- Who these obligations apply to
- Put an AI usage policy in place
- Update privacy practices and policies for AI
- Protect intellectual property and confidentiality
- Manage work health and safety risks
- Build AI into risk management and incident response
- What happens if you get it wrong
- Compliance checklist
- When you need a lawyer
- Audit AI use before you draft another policy
There is no standalone "artificial intelligence law" in Australia yet. But using AI does not happen in a legal vacuum. The moment your team feeds personal information into ChatGPT, generates marketing images with an AI tool, or lets an automated system triage customer complaints, your business takes on obligations that already exist under privacy, copyright, work health and safety and contract law. Regulators expect you to manage AI within those existing frameworks, and for most businesses that happens through internal policies.
The obligations cluster into five groups: an AI usage policy that governs how staff may use the tools; privacy practices and policies updated for AI; protections for intellectual property and confidentiality; work health and safety (WHS) controls for AI-driven systems of work; and risk management and incident response plans that account for AI failure. This article sets out who these obligations apply to, what each one requires in practice, and what is at stake if you leave the policies unaddressed.
Who these obligations apply to
There is no AI-specific licence or registration for ordinary Australian businesses. The obligations come from existing laws and are triggered by what you actually do with AI:
- Privacy: the Privacy Act 1988 (Cth) applies to most businesses with an annual turnover above $3 million (see s 6D). Smaller businesses are still caught if they trade in personal information, hold health information, or act as a credit reporting body. If you use AI to process personal information, the Australian Privacy Principles (APPs) apply, including APP 1 on open and transparent management and APP 11 on security.
- WHS: the Work Health and Safety Act 2011 (Cth) and its state and territory equivalents apply to every person conducting a business or undertaking, including a sole trader with a single worker.
- Copyright and contract: any business that creates, uses or licences content, or owes confidentiality obligations to clients, is exposed. There is no turnover threshold.
- Regulated sectors: financial services and credit licencees must fit AI governance inside their existing licence obligations. When ASIC reviewed 23 Australian financial services and credit licencees in 2024, it reported gaps between how those businesses described their AI use and the governance arrangements actually in place.
Put an AI usage policy in place
The first and most important internal document is an AI usage policy: a set of rules for how employees and other personnel may use generative AI tools such as ChatGPT, Claude or image generators in the course of work.
The policy should state restrictions, including a blanket prohibition on any use that would cause the business to breach a legal obligation. That covers privacy laws, copyright laws, WHS laws and contractual obligations, including confidentiality and privacy clauses. In practice that means banning staff from pasting client information, employee records or trade secrets into public tools, and banning AI use for high-stakes decisions unless a human reviews the result.
The policy should also set out the ethical standards the business expects:
- Ethical data use: avoid using sensitive information without explicit consent.
- Fairness: require that AI systems be designed and used in ways that are fair and unbiased, with processes to audit and address bias.
- Transparency: stakeholders should be able to understand how AI-assisted decisions are reached.
- Roles and responsibilities: name who oversees AI systems and who deals with ethical concerns.
- Alignment: AI practices should sit alongside any industry codes or ethical guidelines the business has committed to.
Human oversight should be built into the policy, not assumed. That means obligations on personnel to verify the inputs they give to AI tools, to check outputs before relying on them, and to label AI-generated work as AI-generated. It also means an express rule that staff must use independent judgement and not rely solely on AI for business decisions.
Finally, the policy should state the consequences of breaching it. A policy that names no disciplinary action is a set of suggestions, not a control. If you later need to discipline an employee for leaking confidential information through an AI tool, the policy is what makes that action defensible.
Update privacy practices and policies for AI
AI runs on data, and much of that data is personal information. Under APP 1 of the Privacy Act 1988 (Cth), an APP entity must take reasonable steps to implement practices, procedures and systems that ensure compliance with the APPs, and must maintain a clearly expressed, up-to-date privacy policy. If AI changes how you collect, hold, use or disclose personal information, your privacy policy and your day-to-day practices must reflect that change. Under APP 11, you must take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify information you no longer need.
AI tools create new channels for leakage. Staff prompts can transmit personal information to a third-party provider, training data can embed it, and outputs can reproduce it for the wrong audience. The privacy policy should address where personal information goes when staff use AI, whether the provider stores or trains on it, and what staff may and may not enter into the tools.
Consent deserves specific attention. If AI involves the processing of sensitive information, such as health information or information about an individual's ethnicity or political views, you will generally need that individual's consent. The Office of the Australian Information Commissioner (OAIC) published two guides in October 2024 that set out how the APPs apply to AI: Guidance on privacy and the use of commercially available AI products and Guidance on privacy and developing and training generative AI models. These are the reference points your policy should be tested against.
Protect intellectual property and confidentiality
Under s 32 of the Copyright Act 1968 (Cth), copyright subsists in an original work only where the author was a "qualified person", defined as an Australian citizen or a person resident in Australia. An AI system cannot be an author. The Federal Court has taken the same position in the patent context, holding in Commissioner of Patents v Thaler ([2022] FCAFC 62) that an AI system could not be named as an inventor under the Patents Act 1990 (Cth).
Two practical consequences follow. First, purely AI-generated text, images or code generally has no copyright protection in Australia. You cannot "own" it in the usual sense, and you cannot stop a competitor from copying it, so a business built on unedited AI output owns very little. Second, you can still infringe copyright through AI. If a tool generates output that reproduces a copyrighted work, or if your business trains or fine-tunes a model on protected material without permission, the business can face an infringement claim. Inputting someone else's copyrighted material can itself be an infringement.
