This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
A routine business task can become a privacy question as soon as personal information is entered into an AI product or an AI-generated assessment is stored against a person. It is normal to find the boundaries difficult because the OAIC has published separate material for organisations using commercial products, developers training models, automated decisions and data breaches. This reference brings those sources together without deciding how the Privacy Act applies to a particular business.
In short: The OAIC says the Privacy Act 1988 and Australian Privacy Principles apply when an organisation covered by the Act handles personal information through AI. Its guidance addresses inputs, generated outputs, transparency, use and disclosure, overseas recipients, accuracy and security. A separate transparency provision for certain automated decisions is scheduled to commence on 10 December 2026. Whether any rule covers a particular organisation or use remains dependent on the Act and the circumstances.
The OAIC has published two central AI privacy guides
The OAIC's central material divides AI activity into using a commercially available product and developing or training a model. Both guides were published on 21 October 2024, but their audiences and boundaries differ.
| Primary source | What it covers | Stated boundary |
|---|---|---|
| Guidance on privacy and the use of commercially available AI products | Selection and use of chatbots, content generators, productivity assistants and other available AI products | The OAIC says it does not cover every privacy issue and is to be read with the Privacy Act and APP Guidelines |
| Guidance on privacy and developing and training generative AI models | Designing, training, adapting and fine-tuning models with personal information | It focuses on APPs 1, 3, 5, 6 and 10 during planning, design and dataset work, rather than every stage or applicable law |
For an ordinary product user, the first guide is the closer source. It says personal information in an AI input remains subject to privacy obligations and that an output can also be personal information, including an inference or an incorrect, artificially generated statement about an identifiable person.
For a business adapting or fine-tuning a model, the development guide is more directly relevant. The OAIC says publicly accessible data is not automatically available for model training and separates practices it presents as legal requirements from recommendations or better practice.
The Privacy Act does not cover every small business in the same way
The OAIC's AI guidance is directed to organisations that are APP entities, not automatically to every Australian business using software. The OAIC's small-business guidance says most businesses with annual turnover of A$3 million or less are not covered, but identifies exceptions, including some health service providers, businesses trading in personal information, related bodies corporate and Commonwealth contracted service providers.
The statutory definition and exceptions appear in section 6D of the Privacy Act 1988. Other provisions, sector rules, contracts and state or territory laws may still matter where the federal APP regime does not apply. The OAIC directs a small business uncertain about coverage to its privacy checklist, an industry association or a lawyer rather than treating turnover alone as a complete answer.
How the OAIC connects the APPs to commercial AI products
The OAIC does not present a separate set of Australian Privacy Principles for AI. Its commercial-product guidance applies the existing principles to the ways an AI system collects, receives, generates, uses, discloses and stores personal information.
| APP area | What the primary sources say about AI |
|---|---|
| APP 1, governance and transparency | The OAIC says an APP entity's practices, procedures, systems and privacy policy need to account for its handling of personal information. Its AI guidance recommends clear information about AI use and identifying public-facing AI systems to users. OAIC commercial-product guidance |
| APPs 3 and 5, collection and notice | The OAIC treats an AI-generated inference about an identifiable person as a collection of personal information. Its guidance also discusses notifying people when a public-facing AI system collects their information. OAIC commercial-product guidance |
| APP 6, use and disclosure | APP 6 addresses use for the primary purpose and secondary uses or disclosures where an exception applies. The OAIC says entering information in an external AI service can be a disclosure if it becomes accessible outside the entity and leaves its effective control. APP 6 Guidelines |
| APP 8, overseas recipients | The OAIC says APP 8 and section 16C create a framework for overseas disclosure and accountability, subject to exceptions. Whether cloud processing is a disclosure or remains a use can depend on access and effective control, not server location alone. APP 8 Guidelines |
| APP 10, data quality | The OAIC says APP entities need to consider the accuracy of personal information collected, used or disclosed through AI. Its guidance describes outputs as probabilistic and warns against treating them automatically as facts about a person. OAIC commercial-product guidance |
| APP 11, security | The OAIC includes security risks, access to inputs and outputs, retention and vendor access among its product-selection considerations. The formal security principle remains APP 11. Australian Privacy Principles Guidelines |
APP 6 is the OAIC's main reference point for prompts containing personal information
The OAIC says entering personal information into an AI system may be a use if the information stays within the organisation's effective control, or a disclosure if it becomes accessible to an outside party and leaves that control. Its commercial-product guidance therefore directs attention to the primary purpose for which the information was collected and any relevant APP 6 exception.
