Is Feeding Company Information Into AI Safe? What Australian Businesses Need to Know
AI is now part of everyday business work, from drafting emails and summarising documents to analysing spreadsheets and creating content.
But getting useful results often means giving AI more context, and that context can include company, customer or employee information.
AI privacy for Australian business is no longer just a question of what an AI tool can do, but how organisations collect, use, disclose and protect the information they give it.
On 31 August 2026, the Australian Government released a Privacy Reform Consultation Paper and exposure draft legislation proposing further changes to how organisations handle personal information. The consultation closes on 18 September 2026.
The proposed reforms are not yet law, but they make one thing worth examining now: how much information should your business actually be giving AI?
Why are Companies Feeding Their Information Into AI?
AI is most useful when it has something to work with.
Ask a vague question and you will usually get a generic answer. Give AI a document, spreadsheet, meeting notes or business context and the output can become far more relevant.
That is why employees are feeding company information into AI.
A marketing employee might upload a campaign brief to create content. An operations employee might paste an internal procedure to make it clearer. An accountant might use AI to analyse a spreadsheet.
The problem is that the information making AI more useful can also be information the business has a responsibility to protect.
A client document, for example, could contain a person’s name, address, financial position, superannuation information, insurance details, health information and family circumstances.
An employee may only want AI to rewrite one paragraph, but uploading the entire document may seem like the easiest option.
The motivation is productivity. The risk comes from the information being used to achieve it.
How to Use AI Without Putting Company Data at Risk
Using AI does not automatically mean putting your business at risk. The bigger issue is treating every AI tool the same or assuming anything entered into an AI system is automatically private.
The OAIC recommends organisations conduct due diligence, consider privacy by design, update policies and understand how AI providers handle information.
Before employees give company information to an AI tool, businesses should consider three things:
What information is actually being entered?
There is a significant difference between asking AI to rewrite a paragraph and uploading an entire customer database.
Personal information, sensitive information and confidential business information should all be treated carefully.
Does AI actually need the information?
Often, it does not. Names, addresses, account numbers and other identifying details can sometimes be removed or replaced with generic labels without affecting the task.
This is data minimisation, using only the information necessary to complete the task.
Which AI tool is being used?
A public AI chatbot, enterprise AI platform and AI tool operating within a controlled business environment may have different privacy, security, retention and access arrangements.
Businesses should understand how the specific tool stores and handles information, who can access it and what happens to information after it has been submitted.
Insight
The safest AI prompt is often the one containing less information.
If an AI tool can complete the task without a person’s name, address, account number, financial details or other identifying information, there may be no reason to provide them.
Protect Sensitive Information Before Giving It to AI
Sensitive information deserves a higher level of caution.
For businesses in financial advice, accounting, mortgage broking, HR and other professional services, a single client or employee file can contain highly revealing information.
Financial and client information
This may include income, expenses, superannuation, investments, insurance, tax information, addresses, family circumstances and financial goals.
Employee information
Internal records may include salaries, performance notes, personal contact details, leave information, employment records or health-related information.
Confidential business information
The risk is not limited to personal information.
Businesses should also protect source code, intellectual property, contracts, customer lists, pricing, financial forecasts, internal procedures and commercial strategies.
Privacy law is only part of the picture. A business could avoid a privacy breach while still exposing valuable confidential information.
What Happens to Company Data When You Put It Into ChatGPT?
AI products can have different settings, account types, data handling arrangements, retention periods and security controls.
Employees should not assume that information disappears simply because they close the browser.
The OAIC has highlighted that organisations may have limited ability to track, control or remove information submitted to commercially available AI tools, depending on how the service operates.
AI can also generate or infer information
AI does more than store information. It can summarise, classify, analyse and infer information from what it receives.
Businesses should therefore consider privacy implications not only for the information they provide, but also for personal information generated through AI processing.
Real-World AI Data Breaches Businesses Can Learn From

