Australia's $50m Privacy Penalty Regime Arrives
The AI regulatory landscape across Australasia has shifted decisively. In the space of twelve months, both Australia and New Zealand have moved from broad policy discussion to concrete legal obligations, expanded enforcement powers, and formal guidance that directly affects how organisations deploy
Australia and New Zealand's 2024–25 AI Compliance Overhaul: What Professional Services Firms Must Know
The AI regulatory landscape across Australasia has shifted decisively. In the space of twelve months, both Australia and New Zealand have moved from broad policy discussion to concrete legal obligations, expanded enforcement powers, and formal guidance that directly affects how organisations deploy AI systems and handle personal data. For international professional services firms and global enterprises operating in or serving clients across these jurisdictions, the window for a passive, wait-and-see approach has closed.
This briefing sets out what has changed, what is coming, and what your organisation needs to do.
Australia: Privacy Reforms With Real Enforcement Teeth
The Privacy and Other Legislation Amendment Act 2024 represents the most significant overhaul of Australian privacy law in years. Key provisions took effect in late 2024, with further changes active by June 2025. The reforms clarify that organisations must take 'reasonable steps' to protect personal information — a standard that now explicitly encompasses both technical and organisational measures. For AI-deploying businesses, this is directly consequential: it means security and governance controls around AI systems are no longer best practice, they are a legal baseline.
The Office of the Australian Information Commissioner (OAIC) has emerged from these reforms considerably stronger. It can now issue infringement and compliance notices and pursue civil penalties of up to AUD 50 million, or 30% of a company's adjusted turnover, for serious or repeated breaches. A statutory tort for serious invasions of privacy, effective from 10 June 2025, adds a further dimension: individuals may now seek legal redress for emotional harm caused by privacy violations without needing to demonstrate economic loss. The OAIC has already demonstrated its intent to act, commencing civil penalty proceedings against Medibank in June 2024 over its 2022 data breach.
The message here is unambiguous. Australia is no longer a jurisdiction where privacy non-compliance carries largely reputational risk. The financial exposure is material, and the regulator is active.
Automated Decision-Making: A Transparency Obligation on the Horizon
One of the most operationally significant developments for AI-using organisations is the incoming automated decision-making transparency requirement. From 10 December 2026, organisations must disclose in their privacy policies when personal information is used in automated processes that significantly affect individuals. The disclosure must cover the types of information involved and the nature of the decisions being made.
This is not an abstract future concern — preparation needs to begin now. Organisations will need to audit their AI and automated systems to identify where personal data feeds into consequential decisions, update privacy documentation accordingly, and establish processes for maintaining those disclosures as systems evolve. For firms operating globally, this requirement sits alongside analogous obligations under the EU AI Act and similar frameworks, making a consolidated, jurisdiction-aware disclosure strategy the only sensible approach.
OAIC Guidance: Obligations for Both AI Users and Developers
In October 2024, the OAIC published dual guidance notes targeting AI product users and AI developers separately — a distinction that matters for professional services firms, many of whom occupy both roles simultaneously. For users, the guidance addresses obligations around what personal data is input into AI systems, what the outputs generate, and the need for human oversight to be genuinely integrated rather than cosmetic. For developers, the OAIC has been explicit about the risks associated with training generative AI models, stressing lawful data collection, accuracy, and purpose limitation under the Australian Privacy Principles.
The OAIC's regulatory priorities for 2025–26 name AI-driven erosion of privacy rights as a direct target, with facial recognition among the technologies under scrutiny. Firms building or procuring AI solutions with biometric or behavioural data components should treat this as a clear signal of where enforcement attention is heading.
Australia's Broader AI Regulatory Direction
Australia's path to AI-specific legislation has not been linear. Following an interim response to its 'Safe and Responsible AI' consultation in January 2024, a Proposals Paper published in September 2024 outlined potential mandatory guardrails for high-risk AI. Initially, Australia declined to pursue a standalone AI Act, opting instead for a voluntary framework. However, in July 2026 Prime Minister Albanese announced plans to legislate Australian Standards for AI, establish a dedicated Office of AI, and introduce mandatory requirements for large AI data centres and training runs — with legislation expected in early 2027.
For global enterprises, this trajectory matters. Organisations that invest now in adaptable AI governance frameworks — rather than point-in-time compliance fixes — will be better positioned as mandatory requirements crystallise. Australia's evolving stance also reflects a broader international pattern: voluntary frameworks are proving to be staging posts, not final destinations.
New Zealand: Principles-Led, But Increasingly Specific
New Zealand has taken a deliberately different architectural approach to AI governance, integrating expectations into existing legal structures rather than enacting a standalone AI law. The government's strategy document, 'New Zealand's Strategy for Artificial Intelligence: Investing with Confidence,' published on 8 July 2025, alongside MBIE's 'Responsible AI Guidance for Businesses,' reinforces this model. The Public Service AI Framework, introduced in February 2025, sets expectations for government agencies that will inevitably shape what the private sector faces as a counterparty and supplier.
The most immediate concrete obligation for businesses is the Biometric Processing Privacy Code 2025, issued in July 2025 and operative from 3 November 2025. This Code introduces specific requirements around the collection, use, and storage of biometric information under New Zealand's Privacy Act 2020. For any organisation deploying facial recognition, voice identification, or other biometric tools in New Zealand — whether for client onboarding, workforce management, or security — this is a compliance event requiring immediate attention.
What This Means for Internationally Operating Firms
For professional services firms and global enterprises, Australasia's 2024–25 reforms do not sit in isolation. They form part of an accelerating international convergence around several core principles: transparency in automated decision-making, meaningful human oversight of AI, purpose limitation in data use, and proportionate governance of high-risk applications.
Firms that have invested in EU AI Act readiness will find significant structural overlap with what Australia and New Zealand now expect. However, the specific thresholds, enforcement mechanisms, and disclosure requirements differ enough to require jurisdiction-specific implementation. A compliance programme that treats Australasia as an afterthought to European obligations is one that carries unquantified risk.
The practical priorities are clear: audit AI systems against the OAIC's guidance framework; review privacy policies for the 2026 automated decision-making disclosure requirement; assess biometric processing activities against New Zealand's new Code; and ensure that procurement and third-party AI vendor contracts reflect the accountability expectations now embedded in both jurisdictions.
How Ops Intel Can Help
Navigating AI compliance across multiple jurisdictions requires more than an awareness of individual regulations — it requires a structured, scalable approach that keeps pace with regulatory change without creating operational paralysis.
Ops Intel works with international professional services firms and global enterprises to build AI compliance programmes that are practical, jurisdiction-aware, and built for longevity. Whether you need a gap analysis against Australian and New Zealand requirements, support preparing for the 2026 automated decision-making disclosures, or a consolidated multi-jurisdictional AI governance framework, our team is ready to help.
Contact Ops Intel today to arrange a compliance assessment and ensure your AI obligations across Australasia — and beyond — are fully under control.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.