The OAIC illustrates this with insurance staff placing a customer's claim and sensitive health information into a public chatbot to prepare an assessment. The example says the company has disclosed the information to the chatbot owner and would need to analyse the purpose and available APP 6 exceptions. As a better-practice position, rather than a universal statutory ban, the OAIC recommends that organisations not enter personal information, particularly sensitive information, into publicly available AI chatbots.
That distinction matters. The source does not say that every use of customer information in every AI product has the same outcome, and this page does not turn the example into one.
APP 8 depends on the data flow, recipient and control
An overseas server does not, by itself, settle the APP 8 question. The OAIC's APP 8 Guidelines distinguish disclosure to an overseas recipient from routing or controlled storage, and explain that providing information to an overseas contractor will generally be a disclosure while limited storage arrangements can sometimes remain a use.
For an AI product, the relevant source questions therefore concern who can access inputs and outputs, whether the provider uses them for training, where subprocessors are located and whether the Australian organisation retains effective control. The OAIC's commercial-product guidance raises these questions but does not publish a list declaring individual AI vendors compliant or non-compliant.
APP 1.7 automated-decision transparency starts on 10 December 2026
As checked on 4 September 2026, the automated-decision provisions had not yet commenced. Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024 sets their commencement for 10 December 2026.
New APP 1.7 applies where an APP entity has arranged for a computer program to make a decision, or do something substantially and directly related to making it, personal information about the individual is used in the program, and the decision could reasonably be expected to significantly affect the individual's rights or interests. APP 1.8 specifies information for the privacy policy, including the kinds of personal information used and the kinds of relevant decisions made solely by a program or materially assisted by one.
The OAIC's APP 1 guidance says the amendments apply to decisions made from 10 December 2026 even if the arrangement, information or program predates commencement. Its examples include decisions affecting statutory benefits, contractual rights and access to significant services such as healthcare.
The OAIC opened a consultation on detailed transparency guidance in May 2026. As of the checked date, the consultation page and the OAIC's 2026 to 2027 corporate plan described that detailed guidance as being developed. This page therefore does not infer answers to disputed scope questions that the final guidance may address.
The NDB scheme can remain relevant when the breached system belongs to a vendor
A breach at an AI provider is not automatically outside an Australian customer's NDB analysis. The OAIC's NDB scheme guide says each regulated entity holding personal information involved in a breach should be able to demonstrate that it is meeting the scheme's requirements.
The guide describes an eligible data breach as unauthorised access, disclosure or loss involving information an entity holds, where serious harm is likely and remedial action has not prevented that likely risk. For suspected eligible breaches, section 26WH of the Privacy Act requires a reasonable and expeditious assessment and all reasonable steps to complete it within 30 days. Confirmed eligible breaches engage statements and notifications under sections 26WK and 26WL, subject to the Act's qualifications and exceptions.
Where several entities hold the same information, the OAIC says the NDB scheme does not prescribe which one conducts the assessment or notification. It recommends clear contractual procedures for communication, assessment, containment, remediation and notification. Its guide includes an example involving an overseas email platform, which supports the vendor principle even though the OAIC has not published an AI-vendor-specific NDB rule.
The unresolved factual questions after any AI provider incident include what information the customer and provider each held, which entities the Act covers, whether serious harm is likely, what remediation achieved and what their contracts say. A vendor's announcement alone does not answer those questions.
OAIC decisions show application to facts, not a rule for every AI system
The OAIC's facial-recognition work demonstrates how the regulator and review tribunal apply technology-neutral privacy principles to a specific system. In February 2026, the Administrative Review Tribunal affirmed findings that Bunnings had contravened APPs 1 and 5 through shortcomings in governance and notification, while departing from the Commissioner's APP 3.3 conclusion. The OAIC summarises that outcome in its statement on the tribunal decision.
The OAIC then updated its facial-recognition privacy guidance in July 2026. The regulator describes the Bunnings matter as a useful case study rather than general permission to deploy biometric technology. It also notes that a separate Kmart determination remained under review when the page was updated.
These materials are relevant evidence of the OAIC's approach to transparency, structured risk assessment and sensitive information. They do not decide whether a different AI product used for a different purpose satisfies the Act.
DISR, ASIC and the ACSC answer different AI questions
Not every Australian Government publication about AI is OAIC guidance. The bodies have distinct remits:
- The Department of Industry, Science and Resources publishes the Guidance for AI Adoption. Its six practices concern responsible AI governance and adoption, and the department presents them as voluntary guidance rather than new legal duties.
