Skip to main content
    Issue #46•18 May 2026

    AI Decision Disclosure

    The audit costs $50k done in-house. The penalty costs $50m if you miss a serious breach.

    From 10 December 2026, Australian businesses using AI to make decisions about people must disclose those decisions in their privacy policy. Hiring filters, credit scoring, insurance pricing, claims triage, customer segmentation: APP 1.7 covers all of them. The OAIC is not waiting; they are already sweeping 60 organisations across 6 sectors before the commencement date arrives.

    If you are a Chair, CFO, CEO, or General Counsel in an Australian business between $100m and $1b, the next 207 days determine whether your board can answer the question your D&O insurer will ask at your October renewal.

    • Can you name every automated decision in your business?
    • Can you describe exactly what data flows into them?
    • Can you prove whether a human overrides the output when the team is under load?

    Across the 12 privacy readiness audits we triaged this quarter, the pattern is almost identical...

    1. Run the Inventory Pass Against the Three Non-Negotiable Rules

    The pattern across corporate boards this year holds - The General Counsel walks into the room carrying 5 to 7 automated decisions they can name confidently. Procurement looks at their logs and sees around 25 SaaS vendors with an AI angle in the contract stack.

    Yet, after 90 minutes with the workflow owners in the room, the people who press the buttons - the real count lands between 10 and 30. In one recent engagement, a client walked out of stage one with 30 mapped decisions where their original corporate count was just 7.

    Procurement knows what the business bought. The workflow owners know what the business runs. Audit your footprint against these three structural boundaries:

    • **The Boundary Rule:**The legal test is a "reasonable expectation of significant effect on rights or interests." A discount eligibility threshold counts. A queue position for human review counts. A loan product pre-selection counts.
    • **The Vendor Rule:**Whoever arranges the decision discloses it. SaaS vendors do not disclose for you. If your business runs an AI-anchored decision about a customer through someone else's tool, the disclosure obligation lands on your desk.
    • **The Workflow Rule:**Build the inventory with the workflow owners, not legal and procurement alone.

    2. Capture Four Data Points For Every Single Decision

    Capture these 4 data points for every decision on the register before the disclosure goes anywhere near your published privacy policy:

    • Model Named: Identify the specific tool, vendor, or in-house system running the decision. If it is a black-box vendor model, acknowledge that in the disclosure and flag the contract for renewal scrutiny.
    • Inputs Listed: Map the personal information flowing into the decision: demographics, transaction history, document content, behavioural signals, location, and any inference layers that derive new data from the original inputs.
    • **Override Described:**Detail the human override honestly. Does it survive a busy week? If a human will not realistically overturn the AI under load, the chain is "intact" and the decision is substantially automated.
    • Outcome Stated: Define what the customer actually gets- approval, rejection, price tier, service level, queue position, or visibility.

    **What this looks like in practice:**Your public privacy policy says: "We use AI to help screen job applications."

    Your internal register names Workday Recruiting as the tool, lists the data inputs (CV text + role description), notes the rejection threshold at 0.65 confidence, and names the specific recruiter who reviews every flagged application.

    The policy is what your customers see, the register is the audit trail the regulator demands.

    Two documents come out of this work: the public privacy policy section published in December, and the audited register that lives behind it, that is reviewed every quarter.


    3. Stress-Test the Register Against the Four Board Traps

    Every board audited this quarter has fallen into at least one of these four operational traps. Verify your footprint passes all four checkpoints before the disclosure ships:

    • **Trap 1:**The "Vendor Handles Disclosure" Assumption: They don't. The arranger discloses, and the arranger is your business. Procurement contracts can shift commercial liability to the vendor, but they cannot alter the regulator's view of statutory accountability.
    • Trap 2: The "Human in the Loop Breaks the Chain" Myth: It only breaks the chain if the human reverses the AI's recommendations under load. If a manager rubber-stamps outputs during a busy week to clear a queue, the AI is anchoring the decision and the chain is intact.
    • **Trap 3:**The "Proprietary Tooling Provides Cover" Illusion: Custom code simply makes the disclosure harder to write because the inputs and weights are opaque. The decision still happens, the customer is still affected, and the obligation still applies.
    • Trap 4: The "General Counsel Has Already Mapped Them" . The first count usually misses two-thirds of the actual decisions. Legal knows the policy, Procurement knows the contracts, but only the workflow owners know where the model actually sits. Run the audit with them present or your count is wrong.


