We Can Name the Vendors. We Can't Name the Decisions.
233 days to APP 1.7. OAIC's already sweeping. Your vendor list isn't the map.
Last month I sat with a client board reviewing their AI governance. Twenty-seven SaaS products on the risk register. Every contract filed, every renewal tracked.
Halfway through, the General Counsel beat me to my own question.
"Ramon, which of the twenty-seven products are making decisions about our customers?"
The room went quiet. Including the GC. I was going to ask for their audit trail. They were asking me for the map.
Going in, her team thought they had five to seven automated decisions in scope. We walked out with thirty. I'd seen this gap before on two other portfolios. I hadn't seen it this wide.
From 10 December 2026, the silence can cost up to $50 million per serious breach.
Boards know the vendors. They can't name the decisions - APP 1.7.
Visibility before disclosure.
Australian enterprises have vendor lists, they don't have decision maps. "Workday" and "what Workday decides" aren't the same thing. One's a logo on a procurement list, the other's a set of customer outcomes the law will hold you accountable for.

What's inside:
- What Part 15 actually requires, and why your vendor contract won't protect you
- The three myths Australian boards are still betting on
- The 90-day decision-path audit (and the lineage problem nobody's talking about)
- Five deliverables, from the 48-hour GC test to the board paper generator
1. What Part 15 requires
The Privacy and Other Legislation Amendment Act 2024 inserted three new subclauses into Australian Privacy Principle 1: APP 1.7, 1.8, and 1.9. All three commence 10 December 2026. The statute's on legislation.gov.au at C2024A00128, Schedule 1, Part 15. OAIC has confirmed the obligations apply to every decision made from that date, regardless of when the system was bought or when the data was originally collected. Legacy systems are in scope.
The statutory trigger, in its own words. APP 1.7 applies where an entity has "arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision" and that decision "could reasonably be expected to significantly affect the rights or interests of an individual," and personal information is used in the program's operation.
Executive translation: If the program's output anchors the outcome, and personal information goes in, you're disclosing. Hiring filters. Credit scoring. Claims triage. Customer segmentation that changes what someone's offered or paid.
Two things about the trigger matter, that you likely missed:
First, "computer program" is deliberately broad. The Explanatory Memorandum is clear the test is technology-neutral. It's about whether a computer program is making or substantially driving a decision using personal information, not whether the vendor calls it "AI." A FICO scoring engine, a SAP configuration rule, a Workday resume-screener, and a GPT-5 copilot are all illustrations of the same principle.
Touch personal information, influence a material decision, you're in scope. There's no "it's just automation, not AI" exemption.
Second, "substantially and directly" catches human-in-the-loop. The EM and OAIC guidance explain this as covering cases where the automated element is a key factor in facilitating the human decision. If the human wouldn't reasonably have reached the same decision without the model's score or recommendation in front of them, treat it as captured. The rubber stamp will not get you out of the disclosure.
The numbers that matter to your board look like this. Three tiers, broadly.
- Serious interference (s 13G): up to the greater of $50 million, three times the benefit, or 30% of adjusted turnover. Less serious interference
- (s 13H) caps at 2,000 penalty units, approximately $3.3 million for bodies corporate at current penalty-unit values. Administrative contraventions
- (s 13K) support infringement notices the Commissioner can issue without going to court: roughly $19,800 per contravention for bodies corporate, and $66,000 for listed corporations.
The Act doesn't hard-code a tier per APP. In practice, an isolated APP 1.7 disclosure failure is likely to land in the lower-tier administrative bracket. But a disclosure failure that forms part of a serious or systemic interference can still attract s 13G.
The OAIC has proved it'll use these powers. The first-ever civil penalty under the Privacy Act came down on 8 October 2025: Australian Clinical Labs, $5.8 million plus $400,000 in OAIC's costs, for a 2022 breach affecting over 223,000 individuals. That case was calculated under the previous maximum of $2.2 million per contravention. The current s 13G cap is $50 million.
You arranged it. You disclose it. The vendor doesn't carry this for you.
