Be open — with workers, clients, subcontractors, and regulators — about when AI is being used, what it does, and what its limitations are. Maintain a complete register of every AI system in operation. From December 2026, selected disclosures are mandatory under the Privacy Act.
Transparency about AI use is not a courtesy — from December 2026, it is a legal requirement. The Privacy Act amendments will mandate that organisations using automated decision-making processes disclose this to affected individuals in plain language. That means your workers, subcontractors, and clients have a right to know when AI is influencing decisions that affect them.
The Centralised Enterprise AI Register is the foundational document for this pillar. It is a mandatory inventory of every AI system in operation — its purpose, the data it uses, its known limitations, the risk assessment outcome, and who owns it. Without this register, you cannot demonstrate compliance with any of the transparency requirements, and you cannot respond credibly when a principal asks what AI you are using on their project.
Transparency obligations extend to your supply chain. If you require transparency from your AI vendors — and Pillar 03 says you must — then your principal has a right to expect the same from you.
During a project audit, your principal requests a list of all AI tools in use on their contract — the purpose of each tool, the data it accesses, and how outputs are reviewed before use. Without a current AI Register you cannot answer this question. Without one, you are not just non-compliant with AI6 — you are unable to demonstrate that your project governance is fit for purpose.
Your HSEQ platform uses AI to analyse site observation data and generate individual worker risk scores. Workers are not told this is happening. From December 2026, this is a privacy law breach — not just a governance gap. Plain-language disclosure of automated decision-making affecting workers is mandatory. The AI Register, privacy policy, and worker communications must all be updated before the deadline.
The register must cover every AI system in operation — including AI features within commercial software platforms. This is a sample of the mandatory fields. Full template available in the audit pack.
| Field | Description | Example |
|---|---|---|
| System name | Name of the AI system or feature | Workforce Scheduler — AI Roster Module |
| Purpose | What the system is used for and what decisions it influences | Automated rostering for site workforce based on skills, availability, and fatigue data |
| Data inputs | What data the system uses, including personal data | Worker profiles, leave records, fatigue monitoring sensor data, historical roster data |
| Risk classification | Triage outcome from Pillar 03 assessment | High — directly affects workers; fatigue-related safety implications |
| Known limitations | Documented model limitations, known failure modes | Model does not account for informal caring responsibilities; performance degrades if > 20% of roster is new workers |
| Human oversight | Who reviews AI outputs before they are actioned | Site HR Manager — mandatory review of all rosters before publication |
| Disclosure status | Whether affected parties have been informed per Privacy Act requirements | Worker disclosure — in progress. Target: October 2026 |
| System owner | Named individual accountable for the system | [Name, Title] |
Transparency obligations span data protection, legal, communications, IT, and procurement. Use this matrix to define and document ownership.
| Function / Activity | Executive / Board | Data Protection Officer | Communications & Legal | IT Development | Procurement & Supply Chain |
|---|---|---|---|---|---|
| AI Register maintenance | A | R | I | C | C |
| Privacy policy & disclosures | I | A | R | C | I |
| Plain-language user communications | I | A | R | C | I |
| AI content identification & labelling | I | C | A | R | I |
| Vendor transparency & supply chain disclosure | I | C | I | R | A |
These four artefacts form the minimum documentation set for Pillar 04 compliance. Three of the four have direct implications for the December 2026 Privacy Act amendments.
A live, version-controlled inventory of every AI system in use across the organisation — including AI features embedded in commercial platforms. Must include purpose, data inputs, risk classification, known limitations, oversight mechanism, disclosure status, and system owner. Updated whenever a new system is deployed or decommissioned.
Updated privacy policies and worker/client-facing notices that explicitly disclose when AI or automated decision-making is being used, what data is involved, and what the individual's rights are. Must be in plain language — not legal boilerplate. Must be updated before December 2026. Existing policies that do not address AI are non-compliant from that date.
User-facing explanations of each AI system that affect workers, clients, or subcontractors. Must describe what the system does, what data it uses, what it cannot do, how outputs are reviewed by a human, and how to contest an AI-influenced decision. Must be accessible to the audience — CALD workers may require translated versions for high-risk systems.
A record of technical information shared between your organisation and AI vendors — including model specifications, testing results, known limitations, data handling practices, and update notifications. Demonstrates that your transparency obligations extend through the supply chain in both directions: you disclose to vendors what context their model operates in, and they disclose to you how their model works.
Your progress is saved automatically. Print this page to include your checklist status in a compliance submission.
Tick each item when you have the required documentation in place.
These are the findings that appear most frequently when contractors are assessed against Pillar 04.
The most fundamental gap — and the most common. Organisations have no documented inventory of the AI systems they operate. When a principal or auditor asks what AI tools are in use on a project, they cannot answer. Without a register, you cannot demonstrate compliance with any other transparency obligation under this pillar or any of the remaining pillars.
Most contractor privacy policies were written before AI use became widespread. They do not mention automated decision-making, AI-assisted processes, or the specific types of AI-related data collection the organisation now conducts. From December 2026, this is not a governance gap — it is a legal non-compliance. Budget time for a legal review and rewrite before the deadline.
Organisations declare purpose-built AI tools but omit the AI features embedded in commercial platforms — the AI scheduling feature in their workforce management system, the predictive analytics in their project controls platform, the AI-assisted compliance checking in their document management tool. All of these are AI systems under AI6. All must be in the register.
Project teams use generative AI tools to draft tender responses, safety reports, and client correspondence — without any systematic process to identify, review, and label AI-generated content before it leaves the organisation. When a principal discovers their project reports were AI-drafted without disclosure, the reputational and contractual consequences are significant.
The full AI Governance Compliance App includes a pre-built AI Register template, a privacy disclosure framework, and plain-language worker communication templates — all updated for the December 2026 Privacy Act requirements.