{"resourceId":"australia-adm-transparency-audit","versions":[{"version":"legacy/2026-09-02/australia-adm-transparency-audit","resource":{"id":"australia-adm-transparency-audit","title":"Australian audit finds automated decision-making authority far more visible than actual government use","organization":"Office of the Australian Information Commissioner","sector":"Federal public administration and digital services","geography":"Australia","publishedAt":"January 21, 2026","sourceName":"Automated decision-making and public reporting under the Freedom of Information Act","sourceLabel":"Australian Information Commissioner review","sourceUrl":"https://www.oaic.gov.au/freedom-of-information/information-commissioner-decisions-and-reports/foi-reports/Automated-decision-making-and-public-reporting-under-the-Freedom-of-Information-Act","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["developers-agents","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"The Australian Information Commissioner reviewed the websites, AI transparency statements, and publication plans of 23 federal agencies authorized by law to use automated decision-making. Only four agencies, 17%, disclosed in their publication-scheme information that they used ADM in decisions affecting the public; nine more referenced ADM without confirming use, and ten did not mention it.","sledRelevance":"The review is newly relevant as Australian public-sector workers press for stronger, enforceable automated-decision safeguards. It shows why a public AI inventory must cover rules engines, calculators, machine learning, and recommendations—not only systems labeled AI—and why affected people need plain-language notice and review rights.","evidence":"The regulator used defined website search procedures and external evidence to test what a member of the public could reasonably discover. It found examples in which agencies described what AI did not do while failing to state what automation did do. The report recommends disclosing statutory authority, actual use, decision types, examples, and governing policies.","architectureImplications":"Maintain a decision-system register linked to statutory authority, service, inputs, business rules or model, human review, appeal path, vendor, and deployed version. Public disclosures should be generated from the same operational inventory used for access control, monitoring, change management, and incident response.","governanceImplications":"Require plain-language notice, examples, and review paths for systems that affect rights or interests. Inventory all automated decisions regardless of marketing label, assign accountable owners, and make change review and public disclosure part of deployment rather than an after-the-fact communications task.","securityPrivacyImplications":"Record data provenance, accuracy checks, personal-information use, role access, retention, and the influence of each automated output on a final decision. Transparency should enable contestability without exposing security-sensitive details or creating new privacy risks.","caveats":"This January report is reused because September 2 workforce pressure made its findings newly relevant; it is not newly published evidence. The desktop review assessed public discoverability, not system accuracy, legality, fairness, or even confirmed use in every authorized agency. Authority to automate does not prove that an agency actually automated decisions."}},{"version":"enrichment/2026-09-05T02:42:45.193Z/australia-adm-transparency-audit","resource":{"id":"australia-adm-transparency-audit","title":"Australian audit finds automated decision-making authority far more visible than actual government use","organization":"Office of the Australian Information Commissioner","sector":"Federal public administration and digital services","geography":"Australia","publishedAt":"January 21, 2026","publicationDate":"2026-01-21","eventDate":null,"sourceName":"Automated decision-making and public reporting under the Freedom of Information Act","sourceLabel":"Australian Information Commissioner review","sourceUrl":"https://www.oaic.gov.au/freedom-of-information/information-commissioner-decisions-and-reports/foi-reports/Automated-decision-making-and-public-reporting-under-the-Freedom-of-Information-Act","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["developers-agents","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"The Australian Information Commissioner reviewed the websites, AI transparency statements, and publication plans of 23 federal agencies authorized by law to use automated decision-making. Only four agencies, 17%, disclosed in their publication-scheme information that they used ADM in decisions affecting the public; nine more referenced ADM without confirming use, and ten did not mention it.","sledRelevance":"The review is newly relevant as Australian public-sector workers press for stronger, enforceable automated-decision safeguards. It shows why a public AI inventory must cover rules engines, calculators, machine learning, and recommendations—not only systems labeled AI—and why affected people need plain-language notice and review rights.","evidence":"The regulator used defined website search procedures and external evidence to test what a member of the public could reasonably discover. It found examples in which agencies described what AI did not do while failing to state what automation did do. The report recommends disclosing statutory authority, actual use, decision types, examples, and governing policies.","architectureImplications":"Maintain a decision-system register linked to statutory authority, service, inputs, business rules or model, human review, appeal path, vendor, and deployed version. Public disclosures should be generated from the same operational inventory used for access control, monitoring, change management, and incident response.","governanceImplications":"Require plain-language notice, examples, and review paths for systems that affect rights or interests. Inventory all automated decisions regardless of marketing label, assign accountable owners, and make change review and public disclosure part of deployment rather than an after-the-fact communications task.","securityPrivacyImplications":"Record data provenance, accuracy checks, personal-information use, role access, retention, and the influence of each automated output on a final decision. Transparency should enable contestability without exposing security-sensitive details or creating new privacy risks.","caveats":"This January report is reused because September 2 workforce pressure made its findings newly relevant; it is not newly published evidence. The desktop review assessed public discoverability, not system accuracy, legality, fairness, or even confirmed use in every authorized agency. Authority to automate does not prove that an agency actually automated decisions.","streamIds":["state-government"],"roles":{"sales":"Interpretation — Problem and stakeholders: Service leaders, legal teams, records officers, auditors, and engagement staff may disclose AI principles while residents cannot discover actual automated decisions or review rights. Discovery: Does public information distinguish authority from real use, and can affected people find meaningful appeals? Value hypothesis: Linking plain-language disclosures to operational records could improve discoverability and accountability. Potential engagement: Review selected rights-affecting services and test what a resident can find and contest. Evidence boundary: The Australian desktop audit concerns public reporting, not accuracy, legality, fairness, or confirmed automation everywhere. January findings were reused for later relevance; neither their publication date nor Australian requirements should be presented as new local obligations or current U.S. legal advice.","engineering":"Interpretation — Fit: Include rules engines, calculators, machine learning, and recommendations affecting public decisions regardless of AI branding. Architecture: Link service, authority, actual use, inputs, version, vendor, human review, and appeals in operational inventory, publishing an approved plain-language view. Prerequisites: Service-owner confirmation and legal/records review of disclosure. Constraints: Authority does not establish deployment; mark unknown status rather than infer it. Security: Protect personal and security-sensitive details while exposing enough for contestability. Proposed validation: Trace selected disclosures to deployed records, test updates after changes, and ask resident reviewers to locate examples and human review. Verify internal provenance and access controls without publishing sensitive case files or implying that discoverability proves decision quality.","delivery":"Interpretation — Work and dependencies: Inventory automated decisions, confirm use, write service-specific notices, and connect maintenance to deployment and change processes. Ownership: Programs attest operation; legal and records review authority and publication; appeal teams maintain channels; communications tests clarity. Skills and adoption: Train contributors to include non-AI automation and frontline staff to explain review paths. Governance checkpoints: Review disclosure before changes and periodically verify public discoverability. Proposed acceptance: Sampled records distinguish authorization from use, examples remain current, and users reach empowered reviewers through published routes. Risks: Accurate internal inventory can remain inaccessible to residents, while excessive disclosure can expose sensitive details; reporting findings must not be overstated as evidence of system performance or fairness."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:42:45.193Z","enrichmentBasis":"archived evidence"}}]}