2. The three myths Australian boards are still betting on
Same three assumptions come up every time. Each one's wrong in a different way.
Myth 1: "Our vendor handles disclosure."
I spoke with an exec at an Australian energy company last month. They'd just publicly announced $15 million to become an "AI-first" organisation. They had no idea APP 1.7 was coming. Their whole roadmap was built around vendor platforms they assumed would handle the compliance layer for them. They won't.
Two boards I'm sitting with this quarter are asking the same question. Only one can produce the map.
APP 1.7 fires on the entity that "arranged for" the program. The Explanatory Memorandum is explicit: the arranger remains responsible even when the program is operated by a different entity.
Again - You bought it. You deployed it. You disclose it. The vendor doesn't.
This matters because enterprise AI in Australia runs inside third-party products more than anywhere else. Salesforce Einstein ranks customer leads. Microsoft Copilot drafts hiring feedback. Workday filters resumes. FICO generates credit scores. Guidewire triages insurance claims. Each is a black box that influences a decision about a customer, and each is the arranger's disclosure problem, not the vendor's.

European courts have already signalled where this goes. Schufa (CJEU C-634/21, Dec 2023) indicated that where a downstream user relies heavily on a vendor's score, the scoring itself can amount to automated decision-making. Dun & Bradstreet (CJEU C-203/22, Feb 2025) indicated that trade-secret arguments don't extinguish the obligation to provide meaningful information about the logic. Persuasive analogies, not binding authority. The Federal Court won't ignore them when Part 15 cases start arriving in 2027.
The practical consequence: your vendor contracts almost certainly don't give you what you need. AI SaaS agreements in use today claim broad data-usage rights and offer little or no IP indemnification. They were written for a world where the customer was the buyer and the regulator was elsewhere. From 10 December 2026, the customer is the buyer, the regulator, and the liable party....
Myth 2: "We have a human in the loop."
This one sounds safer than it is, boards reach for "human-in-the-loop" because it feels like the AI's just advising, and the human carries the judgement. The law doesn't read it that way.
The EM and OAIC guidance explain the "substantially and directly" limb as covering cases where the automated element is a key factor in facilitating the human decision. If the AI's output is what the human's anchoring on, the decision is captured.
The wrong test is- "did a human sign?" Correct: would the human have reached the same conclusion without the score, the recommendation, or the ranked list in front of them? If the honest answer's no, you're disclosing.
When we ran the rubber-stamp test against my client's workflow, that's when it moved from seven decisions to thirty. Credit callbacks a human approves after the model flags them. Claims triaged by an AI and confirmed by an adjuster in under two minutes. Performance reviews drafted from system data and lightly edited before sign-off. Hiring shortlists the recruiter signs off on without re-scoring. Every one of those is a decision the AI made, with a human providing compliance cover that doesn't exist in the statute.
The GC asked me afterwards how we'd found thirty when her team had found seven. We started with customer outcomes, then worked back from there.
Myth 3: "It's proprietary, so we don't have to map it."
Makes it worse, not better. "Proprietary" isn't a shield once the decision affects a customer. The regulator doesn't care who built the logic. They care who deployed it.
The ACL case made this concrete. ACL argued it was reasonable to rely on a third-party security provider. The Federal Court noted that "overreliance" on third parties is itself a breach of APP 11.1.
The same reasoning will apply under APP 1.7. "Our vendor won't tell us how it works" isn't a defence. It's a procurement failure the deployer owns.
There's a narrow protection for commercial-in-confidence information, but it lives in the Explanatory Memorandum, not the statute. It's untested. No Australian court has ruled on how far it extends. The OAIC's enforcement posture, demonstrated in the ACL penalty and the January 2026 sweep of approximately 60 organisations under APP 1.4, is signalling it'll test these new powers in public.
3. The 90-day decision-path audit
We need to map every decision that affects a customer and connect it back to the systems that influenced it. Do not start listing every AI tool.
Four steps. Run this sequence or the map will have holes.
