Talk to Us About How AI Improves Your Security

Every conversation about AI and security in the last two years has been about AI as the threat, and that framing is not wrong. The Australian Signals Directorate has assessed that AI almost certainly enables malicious actors to execute attacks at greater scale and speed, and the numbers behind that assessment are not subtle: more than 84,700 cybercrime reports in a year, roughly one every six minutes, with the average cost per incident rising fifty per cent to $80,850. Convincing phishing used to require somebody who could write. Convincing voice impersonation used to require an impressionist. Neither is true now. What gets far less attention is that the same technology is unusually good at the defensive side of exactly this problem, and that some of the most valuable places to deploy it are on the layer businesses think about least β€” the phone. Voice is where the social engineering actually lands. It is where the authorisation gets given, where the invoice detail gets changed, where the urgent request from the boss arrives, and it is almost always the least monitored channel in the business. This article sets out eight specific gaps that AI closes on that layer, states plainly the four it does nothing for, and covers the governance you need before you switch any of it on β€” including the obligation that lands on 10 December 2026 and applies to more businesses than expect it.

AI Security Β· Australian Business Β· 2026

The Attacker Got AI First. You Can Have It Too.

Australian businesses now report a cybercrime roughly every six minutes, and the average incident costs $80,850. A large part of what makes the current wave work is that AI made convincing fraud cheap to produce at volume. The useful response is not fear β€” it is understanding exactly which of your gaps AI can close, which it cannot touch, and what you need in place before you turn any of it on.

πŸ“… ⏱ 16 min read πŸ‡¦πŸ‡Ί Australian owned, Australian hosted, Australian supported
TL;DR

The published cost position: more than 84,700 cybercrime reports a year in Australia, about one every six minutes; over 1,200 incidents responded to, up 11%; average cost per incident up 50% to $80,850 β€” $56,600 for small business, $97,000 for medium, and $202,700 for organisations over 200 staff. AI made the attack side cheap: convincing phishing at volume, cloned voices, cloned sites. The same asymmetry runs both ways, and the phone layer is where it pays most, because voice is where authorisation is given and it is the least monitored channel in most businesses. Eight places AI closes a real gap: caller verification support, transcript evidence, toll fraud and traffic anomaly detection, social engineering patterns across a call history, synthetic voice awareness, after-hours coverage that kills shadow channels, reviewing every call instead of two per cent, and a continuous audit trail. Four places it does nothing: a compromised password, an unpatched system, a malicious insider with legitimate access, and a business with no process to escalate to. Governance first β€” human control, defined accountability, and the automated-decision transparency obligation commencing 10 December 2026.

The Numbers, Stated Once

Cyber security writing has a habit of leading with alarm and never getting to anything actionable. So here are the published figures once, and then we move to what can be done about them.

84,700+
Cybercrime reports in a year β€” about one every six minutes
$80,850
Average cost per incident, up 50%
1,200+
Incidents responded to, up 11%
$56,600
Average cost for a small business, up 14%
Organisation sizeAverage cost per incidentChange
Small business$56,600Up 14%
Medium business$97,000Up 55%
Large organisations (200+ staff)$202,700Up 219%

The assessment accompanying those figures is the part worth sitting with: AI almost certainly enables malicious actors to execute attacks on a larger scale and at a faster rate. AI-generated phishing, cloned voices and cloned websites have made a category of fraud that used to require genuine skill into something that requires a subscription.

Notice which line grew fastest and what that implies. The 219% increase sits with large organisations β€” the ones with security teams, budgets and controls. That is not a story about small businesses being careless. It is a story about attack quality improving faster than defences, at every size. The correct inference for a smaller business is not that it is safe by obscurity; it is that the attacks reaching it are now the same quality as the ones reaching organisations with a security function.

Why the Phone Layer Is the Gap

Most businesses have spent a decade hardening email. Filters, banners on external senders, link rewriting, staff training, multi-factor authentication. That work was correct and it worked well enough that attackers moved.

They moved to voice, and voice is where three things are simultaneously true.

βœ…

It is where authorisation happens

Payment details get changed on calls. Account access gets granted on calls. Urgency gets manufactured on calls. The decisions with money attached are disproportionately verbal.

πŸ‘οΈ

It is the least monitored channel

Email is logged, searchable and inspected. Calls, in most businesses, are a sample of recordings nobody listens to and a set of notes somebody may have written. There is no filter on a phone call.

