Privacy Act
The Privacy Act 1988, the Australian Privacy Principles, and OAIC guidance applied to AI: de-identification, ADM transparency, and consent.
74 articles
Articles about Privacy Act

Section 39 Requests Need a Branching Evidence Map, Not One Checklist
An aid can be medical treatment, rehabilitation support or something outside both routes. AI can expose the branches and assemble the evidence, but a human must select the statutory path, decide entitlement and preserve the reasons for that choice.
Read article
TOOCS Coding Is Data Quality, Not a Liability Finding
A TOOCS code can improve national data and still prove nothing about liability. Use AI after human entry to test version, evidence traceability and cross-field consistency. Keep every correction with a human coder and every statutory finding with the delegate.
Read article
A Complaint Is Not a Reconsideration: AI Can Route the Issue, Not Close It
A complaint can seek better service, challenge a determination and raise a licence concern in the same paragraph. AI can expose those parallel pathways, but a human must classify the message, protect every clock and approve every response.
Read article
A Defensible Claims Audit Sample Starts With the Population, Not an AI Risk Score
An AI-selected list of unusual claims may be useful for investigation, but it cannot represent a claims management system. Start with the frozen population and Comcare's published sample bands, preserve a representative core, and keep every targeted file, substitution and finding under auditor control.
Read article
Section 54 Intake: AI Can Find Gaps, Not Move the Clock
An intake model that merges receipt, claim compliance and clock status can hide delay behind a neat dashboard. Keep those states separate. AI can reconcile dates and expose missing evidence, but a human must decide section 54 compliance and every lawful exclusion.
Read article
Backdated Incapacity Needs Three Ledgers, Not One Payroll Fix
A retrospective incapacity determination can affect claim payments, payroll transactions and leave records at once, and those records do not carry the same legal meaning. AI should reconcile three ledgers and expose variances, while authorised claims and payroll professionals approve and post every correction.
Read article
Statement Summaries Need Source IDs, Not a Neat Story
A polished narrative can hide who said what, where it appears and what remains contested. A source-level assertion ledger keeps each proposition attached to the original statement, so AI assists evidence navigation while the authorised decision-maker retains every factual and credibility judgement.
Read article
Copilot Can See Your Screen. The Share Picker Is the First Control.
Microsoft 365 Copilot Vision lets a licensed user share an entire screen, a specific window or a mobile camera view during a voice conversation. For regulated Australian teams, the share picker now needs a purpose, a boundary and a stop condition before anyone starts talking.
Read article
Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.
Australia's statutory tort for serious invasions of privacy gives individuals a direct cause of action that runs on different rules to the Australian Privacy Principles. Most AI risk registers do not carry it.
Read article
Normal Weekly Earnings: AI Can Assemble the Evidence, Not Set the Figure
Most NWE mistakes start before the formula: a missing allowance rule, a distorted pay period, or overtime with no evidence of being required. AI can expose those gaps, but the relevant period and section 8 figure remain human determinations.
Read article
A Determination Evidence-Check Skill File Under Section 14
An advanced SRC Act skill file that audits a draft determination's evidence chain against sections 5A, 5B and 14, flags hedged language and gaps, and never touches the decision itself.
Read article
Your AI Vendor's Breach Starts Your Clock
On 6 July 2026 the OAIC reported the highest number of data breach notifications since the scheme began. Meanwhile organisations have quietly handed personal information to a new class of provider. Under the Privacy Act you hold what your AI provider possesses if you control it, which means the assessment clock and the notification are yours, not theirs.
Read article
AI Can Run the Section 14 Clock. It Cannot Decide.
Since 1 April 2024 a determining authority has had 20 calendar days to determine an initial injury claim, 60 for a disease claim and 30 to decide a claimant's request for reconsideration. The count can be frozen, but only by specific statutory triggers. That is a tracking problem AI is genuinely good at, sitting next to a determination it must never touch.
Read article
A Claim Chronology Skill File Built for De-Identification
A reusable six-part skill file that builds claim chronologies from de-identified material only, tags every entry to a source document, flags gaps and conflicts, and never states a view on liability.
Read article
Section 57 Examinations: AI Can Build the Referral, Not Make the Call
Since June 2024 a decision to require a section 57 medical examination is a reviewable determination, and since October 2024 it must comply with a mandatory Guide built around ethical, transparent and accountable decision-making. That raises the stakes on the referral paperwork. AI can assemble the de-identified brief, draft the question set and produce a Guide-aligned record, while the decision to require the examination stays a human judgement.