Step 1. Start with customer outcomes, not systems. List every decision your organisation makes about a customer, employee, or counterparty that could reasonably be expected to significantly affect their rights or interests. Hiring filter yes or no. Credit outcome. Loan amount. Premium price. Claim approved or denied. Product eligibility. Price shown. Offer made or withheld. Benefit granted or refused. Termination. Promotion. Performance rating. Every entity will have fifteen to fifty of these before you're done. Write them down first. Don't touch the tech yet.
Step 2. Trace each decision backward to the systems that influence it. Every outcome I've mapped so far has three to five touchpoints. A credit callback runs through a CRM trigger, a vendor scoring model, an internal rules engine, and a team leader's override. A hiring shortlist runs through an ATS filter, a recruiter screen, and an interview panel fed a scored ranking. Map every step. For each step, note whether the system uses personal information.
Step 3. For each system touchpoint, answer three questions. Does it use personal information (yes or no)? Is the automated output a key factor in the decision (yes or no)? Do you have contractual transparency and audit rights over the logic (yes or no)? You now have a matrix with three flags per row.
Step 4. The gaps are your remediation list. Any row where the first two flags are yes and the third is no is a disclosure exposure you'll have to close before 10 December 2026. Renegotiate the vendor contract, replace the vendor, or remove the system from that decision path.
One caveat the audit can't solve on its own - I have been advising clients on this for the last 12 months. Many AI systems, especially LLM-based ones, don't preserve their owndecision trail. Non-deterministic outputs. No constraint lineage. You're not only mapping what decisions happen. You're mapping what the system can even remember. Where the system doesn't preserve state, you're describing outputs after the fact, not logic. Flag those rows separately. The regulator will ask.
Plan for eight to sixteen weeks of elapsed time for a first-pass map in a $50M to $2B enterprise. Longer if you've got significant shadow AI or multiple SaaS layers. Start now. It's 20 April 2026. You've got 234 days.
Start with what affects customers. Work backward to systems. Flag what the system doesn't preserve. That's the only audit that survives a regulator.

4. Five deliverables
Copy-paste. Each one serves a different stakeholder. Escalating difficulty.
Deliverable 1. The 48-hour test (send today)
One email. To your General Counsel and your Board Chair, in the same thread.
☐ COPY AND PASTE THIS ENTIRE EMAIL
Subject: APP 1.7 readiness, one question, 48 hours
From 10 December 2026, Part 15 of the Privacy and Other Legislation
Amendment Act 2024 requires us to publicly disclose in our privacy
policy every automated or AI-assisted decision that could significantly
affect an individual.
I need one answer in 48 hours: can we produce, on one page, a list
of every customer, employee, or counterparty decision in this
business where an AI or automated system is a key factor in the
outcome? Not a vendor list. A decision list, with the systems
that influence each one and the contractual audit rights we hold
over each.
Deliverable 2. The vendor-to-decision mapping prompt (this week)
Turn your vendor list into a decision map. Paste it into Claude, ChatGPT Enterprise, or whichever tool your team has approved. Fill in the brackets. The output's a first-draft matrix your risk team refines, not a final artefact.
☐ COPY AND PASTE THIS ENTIRE PROMPT
I'm preparing for APP 1.7 compliance under the Privacy and Other
Legislation Amendment Act 2024, which commences 10 December 2026.
My organisation: [your industry, size in revenue, jurisdiction,
core customer-facing products]
Our current AI and automated systems inventory: [paste your vendor
and tool list, one per line]
Our current customer-affecting decisions: [list every decision
your organisation makes that could significantly affect an
individual's rights or interests: hiring, credit, pricing,
eligibility, claims, termination, promotion, service access]
Build me a mapping table with the following columns:
1. Customer decision
2. Systems that influence this decision (one row per system)
3. Does the system use personal information (yes/no)
4. Is the automated output a key factor in the decision (yes/no)
5. Does the system preserve a decision trail we could reproduce
(yes/no/partial)
6. What APP 1.7 disclosure language would apply to this decision
7. What contractual audit rights we should confirm with the vendor
Flag any row where columns 3 and 4 are 'yes' and we have no
vendor audit rights. Those are our priority remediation items.