🧠

It defeats trained scepticism

Staff have been taught to distrust an unexpected email. They have not been taught to distrust a voice, because until recently a voice was a reasonable identity proof. That training gap is the whole opportunity.

So the argument of this article is narrow and specific: the highest-value AI security deployment for most Australian businesses is not a new security product. It is switching on capability that already exists in the communications platform, because that is the channel with the largest gap between how much risk it carries and how much attention it gets.

1. Caller Verification That Actually Verifies

The current state of caller verification in most businesses is a person asking for a name and a date of birth, listening to an answer, and deciding. That process fails against a caller who has done fifteen minutes of research, which is now every caller who matters.

What AI addsHow it helps
Consistent challenge sequencesThe same verification steps every time, in the same order, regardless of how busy, tired or sympathetic the person answering is. Social engineering works on inconsistency.
Cross-checking against the recordWhat the caller says, checked against what the system holds, while the call is still happening rather than afterwards.
Flagging mismatches for a humanNot refusing service β€” escalating. The AI notices the discrepancy and hands it to a person with the discrepancy already stated.
Removing the pressure variableAn automated first stage does not feel embarrassed about asking a third question, does not respond to urgency and cannot be flattered. Those three human traits are what the attacker is actually targeting.
The important limit, stated up front

This is not voice biometrics and we are not proposing that a voice should be an identity proof. The whole premise of the current threat is that a voice can be synthesised. What AI adds here is process consistency and cross-checking, not a magic identification of the human speaking. Any vendor selling you voice-as-password in 2026 is selling you the exact thing that just stopped working.

2. Transcripts as Evidence

The least glamorous item on this list and quite possibly the highest value. An accurate transcript of every call, searchable, timestamped and retained, changes what is provable.

πŸ”

Searchable across everything

When you learn on Thursday that a fraud attempt is circulating, you can ask whether anyone in the business took a call matching it β€” this month, or last quarter. Without transcripts that question has no answer.

πŸ“‘

Provable authorisation

Who approved the change, in what words, at what time. Disputes about verbal authorisation currently resolve on whoever is more confident. With a transcript they resolve on the record.

⏱️

Faster incident response

Reconstructing an incident is where most of the response time goes. A searchable call history collapses days of interviews into an afternoon of queries.

⚠️

And a real obligation attached

Transcripts are personal information. They need a retention period, an access rule and a purpose, decided before you turn them on rather than after. This is a genuine cost of the capability, not a footnote.

3. Toll Fraud and Traffic Anomalies

This is the oldest AI-adjacent security function in telephony and it remains among the most valuable, because the losses are immediate and denominated in real money.

Toll fraud is the compromise of a phone system to place calls someone else pays for β€” historically to international premium destinations, at volume, usually overnight or across a long weekend. The economics are brutal: by the time a human notices on Tuesday morning, the bill exists.

SignalWhy a pattern engine catches it and a person does not
Calls to destinations you have never calledA business's calling geography is remarkably stable. A first-ever call to an unusual international destination at 2am is a strong signal, and nobody is awake to see it.
Volume outside business hoursNot zero β€” plenty of businesses operate at night β€” but a departure from that business's own established pattern rather than a generic rule.
Concurrent call counts that make no senseForty simultaneous calls from an eight-person business is not a busy period. It is a compromise, and it is arithmetically obvious the moment anything is watching.
Registration anomaliesAn extension registering from an unexpected network or geography. Frequently the earliest signal available, and entirely invisible without monitoring.
Why this one belongs to the platform

Toll fraud detection only works where somebody sees the traffic in real time and can act on it. A business running its own system detects it on the invoice. A provider who operates the network and the platform sees the pattern as it forms and can stop it mid-event β€” which is the difference between a conversation about a $40,000 bill and a phone call at 3am telling you something was blocked. This is also why it is worth asking a prospective provider directly what their limits are, what triggers a block, and whether anybody is on the other end of the alert.

4. Patterns Across a History, Not a Call

Here is the capability that is genuinely new, as opposed to older automation being relabelled as AI.

Sophisticated social engineering is rarely a single call. It is a sequence: a harmless call to confirm the receptionist's name, another to learn who approves invoices, a third that mentions the two facts already gathered to establish credibility, and a fourth that asks for the thing. No individual call in that chain looks wrong. Any human reviewing any one of them would find nothing.

The attack is only visible in aggregate, which is precisely the shape of problem pattern recognition across a corpus is good at β€” and precisely the shape of problem that human review of individual calls cannot address, no matter how diligent the humans are. A person who reviews a sample of calls is looking for a bad call. The threat is a sequence of unremarkable ones.