Read article
Your Website AI Assistant Is Someone Else's Code
On 24 June 2026 the Privacy Commissioner published two determinations finding that health providers interfered with privacy by letting third-party tracking pixels collect sensitive information from their websites. The reasoning is not about pixels. It is about who owns third-party code running on a page you control, and the fastest growing category of that code is an AI assistant your customers type into.
Read article
Fine-Tuning Writes Your Data Into the Model
Every organisation customising AI faces the same build decision: prompt it, retrieve for it, or fine-tune it. It is usually argued on accuracy and cost. The axis nobody raises is reversibility. Retrieval leaves your data in a store you own, audit and delete. Fine-tuning copies it into a model artefact you cannot meaningfully un-write, which makes the customisation call a records decision before it is an engineering one.
Read article
The Medical Report Now Has to Declare Its AI
Since 2 March 2026 an expert report prepared for the Administrative Review Tribunal has to state whether it contains generative AI content, identify that content and the applications used, and certify the expert checked all of it. Clause 3.7 is the part claims practitioners have missed. Reports commissioned during the claim end up in the Tribunal's documents and are read against a standard they were never written to meet.
Read article
Your Employee Data Is Exempt. That Is Not Permission.
Most Australian private sector employers are exempt from the Australian Privacy Principles when they handle their own employee records. HR teams read that as headroom for AI. It is not headroom, it is the absence of a floor, and the exemption's edges are exactly where AI workflows leak. Here is what section 7B(3) actually covers, where it stops, and the standard to put in its place.
Read article
A New AI Office Is Not a New AI Obligation
On 15 July 2026 the Commonwealth stood up an Office of AI inside the Department of the Prime Minister and Cabinet and announced a set of Australian Standards for AI. Commentary read it as Australia regulating AI. It is machinery, a standards process and a first target aimed at large data centres. Nothing announced binds how a regulated business uses AI today, and saying otherwise to a board is its own risk.
Read article
Your HRIS Now Lets Anyone Build an Agent
Workday's DevCon launch moved AI agent-building inside the HR system, and general-purpose workspaces like ChatGPT Enterprise and Claude Cowork put the same power in anyone's hands without the built-in guardrails. Here is the governance an HR team needs before it builds an agent that touches employee data: who may build, the go-live gate, and the Australian privacy and Fair Work rules that still apply.
Read article
Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset
The SRC Act guards against paying twice for the same injury: through third-party damages, an overlapping state workers compensation claim, or a state general compensation scheme. AI can flag a file for a possible overlap early and build the chronology of the parallel claim. Calculating the offset or recovery amount is a determination that stays with the case manager.
Read article
Your Recruiter Is Now an Agent, Not a Search Box
LinkedIn's recruiting agent now reaches roughly $450 million in annualised revenue, and its AI screening interview is in testing, which means a growing share of Australian candidates are assessed by an audio or video agent before a human ever sees them. Here is the governance answer HR needs before enabling one: fairness, candidate notice and the record you must be able to produce.
Read article
Your AI Logs the Tokens. Not the Decision.
Your AI telemetry records what the call cost, not what the model was told or what it said. Every content attribute in the OpenTelemetry GenAI conventions ships opt-in, and the conventions warn the message content is likely to hold personal information. That is a privacy default, not an audit default, and the two pull in opposite directions. Here is the capture, redaction and retention decision nobody is being asked to make.
Read article
Structured Outputs: Make Your AI Return Data You Can Audit
Most teams still treat an AI answer as prose to read and re-key. Structured outputs change that. You define a schema, the model is forced to fill it, and you get validated, type-safe data your systems can check. That makes an AI pipeline auditable, but schema-valid is not the same as true, so the human verification step does not go away.
Read article
AI Decides Who Sees Your Job Ad. That Is a Hiring Decision.
Every hiring tool you govern kicks in after someone applies. The bias that decides who even sees the job sits upstream, in the algorithm that delivers the ad. Research shows job ads skew by gender and race even when the targeting is inclusive, and Australian law reaches discriminatory job advertising directly. Here is how HR takes back the top of the funnel.
