Frontrow Technology
← All insights & guides
Guide

Data & Governance

Privacy Act ADM rules: the Copilot scope check

From 10 December 2026, privacy policies must disclose automated decision making. Which Copilot and agent uses count, how to inventory a Microsoft 365 tenant, and a scope-check worksheet.

Sam Williams · 28 August 2026 · 11 min read

From 10 December 2026, Australian Privacy Principle entities that use automated decision making must disclose it in their privacy policies. The requirement comes from the Privacy and Other Legislation Amendment Act 2024, and the law firm alerts covering it are accurate as far as they go. What none of them covers is the operational question: an organisation that has spent 2026 rolling out Microsoft 365 Copilot, building Copilot Studio agents and wiring Power Automate flows now has to work out which of those uses meet the statutory test, find all of them in the tenant, and write the disclosure. That is this guide.

The test: three limbs, all required

The transparency obligation applies where three things are all true. First, the entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision. Second, the decision could reasonably be expected to significantly affect the rights or interests of an individual. Third, personal information about the individual is used in the operation of the computer program. Miss any limb and the disclosure obligation does not bite for that use.

Two features of the drafting deserve attention before any Copilot mapping. The obligation is transparency, not prohibition: nothing in these provisions stops an organisation using automated decision making, provided the privacy policy discloses it. And the 'substantially and directly related' limb deliberately reaches decision support, so a program that produces the assessment a human formally signs off can still be in scope. The OAIC consulted on guidance through the first half of 2026, with submissions closing on 15 June 2026, and intends to issue its guidance by September 2026. Interpretations below are Frontrow's operational reading and should be checked against that guidance when it lands.

Which Copilot and agent uses count

Applying the three limbs to a typical Microsoft 365 estate sorts AI use into three bands.

Almost certainly out of scope

  • Copilot drafting an email, document or presentation that a person then edits and sends. There is no decision by the program, and nothing significantly affecting an individual's rights turns on the draft.
  • Meeting summaries, chat over documents, search and retrieval. These inform a human who decides everything downstream.
  • Back-office agents whose outputs never touch an identifiable individual's entitlements, such as an agent summarising service tickets for a weekly report.

Needs assessment: the decision-support band

  • A Copilot Studio agent that screens or ranks job applicants before a recruiter looks at the pool. The consultation examples repeatedly reference employment decisions, and a shortlist the human rarely departs from is exactly what 'substantially and directly related' is written to catch.
  • An agent that assesses eligibility, hardship, refunds, claims or credit before a staff member confirms. The closer the human step is to a rubber stamp, the stronger the case that the program is doing the substantive work.
  • Automated triage that determines how quickly, or whether, an individual reaches a service or support. Prioritisation is a decision when the queue position materially affects the person.

Likely in scope

  • A Power Automate flow that approves or rejects an application against rules or a model score with no human step. That is a computer program making the decision, and if the subject matter is a loan, a policy, a job, housing or access to a significant service, the significance limb is met on the consultation's own examples.
  • Any agent given authority to action an outcome that affects an individual's entitlements, obligations or access, rather than to recommend it.

How to inventory ADM in a Microsoft 365 tenant

The disclosure can only be as complete as the inventory behind it, and self-reporting by business units reliably misses what citizen developers have built. Pull the inventory from the platform instead. Four passes cover a Microsoft 365 estate.

  1. 1Deployed Copilot agents. The Microsoft 365 admin center's integrated apps and agent management area lists agents made available to the organisation. For each, record what it does, whether its output touches decisions about identifiable people, and what personal information it can reach.
  2. 2Copilot Studio estates. In the Power Platform admin center, enumerate every environment, including the default environment where trial builds accumulate, and list the agents in each. Unused environments are where forgotten decision agents live.
  3. 3Power Automate flows. Filter for flows containing approval actions, condition branches on personal data, or connectors into HR, CRM and finance systems. Flows that auto-action outcomes for individuals are the highest-priority finds in most tenants, because nobody thinks of a flow as ADM.
  4. 4Everything outside the tenant. Custom applications calling Azure AI or other model APIs, and AI features embedded in third-party SaaS such as rostering, lending or recruitment platforms. The statutory test attaches to decisions the entity has arranged for, and a vendor's model making calls about your customers is squarely an arrangement.