What this looks like in practice is unglamorous: repeated calls from a number that never books anything, a caller who asks about internal process rather than about your product, requests that consistently arrive just before close of business, and the same voice appearing across departments. Each is nothing. Together they are a profile worth flagging to a human.

5. Synthetic Voice and the Vishing Problem

We have written at length elsewhere about voice cloning and will not repeat it. The relevant point here is narrower, and it is about what AI can and cannot contribute to the defence.

DefenceEffectiveness
Detecting synthetic audio automaticallyImproving, unreliable. Treat any vendor claim here with heavy scepticism. Generation is currently outrunning detection and betting a control on it is unwise.
Enforcing a callback ruleHighly effective. Any request to change payment details or move money gets verified by calling back on a known number. AI enforces the rule consistently, which is where humans fail.
Flagging the request type regardless of the voiceEffective. Do not try to detect the fake. Detect the ask. A request to change bank details is high-risk whoever appears to be making it.
Training staff with real examplesEffective. Recordings and transcripts of actual attempts on your business beat a generic awareness module by a wide margin.

The strategic point: stop trying to authenticate the voice and start authenticating the request. Voice as an identity proof is over, and no amount of technology restores it. What survives is process β€” out-of-band verification for a defined list of high-risk actions, applied without exception. AI's contribution is that it applies the rule the same way at 4:55pm on a Friday as it does on a Tuesday morning, and that is not a small thing, because 4:55pm on a Friday is when the request arrives.

6. Killing the Shadow Channels

An indirect security benefit that nobody puts in this category, and it may be the largest one on the list.

When a business cannot answer its phone reliably, staff invent workarounds. Personal mobile numbers given to good customers. A WhatsApp group with a supplier. A personal email address used because the shared inbox is unmanageable. Each is a reasonable individual response to an operational failure, and collectively they are a security disaster: business communication happening on channels the business does not control, cannot log, cannot search and cannot revoke when somebody leaves.

πŸ“ž

Calls answered means calls stay on the system

AI answering after hours and at peak means nobody needs a workaround. The traffic stays where it can be logged and governed.

πŸšͺ

Offboarding actually works

When a staff member leaves, revoking a platform account removes their access. It does not remove a customer's habit of texting their personal mobile, and no policy fixes that after the fact.

πŸ“¨

One record instead of six

Voice, SMS and messaging in one history means the interaction record is complete. Six channels means the record is a guess, and a guess is not evidence.

7. Reviewing Every Call Instead of Two Per Cent

Traditional call quality review covers a sample β€” commonly a couple of per cent, chosen by whoever had time. As a security control, a two per cent sample is close to useless: it will find a systemic problem eventually and will essentially never find a targeted one.

Automated review changes the coverage from a sample to the population. For security specifically, that matters in three ways.

  1. Policy breaches surface as a rate, not an anecdote. If verification steps are being skipped, you learn how often and by whom, rather than learning that it happened once in a reviewed call.
  2. Coaching targets the actual gap. Training built on complete data addresses what people are really doing under pressure, not what a reviewer happened to hear.
  3. Trend detection becomes possible. A slow drift in how staff handle unusual requests is invisible at two per cent sampling and obvious at a hundred.
Do not let this become surveillance

Reviewing every call is powerful and it changes the relationship with staff if it is introduced badly. Say what is analysed, why, who sees it and what it will and will not be used for β€” before you switch it on. A control that staff experience as monitoring produces defensive behaviour, and defensive staff are worse at reporting the thing you most need reported. Consultation here is not a compliance formality, it is what makes the control work.

8. An Audit Trail That Writes Itself

Most Australian businesses have some obligation to demonstrate what happened rather than assert it β€” sector rules, regulatory codes, insurance conditions, contractual undertakings. The traditional method is somebody writing a note, which produces a record that is incomplete, retrospective and written by the person with the most reason to shade it.

Question you may have to answerWith notesWith platform records and AI summaries
Did we disclose the required information?Probably β€” somebody remembers doing itHere is the call and the words used
When was the customer first told?ApproximatelyTimestamped
Did we verify identity before acting?Standard practiceHere is the verification sequence, or here is where it was skipped
How did we respond to the complaint?A file note written afterwardsThe whole interaction, in order, across voice and messages

The uncomfortable half of this is worth saying: an audit trail that writes itself also records the times you got it wrong. Businesses that want evidence only when it helps them should not deploy this. Businesses that would rather know are the ones it serves.