Read article
Reasonable Excuse Under the SRC Act: AI Can Structure the Analysis, Not Make the Finding
One test runs through five sections of the SRC Act: whether a claimant who failed to comply had a reasonable excuse. AI can structure that analysis on a de-identified file, sort the facts against the subjective and objective limbs and flag missing evidence. The reasonable-excuse finding, and any suspension or refusal that follows, stays with the human delegate.
Read article
AI in Reference and Background Checks: Verify Facts, Not Character
AI is arriving in the verification stage of hiring: tools that draft reference questions, summarise calls, scrape digital footprints and score candidates. The admin is worth automating; the judgement, the collection decisions and the fairness are not. Here is the line, a five-step process that holds it, and two ready prompts.
Read article
Your AI Agent Can Remember Now. Govern What It Keeps.
In 2026 the major labs shipped persistent memory as a first-class agent feature, barely six weeks apart. An agent that remembers across sessions is a different thing to govern, and a new attack surface. Treat the memory store as a governed data asset with write rules, provenance, expiry and rollback, not invisible plumbing.
Read article
What Your AI Workspace Actually Remembers, and What It Doesn't
Claude Cowork Projects give a workspace persistent memory, and most people have never read what that memory keeps, forgets or separates. Here is the memory model in plain terms, and the settings to decide before your team leans on it.
Read article
AI Can Build the Redundancy. It Cannot Decide It
AI is inside Australian restructures twice: in the headlines and in the HR preparation. The law has moved the other way, with the Fair Work Act and the 2025 Helensburgh Coal ruling reserving the decision, the selection and the consultation for people. Here is the legal line, two reusable prompts, a worked example and the Monday setup.
Read article
Every Application Now Reads Perfectly. Assess the Person.
Candidates now write their applications with AI, so the polish and tailoring recruiters once read as effort no longer signal anything. More than a third of Australian hiring managers say AI-generated CVs make candidates harder to assess. Trying to detect the AI is a losing game. Here is how to redesign selection to measure what a person can actually do, and keep it fair.
Read article
Australia Will Not Pass an AI Act. You Are Still Regulated.
The National AI Plan settled the question every GRC team was waiting on. Australia will not pass a standalone AI Act. That is not a reprieve. It means AI is already regulated, spread across the laws and regulators you answer to now. Here is how to stop waiting for an AI law and map every AI use to the obligation it already touches.
Read article
Two Doctors Disagree: AI Can Map the Conflict, Not Resolve It
When a treating doctor and an independent examiner disagree, the delegate has to weigh two medical opinions and determine liability on the balance of probabilities. AI can build the comparison so you spend your time on the judgement, not the sorting. Here is a de-identified workflow that keeps the weighing, and the decision, with the delegate.
Read article
Use AI to Build Practice Simulations, Not to Award the Pass
HR teams can use an approved AI assistant to build fictional role-plays, reveal information in stages, vary the difficulty and draft coaching questions. What AI must never do is decide whether an employee passed, is competent or faces an employment consequence. Here is the six-step workflow, the standards to write first, and the boundary that keeps assessment human.
Read article
GPT-Live Makes Voice a Work Interface. Check What Gets Recorded
OpenAI's GPT-Live can listen and speak at the same time, making voice feel closer to a continuous work interface than a turn-by-turn chatbot. It is rolling out to consumer ChatGPT plans first, not Business, Enterprise or Edu. That gap makes recording, retention and disclosure rules the immediate workplace question.
Read article
Model Routing Cuts AI Bills. It Also Moves Your Data.
The enterprise AI story has shifted from which model is best to which one you can afford to keep using, and buyers are moving from tokenmaxxing to model routing. The instinct is right. But for Australian regulated work a cheaper model is usually a different provider in a different place, so every routing rule is also a Privacy Act and APRA data-flow decision.
Read article
AI in Complaints Handling: What RG 271 Reserves for a Person
Financial firms are putting AI into the exact process ASIC made enforceable in RG 271. AI can triage, summarise and draft a complaint response, but the 30 day clock, the reasons, the systemic issue call and the fairness of the outcome stay with a person. Here is the obligation map, a worked example and the prompts to build your own.
Read article
AI Can Read the Award. It Cannot Set the Pay.
Award rates rise on 1 July 2026 and almost anyone can now paste a clause into an AI tool and get a confident answer. AI can help you read the award. It can never set the pay, and the law holds a person accountable for the figure.
Read article
AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.
