The fastest way to create an AI risk is to let staff improvise with confidential or personal information while the organisation assumes the tool is “just helping with a draft”.
AI does not suspend privacy obligations
The OAIC makes clear that the Privacy Act applies when AI use involves personal information. Inputs matter, but so do outputs: inferred, incorrect or artificially generated information may still be personal information when it concerns an identifiable person.
As a matter of best practice, the OAIC recommends that organisations do not enter personal information - particularly sensitive information - into publicly available generative AI tools because of the complexity of the privacy risks. The agency also advises privacy-by-design and a Privacy Impact Assessment when organisations consider AI products.
Five questions before approving a product
- What exact business purpose requires the information?
- Does use of the information match the purpose for which it was collected, or is consent or another basis required?
- Where is the data processed and stored, and can the provider use inputs for model training?
- Who can access prompts, files, outputs, logs and support records?
- Can the organisation export, correct and delete information when the service ends?
Create usable rules for staff
A policy should classify information in language staff understand: public, internal, confidential, personal and sensitive. It should name approved tools and explain what may be entered into each one. Training should use realistic examples from the organisation, not abstract warnings.
Design for minimisation
The safest data is data the AI never receives. Remove unnecessary identifiers, restrict retrieval to the engagement and role, set retention rules, log material access and keep sensitive processing behind controlled services. Where a lower-data method can achieve the outcome, use it.
Trust is part of the product
Clients should be able to understand when AI is involved, what it does, what data it uses and how a person can intervene. Privacy notices, AI transparency and human contact should be designed into the experience rather than added after launch.
Next step
Book a privacy review
Ask Studio Ambira to review the privacy and data boundaries of your proposed AI workflow.
Book a privacy reviewSources
Studio Ambira's interpretation is separated from regulator and research findings. Sources checked on .
- 1.Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products
- 2.National AI Centre, Guidance for AI adoption: foundations (5 May 2026)
- 3.Australian Signals Directorate, Engaging with artificial intelligence