Field note
What Australian law actually requires of your AI
There is no Australian AI Act. There are laws that already apply to what your software does, and one date in December 2026 worth putting in the calendar.
Last checked 8 August 2026. Every point below links to the legislation, the regulator or the government publication it comes from. What we could not confirm is listed at the bottom.
01 · Where the rules actually are
There is no Australian AI Act.
Nobody is coming to licence your chatbot. Australia has not passed a law that regulates AI as a category. The government consulted in 2024 on mandatory guardrails for AI in high-risk settings, and those rules were not made. Proposals paper, September 2024 ↗
What applies is the law you were already under. The Privacy Act 1988 covers any personal information your software touches, including information the software works out about someone. The Australian Consumer Law covers what you tell people about it. The ACCC has put that in writing: the prohibitions on misleading or deceptive conduct, unconscionable conduct and false representations "apply equally to consumers of AI-enabled goods and services". accc.gov.au ↗
Your own regulator does not go quiet because a computer did the work. If you are a bank, insurer or super fund, APRA's CPS 234 gives you 72 hours to notify a material information security incident, and that clock runs through your vendors. apra.gov.au ↗ CPS 230 has applied since 1 July 2025. It pulls any vendor supporting a critical operation onto a register you submit to APRA, including software you would call a subscription rather than an outsourcing arrangement. apra.gov.au ↗
So the useful question is a different one. What does this system do with people's information, and what have you told them about it?
02 · The government guidance
Six practices, and none of them are law.
The National AI Centre published its Guidance for AI Adoption on 5 May 2026. industry.gov.au ↗ It replaced the ten guardrails in the Voluntary AI Safety Standard, which had been the reference document since September 2024. industry.gov.au ↗ The ten guardrails became six essential practices.
- Decide who is accountable
- Understand impacts and plan accordingly
- Measure and manage risks
- Share essential information
- Test and monitor
- Maintain human control
The guidance comes in two parts. Foundations is for getting started. Implementation practices is the step-by-step version, and it is long. ai.gov.au ↗
None of it creates a legal duty. It matters anyway, because it is the document a regulator, an insurer or a large customer will hold you against when something goes wrong. Practice four says people should know when they are dealing with AI, and when AI decisions affect them. Practice six says there has to be real human oversight, a way to intervene, and something that still works when the AI is turned off.
One thing worth checking if you are buying. Some Australian firms are still selling AI policies written to the Voluntary AI Safety Standard and its ten guardrails. Ask which document yours is written to, and what date is on it.
03 · The December 2026 change
From 10 December 2026, say so when a computer decides.
If a computer decides something about a person, or does most of the deciding and a human just signs off, and that decision matters to them, you have to say so in your privacy policy. Not the details. Just that it happens, and roughly what information goes into it.
The rule reaches well past AI. A credit scoring tool counts. Software that sorts job applicants counts. So does an automated eligibility check or a rules engine somebody wrote in 2013. The wording was drafted to catch automated decision-making of any kind, not one technology. hwlebsworth.com.au ↗
Most businesses have never sat down and worked out which of their systems this covers. It is about a day's work, and the day is cheaper before December than after.
The precise version
The obligation sits in Australian Privacy Principles 1.7 and 1.8, inserted by the Privacy and Other Legislation Amendment Act 2024. It commences on 10 December 2026. Privacy and Other Legislation Amendment Act 2024 ↗
Three limbs all have to be met before the obligation bites.
- The entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making one.
- The decision could reasonably be expected to significantly affect the individual's rights or interests.
- Personal information is used in the operation of that program.
Where all three are met, the privacy policy has to set out the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to making them. The explanatory memorandum reads "substantially" as the program being a key factor in the human decision, and "directly" as a direct connection to making it. Commercial-in-confidence detail about how the system works does not have to be published. jws.com.au ↗
Decisions read as significantly affecting someone include loan approvals, insurance pricing, screening job applications, benefit eligibility and marking exams. landers.com.au ↗
04 · The new right to sue
Since 10 June 2025 a person can sue you directly over privacy.
This is the change most Australian businesses have not heard about. A statutory tort for serious invasions of privacy commenced on 10 June 2025. An individual can bring a claim in their own name. oaic.gov.au ↗
There are two ways to invade privacy under it: intruding on someone's seclusion, or misusing information that relates to them. Intruding on seclusion is defined to include watching, listening to or recording a person's private activities. An AI system that records a caller sits squarely inside that wording.
The bar is real. The invasion has to be serious, the person must have had a reasonable expectation of privacy, and their privacy interest has to outweigh any competing public interest. The conduct has to be intentional or reckless, so carelessness on its own is not enough. Consent and lawful authority are defences.
