Australian privacy reform — what it means for AI use in professional firms
The direction of travel is toward more accountability, higher penalties and a narrower small-business exemption. Now is not the time to be casual about AI-related disclosures.
Published 26 July 2026
Australian privacy law has been in the middle of the largest reform program since the Privacy Act 1988 was originally passed. The reform has proceeded in tranches — some measures already in force, others on the legislative pipeline, others under active consideration. The direction of travel is consistent and material for anyone thinking about AI use in professional firms.
This article is a plain summary of where the reform stands and what specifically matters for AI.
What has already changed
The most significant change already in force is the substantial increase in maximum penalties for serious or repeated interferences with privacy. What was previously a comparatively modest civil penalty regime is now materially more serious — with maximums that can exceed the value of many mid-tier firms in extreme cases, and that put smaller firms in a position where a single serious breach can be existential.
Alongside that, the Notifiable Data Breaches scheme continues in force, with the OAIC increasingly active in publishing guidance and, where warranted, taking enforcement action. Public statements from the Commissioner have made clear that AI-related privacy failures are within the OAIC’s active interest.
What is coming
Reform tranches have proposed, and are progressively implementing:
A statutory tort for serious invasions of privacy. Where implemented, this gives affected individuals a direct cause of action against organisations that have interfered with their privacy, alongside the regulatory route via the OAIC. In practical terms this means AI-related disclosure incidents can produce not only a regulatory investigation but also private litigation, funded by class-action firms if the affected class is large enough.
Narrowing of the small business exemption. The Privacy Act currently exempts most businesses with annual turnover under $3 million. Successive reform proposals have suggested significantly narrowing or removing this exemption, on the reasonable observation that small businesses handle sensitive personal information no less than large ones. Even without full removal, the trend is toward more categories of small business being brought within scope — particularly those handling health information, children’s information, or other higher-sensitivity data.
A right to erasure. Individuals gaining an enforceable right to require deletion of their personal information, absent lawful reasons to retain it. This has significant practical implications for any organisation holding personal information — and specifically for AI systems, which may have retained material in ways that are difficult to selectively delete.
Direct rights of action. Alongside the tort proposal, expanded rights for individuals to enforce privacy obligations directly rather than only through the OAIC complaints framework.
Automated decision-making transparency. Where organisations use automated systems (including AI) to make decisions substantially affecting individuals, requirements to disclose that use and provide meaningful information about the logic involved.
What this means for AI specifically
Several of the reform themes bear directly on AI use.
The compliance floor is rising
The combination of higher penalties, broader coverage, and direct action rights means that the practical cost of getting AI-related privacy wrong is materially higher than it was two years ago and will likely be higher again in two years’ time.
Positions that were defensible on a low-enforcement-probability basis in the past are less defensible now. Firms that have relied on “no one has been fined for this yet” as an implicit part of their risk assessment need to update.
Notifiability will be more common
The direction of reform is toward lower thresholds for what constitutes an eligible data breach and more categories of harm attracting notification. Together with narrower small-business exemption, this means more incidents will require formal notification — including some that firms would previously have handled internally.
Notification obligations are difficult to satisfy for AI incidents specifically, because most firms have no reliable way to reconstruct what was actually disclosed. See our earlier article on the notifiable data breach framework and AI for detail.
Erasure creates a specific AI problem
The right to erasure — where implemented — creates a specific issue for AI systems that have retained data as part of their operation.
For cloud AI services holding your content on their infrastructure, satisfying an erasure request means asking the provider to delete. Whether they can, whether they will, and how you verify it varies considerably by provider.
For on-premise systems that hold data locally, the erasure obligation is technically easier because the data sits within your control — but it does require you to know what data the AI system holds and be able to selectively remove it. That is a design consideration, not an accident.
Automated decision-making transparency reaches AI-assisted work
Where AI meaningfully influences decisions affecting individuals — recommending an approach in a matter, informing a clinical assessment, contributing to a hiring or lending decision — the emerging transparency requirements will apply.
For professional firms, the practical implication is not usually that AI must be disclosed for every use, but that firms should be able to describe with reasonable specificity how AI is used in their workflow. “We might use AI for some things sometimes” is not adequate transparency; “AI is used for first-pass document summarisation which is then reviewed by a lawyer” is.
The pattern to notice
Individual reforms can be argued about in detail, and reasonable people take different views on specific policy choices. What is harder to argue about is the direction.
Every reform tranche has moved in the same direction: more accountability, higher penalties, broader coverage, more individual rights. There is no plausible reading of the reform program that suggests Australian privacy law is about to become more permissive of ad-hoc AI use with confidential material.
If your firm’s AI-related risk position depended on the current permissiveness being static, that assumption needs updating.
What to do about it, practically
The response to a rising compliance floor is not to attempt to precisely calibrate compliance to whatever it is this year, then recalibrate next year. It is to move to a position that is comfortably above whatever the floor becomes.
For AI specifically, the choices are broadly:
-
Ban AI outright for anything client-facing — which does not work in practice and produces the incidents this reform is trying to address.
-
Rely on enterprise cloud AI with proper governance — which is workable but requires active investment in the governance side (Purview, Sensitivity Labels, access reviews, staff training, audit) that many firms have not made.
-
Move client-confidential AI use to an on-premise system — which removes most of the reform-related risk at the point of architecture, because there is no third party involved to be governed, notified about, or held accountable.
Most firms of any real size will end up at option 2 for general work and option 3 for the confidential core. That is the position that ages best against a reform program moving in the direction Australia’s is.
The specific advice worth taking
None of this is our advice. This article is general information about a reform program, and the actual application to your firm is a conversation with your professional indemnity insurer, your privacy officer if you have one, and where warranted your privacy counsel.
What we can say plainly is that firms that treat the reform program as a distant concern usually end up treating it as an urgent one at a bad time. Assessing your position now is much cheaper than assessing it during an incident.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.