Four Things AI Will Not Do for You

Any article that lists eight benefits and no limits is a brochure. Here are the four categories where AI on the communications layer contributes nothing, and where the money should go instead.

ThreatWhat AI on the phone layer doesWhat actually works
Compromised credentialsNothingMulti-factor authentication, a password manager, conditional access. Do this first, before any of the eight above.
Unpatched systems and known vulnerabilitiesNothingPatching. Unfashionable, unglamorous, and still the highest-return security activity available.
A malicious insider with legitimate accessVery little β€” the activity looks authorised because it isLeast privilege, separation of duties, and dual authorisation on payments.
No process to escalate toGenerates alerts nobody acts onDeciding, in advance and in writing, who is called and what they are empowered to do. An unattended alert is worse than none, because it manufactures false confidence.
The order of operations matters

If you have not done multi-factor authentication and patching, do not start with AI. Nothing in this article substitutes for either, and a business with sophisticated call analytics and shared passwords has bought the interesting control and skipped the effective one. We would rather tell you that than sell you the wrong thing first.

Governance Before Deployment

Australia has no general AI statute and, as at mid-2026, no mandatory guardrails for private business. What exists is the National AI Plan, an AI Safety Institute, and voluntary guidance whose ten guardrails have been distilled into six practices worth using as a checklist whatever your view of regulation.

PracticeWhat it means for a phone-layer deployment
Decide accountabilityName the person responsible for the AI in your phone system. If nobody is named, nobody is accountable, and this is the step most often skipped.
Understand impactsWho is affected β€” customers, staff, callers who never consented to anything. Write it down.
Measure and manage risksWhat happens when it is wrong? A misrouted call is trivial; a wrongly refused verification is not.
Share informationTell people. Callers, staff, customers. Undisclosed AI is a reputational risk on top of any legal one.
Test and monitorCheck it still works. Models change, call patterns change, and a control nobody tests is a control nobody has.
Maintain human controlA person can always override, and there is always a path to a human. For security decisions this is not optional.

Note that from 15 June 2026 the first mandatory AI requirements applied to Commonwealth agencies β€” impact assessments, procurement guidance, foundational training and chief AI officers. If you sell to government, that is not somebody else's framework; it is arriving in your procurement questionnaires.

The 10 December 2026 Obligation

One date deserves its own section because it is close and it is under-recognised.

Automated decision-making transparency, from 10 December 2026

Amendments to the Privacy Act require entities that use personal information in automated decision-making capable of affecting a person's rights or interests to disclose in their privacy policy the kinds of personal information used and the kinds of decisions made. The drafting is broad and captures rule-based tools and automated assessment technologies as well as AI. The regulator has signalled a wide reading, with final guidance expected around September 2026, and civil penalties for serious breaches run to very large amounts.

Why it lands on phone systems: an AI agent that qualifies leads, prioritises a queue, decides who reaches a human quickly, or scores an interaction is plausibly making decisions affecting rights or interests using personal information. The obligation is a privacy-policy disclosure obligation, which is genuinely manageable β€” but only if somebody knows the deployment exists. The businesses that get caught will be the ones where the AI was switched on by an operations team and the privacy policy was last touched by a lawyer in 2023.

Two practical steps, neither expensive. Inventory every automated decision your systems currently make, including the ones that predate anyone calling them AI. Then make sure whoever maintains your privacy policy has that inventory before December.

Twelve Questions to Ask Any AI Security Claim

Including ours. If a vendor cannot answer these plainly, that is the answer.

#QuestionWhy it matters
1Where does the processing physically happen?Jurisdiction determines who can compel access to your call audio.
2Is my call audio or transcript retained, and for how long?Retention you did not choose is retention you cannot defend.
3Is anything used to train a model?Should be no by default, in writing, not in a blog post.
4Who are the subprocessors?You are inheriting their security posture whether you know it or not.
5What happens when the AI is wrong?There must be a defined failure path, not an assumption of correctness.
6Can a human always override?If no, do not deploy it on a security decision.
7What triggers a toll fraud block, and who acts on it?An alert with nobody behind it is theatre.
8Do you claim to detect synthetic voice?An emphatic yes is a reason for scepticism, not comfort.
9What is logged, and can I export it?Evidence you cannot extract is evidence you do not have.
10Who is accountable at 3am?The most useful question in security procurement, and the least asked.
11What does your ADM disclosure look like?If they have not thought about December 2026, they will not help you with it.
12What does this not protect me from?A vendor who cannot answer this has not thought carefully about their own product.

