Versantly

RESEARCH / 01 — ORIGINAL STUDY, 2026

Snapshot 3 September 2026 · 284 policies read

Does your privacy policy admit you use AI?

Generative-AI disclosure in Australian professional-services privacy policies, 98 days before the ADM transparency rule

· Johnny Sukkar · Versantly

FINDING 01

81%

of 284 Australian accounting, legal and financial-services privacy policies make no reference to artificial intelligence, machine learning or automated decision-making.

229 OF 284 · READ 3 SEPTEMBER 2026

8%

23 firms publish a specific disclosure — what AI is used for and at least one safeguard.

9%

26 firms mention automated decision-making or profiling — the subject of the 10 December 2026 obligation.

13%

of accounting policies mention AI at all, against 21% of law firms and 23% of financial-services firms.

39%

of policies dated 2025 or later mention AI; 8% of policies dated 2024 or earlier do.

§ 1

Headline findings

01

Four in five don't mention AI at all. Of 284 firms whose privacy policies we could read, 229 (81%) make no reference to artificial intelligence, machine learning or automated decision-making.

02

Only 23 firms (8%) publish a specific disclosure — what AI is used for and at least one safeguard: human review, no model training on client data, or a named tool.

03

Only 26 firms (9%) mention automated decision-making or profiling — the exact subject of the Privacy Act obligation that commences on 10 December 2026.

04

Accounting firms disclose least. 13% of accounting policies mention AI, against 21% of law firms and 23% of financial-services firms.

05

Recency is the strongest signal. Policies dated 2025 or later mention AI 39% of the time; policies dated 2024 or earlier, 8%; undated policies, 10%. Firms that have touched their policy recently have mostly added AI. Firms that haven't, haven't.

06

Size helps, a little. Top-tier law firms (AFR top-20 by partners): 33% mention AI. Mid-tier law: 19%. Big-4 and top-10 accounting: 22%. Mid-tier accounting: 12%.

§ 2

Why it matters now

From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.

Meanwhile, staff in most professional-services firms already use generative AI on client matters, sanctioned or not. The privacy policy is the one public document where a firm’s position on that is supposed to be visible. Today, for most firms, it isn’t.

§ 3

Results

Depth 0 = no mention. 1 = generic (“may use AI tools”). 2 = specified uses and at least one safeguard. Percentages are of policies read within each row.

SCHEDULE — BY SEGMENT

SegmentReadNo mention (0)Generic (1)Specific (2)Any AIADM clauseNo-training clause
Accounting / advisory9179 (87%)7 (8%)5 (5%)13%7 (8%)0
Legal8970 (79%)10 (11%)9 (10%)21%5 (6%)3
Financial services10480 (77%)15 (14%)9 (9%)23%14 (13%)2
All284229 (81%)32 (11%)23 (8%)19%26 (9%)5

Not readable (blocked 26, no policy found 29): 55 of 339 firms in the frame (16%), excluded from denominators. Standalone public AI-use statements, separate from the privacy policy: 4 firms.

SCHEDULE — BY TIER

Segment · tierReadAny AISpecific (2)
Legal · top-tier (AFR top-20 by partners)1533%3
Legal · mid-tier7419%6
Accounting · Big-4 / top-10922%1
Accounting · mid-tier8212%4
Financial services (brokerages, advice, non-bank lenders)10423%9

SCHEDULE — BY POLICY DATE

Policy last updatedReadAny AI
2025 or later9236 (39%)
2023–2024161 (6%)
2022 or earlier323 (9%)
No date printed14415 (10%)

144 of 284 policies read (51%) carry no last-updated date at all.

What the specific disclosures say

The 23 depth-2 policies cluster around four uses and three safeguards. Uses: meeting recording and transcription (Microsoft Copilot named most often); document review and legal research; drafting and summarising; intake and triage chatbots; risk scoring and assessments. Safeguards: human review before reliance (“assist, not decide”); no training of models on client or personal data; approved-tool lists or enterprise-grade environments.

A small number of policies disclose the reverse: that client or customer data is used to train the firm’s models. Disclosure cuts both ways, and that is the point of the obligation.

APPENDIX

Positive examples

Firms whose privacy policy specifies AI uses and at least one safeguard. Each excerpt was re-read against the live page on 8 September 2026. No firm is named for scoring 0 or 1: absence of a mention in a public policy is not evidence of the absence of a policy.

