Privacy policies and AI
Does your privacy policy need to mention AI?
If your business is covered by the Privacy Act and uses AI in ways that touch personal information, then yes, in substance. The OAIC's position is that organisations should update their privacy policies and notifications with clear and transparent information about their use of AI.
The harder part is that you cannot describe how personal information flows through AI in your business until you know how it flows. A policy edit is the last step, not the first.
General information about Australian obligations, not legal advice.
Is a business required to say it uses AI in its privacy policy?
There is no clause that says "you must use the word AI". What exists is APP 1, which requires an APP entity to manage personal information openly and transparently and to have a clearly expressed and up to date privacy policy, plus OAIC guidance on what that means once AI is involved.
That guidance is direct: businesses should update their privacy policies and notifications with clear and transparent information about their use of AI, including ensuring that any public facing AI tools such as chatbots are clearly identified as such to customers.
So the practical answer is that if AI is part of how your business handles personal information, a privacy policy that does not reflect that is no longer clearly expressed or up to date. The obligation is to describe your actual handling accurately. AI does not create a new obligation so much as expose whether the existing description was ever true.
The same guidance makes a related point that is easy to miss: privacy obligations apply to personal information put into an AI system and to personal information the system generates, including where that output is inferred, incorrect or fabricated. If your business generates content about identifiable people using AI, that is a collection, and your policy should describe it.
Source: Guidance on privacy and the use of commercially available AI products (OAIC, published 21 October 2024, updated 17 January 2025).
What changes for privacy policies on 10 December 2026?
From 10 December 2026, an APP entity that has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests must say so in its privacy policy. The clauses are APP 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024.
What the policy has to state
At the level of kinds, not system detail:
- The kinds of personal information used in the operation of those programs.
- The kinds of decisions made solely by the operation of those programs.
- The kinds of decisions where the program does something substantially and directly related to making the decision, and a person still decides.
What it does not require
- Explaining how a model or algorithm works.
- Telling an individual that a particular decision about them was automated.
- Providing a right to human review of a specific decision.
- Justifying or explaining any individual outcome.
Several published summaries describe this as an obligation to explain automated decisions. It is not. It is a disclosure about kinds, in the policy.
It captures more than fully automated decisions, and less than all AI use
The clause reaches computer-assisted decisions, not only decisions a machine makes alone. The explanatory material treats "substantially" as meaning the program was a key factor in facilitating the human's decision. So a scoring tool that a person then signs off can be captured.
Equally, incidental use is expressly outside it. Drafting, summarising, transcription and documenting a decision a person has already reached are not captured. Decision types worth testing your own operations against: hiring and recruitment shortlisting, credit or lending decisions, insurance pricing or eligibility, access to a service or support, tenancy decisions, and disciplinary or performance decisions.
This obligation binds APP entities. A small business operator outside the Privacy Act does not acquire it. If you are not sure which side of that line your business sits on, resolve that first, because it decides most of this page.
Adding "we use artificial intelligence" to the policy is not governance
It is the change most businesses make, because it is the only one that can be made without finding anything out. It also creates a specific risk: a privacy policy is a public statement about how you handle personal information, and a vague sentence can be both uninformative and wrong.
It tells the reader nothing
A customer cannot work out from it whether their information goes into an AI service, which one, for what, or where it ends up. Transparency is measured by what the reader learns.
It can be inaccurate in both directions
Claiming AI use that does not happen misdescribes your handling. Describing it loosely enough to cover anything can imply consent to uses nobody has assessed.
It skips the work that mattered
The value of the exercise is finding out what is actually happening. A sentence added without that step leaves the same unknowns, now with a public statement over the top.
Before you change the privacy policy, answer these
Each of these is a question about your business, not about the law. Work through them and the policy wording tends to write itself, because you will finally be describing something you can see.
-
What AI is actually in use here?
Include the obvious tools and the ones nobody thinks of as AI: transcription and note-taking in meetings, assistants built into your email and document software, chat widgets on the website, summarisation inside your practice management or CRM system, recruitment screening features in a hiring platform.
