04 / 06

Share essential information

Be open — with workers, clients, subcontractors, and regulators — about when AI is being used, what it does, and what its limitations are. Maintain a complete register of every AI system in operation. From December 2026, selected disclosures are mandatory under the Privacy Act.

Mandatory — Dec 2026 Privacy Act deadline Accountable parties: DPO, Communications, IT, Procurement
Pillar explained

What this pillar requires from your organisation.

Transparency about AI use is not a courtesy — from December 2026, it is a legal requirement. The Privacy Act amendments will mandate that organisations using automated decision-making processes disclose this to affected individuals in plain language. That means your workers, subcontractors, and clients have a right to know when AI is influencing decisions that affect them.

The Centralised Enterprise AI Register is the foundational document for this pillar. It is a mandatory inventory of every AI system in operation — its purpose, the data it uses, its known limitations, the risk assessment outcome, and who owns it. Without this register, you cannot demonstrate compliance with any of the transparency requirements, and you cannot respond credibly when a principal asks what AI you are using on their project.

Transparency obligations extend to your supply chain. If you require transparency from your AI vendors — and Pillar 03 says you must — then your principal has a right to expect the same from you.

December 2026 is not a distant deadline. Privacy Act compliance work typically takes six to twelve months. The time to start is now.
Privacy Act amendments — mandatory from December 2026
Contractor scenario — Principal audit

When a principal asks what AI you use on their project

During a project audit, your principal requests a list of all AI tools in use on their contract — the purpose of each tool, the data it accesses, and how outputs are reviewed before use. Without a current AI Register you cannot answer this question. Without one, you are not just non-compliant with AI6 — you are unable to demonstrate that your project governance is fit for purpose.

Contractor scenario — Workforce

When workers are not told AI is monitoring their performance

Your HSEQ platform uses AI to analyse site observation data and generate individual worker risk scores. Workers are not told this is happening. From December 2026, this is a privacy law breach — not just a governance gap. Plain-language disclosure of automated decision-making affecting workers is mandatory. The AI Register, privacy policy, and worker communications must all be updated before the deadline.


AI register — required fields

What the Centralised Enterprise AI Register must contain

The register must cover every AI system in operation — including AI features within commercial software platforms. This is a sample of the mandatory fields. Full template available in the audit pack.

Enterprise AI Register — sample record
FieldDescriptionExample
System nameName of the AI system or featureWorkforce Scheduler — AI Roster Module
PurposeWhat the system is used for and what decisions it influencesAutomated rostering for site workforce based on skills, availability, and fatigue data
Data inputsWhat data the system uses, including personal dataWorker profiles, leave records, fatigue monitoring sensor data, historical roster data
Risk classificationTriage outcome from Pillar 03 assessmentHigh — directly affects workers; fatigue-related safety implications
Known limitationsDocumented model limitations, known failure modesModel does not account for informal caring responsibilities; performance degrades if > 20% of roster is new workers
Human oversightWho reviews AI outputs before they are actionedSite HR Manager — mandatory review of all rosters before publication
Disclosure statusWhether affected parties have been informed per Privacy Act requirementsWorker disclosure — in progress. Target: October 2026
System ownerNamed individual accountable for the system[Name, Title]
Accountability mapping

Transparency RACI — who does what

Transparency obligations span data protection, legal, communications, IT, and procurement. Use this matrix to define and document ownership.

AAccountable
RResponsible
CConsulted
IInformed
Function / Activity Executive / Board Data Protection Officer Communications & Legal IT Development Procurement & Supply Chain
AI Register maintenance A R I C C
Privacy policy & disclosures I A R C I
Plain-language user communications I A R C I
AI content identification & labelling I C A R I
Vendor transparency & supply chain disclosure I C I R A
Required audit documentation

The documents an auditor will ask for.

These four artefacts form the minimum documentation set for Pillar 04 compliance. Three of the four have direct implications for the December 2026 Privacy Act amendments.

Document 01

Centralised Enterprise AI Register

A live, version-controlled inventory of every AI system in use across the organisation — including AI features embedded in commercial platforms. Must include purpose, data inputs, risk classification, known limitations, oversight mechanism, disclosure status, and system owner. Updated whenever a new system is deployed or decommissioned.

Mandatory — foundational document Download template — available in full pack
Document 02

Privacy Policy & Automated Decision-Making Disclosure

Updated privacy policies and worker/client-facing notices that explicitly disclose when AI or automated decision-making is being used, what data is involved, and what the individual's rights are. Must be in plain language — not legal boilerplate. Must be updated before December 2026. Existing policies that do not address AI are non-compliant from that date.

Mandatory from December 2026 Download template — available in full pack
Document 03

Plain-Language AI Explanations

User-facing explanations of each AI system that affect workers, clients, or subcontractors. Must describe what the system does, what data it uses, what it cannot do, how outputs are reviewed by a human, and how to contest an AI-influenced decision. Must be accessible to the audience — CALD workers may require translated versions for high-risk systems.

Per system — accessible language Download template — available in full pack
Document 04

Supply Chain Information Sharing Log

A record of technical information shared between your organisation and AI vendors — including model specifications, testing results, known limitations, data handling practices, and update notifications. Demonstrates that your transparency obligations extend through the supply chain in both directions: you disclose to vendors what context their model operates in, and they disclose to you how their model works.

Bidirectional — updated at each vendor interaction Download template — available in full pack
Audit-ready checklist

Five questions a compliance auditor will ask.

Your progress is saved automatically. Print this page to include your checklist status in a compliance submission.

Pillar 04 — Transparency checklist

Tick each item when you have the required documentation in place.

0 of 5 items complete 0%
Audit risk

Common gaps auditors find in contractor submissions.

These are the findings that appear most frequently when contractors are assessed against Pillar 04.

No AI Register exists

The most fundamental gap — and the most common. Organisations have no documented inventory of the AI systems they operate. When a principal or auditor asks what AI tools are in use on a project, they cannot answer. Without a register, you cannot demonstrate compliance with any other transparency obligation under this pillar or any of the remaining pillars.

Privacy policy not updated for AI

Most contractor privacy policies were written before AI use became widespread. They do not mention automated decision-making, AI-assisted processes, or the specific types of AI-related data collection the organisation now conducts. From December 2026, this is not a governance gap — it is a legal non-compliance. Budget time for a legal review and rewrite before the deadline.

Commercial software AI features not declared

Organisations declare purpose-built AI tools but omit the AI features embedded in commercial platforms — the AI scheduling feature in their workforce management system, the predictive analytics in their project controls platform, the AI-assisted compliance checking in their document management tool. All of these are AI systems under AI6. All must be in the register.

Generative AI outputs not identified before use

Project teams use generative AI tools to draft tender responses, safety reports, and client correspondence — without any systematic process to identify, review, and label AI-generated content before it leaves the organisation. When a principal discovers their project reports were AI-drafted without disclosure, the reputational and contractual consequences are significant.

Next step

Build your AI Register and privacy disclosures before December 2026.

The full AI Governance Compliance App includes a pre-built AI Register template, a privacy disclosure framework, and plain-language worker communication templates — all updated for the December 2026 Privacy Act requirements.

← Previous 03 — Measure and manage risks Next → 05 — Test and monitor