Talk to us about your communications layer specifically

Tell us how calls are answered, how identity is verified, whether anybody watches your call traffic overnight and what you would have to prove if something went wrong. We will tell you which of the eight are worth switching on for you, and which are not.

Get Started Or call 1300 881 662
The summary

Australian businesses report a cybercrime roughly every six minutes and the average incident costs $80,850, with AI cited as a driver of both the scale and the speed. The same technology helps most on the layer businesses monitor least β€” voice, where authorisation actually happens. Eight real gaps it closes: verification consistency, transcript evidence, toll fraud detection, patterns across a history, request-based rather than voice-based authentication, eliminating shadow channels, complete rather than sampled review, and a self-writing audit trail. Four it does not touch: stolen credentials, unpatched systems, malicious insiders and the absence of an escalation process. Do multi-factor authentication and patching first. Then name an accountable person, disclose what you are doing, keep a human in control, and get your automated-decision inventory to whoever writes your privacy policy before 10 December 2026.

Related reading: voice cloning and vishing in depth, VoIP security and toll fraud, what a real breach looks like from the outside, the December 2026 automated-decisions obligation in detail, and the Scams Prevention Framework.

Frequently Asked Questions

How much does a cyber incident actually cost an Australian business?
According to the published national figures, the average cost per incident rose fifty per cent to $80,850, and the breakdown by size is more useful than the headline. Small businesses averaged $56,600, up fourteen per cent. Medium businesses averaged $97,000, up fifty-five per cent. Organisations with more than two hundred staff averaged $202,700, up two hundred and nineteen per cent. Those figures sit alongside more than 84,700 cybercrime reports in a year, which is roughly one every six minutes, and over 1,200 incidents responded to, an eleven per cent increase. The most instructive part is which line grew fastest: the 219% increase belongs to large organisations, the ones with security teams, budgets and controls in place. That is not a story about small businesses being careless β€” it is a story about attack quality improving faster than defences at every size, and the accompanying assessment is explicit that AI almost certainly enables malicious actors to attack at greater scale and faster rates. For a smaller business the correct inference is not that obscurity provides protection. It is that the attacks now reaching a ten-person company are the same quality as those reaching organisations that employ security professionals, which changes what a proportionate response looks like.
Where does AI genuinely improve security on a business phone system?
Eight places, and they are specific rather than general. First, caller verification consistency: the same challenge sequence every time regardless of how busy or sympathetic the person answering is, with cross-checking against the record while the call is live and mismatches escalated to a human rather than refused outright. Second, transcripts as searchable evidence, which lets you ask whether anyone in the business took a call matching a fraud pattern you only learned about this week. Third, toll fraud and traffic anomaly detection β€” unfamiliar destinations, volume outside your own established pattern, impossible concurrent call counts, and registration from unexpected networks. Fourth, pattern recognition across a call history rather than a single call, which is the only way to see a multi-call social engineering sequence in which no individual call looks wrong. Fifth, enforcing callback and request-type rules rather than trying to authenticate a voice. Sixth, eliminating shadow channels by making sure calls are actually answered, so staff stop inventing workarounds on personal mobiles and messaging apps you cannot log or revoke. Seventh, reviewing every call instead of a two per cent sample, which turns policy breaches from anecdotes into rates. Eighth, an audit trail that writes itself instead of relying on notes written afterwards by the person with most reason to shade them.
Can AI detect a deepfake or cloned voice on a phone call?
Not reliably, and you should treat confident vendor claims here as a reason for scepticism rather than comfort. Automated detection of synthetic audio is improving but generation is currently outrunning detection, and building a security control on the assumption that fakes will be caught is unwise. The strategically correct response is to stop trying to authenticate the voice and start authenticating the request. Voice as an identity proof is finished, and no amount of technology restores it, because the entire premise of the current threat is that a voice can be synthesised convincingly and cheaply. What survives is process: define a list of high-risk actions β€” changing payment or bank details, moving money, granting account access, altering delivery addresses β€” and require out-of-band verification for every one of them, by calling back on a number you already hold, without exception and regardless of who appears to be asking. AI's real contribution here is consistency: it applies that rule the same way at 4:55pm on a Friday as at 10am on a Tuesday, which matters enormously because 4:55pm on a Friday is precisely when the urgent request arrives. The other genuinely effective use is training staff with recordings and transcripts of real attempts on your own business, which outperforms any generic awareness module.
What is toll fraud and how does AI help stop it?