-
Which of those touch personal information?
Not all of them will. A tool used only for internal drafting with no personal detail sits outside this. Be honest about what staff actually paste in, not what the policy says they should.
-
Is the information used or disclosed?
If the provider can access what you put in, that is a disclosure, not just an internal use. That distinction changes what APP 6 requires and what your policy should say.
-
Was that within the purpose you collected it for?
Personal information can be used or disclosed for the purpose it was collected for, or for a related secondary purpose the individual would reasonably expect. The OAIC notes it can be difficult to establish a reasonable expectation for an AI-related secondary use, so this is worth thinking about rather than assuming.
-
Where is it processed, and who else receives it?
Most widely used AI services process outside Australia, which engages APP 8. Subprocessors and connected features such as web search can put information in front of parties you have not assessed.
-
What does the provider do with it?
Retention period, whether inputs are used to train or improve models, whether that can be turned off, and whether the answer differs between the consumer product and the business tier. The answer is a fact about your account and plan, not about the brand.
-
Does any of it generate personal information?
Output that is about an identifiable person is a collection under APP 3, including where the output is wrong. If you generate summaries, assessments or content about customers, patients or candidates, this applies to you.
-
Does any of it feed a decision that significantly affects someone?
This is the APP 1.7 test. Get the answer recorded before December 2026 rather than at it, because the answer often takes longer to establish than the wording takes to write.
-
Who reviews AI output before it is relied on?
Name the person or the role. The OAIC's position is that a human user should be responsible for verifying the accuracy of personal information obtained through AI, and should be able to overturn decisions made by the system.
-
Now write the policy, and the collection notices with it
The privacy policy describes your handling generally. APP 5 notices tell an individual what is happening with their information when you collect it, which is where an AI-related purpose or disclosure should also appear. Updating one and not the other is the most common miss.
Situations that usually mean the policy is out of date
| Situation | What it changes about your handling |
|---|---|
| Staff paste customer detail into a chatbot | A disclosure to the provider. Usually the largest single gap between what a policy says and what happens. |
| AI meeting transcription | Recording and processing what other people said, often including third parties who were never told. Check consent and recording law as well as privacy. |
| A customer service chatbot | Collection through a new channel, plus the OAIC's expectation that customers can tell they are dealing with AI rather than a person. |
| AI document analysis | Bulk exposure. A single upload can put far more personal information into a service than any individual prompt. |
| AI-assisted recruitment | Candidate information, likely inference about individuals, and the clearest candidate for the APP 1.7 disclosure. |
| Generating content from customer records | Both a use of what went in and a collection of what comes out, where the output is about an identifiable person. |
| Sensitive, health or financial information | Sensitive information generally requires consent to be handled, and consent cannot be implied from a collection notice alone. |
| An AI feature switched on inside existing software | Your handling changed without a procurement decision. This is the one that most often escapes review entirely. |
| Processing or storage outside Australia | APP 8 applies to the cross-border disclosure, and your policy should say that information may be disclosed overseas. |
What a useful AI section in a privacy policy covers
There is no clause that suits every organisation, and any wording you copy has to be true of your business or it makes the policy worse. What follows is the set of points a serviceable section addresses, so you can check yours against it.
- What you use AI for. Described by purpose, not by product name, so it survives a change of vendor.
- Which kinds of personal information are involved. Specific enough that a reader can see whether theirs is included.
- Whether information is disclosed to AI providers. If they can access it, say so.
- Whether that happens overseas. Named countries where you know them, and the fact of overseas disclosure where you do not.
- Whether AI generates information about individuals. And what you do to keep it accurate.
- Whether AI is used in decisions about people. With the APP 1.8 kinds, once that applies to you.
- What human review applies. Who checks output before it is relied on.
- How to raise a concern. The existing complaints pathway, made reachable from this context.
- Where customers meet AI directly. A chatbot should be identifiable as one.