Two features make it bite. The claim is actionable without proof of damage, so the caller does not have to show they lost anything. And damages can be awarded for emotional distress, with non-economic loss and any punitive damages capped at the greater of $478,550 and the defamation cap. Privacy and Other Legislation Amendment Act 2024, Sch 2 ↗
It applies to any person or organisation. The small-business exemption in the Privacy Act does not carry across. If your answer has been "we turn over under three million so the Privacy Act does not apply to us", that answer stopped working in June 2025.
05 · Sending information overseas
You stay responsible after the data leaves the country.
Nearly every AI product sends something overseas. Most Australian businesses using one have never asked where.
Australian Privacy Principle 8 says that before you disclose personal information to an overseas recipient, you have to take steps that are reasonable in the circumstances to make sure that recipient does not breach the principles. In practice that means a contract that specifies how the information is handled, how it is secured, what it may be used for, and what happens when there is a breach. oaic.gov.au ↗
Then there is section 16C, which is the part people miss. If the overseas recipient does something with the information that would have breached the principles here, that is treated as your breach. It stays your breach even if you took reasonable steps. You cannot contract it away. You can only make the surface smaller by sending less, or by keeping the processing in Australia.
There are two escapes and neither is easy. The first applies where the recipient is bound by a law or scheme that protects the information in a way substantially similar to the principles, with enforcement the person can reach. The United States has no general law of that kind, so ordinary American software does not qualify. The second is express, informed consent after telling the person that the principle will not apply. Bundled or implied consent does not count, which makes it impractical at any volume.
Separately, when you collect the information you have to tell people whether it is likely to go overseas and to which countries. On a phone call, the regulator's guidance is to explain that at the start of the call. oaic.gov.au ↗
06 · Buying AI off the shelf
Keep customer information out of public chatbots.
The Office of the Australian Information Commissioner published guidance on privacy and commercially available AI products on 21 October 2024, and last updated it on 17 January 2025. It is the clearest statement of what a regulator expects, and it is short enough to read in a sitting. oaic.gov.au ↗
The headline recommendation appears twice in the document. As a matter of best practice, organisations should not enter personal information, and particularly sensitive information, into publicly available generative AI tools, because of the significant and complex privacy risks involved.
Four other points from it are worth knowing before you sign anything. Information an AI generates or infers about a person is a collection of personal information, so it has to be reasonably necessary for what you do. Your records should show where a piece of information came out of an AI and is therefore a probabilistic assessment rather than a fact. When you pick a cloud-hosted product you have to consider where its servers are and whether information could be disclosed outside Australia. And a public AI tool such as a chatbot has to be clearly identified as one to the people using it.
One line in the guidance catches a lot of people out. Consent cannot be inferred merely because you gave someone notice. A recorded announcement is a notice. It is not, by itself, consent.
07 · Recording phone calls
Eight jurisdictions, and they do not agree.
If your AI answers or makes phone calls, this is the section that will cost you money. Almost nobody publishes it correctly, including several products sold into Australia for exactly this purpose.
Start with the federal question, because it is the easy one. Under the Telecommunications (Interception and Access) Act 1979, interception means recording a communication in its passage over the network without the knowledge of the person making it. The test is knowledge, not consent. A clear announcement at the start of the call gives the caller knowledge, so recording your own call is not interception. TIA Act 1979, s 6 ↗
Then there is state law, and there are two separate questions in every state. May you record a conversation you are part of? And may you pass the recording on to somebody who was not on the call? The second question is usually the binding one, because sending the recording, the transcript and the summary to the business is the whole point of an AI receptionist.
Transcripts and AI-written summaries are caught. New South Wales, Queensland, Western Australia and Tasmania all define a record to include a statement or document prepared from the recording. Deleting the audio and keeping the summary does not solve anything.
