AI Vendor Due Diligence
What to check before signing with an AI vendor. Contract clauses, data residency questions, and Privacy Act obligations explained for Australian businesses.
This section covers Australian compliance obligations. If you're outside Australia, see Global & Regional Governance instead.
AI Vendor Contracts and the Privacy Act: What Australian Businesses Should Check
Six vendor contract clauses to review before signing, including APP 8, data residency, training opt-outs and breach notification for Australian businesses.
Signing up for an AI tool should involve the same basic checks as buying any other software service. You need to understand the contract, who can access your information, where that information goes, how support and security incidents are handled, and whether you can leave without losing access to your own records.
AI tools add several questions that ordinary software reviews may not cover. In particular, check whether prompts, uploaded files or other business data may be used to train or improve models. Ask whether you can disable that use, how long the vendor retains data, and what happens to stored information after you close the account.
The common failure is leaving these questions until after payment, rollout or an incident. A short review before purchase gives you the option to compare vendors, request clearer terms or decide that the tool is unsuitable. This hub provides practical assessment guidance, not legal advice or a compliance certification.
In short: Before signing up for an AI tool, check the contract's data-use terms, ask where your data is processed, and confirm what happens to it if you cancel. The vendor should be able to answer these questions before you pay, not after.
Choose the guidance that matches your decision
If you are starting from scratch, use the AI vendor due diligence checklist for Australian businesses. It brings the main commercial, privacy, security and exit questions into one pre-purchase review.
If you already have the agreement and want to review its wording, go to AI contract clauses Australian businesses should check. Use it to examine provisions covering data use, confidentiality, service changes, liability, termination and deletion rather than relying only on the sales page.
If your main question is how a vendor agreement interacts with Australian privacy considerations, read AI vendor contracts and the Privacy Act in Australia. It explains the issue through the Privacy Act and OAIC guidance, while helping you identify questions that may need professional advice for your circumstances.
If you want a plan ready before an incident occurs, use the AI vendor breach response plan template for Australia. It helps assign contacts, preserve information, manage access and organise the first response to a reported vendor breach.
If a breach has already happened, or you want to understand the likely sequence of events, read what happens when an AI tool is breached in Australia. It focuses on the practical steps from receiving the vendor's notice through assessing affected information and communicating with relevant people.
For guidance focused on the regulatory framework, see AI data breaches and Australia's Notifiable Data Breaches scheme. It routes readers through the relevant OAIC framework without assuming that every incident or business has the same position.
If the central concern is where information is stored or processed, rather than the contract as a whole, go to the data sovereignty and AI tools hub. That is the better starting point for questions about overseas processing, hosting locations and cross-border data flows.
Frequently asked questions
What's the single most important thing to check before signing up for an AI tool?
Check what the vendor can do with the information you enter. Look for terms covering prompts, uploaded documents, customer records, model training, service improvement, human review, retention and deletion. The answer may sit across the contract, privacy policy and product settings, so assess those materials together and keep a copy of the versions you reviewed.
Do free-tier AI tools have different data risks from paid tiers?
They can have different terms, settings or support arrangements, but do not assume that free automatically means unsafe or that paid automatically means private. Compare the actual terms for the specific tier you intend to use. Confirm whether data-use controls, retention choices, administrative features and incident support differ between plans before entering business information.
What should I do if a vendor won't answer basic data-handling questions?
Pause the purchase and record the unanswered questions. Ask for a written response or the relevant contract, privacy or security document. If the tool would handle sensitive, confidential or important business information, an unclear answer is a reason to consider another vendor or seek specialist advice before proceeding.
Is reading the contract enough?
No single document necessarily answers every practical question. Review the contract alongside the privacy policy, security information, account controls and cancellation process. Test whether you can export useful records, identify who inside your business will administer access, and note how to contact the vendor about deletion or an incident. If Privacy Act implications are material to the decision, consult current OAIC guidance or an appropriately qualified adviser.