1. Accuracy — AI outputs are not reliable legal facts
  2. Bias — discriminatory outputs and reputational exposure
  3. Privacy — the obligations triggered by entering personal information into AI tools
  4. Data breach exposure — AI platforms are not zero-risk systems
  5. Unintended disclosure — confidential and commercially sensitive information
  6. Where Australian AI regulation currently sits
  7. How Artificer Legal can help
  8. Key takeaways

Generative AI tools are now a practical part of running a business. They draft correspondence, summarise contracts, generate marketing copy and produce internal policies at a pace no human team can match. The efficiency gain is real — but so is the legal exposure if these tools are used without understanding the obligations they trigger.

Australian law does not have a single AI statute. What it has is a dense network of existing obligations — privacy law, copyright law, consumer law — that all apply to how a business uses AI tools. The OAIC, the ACCC and the Department of Industry have each issued guidance or begun consultation on AI-specific rules. The regulatory environment is moving quickly, and businesses that treat AI adoption as a purely commercial decision are missing the legal dimension entirely.

This article explains the five main legal risk areas: accuracy and hallucination, bias in outputs, privacy and data protection, data breach exposure, and unintended disclosure of confidential information. It also sets out where the Australian regulatory framework currently sits, and what practical steps reduce exposure.

Generative AI models produce outputs by predicting statistically plausible text, not by retrieving verified facts. A model trained on data with a cut-off date will not know about legislation amended after that date, a regulator's most recent guidance, or a court decision handed down last month. More significantly, these models can produce references to cases, statutory sections, or regulatory thresholds that simply do not exist — a phenomenon commonly called "hallucination."

For a business, the risk is not abstract. A contract clause citing a non-existent statutory obligation, a workplace policy that misstates a minimum entitlement, or a commercial agreement that references an incorrect regulatory threshold can all expose the business to liability — not the AI tool provider.

Every AI-generated document should be reviewed by someone with the legal knowledge to check the accuracy of any legal claims it contains before that document is relied upon, sent to a counterparty, or used to make a decision.

Bias — discriminatory outputs and reputational exposure

AI models learn from the data they are trained on. Where that training data reflects historical biases — stereotyped representations, demographic skew, or prejudicial framing — the model will reproduce and amplify those patterns in its outputs. The model itself has no mechanism to detect or correct for this.

In a business context, this matters in at least two ways:

  • Operational outputs: AI-assisted hiring tools, customer-facing communication, or product recommendation systems can produce outputs that treat people differently based on protected attributes without the business being aware. This may engage obligations under Commonwealth and state anti-discrimination legislation.
  • Reputational exposure: Documents, marketing content or public-facing text that contains prejudicial framing — even where unintentional — can damage brand reputation and expose the business to consumer backlash or complaints.

The practical response is to build a review step into any process that uses AI to produce outputs that will affect individuals. Businesses that are training or fine-tuning their own models should audit the training data for demographic skew before deployment.

Privacy — the obligations triggered by entering personal information into AI tools

This is the area of most immediate legal risk for most Australian businesses.

When a business enters personal information — an employee's name, a client's health status, a customer's financial details — into a publicly available AI tool, it discloses that information to a third party. The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to that disclosure.

Several APPs are directly engaged:

  • APP 6 requires that personal information be used or disclosed only for the purpose for which it was collected, or a purpose the individual would reasonably expect, or with consent. Entering client information into an AI tool to draft a letter is unlikely to satisfy any of these conditions unless the business has obtained specific authority.
  • APP 8 governs cross-border disclosure of personal information. Most major AI platforms store and process data on servers located outside Australia. Before disclosing personal information to an overseas recipient, the disclosing entity must take reasonable steps to ensure the overseas recipient does not breach the APPs. Under s 16C of the Privacy Act 1988 (Cth), the Australian entity remains accountable for any act or practice of the overseas recipient that would breach the APPs if done in Australia. This accountability framework applies regardless of what the AI provider's terms of service say — the business cannot contract out of its Australian law obligations by accepting a vendor's standard terms.
  • APP 11 requires a business to take reasonable steps to protect personal information from unauthorised access or disclosure. Entering that information into a public AI tool where the provider may use it for model training, or where it could be exposed to a security incident, is difficult to reconcile with that obligation.

The OAIC published guidance in October 2024 — updated in January 2025 — that addresses this directly. The OAIC's position is that, as a matter of best practice, organisations should not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The guidance notes that once information enters an AI system, it becomes very difficult to track, control or remove.

For businesses that handle health information, financial information, or information about children, the risk profile is higher still. These categories attract additional obligations under the APPs, and a breach involving this class of information is more likely to trigger a notifiable data breach threshold.

Data breach exposure — AI platforms are not zero-risk systems

Generative AI platforms are subject to the same categories of security risk as any other cloud service. They can be subject to unauthorised access, data interception, or exploitation of vulnerabilities in the platform's own systems.

