Responsible AI
Before staff put business data into an AI tool: eight questions
A compact privacy and security check for commercially available AI products used by Australian teams.
Before approving an AI product, clarify:
- What business, personal or sensitive information will enter the tool?
- Where is that information processed and stored?
- Who can access prompts, files and outputs?
- Is customer data used to improve the provider's models?
- What administrative and access controls are available?
- Can the organisation retrieve and delete its data?
- What audit evidence and incident notification does the provider offer?
- Who owns the product decision and its regular review?
Define permitted uses and prohibited data before rollout. Public tools should not receive personal or sensitive information by default. Assign an owner, train users and schedule reviews—the due-diligence decision is not set and forget.
Further reading: OAIC guidance on commercially available AI products ↗
Working through a similar decision?
Share the situation and we’ll suggest a focused next step.
Get a free consultation →