| Read time: 2 min
It seems harmless enough.
A manager needs a quick sales summary, so he pastes a customer spreadsheet into a free AI tool. Seconds later, the report is ready. But the spreadsheet contains names, emails, contact details and purchase histories, and no one has checked who can access that information or how it may be used by that AI tool.
A convenient shortcut on an AI tool may ultimately create a privacy breach.
For businesses covered by the Privacy Act 1988 (Cth), privacy obligations apply whenever they handle personal information, that is, information that identifies, or could reasonably identify, someone. Entering this information into an AI tool is a use of the information. It may also be a disclosure to the AI provider if the provider can access it and the business no longer controls how it is handled. This may occur, for example, if the provider can reuse the information to train its large language models.
The practical takeaway is this – if your business uses AI tools, you should:
From 10 December 2026, businesses covered by the Privacy Act must also include additional information about certain automated decisions in their privacy policies. This applies where a computer program makes, or plays a substantial and direct role in making, a decision. The decision must be one that could reasonably be expected to significantly affect a person’s rights or interests. Depending on the circumstances, this may include decisions about employment, credit, insurance or access to important services.
AI tools can save time, but using them responsibly requires more than simply ‘copy, paste and submit’. Your business should set clear rules for using AI, approve suitable tools, review each provider’s terms and conduct a privacy impact assessment where appropriate.
At Bespoke, we help businesses develop practical AI governance. We also update privacy policies, collection notices and contracts to reflect how AI is used in practice. Feel free to contact us for a confidential discussion.