- Which Businesses Are Caught
- Privacy: What Your Chatbot Must Do With Personal Information
- Data Breaches: When You Must Notify
- Consumer Law: Accuracy and the Claims the Bot Makes
- Intellectual Property: Inputs, Outputs and Ownership
- Security, Vendor Risk and Records
- What Happens if You Get It Wrong
- Compliance Checklist
- Where a Lawyer Helps
- Why the Collection Notice Comes First
A website chat widget, a support assistant inside your help desk, or staff using ChatGPT to draft emails can each save your business real time. Each of those uses is also a legal event. When a chatbot collects a customer's name, stores a support transcript, or publishes an answer as fact, it triggers obligations under Australian privacy, consumer, intellectual property and employment law that you carry as the business operating the tool.
There is no dedicated Australian AI law and no blanket ban on chatbots in business. The rules that apply are the ones you already deal with, applied to a new set of facts, plus the government's Voluntary AI Safety Standard, which tells you what good practice looks like. This guide sets out which businesses are caught, the duties that attach at each stage of an AI rollout, and the consequences of missing them.
Which Businesses Are Caught
The obligations that apply depend on who you are and what your tool does. The main points of contact with the law are:
- Privacy: The Privacy Act 1988 (Cth) (the Act) applies to most businesses with an annual turnover above $3 million in the previous financial year (s 6D). Some businesses are covered regardless of size, including health service providers and businesses that trade in personal information. If you are outside the Act, you still cannot assume you are unregulated, because the new statutory tort for serious invasion of privacy applies to anyone.
- Consumer law: The misleading or deceptive conduct prohibition in the Australian Consumer Law (the ACL), which is Schedule 2 of the Competition and Consumer Act 2010 (Cth), applies to every person in trade or commerce. There is no turnover threshold.
- Consumer guarantees: If you sell AI features to consumers, the ACL's consumer guarantees can apply. A "consumer" includes anyone who acquires goods or services priced at or under $100,000, or of a kind ordinarily acquired for personal, domestic or household use (ACL s 3).
- Intellectual property: Copyright protection is automatic, so the question is never whether you registered anything, but whether a human author was involved.
- Regulated advice: If your tool gives financial, legal or medical advice, sector rules may apply on top of everything else.
Privacy: What Your Chatbot Must Do With Personal Information
If your chatbot collects names, emails, purchase histories or chat transcripts, the Australian Privacy Principles (the APPs) in Schedule 1 of the Act set the baseline. The duties most relevant to an AI rollout are:
- Collect only what you need: APP 3 requires that personal information be collected only where it is reasonably necessary for your functions or activities. Do not let the chatbot capture more than the task requires.
- Give a collection notice at the point of capture: Under APP 5, at or before the time you collect personal information you must take reasonable steps to notify the individual of who you are, what you collect, why, and how it will be used and disclosed. For a chat widget, that notice belongs under the input box, not buried in a policy.
- Keep your privacy policy accurate: APP 1 requires you to maintain a clearly expressed, up-to-date policy that reflects what your chatbot actually does with data, including whether a third-party AI provider processes it.
- Respect use and disclosure limits: APP 6 says personal information collected for one purpose cannot be used or disclosed for another unless an exception applies. Using customer support transcripts to train a model is a new purpose.
- Address cross-border processing: If your AI provider hosts or processes data overseas, the cross-border disclosure rules and your contracts need to deal with where the data goes and on what terms.
- Secure the information: APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. For AI tools, that includes access controls, logging and configuring the provider not to train on your data.
On the vendor side, put a data processing agreement in place so the provider's use is limited to your instructions, security standards are set, and breach notification is contractually guaranteed. For internal use, minimise what staff paste into prompts and switch off training modes where the tool offers them.
Data Breaches: When You Must Notify
The Notifiable Data Breaches scheme sits in Part IIIC of the Act. An eligible data breach occurs when there is unauthorised access to, or unauthorised disclosure or loss of, personal information held by an entity, and a reasonable person would conclude there is a likely risk of serious harm to the individuals concerned (s 26WE).
When you become aware of reasonable grounds to believe an eligible data breach has happened, you must prepare a statement describing the breach and give it to the Office of the Australian Information Commissioner as soon as practicable, and notify the affected individuals (or publish the statement on your website if individual notification is not practicable) (ss 26WK and 26WL). The Commissioner can also direct you to notify (s 26WR).
There is an important exception. If you take remedial action before the access or disclosure results in serious harm, and as a result a reasonable person would conclude the breach is no longer likely to result in serious harm, the incident is not an eligible data breach at all (s 26WF). That is the strongest reason to keep a tested breach response plan rather than treating notification as the first step. Chatbots concentrate this risk because prompts and transcripts can sit in vendor logs long after a conversation ends.
Consumer Law: Accuracy and the Claims the Bot Makes
Section 18 of the ACL provides that a person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. If your chatbot publishes product descriptions, answers support questions, or generates marketing copy that reaches customers, the output is your conduct. Publishing an unchecked AI answer that overstates what a product does is no different, in law, from a human employee saying it.
The practical duties that follow are:
- Human review of customer-facing output: Build a check into the workflow for anything the chatbot can publish, send or rely on.
- No promises the bot cannot keep: Train staff on what can and cannot be claimed, and keep the bot's knowledge base accurate and current.
