Brad Ferris.au
The Director's LensEdition 17 · Automated Decisions

The Delegation Nobody Approved

From 10 December, Australian organisations must publish which of their decisions are made substantially by machine. Most boards have filed this as a privacy matter. It is a delegations question, and the inventory it forces is a bigger finding than the deadline.

Published24 July 2026
Read5 minutes
All editions
The Governance Story

On 20 July, iTnews reported that the Attorney-General will lead a new framework regulating automated decision-making across federal agencies, one of five AI safety priorities, with Robodebt and its 57 Royal Commission recommendations sitting behind it. Government moving to regulate its own automated decisions first is worth reading as a leading indicator rather than as a public-sector curiosity. The obligation that already reaches the rest of us is closer than that framework. From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024, APP entities must set out in their privacy policies the kinds of personal information used in substantially automated decisions, and which decisions are made that way. Most boards have filed it as a privacy matter.

It is not a privacy matter. To comply, an organisation has to produce something almost none of them currently hold: a list of the decisions it makes about people substantially by machine. Building that list is the governance event. The privacy policy that follows is the paperwork. Every board has a delegations framework, a document setting out who may decide what and up to what threshold, and nowhere in it does it say that a model may decide. Yet in most organisations of any size, automation has been amending those delegations for years, one system at a time, each change individually sensible and none of them ever put to a board. December forces the list into the open.

The second feature worth sitting with is that this is a disclosure obligation. The output is a public document. Privacy policies are read by journalists, unions, competitors, regulators and plaintiff lawyers, and after 10 December they will state which of your decisions are made substantially by machine. The size of the gap is already measured: an OAIC study this year found that of twenty-three agencies surveyed, only 17 per cent disclosed their use of automated decision-making, and not one had published guidelines on how it deploys it. An obligation that requires you to publish the answer is not a back-office task. It is the mechanism through which every other question about your automated decisions will get asked.

The duty-of-care read follows directly. The section 180 standard is the care a reasonable person in that director's position would exercise, and it scales with the role and with the regulatory environment the entity sits in. A director of an organisation making consequential automated decisions about customers or employees, in a year when a dated statutory obligation and a separate federal framework are both in motion, is expected to know broadly what those decisions are. Delegation is available to a board. Abdication is not. You can hand a decision to management, and management can hand it to a system, but the accountability stays exactly where it started.

Questions I'd Ask in the Boardroom
  • Can management give us a list this quarter of every decision we make about a customer or an employee that is substantially automated? If the honest answer is no, that is the finding, and it is a larger one than the December deadline.
  • Our delegations framework says who may decide what. Which of those delegated authorities are now, in practice, exercised by a system rather than a person, and when did this board approve that shift?
  • After 10 December our privacy policy will state publicly which decisions we automate. Read that document as an outsider would. Does it create a question we would struggle to answer from a regulator, a journalist or a former employee?
  • For each substantially automated decision, is there a human review path a real person could actually use, or is there a policy asserting that one exists?
  • The OAIC found that only 17 per cent of the agencies it surveyed disclosed their use of automated decision-making, and none had published guidelines. If that same test were applied to us, what would it find, and who inside the organisation would know before we did?
Red Flags & Watch Points
  • The December obligation sitting with the privacy or legal team alone. The disclosure is theirs to draft; the inventory behind it is a delegations question and belongs to the board.
  • An automated decision with no named owner. If nobody can say who is accountable for a decision the organisation makes thousands of times a month, the accountability has not been delegated. It has evaporated.
  • A human review path that exists on paper. Contestability that is technically available but practically unusable is the failure mode regulators find first, because complainants find it first.
  • Comfort drawn from the fact that the model only recommends. Where a recommendation is accepted in almost every case, the decision is substantially automated in effect, whatever the process diagram says.
  • Treating September as the start date because that is when guidance arrives. The obligation commences in December regardless of how helpful the guidance turns out to be, and the inventory takes far longer to build than the policy takes to write.
  • Reading Robodebt as a public-sector failure with no private-sector lesson. Strip out the politics and it was a delegation failure: a system making decisions about people at scale, with no effective human override and nobody accountable for the aggregate. That structure is available to any organisation.
Opportunity & Risk Balance

The upside is that this deadline hands a board something it has wanted and struggled to justify asking for. An inventory of automated decisions is a genuinely useful governance artefact well beyond privacy compliance. It shows where the organisation has quietly concentrated judgement into systems, which of those systems nobody owns, and where a small failure would land on a customer or an employee before anyone internally noticed. Boards have found that conversation hard to start because it sounds theoretical and slightly insulting to management. December makes it mandatory, which means there is now a reason to do the work rather than defend its absence. A board that uses the deadline as cover for the inventory gets both the compliance and the oversight.

The downside is that the disclosure arrives whether the inventory exists or not. The pressured version of this is a privacy policy drafted in November from whatever the legal team can assemble in six weeks, describing automated decisions in language vague enough to feel safe and specific enough to be wrong. That document is then public, permanent and quotable. The real exposure is not the penalty regime, serious though it is. It is that a poorly founded public statement about how your organisation makes decisions becomes the first document produced in any complaint, dispute or claim that follows, and the board will be asked what it knew about the decisions it had already published.

Director's Recommendation
My position

Put the inventory on the agenda now rather than in November, and own it as a delegations question rather than a privacy one. Ask management for a list of every decision about a customer or an employee that is substantially automated, with a named accountable owner and a usable human review path recorded against each, and treat any decision that cannot be assigned an owner as a finding in its own right rather than a gap to tidy up later. Then reconcile that list against the delegations framework this board actually approved, and decide explicitly which of these delegations you are prepared to ratify and which you are not. Do that before the disclosure is drafted, because the privacy policy should describe a position the board has taken, not a position the board discovers by reading it. The deadline is 10 December. The inventory is the work, the policy is the by-product, and six weeks is not long enough to do the first in order to write the second.

Researched and drafted by Brad's agentic AI team. Edited and published by Brad Ferris.