OAIC guidance: commercially available AI products
The privacy regulator's October 2024 guidance on adopting off-the-shelf AI tools: check what the product does with personal information before you use it, keep personal information out of public tools, and say what you use in your privacy policy.
- Status
- In force · Australia (Commonwealth) · OAIC
- Applies to
- APP entities using off-the-shelf AI tools, from chatbots to features inside software they already run
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
Guidance from the Office of the Australian Information Commissioner, published 21 October 2024, on how the Privacy Act applies when a business uses an AI product it did not build: a public chatbot, an AI feature inside a productivity suite, a customer-service bot, a transcription tool. It creates no new obligation; it states how the regulator will read the existing Australian Privacy Principles when the tool in question is AI. It is the document the OAIC’s January 2026 privacy policy sweep and its enforcement decisions are measured against, and it is written in plain terms that a business without a specialist can follow.
What it requires
Do your homework before you adopt a tool: the guidance expects an entity to understand what personal information a product collects, uses and discloses, where the data goes, and whether the vendor uses your inputs to train its models, and to take a privacy-by-design approach that includes a privacy impact assessment for any use that could affect people. Treat input as use or disclosure: putting personal information into a tool is a use if it stays under your control and a disclosure if it does not, and entering it into a public chatbot is a disclosure to the chatbot’s owner. The OAIC’s stated best practice is that organisations “do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools”. Treat what AI generates about a person as a collection under APP 3, with consent needed if it is sensitive. Keep uses within what people would reasonably expect, or get consent and offer an opt-out. Take reasonable steps on accuracy under APP 10, because a tool that summarises or infers can be confidently wrong. Tell people when they are dealing with AI, and describe your AI use in your privacy policy.
Does this reach your business?
If the Privacy Act covers you (turnover over $3 million, or a covered category), this is the closest thing to a rulebook for everyday AI use that exists in Australia. It reaches the Copilot licence, the meeting recorder, the chatbot on your website and the AI feature your CRM vendor switched on, not only tools you chose deliberately. If you are below the threshold and not otherwise covered, the guidance does not bind you, but your larger customers will pass its expectations to you in contracts, and the “no personal information in public tools” rule is good practice at any size.
What we recommend
Our advice is to run the guidance as a five-question check on every AI tool your team uses, and to keep the answers. What personal information can it see? Does that information leave our control, and does the vendor train on it? Would the people concerned expect this use? Who checks the output before it is relied on? Have we told people, in the privacy policy and at the point of interaction? Do the check before a new tool goes live and again when the vendor changes the tool. Ban personal information in public chatbots outright; it is the one rule that removes most of the risk at a stroke. The record of those answers, tool by tool, is what the OAIC asks for when it comes looking.
Questions people ask
No. It explains how the existing Australian Privacy Principles apply when the tool is AI. Ignoring it means ignoring the regulator's stated reading of the law.
Yes, without personal information in it. The OAIC's best-practice position is that personal information, and especially sensitive information, should not be entered into publicly available AI tools.
It is a use if the information stays under your control, for example in an enterprise tool with contractual limits, and a disclosure if it does not, for example a public chatbot. The distinction decides which APP 6 rules apply.
The OAIC recommends one as part of a privacy-by-design approach wherever the use could affect people's privacy. It is the fastest way to answer the questions above.