Australia AI and Responsible Technology
How DECTIFY aligns its models and deployments with Australia's AI Ethics Principles, the Voluntary AI Safety Standard, and the OAIC's guidance on facial recognition.
The engineering practice — lifecycle, evaluation, model cards, thresholds, monitoring, withdrawal and governance bodies — is set out at India AI and Responsible Technology and is identical worldwide. This page states how that practice maps onto Australian instruments and what Australian law adds.
1. The framework
Australia has no binding horizontal AI statute. The instruments that govern us are a mix of voluntary standards, regulator guidance, and existing law applied to AI:
- Australia's AI Ethics Principles (Department of Industry, Science and Resources) — eight voluntary principles.
- Voluntary AI Safety Standard — ten guardrails for organisations developing or deploying AI, published by the National AI Centre.
- Proposals for mandatory guardrails in high-risk AI settings — the consultation framework that would make several of those guardrails binding. Facial recognition in public or quasi-public space falls squarely within the high-risk framing.
- OAIC guidance on facial recognition technology in commercial settings, and the Commissioner's determinations applying the Privacy Act to FRT deployments.
- Privacy Act 1988 (Cth), including the automated decision-making transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024.
- Australian Consumer Law — misleading or deceptive conduct, which is what an unsubstantiated accuracy claim is.
- Anti-discrimination law — the Racial Discrimination Act 1975, Sex Discrimination Act 1984, Disability Discrimination Act 1992 and Age Discrimination Act 2004, each of which can be engaged by a system with differential error rates.
2. Mapping to the AI Ethics Principles
| Principle | How we give it effect |
|---|---|
| Human, societal and environmental wellbeing | Deployment review declines uses listed at s.5 regardless of contract value |
| Human-centred values | No profiling by protected attribute; no monitoring of lawful protest, assembly, worship or journalism |
| Fairness | Disaggregated error reporting by demographic group; release blocked where a group error rate materially exceeds the aggregate |
| Privacy protection and security | APP compliance, biometric templates separately encrypted and independently keyed, bounded retention, no bulk template export |
| Reliability and safety | Stress evaluation across the conditions that degrade field performance; conservative default thresholds; published failure modes |
| Transparency and explainability | Published model cards; confidence displayed with every result; the disclosure record described at section 5 |
| Contestability | The customer must be able to explain and review any decision. Harm reports to responsible-ai@dectify.in. Access and correction under APP 12 and 13 |
| Accountability | Named governance roles; approval right separated from revenue ownership; withdrawal authority that has been exercised |
3. Voluntary AI Safety Standard guardrails
We treat the ten guardrails as commitments rather than suggestions, because the mandatory framework is likely to adopt substantially the same content for high-risk settings, and because a customer procuring facial recognition should not have to take our word for any of it.
| Guardrail | Status |
|---|---|
| 1. Accountability process, ownership and training | Named roles, recorded at [governance roster]; annual training for engineering and deployment staff |
| 2. Risk management process | Risk classification before development; impact assessment mandatory for identification-capable systems |
| 3. Data governance and provenance | Provenance recorded per dataset; no Customer Data without written per-product opt-in; no scraped face galleries |
| 4. Testing and monitoring | Pre-release disaggregated evaluation; field false-positive tracking; withdrawal authority |
| 5. Human control and intervention | Mandatory human review before adverse action — contractual, non-waivable, enforced in product |
| 6. Informing end users | Site signage obligation on customers; model cards; confidence shown with every output |
| 7. Contesting outcomes | Explanation record at section 5; APP 12/13 rights; harm reporting channel |
| 8. Supply chain transparency | Sub-processors, Third-Party Terms, model provenance in the card |
| 9. Records for third-party assessment | Evaluation records, model cards, audit logs and deployment reviews retained and available under NDA |
| 10. Stakeholder engagement | Consultation on deployments affecting a defined community; harm reports accepted from anyone, anonymously |
4. Facial recognition: the OAIC's position
The Commissioner has made determinations on facial recognition in commercial settings, and the through-line is consistent: a biometric template is sensitive information; collecting it requires consent unless an exception genuinely applies; a security or loss-prevention purpose does not itself create an exception; and the collection must be proportionate to the harm being addressed.
What follows for a customer deploying FaceTrack in Australia:
- A privacy impact assessment should be completed and retained before deployment, not produced after a complaint.
- The lawful basis for collecting sensitive information must be identified and recorded — consent under APP 3.3, a permitted general situation under s.16A, or the enforcement body exception under APP 3.4.
- Notice must be genuine. A sign at the door that nobody reads, on a system that enrols every passer-by, is not consent.
- Proportionality is assessed against the specific harm. Blanket identification of every customer entering a premises to address occasional theft has been found disproportionate.
- Templates of people who are not the subject of any concern must not be retained. Our 72-hour ambient template expiry exists for exactly this.
DECTIFY will decline a deployment where the customer cannot articulate its lawful basis, and will not configure indiscriminate enrolment. The operational controls are at Biometric, ANPR and Facial Recognition Policy.
5. Automated decision-making transparency
The Privacy and Other Legislation Amendment Act 2024 requires an APP entity's privacy policy to disclose where personal information is used in a computer program to make, or substantially and directly assist in making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.
DECTIFY makes no such decision. We do not decide anything about an individual. Our products produce probabilistic outputs for customers, and our terms prohibit a customer from taking adverse action on an output alone without human review.
Where a customer nonetheless uses an output to substantially assist a decision affecting an individual, the customer is the APP entity making that decision and must make its own disclosure. On request, we provide the customer with what it needs to do so and to answer a contest: the model version, the confidence score, the threshold in force and who set it, the source imagery, the audit record of the human review, and the model card.
6. Accuracy claims and the Australian Consumer Law
An unsubstantiated performance claim is misleading or deceptive conduct under section 18 of the Australian Consumer Law, and a false representation about the performance characteristics of goods or services under section 29. We therefore state accuracy only with the evaluation methodology and dataset attached, we publish the conditions under which performance degrades, and we do not quote a laboratory figure as though it were a field figure.
If you believe a DECTIFY performance claim is not substantiated, write to legal@dectify.in and we will either substantiate it or withdraw it.
7. Reporting a harm
responsible-ai@dectify.in. Reports may be anonymous. Acknowledged within three (3) business days; investigated; the reporter is told what we found and what we changed, unless that would disclose a customer's confidential information. Counts are published at Compliance and Security Updates.
Statutory routes: the OAIC for privacy, the Australian Human Rights Commission for discrimination, and the ACCC or your State fair trading office for a misleading claim.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India