GeekStuff
← Back to News

Australia's AI Standards & Privacy Changes: What Your Business Needs to Know — August 2026

Australia is moving fast on AI and privacy regulation. Three major developments are underway right now — one of them has a hard deadline just four months away. Here's what's changing and what it means for your business.

New AI Standards — Legislation Coming Early 2027

On 15 July 2026, Prime Minister Albanese announced Australia will introduce mandatory AI standards — making us the first country in the world to bring data centre location, energy, and water obligations under a single national framework. A new Office of AI has been established within the Department of the Prime Minister and Cabinet to coordinate the design of these standards across government, and National Cabinet is expected to consider the approach this month.

While the standards will primarily target large data centres and AI training infrastructure, the direction is unmistakable: AI governance is shifting from voluntary guidance to mandatory regulation. For most businesses, the immediate takeaway is to ensure any AI tools you're using — from customer service chatbots to automated screening — comply with existing technology-neutral laws around privacy, consumer protection, and anti-discrimination. The government's AI6 voluntary guidance remains the recommended starting point for responsible AI use.

Legislation is expected to pass Parliament in early 2027. We'll keep you updated as the framework takes shape.

Data Centres Must Fund Their Own Power

Under the proposed standards, large data centre operators will be required to underwrite new renewable electricity generation matching their consumption, pay 100% of their grid connection and network costs, and fund any additional water infrastructure their sites need. This is a significant step beyond the current model, where operators simply purchase green certificates.

The policy responds to AEMO forecasts that data centre electricity demand will more than triple — from 4.7 terawatt hours today to 15.6 TWh by 2030-31, roughly 6.3% of national demand. The goal is straightforward: prevent surging data centre consumption from pushing up power bills for households and small businesses, a pattern already playing out in high-demand US regions like Virginia, where total electricity prices rose 76% year-on-year in early 2026.

For most businesses, this won't create immediate compliance obligations — but it signals a broader expectation that energy-intensive technology infrastructure should carry its own weight. If you run on-premises servers or are planning a cloud migration, energy efficiency and location considerations are becoming part of the regulatory conversation.

Privacy Act Deadline: Automated Decisions — 10 December 2026

This one has a hard deadline and it affects any business handling personal information. From 10 December 2026, organisations bound by the Privacy Act (known as APP entities) must update their privacy policies to disclose any use of "automated decision making" involving personal information.

The definition is broad. You are considered to be using automated decision making if a computer program makes, or substantially assists in making, a decision that could significantly affect an individual's rights or interests — and personal information is used in the process. This covers:

  • AI-driven credit assessments or loan approvals
  • Automated recruitment screening or resume filtering
  • Claims processing and eligibility checks
  • Customer onboarding and identity verification
  • Even rules-based filtering — the trigger is the use of personal information in an automated process, not just complex AI

If this applies to your business, your privacy policy must disclose:

  • What kinds of personal information are used in the automated process
  • What kinds of decisions are made solely by software
  • What kinds of decisions involve software assisting a human decision-maker

The Office of the Australian Information Commissioner (OAIC) can issue infringement notices, and civil penalties apply for non-compliance. The time to start is now — auditing your data flows, identifying automated decision points, and drafting compliant policy language takes longer than most businesses expect. A Privacy Impact Assessment is strongly recommended, and for government agencies it's already mandatory for high-risk projects.

What You Should Do Right Now

Before December 2026: review any software or workflow that uses customer data to make or assist decisions. Map where personal information flows into automated processes. If your privacy policy doesn't mention automated decision making, it will need updating before the deadline.

Longer term: keep an eye on the AI standards legislation as it develops through 2027. If you're using AI tools — especially in customer-facing roles — start documenting what you use and how decisions are made.

We're tracking these developments closely. If you'd like help auditing your data processes or updating your privacy policy ahead of the December deadline, get in touch — we're here to help.


Sources: