Practical AI and SaaS for Business

OAIC AI Guidance for Australian Business: What the Privacy Regulator Expects

The OAIC has published clear guidance on how Australian businesses must handle AI tools under the Privacy Act. Here is what it means in practice for a small or medium business using commercial AI products.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You're the office manager at a mid-size bookkeeping practice, and AI compliance landed on your desk because nobody else wanted it. Your team pastes client financial records into ChatGPT without a second thought, and you don't know if that breaches the Privacy Act, or just makes you nervous. Read this and you'll know exactly what the OAIC expects from a practice your size, and the practical steps that cover you. No legal background required. Plain English, five minutes.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

If you have heard that the privacy regulator has released guidance on AI tools, but you are not sure what it actually requires of a business like yours, you are not alone. Most of the commentary has been written for lawyers and compliance officers, not for the owner of a 20-person practice who just wants to know whether using ChatGPT or Copilot is putting the business at risk. This article explains what the Office of the Australian Information Commissioner (OAIC) expects, in plain language, so you can work out what steps you need to take.

In short: The OAIC expects Australian organisations to treat AI tools as a privacy risk that needs active management, not a product you simply buy and use. That means assessing the risk before deploying a tool, checking what your vendors do with data, limiting what data you feed into AI systems, and making sure your staff have clear guidelines. None of this requires a legal team, but it does require deliberate action. Read on for what that looks like in practice for an SMB.

This article is general information, not legal advice. It summarises OAIC guidance in plain language; for advice on your specific obligations, consult a qualified privacy professional or the OAIC directly.

What Is the OAIC and Why Does Its Guidance Matter?

The Office of the Australian Information Commissioner is the government body responsible for overseeing the Privacy Act 1988. It regulates how organisations collect, use, store, and disclose personal information. The OAIC can investigate complaints, conduct audits, and issue determinations against organisations that breach the Australian Privacy Principles (APPs).

In recent years, the OAIC has published specific guidance on how the existing privacy framework applies to AI tools, including commercially available products like ChatGPT, Microsoft Copilot, Google Gemini, and similar systems. This guidance does not change the law, but it does clarify what the OAIC considers to be reasonable compliance behaviour when you use AI products in your business.

Understanding this guidance matters because it sets the standard against which your business would be assessed if a privacy complaint were made, or if the OAIC conducted an audit. If you have not taken the steps the OAIC considers reasonable, you face greater exposure under the Privacy Act. The good news is that most of what the OAIC expects is achievable for an SMB without specialist legal support, as long as you know what to do. For a broader overview of how the Privacy Act applies to AI use in Australian business, see our guide at needtoknowai.com/guides/ai-privacy-act-australia/.

Privacy Impact Assessments: Assessing Risk Before You Deploy

One of the clearest expectations in the OAIC's AI guidance is that organisations should conduct a Privacy Impact Assessment (PIA) before deploying an AI tool that handles personal information. A PIA is a structured process for identifying what personal data is involved, what risks that creates, and what you are going to do about those risks.

For a large organisation, a PIA can be an extensive formal document. For an SMB, it does not need to be that complex. The core questions are: What personal information will the AI tool see or process? Where does that information go and who can access it? What is the worst-case risk if something goes wrong? And what steps will you take to reduce that risk?

In practice, this means that before you let your staff feed client names, emails, financial records, or health information into an AI tool, you should have a documented record that you thought about it, identified the risk, and put controls in place. A one-page internal assessment is far better than nothing, and it gives you a defensible position if questions are ever raised. Our guide on shadow AI auditing covers how to find AI use in your business that may not have gone through any assessment process: needtoknowai.com/guides/shadow-ai-audit-australia/.

Transparency Obligations: Telling People How Their Data Is Used

The Privacy Act requires organisations to be transparent about how they collect and use personal information. When you use an AI tool to process information about your clients, customers, or employees, the OAIC expects that your privacy policy and collection notices reflect this.

In concrete terms, if you are using an AI tool to summarise client communications, generate reports that include personal data, or automate decisions that affect individuals, your privacy documentation should say so, at least in general terms. You do not need to name every specific tool, but the fact that you use AI systems for these purposes should be disclosed.

For most small businesses, this means reviewing your privacy policy and updating it if it does not mention AI-assisted processing. It also means being honest with clients if they ask how their information is handled. The OAIC's position is that individuals have a right to know when their information is being processed by automated systems, particularly where those systems are making or contributing to decisions that affect them.

Data Minimisation: Only Feed AI What It Needs

Data minimisation is the principle that you should only collect, use, and disclose as much personal information as is necessary for the specific purpose at hand. The OAIC explicitly applies this principle to AI tool use, and it is one of the most practical things an SMB can act on immediately.