OpenAI bought Ona and published research showing AI agents now run for hours, not seconds. The unit you have to govern moved from the prompt to the environment the agent runs in.
Read article
The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
Treasury's exposure-draft codes for the Scams Prevention Framework set a technology-neutral reasonable-steps duty on banks, telcos and digital platforms. The scams it targets are now AI-generated, which raises the bar and creates a second duty: govern the detection AI you deploy to meet the first.
Read article
AI Note-Takers in HR Meetings: Consent Before the Transcript
AI meeting assistants now record HR's most sensitive conversations by default, and often nobody in the room agreed to it. Here is a consent-and-records protocol that keeps the time savings without manufacturing your next privacy breach.
Read article
AI Can Analyse Your Engagement Survey Without Surveilling Your People
AI can read every free-text comment in your engagement survey and turn a thousand of them into themes in minutes. Done well, it finally puts that feedback to use. Done badly, it turns a survey into surveillance. Here is the line, and a workflow that stays on the right side of it.
Read article
Context Engineering: What the Model Is Allowed to See
The reliability of an AI system is decided less by how you word the prompt and more by what you let into the context window. Context engineering is the named discipline for that, and it is the highest-leverage AI skill for anyone doing real work, especially in regulated settings.
Read article
OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.
On 24 June, OpenAI and Broadcom unveiled Jalapeño, OpenAI's first custom chip, built to run its models more cheaply. The coverage is about a strike at Nvidia. The useful signal for a practitioner is the opposite of hardware: it is the falling cost of intelligence, and what that does to your AI decisions and your governance. Cost has quietly been holding AI back. That fence is coming down.
Read article
Your AI Assistant Just Became a Shared Teammate. Govern the Channel.
On 23 June, Anthropic launched Claude Tag, a single shared Claude that lives in a Slack workspace with its own memory and admin-scoped access to channels, tools and data. The unit of AI collaboration just moved from the private conversation to the team channel. The thing you now have to govern is no longer a prompt. It is a standing presence. Here is what changes, and the three decisions to make before it is live.
Read article
AI and Permanent Impairment: Organise the Evidence, Keep the Judgement
A permanent impairment claim under section 24 lives or dies on the medical evidence. AI can assemble, de-identify and structure that evidence against the approved Guide, and surface the gaps. It cannot assess the impairment or make the determination. Here is the workflow.
Read article
AI in Workplace Investigations: Organise the File, Not the Finding
AI can compress the administrative weight of a workplace investigation: planning, transcribing, organising evidence, drafting the framework. It cannot assess credibility, weigh the evidence or make the finding. Here is how to use it without compromising procedural fairness.
Read article
The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.
On 16 June, China's Z.ai released GLM-5.2 under an MIT licence with no regional limits, the highest-ranked open-weights model on its own coding benchmarks. With Anthropic's Fable 5 pulled by a US directive, the strongest model you can simply download and run is now Chinese. The decision that carries your risk is not the model. It is whether you run the open weights yourself or send your data to the hosted API.
Read article
AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control
AI screening, ranking and performance tools sit squarely inside the positive duty under the Sex Discrimination Act, the Fair Work Act and the Privacy Act. Here is the control framework Australian HR teams need before they deploy.
Read article
AI Worker Monitoring in Australia: What HR Can and Cannot Do
A practitioner guide for Australian HR teams on the privacy, surveillance, Fair Work and WHS rules that govern AI monitoring of workers, including the new automated decision-making transparency duty from 10 December 2026.
Read article
ChatGPT Just Got Better at Health. Mind the Boundary.
On 18 June OpenAI announced a substantial step up in ChatGPT's health intelligence, free to the 230 million people who already ask it health questions every week. Better answers do not move the boundary between information and a clinical decision. Here is what that means for Australian professionals this week.
Read article
AI-Assisted Onboarding: A 90-Day Plan That Keeps the Human In
Onboarding is where unmanaged AI does the quietest damage, because a new starter cannot tell a confident wrong answer from a right one. Here is a 90-day pattern, with a ready-to-build Onboarding Assistant project, where AI drafts and organises and people decide and connect.
Read article
Automated Decisions Now Belong in Your Privacy Policy
From 10 December 2026, APP entities that use personal information in automated decisions affecting people's rights must say so in their privacy policy. For Australian financial services, that is most of the AI already running in underwriting, fraud, collections and claims. Here is the readiness work, with a reusable AI project, prompt library and a worked insurer example.