Toll fraud is the compromise of a phone system to place calls that somebody else pays for, historically to international premium-rate destinations, at high volume, and typically overnight or across a long weekend so that the losses accumulate before anybody notices. The economics are unforgiving: by the time a person looks at the traffic on Tuesday morning, the bill already exists. Pattern detection catches four signals that a human realistically cannot. Calls to destinations the business has never called before, since a business's calling geography is remarkably stable and a first-ever call to an unusual international destination at two in the morning is a strong indicator with nobody awake to see it. Volume outside business hours, measured against that specific business's own established pattern rather than a generic rule, because plenty of businesses legitimately operate at night. Concurrent call counts that make no arithmetic sense, such as forty simultaneous calls from an eight-person company. And registration anomalies, where an extension appears from an unexpected network or geography, which is frequently the earliest available signal and completely invisible without monitoring. Crucially this only works where somebody sees the traffic in real time and can act, which is why it belongs with a provider who operates the network and platform rather than with a business watching its own invoices.
What can AI not protect my business from?
Four categories, and being honest about them is more useful than a longer list of benefits. Compromised credentials: if an attacker has a valid password, AI on the phone layer contributes nothing, and the answer is multi-factor authentication, a password manager and conditional access. Unpatched systems and known vulnerabilities: again nothing, and the answer is patching, which remains the least fashionable and highest-return security activity available. A malicious insider with legitimate access: very little, because the activity looks authorised for the simple reason that it is, and the answers are least privilege, separation of duties and dual authorisation on payments. And the absence of a process to escalate to: AI will happily generate alerts that nobody acts on, which is actively worse than no alerting because it manufactures false confidence β€” the answer is deciding in advance and in writing who gets called and what they are empowered to do. The order of operations matters more than the tooling. If you have not implemented multi-factor authentication and you are not patching, do not start with AI. A business with sophisticated call analytics and shared passwords has bought the interesting control and skipped the effective one, and any provider worth dealing with will tell you so before selling you something.
What governance do I need before switching on AI in my phone system?
Australia has no general AI statute and, as at mid-2026, no mandatory guardrails for private business β€” what exists is the National AI Plan, an AI Safety Institute and voluntary guidance whose ten guardrails have been distilled into six practices that work well as a checklist regardless of your view on regulation. Decide accountability: name the specific person responsible for the AI in your phone system, because if nobody is named nobody is accountable, and this is the step most often skipped. Understand impacts: write down who is affected, including customers, staff, and callers who never consented to anything. Measure and manage risks: establish what happens when it is wrong, since a misrouted call is trivial while a wrongly refused verification is not. Share information: tell callers, staff and customers, because undisclosed AI carries reputational risk on top of any legal exposure. Test and monitor: check it still works, since models change and call patterns change, and a control nobody tests is a control nobody has. Maintain human control: a person must always be able to override and there must always be a path to a human, which is not optional for security decisions. Note also that from 15 June 2026 the first mandatory AI requirements applied to Commonwealth agencies, so if you sell to government these will arrive in your procurement questionnaires.
What is the 10 December 2026 automated decision-making obligation?
From 10 December 2026, amendments to the Privacy Act require entities that use personal information in automated decision-making capable of affecting a person's rights or interests to disclose in their privacy policy the kinds of personal information used and the kinds of decisions made using it. The drafting is deliberately broad and captures rule-based tools and automated assessment technologies as well as AI systems, the regulator has signalled a wide reading with final guidance expected around September 2026, and civil penalties for serious interferences with privacy run to very large amounts. It lands on phone systems more often than businesses expect, because an AI agent that qualifies leads, prioritises a queue, determines who reaches a human quickly, or scores an interaction is plausibly making decisions affecting rights or interests using personal information. The obligation itself is a privacy-policy disclosure obligation and is genuinely manageable β€” but only if somebody knows the deployment exists. The businesses that will get caught are the ones where an operations team switched the AI on and the privacy policy was last reviewed by a lawyer in 2023. Two steps, neither expensive: inventory every automated decision your systems make, including ones that predate anybody calling them AI, and get that inventory to whoever maintains your privacy policy well before December.

What to Read Next

Your next reads

Uniden Voice Over Cloud logo

Australia’s smartest AI-powered cloud phone system β€” Australian owned, Australian hosted, Australian supported. unidenvoice.com | 1300 881 662