This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If someone in your business is using an AI tool and you have no record of it, that is a governance gap, not a minor admin issue. The Office of the Australian Information Commissioner (OAIC) has made clear that businesses handling personal information are accountable for how that information is processed, including when it passes through third-party AI systems. An AI register is the first practical step toward meeting that accountability.
If you have heard that your business should have an AI register but are not sure what that means or where to start, that is a normal place to be. Most small and medium Australian businesses have not built one yet, even those already using AI tools daily. This guide explains what an AI register is, why Australian businesses need one, and gives you a free, ready-to-use template you can fill in today.
In short: An AI register is a simple document listing every AI tool your business uses, what it does, what data it handles, and who approved it. Under Australian Privacy Act 1988 obligations, particularly APP 1 (accountability) and APP 8 (cross-border disclosure), you need to be able to demonstrate that you know what AI tools are processing your customers' data and on what terms. The template below gives you a starting point in under an hour.
This article is general information, not legal advice. For advice on your specific Privacy Act obligations, consult a qualified privacy professional.
What Is an AI Register?
An AI register is a document or spreadsheet that lists every artificial intelligence tool your business uses, along with key details about each one: what it does, what data it touches, where that data is stored, and who has approved its use. Think of it as the AI equivalent of an asset register or a software licence list. The difference is that AI tools often process personal information, which brings them under Australian privacy law in ways that a standard software tool may not.
The register does not need to be complex. For most small and medium businesses, a well-structured spreadsheet is enough. What matters is that the information is captured, kept current, and accessible when you need it, whether that is for an internal review, a client query, or an OAIC investigation.
An AI register typically covers tools like ChatGPT, Microsoft Copilot, Google Gemini, AI features inside your CRM or accounting software, transcription tools like Otter.ai or Fireflies, image generators, and any other AI-assisted system your staff use for business purposes. If it processes business or customer data and uses AI, it belongs in the register.
Why Australian Businesses Need One
Australian businesses that handle personal information are required under the Privacy Act 1988 to take reasonable steps to protect that information and to be accountable for how it is managed. Australian Privacy Principle 1 (APP 1) requires covered entities to have a clear and up-to-date privacy policy and to manage personal information in an open and transparent way. An AI register is a direct tool for meeting that requirement when AI tools are involved in data handling.
Australian Privacy Principle 8 (APP 8) adds a specific obligation around cross-border disclosure. Many AI tools are built and hosted by US companies, which means data entered into them may be processed on servers outside Australia. Under APP 8, the OAIC's guidance outlines that before disclosing personal information to an overseas recipient, entities are expected to take reasonable steps to ensure the overseas recipient does not handle the data in a way that breaches the APPs. See APP 8 guidance at oaic.gov.au. An AI register helps you identify which tools create APP 8 exposure and prompts you to check the vendor's data residency terms.
The OAIC has also published AI-specific guidance noting that organisations using AI systems to make or assist with decisions that affect individuals must be able to explain and account for those decisions. That accountability starts with knowing which AI tools are in use. You cannot account for a tool you do not know exists.
Shadow AI is the hidden risk. Shadow AI refers to AI tools that staff adopt on their own, without IT or management awareness. A staff member pasting client data into a free AI writing tool is a real and common example. An AI register, combined with a basic AI policy, is how you close that gap. See the related guide on conducting a shadow AI audit for the process that surfaces these tools before they become a problem.
Who Needs an AI Register
The Privacy Act 1988 currently applies to Australian Government agencies and private sector organisations with an annual turnover above $3 million. If your business is below that threshold, the Act may not apply to you directly, but certain sectors are covered regardless of turnover, including health service providers, tax file number service providers, and credit providers. Check whether your business falls under one of those sector-specific categories even if your turnover is under $3 million.
Even if the Privacy Act does not currently apply to your business, building an AI register now is still worth doing. The federal government has been consulting on significant reforms to the Privacy Act that would lower or remove the turnover threshold, potentially bringing many more small businesses into scope. Building your governance practices before the law changes is a lower-stress approach than scrambling to comply after the fact.
Beyond legal compliance, an AI register is simply good business practice. If a client asks whether their data has been put through an AI tool, you want to be able to answer that question accurately. If a staff member leaves and took AI tools with them that no one else knew about, you want to know what was in use. The register protects you operationally, not just legally.
What Goes in an AI Register
A practical AI register captures enough information to answer the questions a privacy officer, an auditor, or a concerned client would ask. The columns below reflect what the OAIC's accountability guidance requires and what an APP 8 cross-border disclosure assessment needs. You do not need to go beyond these for most small and medium businesses.
