1. Which business structure actually matters here
  2. What director duties require from you
  3. Where the Privacy Act applies to your business
  4. The Australian Consumer Law and what it catches
  5. Intellectual property — what you own and what you don't
  6. Core contracts you need before taking on clients
  7. Sector-specific obligations worth checking early
  8. How Artificer Legal can help structure your AI venture
  9. The thing most AI founders get wrong at the start

You have an AI product or service taking shape. Maybe you are automating something for small businesses, packaging a large language model into a niche vertical, or offering implementation consulting. The legal groundwork is the same regardless of how the product works — and getting it wrong early is far more expensive than getting it right.

This article works through the legal questions an AI founder or early-stage operator in Australia needs to answer before they take on paying customers, hire staff, or move data outside their own systems.

Which business structure actually matters here

The choice between sole trader and company is not just an accounting question. For an AI business it has practical consequences for risk isolation, IP ownership, and future capital raising.

A sole trader structure is cheap to establish and simple to administer, but there is no separation between your personal assets and business liabilities. If your AI tool produces a bad recommendation for a client and they suffer a loss, your personal exposure tracks that loss. Most AI service and product businesses carry meaningful liability risk — automated outputs can affect business decisions, and the indemnity clauses clients expect to see in your agreements assume a counterparty with some legal substance behind it.

Incorporating as a company through ASIC creates a separate legal entity. The company holds contracts, owns IP, and bears liability. Your personal exposure is limited to your investment in the company (subject to you meeting your director duties — more on that below). A company can also issue shares, which matters if you want to bring in co-founders, grant equity to early employees, or raise capital.

Once you have a company, you will need an Australian Business Number (ABN) from the ATO and may need to register a business name with ASIC if you trade under a name other than the company's legal name.

If you have co-founders, lock in a shareholders agreement before any value accrues to the company. That document sets the rules for decisions, share transfers, exits, and what happens when founders disagree. Doing it after the fact — when someone has already walked out or when you are mid-fundraise — is a much harder conversation.

What director duties require from you

Once you incorporate, you are a director of an Australian company, and the Corporations Act 2001 (Cth) imposes obligations on you personally.

Under s 180, you must exercise your powers and discharge your duties with the degree of care and diligence a reasonable person in your position would exercise. Under s 181, you must act in good faith in the best interests of the company and for a proper purpose. These are civil penalty provisions — breach can attract personal liability even when the company itself is solvent.

For an AI business, these duties have a practical implication: when you make decisions about which third-party model APIs you use, what data your product handles, and what liability exposure you take on in contracts, you are making business judgements that courts will assess against a reasonable director standard. Keeping clear records of how you assessed those decisions — including version histories of terms accepted, model providers selected, and risk mitigations put in place — is good governance, not just paperwork.

Where the Privacy Act applies to your business

The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) govern how private sector entities collect, use, disclose, and secure personal information.

There is a small business exemption under s 6D of the Privacy Act: a business with annual turnover of $3 million or less is generally not required to comply. But that exemption is narrower than it looks for most AI businesses:

  • If you are a health service provider (including apps or services that handle health records), you are covered regardless of turnover.
  • If you collect personal information and disclose it to anyone for a benefit (including providing data to a model API that uses it for training), you may be treated as carrying on a business that trades in personal information — which removes the exemption.
  • If a client's contract requires you to comply with the Privacy Act, you are contractually bound even if you are technically below the threshold.

In practice, most AI products and services handle personal information from day one — customer queries, employee data fed into automations, sales records processed by analytics tools. It is safer to build for compliance from the start than to retrofit privacy obligations after you have scaled past the threshold or signed a large enterprise customer whose procurement team expects a Privacy Policy and a Data Processing Agreement.

The APPs require you to collect only the personal information you need, tell people why you are collecting it, secure it appropriately, and give individuals a mechanism to access or correct their records. APP 1 specifically requires you to have a clear, published privacy policy. APP 11 requires reasonable steps to protect personal information from misuse, loss, and unauthorised access or disclosure.

If you are processing personal information on behalf of a client — rather than for your own purposes — you are acting as a processor, and your client may require a Data Processing Agreement setting out your security obligations, breach notification timelines, sub-processor controls, and data deletion arrangements.

The Australian Consumer Law and what it catches

The Australian Consumer Law (ACL) is Schedule 2 of the Competition and Consumer Act 2010 (Cth). If you sell products or services in trade or commerce, it applies.

Section 18 prohibits misleading or deceptive conduct. For AI businesses, this has two practical edges. First, your marketing claims about what your product can do. If you tell a prospective customer that your tool will reduce their admin time by a specific figure, or that it produces legally compliant documents, those claims can attract liability if they are false or cannot be substantiated. Frame AI outputs as assistance or recommendations, not as guaranteed results, and document the basis for any performance claims you do make.

Second, your terms. Section 23 of the ACL renders unfair terms in standard-form consumer contracts and standard-form small business contracts void. A term that excludes all liability regardless of circumstances, or that gives you the unilateral right to vary the contract materially without notice, is the kind of clause that attracts scrutiny. Well-drafted SaaS terms allocate liability sensibly rather than trying to exclude it entirely, which is both better legal practice and more commercially credible with sophisticated customers.

