thirdbrain.

Across every function

What stays the same, whatever your function

The guides go function by function. These are the things that do not change between them: the Australian rules that apply wherever AI touches your business, the calls that stay with a person, and how to set the tools up so your data stays yours. Each guide then adds the specifics for its own work. This is the general picture; which of it applies, and how, depends on your business, and that judgement is yours.

  1. The claims you make are yours

    Keep this decision with a person

    Under the Australian Consumer Law, a misleading claim is your business’s liability no matter who or what drafted the words. AI writes confident claims it cannot stand up, so a person decides what you can truthfully say and holds the proof behind it. This is not a review you can hand back to the model.

    Where it shows up: Marketing claims and ad copy, sales proposals, procurement representations, what a support chatbot tells a customer, and the duty not to mislead the court in legal.

  2. Personal information stays governed

    Customer and staff details are personal information under the Privacy Act, and you stay responsible for them even when an overseas AI tool does the processing. From 10 December 2026 you also have to disclose substantially automated decisions that could significantly affect someone. Keep sensitive detail out of public tools, and keep a person in any decision that materially affects a person.

    Where it shows up: Hiring and people data in HR, customer lists in marketing, client financial data in finance, and sensitive detail in support tickets.

  3. The numbers you report are yours

    Keep this decision with a person

    A language model is not a calculator. It will produce a plausible, wrong figure inside fluent prose. AI can assemble the report and draft the commentary, but a person traces every number back to source before it goes to a board, a client, an auditor or the tax office.

    Where it shows up: Reported figures and BAS in finance, campaign ROI in marketing, claimed savings in procurement, and the committed forecast in sales.

  4. Consent and the sending rules still apply

    Every marketing or outreach message needs consent, a clear sender and a working unsubscribe under the Spam Act, whether a person or a model wrote it. AI does not change the rule; it just makes it easier to breach at scale. The same goes for marketing calls and the Do Not Call register.

    Where it shows up: Email and newsletters in marketing, outreach and sequences in sales, and success outreach and surveys in support.

  5. Where your data lives, and whether it trains the model

    Two settings decide how exposed your data is. The first is where it runs and is stored: an Australian region is increasingly available for the processing, but where data sits at rest can still be offshore, so treat residency as a moving target and confirm it with the vendor. The second is whether the tool learns from what you put in. On business and enterprise tiers, reputable vendors do not train on your inputs by default and offer a no-retention option. Check both before you load anything sensitive, because under the Privacy Act the responsibility stays with you wherever the data goes.

    Where it shows up: Every function that puts customer, staff or commercial detail into an AI tool.

Two of these, the claims you make and the numbers you report, are places we hold a firm view that AI should not make the call. The rest are standing rules and settings that apply whoever drafts the message. These are the ones that cut across every function; each guide then names the specifics for its own work. Where we have a strong view, we say it plainly.

All of this is general. Some of it will apply to you in full, some only in part, and some not at all, depending on what your business actually does and the data it handles. Working out which is which is your call. You know your business better than any guide can, and we are here to help you think it through, not to decide it for you.

See where each of these applies in your function

Questions

The questions this raises.

What does it mean for AI to "train" on my data?

Training is how a model learns: it improves by taking in large amounts of text. If a tool trains on what you type, your information can influence the answers it later gives other people. On business and enterprise tiers, reputable vendors turn this off by default, so your inputs are used to answer you and are not absorbed into the model. It is worth confirming the setting before you load anything sensitive.

Does my data leave Australia when I use AI?

It can. Where the model runs can often be set to an Australian region, but where your data is stored at rest may still be overseas, and this is changing month to month, so confirm it with the vendor. Either way, under the Privacy Act the responsibility stays with you, so the practical steps are the same: use a business tier with training off and no retention, and keep sensitive detail to a minimum.

Is it safe to put customer or staff information into an AI tool?

Treat it as something to do deliberately, not by default. Best practice is to avoid putting personal information in unless you genuinely need to, and to strip out or stand in for the identifying detail where you can, for example working from a summary, a reference number or a de-identified extract rather than the full record. Where you do need the real detail, make it a conscious call: use a business tier with training and retention off, keep the data to the minimum, and only proceed once the risk has been assessed and either mitigated with those controls or knowingly accepted by someone who can make that decision. A simple test still holds: do not put in something you could not comfortably explain handing to an overseas supplier.

How do I know which of these apply to my business?

Most of it comes down to your function and the data you handle, which is what the function guides walk through. If you would like a hand working out where these land for you and what a sensible first step looks like, book a quick chat.

Book a discovery call

A first conversation

Not sure where these land in your business?

Book a confidential chat. Tell us where you are weighing AI up, and we will talk through where these rules sit for you and what a sensible first step looks like. No deck, no pitch.