1. What AI document review is, and what it can't tell you
  2. When AI review earns its keep, and when it is a liability
  3. Does the Privacy Act even apply to your business?
  4. What the APPs require once you upload documents
  5. Confidentiality and trade secrets: a risk that has nothing to do with privacy law
  6. Who owns what when AI helps with drafting
  7. The Australian Consumer Law catch: the AI did not say it, you did
  8. A safe rollout: the checklist that keeps AI review useful
  9. The documents and policies that make AI review safe
  10. When AI-assisted review needs a lawyer
  11. Why the law still treats the AI tool as your tool

A supplier agreement lands in your inbox, there is a stack of renewals behind it, and a colleague suggests pasting the lot into an AI tool for a quick read. AI document review can summarise long agreements, compare versions and flag risky clauses in seconds, and for a small business that genuinely saves time. But the tool you paste your contracts into is also a place where privacy obligations, confidentiality and intellectual property can quietly go wrong. This article sets out what AI document review can and can't do, which Australian laws apply when you use it, and the practical steps that keep the time savings without the exposure.

What AI document review is, and what it can't tell you

AI document review uses software, often built on large language models, to read and analyse contracts and other documents. It can summarise a long agreement, spot unusual clauses, suggest drafting tweaks and compare versions of the same document to show what changed.

The limits matter more than the capabilities. An AI tool applies statistical pattern matching, not legal analysis. It does not know your risk appetite, your negotiation strategy, or whether a particular clause is valid or enforceable under Australian law. Its output is only as good as the document you feed it and the prompt you write, and when it gets something wrong it tends to do so confidently. Treat it as a fast first reader that produces drafts to check, not as a source of conclusions you can act on.

When AI review earns its keep, and when it is a liability

For a small business, the sensible split is between low-risk administrative work and anything that could actually hurt you.

Good use cases include:

  • First-pass triage: working through standard agreements such as NDAs and low-value supplier contracts to pull out key terms and obvious red flags.
  • Version comparisons: checking what changed between an old and a new draft before you sign or negotiate.
  • Internal summaries: answering questions like "what are the termination triggers in this agreement?" for stakeholders.
  • Checklist building: testing your own must-have and must-avoid clause list against incoming documents.

Use AI with caution, or not at all, for:

  • High-stakes or unusual deals: equity, IP assignments, complex licensing and financing arrangements, where a misread is expensive.
  • Documents containing sensitive personal or health information: the privacy risk of uploading them is high.
  • Contracts under specialist regimes: franchising, financial services and healthcare agreements carry obligations AI will not reliably pick up.
  • Anything where an error creates real liability: if a wrong summary would lead you into a bad commitment, that document stays with a human.

The working model is human-in-the-loop. AI speeds up the administrative reading, and a qualified reviewer makes the final call. For material or unfamiliar contracts, that reviewer should be a lawyer.

Does the Privacy Act even apply to your business?

The first question most guides skip is whether the Privacy Act 1988 (Cth) applies to you at all. It does not cover every business. Under s 6D, a business is a "small business" if its annual turnover for the previous financial year was $3 million or less, and most small businesses are exempt from most of the Australian Privacy Principles (APPs).

There are exceptions. The exemption does not apply if your business provides health services, trades in personal information, or is a Commonwealth government contractor, among other carve-outs. So a small business that happens to hold customer health data is already inside the Act.

And the exemption has an expiry date. The Privacy and Other Legislation Amendment Act 2024 (Cth) received Royal Assent on 10 December 2024, and the provisions removing the small business exemption commence on 10 December 2026. From that date, businesses with turnover under $3 million will need to comply with the full set of APPs. If you are exempt today, the practical answer is to build APP-compliant habits now rather than rework your processes in eighteen months.

What the APPs require once you upload documents

If you are an APP entity now, or will be in December 2026, uploading documents that contain personal information brings the APPs into play. Three obligations matter most for AI document review:

  • Cross-border disclosure: Most AI document review tools run on offshore cloud infrastructure, and sending documents to them can be a disclosure to an overseas recipient. APP 8 requires an APP entity, before disclosing personal information overseas, to take reasonable steps to ensure the overseas recipient does not breach the APPs. Section 16C then makes the disclosing entity accountable: the acts of the overseas recipient are treated as the acts of the entity. In other words, you cannot outsource the privacy problem to the vendor.

  • Security: The APPs require reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. A tool without adequate encryption, access controls and data residency arrangements is hard to defend as "reasonable steps".

  • Data breach notification: Part IIIC of the Privacy Act requires an entity that is aware of reasonable grounds to believe there has been an eligible data breach to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under s 26WL. If personal information leaks through an AI vendor's systems, that can be an eligible data breach, and your "data breach response plan" becomes a statutory obligation rather than good hygiene.

The OAIC has published guidance on privacy and the use of commercially available AI products, which is a useful starting point before you choose a tool. The practical consequences are straightforward: minimise what you upload, redact personal information before it goes anywhere near the tool, confirm where data is stored and processed, and make sure the vendor's terms rule out training on your data.

Confidentiality and trade secrets: a risk that has nothing to do with privacy law

Even with no personal information in sight, uploading a draft agreement can be a disclosure. Vendor personnel may be able to see prompts and uploads, some products use customer data to improve their models, and the settings that stop that behaviour are not always on by default.