- Do not rely on disclaimers: A disclaimer can set expectations about the limits of the tool, but it does not cure a statement that is misleading. Saying "AI-generated, check for accuracy" does not make a false claim true.
- Watch the guarantees: If you sell an AI feature to a consumer, the consumer guarantees apply to it, and a chatbot that routinely gives wrong answers may fail the requirements of acceptable quality and due care and skill.
- Know the regulated advice line: If your tool gives financial advice, that may be financial product advice requiring an Australian financial services licence under the Corporations Act 2001 (Cth). Legal and medical advice can engage state and territory legal profession laws and health practitioner regulation. If a use case drifts toward advice, get advice yourself before launch.
Intellectual Property: Inputs, Outputs and Ownership
Think of IP on two sides of the model: what you put in and what comes out.
On the input side, your knowledge base, customer data and internal documents are confidential assets. Check the provider's terms to ensure your data is not used to train the model for others, and back that up with confidentiality clauses and access controls.
On the output side, Australian copyright law requires a human author. In Acohs Pty Ltd v Ucorp Pty Ltd [2012] FCAFC 16, the Full Federal Court held that copyright did not subsist in HTML source code generated by a computer program, because no human had produced it. The same logic applies to purely AI-generated text or images: if no human contributed sufficient creative input, there may be no copyright protection at all. That has two practical consequences. First, content you assumed you owned may be copyable by competitors. Second, you cannot assume the output is clean, because a model can reproduce material from its training data that resembles third-party works.
The duties are to document human involvement where you want protection, run checks on high-risk output such as logos, packaging and ad campaigns, and fix ownership in contracts. Employment agreements should confirm the business owns outputs created in the course of employment, and contractor agreements should assign IP and impose confidentiality.
Security, Vendor Risk and Records
Any system that ingests customer information needs proportionate security. Vet providers on certifications, data residency, audit logging and access controls; restrict prompts to the minimum data required; and monitor logs for misuse.
On retention, there is no general federal data retention law that tells an ordinary business how long to keep chat logs. The federal data retention regime applies to telecommunications providers. Your obligations come from two directions. APP 11 requires you to destroy or de-identify personal information once it is no longer needed, and specific record-keeping rules, such as those for tax and employment records, can require particular documents to be kept for set periods. Decide what you keep and for how long, schedule deletion, and make sure your chatbot's log settings match that schedule.
What Happens if You Get It Wrong
The consequences of getting it wrong fall into four areas:
- Privacy penalties: A serious or repeated interference with privacy is a civil penalty provision. For a body corporate, the maximum penalty is the greatest of $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover; for individuals it is $2.5 million (s 13G of the Act). The OAIC can investigate, make determinations including compensation orders, and pursue penalties in the courts.
- The new privacy tort: The Act now contains a statutory cause of action in tort for serious invasion of privacy. A plaintiff must show an intrusion upon seclusion or a misuse of information, a reasonable expectation of privacy, intentional or reckless conduct, and seriousness, with a public interest balance. It is actionable without proof of damage. A chatbot that mishandles or leaks personal information is exactly the kind of conduct this tort was written for.
- ACL exposure: Breaches of penalty provisions in the ACL, such as the false representation provisions, can attract civil penalties for a body corporate of up to the greatest of $100 million, three times the benefit obtained, or 30% of adjusted turnover (ACL s 224). Misleading or deceptive conduct under s 18 is not itself a penalty provision, but it exposes you to damages and injunctions, and the ACCC and state regulators actively watch AI-enabled selling.
- Contract and reputational risk: Vendor claims, customer disputes and regulator scrutiny all become more expensive after an incident. A breach notification also lands in a public register.
Compliance Checklist
Work through this checklist before launch:
- Map use cases and data: List where AI is used and what data each use involves. Identify personal information and confidential material.
- Add a collection notice: Place it at the point of capture, and update your privacy policy to reflect chatbot practices.
- Put data processing agreements in place: With providers, disable training on your data and confirm data residency.
- Build human review: Add it to any workflow where AI output reaches customers.
- Issue an AI use policy: Covering approved tools, no sensitive data in prompts, and mandatory review of customer-facing output, with staff trained on it.
- Keep a breach response plan: Test it so you can assess and act before any notification clock starts.
- Set a retention schedule: For logs and prompts, with deletion aligned to it.
- Fix IP ownership: In employment and contractor agreements, and check high-risk output for infringement.
- Assess the advice line: If your tool answers questions about finance, health or the law.
Where a Lawyer Helps
A lawyer's value here is not drafting the chatbot, but mapping the obligations around it. A practitioner can run a privacy impact assessment over your data flows, draft or review the data processing agreement and privacy documents, advise on whether a use case crosses into regulated advice, review IP ownership clauses, and build a breach response plan that matches the NDB scheme. The cost of that work is small against a $50 million penalty exposure or a privacy tort claim.
Why the Collection Notice Comes First
If you take one action this week, make it the collection notice under the chat input box. It is the cheapest, most visible and most often missed duty in the whole rollout. Businesses routinely assume the AI provider's own pop-up covers it, or that a privacy policy link somewhere on the site is enough, but APP 5 requires notice at or before collection, and it must say what you do with the data, including whether a provider overseas processes it. With the privacy tort now in force, misuse of information carries direct liability rather than a regulator's letter. A short notice under the box, a checked "no training" setting, and a vendor contract that matches your practices will put you ahead of most businesses that launch a chatbot this year.