On 10 December, You Have to Say It Out Loud. Two colleagues at a desk in a busy daylit office, working through what a system decides and what they do when they disagree with it. By Morris Misel.

On 10 December, You Have to Say It Out Loud

Most of the organisations I work with don’t have an AI policy. I’ve spent a good part of this year telling them to write one, and the response in the room is almost always the same. Not resistance. Something closer to a blank. They’d write one if they knew what one looked like, and nobody has shown them.

In a bit over three months, that stops being a matter of good practice.

From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024, an Australian organisation covered by the Privacy Act has to add something to its privacy policy. If it has arranged for a computer program to make a decision, or to do something substantially and directly related to making one, where that decision could reasonably be expected to significantly affect a person’s rights or interests, and personal information about that person is used in the program, then it has to say so in public.

Three things have to be named. The kinds of personal information those programs use. The kinds of decisions made solely by a program. And the kinds of decisions where the program does a substantial part of the work and a person signs at the end.

Read it once and it sounds like a compliance job. Read it twice and you notice what it doesn’t ask for.

It doesn’t ask you to stop. It doesn’t ask for consent, or a fairness test, or an appeal path, or an accountable officer, or a standard the program has to meet. It asks you to write down what you’re already doing and publish it where anybody can read it.

That’s the whole obligation. And it’s going to be the hardest easy thing Australian organisations do this year.

The obligation isn’t about AI

Nearly everyone I’ve raised this with has heard it as an AI story. It isn’t, and the gap between those two readings is where the trouble sits.

The words in the legislation are “a computer program”. That’s deliberately wide. It takes in the AI tool somebody licensed in March. It also takes in the scoring rule written in 2014 that nobody has looked at since, the eligibility logic inside a system that predates everyone currently working on it, the automated assessment your vendor switched on in an upgrade, and the spreadsheet a departed staff member built that three teams still run their numbers through.

This matters more than it looks, and it’s the reason I keep pulling machines and AI apart when everyone else runs them together as one word.

HUMAND separates them on purpose. Humans, Machines, AI, Navigation, Design. A machine is deterministic. Give it the same inputs and it returns the same answer, every time, and if the answer is wrong it’s wrong the same way for everybody, forever, until somebody changes the rule. AI is probabilistic. Give it the same inputs and it may not return the same answer, its confidence and its accuracy are different things, and it fails unevenly and quietly.

Those two things need different governance, different checking, and different lines drawn around them. Treating them as one category is how organisations end up applying AI-grade scrutiny to a new chatbot while a fifteen-year-old rule quietly decides who gets a payment plan.

The disclosure obligation makes no such distinction. It captures both. So an organisation that scopes this as an AI exercise will produce a list of the things it bought recently and miss most of what actually decides.

Start from the decision, not the technology. That’s the whole trick.

The list is the hard part

To publish the kinds of personal information your programs use, you first have to know which programs those are. To publish the kinds of decisions they make, you have to know what they decide. Not what they were bought to do. What they decide now, in practice, where the work happens.

I’ve yet to sit in a room where that list existed as a document.

Not because anybody has been careless. Because nothing has ever required the list to exist, and the way these tools arrived made it nobody’s job to hold one.

Think about how the past three years actually went. A team found something that took a job from four hours to twenty minutes, so they used it. Somebody in a different part of the building found something else for a different job, and that worked too. A vendor upgraded a system that had been in the business for a decade and the upgrade arrived with a scoring feature switched on by default. A finance platform started ranking. A recruitment system started ordering. A service desk started triaging.

None of that was a decision to automate decisions. Every step of it was somebody doing their job well, at the level of the work, with what was in front of them. The sum of all those small sensible steps is an organisation that now decides a great deal without people, and has no register of where.

That’s allocation drift, and it’s exactly what the HUMAND question exists to catch. Which work belongs with humans, which with machines, which with AI, and which with a combination. Most leaders treat it as a question they’ll get to. Their organisation has been answering it continuously, task by task, at the level of whoever was closest to the work, for three years. The answers are already in the building. Nobody has been holding the total.

