Agentic Institute · Guide · Australia and the European Union

AI transparency for firms using agents: Australia and the EU

What Australia's automated-decision transparency rules and the EU AI Act mean for the agents your firm runs - and where to start.

Two regimes, one starting point: know where your agents make or inform decisions about people. The Australian column below is about the Privacy Act and the guidance of the Office of the Australian Information Commissioner (OAIC), Australia's privacy regulator; it concerns Australia only. The EU column is about Regulation (EU) 2024/1689, the EU AI Act. Each is shown dimension by dimension, so you can read one column or compare both.

As at 8 Oct 2026. General information, not legal advice.

Two regimes, side by side

Australia and the European Union, dimension by dimension

Left: Australia, under the Privacy Act, with the OAIC's guidance. Right: the European Union, under the EU AI Act. Read down one column, or across a row.

1 · Who it covers, and from when

Australia · Privacy Act

Organisations covered by the Australian Privacy Principles

From 10 December 2026, organisations covered by the Australian Privacy Principles must include information in their privacy policy when they have arranged for a computer program to make a decision, or to do something substantially and directly related to making one, that could reasonably be expected to significantly affect an individual's rights or interests, and personal information about that individual is used.

European Union · AI Act

Providers and deployers, inside the EU and sometimes beyond

The Act can also reach organisations outside the EU where an AI system's output is used in the EU (Article 2(1)(c)); whether that applies to your work is a question for your lawyer.

Article 50 transparency duties have applied since 2 August 2026, for example where a provider's AI system interacts directly with people.

2 · What it asks of you

Australia · Privacy Act

Say it in your privacy policy

The policy must describe the kinds of personal information used, the kinds of decisions made solely by computer programs, and the kinds of decisions where a program does something substantially and directly related to making them.

European Union · AI Act

Literacy is the floor

Since 27 July 2026, Article 4 of the EU AI Act asks providers and deployers to take measures to support the AI literacy of their staff and others using AI systems on their behalf; it does not require a guaranteed level of AI literacy.

3 · What the regulator says

Australia · OAIC guidance, Sep 2026

The Office of the Australian Information Commissioner

The OAIC is Australia's federal privacy regulator. Its September 2026 guidance on these rules says:

The OAIC says "computer program" includes rule-based processes, machine learning and generative AI, including chatbots.

Buying, configuring or relying on a third-party program can count as having "arranged for" it.

European Union · European Commission

Agents are already inside the Act

The European Commission's AI Act Service Desk answers the agent question directly:

The European Commission says AI agents are not a separate legal category under the Act; its existing definitions cover them.

4 · Human review and oversight

Australia · OAIC guidance, Sep 2026

Review is not an exit

Human review alone doesn't take a decision out of scope: the OAIC says a decision may be in scope even where the program's output is subject to human review.

The OAIC's examples include recruitment software that sorts candidates and AI-generated reports used to rank employee performance or set bonuses.

European Union · AI Act

Oversight is the ceiling

For high-risk uses listed in Annex III, from 2 December 2027, deployers must assign human oversight to people with the necessary competence, training and authority (Article 26(2)).

5 · Limits, and when you are unsure

Australia · Privacy Act

Take the cautious path, with your lawyer

Where an organisation is unsure, the OAIC suggests taking a cautious approach and including the information.

Whether these rules apply to your organisation, and what your privacy policy says, is for you and your lawyer to decide. Some organisations may be exempt from the Privacy Act.

European Union · AI Act

What this page leaves out

Not covered: provider technical documentation, quality management systems, conformity assessment, CE marking, registration and general-purpose AI model duties (EU AI Act Articles 11, 17, 43, 48, 49 and 53-55).

Both regimes · Where to start

Start with an inventory, not a policy draft

An engineering view of the first steps, the same on both sides. Your lawyer or privacy officer decides what you disclose.

Step 1

List

List every agent and AI tool you built, bought or configured.

Step 2

Mark

Note which ones make or inform decisions about people, and what personal information each uses.