| Where | Recording a call you are on | Passing the recording on | The Act |
|---|---|---|---|
| New South Wales | An offence for a party to record, unless every principal party consents, or the recording protects your lawful interests, or it is not made for passing on | Restricted only where the recording itself was unlawful | SDA 2007 (NSW) ↗ |
| Victoria | Allowed. The offence only covers recording a conversation you are not part of | Needs the consent of each party, or public interest, or your lawful interests | SDA 1999 (Vic) ↗ |
| Queensland | Allowed for a party to the conversation | Needs the consent of all other parties, or duty, public interest, or lawful interests | IPA 1971 (Qld) ↗ |
| Western Australia | An offence for a party to record, unless every principal party consents or the recording protects your lawful interests. There is no not-for-passing-on exception | Needs the consent of each principal party, or duty, or lawful interests | SDA 1998 (WA) ↗ |
| South Australia | An offence for a party to record, unless all principal parties consent or the recording protects your lawful interests | Restricted where you relied on the lawful-interests limb to record | SDA 2016 (SA) ↗ |
| Tasmania | An offence for a party to record, unless all principal parties consent, or lawful interests, or it is not made for passing on | Restricted even when the recording was lawful | LDA 1991 (Tas) ↗ |
| Northern Territory | Allowed. The offence only covers recording a conversation you are not part of | Needs the consent of each party, or public interest, or lawful interests | SDA 2007 (NT) ↗ |
| Australian Capital Territory | An offence for a party to record, unless each principal party consents, or lawful interests, or it is not made for passing on | Restricted even when the recording was lawful | LDA 1992 (ACT) ↗ |
Western Australia is the strictest. It has no exception for a recording made privately and never passed on, so consent is the only realistic path. Tasmania and the Australian Capital Territory restrict passing a recording on even when the recording itself was perfectly lawful. South Australia has a quirk that runs the other way: its restriction on using the material only engages if you relied on the lawful-interests limb to record, so recording on consent is strictly cleaner there.
One design is lawful in all eight. Get the express or implied consent of every principal party at the start of the call, before recording begins, and make that consent cover both the recording and the passing on of the recording, transcript and summary. Nothing else clears Western Australia, Tasmania and the ACT at the same time.
Which means the greeting has to do real work. Who the business is. That the assistant is an AI and not a person. That the call is recorded and transcribed, and why. That the recording, transcript and summary go to the business and to a provider that may process them overseas. A genuine way to say no and still get help. And a way to reach a human. The greeting has to play before the recorder starts, and the no-recording branch has to actually exist, or the disclosure is theatre and recording it was the offence.
08 · What this means for you
Four things worth doing this quarter.
List every place software decides something about a person.
Not only the AI. Quoting rules, credit checks, applicant screening, eligibility calculators, anything that scores or sorts people. Write down what information goes in, what comes out, and whether a human genuinely makes the call or just approves what the screen suggests. That list is what the December 2026 privacy policy change asks you to describe, and it takes about a day.
Find out which countries your vendor processes in, and write it down.
Ask for the list of subprocessors and the country each one is in. Ask whether your data trains their models. Ask what the retention period is for recordings, transcripts and logs. If the answer takes more than a week, that is information too. You need the country list anyway, because you have to tell people where their information goes.
If you record calls, rewrite the greeting and test the opt-out.
Consent at the start, covering the recording and everything you do with it afterwards. A branch that takes a message without recording, which somebody has actually rung and tested. And a log, per call, of which version of the disclosure played and what the caller did. That log is the evidence you will want if a caller complains.
Keep personal information out of public AI tools.
The cheapest control on this page, and the one the regulator has stated plainly. Tell your staff. Then give them a tool with a contract behind it so they have somewhere to go instead.
09 · Honesty
What we could not confirm.
We are not lawyers and this page is not legal advice. It is a reading of published sources, dated, with the sources attached so you can check us or hand the links to your solicitor.
- Penalty amounts under the Privacy Act. Secondary sources disagree on the infringement notice figures, and the Commonwealth penalty unit is indexed, so dollar conversions age badly. We have stated none. The amending Act is here if you need them. Act No. 128 of 2024 ↗
- Two publication dates for the same guidance. The Guidance for AI Adoption appears on industry.gov.au dated 5 May 2026 and has also been reported with an October 2025 date. We have used the industry.gov.au date. The six practices are the same in both.
- Currency of some state Acts. The New South Wales and South Australian text was read from archived captures, because both official registers block automated access. The South Australian version we read is the consolidation that ran to 20 September 2023, and a later one exists. The Queensland consolidation is current as at 1 July 2024, the Western Australian one as at 5 April 2023, and the ACT republication dates from February 2022. We did not check for amendments in progress.
- Whether the mandatory guardrails were formally abandoned. The 2024 proposals paper exists and no mandatory guardrails have been made. We could not retrieve a primary government statement withdrawing them, so we have described what happened rather than quoting a decision.
- The age of the regulator's AI guidance. The OAIC guidance was last updated in January 2025. It predates both the statutory tort commencing and the December 2026 privacy policy change, so read it alongside them rather than on its own.
- Limitation periods for the statutory tort. Secondary sources describe a three-year period from the invasion, or one year from awareness. We did not verify that against the Act, so we have left it out of the body of this page.
If you find something here that is wrong or out of date, tell us and we will fix it and note the change.
Last checked 8 August 2026. All field notes
Tell us what's slow.
Describe the part of your week that takes too long. You will get a reply from a person, usually the same day.
Or email hello@westringia.com directly.