Secure AI for business
Secure AI for business: a checklist for Australian organisations
A practical checklist for choosing safe AI tools for business in Australia, based on the OAIC's guidance on commercially available AI products, with what the vendor should handle and what stays your responsibility.
- Claude requests processed only in AWS Sydney and Melbourne
- Prompts and documents never used to train AI models
- SSO and audit logs available on Enterprise
General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.
Secure AI for business comes down to two things: choosing a tool that handles your data properly, and using it in a way your obligations allow. The first is mostly the vendor's job. The second is always yours. This checklist of what makes AI tools safe for business in Australia covers both, using the Office of the Australian Information Commissioner's (OAIC) guidance on commercially available AI products as the baseline.
What the OAIC expects when you adopt an AI product
The OAIC's guidance, published in October 2024, applies to the AI tools most organisations actually use: chatbots, content generators and productivity assistants for writing, note-taking and transcription. Its main points:
- Privacy obligations cover inputs and outputs. Personal information you type in, and personal information the AI generates, both fall under the Privacy Act. That includes wrong or invented information about an identifiable person.
- Do due diligence, and keep doing it. Check the product suits its intended use, how humans will oversee it, its security, and who can access what you enter. The OAIC says this shouldn't be a "set and forget" exercise.
- Know where the servers are. For cloud AI, consider where servers are located and whether personal information could be disclosed outside Australia.
- Read the terms. Understand whether the service terms give the developer access to the data you input or generate.
- Keep personal information out of public tools. As a matter of best practice, the OAIC recommends that organisations don't enter personal information, and particularly sensitive information, into publicly available generative AI tools.
- Govern its use. Have internal policies that define permitted and prohibited uses, human oversight of outputs, regular monitoring and staff training.
The secure AI for business checklist
| Check | What to look for | How AusGPT handles it | Your responsibility |
|---|---|---|---|
| 1. Data location | Where data is stored at rest and where AI processing runs | Stored on AWS in Sydney. Claude requests are routed only between AWS Sydney and Melbourne. Dictation uses Amazon Transcribe in Sydney | Record this in your privacy impact assessment. Check the other tools in your workflow too |
| 2. Training on your data | A clear statement that prompts and files aren't used to train models | Never used to train AI models. Amazon Bedrock doesn't share prompts or responses with Anthropic or other model providers | Stop staff using personal accounts on public AI tools for work |
| 3. Who else can see it | Vendor staff, subprocessors and model providers with access to inputs | Bedrock states that model providers have no access to customer prompts and completions | Read our privacy policy and contract terms, and ask us anything your review needs |
| 4. Access control | Managed accounts, an admin who controls membership, single sign-on | Team workspaces with member invitations. SSO and audit logs on Enterprise | Decide who is invited, remove leavers promptly, and set rules for sharing conversations |
| 5. Retention | How long conversations and files are kept, and how deletion works | Ask us how retention and deletion work for your account | Align AI use with your record-keeping obligations, and don't upload what you're not allowed to keep |
| 6. Vendor terms | Who operates the service, where it's hosted, and what happens to your data | AusGPT is a Melbourne-based company running on AWS in Australia | Review the contract and privacy terms like any other supplier handling your data |
| 7. Staff policy | Rules on which tools are approved and what information can go in | A shared prompt library with folders helps teams reuse approved prompts | Write the policy, train staff, and check it's followed |
| 8. Human review | A person checks outputs before they're relied on | Treat every AusGPT response as a draft for a person to check | Verify outputs, label AI-generated records, and keep a human in decisions that affect people |
Why data location covers storage and processing
Many AI products store your conversations in one place and run the model somewhere else. A tool can keep chat history in Australia while sending every prompt overseas for processing. For personal information, that matters: under Australian Privacy Principle 8, an organisation that discloses personal information to an overseas recipient generally remains accountable for how that recipient handles it.