- The Australian Securities and Investments Commission's Report 798 reports on AI governance among financial services and credit licensees. It is sector-regulator material, not a general interpretation of the Privacy Act.
- The Australian Signals Directorate's Australian Cyber Security Centre publishes security guidance for engaging with AI. It addresses threats, supply chains, access controls and incident response, rather than administering the APPs.
Those sources are included to mark the boundary, not to merge several regulatory regimes into one checklist.
Where the OAIC's published AI position stops
The OAIC explains its interpretation and enforcement approach, but its guidance repeatedly says application depends on the circumstances and that the documents are not exhaustive. It does not approve named commercial AI tools, publish a universal list of acceptable prompts, decide whether a particular SMB falls within an exemption or allocate NDB responsibility between a customer and vendor in advance.
The commercial-product guide also mixes descriptions of statutory requirements with recommendations and better-practice measures. Those categories should not be silently converted into identical obligations. The development guide expressly says recommendations or suggestions identify matters of better practice rather than clear legal requirements.
Questions involving a business's coverage under the Act, an APP 6 exception, effective control of cloud data, the seriousness of harm after a breach or the reach of APP 1.7 require facts beyond a general reference page. The OAIC, an industry body or a qualified adviser is the appropriate source for a position tied to those facts.
Questions the OAIC material raises for an AI user or vendor
These are source-navigation questions, not a compliance checklist:
- Is the organisation an APP entity under the Privacy Act, including through a small-business exception or voluntary opt-in?
- Does the system receive, generate or infer information about an identified or reasonably identifiable person?
- Do the provider and its subprocessors receive access to prompts, files, logs or generated outputs, and can they use that material for model development?
- Does the proposed handling match the primary purpose described when the information was collected, or is an APP 6 exception being considered?
- Is an overseas provider receiving the information, or is the arrangement closer to controlled storage as described in the APP 8 Guidelines?
- Does a computer program make or materially assist a decision that could significantly affect an individual's rights or interests after 10 December 2026?
- If a provider reports a breach, which entities held the information and which facts determine whether the NDB serious-harm threshold is met?
- Which parts of a proposed approach come from the Act, which come from OAIC recommendations and which are the business's own risk decisions?
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Does the Privacy Act apply whenever a business uses AI?
No. The OAIC’s guidance on privacy and the use of commercially available AI products says the Privacy Act applies to AI uses involving personal information by entities the Act covers. Coverage of a small business can depend on turnover, activities, relationships, contracts and whether it has opted in.
Does the OAIC prohibit entering customer information into every AI product?
No universal prohibition appears in the commercial-product guidance. The OAIC discusses APP 6, the product's data flows and the circumstances, while recommending as better practice that organisations not enter personal information, particularly sensitive information, into publicly available AI chatbots.
Is overseas AI hosting automatically an APP 8 disclosure?
No. The OAIC distinguishes disclosure to an overseas recipient from some routing, storage and contractor arrangements based on access and effective control. The actual architecture and contract determine which part of the APP 8 guidance is relevant.
What changes on 10 December 2026?
APPs 1.7 to 1.9 are scheduled to commence. They add privacy-policy transparency provisions for specified computer-assisted decisions using personal information that could reasonably be expected to significantly affect an individual's rights or interests.
Who reports a breach if both an Australian business and its AI vendor hold the data?
The OAIC’s Part 4 guidance on the Notifiable Data Breaches scheme says the scheme does not prescribe which entity assesses or notifies where several entities hold the affected information. Each regulated entity should be able to demonstrate that it meets the scheme, while contractual arrangements can allocate communication and response work.
Has the OAIC approved any AI products as privacy compliant?
The reviewed OAIC sources, including its guidance on privacy and the use of commercially available AI products, do not provide an approved-product list. They describe principles, questions, examples and regulatory expectations, leaving product-specific and use-specific conclusions to the relevant facts.
Methodology
This desk-research assessment was checked on 4 September 2026 against the OAIC's two central AI privacy guides, current APP Guidelines, NDB guidance, automated-decision consultation material, facial-recognition material, the Privacy Act 1988 and the Privacy and Other Legislation Amendment Act 2024. No product was tested, and no conclusion about a particular organisation's legal position was made.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
For a practical planning artefact, use the Australian AI register template to record systems, owners, data flows and unresolved questions. The template does not determine compliance or replace advice tied to a business's circumstances.
Australian AI register template