Artificial intelligence tools have become a routine part of running an Australian business. Generative writing assistants, automated customer support, AI-powered data analysis, predictive inventory systems — startups are using them from day one, often before any legal framework is in place.
That gap matters. The legal questions that come with AI services are not hypothetical: they arise the first time a staff member uploads a client file into a chatbot, the first time marketing publishes an AI-generated product claim, or the first time a supplier's platform goes down and takes a client-facing feature with it.
This article explains the core legal concepts every Australian startup founder or director should understand before building AI services into their operations. It covers:
- intellectual property and who owns AI-generated outputs
- privacy obligations when feeding data into AI tools
- Australian Consumer Law risks from AI-generated content
- what to check in AI supplier contracts
- workplace policies and employment obligations
- the documents your business actually needs
Intellectual property: who owns what an AI produces
Intellectual property questions are usually the first thing founders ask about AI tools, and the answer is not straightforward.
Copyright does not automatically protect AI-generated outputs
Under the Copyright Act 1968 (Cth), copyright subsists in original literary, dramatic, musical, and artistic works where there is a human author. Sections 32 and 35 make clear that authorship — and therefore initial ownership — flows from a human creator. IP Australia has confirmed that purely AI-generated works, with no meaningful human creative input, will not attract copyright protection under current Australian law.
In practice, this creates two risks. First, if your business is generating marketing materials, code, product designs, or client deliverables using AI, the output may not be copyright-protected at all unless a human made creative choices in producing it. Second, the more a human directs, selects, and shapes the output, the stronger the claim to copyright — but this is a grey area the law has not yet fully resolved.
Your inputs can be at risk too
Most AI platforms reserve the right to process your inputs — the prompts, documents, data, and files you provide — in ways that may include model training. Before uploading any confidential business information, client materials, or commercially sensitive data, review the provider's terms carefully. If the platform retains or uses your inputs beyond immediate processing, that creates confidentiality and IP exposure for your business.
If you are building a product that depends on AI-generated outputs, or delivering client work using AI tools, getting IP ownership in your agreements clarified early is essential — both in your supplier contracts and in your client-facing terms.
Trade mark and brand risk from AI-generated content
AI-generated images, logos, slogans, and text can inadvertently reproduce elements of existing registered trade marks. The fact that a tool generated the output does not insulate you from a trade mark infringement claim. Treat IP clearance as a workflow step, not an afterthought, when using AI-generated brand materials commercially.
Privacy obligations when using AI tools
The Privacy Act 1988 and who it covers
The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) govern how organisations handle personal information. Under s 6D of the Act, a "small business operator" is generally defined as having an annual turnover of $3 million or less — and most small business operators are exempt from the Act. However, the exemption has important carve-outs: health service providers, businesses that trade in personal information, and several other categories are covered regardless of turnover. If you are unsure whether your business falls within the Act, take legal advice rather than assume the exemption applies.
Even if your business is currently below the threshold, exceeding $3 million in turnover brings you within the Act's scope from the following financial year. Planning your privacy framework ahead of that threshold is far less disruptive than retrofitting it after the fact.
What counts as personal information, and why it matters for AI tools
Personal information is broadly defined — it includes any information or opinion about an identified individual, or an individual who is reasonably identifiable. Customer names, email addresses, purchase histories, employee records, support tickets, and meeting notes can all qualify. Health information and certain other categories are treated as sensitive information and attract additional obligations under the APPs.
The problem for AI users is that tools work best when fed real business data. Before uploading anything, ask: is this personal information? Was it collected for this purpose? Does the platform send it offshore?
Cross-border disclosure and overseas AI providers
Most major AI platforms operate servers outside Australia. APP 8 requires APP entities to take reasonable steps to ensure an overseas recipient does not breach the APPs when handling personal information. If the overseas platform does not offer adequate contractual protections and does not operate under a substantially equivalent privacy framework, the Australian entity remains accountable for how the information is handled offshore. This obligation cannot simply be transferred away in a terms of service acceptance.
Security obligations under APP 11
APP 11 requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. A new sub-clause inserted in December 2024 makes explicit that "reasonable steps" includes both technical and organisational measures. Feeding personal information into an unsecured or inadequately vetted AI platform without appropriate controls may itself constitute a failure of this obligation.
The Notifiable Data Breaches scheme
Businesses covered by the Privacy Act — including those with annual turnover above $3 million — are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Act. An eligible data breach must be reported to the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. A data breach occurring through an AI platform — whether from a security failure on the provider's side or from unauthorised model training that exposes user data — can trigger these obligations.
