2026-07-20OPINION · WORKPLACEAI · HRCOMPLIANCE · PRIVACYGOVERNANCE · AIREGULATION · DATAGOVERNANCE5 MIN READ READ
FILED UNDER

Did Your Board Know HR Bought an AI Surveillance Tool?

Procurement approved it. Legal wasn't in the room. Regulators are starting to ask questions.

The HR Tool You Approved Is Now a Compliance Problem You Don’t Know You Have

Most CEOs and CHROs who signed off on AI-assisted hiring platforms, performance monitoring tools, or workforce analytics software in the last three years did not treat those decisions as data governance decisions. They treated them as procurement decisions. That distinction is now catching up with them.

Victorian Labor’s proposal to restrict workplace AI and biometric surveillance — covered by iTnews — is not an isolated state-level experiment. It reflects a regulatory direction that is moving federally, and organisations that deployed these tools quietly, without privacy impact assessments, without legal counsel, and without board visibility, are sitting on undisclosed compliance exposure. Most of them have no idea.

What HR Actually Bought

The platforms are not mysterious. They include tools that score candidates using behavioural or linguistic analysis, systems that infer employee sentiment from email and calendar patterns, productivity monitoring software that tracks keystrokes and application usage, and scheduling tools that use historical performance data to make workforce decisions. Many are bundled inside larger HR platforms — Workday, SAP SuccessFactors, Microsoft Viva — which makes them easier to approve and harder to scrutinise.

The procurement story is usually the same. HR identifies a capability. A vendor demo impresses. IT confirms integration. Legal is not in the room. Privacy counsel is not in the room. The privacy impact assessment either does not happen or is completed after the fact as a box-ticking exercise. The board sees a line item on an operational budget, not a data governance decision with legal exposure attached to it.

That is the problem. Not the technology itself — the decision-making process that treated it as something other than what it is.

What These Tools Actually Do With Employee Data

The regulatory concern is not hypothetical. These tools collect and infer far more than organisations realise when they sign the contract. Sentiment inference from communication metadata. Productivity scoring that becomes a de facto performance record. Candidate assessments that may embed demographic bias. Biometric data — facial recognition for attendance, voice analysis for call centre monitoring — that carries specific legal obligations most HR buyers have never read.

Under the Privacy Act 1988, employee records have historically enjoyed an exemption from the Australian Privacy Principles. That exemption is narrower than most organisations assume, and it does not cover data collected before employment begins — meaning AI-assisted candidate screening sits in a different legal position than internal performance monitoring. The exemption is also under active reconsideration as part of the ongoing Privacy Act reform process, which the Attorney-General’s Department has been progressing since the 2022 review.

Organisations that assumed the employee records exemption gave them broad licence to deploy whatever HR analytics they chose made a legal assumption without legal advice. Some of them made it years ago and have not revisited it.

Why Victoria Matters Beyond Victoria

State-level workplace surveillance legislation does not stay at the state level. Victoria introducing restrictions creates pressure on the federal government to harmonise, particularly given the Privacy Act reform already in motion and Labor’s stated commitments to strengthening worker protections. It also creates immediate exposure for Victorian employers — which includes every national organisation with Victorian employees.

More importantly, it signals what regulators and legislators now believe is reasonable. When a regulator eventually investigates an AI-assisted HR decision — a hiring outcome that appears discriminatory, a dismissal that relied on algorithmic performance data, a redundancy process informed by productivity monitoring — the existence of this regulatory conversation will form part of the context. “We didn’t know this was regulated” becomes a harder argument when the legislative debate was public.

The OAIC has also been explicit, in its guidance on privacy and AI, that automated decision-making involving personal information requires transparency and accountability. Organisations using AI tools to inform hiring or performance decisions that affect individuals are already operating in a space where regulatory expectations exist — even before new state legislation passes.

The Board Visibility Problem

Here is the specific governance failure most boards have not addressed: they do not know what employee data their HR platforms are collecting, inferring, or sharing with third parties.

Ask the question in your next board meeting. Ask the CHRO or CIO to describe what data your HR platforms collect about employees and candidates, what is inferred from that data, who it is shared with, and what the legal basis for collection and processing is. If the answer is confident and complete, you are in better shape than most. If the answer is vague, deferred, or met with clarifying questions about what you mean, you have identified a governance gap that has regulatory and reputational consequences.

This is not a hypothetical risk. It is the kind of undisclosed exposure that surfaces during due diligence, regulatory investigation, or employment disputes — at which point the cost of having not done the work upfront becomes very clear.

What Needs to Happen Now

This is not a technology problem to hand to IT. The response belongs with the CEO, the CHRO, and legal counsel, and it has three components.

First, inventory what you have actually deployed. Not what procurement approved, but what is running. Many organisations have HR tools in active use that were never formally approved because they were bundled inside a platform that was. Include Microsoft Viva, any LinkedIn Talent products, and any third-party integrations with your ATS or HRIS.

Second, commission a legal review of what those tools collect and infer, against the current Privacy Act obligations and the anticipated direction of reform. That review should specifically address the employee records exemption, candidate data, and any biometric collection.

Third, brief your board. Not on the technology — on the exposure. The board should understand what employee data the organisation holds, what it is used for, and whether current practices are defensible under regulatory scrutiny. If they cannot answer those questions today, they cannot govern the risk.

The Victorian proposal is not the threat. The threat is that your organisation made a series of quiet procurement decisions that created legal and regulatory exposure, and nobody with the authority to manage that exposure was involved. That is fixable. But not while it remains invisible.

Next dossier
Certification Is Not Posture: What the CMMC Pause Reveals →
Engage the author
Adam van Vliet is currently taking on briefs for FY26.
Brief Adam
Share