On 10 December, the total is what gets published.

The individuals are further ahead than the organisation

There’s a pattern I keep coming back to, and it shows up the same way whether I’m sitting with financial services, with education, or with local government and the small businesses that ring it.

The individuals are further ahead than the organisation. Not marginally. Consistently.

The people doing the work have found uses that are more specific, more sophisticated and more embedded than anything in the organisation’s own strategy. They know what the tool is good at. They know where it lies to them. They’ve built small private protocols for checking it, which they’ve never been asked about and never written down. They know things about the organisation’s exposure that the organisation doesn’t know about itself.

And in every one of those settings, the response to that gap has been to run training.

Training looks reasonable. It’s visible, it’s budgetable, it reports well to a board, and it produces an attendance list. It also answers a question nobody asked. Training addresses capability, and capability isn’t the gap. The people are already capable. That’s the finding being described.

The gap is authority. Nobody has said where a program’s answer is sufficient and where it isn’t, so everybody has decided for themselves, sensibly, in isolation, at pace, and alone.

That isn’t a workforce problem. It’s an unmade decision. And while it stays unmade it gets made hundreds of times a week by people who were never asked to make it and are carrying it without cover. I set the shape of this out in When AI Is in the Room, Who Is Actually Deciding?, and in AI Is Not Replacing Judgement. It’s Exposing Where It’s Missing. The question sounds abstract right up until somebody tries to answer it about one real process, and then it gets very concrete very fast.

What the disclosure actually exposes

This is an Immediate Futures matter rather than a date in a compliance calendar, and the reason is that the obligation works like a mirror. It makes an organisation describe itself in public, in words a customer or a parent or a ratepayer can read. The moment you try to write that description honestly, three things surface that were never on anybody’s agenda.

You find programs you didn’t know were deciding. Something described internally as a flag, a score, a priority order or a recommendation turns out, when you follow it downstream, to determine the outcome almost every time. The human signature at the end is real. The person providing it hasn’t overturned the result in eleven months, and everybody in the process knows it.

You find decisions with no owner. Ask who decides whether a threshold moves and you get a name. Ask who decided that this should be decided without a person at all, and you get a pause. Those are different questions and the second one has usually never been asked out loud.

And you find that the description you’d have to publish isn’t the description your own people would give. That gap, between what an organisation believes about itself and what the work looks like at the coalface, is the most reliable predictor I know of a trust problem arriving later. I’ve written about how that ends in When Trust Breaks Down in Organisations, It’s Never the Trust That Broke. Trust rarely collapses over one bad decision. It collapses when people find out that something they thought was decided one way has been decided another way for a long time, and nobody told them. That’s a Trust Cliff, and publication is the moment the edge becomes visible to everyone at once.

The ripple effects nobody has costed

Disclosure looks like a documentation task. It isn’t, because publication changes who can see.

Right now the way your organisation decides is known in fragments. The team knows their part. The vendor knows theirs. The privacy officer maintains a register. Nobody holds the whole, and because nobody holds the whole, nobody outside can compare.

Publish and that changes on one day, across a whole economy, for every covered organisation simultaneously.

Your customers can read it. So can your competitors, the journalist writing about your sector, the union across the table, the regulator deciding where to look, the lawyer taking instructions from someone who believes they were treated unfairly, and the candidate who never got the interview. None of them needed a new right. They needed the list, and now the list exists.

These are Ripple Effects, and they run further than the first order.

The second order is comparison. When one organisation in a sector publishes something careful and specific and another publishes something vague, the vague one doesn’t read as cautious. It reads as sloppy or evasive, and neither is recoverable quickly. The first honest disclosure in a sector sets the floor for everybody else, and it’ll be set by somebody who isn’t thinking about you when they set it.

