Generative AI tools, including ChatGPT, Gemini, Copilot, Claude and others, are now part of everyday workplace life. Employees use them to draft correspondence, summarise documents, and assist with decisions, often well ahead of any formal policy or oversight.
This creates real legal risk. When your employees upload personal information, confidential business data, or commercially sensitive material into publicly available AI systems, your business faces exposure under the Privacy Act 1988 (Cth)(“Privacy Act”), the Australian Privacy Principles (APPs), and common law claims for negligence and tort, breach of contract, not to mention as broader confidentiality and cybersecurity obligations.
Not all AI tools carry the same risk
Unlike traditional enterprise software, many AI platforms store and process user inputs through third-party systems — and information entered may be retained, reviewed, or used to train AI models.
This creates immediate concerns where employees upload:
- Customer/client information;
- employee records;
- commercially sensitive material;
- confidential contracts; or
- internal business strategies and confidential information.
The level of risk depends on which platform employees are using. Publicly accessible platforms — such as the free version of ChatGPT — offer limited data protections. Enterprise AI solutions deployed under corporate licensing arrangements are different: they typically include security controls, restricted model training, and contractual privacy protections.
Most employers recognise the enormous benefits AI can provide to their business and the failure to embrace AI will mean they are left behind their competitors. As such, most organisations are moving away from blanket AI bans and instead implementing governance frameworks with approved enterprise tools. However, enterprise deployment does not eliminate legal risk, rather it enhances this risk in an environment that is almost completely unregulated and untested.
The traditional rules and laws still apply but in a vastly changed landscape and navigating this change appropriately is vital to ensuring the safety of your organisational data, reputation and long-term success.
New Privacy Act Requirements for Automated Decision-Making Transparency
The Privacy and Other Legislation Amendment Act 2024 (Cth) (POLA Act) introduced amendments to the Privacy Act requiring Australian Privacy Principle (APP) entities to disclose information about their use of automated decision-making technologies in their privacy policies.
From 10 December 2026, new automated decision-making transparency obligations under the Privacy Act 1988 (Cth) (Privacy Act) will take effect.
At the same time, the Office of the Australian Information Commissioner (OAIC) has increased its focus on privacy policy compliance and is currently conducting a compliance sweep of organisations’ privacy policies.
Under APP 1.7, the obligations apply where an APP entity uses a computer program that relies on an individual’s personal information to make, or directly support, a decision that could reasonably be expected to have a significant impact on that individual’s rights or interests. Where the obligation applies, APP 1.8 requires the entity’s privacy policy to describe:
- the types of personal information used in the operation of automated decision-making technologies;
- the types of decisions made solely through automated decision-making processes; and
- the types of decisions in which automated decision-making technology performs a substantial and direct role in the decision-making process, even where a human decision-maker remains involved.
Organisations that use artificial intelligence, algorithms, automated screening tools, profiling systems or other decision-support technologies should carefully assess whether these new requirements apply to their operations and ensure that their privacy policies are updated before the commencement date.
New Statutory Tort for Serious Invasions of Privacy
A further significant privacy reform is the commencement of the new statutory tort for serious invasions of privacy on 10 June 2025.
The tort creates a standalone cause of action, enabling individuals to seek compensation and other remedies directly from the courts for serious invasions of their privacy. Importantly, a claim may be brought independently of the Privacy Act and the Australian Privacy Principles (APPs), providing an additional avenue of redress for affected individuals.
The new tort is particularly relevant for employers. While the Privacy Act contains an employee records exemption that limits the application of certain privacy obligations in the employment context, that exemption does not prevent an employee from pursuing a claim for a serious invasion of privacy. As a result, conduct that may previously have fallen outside the Privacy Act’s regulatory framework could still expose an employer to litigation and liability under the new tort.
Examples of conduct that may give rise to risk include unauthorised disclosure of sensitive personal information, misuse of employee data, or other conduct that unreasonably intrudes upon an individual’s privacy in circumstances where the invasion is considered serious.
What if something goes wrong?
