How the Privacy Act 2026 Changes the Way Aussie SMEs Use AI (And What to Do About It)
Back to Latest News
AI & PrivacyPrivacy ActAI ComplianceAustralian BusinessAutomated Decision-MakingData PrivacySMEOAIC

How the Privacy Act 2026 Changes the Way Aussie SMEs Use AI (And What to Do About It)

AI can save your team hours — but it often works with information about real people. Here is what is actually changing under Australia’s privacy reforms from 10 December 2026, and a practical 6-step checklist to help your SME use AI confidently and responsibly.

Evolve with AI11 August 2026
How the Privacy Act 2026 Changes the Way Aussie SMEs Use AI (And What to Do About It)

AI can save your team hours.

It can summarise documents, respond to customer enquiries, analyse business data and automate repetitive admin.

But there is a catch.

AI often works with information about real people.

That might include customer names, email addresses, employment details, health information, financial records, customer preferences or even AI-generated assumptions about an individual.

If you are feeling unsure about what your business can safely put into AI tools, you are not alone. The rules are developing quickly, and the language around AI compliance can become unnecessarily complicated.

Let’s keep it practical.

First, there is no separate piece of legislation officially called the “Privacy Act 2026”. The relevant law remains the Privacy Act 1988, including reforms made by the Privacy and Other Legislation Amendment Act 2024.

One important reform begins on 10 December 2026.

It creates a specific transparency obligation for certain automated decision-making (ADM) systems.

That does not mean AI is prohibited.

It does mean that covered businesses need to understand how AI uses personal information and be able to explain it clearly.

This article is general information only and is not legal advice. Speak with a qualified privacy professional about your circumstances.


1. What is actually changing in 2026?

From 10 December 2026, an APP entity using personal information in automated decision-making may need to update its privacy policy.

The obligation applies when:

  1. A computer program makes a decision, or performs something substantially and directly related to making a decision.
  2. The decision could reasonably be expected to significantly affect an individual’s rights or interests.
  3. Personal information about that individual is used in the operation of the program.

The privacy policy will need to explain:

  • The kinds of personal information used by the automated system.
  • The kinds of decisions made solely by the system.
  • The kinds of decisions where the system performs something substantially and directly related to making the decision.

For example, an AI system might automatically:

  • Screen job applicants.
  • Determine eligibility for a service.
  • Assess a credit or insurance application.
  • Set a price or access level.
  • Decide whether a customer receives a particular benefit.
  • Make recommendations that materially influence a significant decision.

A human clicking “approve” at the end does not automatically remove the system from consideration. If the AI does the substantial work behind the decision, it may still be relevant.

The focus is not on whether you use a tool with an “AI” label. It is on what the system does, what personal information it uses and how much the outcome affects people.

The reforms also reinforce the need for good privacy governance, security, transparency and accountability.

That is why waiting until December 2026 is not a great strategy.


2. Does the Privacy Act apply to your SME?

Not every small business is automatically covered by the Privacy Act.

Generally, a small business with annual turnover of $3 million or less may be exempt. However, there are important exceptions.

Your business may already be covered if it:

  • Has annual turnover above the relevant threshold.
  • Provides a health service or handles health information in the course of providing that service.
  • Trades in personal information.
  • Provides services under a Commonwealth contract.
  • Operates in credit reporting or certain financial services contexts.
  • Operates a residential tenancy database.
  • Is an entity covered by the anti-money laundering and counter-terrorism financing framework.
  • Is related to a larger entity covered by the Privacy Act.
  • Has voluntarily opted in.
  • Falls within another specific exception or regulated sector.

So, “we’re only a small business” is not a complete privacy assessment.

At the same time, it is also incorrect to assume every Australian SME is automatically subject to every Privacy Act obligation today.

The OAIC’s small business guidance is a useful starting point. You should also speak with a qualified privacy professional if your position is unclear.

Even if the Act does not currently cover your business, strong privacy practices are still commercially sensible.