The third order is internal, and it’s the one I’d watch from a board seat. The published description becomes the standard your own people hold you to. If the policy says a person reviews every adverse outcome, then every instance where that review is a formality becomes a live gap between what you say and what you do. Your staff will notice first. They always do. They’re the ones performing the formality.

Most of the leadership problems I see aren’t new problems. They’re the consequences of decisions that looked reasonable at the time and were never followed far enough forward.

What I’d do with the time that’s left

There are a bit over three months. That’s a real preparation window, and it’s short enough that anyone starting in November will be writing a description under pressure rather than deciding anything.

Four moves, in this order.

Build the list before you write the policy. Not a survey. A walk. Go to the places where decisions about people actually happen, credit, enrolment, eligibility, rostering, triage, hiring, complaints, pricing, enforcement, and ask the person doing the work what the system gives them and what they do with it. You’ll find things that appear in no procurement record, because they arrived as features rather than purchases. The list is the deliverable. Everything else follows it.

Sort by consequence, not by technology. It doesn’t matter whether the answer comes from a large language model, a rule written in 2014 or a spreadsheet somebody left behind. The legislation is deliberately broad and so should you be. What matters is how much of a person’s life turns on the answer. Sort that way and the top of your list will look nothing like the top of your AI project register.

Above your consequence line, make the authority explicit. This is where Decision Trust Zones does the work. For each decision, name where the program’s answer is sufficient on its own, where it’s an input a person weighs, and where you won’t let it near the call at all. Write the lines down. Then tell the people currently making that judgement privately that the organisation has now made it for them. That single act removes more risk than any amount of training, because it converts hundreds of isolated private decisions into one the organisation owns.

Then write the policy, in language somebody outside your industry can read. This is where most organisations will lose ground they didn’t need to lose. A disclosure written in the vocabulary of your internal systems technically complies and publicly reads as concealment. A disclosure written plainly reads as an organisation that knows what it’s doing. They cost the same to produce. Only one of them earns anything.

The confidence problem underneath it

Something I’ve written about before is going to make this harder than it looks.

Leaders are consistently more confident about their organisation’s readiness than the evidence supports. I set that out at length in Confident But Unprepared, and this obligation will test it unusually publicly, because for the first time the readiness claim has to be written down, signed, and left where anyone can check it.

The risk isn’t that organisations fail to publish. Most will publish. The risk is that they publish a description assembled from what leadership believes is happening, without the walk that would have told them what’s actually happening. That document will be wrong in ways nobody in the executive can see and several people below them can. And it will sit on a website as a standing public statement about how the organisation decides.

There’s no version of this where the honest list is the more expensive option. The honest list costs a few uncomfortable months in 2026. The confident guess costs you the day somebody demonstrates it was wrong.

The part worth wanting

I’d rather not leave this as a compliance story, because that’s the framing every piece of coverage has taken and it’s the framing that gets organisations to do the minimum.

This is the first time an Australian organisation has had a legitimate, externally imposed, calendar-bound reason to find out what it actually decides without a person in the loop. Not what it planned to. What it does.

Most change programmes would take that deal in a heartbeat. You normally have to manufacture the mandate, argue the budget, and convince forty people that a mapping exercise is worth their week. Here the mandate is legislated, the date is fixed, and nobody has to be persuaded that it matters. The work you’d want to do anyway, mapping where judgement sits, naming where authority lies, closing the distance between what the organisation says about itself and what its people experience, is the same work the obligation requires.

Organisations that treat 10 December as a publishing deadline will publish something on 10 December.

Organisations that treat it as the walk they’ve been putting off will come out of it holding something they’ve been missing for three years: an accurate description of how they decide. That’s worth more than the compliance. It’s what every other decision about AI in that organisation should have been resting on and hasn’t been.

