🚀 Ready to strengthen your startup’s legal foundations? Register for our free webinar here 👉 REGISTER

AI Disclosure Requirements Australia: Do Businesses Have to Disclose AI Use?

AI Disclosure Requirements Australia: Do Businesses Have to Disclose AI Use?

If you run a startup that uses artificial intelligence, you have probably heard that Australian businesses will soon be forced to disclose every use of AI. It is a common belief, and it makes founders nervous. 

The good news is that it is not quite right. 

At Allied Legal, we work with technology founders who are building AI into their products every day, and this question comes up constantly. So let us clear up what Australia’s AI disclosure requirements actually are, what changes on 10 December 2026, and whether any of it applies to you. 

Do Businesses Have to Disclose AI Use? 

There is no general law in Australia that requires a business to announce it uses AI. You do not need a label on your website saying “this service is powered by artificial intelligence.” 

Australia has deliberately taken this path. The Government has confirmed it will not proceed at this time with the previously proposed mandatory guardrails for high-risk AI. The National AI Plan sets out the approach it took instead, building on Australia’s existing, largely technology-neutral laws, with targeted reform where gaps appear.  

That does not mean there is nothing to do. Two real obligations shape the AI disclosure requirements Australia presents. The first is a new privacy rule commencing on 10 December 2026. The second is the existing prohibition on misleading or deceptive conduct, which already applies to what you tell people about your AI. The rest of this article explains both. 

The New Privacy Rules: APP 1.7 to 1.9 

The main development is a change to the Privacy Act. Three new provisions, known as Australian Privacy Principles 1.7, 1.8 and 1.9, were introduced by the Privacy and Other Legislation Amendment Act 2024 and commence on 10 December 2026. 

When the Rules Apply 

In plain terms, the rules apply where your business has arranged for a computer program to make a decision about a person, or to do something that substantially and directly feeds into a human making that decision, the decision could significantly affect that person, and personal information is used in the process. 

“Computer program” is read broadly. The Explanatory Memorandum says the term takes its ordinary meaning and covers a broad range of things, including pre-programmed rule-based processes, artificial intelligence and machine learning. This is not only about cutting-edge AI.  

What Your Privacy Policy Must Say 

You do not have to list every decision line by line. The rules ask you to describe things in categories: the kinds of personal information the program uses, the kinds of decisions it makes on its own, and the kinds of decisions where it does most of the work but a human signs off. 

Three Details Founders Miss 

A few features of these rules catch people out. 

First, adding a human decision-maker does not automatically put you outside the rules. If the program’s output is a key factor in the human’s decision, the rule can still apply. Second, refusing or failing to make a decision still counts, so declining an application is covered. Third, the effect can be good or bad for the person, so a decision granting a benefit is treated the same as one denying it. 

Think loan approvals, insurance pricing, tenancy screening and shortlisting job applications. 

A Rule About Openness, Not a BanA Rule About Openness, Not a Ban 

None of this is as heavy as it first sounds. You can keep automating decisions, and the disclosure only has to appear in your privacy policy. There is no obligation to flag it in the moment, explain your reasoning, or give someone a human to appeal to.  

Can You Rely on the Small Business Exemption? 

Here is where many founders get caught out. 

The Privacy Act generally does not apply to businesses with an annual turnover of $3 million or less. Since most early-stage startups sit well under that figure, the natural assumption is that none of this matters yet, however, the exemption comes with exceptions that apply regardless of turnover.  

The main ones involve exchange: you lose the exemption if you hand over someone’s personal information and get something in return, or if you give something away in order to collect it. Providing a health service and holding health information also takes you outside the exemption.

Many startups are built around these categories, and if any of them describe your product, being under the turnover threshold may not protect you.  

The Duty Not to Mislead

The second piece of the puzzle already applies today. 

The general prohibition on misleading or deceptive conduct under the Australian Consumer Law covers what you tell people about your AI. Claims about how capable or accurate your AI is can mislead, and that is what the law targets.

A business may also be responsible for misleading things its own AI tells a customer, although this has not yet been tested in an Australian court. Importantly, this duty does not require bad intent, meaning you can breach it while acting honestly. 

The rule of thumb is simple. You do not have to announce your AI, but you must not let it mislead. 

The Fine Print Is Still Being Written

Parts of the new privacy rules are not fully settled. 

The Office of the Australian Information Commissioner released an issues paper in May 2026 and expects to publish guidance around September 2026. Until then, key terms remain open, including where the line sits for a decision “substantially and directly related” to a program’s output and when an effect is significant enough to trigger the rule. 

If your product sits in a grey area, that is a sign to get advice rather than guess. 

What Startups Should Do Now

You do not need to panic, but preparation beats scrambling near the deadline. 

Start with a simple stocktake. Work out whether your product uses personal information to make or support decisions about people, including third-party tools and AI features embedded in software you did not build. From there, plan to update your privacy policy so it describes those decisions in categories, keep your marketing claims about AI accurate, and watch for the regulator’s guidance later in 2026.

Frequently Asked Questions

1. Do businesses have to disclose their use of AI in Australia?
No. There is currently no general law requiring Australian businesses to publicly disclose every use of artificial intelligence. However, certain organisations may need to disclose automated decision-making practices in their privacy policies from 10 December 2026.

2. What are the new AI disclosure requirements coming into effect in 2026?
From 10 December 2026, some organisations covered by the Privacy Act must explain in their privacy policies how computer programs, including AI systems, are used to make or substantially assist decisions involving personal information that may significantly affect individuals.

3. Does the new law apply only to artificial intelligence?
No. The rules apply broadly to computer programs, which can include traditional rule-based systems, machine learning models, and AI tools. The requirements are not limited to advanced AI technologies.

4. Can a business be liable for misleading claims about AI?
Yes. Australian Consumer Law prohibits misleading or deceptive conduct. Businesses should ensure any claims about their AI’s capabilities, accuracy, or functionality are truthful and supported by evidence.

5. What should businesses do now to prepare?
Businesses should review how AI and automated systems are used, identify any processes involving personal information and significant decisions, assess whether the Privacy Act applies to them, and update their privacy policies before the new requirements commence.

Final Thoughts

The idea that every Australian business will soon have to disclose all AI use is a myth, but it points at something real. The genuine AI disclosure requirements in Australia are the new privacy rules starting on 10 December 2026 and the existing duty not to mislead.

At Allied Legal, we advise founders and technology businesses on privacy compliance, product regulation and the legal issues that come with building AI-enabled products. If you are unsure whether the new rules reach your business, getting advice early gives you time to prepare properly rather than react under pressure. 

This article is intended for general information only and does not constitute legal advice. Specific advice should be obtained before acting or relying on any information discussed above.

Rahul Kumar

Rahul Kumar

Rahul Kumar is the founder of Allied Legal and a seasoned corporate lawyer with over 19 years of experience advising on complex corporate law matters. A recognised specialist in the startup and scaleup space, Rahul has a deep understanding of the legal and commercial challenges faced by high-growth businesses.

Having worked at both national and international firms, his expertise spans corporate structuring, capital raising, shareholder arrangements, mergers and acquisitions, and strategic governance.