Format as a table I can paste into a board paper.
Replaces roughly fifteen hours of manual mapping across legal, procurement, and risk for a first-pass matrix.
Deliverable 3. The rubber-stamp test (this month)
Run this across your top ten customer-affecting workflows. ☐ COPY AND PASTE THIS ENTIRE PROMPT
I need to test whether our "human-in-the-loop" decisions
pass the APP 1.7 "substantially and directly" test under the
Explanatory Memorandum to the Privacy and Other Legislation
Amendment Act 2024.
The EM and OAIC guidance explain "substantially and directly" as
covering cases where the automated element is a key factor in
facilitating the human decision-maker.
For each of the workflows I list below, answer four questions:
1. What is the automated output the human sees before deciding?
2. In what percentage of cases does the human override the
automated output?
3. How much time does the human spend on each decision on average?
4. Would the human reasonably have reached the same decision
without seeing the automated output?
If the answer to 4 is "no" or "probably not," that decision is
captured by APP 1.7 regardless of the human sign-off, and must
be disclosed.
Our workflows: [paste your top ten customer-affecting workflows,
one per line, with a one-sentence description of each]
Output a table ranking each workflow by APP 1.7 exposure: captured,
probably captured, genuinely human-led. For each "captured" or
"probably captured" row, draft one sentence of privacy-policy
disclosure language.
Every client I've run this with has found three to four times more captured decisions than they expected going in.
Deliverable 4. The AI use case register (reference asset)
The living artefact. Every organisation subject to Part 15 needs one, and the OAIC will want to see it if you're ever asked.
☐ COPY AND PASTE THIS ENTIRE PROMPT
Build me an AI use case register template for APP 1.7 compliance,
aligned with NIST AI Risk Management (Govern, Map, Measure, Manage)
and the NSW AI Assessment Framework risk tiers.
For each use case, capture:
- System name, vendor, rollout status
- Business purpose and decision type
- Whether fully automated, human-in-the-loop, or decision-support
- Whether the automated element is a "key factor" (APP 1.7 test)
- Categories of personal information used
- Cohorts affected (customers, employees, counterparties)
- APP 1.7 trigger status (yes/no/borderline)
- Decision-trail preservation (full/partial/none)
- Privacy Impact Assessment status
- Bias and accuracy testing status
- Contractual audit rights over the vendor
- Last review date
- Risk classification (NSW AIAF Level 1-4)
- Owner accountability (named person, not team)
Format as a schema I can build in a spreadsheet or GRC tool.
Pre-populate the first three rows with examples from [your
industry] so my team sees how to fill it in.
This becomes the single artefact your legal, risk, procurement, and IT teams all work from.
Deliverable 5. The board paper generator
☐ COPY AND PASTE THIS ENTIRE PROMPT
I need a one-page board paper on my organisation's APP 1.7 readiness.
Context:
- Part 15 of the Privacy and Other Legislation Amendment Act 2024
commences 10 December 2026
- APP 1.7 requires public disclosure of automated and AI-assisted
decisions affecting individuals' rights or interests
- Serious interference penalties under s 13G reach the greater of
$50 million, three times the benefit, or 30% of adjusted turnover
- The OAIC has already demonstrated willingness to seek Federal
Court penalties (Australian Clinical Labs, $5.8M plus costs,
October 2025)
- The OAIC ran its first privacy policy compliance sweep of
approximately 60 organisations in January 2026
My inputs:
- AI use case register: [paste your current register, or write
"we do not have one"]
- Current privacy policy automated decisions section: [paste it,
or write "our policy does not currently address automated
decisions"]
- Our last three customer-facing AI rollouts: [list them]
Build me a one-page board paper with these four sections:
1. Exposure view: How many customer-affecting decisions are
likely captured by APP 1.7, and what is our current disclosure
coverage? Be honest, not optimistic.