Customers, employees and business partners increasingly expect you to handle information responsibly.

Trust is an asset.


3. How AI use creates privacy risk

AI privacy risk is not limited to sophisticated machine-learning projects.

It can appear in ordinary day-to-day workflows.

Abstract glowing blue AI network of interconnected nodes representing AI privacy risk in everyday business workflows

Prompts and uploads

An employee pastes a customer complaint into a public chatbot.

Another uploads a spreadsheet containing names and purchase history.

Someone else asks an AI tool to summarise a medical report or rewrite a performance review.

The information may be personal information. Entering it into an external tool may also involve a disclosure, depending on how the system operates and who can access the data.

The OAIC recommends, as a matter of best practice, that organisations do not enter personal information — particularly sensitive information — into publicly available generative AI tools.

AI outputs and inferences

AI outputs are not automatically harmless because the tool generated them.

If an output identifies, describes or makes an inference about an individual, it may be personal information. This can include information that is inaccurate or completely fabricated if the person is reasonably identifiable.

For example, an AI system might incorrectly infer that a customer is financially risky, unlikely to pay or unsuitable for a service.

That output still needs careful handling.

Profiling and personalisation

Personalised marketing is not automatically high risk.

However, the risk increases when profiling affects:

  • Eligibility.
  • Pricing.
  • Access to services.
  • Employment opportunities.
  • Credit or insurance outcomes.
  • Customer support or escalation pathways.

Ask a simple question:

Could this AI-generated profile materially change what an individual can access or receive?

Automated decisions

A system that drafts a customer email is very different from a system that decides whether a customer receives a loan, benefit, tenancy or job interview.

The second category requires much stronger controls around accuracy, fairness, explainability and human oversight.

Third-party tools

Before approving an AI product, check:

  • What happens to prompts and uploaded files?
  • Is information used to train or improve the provider’s models?
  • Who can access the data?
  • How long is it retained?
  • Can you delete it?
  • Is the provider acting as a service provider or using the information for its own purposes?
  • Can you disable data-sharing features?

“Popular” does not automatically mean “appropriate for your business”.

Overseas disclosures

Many AI products use cloud infrastructure or service providers located outside Australia.

If personal information is disclosed overseas, you may need to consider your obligations under APP 8, as well as the vendor’s contractual and security arrangements.

Data location is not the only issue.

You also need to understand who controls the information and what legal protections apply.


4. Your practical 6-step AI privacy checklist

Six-step AI privacy journey infographic — map and manage AI use, classify risk, update policies, review vendors, set access and human-review controls, then test and train

Step 1: Map your AI use cases and personal information

Create a simple register of every AI tool used in your business.

Include informal use by staff.

For each tool, record:

  • What the tool does.
  • Which team uses it.
  • What information goes in.
  • What information comes out.
  • Whether the tool affects customers, employees or applicants.
  • Whether information leaves your systems.

You cannot manage “shadow AI” that you cannot see.

Step 2: Classify the risk

Place each use case into a practical category:

  • Low risk: No personal information, or limited information used for internal productivity.
  • Moderate risk: Personal information is used, but a human reviews the output and the decision is not significant.
  • High risk: Sensitive information, profiling or decisions that could significantly affect a person’s rights or interests.

High-risk uses deserve a privacy impact assessment and a more formal approval process.

Step 3: Update your privacy policy and notices

If your business is an APP entity and the ADM obligation applies, your privacy policy should clearly describe:

  • The kinds of personal information used.
  • The kinds of decisions made solely by automated systems.
  • The kinds of decisions where AI substantially and directly assists the decision.

Your collection notices should also accurately explain relevant AI-related uses and disclosures.

Avoid vague language such as “we may use technology to improve our services”.

Use plain English.

People should be able to understand what is happening without needing a law degree.