Your key legal obligations
The most important obligations deal with:
- Maintenance of privacy whilst using AI and complying with the Privacy Act and APPs. Ensuring that the use of information is limited to its intended purpose. As we know AI now uses the data it is fed to teach itself. This use of information may be contrary to the purpose for which it was collected.
- Maintaining confidentiality over the relevant information. All publicly available AI systems are open source and allow access to anyone who has access to the relevant tool. This means that information placed on the AI tool will be available to the world at large.
- Guarding against data breaches.
Possibility of Data Breaches
Australian law requires businesses to notify the privacy regulator — the Office of the Australian Information Commissioner (OAIC) — and affected individuals when a serious data breach occurs. AI creates new ways for that to happen: a hacked platform, a misconfigured tool, or an employee accidentally sharing confidential information with the wrong chatbot can all trigger notification obligations. It pays to know the rules before something goes wrong, not after.
More importantly, it is imperative in this new age of AI to understand how it works and more particularly, how the AI your staff are using, deals with information. If a breach occurs, it may expose the business to several levels of harm, from non-compliance with Privacy laws, reporting obligations, reputational harm and all the associated costs.
How should employees be using AI?
This is a fundamental question, often overlooked. That is to what level should AI be used in everyday work tasks. Should it be the first port for drafting anything, or does the business first want the employee to do the first draft. This may make a substantial difference in the long term, as if all work is farmed through AI, what impact will this have an employee capability and actual knowledge.
Is AI there to assist in tasks that are mundane and are far quicker for AI, for example data collection and sorting, creating lists and chronologies, summarising documents and the like. However, care needs to be taken when AI is used to substitute for human ingenuity, consideration and guidance.
What should your business do?
AI is a reality, and employees will be using some form of AI if not now, then very soon. Businesses need to be proactive as to how this happens and ensure safeguards are put in place to protect the business.
Put an AI policy in place. Tell employees which tools are approved, what they can and can’t upload, and what happens if they get it wrong. It doesn’t need to be long — it just needs to be clear.
The policy should make clear when and how AI can be used, and when it is not acceptable. It should also ensure that any use of AI and the results provided are independently verified by the employee. the policy should make clear that the use of AI should be a tool and not something that perform the task required entirely. AS such, from a performance perspective, the employee will remain responsible for the work regardless of the use of AI.
There needs to be a mechanism in place to ensure the rules are observed, given that accessing AI is now as easy as doing a google search. In fact, google itself uses AI for this purpose.
Ensure you have a robust Privacy Policy which deals with the new changes and the use of AI.
Give your existing policies a health check. Your IT, confidentiality, and HR documents were probably written before AI was part of everyday work. A quick review can close real gaps. These documents should be updated to include the use of AI.
Train your people. Most AI-related incidents aren’t caused by bad intentions — they happen because no one explained the rules. A short, practical training session on the Company policy, what is and is not acceptable use, what documents and information can be used with respect to each for of AI and whether some forms of AI are not permitted will makes a real difference.
Understand your AI vendor. Before you roll out an enterprise AI tool, know where your data is stored, who can access it, and what your contract says about a breach.
Ask the hard questions before deploying new AI tools. What personal data does this system use? Where does it go? Who can access it? A simple review before you roll anything out can save significant headaches down the track.
Update your privacy policy before December 2026. New laws now require businesses to be upfront when AI is used to make significant decisions about people — hiring, performance reviews, redundancy. The deadline is coming. The time to act is now.
Looking ahead
The regulatory dial is turning. Privacy law is being updated to reflect how AI is actually being used in workplaces, and the pace of change is only going to increase. The businesses that will handle this best are not necessarily those with the most sophisticated AI tools — they’re the ones who took the time to build basic habits: clear policies, informed employees, and a genuine understanding of where their data goes.
How we can assist
AI governance is genuinely new territory for most businesses, and the law is still catching up. We work with employers across all industries to help them navigate the practical and legal side of AI in the workplace — without the jargon. Whether you need an AI policy drafted from scratch, your existing documents reviewed, or you just want to understand what your obligations actually are, our employment and Privacy law teams are here to help.
This article is for general information purposes only and does not constitute legal or professional advice. It should not be used as a substitute for legal advice relating to your particular circumstances. Please also note that the law may have changed since the date of this article.