Australian Consumer Law and AI-generated content
The Competition and Consumer Act 2010 (Cth), Schedule 2 — the Australian Consumer Law (ACL) — applies to every business selling goods or services in Australia. Under s 18, a person must not engage in conduct that is misleading or deceptive, or likely to mislead or deceive. Section 29 separately prohibits false or misleading representations about goods and services.
AI tools make it easy to generate claims at scale — product descriptions, testimonials, performance statements, before-and-after comparisons. The fact that the content was AI-generated provides no defence if the output is misleading. The ACCC enforces the ACL and can pursue civil penalties for contraventions.
The practical risk for a startup is publishing AI-generated marketing copy that has not been reviewed against what the product actually does. A human review step for any customer-facing content involving product claims, pricing, performance, health or safety, or guarantees is a straightforward control that reduces ACL exposure significantly.
What to check in AI supplier contracts
Standard form AI provider agreements are often non-negotiable in their core terms — but understanding what you have agreed to is a prerequisite for managing risk.
Key areas to review before committing to any AI service:
- IP and output ownership: Does the provider grant you sufficient rights to use outputs commercially? Can you sublicence AI-generated deliverables to your clients?
- Data use and model training: Does the provider use your inputs, outputs, or user interactions to train or improve its models? If so, on what terms and with what opt-out rights?
- Confidentiality: What are the provider's obligations around keeping your data confidential? Is it shared with subcontractors or affiliated entities?
- Liability and indemnity: Most AI providers heavily limit their liability — often to fees paid in a recent period, and usually excluding indirect or consequential loss. If the AI tool goes down, produces incorrect outputs that cause client loss, or triggers a data breach, you need to understand whether you carry most of that risk.
- Suspension and termination: Can the provider cut access unilaterally? If your product or operations depend on the service, what are your continuity options?
- Data export: Can you retrieve your data and outputs if you leave the platform?
The unfair contract terms regime under the ACL — which was significantly expanded from 9 November 2023 — now applies to standard form contracts with businesses employing fewer than 100 people or with annual turnover under $10 million. Proposing, using, or relying on an unfair contract term in a standard form contract is now prohibited and can attract penalties. This cuts both ways: as an AI consumer, you may have protections under these provisions; as an AI service seller, your own customer terms must comply.
Workplace obligations and AI use policies
Employees and contractors using AI tools at work create real legal exposure if the boundaries are unclear.
Common scenarios that generate problems:
- A staff member uploads client files, financial records, or commercially sensitive documents to a generative AI tool whose terms permit model training on inputs.
- A contractor uses AI to draft deliverables and the business later discovers ownership of the output is ambiguous.
- AI tools are used to screen candidates for roles or to evaluate employee performance, raising questions about fairness and potentially engaging anti-discrimination obligations.
A workplace AI use policy does not need to be elaborate, but it should clearly set out: which tools employees may use, what categories of information may not be entered into any AI tool, and who is responsible for reviewing AI-generated work before it goes to clients or is published. These controls should be reflected in employment contracts and contractor agreements, particularly around confidentiality, IP ownership of work product, and acceptable use of business systems.
Where professional help is usually required — how Artificer Legal can assist
The legal issues that arise from using AI services touch multiple areas of law simultaneously — privacy, intellectual property, consumer protection, and employment — and the specific obligations depend heavily on your business structure, what data you handle, and what you are selling.
A lawyer can help you:
- assess whether your business is covered by the Privacy Act and what your obligations are under the APPs
- review your AI supplier contracts for IP, data use, liability, and termination risk
- draft or update customer-facing terms, website terms, and privacy policies to reflect your actual use of AI tools
- prepare employment contracts and internal AI use policies that create clear confidentiality and IP boundaries
- advise on trade mark and copyright clearance for AI-generated brand materials
At Artificer Legal, we work with Australian founders, directors, and operators who want practical legal advice — not boilerplate. If you are building AI services into your business, or selling AI-enabled services to clients, we can help you build the right legal framework from the start.
Getting the foundations right
AI services can unlock genuine speed and scale advantages for an Australian startup. But each tool you adopt can also introduce privacy, IP, or consumer law exposure if the underlying legal framework is not in place.
The key principles to keep in mind:
- Copyright in AI outputs is not automatic — human creative input is required under the Copyright Act 1968 (Cth), and purely AI-generated work may not be protected at all.
- Privacy obligations follow the data — uploading personal information into an AI platform can engage your obligations under the APPs, APP 8, and the NDB scheme, regardless of whether the platform is based in Australia.
- The ACL applies to every claim you publish — AI-generated marketing content must be accurate and not misleading, and you remain responsible for it.
- Supplier terms govern your risk — reviewing IP ownership, data use, liability limits, and termination rights before you depend on a platform is far cheaper than discovering the problem later.
- A written AI use policy is a practical necessity if you have staff or contractors working with AI tools and client or business data.