Several publicly reported incidents have involved AI platforms either inadvertently exposing user inputs to other users, or being susceptible to techniques designed to extract information from the model's training data. The risk is not hypothetical.

For businesses that are APP entities under the Privacy Act 1988 (Cth), a data breach involving personal information may trigger mandatory notification obligations under the Notifiable Data Breaches scheme if it is likely to result in serious harm to any individual whose information is involved. The notification obligations run to both the OAIC and the affected individuals, and the reputational and operational consequences of a notified breach can be significant.

Before adopting any AI tool that will process personal information, a business should review the vendor's data security practices and the terms under which that data is handled, stored and deleted. Where the tool's terms do not provide adequate assurance, the risk of using it for personal information processing needs to be consciously accepted and documented — not simply overlooked.

Unintended disclosure — confidential and commercially sensitive information

Public AI tools generate outputs by drawing on patterns learned from their training data and, in some implementations, from prior conversations with other users. Entering commercially sensitive information — a business strategy, unreleased product specifications, a client list, or negotiating positions — into a public AI tool creates a risk that this information is processed, stored, or incorporated into the model's outputs in ways the business cannot control.

Most AI providers allow users to opt out of having inputs used for model training. This opt-out mechanism reduces some of the risk but does not eliminate it. The data still passes through the provider's systems and may be retained for security, compliance, or other operational purposes as permitted by the provider's terms.

The practical approach is to treat a public AI tool as a non-confidential channel. Information that would not be emailed to an external party without a non-disclosure agreement in place should not be entered into a public AI tool. Where AI processing is necessary for sensitive work, businesses should use enterprise-grade tools that offer data processing agreements and explicit commitments about data isolation.

Where Australian AI regulation currently sits

Australia does not yet have a dedicated AI Act. The current regulatory position is a combination of existing law and a developing voluntary and mandatory framework:

  • The Voluntary AI Safety Standard, released by the Department of Industry, Science and Resources in September 2024, sets out ten guardrails covering transparency, accountability, human oversight and data governance. Compliance is voluntary for now, but the standard signals the direction of regulation.
  • The Department consulted in 2024 on a proposals paper for mandatory guardrails for AI in high-risk settings. The proposed mandatory framework would require developers and deployers of high-risk AI to take specific steps across the AI lifecycle. That framework had not been enacted as at the date of this article, but the consultation closed in October 2024 and legislative development is underway.
  • The OAIC's October 2024 AI guidance sits within the existing Privacy Act framework. It is not a new law — it is the regulator's articulation of how existing APPs apply to AI. Non-compliance with the APPs is enforceable now.
  • Under s 18 of the Competition and Consumer Act 2010 (Cth) (Schedule 2 — the Australian Consumer Law), a business must not engage in misleading or deceptive conduct in trade or commerce. Where AI-generated content contains factual errors about a product, service, or the business's own capabilities, and that content reaches consumers, s 18 exposure arises regardless of how the error was produced. The AI tool's involvement is not a defence.

On copyright, the position in Australia is that copyright subsists in a work only where there is human authorship. The Full Federal Court in Telstra Corporation Ltd v Phone Directories Company Pty Ltd [2010] FCAFC 149 held that copyright could not subsist in works where the creative contribution of any human author could not be identified. A purely AI-generated document — one where no human author exercised creative input — is likely to attract no copyright protection in Australia, which means the business has no IP ownership over it. Any AI-generated work intended to be commercially significant or to carry trade mark or brand association should include substantive human creative input to preserve copyright protection.

The legal risks of AI adoption are not abstract — they are traceable to specific obligations in existing Australian law that are already enforceable. Getting the governance framework right before the problem arises is considerably less expensive than addressing a privacy complaint, a data breach notification, or a misleading conduct claim after the fact.

Artificer Legal works with Australian businesses to:

  • Review existing privacy policies and data handling procedures to identify whether current AI tool usage is compliant with the APPs
  • Draft or review AI usage policies that address the risks of staff entering personal information, confidential information, or legally sensitive data into public AI tools
  • Assess vendor contracts and data processing agreements for AI tools to identify APP 8 and security gaps
  • Advise on copyright ownership where AI-generated work is commercially significant

Key takeaways

Generative AI tools are commercially useful but legally non-trivial. Before embedding them into your business processes, it is worth mapping the risks:

  • AI outputs are not legally reliable — every document requires human review before it is relied upon or sent to a counterparty
  • Entering personal information into a public AI tool engages your obligations under the Australian Privacy Principles, particularly APP 6, APP 8 and APP 11 — the OAIC recommends against it as a matter of best practice
  • Under s 16C of the Privacy Act, your business remains accountable for what an overseas AI provider does with personal information you disclose to it
  • AI-generated documents may not attract copyright protection unless a human author contributed substantive creative input
  • Factual errors in AI-generated content that reaches consumers can give rise to misleading conduct liability under s 18 of the Australian Consumer Law
  • Australia's mandatory AI guardrail framework is in development — businesses that build governance practices now will be better placed when it arrives