In plain terms, this means: do not paste a client's full file into an AI prompt when you only need to summarise one part of it. Do not upload a spreadsheet containing hundreds of customer records when the task only requires working with a handful. Strip out names, addresses, and identifying details before feeding documents into AI tools unless those details are genuinely necessary for the task.

Picture the office manager at a mid-size bookkeeping practice preparing a set of BAS returns with AI assistance. Instead of pasting the client's entire ledger, including every transaction and every account holder's name, into the prompt, she now exports just the categorised figures for the relevant quarter and strips out client names before running the summary. That's the difference between a defensible data minimisation practice and a privacy incident waiting to happen, and it took her about five minutes to change the habit.

Staff training is critical here. Without clear guidance, most employees will take the path of least resistance, which often means copying and pasting more information than is necessary. A simple internal rule, documented and communicated, can reduce your exposure significantly. A policy template for exactly this kind of guidance is available at needtoknowai.com/guides/free-ai-staff-policy-template-australia/.

Vendor Due Diligence: Checking What Your AI Provider Actually Does

The OAIC's guidance is clear that using a third-party AI product does not transfer your privacy obligations to the vendor. You remain accountable for what happens to the personal information you share with that vendor's systems. This means you need to understand, at a reasonable level, what your AI vendor does with the data you put into their product.

The key questions to answer for any commercial AI tool you use are: Does the vendor use your data to train their models? Where is your data stored, and in which country? What are the vendor's data retention periods? Does the vendor have a data processing agreement or privacy addendum available? If the vendor stores data in the United States or elsewhere outside Australia, Australian Privacy Principle 8 (APP 8) requires you to take reasonable steps to ensure that overseas recipient handles the information consistently with the APPs.

For common tools: Microsoft's enterprise plans (Copilot for Microsoft 365) offer a data processing agreement and do not use customer data for model training by default. OpenAI's API and ChatGPT Enterprise similarly offer opt-out of training data use, but the consumer version of ChatGPT uses conversations for training unless you disable it in settings. Google Workspace AI features are governed by Google's Workspace data processing terms. Always check the current terms on the vendor's website, as these change, and make a note of when you checked.

APP 8 cross-border disclosure: If your AI vendor stores or processes data in the United States or another country, APP 8 applies. Under APP 8, the OAIC's guidance outlines that businesses are expected to take reasonable steps to ensure the overseas recipient protects the information under standards comparable to the APPs. Vendor privacy addenda and data processing agreements are the main mechanism for addressing this requirement. See the OAIC's APP 8 guidance at oaic.gov.au.

Employee AI Use Policies: What "Taking Reasonable Steps" Means

The phrase "taking reasonable steps" appears throughout the Privacy Act and the OAIC's guidance. It is the standard against which your organisation's conduct is assessed. Reasonable steps are not the same as perfect steps, but they do require deliberate, documented action, not a passive assumption that everything is fine.

For an SMB using commercial AI tools, the OAIC's guidance points to the following as elements of a reasonable approach: having a written policy that tells staff what AI tools are approved, what kinds of information can and cannot be used in those tools, and what to do if they are unsure. Conducting basic training so staff understand the policy and the reason behind it. Reviewing and updating the policy as the tools you use change.

A policy does not need to be long. A one to two page document that covers approved tools, prohibited data types (such as client personal information, health records, financial data without explicit approval), and the process for requesting approval of a new tool is sufficient to demonstrate that your organisation has taken the matter seriously. What the OAIC is looking for is evidence of intent and process, not a compliance framework the size of a bank's.

The automated decision-making transparency requirements under the Privacy Act amendments are also relevant context here. If your business uses AI tools that contribute to decisions about individuals (credit assessments, hiring, service delivery), specific disclosure obligations take effect in December 2026. For detail on the December 2026 automated decision-making deadline, see our guide at needtoknowai.com/guides/privacy-act-adm-december-deadline-australia/.

What This Means for Specific Industries

The OAIC's guidance applies to all organisations covered by the Privacy Act, but the risk level varies considerably depending on the kind of information your business handles. Professional services firms, healthcare providers, and financial services businesses carry higher risk because the information they handle is more sensitive and the consequences of a breach are more serious.

Accounting and bookkeeping practices handle financial records, tax file numbers, and sometimes health information through their clients. Using an AI tool to summarise client accounts or draft correspondence that includes financial details puts that data in scope for privacy regulation. A PIA and a data minimisation policy are not optional in this context.

Allied health and medical practices are subject to both the Privacy Act and specific health privacy obligations. AI tools used to summarise patient notes, generate referral letters, or assist with clinical documentation must be assessed carefully. Health information is sensitive information under the Privacy Act, with higher obligations attached, and the OAIC would apply close scrutiny to any breach involving health data and AI systems.