Read article
Business Teams Can Now Build Their Own AI Agents
Databricks launched Genie One this week, an agentic coworker pitched at finance and marketing teams, not engineers. The real shift is who holds the build button, and where that moves the control point. Here is what to do this week, with a governance prompt you can run today.
Read article
AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order
The week a US directive forced Anthropic to suspend two new frontier models worldwide, plus six verified vendor moves and a repeatable method for turning AI news into Monday actions.
Read article
Build the Knowledge Spine That Stops Generic AI Output
Generic AI output is a context problem, not a prompt problem. Learn how a governed knowledge spine grounds your models in real organisational knowledge, with worked examples for GRC, workers compensation and HR.
Read article
Gold Standard Claude Workspace Setup
A gold standard Claude workspace for Australian enterprise teams. The right surface for each job, the files that carry context, an interview method to build each one, and the data-governance gates that keep it safe.
Read article
Gold Standard ChatGPT and Codex Setup
Build ChatGPT and Codex into one AI operating system for Australian enterprise work: the right surface per job, an interview method to build each one, and the data gates that keep it safe.
Read article
Build a WC Evidence Chronology Tool Without Outsourcing Judgement
A practical pattern for using an LLM to build an offline, de-identified workers compensation evidence chronology tool that organises facts while the delegate keeps every SRC Act decision.
Read article
Turn a Teams Transcript Into a Controlled HR SOP
A staged, evidence-first method for converting a recorded HR meeting into a governed standard operating procedure with an owner, a version history and a review rhythm.
Read article
Claude Fable 5: Frontier Capability, With Conditions Attached
Anthropic has put a Mythos-class model on general release, and the conditions matter as much as the capability. A silent classifier fallback, a mandatory 30-day retention policy and a 23 June billing switch all belong in your next third-party AI assessment.
Read article
AI in Performance Reviews: Draft the Words, Keep the Judgement
AI can synthesise a year of evidence notes into a solid first draft of review feedback. It cannot own the rating, the calibration case or the conversation. Here is the workflow that keeps the line clear.
Read article
AI Literacy Is a Management Skill, Not a Training Module
Managers must embed AI literacy through daily behaviours like prompting, verification, privacy hygiene, escalation and review to ensure responsible AI use.
Read article
Prompt Libraries Make WC AI Safer Only When Human Review Comes First
A practical SRC Act article on de-identification, placeholder prompt libraries, file-note drafting and human review controls for workers compensation communications.
Read article
Workplace AI and Privacy: The Trust Test HR Cannot Outsource
AI productivity tools can reshape workplace data collection, monitoring and employee trust. HR needs a privacy-first governance model before adoption scales.
Read article
AI in Hiring Needs Human Review Before It Needs Another Tool
Australian HR teams can use AI in recruitment, but hiring workflows need privacy discipline, bias checks, candidate transparency and accountable human judgement.
Read article
Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators
Predictive triage models promise faster decisions and better outcomes. They also concentrate legal, ethical, and procedural fairness risk. Here is how to think about both.
Read article
AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance
AI is now operating across five workflows in workers compensation claims. The value is real. The governance baseline is non-negotiable. A practitioner's map of where each tool fits, what it actually does, and what to never do.
Read article
AML/CTF and Large Language Models: A Compliance View
Large language models are now embedded across AML/CTF programs, from suspicious matter triage to KYC document review. AUSTRAC's posture on these uses is shaping. Reporting entities need a clear governance position now, not later.
Read article
Privacy-Safe AI for Regulated Work: A Working Practitioner's Guide
Workers compensation, GRC, HR and clinical roles all sit on regulated data. Using AI well in those roles is not optional. Doing it safely is not optional either. This is the practitioner's guide.
Read article
The De-Identification Toolkit for Case Managers Working With AI
A working toolkit for case managers who use AI inside live claim files. Five identifier categories, a placeholder convention, and a daily desk routine.
Read article
On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano
On-device AI is enterprise-ready in narrow ways and not in the ways the demos suggest. Apple Intelligence and Pixel Gemini Nano in April 2026: what works, what does not, and the real privacy story.
Read article
The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign
Three serious open-weight contenders shipped in April 2026. None of them is the right answer for every workload, but each has carved out a defensible enterprise niche. Here is the comparison.
Read article