Across every function
The guides go function by function. These are the things that do not change between them: the Australian rules that apply wherever AI touches your business, the calls that stay with a person, and how to set the tools up so your data stays yours. Each guide then adds the specifics for its own work. This is the general picture; which of it applies, and how, depends on your business, and that judgement is yours.
Under the Australian Consumer Law, a misleading claim is your business’s liability no matter who or what drafted the words. AI writes confident claims it cannot stand up, so a person decides what you can truthfully say and holds the proof behind it. This is not a review you can hand back to the model.
Where it shows up: Marketing claims and ad copy, sales proposals, procurement representations, what a support chatbot tells a customer, and the duty not to mislead the court in legal.
Customer and staff details are personal information under the Privacy Act, and you stay responsible for them even when an overseas AI tool does the processing. From 10 December 2026 you also have to disclose substantially automated decisions that could significantly affect someone. Keep sensitive detail out of public tools, and keep a person in any decision that materially affects a person.
Where it shows up: Hiring and people data in HR, customer lists in marketing, client financial data in finance, and sensitive detail in support tickets.
A language model is not a calculator. It will produce a plausible, wrong figure inside fluent prose. AI can assemble the report and draft the commentary, but a person traces every number back to source before it goes to a board, a client, an auditor or the tax office.
Where it shows up: Reported figures and BAS in finance, campaign ROI in marketing, claimed savings in procurement, and the committed forecast in sales.
Every marketing or outreach message needs consent, a clear sender and a working unsubscribe under the Spam Act, whether a person or a model wrote it. AI does not change the rule; it just makes it easier to breach at scale. The same goes for marketing calls and the Do Not Call register.
Where it shows up: Email and newsletters in marketing, outreach and sequences in sales, and success outreach and surveys in support.
Two settings decide how exposed your data is. The first is where it runs and is stored: an Australian region is increasingly available for the processing, but where data sits at rest can still be offshore, so treat residency as a moving target and confirm it with the vendor. The second is whether the tool learns from what you put in. On business and enterprise tiers, reputable vendors do not train on your inputs by default and offer a no-retention option. Check both before you load anything sensitive, because under the Privacy Act the responsibility stays with you wherever the data goes.
Where it shows up: Every function that puts customer, staff or commercial detail into an AI tool.
Two of these, the claims you make and the numbers you report, are places we hold a firm view that AI should not make the call. The rest are standing rules and settings that apply whoever drafts the message. These are the ones that cut across every function; each guide then names the specifics for its own work. Where we have a strong view, we say it plainly.
All of this is general. Some of it will apply to you in full, some only in part, and some not at all, depending on what your business actually does and the data it handles. Working out which is which is your call. You know your business better than any guide can, and we are here to help you think it through, not to decide it for you.
Questions
Training is how a model learns: it improves by taking in large amounts of text. If a tool trains on what you type, your information can influence the answers it later gives other people. On business and enterprise tiers, reputable vendors turn this off by default, so your inputs are used to answer you and are not absorbed into the model. It is worth confirming the setting before you load anything sensitive.
It can. Where the model runs can often be set to an Australian region, but where your data is stored at rest may still be overseas, and this is changing month to month, so confirm it with the vendor. Either way, under the Privacy Act the responsibility stays with you, so the practical steps are the same: use a business tier with training off and no retention, and keep sensitive detail to a minimum.
Treat it as something to do deliberately, not by default. Best practice is to avoid putting personal information in unless you genuinely need to, and to strip out or stand in for the identifying detail where you can, for example working from a summary, a reference number or a de-identified extract rather than the full record. Where you do need the real detail, make it a conscious call: use a business tier with training and retention off, keep the data to the minimum, and only proceed once the risk has been assessed and either mitigated with those controls or knowingly accepted by someone who can make that decision. A simple test still holds: do not put in something you could not comfortably explain handing to an overseas supplier.
Most of it comes down to your function and the data you handle, which is what the function guides walk through. If you would like a hand working out where these land for you and what a sensible first step looks like, book a quick chat.
Book a discovery callGo to the source
The Australian rules and the tooling settings behind this page, from the regulators and the vendor:
These are starting points, not legal advice. The ground moves, so confirm the current state for your own setup.
A first conversation
Book a confidential chat. Tell us where you are weighing AI up, and we will talk through where these rules sit for you and what a sensible first step looks like. No deck, no pitch.