For Australian business owners

Before you put company or client data into AI, read this.

Most businesses are already feeding customer data, financials, and confidential documents into public AI tools — with no clear idea what leaves the building or where it lands. Here's the plain version of what the law expects, what's coming, and how to stay in control.

Your team isn't being careless. They're being helpful. And that's exactly the problem.

The problem nobody put in the onboarding doc

Your people aren't trying to cause a breach. They're trying to get the job done.

They paste a client email into ChatGPT to draft a reply. They drop a contract into an LLM to summarise it. They ask a public model to clean up a spreadsheet of customer records. None of it is malicious. A lot of it can be a notifiable data breach under Australian law.

The tool doesn't tell you what it keeps. The vendor's terms say they may train on your inputs. And once it's sent, you can't unsend it.

Why this matters now — from the law down to your desk

1

The law has already caught up

The Privacy Act 1988 and the Australian Privacy Principles already cover this. APP 11 says you must take "reasonable steps" to protect personal information — and that now includes how you use AI. If client or staff data goes into a public model without controls, the OAIC's position is straightforward: that's on you.

Source: OAIC — APP 11 Security of personal information
2

AI now has its own standard

In September 2024 the federal government published the Voluntary AI Safety Standard — eight guardrails for any organisation using AI. Alongside it, a proposal for mandatory guardrails in high-risk settings is on the table. The mandatory version isn't law yet — but the voluntary one is live now, and it's a fair signal of where the bar is heading.

Source: Voluntary AI Safety Standard (Dept of Industry, Science & Resources)
3

It reaches past our border

If you serve anyone in the EU, the EU AI Act applies to you regardless of where you sit. It's extraterritorial. Australian businesses with even a handful of European users are in scope for its obligations around high-risk AI use.

Source: EU AI Act
4

What it means for you — concretely

  • A staff member pasting customer PII into a public LLM can be a notifiable breach.
  • Confidential documents summarised offshore leave your control and your jurisdiction.
  • A black-box model makes a decision about a person — pricing, hiring, credit — with no audit trail.
  • You can't answer "where did that data go?" because nobody mapped it.
The blind spot

What almost nobody tells you

The mistake I see every single week isn't a missing policy. It's that businesses buy the AI tool before they know what data is already leaving the building. You can't govern what you haven't mapped. The first thing I do with any client isn't pick a model — it's map every place data flows out today. Most "AI strategy" consultants skip that and sell you a subscription. That's backwards, and it's why so many AI projects either stall or quietly turn into a compliance liability. Local-first AI isn't only about privacy either — it's about not having your roadmap held hostage by a vendor's API pricing or a foreign policy shift you don't control.

Get the checklist

The Australian AI Readiness Checklist

15 points to run before any team member touches an AI tool with company or client data. Free. No fluff. Built from the same standard I walk clients through.

I'll email it straight to you. No list, no follow-up spam — just the checklist and a clear next step if you want one.

Not sure how exposed you are?

Take the 2-minute AI data-leak exposure check. 12 questions, a score out of 100, and the checklist at the end.

1. Do you know every place company or client data currently leaves your business?
2. Are staff using public AI tools (ChatGPT, Copilot, etc.) for work?
3. When staff paste data into an AI tool, does it contain personal information (client names, emails, financials)?
4. Do you have an AI usage policy your team has actually read?
5. Do you know where the AI tools you use store and process data (Australia, US, EU, elsewhere)?
6. Are any AI decisions made about people (hiring, credit, pricing) without a human review step?
7. Have you considered running AI models locally / on your own infrastructure?
8. If a regulator (OAIC) asked today, could you show what data flows to which AI vendor?
9. Do your contracts with AI vendors address data residency and training-on-inputs?
10. Is someone in the business accountable for AI risk (a named owner)?
11. Have you trained staff on what not to put into public AI tools?
12. Do you have a plan if an AI tool you depend on changes price or terms overnight?

Work with me

If the checklist raised more questions than it answered, that's normal — it's the point. The fix isn't a bigger policy. It's mapping where your data goes, then choosing the right model and guardrails for each job.

I help Australian businesses put AI to work without losing control of their data: AI integration, local-first and uncensored stacks, and a clear strategy that routes into real delivery. Start a conversation.