HomeAustraliaAI hiring compliance in Australia
Australia · Compliance

AI hiring compliance in Australia: the 2026 rulebook

Australia has no single "AI hiring law" — it has five overlapping regimes that all apply at once, and one of them starts on 10 December 2026. Here is what each actually requires of an employer using AI to screen candidates, and the checklist to hold a vendor against.

Updated 23 August 202614 min readFirstPanel research team
Key takeaways
  • From 10 December 2026, APP 1.7 requires your privacy policy to disclose automated decision-making that significantly affects a person — screening candidates is squarely inside that.
  • The Fair Work Act reverses the burden of proof: a rejected applicant only has to allege a protected attribute played a part, and you must prove it did not.
  • A rejected applicant is not bound by the 21-day dismissal clock, so the general six-year limitation period applies — your decision records must outlive it.
  • Using a vendor does not transfer liability. There is no "black box" defence: the employer answers for the screen.
  • The practical safeguard is unchanged across all five regimes — job-relevant criteria, evidence behind every score, and a named human who makes the decision.

Five regimes, one recruitment process

Australian employers keep asking which law governs AI in hiring, and the honest answer is that none of them do exclusively. Five separate regimes each catch a different part of the same screening decision, and an AI tool has to satisfy all of them simultaneously.

RegimeWhat it catchesStatus in 2026
Privacy Act 1988 (Cth)Collection, use and disclosure of candidate personal information; from APP 1.7, transparency about automated decision-makingADM transparency commences 10 December 2026
Fair Work Act 2009 (Cth)Adverse action — including refusing to employ — because of a protected attribute, with a reversed burden of proofIn force; uncapped compensation under s.545
Federal discrimination ActsRace, sex, disability and age discrimination in recruitment, plus advertising offencesIn force
State and territory anti-discrimination lawAdditional protected attributes and different thresholds by jurisdictionIn force; varies by state
NSW work health and safetyDuties on a PCBU using AI, algorithms or automation to allocate and manage workDigital Work Systems amendment passed February 2026
Sources: Privacy Act 1988 (Cth) as amended by the Privacy and Other Legislation Amendment Act 2024; Fair Work Act 2009 (Cth) ss. 351, 360, 361, 544, 545; Racial, Sex, Disability and Age Discrimination Acts.

Public-sector employers carry a sixth layer: the Australian Public Service Commission has issued principles for agency use of AI in recruitment, which APS agencies were expected to have implemented from 1 June 2026.

Privacy: the APP 1.7 transparency obligation from 10 December 2026

The Privacy and Other Legislation Amendment Act 2024 inserted a new automated decision-making transparency requirement into APP 1. It commences on 10 December 2026, which means every Australian employer running AI-assisted screening has a hard deadline to update a public document.

The trigger is deliberately broad. If you arrange for a computer program to use personal information to make — or to directly support the making of — a decision that could reasonably be expected to significantly affect an individual’s rights or interests, you are inside the obligation. Deciding who gets an interview is the canonical example regulators reach for, and the OAIC has signalled it reads "directly support" broadly rather than narrowly.

What you actually have to publish

  • The kinds of personal information used in the operation of the automated decision-making technology.
  • The kinds of decisions made solely by automated means.
  • The kinds of decisions for which the technology substantially and directly supports a human decision-maker.

Note the third limb carefully. A great many vendors and employers assume that keeping a human in the loop takes them outside the regime. It does not — it moves them from the second bullet to the third. Human review changes what you must disclose, not whether you must disclose.

The practical consequence for procurement: before December, ask every screening vendor for a written statement of exactly which personal information their model consumes, and which decisions are made or supported automatically. If they cannot produce it, you cannot write your privacy policy.

The dedicated walkthrough, including draft privacy-policy language you can adapt, is in our guide to APP 1.7 and automated decision-making.

Fair Work: the reversed burden of proof is the real exposure

Most AI-hiring compliance writing in Australia leads with privacy. That is the wrong order of risk. The general protections regime in the Fair Work Act is the provision that turns an unexplainable model into an indefensible position.

Section 351 makes it unlawful to take adverse action — which expressly includes refusing to employ — because of race, colour, sex, sexual orientation, age, physical or mental disability, marital status, family or carer’s responsibilities, pregnancy, religion, political opinion, national extraction or social origin.

Two further sections do the damage. Section 360 says an action is taken for a particular reason if the reasons merely include that reason — there is no dominance threshold, any contribution is enough. Section 361 then presumes the action was taken for the alleged reason unless the employer proves otherwise.

The six-year record-keeping floor

The 21-day clock people associate with Fair Work claims is a dismissal clock — it does not catch a rejected applicant. The general six-year limitation period in s.544 applies instead. That makes Australian record retention for hiring decisions materially longer than in most comparable markets, and it is the number your data-retention policy should be set to, not the twelve months a generic ATS defaults to.

Compensation under s.545 is uncapped, and a court may order the employer to actually employ the applicant. That combination — reversed onus, uncapped remedy, six-year window — is why the useful artefact in Australia is not a fairness dashboard. It is a per-decision defensibility record.

Liability: the vendor’s model, the employer’s problem

A recurring hope in procurement is that buying a certified tool moves the risk to the vendor. Under Australian discrimination and employment law it does not. If an automated screen filters out candidates on the basis of a protected attribute — or on a proxy for one — the employer, and in agency arrangements the recruiter, answers for it.

Commentary on the Australian position has converged on a blunt formulation: the black-box defence is dead. "The algorithm did it" is not a defence to a s.351 claim, because s.361 does not care how the reason entered the decision, only whether it did.