The eight columns covered in this template are: Tool Name, Business Function, Data Processed, Data Residency, Training Data Opt-Out (Y/N), Approved Users, Review Date, and Notes. Each is explained in the completed example rows in the template below.
Free AI Register Template (T-02)
The template below is ready to use. Copy it into a spreadsheet, add your own tools, and update the Review Date column at least every six months. The example rows show how to complete each column for common tools. Delete or overwrite the example rows once you have populated the register with your own tools.
| Tool Name | Business Function | Data Processed | Data Residency | Training Data Opt-Out (Y/N) | Approved Users | Review Date | Notes |
|---|---|---|---|---|---|---|---|
| ChatGPT (OpenAI) | Drafting emails, summarising documents | Internal text only. No client personal information. | US (OpenAI, Microsoft Azure infrastructure) | Y. Opted out via OpenAI privacy settings | Marketing team (3 staff) | 2026-12-01 | Staff instructed not to paste client names or contact details. Review usage policy annually. |
| Microsoft Copilot (M365) | Meeting transcription, email drafting, document summaries | Email content, meeting audio, internal documents | Australia (Microsoft AU data centres) under M365 enterprise terms | Y. Microsoft commercial data protection commitments apply | All staff (15 licensed users) | 2026-12-01 | Data residency confirmed via Microsoft admin centre. Review after any M365 plan change. |
| Fireflies.ai | Meeting transcription and note-taking | Meeting audio, speaker names, meeting content (may include client names) | US (Fireflies, AWS us-east) | N. Check vendor privacy settings; default may allow training use | Sales team (4 staff) | 2026-09-01 | APP 8 cross-border disclosure applies. Clients should be informed via privacy policy that meetings may be transcribed using a US-hosted AI tool. Seek opt-out option in vendor settings. |
| Xero AI features (built-in) | Invoice categorisation, anomaly detection, cash flow forecasting | Financial transaction data, supplier and customer names | Australia/NZ (Xero AU region, AWS ap-southeast-2) | Y. Xero terms state financial data is not used to train public AI models | Finance team (2 staff) | 2026-12-01 | AI features bundled into Xero subscription. Confirm data terms each time Xero updates its product terms. |
| Google Gemini (via Workspace) | Drafting in Docs/Gmail, summarising Sheets data | Email content, document text, spreadsheet data | US (Google infrastructure; AU data region available for Workspace Business Plus and above) | Y. Google Workspace terms: customer data not used to train generative AI models | All staff (15 users) | 2026-12-01 | Confirm current plan tier. AU data region only available on higher-tier plans. Review residency if plan changes. |
| [Add your tool here] | [What your business uses it for] | [Type of data entered or processed] | [Country and cloud provider] | [Y / N / Unknown] | [Name or role of approved users] | [Date to review next] | [Any relevant compliance notes] |
NTKAI T-02 AI Register Template. Free to use and adapt for your business. Last template update: June 2026. Review your completed register at least every six months, or whenever you add a new AI tool.
How to Complete Your AI Register
Start by running a quick audit of your current AI tool usage before you fill in the register. The best way to do this is to ask every team member directly, check your software subscription list, and look at what browser extensions and apps are installed on work devices. Staff often use tools that management is not aware of, particularly free-tier AI tools. The shadow AI audit guide covers this process in detail, including the 10 specific steps in the shadow AI audit checklist.
Once you have a list of tools, work through each column in the register. For data residency, check the vendor's privacy policy or data processing agreement, not just their marketing page. Look for phrases like "your data is processed in" or "data stored in" and note the country. If you cannot find this information easily, that is a signal the vendor's privacy documentation needs scrutiny before you continue using the tool with business data.
For the Training Data Opt-Out column, check whether the vendor's default setting allows them to use your data to train their AI models. Many free-tier tools default to opt-in for training use. Enterprise and paid tiers typically include data protection terms that exclude customer data from training. Document what you have found and what setting is currently active.
Keeping the Register Current
An AI register that is out of date is only marginally better than no register at all. The Review Date column in the template is there for a reason: set a calendar reminder for each tool so you check the vendor's current terms at that date. Vendor terms change, data residency arrangements change, and new AI features get added to tools you already use without announcement.
Appoint someone in your business as the owner of the register. In a small business, this is often the office manager, operations lead, or the owner themselves. The job is not complex, but it needs a named person to be responsible for it, otherwise it will not get done.
Set a firm rule that any new AI tool must be added to the register before it is used for business purposes involving personal information. This rule, combined with a basic staff AI policy, is how you prevent shadow AI accumulating over time. The free AI staff policy template covers the policy side, and this register is the tracking mechanism that sits alongside it.