2. Top three gaps: The three highest-risk decisions where we
either do not have disclosure language drafted, do not have
vendor audit rights, or both. Name each decision, each system,
and the specific risk.
3. Remediation plan: For each gap, a 90-day action owner, a
budget estimate, and a dependency list.
4. Board decision: What the board is being asked to approve or
note, framed as "do nothing / accept risk / fund remediation
/ pause the rollout." Be specific about which option applies
to which gap.
Do not hedge. If you cannot answer a section honestly from the
inputs I gave you, say "insufficient information to assess" and
list what I would need to provide.
Australian governance position
Part 15 doesn't stand alone. OAIC, ASIC, ACCC, APRA, the DTA, and the Fair Work Commission are all pulling on the same thread: you can't deploy AI across the enterprise and pretend it's "just IT."
OAIC has already used its s 33C powers to review privacy policies at scale. The January 2026 sweep of approximately 60 organisations under APP 1.4 was the dress rehearsal. Privacy Commissioner Carly Kind has signalled AI and automated decision-making transparency as a 2025-26 focus. The same mechanism applies to APP 1.7 from December.
ASIC published Report 798 Beware the Gap: Governance arrangements in the face of AI innovation on 29 October 2024, reviewing 23 AFS and credit licensees. It concluded governance was lagging adoption. Technology-neutral obligations under the Corporations Act, directors' duties, and the ACL already apply. Financial services licensees don't get to wait for Part 15 to care about AI governance.
ACCC filed proceedings against Microsoft in October 2025 over Copilot subscription pricing disclosures. The first major AI-washing case in Australia.
APRA CPS 230 (Operational Risk Management) commenced 1 July 2025 for significant financial institutions. Its third-party and operational-risk obligations are already being used to police AI procurement in banking and insurance.
DTA already requires Commonwealth agencies to maintain an AI Transparency Statement and an internal AI use case register. From 15 June 2026, a mandatory AI Impact Assessment applies. If you service Commonwealth agencies, they'll ask about your equivalents. Public sector is already in scope.
Fair Work Commission is scrutinising algorithmic hiring tools and has published its own AI transparency guidance.
Before Friday
Send Deliverable 1. One email to your General Counsel and your Board Chair. Forty-eight hours for a yes-or-no answer on whether they can produce the one-page decision-path map.
Ninety seconds to send. The answer will tell you more about where you stand.
Forward this to your General Counsel and your Board Chair:
"Can we produce, on one page, a decision-path map of every customer outcome touched by AI in our business, or not?"
About Applied AI Australia
AI and privacy law in Australia are moving faster than most boards and ELTs can track in the time they have. APP 1.7, higher penalty caps, and OAIC privacy sweeps mean automated decisions are now a front-of-house topic for growth, risk, people, and technology.
We help Australian companies between $50M and $2B turn AI into revenue, margin, time, and better governance. One podcast, one newsletter, every week, built so you can brief a board in under an hour.
Listen now and subscribe: Available on Apple and Spotify
If someone forwarded this email, subscribe to the newsletter: Here.
If APP 1.7 is on your board agenda this quarter and you'd rather have the conversation with an operator than a consultant, reply APPLIED AI with two dates for a 30-minute session.
Disclaimer: Nothing in this newsletter is advice. It's research, pattern recognition, and publicly available information organised for executives who don't have five hours a day to read court filings. Before you act on any of this, talk to your own advisor. Or get in touch to book in an engagement.
Primary sources: Privacy and Other Legislation Amendment Act 2024 (Cth) Schedule 1 Part 15; Explanatory Memorandum; OAIC APP 1 Guidelines (Chapter 1); Australian Information Commissioner v Australian Clinical Labs (No 2) [2025] FCA 1224; OAIC media release October 2025; ASIC REP 798 (29 October 2024); Schufa CJEU C-634/21; Dun & Bradstreet CJEU C-203/22; APRA CPS 230; DTA Policy for the Responsible Use of AI in Government.
Ready to deploy AI with confidence?
Get board-ready frameworks and strategic guidance for Australian executives navigating AI transformation.
Discuss your AI problem