Record each entry against the three limbs: what decision or decision-related thing the program does, why it does or does not significantly affect rights or interests, and what personal information it uses. That worksheet is both the scope decision and the audit trail for defending it later. Where an entity is also standing up agent identity governance through Microsoft Entra Agent ID, the same agent registry does double duty as the ADM inventory's system of record.

What the privacy policy must actually say

For uses that meet the test, the privacy policy must set out three things: the kinds of personal information used in the operation of the relevant computer programs, the types of decisions made by the operation of those programs, and the types of decisions for which the programs do a thing substantially and directly related to the decision. Note what is not required: the obligation does not compel naming products, publishing model details or disclosing logic. Describing kinds and types is the statutory task, and a policy that says the organisation uses automated systems drawing on application, employment and financial information to assess loan applications, with final decisions made by staff, is closer to the mark than a paragraph of AI boilerplate.

Sequencing matters more than usual here. The OAIC intends to publish its guidance by September 2026, and the obligation commences on 10 December 2026. That leaves roughly one quarter between guidance and deadline, which is not enough time to start the inventory after the guidance arrives. The workable order is inventory now, draft disclosures against the plain words of the provisions, then adjust wording when the guidance lands.

The scope-check worksheet

For every agent, flow or AI feature the inventory surfaces, answer these in writing.

  1. 1What does the program produce: a draft, a recommendation, a ranking, or an actioned outcome?
  2. 2Does an identifiable individual's job, money, housing, insurance, healthcare or access to a significant service turn on that output?
  3. 3Is personal information about that individual used in the program's operation, including as retrieval context for an agent?
  4. 4Where a human sits in the flow, do they exercise real discretion with independent information, or confirm the program's output as a matter of routine?
  5. 5Who arranged for the program: your entity, or a vendor acting on your instructions? Both point back to your privacy policy.
  6. 6If in scope: are the kinds of personal information and the types of decisions involved described in the current privacy policy? If not, that is the drafting gap to close before 10 December 2026.

Verified August 2026 against the OAIC's consultation on guidance for transparency in automated decision making, the OAIC's ADM issues paper, White & Case's alert of 18 June 2026 and the Privacy and Other Legislation Amendment Act 2024 as published on the Federal Register of Legislation. The scope analysis for specific Copilot and agent patterns is Frontrow's operational reading of the provisions; the OAIC's guidance, expected by September 2026, is the authority to check it against.

Common questions

Frequently asked

Is Microsoft 365 Copilot automated decision making under the Privacy Act?
Ordinary Copilot use, drafting, summarising and answering questions for a person who then decides, does not meet the test, because no decision significantly affecting an individual's rights is made or substantially advanced by the program. The analysis changes for agents that score, rank, triage, approve or reject: those uses need a documented assessment against the three statutory limbs.
When do the ADM transparency requirements start?
10 December 2026. The requirement was introduced by the Privacy and Other Legislation Amendment Act 2024 with a two-year lead time, and both the OAIC and law firm coverage confirm the commencement date. Privacy policies need to be updated by that date for any in-scope automated decision making.
Does the new obligation prohibit or restrict automated decisions?
No. It is a transparency obligation attached to Australian Privacy Principle 1. In-scope entities must describe in their privacy policy the kinds of personal information used and the types of decisions involved. Other laws can separately constrain specific automated decisions, but these provisions require disclosure, not permission.
Does a human reviewing the agent's output take us out of scope?
Not automatically. The provisions also capture programs that do a thing substantially and directly related to making a decision, which is aimed at decision support. Whether routine human sign-off changes the analysis is one of the questions the OAIC consulted on, so record how much real discretion the human exercises and revisit when the guidance is published, expected by September 2026.
What exactly has to appear in the privacy policy?
Three things for in-scope uses: the kinds of personal information used in the operation of the relevant computer programs, the types of decisions those programs make, and the types of decisions the programs do something substantially and directly related to making. Product names, model details and decision logic are not required by these provisions.
Our decision automation lives in a vendor's platform, not our tenant. Are we covered?
If your organisation arranged for the vendor's program to make or substantially contribute to decisions about individuals using their personal information, the disclosure obligation sits with your privacy policy. Vendor-hosted AI belongs in the same inventory as Copilot Studio agents and Power Automate flows, with the same three-limb assessment.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.