And it’s where the AI policy comes from. Not from a template, and not from a lawyer’s precedent. From the list. Write down what you decide without a person, decide which of those you’re comfortable with, and the policy writes itself out of the answers. That’s why I’ve been telling people to start one. This just gives them the deadline I couldn’t.

Start the walk this week. Take somebody who does the work rather than reports on it. Ask them what the system tells them, and what they do when they disagree with it.

You’ll know inside an hour whether your organisation is ready to say this out loud.

Choose Forward.

Sources

Frequently Asked Questions

What changes on 10 December 2026 under Australian privacy law?

From 10 December 2026, organisations covered by the Privacy Act must state in their privacy policy that they use computer programs to make, or substantially contribute to, decisions that significantly affect a person's rights or interests where personal information is used. They must name the kinds of personal information involved, the kinds of decisions made solely by a program, and the kinds of decisions where a program does a substantial part of the work. The obligation was created by the Privacy and Other Legislation Amendment Act 2024, which received assent on 10 December 2024, and the OAIC can issue infringement and compliance notices for a privacy policy that doesn't meet it.

Does the automated decision-making disclosure only apply to AI?

No. The legislation refers to a computer program, which is deliberately broad. It captures AI systems, rule-based tools, legacy scoring logic and automated assessment technologies alike. An organisation that scopes the work as an AI exercise will miss most of what actually decides, because much of it predates the current wave of AI tools entirely.

What is the difference between a machine decision and an AI decision?

A machine decision is deterministic. The same inputs return the same answer every time, and if it's wrong, it's wrong in the same way for everyone until someone changes the rule. An AI decision is probabilistic. The same inputs may return different answers, confidence and accuracy are separate things, and failures are uneven and quiet. The HUMAND framework separates humans, machines and AI for exactly this reason: they need different governance and different lines drawn around them.

Why can't most organisations produce a list of their automated decisions?

Because nothing has ever required the list to exist. Automated decision-making accumulated task by task, through tools individual teams adopted, vendor upgrades that switched features on by default, and legacy logic nobody has revisited. Every step was reasonable in isolation. Nobody was holding the total. Morris Misel calls this allocation drift.

What should an organisation do before 10 December 2026?

Four things, in order. Build the list by walking the places where decisions about people are made and asking the people doing the work, rather than sending a survey. Sort the list by how much of a person's life turns on the answer, not by which technology is involved. For everything above that line, use Decision Trust Zones to name where a program's answer is sufficient, where it's an input a person weighs, and where it isn't allowed near the decision. Then write the policy in plain language a reader outside the industry can understand.

Is this the same as an AI policy?

No, but it's where an AI policy should start. The disclosure forces an organisation to produce an accurate description of what it currently decides without a person in the loop. Once that list exists and the organisation has decided which of those decisions it's comfortable with, the policy follows from the answers rather than from a template. —


Where this goes next

If your organisation is starting the walk before 10 December, the useful conversation isn’t about the disclosure. It’s about where authority sits once you can see the list. That’s part of the work I do with boards and leadership teams, and it’s what I take onto a stage.

Book Morris for a keynote, board session or workshop

Every week I publish Glimpses from the Future, short reads on the signals already arriving and what they ask of leaders. Subscribe here.


About Morris Misel

Morris Misel is a foresight strategist and keynote speaker based in Melbourne, Australia. With 30+ years of experience working with leaders, boards, associations, and organisations across Australia and internationally, Morris works with people to prepare for uncertainty, interpret signals, and make better strategic choices.

His work is grounded in several proprietary frameworks including HUMAND (a decision model for human, machine and AI work allocation), PTFA (Past Trauma, Future Anxiety), Ripple Effects (second and third-order consequence mapping), and Immediate Futures (what is already arriving and needs attention now).

Morris speaks regularly on the future of work, leadership in uncertainty, AI strategy, and organisational foresight. He is a regular guest on RTHK Radio 3 (Hong Kong) and has appeared across Australian and international media.

Learn more: morrisfuturist.com | morrismisel.com

Leave a comment