Initiative overview
Robust privacy safeguards are essential in protecting individual rights and to realise the benefits of AI by building the trust and confidence of the community engaging with the digital economy. How businesses should be approaching AI and what good AI governance looks like is a pressing issue of interest and challenge for industry. The Australian community is increasingly concerned about the privacy risks and harms associated with personal information being used to develop generative AI products.
This initiative address these by outlining key privacy considerations and requirements when selecting and using AI products, and highlighting a governance approach that enables innovation while being respectful of privacy rights.
The goal of the guidance is to clarify how Australia’s privacy laws apply to AI and set out the expectations of the OAIC as Australia’s independent privacy regulator. It aims to make privacy compliance easier by articulating what good AI governance looks like and outlining practical steps to help businesses follow privacy best practices. It is not intended to be a comprehensive overview of all privacy risks and obligations that apply to the use of AI.
The guidance was written based on the current state of technology and market practices at the time of writing while recognising that future developments are likely to affect how risks and mitigations are understood (e.g. the emergence of agentic AI). Hence, each section of the guidance contains high-level statements of the law that can adapt to these changes and are supported by detailed examples grounded in what is concretely known about AI at the time of publication. To accommodate the dynamism and rapidity of AI developments and legislative reforms to Australia’s privacy framework, further guidance may be issued in the future as per the OAIC’s guidance making functions.
The guidance has supplementary materials that distil key insights and prompt businesses to practically reflect on their privacy approach. This includes a top five takeaways summary, and checklists of privacy considerations when selecting and using commercially available AI products.
The guidance applies to all types of AI systems involving personal information but will be particularly useful in relation to generative AI products. It does not address privacy considerations associated with development and training of AI systems.



























