RESEARCH / 01 — ORIGINAL STUDY, 2026
Snapshot 3 September 2026 · 284 policies readDoes your privacy policy admit you use AI?
Generative-AI disclosure in Australian professional-services privacy policies, 98 days before the ADM transparency rule
· Johnny Sukkar · Versantly
FINDING 01
81%
of 284 Australian accounting, legal and financial-services privacy policies make no reference to artificial intelligence, machine learning or automated decision-making.
229 OF 284 · READ 3 SEPTEMBER 2026
8%
23 firms publish a specific disclosure — what AI is used for and at least one safeguard.
9%
26 firms mention automated decision-making or profiling — the subject of the 10 December 2026 obligation.
13%
of accounting policies mention AI at all, against 21% of law firms and 23% of financial-services firms.
39%
of policies dated 2025 or later mention AI; 8% of policies dated 2024 or earlier do.
§ 1
Headline findings
01
Four in five don't mention AI at all. Of 284 firms whose privacy policies we could read, 229 (81%) make no reference to artificial intelligence, machine learning or automated decision-making.
02
Only 23 firms (8%) publish a specific disclosure — what AI is used for and at least one safeguard: human review, no model training on client data, or a named tool.
03
Only 26 firms (9%) mention automated decision-making or profiling — the exact subject of the Privacy Act obligation that commences on 10 December 2026.
04
Accounting firms disclose least. 13% of accounting policies mention AI, against 21% of law firms and 23% of financial-services firms.
05
Recency is the strongest signal. Policies dated 2025 or later mention AI 39% of the time; policies dated 2024 or earlier, 8%; undated policies, 10%. Firms that have touched their policy recently have mostly added AI. Firms that haven't, haven't.
06
Size helps, a little. Top-tier law firms (AFR top-20 by partners): 33% mention AI. Mid-tier law: 19%. Big-4 and top-10 accounting: 22%. Mid-tier accounting: 12%.
§ 2
Why it matters now
“From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.”
Meanwhile, staff in most professional-services firms already use generative AI on client matters, sanctioned or not. The privacy policy is the one public document where a firm’s position on that is supposed to be visible. Today, for most firms, it isn’t.
§ 3
Results
Depth 0 = no mention. 1 = generic (“may use AI tools”). 2 = specified uses and at least one safeguard. Percentages are of policies read within each row.
SCHEDULE — BY SEGMENT
| Segment | Read | No mention (0) | Generic (1) | Specific (2) | Any AI | ADM clause | No-training clause |
|---|---|---|---|---|---|---|---|
| Accounting / advisory | 91 | 79 (87%) | 7 (8%) | 5 (5%) | 13% | 7 (8%) | 0 |
| Legal | 89 | 70 (79%) | 10 (11%) | 9 (10%) | 21% | 5 (6%) | 3 |
| Financial services | 104 | 80 (77%) | 15 (14%) | 9 (9%) | 23% | 14 (13%) | 2 |
| All | 284 | 229 (81%) | 32 (11%) | 23 (8%) | 19% | 26 (9%) | 5 |
Not readable (blocked 26, no policy found 29): 55 of 339 firms in the frame (16%), excluded from denominators. Standalone public AI-use statements, separate from the privacy policy: 4 firms.
SCHEDULE — BY TIER
| Segment · tier | Read | Any AI | Specific (2) |
|---|---|---|---|
| Legal · top-tier (AFR top-20 by partners) | 15 | 33% | 3 |
| Legal · mid-tier | 74 | 19% | 6 |
| Accounting · Big-4 / top-10 | 9 | 22% | 1 |
| Accounting · mid-tier | 82 | 12% | 4 |
| Financial services (brokerages, advice, non-bank lenders) | 104 | 23% | 9 |
SCHEDULE — BY POLICY DATE
| Policy last updated | Read | Any AI |
|---|---|---|
| 2025 or later | 92 | 36 (39%) |
| 2023–2024 | 16 | 1 (6%) |
| 2022 or earlier | 32 | 3 (9%) |
| No date printed | 144 | 15 (10%) |
144 of 284 policies read (51%) carry no last-updated date at all.
What the specific disclosures say
The 23 depth-2 policies cluster around four uses and three safeguards. Uses: meeting recording and transcription (Microsoft Copilot named most often); document review and legal research; drafting and summarising; intake and triage chatbots; risk scoring and assessments. Safeguards: human review before reliance (“assist, not decide”); no training of models on client or personal data; approved-tool lists or enterprise-grade environments.
A small number of policies disclose the reverse: that client or customer data is used to train the firm’s models. Disclosure cuts both ways, and that is the point of the obligation.
APPENDIX
Positive examples
Firms whose privacy policy specifies AI uses and at least one safeguard. Each excerpt was re-read against the live page on 8 September 2026. No firm is named for scoring 0 or 1: absence of a mention in a public policy is not evidence of the absence of a policy.
