Out-Law / Your Daily Need-To-Know

OUT-LAW NEWS

Australian regulator flag human oversight may not avoid new ADM transparency duties

iStock-1091348950_Digital - SEOSocialEditorial image

Credit: iStock


Australian organisations and businesses should be aware that any decision made using automated decision making (ADM) technology, even if a human ultimately approves it, may be captured under new obligations which commence later this year, according to experts at Pinsent Masons.

The Office of the Australian Information Commissioner (OAIC), Australia's privacy and information regulator, released its final resources on the new ADM transparency obligations on 30 September. These obligations commence on 10 December 2026 and require updates to privacy policies to include in scope ADM and the personal information used.

The resources include a fact sheet, supplementary guidance for Commonwealth government agencies, a flowchart and updates that have already been made to the APP 1 section of the OAIC’s Australian privacy principles (APP) guidelines. The resources reflect feedback received during the OAIC's consultation process earlier this year, outlining the obligations organisations and businesses will face once the requirements come into effect and providing examples of the types of technology and decisions in scope and illustrations of disclosures.

Veronica Scott, an expert in data, privacy and cyber law at Pinsent Masons, said: "The OAIC's final guidance confirms that organisations should not be taking too narrow a view of what constitutes automated decision-making that must be disclosed. The primary disclosure obligation will generally remain with the organisation using personal information to make or inform the relevant decision.”

"The most significant message from the guidance is that human involvement does not automatically remove a decision-making process from the scope of the disclosure regime," she said.

"Many organisations assume there is no transparency obligation where a staff member makes the final decision. However, the OAIC's guidance suggests the more important question is whether a computer program remains a key factor in producing or influencing the outcome."

The guidance confirms that the obligation extends beyond 'high-risk AI' and can apply to a broad range of computer programs and software. Importantly, the OAIC clarified one of the most significant issues raised during the consultation process: a 'human in the loop' does not necessarily mean a process falls outside the transparency obligation.

According to the OAIC fact sheet, a computer program may be 'substantially and directly related' to a decision where it advises an outcome, determines an outcome or otherwise influences an outcome, even if a human ultimately reviews or approves the decision. The guidance also indicates that systems may remain within scope even if their outputs are advisory rather than determinative.

Simon McDonald, an expert in technology law at Pinsent Masons, said: "If a system recommends candidates for interview, generates risk scores, prioritises customers, personalises pricing, assesses eligibility or otherwise materially influences a person's outcome, disclosure obligations may still arise even where a human ultimately approves the decision.”

"This means organisations need to look beyond standalone artificial intelligence systems and examine the broader reality of how software and automation are embedded in operational decision-making," he said.

"For many businesses, the challenge is unlikely to be identifying a single tool or automated process. Rather, it will be understanding how numerous automated and semi-automated processes interact across the organisation and whether those processes require disclosure under APP 1.

“As commencement approaches, following a two-year transition period, organisations should be prioritising completing their AI and ADM mapping exercises, and assessing whether they significantly affect individuals' rights or interests, identifying what personal information is involved and updating privacy policies where required. Commercially sensitive or confidential information will not need to be disclosed”.

Once this exercise is completed, if in doubt, the ADM should be disclosed in the updates to privacy policies, which should be carefully drafted in a way that ensures sufficient transparency and technical information without overwhelming individuals, so they can understand how their personal information is used in these types of decisions and exercise their rights, according to Scott.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.