Australian Privacy Context: What You Are Accountable For
Under APP 1, the OAIC's guidance outlines that businesses are expected to manage personal information in an open and transparent way and maintain a current, accurate privacy policy. If your business uses AI tools that process customer or employee personal information, your privacy policy should reflect that. A completed AI register is evidence that you know which tools are in use and have assessed their data handling, which directly supports an APP 1 compliance position.
Under APP 8, the OAIC's guidance outlines that before disclosing personal information to an overseas recipient, businesses are expected to take reasonable steps to ensure that recipient will not handle the data in breach of the APPs. When an Australian business enters customer data into a US-hosted AI tool, that is a cross-border disclosure for APP 8 purposes. The register's Data Residency column is where you document which tools create APP 8 exposure, so you can either mitigate it (by updating your privacy policy to disclose it, or by choosing a tool with Australian data residency) or confirm it has been assessed.
The OAIC has also flagged that accountability for AI-assisted decisions is a priority area. If your business uses AI to assist with decisions that affect individuals, such as using an AI tool to screen job applications or to generate credit assessments, you need to be able to explain the role AI played in that decision. An AI register is the baseline for that accountability. For more context on how the OAIC approaches AI governance, see the OAIC AI guidance summary.
Pair the register with an AI staff policy. The register tells you what tools are in use. A staff policy tells your team what they are and are not allowed to do with those tools. Together, they cover both accountability and prevention. The free AI staff policy template for Australian businesses is designed to work alongside this register.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools.
See also: our AI vendor contracts and Privacy Act guide.
Try our free AI Policy Generator to generate a customised AI policy for your business.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Related reading: our free AI acceptable use policy template and our AI governance by region.
Related reading: Claude AI Review for Australian Business and Notion AI Review for Australian Small Business.
Is an AI register a legal requirement for Australian businesses?
There is no Australian law that uses the phrase "AI register" or requires one by that specific name. However, Privacy Act 1988 obligations, particularly APP 1 (accountability and transparency) and APP 8 (cross-border disclosure), create real accountability requirements that an AI register helps you meet. If your business handles personal information and uses AI tools, building a register is a practical and defensible way to demonstrate that you are managing those tools responsibly. As AI-specific regulation develops in Australia, documented governance like a register is also likely to be relevant to compliance assessments.
What counts as an AI tool for the purposes of the register?
Any software or feature that uses artificial intelligence to process, generate, or analyse data qualifies. This includes standalone tools like ChatGPT and Gemini, AI features built into software you already use (Xero's AI categorisation, Microsoft Copilot in M365, AI features in your CRM), transcription tools, image generators, and AI-assisted scheduling or customer service tools. If it does something intelligent with your data and is not a simple rule-based automation, include it. When in doubt, add it to the register, not leaving it out.
How do I find out where an AI tool stores my data?
Check the vendor's privacy policy, data processing agreement, or terms of service and look for references to data storage locations or data residency. Many vendors publish a specific data residency or data processing page. If you cannot find this information, email the vendor's support team and ask directly: "Where is customer data processed and stored?" If they cannot or will not answer that question, that is important information when deciding whether the tool is appropriate for business use involving personal information.
Do free-tier AI tools create a higher compliance risk than paid tools?
Generally yes, and the main reason is training data terms. Many free-tier AI tools default to using your inputs to improve their models, which means personal information you enter may be used in ways you did not intend and may be harder to delete or control. Paid tiers and enterprise agreements typically include explicit data protection terms that exclude customer data from training use and provide clearer commitments around data retention and deletion. If your business is regularly entering personal information into a free AI tool, that is a situation worth reviewing against APP 8 and your privacy policy obligations.
How often should I update the AI register?
Review the full register at least every six months. Individual entries should be reviewed sooner if the vendor publishes updated terms, if you change your subscription plan, or if the tool adds new AI features. Add a Review Date to each row and set calendar reminders so the reviews actually happen. The register owner should also check for newly adopted tools at each review by asking team members directly, since shadow AI adoption tends to accumulate between formal reviews.
What should I do if I find an AI tool my staff are using that I did not approve?
First, determine what data the tool has been used with. If personal information has been entered, check the tool's privacy terms to understand where that data went and whether you can request deletion. Then add the tool to your register and make a decision: either approve it with conditions (restrict what data can be used with it), or ban it and remove access. Use the discovery as an opportunity to reinforce your AI usage policy with staff and to tighten the process for approving new tools. The shadow AI audit guide covers how to investigate this systematically rather than reactively.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.
Once you have your AI register in place, a shadow AI audit tells you whether the register is complete. The audit process surfaces tools your staff are using that have not been formally approved, giving you an accurate starting point rather than a partial one.
Run a Shadow AI Audit