On 10 December Your Privacy Policy Becomes a Public Statement About Your AI

On 10 December Your Privacy Policy Becomes a Public Statement About Your AI

A compliance obligation drafted by lawyers is about to become the most-read paragraph on many Australian websites. Decide now who writes it.

Two things are happening on the Australian AI calendar at once. National Cabinet considers the Australian Standards for AI this month, following the Prime Minister's July announcement of an intention to legislate the standards and the establishment of an Office of AI inside the Department of the Prime Minister and Cabinet. Draft standards, consultation papers, and implementation guidance are expected across late 2026, with legislation going to Parliament in early 2027.

The second thing is closer and firmer. From 10 December 2026, organisations covered by the Australian Privacy Principles must set out in their privacy policies the kinds of personal information they use in automated decision-making and the kinds of decisions they make that way. The obligation arrived through the Privacy and Other Legislation Amendment Act 2024, and the Office of the Australian Information Commissioner has run a consultation on the guidance and intends to publish it by September 2026.

Third Hemisphere advises technology, financial services, and impact organisations on reputation and issues management, and this obligation belongs on the issues register alongside its place on the compliance checklist. The reason is straightforward. A privacy policy is a public document. On 10 December, several thousand Australian organisations will simultaneously publish a plain-language description of where they use AI to make decisions about people, and those descriptions will be directly comparable to each other.

What does the 10 December 2026 obligation require?

The obligation requires a covered organisation to describe, in general terms and inside its privacy policy, the kinds of personal information used in automated decision-making, the kinds of decisions made using computer programs, and broadly how the automated process works. It is a disclosure requirement. Nothing in it prohibits automated decision-making, and no organisation has to stop using a tool. The requirement is to tell people what the tool does.

That is a modest legal ask and a substantial communications event. Legal teams are well equipped to write a compliant paragraph. Fewer organisations have thought about how the compliant paragraph reads to a customer, a journalist, a competitor's analyst, or a plaintiff firm building a list of targets.

Which decisions count as significantly affecting a person?

The term is not yet defined by regulation, and guidance so far points to decisions about credit, insurance, employment, tenancy, and access to services. Legal commentary on the practical implications of the new requirements notes that the scope will only become settled once the OAIC guidance lands. For a communications team, the useful move is to work from the wider reading. If a system contributes to a decision that changes what a person can get, do, or pay, assume it is in scope and prepare the wording. Narrowing later is easy. Discovering in December that an omission is defensible legally and indefensible publicly is not.

Why the wording carries reputational weight

Three groups will read these disclosures closely in the same fortnight.

  • Journalists. A technology or consumer affairs reporter can compare 20 privacy policies in an afternoon. The story writes itself: which insurers, lenders, employers, and landlords use AI to decide about you, and which ones say the least about it. Vague wording becomes the story, because vagueness is the finding.

  • Customers and employees. Only 30 percent of Australians believe the benefits of AI outweigh the risks, the lowest result of 47 countries surveyed in research covering over 48,000 people. A disclosure that reads as reluctant confirms an existing suspicion.

  • Competitors and regulators. The OAIC has already run a compliance sweep across property, pharmacy, retail, and digital services in 2026. A disclosure that contradicts a company's marketing claims about human oversight creates a live inconsistency in a public document.

The organisations that come out of December well will be the ones whose disclosure reads as a considered account of how they use automated decision-making and where a human stays in the loop. The organisations that come out of it badly will be the ones whose disclosure reads as though nobody wanted to write it.

Four things worth doing before December

1. Build the inventory, and expect it to surprise you

Ask every function which automated or AI-assisted tools contribute to decisions about individuals. Credit scoring and resume screening surface immediately. Fraud flags, dynamic pricing, chatbot triage that determines who reaches a human, and vendor tools embedded inside a platform take longer to surface, and they are frequently the ones that create the disclosure problem. This work takes weeks, which is why August is the right month for it.

2. Put communications in the room for the drafting

Legal should own compliance and communications should own readability, and the two should draft together. The test for the final wording: could a customer read this paragraph, explain it accurately to a friend, and feel that the organisation had been straight with them. A paragraph that passes a legal review and fails that test has created an exposure.

3. Pre-draft the holding statement

Assume a journalist calls in the week of 10 December with a specific question about one line in the disclosure. Write the holding statement now, while the subject matter experts are available and nobody is under deadline pressure. Include the scope of automated decision-making, the human oversight arrangements, the review and appeal mechanism, and the named spokesperson. Third Hemisphere prepares these as standard practice for clients ahead of any dated regulatory obligation, because a statement written in advance is materially better than one written in an hour.

4. Brief the spokesperson on the hard question

The hard question is rarely about the technology. It is "can a person get a decision reviewed by a human, and how long does that take". A spokesperson who can answer that in one sentence, with a number, controls the interview. A spokesperson who redirects to a general statement about responsible AI hands the story to the reporter.

What does a well-written disclosure look like?

A well-written disclosure names the decision, names the input, and names the human. It reads closer to a plain explanation than to a legal clause, and it gives a reader enough to act on. Three elements do most of the work.

  • The specific decision, in the customer's language. "We use an automated system to give an initial credit assessment on personal loan applications" tells a reader what happened to them. "We may use automated processing in connection with certain services" does not.

  • The information the system uses. Categories are enough, and vagueness is where trust erodes. Naming income data, repayment history, and identity verification is more credible than a reference to relevant personal information.

  • The route to a human. The single most reassuring line an organisation can publish is a clear statement that a person can ask for a decision to be reviewed by a staff member, with the mechanism and the timeframe attached.

The wording also needs to survive comparison with everything else the organisation says publicly. If a homepage promises that every decision has human oversight and the privacy policy describes fully automated approvals, the inconsistency becomes the finding. Reconciling those two documents is a communications job and it should happen before December, not after a journalist notices.

The opportunity most organisations will miss

December's obligation gives every covered organisation a licensed reason to make a public statement about how it uses AI, at a moment when the public is sceptical and the whole market is publishing at once. An organisation that has done the inventory properly, keeps a human in the loop where it counts, and can describe both clearly has a credible position to state and a reason to state it. An organisation whose disclosure lands as boilerplate has spent the same compliance effort and gained nothing.

The distinction is not the quality of the AI governance. It is whether anyone treated the disclosure as a communication.

How Third Hemisphere approaches this

Third Hemisphere works with clients on dated regulatory events as issues management projects, which means running them backwards from the compliance date. For the 10 December obligation that sequence covers the internal inventory, a plain-language wording review alongside legal, a pre-drafted holding statement and question-and-answer document, spokesperson preparation, and a decision about whether to make a proactive statement or hold a reactive one. The agency's work on reputation, regulation, and technology sits across its insights page and its blog.

This piece describes reputation risk and it is not legal advice. Organisations should take their own advice on the scope of the obligation, and should watch for the OAIC guidance due by September 2026.

The takeaway

Treat the 10 December privacy policy obligation as a public statement about your AI, and draft it with communications in the room from the start. The compliance work is a paragraph. The reputational consequence of that paragraph will run for the following year, in coverage, in customer trust, and in every claim your organisation makes about human oversight.

Four months is enough time to do this properly. Third Hemisphere runs the communications side of dated regulatory obligations for technology and financial services clients.