    4. Enforce The Filter on Every Next Board Pack

    The audit is the work the next board pack must fund. Moving forward, every single AI initiative must pass these 4 questions before it receives a single dollar of corporate capital:

    1. Revenue, Cost, Time, or Risk: Which specific corporate lever does this initiative move, and by how much? If the answer is none of the four - kill it.
    2. The Governance: Does the business case explicitly budget for build cost, audit cost, vendor map cost, disclosure cost, and resilience trigger costs on a single visible line?
    3. **The Accountable Director:**Is there a single, named director individually accountable? APRA put this in writing on 30 April 2026; every Australian board will be measured against it via D&O renewals and AGM scrutiny inside 12 months.
    4. The Kill List: Is there a specific, measurable, owned, and calendar-dated point at which the board agrees to stop spending if the initiative isn't tracking?

    5. Execute the General Counsel Prompt Today

    The cheapest version of stage one is a single prompt your General Counsel can execute against your AI tool inventory. Copy, paste below:

    PULL EVERY SAAS TOOL, IN-HOUSE MODEL, OR THIRD-PARTY INTEGRATION IN OUR BUSINESS THAT USES PERSONAL INFORMATION TO MAKE OR SUBSTANTIALLY ANCHOR A DECISION AFFECTING AN INDIVIDUAL. THE THRESHOLD IS A "REASONABLE EXPECTATION OF SIGNIFICANT EFFECT ON THE PERSON'S RIGHTS OR INTERESTS." INCLUDE HIRING FILTERS, CREDIT SCORING, INSURANCE PRICING, CLAIMS TRIAGE, CUSTOMER SEGMENTATION, BENEFITS ELIGIBILITY, FRAUD DETECTION, AND ANY INFERENCE LAYER THAT DERIVES NEW DATA. FOR EACH SYSTEM ON THE LIST, NOTE: 
    1. MODEL NAMED 
    2. DATA INPUTS 
    3. HUMAN OVERRIDE (EXISTS / EFFECTIVE / NEITHER) 
    4. CUSTOMER-FACING OUTCOME. 
    
    FLAG ANY SYSTEM WHERE THE HUMAN OVERRIDE LOOKS LIKE A RUBBER STAMP RATHER THAN A GENUINE REVERSAL. RETURN THE LIST IN TWO COLUMNS: THINGS WE CAN DISCLOSE IN PLAIN ENGLISH TODAY, AND THINGS THAT NEED WORKFLOW OWNER INPUT BEFORE DECEMBER.
    

    **Action Item:**Hand this to your General Counsel this week. If the count comes back at 5 to 7, you are still in step 1. Run it again with the workflow owners in the room. The actual count is what you take to the board, and it is what your insurer will read at your October renewal.


    6. What Lands on Your Desk This Week: The Executive Action Checklist

    Immediate Operational Setup:

    • The AI Prompt Check: Paste this entire newsletter into Claude or ChatGPT and ask it to map your company's known automated decisions against the four data points.
    • **The Risk Pre-Read:**Screenshot the Four Traps checklist and bring it to your next risk committee meeting.

