APP 1.7 to 1.9 explained: the 10 December 2026 automated decision deadline

From 10 December 2026, if AI or any other software uses personal information to make, or substantially shape, a decision that could significantly affect someone, your privacy policy must say so: which kinds of decisions, and which kinds of personal information.
Key points
- APP 1.7, 1.8 and 1.9 come from the Privacy and Other Legislation Amendment Act 2024 and apply from 10 December 2026.
- They cover any decision made, or substantially shaped, by AI or software that could significantly affect a person, using their personal information.
- Your privacy policy must name the kinds of decisions involved and the kinds of personal information used.
- A human sign-off does not take a decision out of scope. It only changes how you describe it.
- It is not a ban on AI. It is a test of whether you know what your AI is actually deciding.
What are APP 1.7, 1.8 and 1.9?
Three new clauses in Australian Privacy Principle 1, added by the Privacy and Other Legislation Amendment Act 2024. Parliament gave organisations two years to prepare. That window closes on 10 December 2026.
They apply to APP entities: government agencies, organisations with annual turnover above A$3 million, and some smaller businesses such as health service providers.
The short version: if your AI makes or shapes decisions about people, you have to say so.
When does APP 1.7 apply to your AI?
When all three of these are true.
1. A computer program makes a decision, or does something substantially and directly related to making one. AI agents, models, scoring tools and automated workflows all count.
2. The decision could reasonably be expected to significantly affect someone's rights or interests.
3. The program uses personal information about that person.
What must your privacy policy say?
APP 1.8 requires three disclosures: the kinds of personal information your programs use, the kinds of decisions made solely by them, and the kinds of decisions they substantially shape.
APP 1.9 sets the scope. A decision includes refusing or failing to decide. It significantly affects someone if it touches a benefit, their rights under a contract, or their access to a significant service or support.
Three mistakes most businesses are making
“We don't use AI for decisions.” The OAIC reads computer program broadly. It covers AI and machine learning, rule-based software, and everyday tools including spreadsheets and generative AI. If a model scores, ranks or recommends, it is in play.
“A human signs off, so it isn't automated.” If the AI shortlists and a person mostly follows it, the AI substantially shaped the decision. Human approval changes the category, not the obligation.
“It's just a policy update.” The paragraph takes an hour. Knowing what to write takes an inventory most businesses do not have, because their AI is spread across vendors, plug-ins and staff using chatbots on personal accounts.
Two examples: in scope, and out
In scope: a property manager uses AI to score rental applications on income, rental history and references, and an agent approves the top-ranked applicant. That is access to a significant service, decided with personal information. It belongs in the privacy policy, even with the agent's sign-off.
Out of scope: the same business uses AI to write property listings from photos and floor plans. No personal information, and no significant effect on anyone. Nothing to disclose.
Why 10 December matters now
It is a hard date. Your privacy policy has to be accurate on day one.
Privacy policies are an active enforcement focus. The 2024 reforms let the OAIC issue infringement notices for policies missing required content, without going to court.
A wrong disclosure is worse than a vague one. Saying you do not use automated decisions, while a team runs an AI scoring tool, is a statement you cannot defend.
And the answer moves every time a team adopts a new AI tool. An audit in November is out of date by February.
Your six-step readiness checklist
1. List every AI tool and program that touches a decision about a person, including vendor features, plug-ins and staff-adopted chatbots.
2. Run the three APP 1.7 tests on each, and record why it is in or out.
3. Classify each in-scope decision: made solely by AI, or substantially shaped by it.
4. Record the kinds of personal information each one uses.
5. Write the disclosure in plain language and update the privacy policy before 10 December.
6. Make it a process, so every new AI tool triggers a policy check instead of an audit surprise.
How Ninjafy solves APP 1.7 to 1.9
The real compliance risk is not one rogue model. It is AI sprawl: a copilot here, a chatbot there, agents on personal accounts, each with its own settings and no shared record. Nobody can write an accurate privacy policy for that.
Ninjafy replaces sprawl with one federated AI operating model. Every AI teammate, in every team, runs under the same role-based permissions, the same guardrails and the same log. Compliance becomes organisation-wide by design, not team by team by hope.
Every action and every decision is recorded. So when the policy asks what your AI decides, and using what, you are reading from a record rather than guessing.
Ninjafy does not write your privacy policy or replace legal advice. It gives you the evidence the policy depends on.
| What APP 1.7 to 1.9 needs | How Ninjafy provides it |
|---|---|
| Know which AI makes or shapes decisions | One register of every AI teammate, its skills, its tools and the systems it can reach. |
| Know what personal information it uses | Role-based permissions scope every teammate's data access, and a PII guardrail can block personal information outright. |
| Classify: solely AI, or AI-shaped | Approval gates put a named person on anything that matters, so the policy describes a real process. |
| Prove the disclosure is accurate | Every decision is logged and exportable: what was asked, what happened, who or what decided, and the policy in force. |
| Keep it current | Guardrails are set once at organisation level. Teams and teammates can only tighten them, so new AI comes through one governed front door. |
Every decision, on the record
One export covers every approval decision in a period: what was asked, what happened, whether a person or the AI decided, and the policy in force at the time. Where an AI judge took part, it records the model, its confidence and its reasoning. Hand it to a reviewer as the evidence behind your APP 1.8 disclosure.

Your AI policy, enforced not documented
Guardrails turn your AI policy into live controls: human approval before irreversible actions, PII access control, restricted email domains. Set them once at organisation level and they apply to every team and every AI teammate. Teams can tighten them, never loosen them without an approved override.

Every AI action, logged
The activity log records every action an AI teammate takes, with the outcome, the time and the evidence, at teammate, team and organisation level. When someone asks what your AI did last Tuesday and why, the answer already exists.
- OAIC: APP Guidelines, Chapter 1 (APP 1)
- Allens: Automated decision-making transparency (June 2026)
- MinterEllison: OAIC ramps up privacy enforcement
- Sparke Helmore: OAIC's crackdown on privacy policies

Common questions
- What are APP 1.7, 1.8 and 1.9?
- New clauses in Australian Privacy Principle 1, added by the Privacy and Other Legislation Amendment Act 2024. They require organisations to disclose in their privacy policy when AI or other software uses personal information to make, or substantially shape, decisions that could significantly affect someone.
- When do APP 1.7 to 1.9 start?
- 10 December 2026.
- What must the privacy policy say?
- The kinds of personal information used, the kinds of decisions made solely by AI or software, and the kinds of decisions it substantially shapes.
- Does this only apply to AI?
- No. AI is the main driver, but rule-based software and spreadsheets can count too.
- Does a human approval step take a decision out of scope?
- Not necessarily. If the AI substantially shaped the decision, it still needs to be disclosed. Human approval changes how you describe it, not whether you do.
- Does APP 1.7 ban AI decision-making?
- No. It is a transparency obligation. You can keep using AI, as long as your privacy policy describes it accurately.
- How does Ninjafy help with APP 1.7?
- Ninjafy runs every AI teammate in one federated operating model, with role-based permissions, organisation-level guardrails and every action and decision logged. That gives you an accurate, exportable record of what your AI decides, using what, and where a person approves.
- Is this legal advice?
- No. This is general information. Check your specific obligations with your legal adviser.
Keep reading
- 6 foundations winning businesses will not compromise on
The six foundations that turn an AI agent into a compounding teammate: multiplayer, governed, compounding, proactive, owned and impact-based.
- Which AI agent platform is right for your business?
A six-question buying guide comparing Ninjafy with work assistants, AI teammates, agent builders, business suites, enterprise AI and building your own.