Trades and field service businesses typically handle less sensitive personal information, but they still collect customer addresses, contact details, and sometimes payment information. If you are using AI tools to generate quotes, schedule jobs, or communicate with customers, the same basic principles apply, even if the risk threshold is lower.

A Practical Checklist for SMBs

The following steps represent what the OAIC's guidance identifies as a reasonable approach for an organisation using commercially available AI products. None of these require a lawyer to complete, though for higher-risk industries it is worth a short conversation with a privacy-aware solicitor before finalising your approach.

  • Document which AI tools your business is currently using or plans to use.
  • For each tool, check the vendor's privacy policy and terms: does the vendor use your data for model training, where is data stored, and is a data processing agreement available?
  • Conduct a basic Privacy Impact Assessment before deploying any AI tool that will process client or employee personal information. Record the risks identified and the steps taken to address them.
  • Update your privacy policy to reflect that the business uses AI tools to process personal information.
  • Write a short internal AI use policy that tells staff which tools are approved, what data types are off-limits, and what to do if they are uncertain.
  • Train staff on the policy, at minimum a short briefing that covers the why as well as the what.
  • Set a review date, at least annually, to check whether tools have changed, whether vendor terms have been updated, and whether staff are following the policy.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: can staff upload customer data to AI tools, AI data residency in Australia, AI tools with Australian data centres, HR AI compliance in Australia, AI vendor contracts and Privacy Act, AI data breaches and the NDB scheme, Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.

Related reading: our OAIC AI compliance checklist and our Australian government AI policy roundup.

Related reading: our AI grants and funding available for Australian businesses and our international AI regulations explained.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.

Related reading: our is AI regulated in Australia.

For more OAIC-attributed guidance and where to find it, see our OAIC guidance hub.

Does the OAIC's AI guidance apply to small businesses?

Yes, if your business is covered by the Privacy Act 1988. Generally, this means businesses with an annual turnover above $3 million, or smaller businesses that handle health information, provide certain services to the government, or trade in personal information. If the Privacy Act applies to your business, the OAIC's guidance on AI applies too. If you are below the threshold and do not fall into one of the exceptions, you may still want to follow the guidance as a best practice, particularly if you handle sensitive client data.

What AI tools is the OAIC guidance referring to?

The OAIC's guidance covers commercially available AI products, which includes tools like ChatGPT, Microsoft Copilot, Google Gemini, and any other AI system that your staff use as part of their work. It also covers AI features built into software you already use, such as AI writing tools inside your CRM, accounting software with AI analysis features, or document platforms with AI summaries. If a tool processes personal information using AI, the guidance applies.

Do we need to do a Privacy Impact Assessment for every AI tool we use?

The OAIC recommends conducting a PIA before deploying AI tools that handle personal information. You do not need a separate formal document for every tool, but for any tool that regularly processes client, customer, or employee personal data, you should have a documented record that you assessed the risk. For low-risk uses, a brief internal note covering the key questions is sufficient. For tools handling sensitive information such as health or financial records, a more thorough assessment is appropriate.

Is it a breach of privacy to use ChatGPT or Copilot for work tasks?

Not automatically, but it depends on what information you put into the tool and under what terms. Using an AI tool to draft a generic email or summarise a publicly available document carries minimal privacy risk. Using it to process client personal information, financial records, or health data creates obligations. You need to check whether the vendor uses your inputs for training, ensure your privacy policy covers the use, and make sure staff follow data minimisation practices. The consumer version of ChatGPT, used without a business account, carries higher risk because data handling terms differ from enterprise versions.

What happens if we do not follow the OAIC's guidance on AI?

Failing to follow the guidance does not automatically mean a fine or enforcement action. However, if a privacy complaint is made against your business, or if the OAIC audits your practices, the guidance sets the standard for what counts as reasonable behaviour. If you cannot show that you took reasonable steps, including assessing risk, updating your privacy policy, and informing staff, the OAIC may find that you breached the Australian Privacy Principles. Penalties under the Privacy Act can reach $2.22 million for serious or repeated breaches for organisations.

Where can we find the OAIC's actual guidance documents?

The OAIC publishes its AI-related guidance on its website at oaic.gov.au. Key documents include the guidance on privacy and artificial intelligence and the guidance on privacy impact assessments. These are freely available and written in plain English, though they are structured for legal and compliance readers. The guidance is updated periodically, so note the publication date when you access them and check for updates when you conduct your annual review.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Download a free AI staff policy template for Australian businesses, covering approved tools, data handling rules, and employee guidelines. Ready to adapt for your industry.

Get the Free Policy Template