Everything written on this page is independent. I don’t sell software and I take no fees from anyone who does. Nothing changes for me whichever platform your brokerage runs.
Nobody at your brokerage decided to adopt AI. One by one the JAVLN updates arrive: an AI-powered Client Activity Summary in Officetech, content summarisation and search in the platform, agentic and copilot capability named by the CEO as where things are heading. Updates like these don’t get an adoption decision, so they never get a compliance look either.
From 10 December, that gap matters. Your privacy policy will need to disclose where computer programs shape decisions about clients, and features nobody consciously chose are the ones nobody has checked.
What the rules say
The new rules are about decisions. From 10 December 2026, if your firm is covered by the Privacy Act, your privacy policy has to disclose where a computer program uses personal information to make a decision that could significantly affect someone, or to do something substantially and directly related to making one. Scoring, flagging or blocking something in a way that shapes what a person decides next can be enough, even when a person makes the final call. So the practical question for a brokerage is not “do we use AI”. It is “which decisions about clients do we make, and what does software do inside them”.
Two points are commonly misunderstood. The disclosure covers the kinds of personal information used and the kinds of decisions involved. You are not required to explain how a system’s internal logic works. And “computer program” is defined broadly. Ordinary rule-based automation is in scope, not just AI.
Getting this wrong carries real penalties. The regulator can issue compliance notices and infringement notices for a privacy policy that falls short, and court-imposed penalties for a corporation at this tier currently run to the low hundreds of thousands. But for a brokerage the sharper risk is not the fine. Your business runs on clients trusting you with sensitive information, and the regulator has already been sweeping privacy policies in high-risk sectors and publishing what it finds. Being named for a non-compliant policy costs more than the notice does.
I also want to note that being in scope is not a black mark. The rules do not say automated decision-making is bad, and they do not tell you to stop. Some of the features most likely to be in scope are the ones doing the most for your clients. Fast renewals and broad quote coverage are good things. The obligation is simply to say in your privacy policy that a program plays that role. This is why not acting is the unnecessary risk: the fix is a mapping exercise and a few paragraphs of drafting, the rules have been public since late 2024, and the deadline is simply arriving.
Walking JAVLN’s features through the test
The useful exercise is not asking whether JAVLN is compliant. This obligation attaches to your firm’s processes, not to the software itself. The same feature, configured the same way, can be in scope at one brokerage and out of scope at the next, because what matters is the process around it: what the feature feeds into, who acts on its output, and what the client experiences as a result. That is also why asking JAVLN will not settle it, and why JAVLN is careful to say it keeps human oversight at the centre as AI becomes part of broker workflows.
Plenty of automation is clearly out of scope. JAVLN’s automated bank reconciliation is a computer program, but it does not go near a decision about a client’s interests. The features worth attention are the ones sitting inside decisions.
The examples below are illustrations, not rulings. They show how the same feature lands differently depending on the process around it. Your firm’s version of each will have details these sketches cannot capture, and those details are usually where the answer lives.
Multi-quote connectivity.
JAVLN describes its Platform as driving “multi-quote connectivity”: quotes from multiple insurers, gathered into one place instead of across portals and spreadsheets. This is worth particular attention because it sits inside the placement step, where a recommendation to a client actually gets formed.
If your setup uses it purely as plumbing, every quote comes back, the broker reads them all and forms a recommendation from their own judgement, then the program is moving paper faster and most firms would assess that as out of scope. The picture changes if anything between the quotes arriving and the client hearing a recommendation narrows the field. A default sort order that brokers rarely change. A shortlist. A filter that quietly drops options. At that point a program is shaping which insurers a client is ever told about, and it is hard to describe that as anything other than substantially and directly related to a decision affecting their interests. The uncomfortable question for a busy brokerage is not whether the software ranks quotes. It is whether your brokers, in practice, treat whatever appears first as the answer. And if the answer is yes, that is a disclosure to write, not a feature to switch off.
Automated renewals.
A JAVLN customer describes the biggest gain as time saved by automating tasks previously done manually, “such as our renewal process“. Renewal automation is genuinely valuable, and it spans a wide range of setups.
At one end, the system prepares renewal paperwork and reminders while a broker still reviews every file and speaks to every client before anything issues. The program is doing assembly, the broker is making the decision, and most firms would assess that as out of scope. At the other end, renewals below a premium threshold roll over automatically unless someone intervenes. There, the program is not helping with the decision. Its output effectively is the decision for every client who does not get a call, and terms or pricing can change in the process. A middle case, where the system flags which renewals deserve attention and brokers work the flagged list, is the genuinely hard one and requires an understanding of the firm: if the flagging shapes which clients get human attention, this is precisely the “substantially and directly related” territory the rules describe.
The AI Client Activity Summary.
JAVLN Officetech generates an AI-powered summary of client activity. A summary decides nothing by itself, and if advisers treat it as a starting point before reading the file, it is hard to see a decision the program is substantially shaping.
The picture shifts with how it is actually used. If summaries have quietly become the file review, so that what the AI chose to include or omit determines what an adviser knows before recommending cover, the tool has moved from convenience to input. Whether that crosses the threshold is a judgement call, and it is one your firm should make deliberately rather than discover it has made by habit.
One more thing about broking specifically
The obligation applies to organisations covered by the Privacy Act. Broadly, that means turnover above AUD 3 million, and it also captures organisations handling sensitive information regardless of turnover. Claims work routinely involves injury, health and financial hardship. A small brokerage that assumes it is under the threshold may still be in scope through its claims handling alone. Do not settle this one by guesswork.
What to do before December
The work is not complicated, but it does need doing deliberately.
- Confirm whether your firm is covered by the Privacy Act, including the sensitive information question.
- Write down each of your workflows that involves clients and identify the decision points.
- Take note of where a computer program is involved in each decision and evaluate whether it is in scope.
- For anything in scope, draft the disclosure: the kinds of personal information used and the kinds of decisions involved.
- Have your lawyer review the wording before it goes into your privacy policy.
That is the whole job. You do not need to audit JAVLN’s models or renegotiate your contract to meet this obligation.
Why there is no yes or no answer
Privacy compliance has mostly been something firms could settle at the software level. Choose a reputable vendor, sign sensible terms, keep the certifications on file. The ADM disclosure works differently. JAVLN’s automated renewals will be in scope at one brokerage and out of scope at another running the identical feature, because the difference lives in everything around the feature: whether a fresh needs conversation happens at renewal, who reviews what the system flags, what the reviewer does with the information, what the client is told and when. That is why nothing in this piece says “if you use this feature, update your policy”. No honest analysis of the software alone can say that. The answer is in how your firm works, and only your firm can see that.
If you’d rather not run this yourself
Everything above is enough to do the assessment on your own, and the five steps are the whole of it. If you would rather hand it to someone who already knows the sector, that is what I do: a fixed-price assessment of what is in scope for your firm specifically, what your privacy policy needs to say, and what to fix before December. Details on the Get sorted for the Privacy Act changes page, or book a 30-minute call.