Privacy-safe AI for regulated work
Learning Hub artefact

What to check before AI touches regulated data

Five questions to answer before any AI workflow touches regulated data, the eight-field workflow record that makes it defensible, and the mistakes that undo it.

Regulated data AI pre-use check · Free, no sign-up · Plain markdown

Download the Regulated data AI pre-use check (.md)

What this is for

Before any AI workflow that touches data more sensitive than yesterday's coffee order, there are five questions worth five minutes. The fifth is the one almost no one writes down, and it is the one an auditor asks first.

This is the pre-use assessment from the privacy-safe AI explainer, with the workflow record that turns a decision into something you can hand to a regulator.

How to use it

Walk the five questions and write your answers down. If you cannot answer all five, do not proceed. The five-step assessment is the gatekeeper, not the prompt.

Then complete the eight-field workflow record before the work happens. Documentation that does not exist before the work happens is documentation that will not exist after.

The artefact

Section 1: five questions before AI touches regulated data

1. What is the data classification?

Public, internal, confidential, or restricted, using your organisation's classification framework. If you do not have one, default to treating anything that names a person, a customer, a claim, a financial position, or an internal process as confidential or higher.

2. Who is the data subject and what consent applies?

For workers compensation: the claimant, the employer, the treating practitioner. For HR: the employee. For GRC: the customer, the regulator, the named third party. Each has rights under the Privacy Act and the relevant sectoral regime. Consent for one purpose does not extend to AI processing unless that was contemplated.

3. What jurisdiction governs the data?

Australian regulated data has Australian rules. Some sectors require data residency in Australia or in jurisdictions on an approved list. Some prohibit cross-border processing without specific consent or a contractual basis. The tool you pick must respect this.

4. What is the worst-case downstream use?

If the prompt and the data leak, what is the worst case. A claimant's medical history posted on a forum. A customer's identifying details used to train a future model. A regulator's confidential request inadvertently disclosed. The worst-case scenario is the floor for your decision, not the average case.

5. What is the documented justification for using AI on this data?

If a regulator or an internal auditor asks why this data went through this tool, what is your documented answer. "It saved time" is not a sufficient answer. "We assessed the privacy posture against APP 11, the tool meets the criteria, and the workflow is documented in our AI register" is.

Section 2: the workflow record

For any AI workflow that touches regulated data, document the following.

  1. The purpose, named and bounded
  2. The data classification and the data subjects affected
  3. The tool, the tier, and the contractual basis, or "no contract, consumer tier, only non-regulated data permitted"
  4. The de-identification step, if any
  5. The retention and deletion expectation
  6. The human review step, with a named role and a named action
  7. The escalation path if the tool produces an output that should not be relied on
  8. The owner, the reviewer, and the review cadence

This becomes part of your AI register. It is the document you hand to a regulator, an internal auditor, or your replacement when you leave the role. Workflows without this documentation are not workflows. They are habits, and habits are not defensible.

Section 3: the mistakes that undo it

  • Trusting the consumer tier with regulated data because the company name is famous. Major providers run consumer tiers and enterprise tiers separately. A famous brand does not equal an enterprise contract. The contract is what you rely on.
  • Assuming a paid account means enterprise. A personal paid account is still consumer tier. Enterprise tier is contracted at the organisation level.
  • Paste now, document later. Build the documentation into the workflow design.
  • Treating the AI as the decision-maker. Regulated work decisions belong to a human, named in your file, with the authority to make that decision. The AI assists. The AI does not decide.
  • Assuming de-identification scales. It works case by case. It does not necessarily work at the volume and pattern level.

TheAICommand. Intelligence, At Your Command.

Download the Regulated data AI pre-use check (.md)← Read the full article

General information and education only. Not legal, compliance, financial, or professional advice. This artefact is assembled from Privacy-safe AI for regulated work and adds nothing to it. Free to use and adapt internally, with attribution appreciated and no warranty. Check it against your own obligations and your organisation's policies before you rely on it.