AI Automated Decision-Making Compliance 2026

12 Aug 2026 · 4 min read

AI automated decision-making compliance now spans the EU AI Act, Australia's 2026 ADM reforms, and US state laws such as the CCPA. Across all three, the common thread is to disclose automated decision-making, keep humans in the loop, and document how AI affects people.

AI and automated decision-making (ADM) compliance has become a board-level concern, and the rules differ by region. As of 2026, three frameworks matter most for organisations using AI for analytics: the EU AI Act, Australia's automated decision-making reforms, and US state privacy laws such as the California Consumer Privacy Act (CCPA). They differ in detail, but they share a clear common thread: if AI or automated logic makes or materially informs a decision about a person, you should disclose it, keep a human in the loop where it matters, and be able to explain it. This guide is an orientation, not legal advice, and you should confirm specifics with qualified counsel.

Why this matters for analytics

BI and AI for analytics are increasingly used to score, segment, prioritise, and recommend. When those outputs feed decisions about individuals, such as creditworthiness, eligibility, pricing, or employment, they can cross into regulated automated decision-making. A dashboard that simply reports the past is low risk; a model that drives a decision about a person is not. Knowing which side of that line you are on is the starting point for compliance.

The three regimes at a glance

RegimeRegionCore obligation for ADM
EU AI ActEU, plus extraterritorial reachRisk-based duties, transparency, oversight; stricter rules for high-risk uses
ADM reformsAustralia (2026)Transparency about automated decisions affecting individuals; explanation and oversight expectations
CCPA and US state lawsUS (state by state)Disclosure of automated decision-making, with rights to access and, in some cases, opt out

EU AI Act

The EU AI Act takes a risk-based approach. Many analytics uses are minimal or limited risk, carrying transparency obligations, while uses that affect access to essential services, employment, or similar can be high risk and carry stricter requirements around data governance, documentation, human oversight, and transparency. Crucially, the Act has extraterritorial reach: organisations outside the EU can be in scope where their AI output is used within the EU. Phased obligations apply over time, so check the current effective dates and your classification with counsel.

Australia's automated decision-making reforms

Australia has been strengthening expectations around automated decision-making as part of its privacy reform programme, with measures taking effect through 2026. The direction of travel is toward greater transparency about when automated systems are used to make or substantially inform decisions affecting individuals, alongside expectations of explanation and meaningful human involvement. If you serve Australian customers or operate there, treat ADM transparency as a near-term requirement and confirm the precise commencement and scope of the rules.

CCPA and US state laws

There is no single US federal AI law. Instead, a patchwork of state privacy laws, led by California's CCPA and its regulations on automated decision-making technology, is establishing disclosure obligations and individual rights. The common pattern is the right to know when automated decision-making is used and, in some cases, to access information about it or opt out. Other states are following with their own variations, so multi-state operators should map obligations state by state.

The common core: what to do regardless of region

Rather than building three separate programmes, anchor on the shared requirements, then layer regional specifics on top.

  1. Inventory your ADM. List every place where AI or automated logic makes or materially informs a decision about a person. You cannot govern what you have not mapped.
  2. Disclose it. Tell affected individuals clearly when automated decision-making is involved. Transparency is the single most consistent requirement across regimes.
  3. Keep humans in the loop. For decisions with legal or similarly significant effects, ensure meaningful human review rather than rubber-stamping.
  4. Document and explain. Record how each system works, what data it uses, and how its outputs are reviewed, so you can respond to regulators and individuals.
  5. Manage data and bias. Use governed, quality data and test for unfair outcomes, since both EU and US rules pay close attention to discrimination.

How this connects to Power BI Copilot and AI features

Generative AI features such as Power BI Copilot can contribute to decisions if their output is used that way. If Copilot summaries or AI-driven scores inform consequential decisions about individuals, the disclosure and oversight principles above apply. Building on a clean, governed semantic model also makes explanation easier, which is why readiness and governance go hand in hand. See our Power BI Copilot guide for 2026 and Power BI Copilot readiness for the foundations, and our AI for Analytics approach for governed deployment.

A pragmatic starting point

Most organisations do not need a sprawling compliance project to begin. They need a clear inventory of where AI touches decisions about people, clear disclosure, and documented human oversight. From there, you can address the EU AI Act, Australian ADM, and US state specifics that apply to you, with legal advice on the details.

If you want help mapping where AI and automated logic influence decisions in your reporting and data platform, and building governance around it, book a Trusted Numbers Review. We assess your analytics estate, identify where ADM disclosure and oversight apply, and give you a prioritised, fixed-scope plan to deploy AI for analytics responsibly.

Frequently asked questions

Do I have to tell people when AI makes a decision about them?

In most major regimes, yes, where the decision has a legal or similarly significant effect. The EU AI Act, Australia's ADM reforms, and US state laws increasingly require disclosure of automated decision-making to the people affected.

Does the EU AI Act apply to a UK or US company?

It can. The EU AI Act applies based on where the AI output is used, so organisations outside the EU can fall in scope if they offer AI systems or their output is used in the EU. Take legal advice on your specific situation.

What is the simplest first step toward compliance?

Inventory where AI or automated logic influences decisions about individuals, then ensure each use is disclosed, has appropriate human oversight, and is documented. This addresses the common core of most regimes.

Do these rules apply to a UK organisation?

The UK relies on its own data protection rules on automated decisions rather than the EU AI Act, so check UK law directly and take advice. You can still be caught by the EU AI Act where your AI output is used in the EU, or by US and Australian rules where you operate there.

Want this set up and handled for you?

Start with a fixed-price Trusted Numbers Review: two weeks, written findings on why your figures disagree, and one fixed price to put it right.