Step 3

Record

Record who reviews each output before it affects someone, and keep the record.

Step 4

Test

Have someone who didn't build or configure the agent test it, including the human override.

Step 5

Ask

Ask your vendors for the clear, high-level information the OAIC says they should give about how their software can be used to make decisions.

Step 6

Hand over

Take the list to your lawyer or privacy officer. In Australia, the OAIC's flowchart (under Sources) is the tool they will use.

Oversight is only as real as its records. It is evidence of how you work, not a way around disclosure.

The floor

EU AI Act Training

AI literacy for every staff member, and briefings for boards.

See EU AI Act Training →
The crosswalk

How the eight principles map to both regimes

Each Manifesto principle has an evidence test. This map shows where the record each test leaves can help, in Australia and under the EU AI Act. This map is engineering input: it shows where a record can help, not that any obligation is met.

PrincipleThe record its test leavesUseful in Australia forUseful under the EU AI Act for
01 Augmentation over AutomationWhat each agent does in a decision: decides, recommends, drafts or nothingSeeing which decisions a program makes or informsWho oversees high-risk uses (Art 26(2))
02 Bounded AdaptabilityThe inputs each agent is allowed to useThe kinds of personal information usedSpotting changes of purpose that can change your role (Art 25)
03 TransparencyWhat people are told, and the inputs your privacy officer needsDrafting inputs for the privacy policyTransparency duties (Art 50)
04 Human-Centred DesignWho is affected, and howInput to whether an effect is significant - your lawyer decidesThe context of use your literacy measures consider (Art 4)
05 Accountable CollaborationOwner, supplier, and built, bought or configured, per agentWhether you "arranged for" a programProvider or deployer role (Arts 3 and 25)
06 Responsible OperationTool and credential inventory; prohibited-use screenWhich agents touch personal informationThe prohibited practices screen (Art 5)
07 Paced ImprovementA change log with a re-check triggerKeeping the policy current when tools changeMonitoring high-risk uses (Art 26(5))
08 Verified TrustBuilder-evaluator separation, override test, sign-offEvidence of the oversight you describeOversight and log records for high-risk uses (Art 26(2), 26(6)); your Article 4 measures log

Scroll the table sideways on a phone.

How we can help

Four steps, in order

StepOfferStatusLink
1 · ReadAI Agents Manifesto + Agent Evidence Index (free)FreeGet the Manifesto →
2 · LearnAgentic Institute: Foundations, Practitioner, EU AI Act Training, bring-your-own-agent workshopRegister interestSee the Agentic Institute →
3 · ApplyHealth Check - decisions about peopleEnquiryEnquire →
4 · OwnFractional Chief AI OfficerBook a callSee Fractional CAIO →

A fixed-scope Health Check that finds where your agents and tools inform decisions about people and records the oversight you have, checked by someone who didn't build them, so your lawyer can decide what your privacy policy needs to say.

We don't review agents that Netlifestyle AI or a related party built. Pricing on enquiry.

Need to make the case inside your firm? The champion kit is a one-page brief for the person who signs off on AI.

For lawyers and advisers

If you advise organisations on this

Disclosures start with facts: which programs inform decisions about people, what personal information they use, and what oversight actually happens. We document those facts, checked by someone other than the builder, for your client and for you. We don't give legal advice, classify decisions or draft policy wording.

We have no referral arrangement with any law firm.

What this page is not

General information, not legal advice

General information about APP 1.7-1.9 and the EU AI Act as at 8 Oct 2026, based on the OAIC and European Commission sources linked below. It is not legal advice, and it does not tell you whether an obligation applies to you. Our training, kits and reviews can help you build records others can check; they do not make an organisation compliant.

How we apply this to ourselves: How Netlifestyle AI uses AI.

Sources and page history

Sources

Australia: the Office of the Australian Information Commissioner (OAIC). European Union: EUR-Lex and the European Commission.

Page history: 8 Oct 2026 first published. Every regulatory sentence on this page was reviewed by an external legal adviser before publication.