If your documents contain pricing, customer lists, trade secrets or unpublished deal terms, this is a commercial risk independent of privacy law, and it is largely irreversible once the information is out. Protect it with a non-disclosure agreement with external parties who see your drafts, internal rules about what can and cannot be pasted into AI tools, and vendor settings that lock down access and prohibit training on your data.

Who owns what when AI helps with drafting

Two questions come up whenever AI produces summaries, clause language or playbooks: who owns the outputs, and does the vendor claim rights over your inputs? Check the vendor's terms for IP assignments, licences and usage rights before you rely on them.

Australian law also puts limits on AI-generated output. In Commissioner of Patents v Thaler [2022] FCAFC 62, the Full Federal Court confirmed that an AI system cannot be an inventor under the Patents Act 1990 (Cth), upholding the earlier decision in Thaler v Commissioner of Patents [2021] FCA 879. Copyright law is built around human authorship, and whether purely AI-generated material attracts copyright protection in Australia remains unsettled. The safe assumption is that AI-drafted clause language is not a protectable asset you own. Keep your own templates, playbooks and know-how as your core assets, and state in the contracts you issue that your custom terms remain yours.

The Australian Consumer Law catch: the AI did not say it, you did

Under s 18 of the Australian Consumer Law (ACL) (Schedule 2 of the Competition and Consumer Act 2010 (Cth)), a person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. There is no "the AI said so" defence.

If you rely on an AI summary when you make claims to customers, whether about warranties, performance or refund policies, the accuracy of those statements is your responsibility, and the ACL's specific prohibitions on false or misleading representations in Part 3-1 can bite as well. Treat AI outputs as drafts to verify before they reach a customer, especially where customer rights, refund policies or liability limitations are involved.

A safe rollout: the checklist that keeps AI review useful

The businesses that get this right treat AI review as a process, not a shortcut. The steps are:

  1. Map your use cases and classify risk: List the document types you want to review, grade them low, medium or high risk by value, complexity and data sensitivity, and decide which categories are AI-eligible at all.
  2. Do vendor due diligence: Check security (encryption, certifications), data residency and access controls, confirm the tool will not train on your data by default, and set user permissions and multi-factor authentication for your team.
  3. Build a review playbook: Define what is acceptable, what needs negotiation and what is a hard "no". Write standard prompts that reflect your risk appetite, and include escalation rules for when a manager or lawyer needs to step in.
  4. Protect data and confidentiality: Redact personal information and secrets before uploading, publish internal guidance on allowed and forbidden content, and use a data processing agreement when a vendor handles personal information for you.
  5. Keep a human in the loop: Require a person to confirm every AI-generated summary or clause suggestion, and build a sign-off step for higher-risk documents.
  6. Record and audit: Save prompts, outputs and final decisions to the matter file, maintain a contract register of key dates and risk positions, and align your incident response with the data breach notification rules.
  7. Train your team: Cover safe prompting, redaction and escalation, and refresh training when you change vendors or update the playbook.

There is also a national framework to borrow from. The Australian Government's Voluntary AI Safety Standard, published in September 2024, sets out ten guardrails for developing and using AI, and the October 2025 Guidance for AI Adoption distils six essential practices. It is voluntary, but it gives a small business a tested structure for an AI governance policy without reinventing one.

The documents and policies that make AI review safe

AI review works best when you measure every output against your own pre-approved positions. That means having the core documents in place:

  • Terms of trade or customer contract: your baseline commercial terms, covering scope, fees, IP ownership, liability caps and termination rights.
  • Privacy policy: an accurate description of how you collect, use and disclose personal information, including what happens when it flows through an AI tool.
  • Non-disclosure agreement: protects confidential information when you share drafts or test vendors.
  • Data processing agreement: sets privacy and security obligations when a vendor processes personal information on your behalf.
  • Generative AI use policy: internal rules for staff on permitted use, redaction and escalation.
  • Data breach response plan: the playbook for identifying, containing and notifying if personal information is compromised.
  • Contract review process: a legal review pathway for higher-risk or non-standard agreements so nothing critical relies solely on an AI output.

When AI-assisted review needs a lawyer

A lawyer adds value at the points where a wrong guess is expensive: confirming whether your business is, or will be, an APP entity and what that means for your AI use; deciding which document categories are safe for AI review; reviewing and negotiating the vendor's terms on training, IP, liability, data residency and sub-processors; drafting the data processing agreement and AI use policy; calibrating a playbook that reflects Australian law and your actual risk appetite; and assessing consumer law exposure for anything customer-facing that was built on an AI output. If something has already gone wrong, a lawyer can also manage the assessment and notification steps under the data breach scheme. Artificer Legal can help with any of these, including a review of the contracts and policies above before you roll AI out.

Why the law still treats the AI tool as your tool

The most misunderstood element of AI document review is where responsibility lands. When you upload a contract containing personal information to an overseas AI platform, APP 8 and s 16C make you the accountable party regardless of where the vendor processes the data, and Part IIIC does not excuse a data breach because it happened inside someone else's cloud. From 10 December 2026, the small business exemption disappears, so "we are too small for privacy law" stops being an argument on a fixed date.

In short: AI document review is a fast first reader for triage, comparisons and summaries, but the law treats its mistakes as yours. Know whether the Privacy Act applies to you, watch the cross-border, security and breach-notification obligations, protect confidentiality and IP, verify anything that reaches a customer under the Australian Consumer Law, and keep a human in the loop with a clear playbook, redaction rules and records. Back the process with terms of trade, a privacy policy, an NDA, a data processing agreement and an AI use policy, and take the genuinely high-stakes documents to a lawyer.