Where proxies actually creep in

  • Postcode and suburb, which correlate with national extraction and social origin in most Australian capitals.
  • Gaps in work history, which correlate with pregnancy, carer’s responsibilities and disability.
  • Accent, fluency and speech-rate features, which correlate with national extraction — and are a live risk for any tool scoring audio rather than transcript content.
  • Facial or emotion inference of any kind, which correlates with disability and ethnicity and is prohibited for hiring systems in the EU outright.
  • Graduation year and school-leaving date, which are age by another name.
  • Continuous availability requirements written into a screen, which catch carer’s responsibilities and religious observance.

The defensible architecture is to make the unlawful criterion impossible to configure in the first place, rather than to catch it in a quarterly audit after several hundred people have been screened by it. FirstPanel compiles hiring rules rather than accepting free text, refuses criteria that reference or proxy a protected attribute at configuration time, and scores from transcript content only — never video frames, audio features, names or postcodes.

NSW: work health and safety duties for digital work systems

In February 2026 New South Wales passed a work health and safety amendment covering digital work systems, imposing duties on a person conducting a business or undertaking that uses AI, algorithms, automation or online platforms to allocate and manage work.

Its centre of gravity is work allocation and management rather than recruitment specifically, so the direct hiring application is narrower than the privacy and discrimination regimes. Two things still matter for a TA function in NSW.

  1. 01It establishes that an automated system used on people at work is a WHS matter, not only a privacy or HR matter — which pulls a different internal function, and a different consultation obligation, into your vendor review.
  2. 02It signals the direction of Australian regulation: state-level, duty-based, and focused on the psychosocial effects of algorithmic management. Employers standing up AI screening now should expect the assurance questions asked of work-allocation systems to arrive at recruitment systems next.

Check the commencement and regulation-making detail with NSW counsel; the amendment’s operative provisions and any supporting regulations may phase in separately from assent.

Public sector: the APSC recruitment principles

The Australian Public Service Commission has published principles for agency use of AI in recruitment, which APS agencies were expected to implement from 1 June 2026. They sit on top of, not instead of, the merit principle in the Public Service Act.

For a vendor, the practical effect is that an APS buyer will ask for things a private buyer often does not: a documented statement of where AI is used in the process, evidence that the merit-based assessment remains genuinely comparative, a named delegate accountable for each decision, candidate-facing disclosure, and an accessibility path for candidates who cannot or will not use the AI channel.

If you are procuring for an agency, our dedicated page on the APSC principles maps each principle to the assurance artefact you should be asking a vendor to produce.

The compliance checklist to run a vendor through

Twelve questions. If a screening vendor cannot answer all twelve in writing, you cannot complete your own APP 1.7 disclosure or defend a s.351 claim, whatever their marketing says.

  1. 01Exactly which personal information does the scoring model receive? Ask for the field list, not a category.
  2. 02Does the model see video frames, audio features or facial data at any point in scoring? If yes, why?
  3. 03Which decisions are made solely by the system, and which substantially and directly support a human? You need both lists verbatim for APP 1.7.
  4. 04Can you produce, for any individual candidate, the questions asked, the evidence cited for each score, and the criteria the system was forbidden to consider?
  5. 05Are hiring criteria free text, or compiled against a rule set that refuses unlawful and proxy criteria before an interview runs?
  6. 06Is adverse impact monitored per requisition and before shortlists ship, or reported quarterly after the fact?
  7. 07Who is the named human decision-maker in the record, and is their rationale captured contemporaneously?
  8. 08What is the retention period for decision records, and does it reach six years?
  9. 09Where is candidate data stored and processed, and is an Australian residency option available?
  10. 10What happens when the model has insufficient evidence — does it guess, or abstain and probe?
  11. 11What is the accessibility and alternative-channel path for a candidate who cannot complete an AI interview?
  12. 12What candidate-facing disclosure and consent is presented before the interview, and is the acknowledgement recorded?
FAQ

Frequently asked

Is AI screening legal in Australia?+

Yes. No Australian law prohibits using AI to assess candidates. The obligations are about transparency, non-discrimination and the ability to explain a decision: disclose automated decision-making in your privacy policy from 10 December 2026, keep criteria job-relevant, and retain a per-decision record you could produce if a rejected applicant alleges a protected attribute played a part.

Does keeping a human in the loop remove the compliance burden?+

No, but it substantially improves your position. Under APP 1.7 human involvement changes what you disclose rather than whether you disclose. Under the Fair Work Act a named human decision-maker with a contemporaneous rationale is exactly the evidence that discharges the reversed burden of proof — provided the human is genuinely deciding and the record shows it.

How long do we have to keep AI screening records in Australia?+

Set your floor at six years. A rejected applicant is not caught by the 21-day dismissal clock, so the general six-year limitation period in s.544 of the Fair Work Act applies. Retention periods shorter than that leave you unable to defend a claim that is still live.

If our vendor’s model discriminates, are we liable or are they?+

You are, as the employer. Australian discrimination and employment law does not treat outsourcing the screen as outsourcing the duty, and there is no black-box defence. That is why vendor selection should turn on whether the vendor can hand you the evidence to defend the decision, not on whether they carry the risk.

What is the single highest-value thing to fix first?+

Per-decision records. Privacy-policy language can be drafted in an afternoon. The ability to reconstruct, for any individual candidate from up to six years ago, what was asked, what evidence supported each score and which named human decided, cannot be retrofitted — either the system captured it at the time or the record does not exist.

Bring your legal team to the pilot

Run one requisition end to end and keep the artefacts — the rule pack in force, the per-decision records, the adverse-impact report. It is the fastest way to find out whether a screen is defensible.