Confidentiality is the related risk that most often bites in practice. Pasting a client's draft agreement, a pricing model or commercially sensitive information into a public generative AI tool may amount to disclosure of that information, which can breach confidentiality clauses in your contracts and your obligations to clients, and can destroy legal professional privilege over the material. The AI usage policy should say in plain terms what categories of information must never be entered into a tool, and should require AI-generated work to be labelled so that clients and colleagues can tell what came from a machine.
Manage work health and safety risks
WHS law does not distinguish between a hazard created by a machine on a factory floor and one created by an algorithm. Under s 19 of the Work Health and Safety Act 2011 (Cth), a person conducting a business or undertaking must ensure, so far as is reasonably practicable, the health and safety of workers and other persons, including through safe systems of work. If an AI system sets productivity targets, paces workers, monitors their activity or makes rostering decisions, it is part of the system of work and must be assessed like any other workplace hazard.
The WHS risks are not limited to physical injury. Algorithmic management can create psychosocial hazards: unrealistic workloads, constant monitoring, or decisions about staff made without explanation. A business should identify which AI systems touch workers, assess the risks they create, and put controls in place, just as it would for any other hazard. The policy should also set out how AI-related incidents involving workers are reported and investigated.
Officers carry a personal duty. Under s 27 of the Work Health and Safety Act 2011 (Cth), an officer must exercise due diligence to ensure the business complies with its WHS duties. That includes taking reasonable steps to understand the AI systems the business uses and to verify that the business has appropriate processes for AI-related risks. Directors and senior managers cannot treat AI governance as an IT matter that someone else owns.
Build AI into risk management and incident response
AI introduces risks that standard risk registers do not capture: incorrect or hallucinated outputs, bias, data leakage to providers, dependence on third-party tools that change without notice, and prompt injection attacks. Your risk management policies should be reviewed so that AI-related risks are identified, assessed and assigned an owner, with mitigation strategies in place.
Incident response plans need the same treatment. If an AI tool is involved in a data breach, Part IIIC of the Privacy Act 1988 (Cth) requires an entity that is aware of reasonable grounds to believe an eligible data breach has occurred to notify the OAIC and affected individuals. Your data breach response plan should cover AI-specific scenarios, such as personal information sent to a provider through a staff prompt, a tool that reproduces sensitive information to the wrong recipient, or a vendor breach that exposes data your business loaded into their system. For financial services and credit licencees, ASIC's October 2024 review is a direct signal that the regulator expects governance arrangements to keep pace with actual AI use.
Keep one eye on the horizon. In September 2024 the Australian Government published a proposals paper on mandatory guardrails for AI in high-risk settings, and a Senate committee has since recommended dedicated AI legislation. None of that is law yet, but policies drafted now should be structured so they can adapt when new obligations arrive.
What happens if you get it wrong
The consequences are not hypothetical, and they attach to the existing laws AI use triggers:
- Privacy: under s 13G of the Privacy Act 1988 (Cth), serious or repeated interference with privacy exposes a body corporate to a civil penalty of up to the greatest of $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover during the breach period. Individuals face up to $2.5 million. The OAIC can also investigate, accept enforceable undertakings and seek court orders.
- Copyright: infringement can mean damages, an account of profits and injunctions, and it can put your own AI-generated content at risk because you cannot assert copyright in it.
- WHS: under Schedule 4 of the Work Health and Safety Act 2011 (Cth), a Category 1 offence (recklessly or negligently exposing a person to the risk of death or serious injury) carries a maximum fine of $15 million for a body corporate, and individuals can face fines or up to 15 years' imprisonment. Even a Category 3 failure to comply with a duty carries up to $700,000 for a body corporate.
- Contract: a confidentiality breach through an AI tool can mean damages, termination of a client engagement and loss of trust that no policy rewrite can restore.
Compliance checklist
Confirm each item is covered before staff use AI tools:
- [ ] Identify every AI tool in use, including shadow use by staff on personal accounts.
- [ ] Draft an AI usage policy covering restrictions, ethics, human oversight, labelling and disciplinary consequences.
- [ ] Update the privacy policy and practices so they reflect how AI collects, uses and stores personal information.
- [ ] Confirm consent is obtained before sensitive information is processed with AI.
- [ ] Make sure the data breach response plan covers AI-related incidents and the Part IIIC notification obligations.
- [ ] Review intellectual property: label AI-generated output, do not claim ownership of purely AI output, and check what staff may input.
- [ ] Run a WHS risk assessment over AI systems that affect workers, with officer sign-off.
- [ ] Schedule a regular policy review, because AI tools and the rules around them change quickly.
When you need a lawyer
A lawyer can help with the drafting and review work this article describes: the AI usage policy, the privacy policy updates, and the confidentiality clauses that protect you when staff use AI. A lawyer is also needed when a contract with an AI vendor is on the table, because data use, intellectual property in outputs and liability for incorrect results are usually buried in the vendor's terms. For directors, legal input on WHS due diligence and AI risk assessment can be the difference between a personal prosecution and a defensible process. And if an AI-related incident has already happened, or a regulator has come knocking, get advice before you respond rather than after.
Audit AI use before you draft another policy
The misstep that costs businesses most is drafting the policy before knowing what staff actually do. An AI usage policy that forbids the wrong tools while everyone quietly uses their own ChatGPT account on a personal device is worse than no policy, because it gives you no record, no control and no defensible basis for action. Before you write a single clause, ask every team what AI tools they use and what they feed into them. The answer will show you which obligations are live in your business: whether client data is entering public tools, whether AI output is being published unlabelled, and whether automated systems are already making decisions about workers. That audit is the starting point for the policies above, and it is the first thing to do this week. From there, draft the AI usage policy, update the privacy and incident response documents, and treat the whole set as living documents that change as fast as the technology does.