From 10 December 2026, Australian Privacy Principle entities that use automated decision making must disclose it in their privacy policies. The requirement comes from the Privacy and Other Legislation Amendment Act 2024, and the law firm alerts covering it are accurate as far as they go. What none of them covers is the operational question: an organisation that has spent 2026 rolling out Microsoft 365 Copilot, building Copilot Studio agents and wiring Power Automate flows now has to work out which of those uses meet the statutory test, find all of them in the tenant, and write the disclosure. That is this guide.
The test: three limbs, all required
The transparency obligation applies where three things are all true. First, the entity has arranged for a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision. Second, the decision could reasonably be expected to significantly affect the rights or interests of an individual. Third, personal information about the individual is used in the operation of the computer program. Miss any limb and the disclosure obligation does not bite for that use.
Two features of the drafting deserve attention before any Copilot mapping. The obligation is transparency, not prohibition: nothing in these provisions stops an organisation using automated decision making, provided the privacy policy discloses it. And the 'substantially and directly related' limb deliberately reaches decision support, so a program that produces the assessment a human formally signs off can still be in scope. The OAIC consulted on guidance through the first half of 2026, with submissions closing on 15 June 2026, and intends to issue its guidance by September 2026. Interpretations below are Frontrow's operational reading and should be checked against that guidance when it lands.
Which Copilot and agent uses count
Applying the three limbs to a typical Microsoft 365 estate sorts AI use into three bands.
Almost certainly out of scope
- Copilot drafting an email, document or presentation that a person then edits and sends. There is no decision by the program, and nothing significantly affecting an individual's rights turns on the draft.
- Meeting summaries, chat over documents, search and retrieval. These inform a human who decides everything downstream.
- Back-office agents whose outputs never touch an identifiable individual's entitlements, such as an agent summarising service tickets for a weekly report.
Needs assessment: the decision-support band
- A Copilot Studio agent that screens or ranks job applicants before a recruiter looks at the pool. The consultation examples repeatedly reference employment decisions, and a shortlist the human rarely departs from is exactly what 'substantially and directly related' is written to catch.
- An agent that assesses eligibility, hardship, refunds, claims or credit before a staff member confirms. The closer the human step is to a rubber stamp, the stronger the case that the program is doing the substantive work.
- Automated triage that determines how quickly, or whether, an individual reaches a service or support. Prioritisation is a decision when the queue position materially affects the person.
Likely in scope
- A Power Automate flow that approves or rejects an application against rules or a model score with no human step. That is a computer program making the decision, and if the subject matter is a loan, a policy, a job, housing or access to a significant service, the significance limb is met on the consultation's own examples.
- Any agent given authority to action an outcome that affects an individual's entitlements, obligations or access, rather than to recommend it.
How to inventory ADM in a Microsoft 365 tenant
The disclosure can only be as complete as the inventory behind it, and self-reporting by business units reliably misses what citizen developers have built. Pull the inventory from the platform instead. Four passes cover a Microsoft 365 estate.
- 1Deployed Copilot agents. The Microsoft 365 admin center's integrated apps and agent management area lists agents made available to the organisation. For each, record what it does, whether its output touches decisions about identifiable people, and what personal information it can reach.
- 2Copilot Studio estates. In the Power Platform admin center, enumerate every environment, including the default environment where trial builds accumulate, and list the agents in each. Unused environments are where forgotten decision agents live.
- 3Power Automate flows. Filter for flows containing approval actions, condition branches on personal data, or connectors into HR, CRM and finance systems. Flows that auto-action outcomes for individuals are the highest-priority finds in most tenants, because nobody thinks of a flow as ADM.
- 4Everything outside the tenant. Custom applications calling Azure AI or other model APIs, and AI features embedded in third-party SaaS such as rostering, lending or recruitment platforms. The statutory test attaches to decisions the entity has arranged for, and a vendor's model making calls about your customers is squarely an arrangement.
Record each entry against the three limbs: what decision or decision-related thing the program does, why it does or does not significantly affect rights or interests, and what personal information it uses. That worksheet is both the scope decision and the audit trail for defending it later. Where an entity is also standing up agent identity governance through Microsoft Entra Agent ID, the same agent registry does double duty as the ADM inventory's system of record.
What the privacy policy must actually say
For uses that meet the test, the privacy policy must set out three things: the kinds of personal information used in the operation of the relevant computer programs, the types of decisions made by the operation of those programs, and the types of decisions for which the programs do a thing substantially and directly related to the decision. Note what is not required: the obligation does not compel naming products, publishing model details or disclosing logic. Describing kinds and types is the statutory task, and a policy that says the organisation uses automated systems drawing on application, employment and financial information to assess loan applications, with final decisions made by staff, is closer to the mark than a paragraph of AI boilerplate.
Sequencing matters more than usual here. The OAIC intends to publish its guidance by September 2026, and the obligation commences on 10 December 2026. That leaves roughly one quarter between guidance and deadline, which is not enough time to start the inventory after the guidance arrives. The workable order is inventory now, draft disclosures against the plain words of the provisions, then adjust wording when the guidance lands.
The scope-check worksheet
For every agent, flow or AI feature the inventory surfaces, answer these in writing.
- 1What does the program produce: a draft, a recommendation, a ranking, or an actioned outcome?
- 2Does an identifiable individual's job, money, housing, insurance, healthcare or access to a significant service turn on that output?
- 3Is personal information about that individual used in the program's operation, including as retrieval context for an agent?
- 4Where a human sits in the flow, do they exercise real discretion with independent information, or confirm the program's output as a matter of routine?
- 5Who arranged for the program: your entity, or a vendor acting on your instructions? Both point back to your privacy policy.
- 6If in scope: are the kinds of personal information and the types of decisions involved described in the current privacy policy? If not, that is the drafting gap to close before 10 December 2026.
Verified August 2026 against the OAIC's consultation on guidance for transparency in automated decision making, the OAIC's ADM issues paper, White & Case's alert of 18 June 2026 and the Privacy and Other Legislation Amendment Act 2024 as published on the Federal Register of Legislation. The scope analysis for specific Copilot and agent patterns is Frontrow's operational reading of the provisions; the OAIC's guidance, expected by September 2026, is the authority to check it against.