The ACL also implies consumer guarantees into contracts for services — guarantees that services will be rendered with due care and skill, and will be fit for the stated purpose. You cannot contract out of these. Where your service involves AI outputs that may not always meet those standards, your terms need to clearly define what the service is (and is not) rather than relying on exclusion clauses to do the work.

Intellectual property — what you own and what you don't

Three distinct IP questions arise for most AI businesses.

Your own IP. The Copyright Act 1968 (Cth) protects original works (code, written content, training materials) where there is a human author. Copyright in work created by employees in the course of their employment vests in the employer by default. Copyright in work commissioned from contractors does not vest in the commissioning party by default — a written assignment is required. If you engage freelance developers to build your product, or contractors to create training data or prompt libraries, make sure IP assignment is expressly included in their agreements. Unwritten assumptions about ownership create disputes at exactly the wrong time (due diligence, fundraising, acquisition).

The model and API layer. If you are building on a third-party model via an API, read the provider's usage terms before you go to market. Most large model providers restrict use in certain sectors (healthcare, legal advice, certain government applications), prohibit presenting outputs as human-generated, and include provisions about how they handle prompts and training. Operating outside those terms creates contractual risk and may expose you to claims from end users if the model behaves in ways the licence did not permit.

AI-generated output. Australian copyright law currently requires a human author for copyright to subsist in a work. Output generated solely by an AI model, without sufficient human creative contribution, is unlikely to attract copyright protection. This is an evolving area — there is no definitive court ruling on the point — but it means you should not promise clients that AI-generated content is copyright-protected. If copyright ownership of deliverables matters to the client, build in a human authorship and editorial step and document it.

Core contracts you need before taking on clients

The documents you need depend on your model, but for most AI businesses the minimum set is:

Services agreement. If you are providing implementation, consulting, or managed services, you need a written agreement that defines deliverables, fees, IP ownership, data handling obligations, liability limits, and what happens when things go wrong. Verbal agreements and email chains leave every one of those questions open for dispute.

SaaS terms or end-user licence. If you are providing software or a platform, your user-facing terms govern access, acceptable use, support scope, uptime, and the limits of your responsibility. The terms need to match how the product actually works — generic templates often miss the specifics of AI behaviour (hallucinations, output variability, model updates affecting functionality) that you need to address.

Privacy policy. Required under APP 1 if you are an APP entity, and expected by enterprise clients regardless. It must accurately describe how you collect, use, store, and disclose personal information — a policy that does not match your actual practices is worse than no policy.

Non-disclosure agreement. Use one before sharing client datasets, proprietary processes, or confidential business information with contractors, partners, or prospective customers in a pilot phase.

Employment contracts. If you hire, each employee needs a written contract that specifies their role, remuneration, IP assignment (so the IP they create vests in the company), confidentiality obligations, and notice periods. Obligations under the Fair Work Act 2009 (Cth) — including the National Employment Standards — apply regardless of what the contract says, but a well-drafted contract reduces ambiguity and manages expectations on both sides.

Sector-specific obligations worth checking early

The AI business models that carry the highest legal risk are those that operate in or adjacent to regulated industries. If your product touches health records, financial advice, legal information, or government data, additional frameworks apply.

Health information is sensitive information under the Privacy Act and attracts additional APPs. Financial products and services are regulated by ASIC. Providing legal advice without a practising certificate raises unauthorised legal practice issues under state and territory law. If you are building tools that operate in these spaces, early advice on the regulatory framework is not optional — the consequences of getting it wrong (regulatory action, client liability, loss of accreditation) are disproportionate.

Even outside those sectors, if you are selling to enterprise clients or government, expect procurement teams to ask about data residency, security certifications, sub-processor lists, and breach notification procedures. Building those answers into your product and contracts from the start is faster than retrofitting.

The legal questions that matter most for an AI business are the ones where the commercial and legal calls intersect — and where getting it wrong is expensive to unwind. Artificer Legal works with founders and operators at this intersection.

We can advise on the right structure for your specific situation (sole trader versus company, whether a holding structure is appropriate for IP ring-fencing), draft and review your core agreements (services agreements, SaaS terms, NDAs, employment contracts), and ensure your privacy documentation matches both your actual data flows and the requirements of the Privacy Act. Where your product operates in or near a regulated sector, we can map the specific obligations that apply and identify where your contracts or product architecture need to account for them.

If you are at the planning stage, an early conversation is worth more than a document review after the fact — the structure you choose now determines what is easy and what is painful later.

The thing most AI founders get wrong at the start

The most common error is treating legal foundations as something to address once the product is working. By the time a pilot customer asks for a Data Processing Agreement, or an enterprise prospect wants to see your privacy policy, or a founding team dispute emerges over who owns the IP created in the first year — the position has hardened and the options have narrowed.

The decisions that are cheapest to make correctly are the ones made early: the shareholders agreement before value exists, the IP assignment clauses before the contractors leave, the privacy architecture before the data is collected. The legal framework does not slow down an AI business that gets it right from the start; it protects the value you are building.

To recap the key points this article has covered: choose a corporate structure that separates personal and business risk; understand that director duties under the Corporations Act 2001 (Cth) create personal obligations from the moment you incorporate; check whether the Privacy Act small business exemption actually applies to your model before assuming it does; frame your marketing claims carefully under the ACL's prohibition on misleading conduct; secure IP assignments from contractors in writing; and put your core customer-facing documents in place before launch, not after.