SegmentFirmWhat the policy says
Accounting / advisoryBlueRockWe may use artificial intelligence (AI) tools to assist in recording, transcribing, and summarising client meetings
Accounting / advisoryEY Australiato enable the use of AI powered virtual assistants (e.g. Microsoft Copilot) to provide valuable insights about it
Accounting / advisoryHood Sweeneyuse artificial intelligence systems, including those offered by Microsoft, Open AI, Anthropic and Google to assist it in providing products or services to you
Accounting / advisoryKelly+PartnersMicrosoft Copilot, used on Microsoft Teams, is our approved tool for recording and transcribing meetings
Accounting / advisorySinclair Wilsonwe may use secure digital or artificial-intelligence (AI) tools to assist with data analysis or document processing. These tools operate within approved, privacy-compliant environments
Financial servicesActOn WealthWe may use digital tools and AI-powered software to assist with: Transcribing meetings (audio/video); Summarising key points from our conversations; Pre-populating documentation
Financial servicesE&P Financial Group (Evans Dixon)Our AI systems operate under meaningful human supervision with appropriate testing, validation, and governance frameworks
Financial servicesHewison Private WealthWe will not utilise your personal information to train AI systems without first obtaining your explicit, informed consent.
Financial servicesHome Loan ExpertsWe do not use your personal information, financial records or chat transcripts to train AI models
Financial servicesLoan Marketdevelop, improve and train our propriety AI models … Our brokers, and not the system, will make the decision as to which products will be recommended
Financial servicesNOW FinanceThese assessments substantially assist human decision-makers and are subject to human review before final credit decisions are made
Financial servicesPivot Wealthwe may make use of artificial intelligence (AI) tools when we record, transcribe or summarise client meetings … processed by Anthropic’s Claude AI
Financial servicesShiftautomated systems may provide recommendations, alerts, risk ratings or other outputs that are reviewed by our personnel before a final decision is made
Financial servicesViridian Financial GroupAI is used to assist our staff and does not make decisions about clients
LegalAshurstuses Artificial Intelligence ("AI") tools, including to support legal research, document review, due diligence, data analysis, automation, translation, and transcription
LegalBlackwall Legalwe will not use your personal information in any artificial intelligence tools which are publicly available
LegalDixon & KingThese tools do not make final decisions about you or our clients (on an automated basis or otherwise
LegalLander & Rogersgoverned processing using approved AI enabled tools for purposes such as document analysis, research assistance, workflow optimisation, and risk management
LegalMacpherson KelleyWe may use automated decision platforms to substantially and directly assist with our decisions to determine if we will act for you under our AML policies
LegalMaurice BlackburnWe may use automated tools, including chatbot and intake tools, to assist with triage and referral decisions
LegalPhi Finney McDonaldpolicy not to permit the use of personal information collected pursuant to this privacy policy to train datasets or models
LegalSlater & GordonAI tools are used to support our work, they do not replace the professional judgement, supervision and responsibility of our Employees
LegalSparke HelmoreWe use enterprise-grade AI tools to support our lawyers with tasks such as legal research, document review, summarisation and drafting

23 OF 23 DEPTH-2 POLICIES VERIFIED ON RE-READ · CORRECTIONS: hello@versantly.ai

§ 4

Method

Frame
339 Australian firms across three segments, built 3 September 2026 from public, non-paywalled lists only: the AFR Law Partnership Survey top-20 (via Point Blank), Legal 500 Australia, Doyle's Guide state lists, firms self-reporting an AFR Top 100 Accounting rank, the 2019 AFR Top 100 named list, mid-tier accounting network members, The Adviser Top 25 and MPA Top 50 brokerages, advice-licensee lists and non-bank lenders. Ranks are as published by each source, not re-derived. The frame is composite and mid-tier weighted; it is not a census.
Unit
The firm's public privacy policy page, reached from the homepage footer (or /privacy-policy, /privacy), fetched 3 September 2026. One document per firm; standalone AI statements noted if linked from the homepage. Where a firm's privacy link resolves to a parent or licensee's policy, the page reached was scored. One global firm redirected to its global statement, which was scored in place of an Australian one.
Scoring (rubric v1)
Depth 0 = no mention of AI, machine learning or automated decisions; 1 = generic (“may use AI tools”); 2 = specified uses and at least one safeguard. Also recorded: automated-decision-making or profiling clause (Y/N); “no training on your data” clause (Y/N); standalone AI statement (Y/N); policy last-updated date as printed. A rights-boilerplate mention of “profiling” or “automated decision making” counts as depth 1 plus an ADM clause under the literal rubric; under a strict “discloses AI use” reading those firms would score 0 and the headline would move one point higher.
Exclusions
55 firms (16%) where the policy was bot-blocked (26) or not discoverable (29) are reported but excluded from percentages. PDF and JavaScript-rendered policies that could not be read were counted as blocked, never as 0.
Quality assurance
Blind re-score of a random 40-firm sample (30 scored 0, 10 scored 1) by an independent pass: 38/40 agreement (95%). The two disagreements were corrected in the dataset before any figure above was computed. The residual false-negative rate on depth 0 is therefore estimated at or below three percent; the headline is stated to the nearest whole percent and survives that error.
Limitations
A snapshot of public text on one day; sites change. “Publishes” is not “has”. Automated fetching reads what a browser would, but PDF and script-rendered policies may be under-read. Per-firm scores beyond the positive appendix are not published. No personal information was collected: the unit of analysis is a company's published policy text.
Cite as
Johnny Sukkar (2026). Does your privacy policy admit you use AI? Generative-AI disclosure in Australian professional-services privacy policies, 98 days before the ADM transparency rule. Versantly. https://versantly.ai/research/ai-disclosure-2026