| Segment | Firm | What the policy says |
|---|---|---|
| Accounting / advisory | BlueRock | “We may use artificial intelligence (AI) tools to assist in recording, transcribing, and summarising client meetings” |
| Accounting / advisory | EY Australia | “to enable the use of AI powered virtual assistants (e.g. Microsoft Copilot) to provide valuable insights about it” |
| Accounting / advisory | Hood Sweeney | “use artificial intelligence systems, including those offered by Microsoft, Open AI, Anthropic and Google to assist it in providing products or services to you” |
| Accounting / advisory | Kelly+Partners | “Microsoft Copilot, used on Microsoft Teams, is our approved tool for recording and transcribing meetings” |
| Accounting / advisory | Sinclair Wilson | “we may use secure digital or artificial-intelligence (AI) tools to assist with data analysis or document processing. These tools operate within approved, privacy-compliant environments” |
| Financial services | ActOn Wealth | “We may use digital tools and AI-powered software to assist with: Transcribing meetings (audio/video); Summarising key points from our conversations; Pre-populating documentation” |
| Financial services | E&P Financial Group (Evans Dixon) | “Our AI systems operate under meaningful human supervision with appropriate testing, validation, and governance frameworks” |
| Financial services | Hewison Private Wealth | “We will not utilise your personal information to train AI systems without first obtaining your explicit, informed consent.” |
| Financial services | Home Loan Experts | “We do not use your personal information, financial records or chat transcripts to train AI models” |
| Financial services | Loan Market | “develop, improve and train our propriety AI models … Our brokers, and not the system, will make the decision as to which products will be recommended” |
| Financial services | NOW Finance | “These assessments substantially assist human decision-makers and are subject to human review before final credit decisions are made” |
| Financial services | Pivot Wealth | “we may make use of artificial intelligence (AI) tools when we record, transcribe or summarise client meetings … processed by Anthropic’s Claude AI” |
| Financial services | Shift | “automated systems may provide recommendations, alerts, risk ratings or other outputs that are reviewed by our personnel before a final decision is made” |
| Financial services | Viridian Financial Group | “AI is used to assist our staff and does not make decisions about clients” |
| Legal | Ashurst | “uses Artificial Intelligence ("AI") tools, including to support legal research, document review, due diligence, data analysis, automation, translation, and transcription” |
| Legal | Blackwall Legal | “we will not use your personal information in any artificial intelligence tools which are publicly available” |
| Legal | Dixon & King | “These tools do not make final decisions about you or our clients (on an automated basis or otherwise” |
| Legal | Lander & Rogers | “governed processing using approved AI enabled tools for purposes such as document analysis, research assistance, workflow optimisation, and risk management” |
| Legal | Macpherson Kelley | “We may use automated decision platforms to substantially and directly assist with our decisions to determine if we will act for you under our AML policies” |
| Legal | Maurice Blackburn | “We may use automated tools, including chatbot and intake tools, to assist with triage and referral decisions” |
| Legal | Phi Finney McDonald | “policy not to permit the use of personal information collected pursuant to this privacy policy to train datasets or models” |
| Legal | Slater & Gordon | “AI tools are used to support our work, they do not replace the professional judgement, supervision and responsibility of our Employees” |
| Legal | Sparke Helmore | “We use enterprise-grade AI tools to support our lawyers with tasks such as legal research, document review, summarisation and drafting” |
23 OF 23 DEPTH-2 POLICIES VERIFIED ON RE-READ · CORRECTIONS: hello@versantly.ai
§ 4
Method
- Frame
- 339 Australian firms across three segments, built 3 September 2026 from public, non-paywalled lists only: the AFR Law Partnership Survey top-20 (via Point Blank), Legal 500 Australia, Doyle's Guide state lists, firms self-reporting an AFR Top 100 Accounting rank, the 2019 AFR Top 100 named list, mid-tier accounting network members, The Adviser Top 25 and MPA Top 50 brokerages, advice-licensee lists and non-bank lenders. Ranks are as published by each source, not re-derived. The frame is composite and mid-tier weighted; it is not a census.
- Unit
- The firm's public privacy policy page, reached from the homepage footer (or /privacy-policy, /privacy), fetched 3 September 2026. One document per firm; standalone AI statements noted if linked from the homepage. Where a firm's privacy link resolves to a parent or licensee's policy, the page reached was scored. One global firm redirected to its global statement, which was scored in place of an Australian one.
- Scoring (rubric v1)
- Depth 0 = no mention of AI, machine learning or automated decisions; 1 = generic (“may use AI tools”); 2 = specified uses and at least one safeguard. Also recorded: automated-decision-making or profiling clause (Y/N); “no training on your data” clause (Y/N); standalone AI statement (Y/N); policy last-updated date as printed. A rights-boilerplate mention of “profiling” or “automated decision making” counts as depth 1 plus an ADM clause under the literal rubric; under a strict “discloses AI use” reading those firms would score 0 and the headline would move one point higher.
- Exclusions
- 55 firms (16%) where the policy was bot-blocked (26) or not discoverable (29) are reported but excluded from percentages. PDF and JavaScript-rendered policies that could not be read were counted as blocked, never as 0.
- Quality assurance
- Blind re-score of a random 40-firm sample (30 scored 0, 10 scored 1) by an independent pass: 38/40 agreement (95%). The two disagreements were corrected in the dataset before any figure above was computed. The residual false-negative rate on depth 0 is therefore estimated at or below three percent; the headline is stated to the nearest whole percent and survives that error.
- Limitations
- A snapshot of public text on one day; sites change. “Publishes” is not “has”. Automated fetching reads what a browser would, but PDF and script-rendered policies may be under-read. Per-firm scores beyond the positive appendix are not published. No personal information was collected: the unit of analysis is a company's published policy text.
- Cite as
- Johnny Sukkar (2026). Does your privacy policy admit you use AI? Generative-AI disclosure in Australian professional-services privacy policies, 98 days before the ADM transparency rule. Versantly. https://versantly.ai/research/ai-disclosure-2026