Step 4: Review vendors and cross-border data handling

Ask each provider for clear answers about:

  • Data storage locations.
  • Retention periods.
  • Model training.
  • Sub-processors.
  • Security controls.
  • Deletion processes.
  • Access permissions.
  • Breach notification.
  • Overseas disclosures.

If the provider cannot explain how your information is handled, that is a decision-making problem — not a minor technical detail.

Step 5: Set access, retention and human-review controls

Use the minimum information necessary.

Restrict access by role.

Avoid giving an AI assistant access to your entire customer database when it only needs a small, specific dataset.

Set retention and deletion rules for prompts, recordings, transcripts and outputs.

For higher-risk uses, make sure a trained person can:

  • Review the relevant information.
  • Identify errors or bias.
  • Explain the outcome.
  • Correct the record.
  • Overturn the AI recommendation or decision.

Human review should be meaningful, not a rubber stamp.

Step 6: Test, document and train

Test AI systems before deployment and periodically afterwards.

Look for:

  • Incorrect outputs.
  • Biased results.
  • Unexpected personal information.
  • Inconsistent treatment.
  • Security weaknesses.
  • Poor responses to unusual requests.

Keep records of your testing, approvals, changes and incidents.

Then train your team on the practical rules:

  • What can be entered into AI tools.
  • What must never be uploaded.
  • Which tools are approved.
  • When human review is required.
  • How to report a problem.

A policy nobody understands is decoration.


5. Low-risk and higher-risk AI examples

Lower-risk examples Higher-risk examples
Drafting a generic blog outline Screening job applicants
Summarising an internal meeting with no sensitive content Ranking employees for promotion or dismissal
Rewriting a public-facing email Assessing creditworthiness
Brainstorming marketing ideas without customer data Determining access to a significant service
Analysing anonymised operational data Inferring health, financial or behavioural traits
Creating a first draft for human review Automatically rejecting a claim or application

The same tool can be low risk in one workflow and high risk in another.

The use case matters more than the brand name.


6. What to do this month

You do not need to solve every AI and privacy question in one afternoon.

Start with four actions:

  1. Create an AI register. List every tool currently used by your team.
  2. Pause unsafe inputs. Tell staff not to enter customer or sensitive information into public AI tools until approved.
  3. Identify significant decisions. Find any workflow involving eligibility, employment, pricing, credit, claims or access to services.
  4. Book a privacy and AI planning session. Review your highest-risk use cases, vendors and policy gaps.
Strategic AI Transformations for Australian Businesses — Strategy First, Software Second. Kick off your free AI audit with Evolve With AI

At Evolve With AI, we take a strategy-first approach.

That means we do not begin by throwing another shiny tool at your team.

We begin by understanding your goals, data flows, risks and operational bottlenecks. From there, we can build a practical 90-day roadmap covering AI readiness, approved tools, workflow automation, privacy considerations and measurable outcomes.

Our 12+ hands-on AI workshops can also help your team build safer day-to-day habits with prompting, productivity tools, automation, data analysis and practical AI workflows.

12 Hands-On AI Workshops — practical training for corporate growth and future readiness, Australian Business Series by Evolve With AI

The goal is not to stop using AI.

The goal is to use it confidently, responsibly and for work that genuinely moves your business forward.

If you would like a clear starting point, explore our AI readiness assessment, review our AI strategy and roadmap service, or book a discovery conversation.

No pressure.

Just an honest look at where you are, what needs attention and what your next sensible step could be.


Sources

  • OAIC: Consultation on Guidance for Transparency in Automated Decision Making
  • OAIC: Automated Decision-Making Issues Paper
  • OAIC: Guidance on privacy and the use of commercially available AI products
  • OAIC: Small business and the Privacy Act
  • Privacy and Other Legislation Amendment Act 2024
  • Attorney-General’s Department: Privacy

This article is general information only and is not legal advice. Speak with a qualified privacy professional about your circumstances.

Ready to Start Your AI Transformation?

Book a free discovery call and let's explore how AI can transform your business.