    Role-Specific Directives:

    • If you're a Chair: Request the finalised stage-one inventory from your General Counsel and CEO by 30 June. Set the formal cadence for the quarterly review now, rather than waiting for October.
    • If you're a CFO: Build the dedicated audit cost line directly into the next AI capital paper. Explicitly tie this spend to a 90-day baseline and a stage-gate you co-own.
    • If you're a General Counsel: Forward the GC prompt from Section 5 to your legal team today with instructions to return the two-column list by Friday. Block out 90 minutes the following week with your workflow owners to validate the real numbers.
    • If you're a CEO: Assign a specific member as the named AI literacy lead and brief the rest of the board to the same operational level. APRA's benchmark enters your D&O renewal conversations regardless of readiness....

    **Before Friday:**Can we name every automated decision in our business today, and can we prove our human override?

    Until next time,

    Ramon.


    If your AI investment is not hitting the P&L

    I'm now taking executive briefings with Australian Boards and executive teams between $100 million and $1 billion in revenue. We surface where AI matters in your business, what risks need control, and what the right next step looks like before any budget is committed.

    What we'll cover

    • Where AI is already affecting growth, margins, time and risk in your business (including governance on APP 1.7.
    • Which business problems are worth investigating
    • The right next step. Audit, workshop, roadmap, or pilot

    Book here.


    About Applied AI Australia

    I am an executive who advises, not a career consultant.

    After carrying a nine-figure P&L at News Corp, I built Applied AI Australia because I kept seeing smart executives sold vague AI strategies that never changed the bottom line.

    CEOs and CFOs do not need more AI "hype". They need to know which decisions AI should change, what risk it creates, and how to get value without creating chaos.

    Staying up to date with AI is hard, so we publish a regular podcast and weekly newsletter to give busy executives the judgment they need in less than an hour a week.

    Listen on Spotify or Apple Podcasts.


    **Disclaimer:**Nothing in this newsletter is legal, financial, or professional advice. It is research, pattern‑recognition, and practical operating observations for Australian boards and executives. Before acting on any of it, speak with your own adviser, or get in touch if you want to discuss an engagement.


    Sources

    • APP 1.7 and automated decision transparency: OAIC, Australian Privacy Principles guidelines; TerraLex, "Australian Privacy Law Update: Automated Decisions 2026", https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines and https://www.terralex.org/news/australian-privacy-law-update-what-app-entities-need-to-know-in-2026.
    • Penalty caps: Herbert Smith Freehills, "Australia passes bill to fine companies up to $50 million for data breaches" and similar commentary on the 2022 Privacy Act amendments.
    • OAIC 2026 privacy compliance sweep: OAIC, "Privacy compliance sweep to put privacy policies under the spotlight" and related firm summaries (e.g., Russell Kennedy, MinterEllison) on the 2026 sweep.
    • Australian Clinical Labs $5.8m penalty: DLA Piper, "Australian Clinical Labs ordered to pay AUD 5.8 million following cyber incident" and associated case‑commentary pieces.
    • APRA AI governance expectations: APRA, "APRA calls for a step‑change in AI‑related risk management and governance" and "APRA letter to industry on artificial intelligence (AI)", with commentary from MinterEllison and others.

    Briefing Appendix: Australian Governance Context

    • **Enforcement Signal:**The OAIC is currently sweeping 60 organisations across 6 sectors ahead of the December deadline. D&O insurers are actively using these enforcement signals to price October renewals.
    • **Accountability Benchmarks:**APRA's 30 April 2026 benchmark mandates individual director accountability. Simultaneously, the Federal Budget's "human decides, AI prepares" framework establishes the baseline compliance operating standard.
    • Precedent Risk: The Federal Court confirmed a $5.8 million penalty against Australian Clinical Labs in October 2025 for data governance failures. APP 1.7 institutionalises this exposure on 10 December 2026.

    The OAIC, VAISS, and the AICD Directors' Guide all place AI governance as a board-level responsibility.

    Ready to deploy AI with confidence?

    Get board-ready frameworks and strategic guidance for Australian executives navigating AI transformation.

    Discuss your AI problem

    The Executive Brief

    Practical AI strategy for Australian executives. No fluff. No jargon. Just what matters.

    We send one brief per week. Unsubscribe any time.