Disclaimer: This article provides technical guidance only and does not constitute legal advice. For legal interpretation of ADM obligations under Australian privacy law, please consult a qualified legal professional.
From 10 December 2026, Australian organisations will face new Automated Decision Making (ADM) transparency obligations under the Privacy and Other Legislation Amendment Act 2024. These obligations require APP entities to include information in their privacy policies about certain types of automated decisions made using personal information.
The Office of the Australian Information Commissioner (OAIC) outlines that ADM transparency applies when:
- a computer program makes a decision, or performs an action substantially and directly related to making a decision
- the decision could reasonably be expected to significantly affect the rights or interests of an individual
- personal information is used in the operation of the program
These obligations apply whether the decision is beneficial or adverse, and include situations where a system refuses or fails to make a decision. The OAIC will release detailed guidance in 2026, but organisations can begin preparing now by understanding the technical behaviour of their AI agents.
For businesses using Copilot Studio agents inside Dynamics 365 and the Power Platform, this change introduces important technical considerations around how agents operate, how they use personal information, and how their decision logic is governed.
What ADM transparency means from a technical standpoint
The ADM obligations require organisations to disclose:
- the kinds of personal information used in automated decision-making
- the kinds of decisions made solely by computer programs
- the kinds of decisions substantially informed by computer programs
Before legal teams can update privacy policies, technical teams must understand:
- which systems perform ADM
- how those systems use personal information
- what decisions they make or influence
- how those decisions affect individuals
- how those decisions are triggered inside Dynamics 365
Where Copilot Studio AI agents in Dynamics 365 may intersect with ADM
Copilot Studio AI agents can perform a wide range of actions inside Dynamics 365 and Dataverse.
From a technical standpoint, ADM transparency may be relevant when an agent:
- reads or uses personal information
- produces outputs that staff rely on when making decisions
- performs steps substantially related to a decision
- triggers workflows that affect access to services or entitlements
- updates records that influence downstream decisions
- automates parts of a multi step assessment process
Whether these actions fall under ADM obligations depends entirely on:
- the nature of the decision
- the impact on the individual
- the degree of human oversight
- the industry context
- the significance of the service or support involved
Dynamics 365 is used across many sectors including healthcare, financial services, government, social support, education and regulated industries, where decisions may affect rights or interests. Technical teams should therefore understand how agents behave, what data they use, and what decisions they influence, so legal teams can determine whether ADM obligations apply.
5 technical best practices that support ADM transparency
ADM transparency doesn’t just introduce a new requirement come December 2026, it reinforces the importance of designing, documenting and governing Copilot Studio agents properly from the start. These practices are already essential for building reliable AI agents in Dynamics 365, ADM simply adds another layer of clarity to how your agents work.
1. Plan and document agent behaviour from the outset
Clear planning is the foundation of both good agent design and ADM readiness. Organisations should maintain documentation that describes:
- the purpose of each agent
- the data it uses
- the actions it performs
- the decisions it supports or informs
Many organisations also prototype and evaluate agent behaviour upstream in Microsoft Foundry (formerly Azure AI Studio), ensuring prompts, grounding data and evaluation steps are well understood before agents are deployed into Copilot Studio.
This is standard best practice for Copilot Studio agent design and ensures teams always understand how agents behave.
2. Understand where agents interact with personal information
ADM transparency highlights the importance of knowing how agents use data. Technical teams should have visibility into:
- Dataverse tables accessed
- fields read or written
- connectors used
- flows triggered
- prompts or topics referencing personal information
Where agents rely on retrieval augmented generation or external knowledge sources, Microsoft Foundry provides traceability and evaluation tools that help teams understand how personal information is used during inference and how agent outputs are generated.
This isn’t just about classifying ADM, it’s about maintaining clear data pathways, which is essential for governance, protection and long term reliability.
3. Map dependencies and decision related workflows
Copilot Studio agents often sit inside broader Dynamics 365 processes. Understanding how agent outputs feed into workflows helps ensure:
- predictable behaviour
- clear human oversight
- reliable downstream processes
- continuity across environments
This is part of good solution architecture and becomes even more important when organisations need to explain how automated steps contribute to decision making.
4. Strengthen governance and lifecycle management
ADM transparency reinforces the need for strong governance around AI agents. This includes:
- change control
- versioning
- approval workflows
- monitoring
- rollback capability
- environment separation
- permission scoping
For organisations using Microsoft Foundry alongside Copilot Studio, evaluation pipelines and versioning controls support consistent governance and help teams maintain transparency over how agent logic evolves.
These practices already underpin reliable Dynamics 365 and Power Platform solutions, ADM simply adds another reason to maintain them.
5. Protect agents and maintain continuity over time
Reliable agent behaviour depends on having the ability to:
- restore previous versions
- recover agent configurations
- maintain dependency aware backups
- ensure continuity across environments
This is part of protecting Copilot Studio agent assets and maintaining long term operational stability and it supports transparency by ensuring organisations can trace how agents have evolved.
Bringing Copilot Studio best practices and ADM transparency together
When organisations have:
- clear AI agent documentation
- strong AI governance
- reliable agent lifecycle management
- protected agent configurations
- well understood data flows
…they are already in a strong position to support ADM transparency when legal teams need to update privacy policies.
ADM doesn’t change how Copilot Studio agents should be built, it simply reinforces the importance of good design, governance and protection, which are already best practice for Dynamics 365.
Walkerscott helps organisations design and build agentic AI in Dynamics 365 and the Power Platform, supported by Microsoft Foundry for developing, grounding and governing AI components from the start. This ensures agents are documented, protected and aligned with ADM transparency over time.
How Walkerscott supports organisations
Walkerscott provides Dynamics 365 and AI consulting to help organisations:
- design and build agentic AI using Copilot Studio and Microsoft Foundry
- develop and ground AI components in Foundry before deployment into Dynamics 365
- understand how agents interact with Dataverse
- map agent behaviour and dependencies
- implement lifecycle and environment strategy
- strengthen governance and change control
- protect agents with backup and selective restore
- ensure agents are designed and governed in ways that naturally support ADM transparency
Not sure where to start with assessing ADM impacts on your AI and automations in Dynamics 365?
Get in touch with us today.