- When it was last reviewed. A dated policy is a claim you can stand behind.
Do not publish wording you have not verified
A privacy policy is a public representation about your business. A statement that inputs are never used for training, or that information stays in Australia, is a claim about a specific provider on a specific plan with specific settings. Check it against the provider's current documentation and your own account configuration before it goes on the website, and re-check it when the plan changes.
How this usually surfaces
An allied health clinic with six practitioners
One clinician starts using an AI note-taking tool during consultations. It works well, so within two months three others are using it, one on a personal subscription. The clinic's privacy policy is four years old, says information is stored in its practice management system, and does not mention transcription, AI or overseas processing.
Nothing here is exotic and nothing was done maliciously. But the clinic's published description of its handling of health information is now inaccurate, the clinic cannot say where consultation content is processed or retained, and patients were not told. Health information is sensitive information, and a practice that holds it is covered by the Privacy Act regardless of turnover.
The fix is not a sentence in the policy. It is deciding which tool is approved, assessing it, telling patients, and then describing what is now true.
Keeping the policy connected to what is actually happening
A privacy policy goes stale because the business changes and the document does not. The useful thing a compliance platform does here is hold the facts the policy depends on, with owners and review dates against them.
The automated decision question, asked once
Cleverer's Policy Builder asks whether computer programs make or substantially inform significant decisions about individuals. Where the answer is yes or unsure, the Privacy and Data Handling Policy carries the APP 1.7 to 1.9 section and the record of what still has to be determined.
Applicability answered at organisation level
Whether the Privacy Act applies to your business, and why, is recorded once and flows into every policy that depends on it, rather than being re-guessed each time a document is written.
Providers and review dates in one register
The vendor register records what each AI provider receives, where it is stored, whether the disclosure is offshore, whether subprocessors are known, who owns the relationship and when it is next due for review.
Cleverer does not publish or host your public privacy policy, and it does not tell you whether your wording is legally sufficient. It holds the organisational facts and the review cycle behind it. More on Privacy Act compliance.
Work out what your policy would have to say
The Readiness Check covers policies, responsibilities, suppliers, training and evidence. It is a quick way to see whether the description you publish still matches the business you run.
Questions about AI and privacy policies
Does a privacy policy have to mention AI by name?
No specific wording is mandated. APP 1 requires a clearly expressed and up to date privacy policy that describes how you handle personal information, and the OAIC's guidance is that organisations should update their privacy policies and notifications with clear and transparent information about their use of AI. If AI is part of how personal information moves through your business, a policy that omits it is not accurate.
What has to be disclosed from 10 December 2026?
Where an APP entity has arranged for a computer program to make, or to do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect an individual's rights or interests, its privacy policy must state the kinds of personal information used and the kinds of decisions involved. It does not require explaining how the program works or justifying any individual decision.
Does using Microsoft Copilot or ChatGPT mean my policy needs updating?
It depends on whether personal information goes into them. If staff use an AI tool only for drafting with no customer, patient or employee detail involved, your handling of personal information has not changed. If they paste in client records, or if a transcription tool captures a conversation with a customer, then your description of how you handle personal information is out of date.
Is a chatbot on our website something we have to disclose?
The OAIC's guidance is that public-facing AI tools such as chatbots should be clearly identified as AI to external users. Beyond that, a chatbot is a collection channel, so what it collects and what happens to it belongs in your privacy policy and in the notice a user sees at the point of collection.
Is updating the privacy policy enough on its own?
No. The policy is a description. If the description is accurate but the underlying handling was never decided, assessed or communicated to staff, the policy has documented an unmanaged practice rather than a governed one. It also has to be matched by your APP 5 collection notices, which is the step most often skipped.
Can we copy an AI clause from another company's privacy policy?
Not safely. A privacy policy is a representation about your own handling, and a clause that describes someone else's arrangements, retention settings or overseas processing will be wrong about yours. Use another policy to see what points get covered, then write what is true here.