Insights
GovernPrivacy and trust

Before staff paste client data into AI, read this

Public AI tools can create privacy, confidentiality and control risks. Australian SMEs need clear data rules, product due diligence and privacy-by-design before scaling use.

By Geoff Gourley · 7 min read · Reviewed

The fastest way to create an AI risk is to let staff improvise with confidential or personal information while the organisation assumes the tool is “just helping with a draft”.

AI does not suspend privacy obligations

The OAIC makes clear that the Privacy Act applies when AI use involves personal information. Inputs matter, but so do outputs: inferred, incorrect or artificially generated information may still be personal information when it concerns an identifiable person.

As a matter of best practice, the OAIC recommends that organisations do not enter personal information - particularly sensitive information - into publicly available generative AI tools because of the complexity of the privacy risks. The agency also advises privacy-by-design and a Privacy Impact Assessment when organisations consider AI products.

Five questions before approving a product

  • What exact business purpose requires the information?
  • Does use of the information match the purpose for which it was collected, or is consent or another basis required?
  • Where is the data processed and stored, and can the provider use inputs for model training?
  • Who can access prompts, files, outputs, logs and support records?
  • Can the organisation export, correct and delete information when the service ends?

Create usable rules for staff

A policy should classify information in language staff understand: public, internal, confidential, personal and sensitive. It should name approved tools and explain what may be entered into each one. Training should use realistic examples from the organisation, not abstract warnings.

Design for minimisation

The safest data is data the AI never receives. Remove unnecessary identifiers, restrict retrieval to the engagement and role, set retention rules, log material access and keep sensitive processing behind controlled services. Where a lower-data method can achieve the outcome, use it.

Trust is part of the product

Clients should be able to understand when AI is involved, what it does, what data it uses and how a person can intervene. Privacy notices, AI transparency and human contact should be designed into the experience rather than added after launch.

Next step

Book a privacy review

Ask Studio Ambira to review the privacy and data boundaries of your proposed AI workflow.

Book a privacy review

Sources

Studio Ambira's interpretation is separated from regulator and research findings. Sources checked on .

  1. 1.Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products
  2. 2.National AI Centre, Guidance for AI adoption: foundations (5 May 2026)
  3. 3.Australian Signals Directorate, Engaging with artificial intelligence

Keep reading

Stay in the loop

Occasional notes on building AI-native businesses — practical, no noise. Unsubscribe any time.