New transparency obligations for automated-decision making will commence in December. Corrs Chambers Westgarth recently reviewed these changes and the likely future adjustments that may follow. The firm’s partners Arvind Dixit and James North break down these changes with additional insights from Special Counsel Emily Cravigan and Associate Lachie Dowling.
New transparency regulations are poised to reshape automated decision-making within superannuation from December onwards. With new obligations rolling out soon and further reforms looming over the horizon, superannuation funds need to understand where automation influences their member decisions and ensure they are ready to comply.
What is ADM and is it the same as AI?
‘Automated decision-making’ (ADM) refers to the use of technology, such as computer programs, software algorithms or artificial intelligence, to make decisions about people with minimal to no human input.
ADM and ‘artificial intelligence’ (AI) are related but distinct concepts. ADM is a broader category that captures any use of a computer system to make or materially influence a decision without meaningful human input. This applies whether that system is powered by AI or simple rules-based logic: not all ADM involves AI, and not all AI use constitutes ADM. The regulatory reforms discussed in this article target ADM rather than AI specifically (though the rising adoption of AI has accelerated the prevalence of ADM).
Why is change coming?
Until recently, Australia lacked a dedicated legislative framework governing ADM at the Commonwealth level. The Privacy Act 1988 (Cth) has long regulated how Australian Privacy Principles (APP) entities handle ‘personal information’. However, the Act did not specifically address the use of automated systems in decision-making.
One of the highly publicised catalysts for change was the Royal Commission into the ‘Robodebt’ Scheme, which published its report in July 2023 (here). The scheme’s use of automated data-matching to issue debt notices to welfare recipients resulted in widespread false overpayment notices. The royal commission called on the Commonwealth to introduce a consistent legal framework for automation in government services (Recommendation 17.1). This included clear paths for review, plain-language explanations of automated processes and the availability of algorithms for independent scrutiny.
Beyond this controversy, there has been a broad push across public and private sectors to emphasise transparency in decision-making and governance arrangements as automation becomes more commonplace. The Office of the Australian Information Commissioner (the OAIC) opened a public consultation in May 2026 (see here) to inform its guidance on ADM transparency obligations, with the guidance expected in September 2026.
What is changing?
The Privacy and Other Legislation Amendment Act 2024 (Cth), passed in November 2024, introduces the first dedicated ADM transparency obligation into the APPs, which govern the collection, use and disclosure of personal information.
Commencing on 10 December 2026:
- APP 1.7 will require APP entities to include information in their privacy policies where they have arranged for a computer program to make or do a thing substantially and directly related to making a decision. This applies when that decision could reasonably be expected to significantly affect an individual’s rights or interests, and where personal information is used in that process.
- APP 1.8 will require entities to specifythe kinds of personal information used, the kinds of decisions made solely by automated operation, and the kinds of decisions for which automated processes are substantially and directly related to the making of the decision.
- APP 1.9 clarifies that ‘making a decision’ for the purposes of APP 1.7 and APP 1.8 includes refusing or failing to make a decision, and that the obligations apply regardless of whether the decision is beneficial or adverse to the individual.
‘Computer program’ is not limited to AI, it extends to everyday tools that many funds already rely on, such as spreadsheet-based scoring models, automated triaging tools and administration workflows.
The regulatory outlook
The transparency obligations in APPs 1.7 – 1.9 represent only the first tranche of reform. The Privacy Act Review Report (February 2023, see here), conducted by the Attorney-General’s Department, recommended a right for individuals to request meaningful information about how substantially automated decisions with legal or similarly significant effect are made (Proposal 19.3).The Government agreed to this in its Response (see here). A second tranche of Privacy Act reforms is expected to address this right, along with broader changes including a potential ‘fair and reasonable’ test, expanded definitions of personal information, and mandatory privacy impact assessments for ‘high risk’ activities.
ADM in superannuation: What steps does the sector need to take now?
Superannuation funds are significant ADM users. Common applications include claims triaging and decision support, insurance underwriting, member communications, fraud detection, switching or withdrawal request processing, investment decision processes, and eligibility assessments. Many of these decisions – such as those affecting insurance claims, account access, or benefit entitlements – could reasonably be expected to ’significantly affect’ a member’s rights or interests under the new APP 1.7 threshold.
Superannuation trustees face parallel obligations as they must comply with the new ADM requirements in the Privacy Act as well as a range of other laws. Although the Australian Prudential Regulation Authority (APRA) has not introduced AI-specific requirements under CPS 230 (Operational Risk Management) or CPS 234 (Information Security), these standards already apply (alongside the Privacy Act) to AI and ADM risks. In an April 2026 letter to industry, APRA warned that AI adoption is outpacing governance and that boards should maintain sufficient AI understanding to provide effective oversight aligned with the entity’s risk appetite. Importantly, ADM can support trustee decisions, but responsibility remains with the trustee, and the trustee must be able to explain and justify ADM-assisted decisions if challenged.
Superannuation funds should take the following steps now to prepare:
- Audit ADM use cases. Conduct a comprehensive audit to identify where automated systems are used to make or materially influence decisions about members (whether such systems are used by your organisation directly or by a third-party service provider on your behalf). This includes not only obvious applications like claims engines but also algorithmic communications, risk scoring, and administration platforms. This audit will also assist in the context of supply-chain transparency requirements under CPS 230.
- Assess which decisions cross the ‘significantly affect’ threshold. Determine which automated processes could reasonably be expected to significantly affect members’ rights or interests. Decisions about insurance claims, benefit eligibility, early release of super, and account restrictions are likely candidates. Given the criticality of superannuation and associated services to individuals, including vulnerable persons, superannuation funds should take a cautious approach.
- Update privacy policies. Prepare to update privacy policy disclosures to meet the specificity required by new APP 1.8. Generic statements about ‘using technology to improve services’ will not suffice. Disclosures need to be clear and easy to understand.
- Be aware of future rights-based obligations. While not yet legislated, the anticipated right for individuals to request meaningful information about how automated decisions are made (Proposal 19.3 of the Privacy Act Review Report) will require funds to ensure their systems are explainable, not merely transparent at the privacy policy level, but capable of articulating how individual decisions were reached.
The 10 December 2026 deadline for ADM transparency obligations is firm, but it represents only the beginning of a broader regulatory shift. Superannuation funds that understand their ADM landscape now will be better positioned to meet their immediate disclosure requirements and the more substantive obligations likely to follow.
Importantly, ADM must be implemented and managed as part of a superannuation fund’s cyber and AI governance more broadly. As best practice, trustees and boards should understand where AI is used within their organisation, including supply chains, and have clear governance arrangements in place to develop an AI strategy and oversee the implementation of AI to ensure it aligns with the organisation’s risk appetite and regulatory obligations.