AusGPT was built so the answer is the same for both. Claude runs through Amazon Bedrock's Australian cross-region inference profile, which keeps processing within Sydney and Melbourne, and conversations and documents stay on AWS in Sydney. To compare how other assistants handle this, see our comparison of private ChatGPT options.
What stays your responsibility
A secure tool reduces risk. It doesn't make every use lawful or every answer right. These parts are always yours:
- Purpose. Under APP 6, using personal information for a purpose other than the one it was collected for generally needs consent, or must be related to the original purpose and within the person's reasonable expectations. The OAIC notes that entering personal information into an AI system may be a use or a disclosure, and APP 6 applies either way.
- Sensitive information. Health, disability and similar information carries extra obligations. Some regulators and professional bodies have their own expectations about AI, so check yours.
- Accuracy. The OAIC suggests treating AI outputs as statistically informed guesses and making sure your records show where information came from AI. Someone has to check the facts.
- Transparency. Update your privacy policy and notices to describe how you use AI. From 10 December 2026, organisations covered by the Privacy Act that use personal information in automated decision-making with the potential to affect individuals' rights or interests must explain in their privacy policies the kinds of personal information used and the kinds of decisions made.
- Governance. The National AI Centre's Guidance for AI Adoption sets out six essential practices for organisations, from deciding who is accountable to maintaining human control. It's a useful frame for a lightweight AI policy.
Give your team AI that keeps data in Australia
AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.
A simple rollout plan
- List the uses. Write down what staff want AI for: drafting emails, summarising documents, preparing reports.
- Classify the information. Note which uses involve personal, sensitive or confidential information, and which don't.
- Choose an approved tool. Pick one that passes checks 1 to 6 above, and tell staff which tool to use.
- Write a one-page policy. Approved tools, what information can and can't go in, who reviews outputs, and who to ask.
- Share good prompts. Save prompts that work in a shared library so staff don't improvise with sensitive data.
- Review regularly. Revisit the policy as tools, guidance and your own use change.
For more on how AusGPT approaches security, see the security page, or contact us with your questionnaire.
Sources
- OAIC: Guidance on privacy and the use of commercially available AI products (21 October 2024, updated 17 January 2025)
- OAIC: APP guidelines, Chapter 8 (cross-border disclosure of personal information)
- OAIC: Consultation on guidance for transparency in automated decision making (18 May 2026)
- National AI Centre: Guidance for AI adoption, implementation guidance
- AWS: Amazon Bedrock cross-region inference for Claude in Japan and Australia (31 October 2025)
- AWS: Amazon Bedrock data protection
- AWS: Amazon Bedrock FAQs
Frequently asked questions
- What are safe AI tools for business in Australia?
- A safe AI tool for an Australian business is one where you know where data is stored and processed, the vendor doesn't train models on your data, you control who has access, and the terms tell you who else can see your information. Safety also depends on how you use it: a staff policy, care with personal information and human review of outputs.
- Can staff put personal information into ChatGPT?
- The OAIC recommends, as best practice, that organisations don't enter personal information, and particularly sensitive information, into publicly available generative AI tools. In any AI tool, the Privacy Act still applies: using personal information for a secondary purpose generally needs consent, or must be related to the original purpose and within the person's reasonable expectations (APP 6).
- Does keeping data in Australia make an AI tool compliant?
- No. Onshore storage and processing reduce cross-border disclosure questions under APP 8, but you still need a lawful purpose for using personal information, accurate records, reasonable security, transparency in your privacy policy and human oversight. No tool makes you compliant on its own.
- Do we need a privacy impact assessment before using AI?
- The OAIC recommends a privacy-by-design approach that includes conducting a privacy impact assessment when adopting AI products. A short assessment of what data staff will enter, where it goes and who can see it is a sensible starting point for most organisations.
- How does AusGPT keep data secure?
- AusGPT runs Anthropic's Claude models through Amazon Bedrock's Australian cross-region inference, which routes requests only between AWS Sydney and Melbourne. Conversations and documents are stored on AWS in Sydney and are never used to train AI models. Enterprise plans add SSO and audit logs.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.