets the public, including chatbots and call summaries
Overseas disclosures identified, with APP 8 reasonable steps documented
Human review on every decision that significantly affects a person
A two page AI use policy every staff member has actually read
Retention periods set on prompts, transcripts and logs
Breach response plan updated to include AI vendors as a possible source
Systems that make or assist decisions about people mapped, ahead of December 2026
A quarterly review date in the calendar with a name against it

SECTION 12Common questions

Do we need consent to use AI on customer data?

It depends on the purpose. Using AI to do the thing you already collected the data for, such as summarising a support ticket to answer it faster, generally sits within the original purpose. Using the same data to train a model, build a new product or profile customers is a secondary use and usually needs consent. When in doubt, ask whether the customer would be surprised. Surprise is the tell.

Is ChatGPT or Claude safe for business use in Australia?

Both can be, on the right plan. Business, enterprise and API tiers from the major providers exclude your content from model training by default, and offer retention controls and contractual commitments. Free consumer tiers generally do not. The tool is not the risk. The plan and the configuration are.

What if we are under the $3 million small business threshold?

You are currently exempt from the Privacy Act, but not from the statutory tort that commenced in June 2025, not from the Australian Consumer Law, not from your contractual obligations to clients, and not from procurement requirements. The exemption is also politically fragile. Building to the APPs now is cheaper than retrofitting later.

Can we be fined for how we use AI?

Not for using AI as such, because there is no AI Act. You can be penalised under the Privacy Act for how you handle personal information while using it, and the penalties are now tiered so that ordinary breaches are far more likely to be pursued than they were a few years ago.

Does AI-generated content belong to us?

Copyright in Australia requires human authorship. Material generated by a machine with no meaningful human input may attract no copyright at all, which means nobody can stop a competitor copying it. Substantial human direction and editing is what supports a claim. Treat raw model output as a draft, not an asset.

Do we have to tell customers we use AI?

Where AI processes their personal information, yes, through your privacy policy and collection notices. Where AI interacts with them directly, such as a chatbot, telling them is both good practice and the safest position under the Australian Consumer Law. From December 2026, disclosure becomes mandatory for computer programs used in decisions that significantly affect people.

REFERENCESSources

[1] Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principles.
[2] OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024.
[3] OAIC, Guidance on privacy and developing and training generative AI models, 21 October 2024.
[4] Privacy and Other Legislation Amendment Act 2024 (Cth), assented 10 December 2024.
[5] Privacy Act 1988 (Cth), Schedule 2, statutory tort for serious invasions of privacy, commenced 10 June 2025.
[6] Department of Industry, Science and Resources, Voluntary AI Safety Standard, September 2024.
[7] Department of Industry, Science and Resources, Proposals paper for introducing mandatory guardrails for AI in high-risk settings, September 2024.
[8] Competition and Consumer Act 2010 (Cth), Schedule 2, Australian Consumer Law, ss18 and 29.
[9] Telstra Corporation Ltd v Phone Directories Company Pty Ltd [2010] FCAFC 149, on human authorship and copyright.

Written by Automatrix

Want to know what your team has already connected?

We audit which AI tools are running in your business, what data each one can reach, and where that data ends up. You get the register, the gaps, and a plain list of what to fix first. Free, and the findings are yours either way.

0% read