
Using AI at work?

Privacy governance should come before prompts
Direct answer
Before staff use commercially available AI tools with customer, employee, client or supplier information, an Australian business should decide what information may be entered, what must never be entered, who is allowed to use which tools, how outputs will be checked, and whether the tool’s settings and contract terms are suitable for the information involved.
AI adoption should be treated as a privacy, confidentiality and risk-management issue — not just a productivity experiment.
Why this matters
Many AI products are easy to start using and hard to govern after informal habits form. Staff may begin using general-purpose tools for summarising emails, drafting customer replies, reviewing contracts, analysing complaints, preparing HR material or organising business records before the organisation has decided what safeguards apply.
The legal and practical risk is rarely the mere fact that a business uses AI. The risk is uncontrolled use: personal information copied into unsuitable systems, confidential material disclosed without proper approval, unclear retention or training settings, poor records of high-risk use, and outputs relied on without human review.
That is why the first question should not be “Which AI tool should we buy?” It should be: “What information are we handling, what duties apply to it, and what controls do we need before people start using the tool?”
The OAIC’s guidance confirms the governance problem
The Office of the Australian Information Commissioner has published guidance for businesses using commercially available AI products and for developers using personal information to develop or train generative AI models.
The practical message for businesses is clear: privacy obligations can apply to both information entered into an AI system and AI-generated outputs where those outputs contain personal information. Businesses need to assess AI privacy risks before deployment, choose appropriate products, and use governance measures that match the information being handled.
The OAIC’s media release announcing the guidance also records Privacy Commissioner Carly Kind’s warning that AI products should not be used simply because they are available, and that robust privacy governance and safeguards are essential to gaining value from AI while maintaining community trust.
For Australian businesses, that is a useful framing. AI may be commercially valuable, but convenience is not a governance strategy.
A practical AI privacy checklist for businesses
A useful starting point is to document the answer to eight questions.
-
Which AI tools are staff already using? This includes approved tools, trial tools, browser extensions, document platforms, CRM features, meeting assistants and informal use of public chatbots.
-
What information might be entered? Identify customer records, employee information, complaints, contracts, medical or financial information, identity documents, legal correspondence, confidential commercial material and any other sensitive categories.
-
Which information is prohibited or restricted? Some material should not be entered into public or unapproved tools at all. Other material may only be used after redaction, minimisation or approval.
-
What does the vendor do with inputs and outputs? Check retention, training use, access controls, audit logs, data location, subprocessors, deletion rights and business/enterprise settings. A tool being popular does not answer these questions.
-
Who is allowed to use the tool, and for what purpose? Different rules may be needed for marketing, internal administration, HR, legal work, customer service and management decision-making.
-
What human review is required? AI outputs can be incomplete, inaccurate, outdated or inappropriate for the context. Human review should be mandatory before outputs affect customers, employees, legal rights, regulatory obligations or external communications.
-
What records should be kept? Sensitive or high-impact uses may require a record of the tool used, the purpose, the information category, approval steps, review steps and final decision-maker.
-
Do contracts, privacy notices and policies match actual use? AI governance is not only an IT policy. It may affect privacy notices, supplier contracts, employment policies, confidentiality terms, client engagement terms, data breach procedures and board or management risk reporting.
Where LawFlow fits
LawFlow’s approach is AI-assisted and lawyer-led. We use technology to reduce wasted process time — for example, document organisation, extraction, comparison, chronology-building and first-pass drafting support — while keeping legal judgment, confidentiality controls and final advice with a lawyer.
For businesses adopting AI, the same principle applies. AI should reduce wasted work, but the workflow needs to preserve accountability. The right question is not whether AI is “allowed” in the abstract. The better question is how the business can use AI in a way that is useful, supervised, privacy-aware and commercially defensible.
That may involve:
-
an AI acceptable-use policy;
-
a privacy and confidentiality risk assessment;
-
staff guidance on prompts and prohibited information;
-
a list of approved and unapproved AI tools;
-
contract and vendor-term review;
-
redaction and minimisation protocols;
-
human-review rules for outputs;
-
incident-response steps for accidental disclosure; and
-
regular review as tools and regulatory expectations change.
A short, practical governance framework is usually more valuable than a long policy no one reads. The aim is not to stop useful AI adoption. The aim is to make it safe enough to use well.
Key takeaway
If your business is using AI, privacy governance should come before prompts.
Start with the information, not the tool. Decide what can be entered, what must be kept out, which settings and contracts are acceptable, and who remains responsible for checking outputs. That is how AI becomes a controlled business capability rather than an unmanaged privacy risk.
Sources
-
Office of the Australian Information Commissioner, “Guidance on privacy and the use of commercially available AI products”: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
-
Office of the Australian Information Commissioner, “Guidance on privacy and developing and training generative AI models”: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models
-
Office of the Australian Information Commissioner, “New AI guidance makes privacy compliance easier for business”: https://www.oaic.gov.au/news/media-centre/new-ai-guidance-makes-privacy-compliance-easier-for-business
Disclaimer
This article is general information, not legal advice. For advice about your circumstances, contact LawFlow.