The risks of putting company or personal information into AI are not theoretical. Several incidents show how quickly a routine productivity task can become a data or confidentiality issue.
NSW Reconstruction Authority and ChatGPT
Between 12 and 15 March 2025, a former contractor working on the NSW Reconstruction Authority’s Northern Rivers Resilient Homes Program uploaded program information to ChatGPT.
The NSW Government later confirmed 2,031 people were affected, with the data including names, contact details, addresses, dates of birth, sensitive health information and limited financial commentary. Banking and financial account details were not included.
It is a clear example of how using AI for a legitimate work task can still create a privacy incident without the right controls.
Samsung and confidential source code
In 2023, Samsung restricted employees’ use of generative AI after employees entered confidential information into ChatGPT, including sensitive source code.
The risk isn’t limited to personal information. Source code, intellectual property, internal documents and commercial information can be just as valuable to a business.
No digital system is completely risk-free, which is why businesses need controls that account for both human error and technology failures.
Insight
In March 2023, OpenAI took ChatGPT offline after a bug allowed some users to see titles from another user’s chat history. The incident was a reminder that AI privacy risks do not always come from an employee intentionally entering sensitive information.
How Australia's Proposed Privacy Law Changes AI Data Handling
Australia’s privacy framework is continuing to evolve, and the latest proposed reforms place greater emphasis on how organisations collect, use, disclose and protect personal information.
One important proposed change is a broader definition of personal information based on information that relates to an identified or reasonably identifiable individual.
This could capture information such as names, dates of birth, addresses, contact details, identifiers, characteristics, behaviours, preferences, patterns and location information where it can be linked to an identifiable person.
Greater focus on fair and reasonable data use
The proposed framework would introduce a broader fair and reasonable requirement, taking into account factors including:
- reasonable expectations
- transparency
- data minimisation
- genuine choice
- proportionality and potential impacts
For AI use, this reinforces an important principle: just because information is available does not mean an organisation needs to give all of it to an AI tool.
Stronger security and breach obligations
The proposed reforms also include stronger expectations around data mapping, security assessments and destroying information when it is no longer needed.
They also propose a 72-hour notification period to the OAIC for an eligible data breach once an organisation has reasonable grounds to believe one has occurred.
These reforms are not yet law and may change as the consultation process continues.
How to Protect Company Data When Employees Use AI
Businesses do not necessarily need to ban AI. A better approach is to establish clear boundaries around how it is used.
1. Classify information
Employees should understand the difference between public, internal, confidential, personal and sensitive information.
2. Approve the AI tools employees can use
An approved tools list can help prevent employees from casually uploading business information into unknown AI applications.
3. Remove unnecessary information
Before uploading anything, ask: What can I remove without affecting the result?
Names, addresses, account numbers and other identifying details may not be necessary.
4. Set rules for sensitive and confidential data
Policies should cover more than customer information. They should also address intellectual property, source code, contracts, passwords, commercial strategies and other confidential material.
5. Keep humans responsible
AI can produce inaccurate, incomplete or misleading information.
Human review is particularly important when an AI output affects customers, employees, financial decisions, compliance or other high-stakes activities.
6. Train employees
People need to understand not just what the rules are, but why they exist. A five-minute productivity gain is not worth creating a privacy or confidentiality problem.
The 30% Rule for Safer AI Use
The 30% rule in AI has no single official definition or legal meaning. One common interpretation is that AI handles repetitive work while humans retain responsibility for judgement, quality control and accountability.
For businesses, the takeaway is simple: use AI where it adds value, keep humans in control, and only provide the information it needs.
If AI only needs a paragraph, don’t upload the entire document. If it needs a spreadsheet, consider whether every column is necessary. Less data means less unnecessary exposure.
Build AI Governance Around People, Data and Technology
AI governance is no longer just an IT issue. It sits across technology, privacy, cybersecurity, compliance, HR, operations and leadership.
This is particularly important for professional services businesses where employees may already have access to highly sensitive customer information.
ASIC has also highlighted the need for financial services businesses to consider how AI is governed and managed, identifying risks including inaccurate information, bias, customer vulnerability and weaknesses in governance.
Good AI governance should answer practical questions:
- Who can use AI?
- Which tools can they use?
- What information can they enter?
- What information is prohibited?
- When does a human need to review the output?
- Who is accountable if something goes wrong?
The answers should not sit solely with IT. They are business decisions.
Use AI Without Losing Control of Your Business Data
AI can help businesses reduce repetitive work, improve productivity and help employees get more done. But don’t give information simply because you have it.
The smarter approach is to make AI use deliberate: understand the tool, minimise the data, protect sensitive information, set clear boundaries and keep humans accountable for important decisions.
Advice2Talent helps Australian businesses build workforce and operational models that bring together people, technology and AI. If you’re reviewing how AI could fit into your business without compromising control, privacy or accountability, contact us today..
This article provides general information only and is not legal advice. Australia’s proposed privacy reforms are not yet law and may change during the legislative process.
Articles You Might Also Like

Is Feeding Company Information Into AI Safe? What Australian Businesses Need to Know
AI is becoming part of everyday business, but giving AI more information can also create privacy and confidentiality risks. Here’s what Australian businesses need to consider before putting company, client or employee information into AI tools.

AI in the Workplace: How Businesses are Redesigning Jobs and Roles
AI isn’t simply replacing jobs. It’s changing who does what. Discover how Australian businesses are redesigning roles, reallocating responsibilities and combining AI with human expertise to build more capable, efficient teams.

Experience vs Expertise: Which Matters More When Hiring?
Years of experience can tell you where a candidate has been, but expertise tells you what they can do. Learn how to assess both when hiring the right candidate.

Where the Biggest Opportunities are in Wealth Management
Australia’s wealth management opportunity is growing – but so is the challenge of serving it. Explore where the biggest opportunities lie, from retirement advice and adviser capacity to technology and smarter workforce models.

Operational Intelligence: The New Competitive Advantage for Growing Businesses
AI can automate tasks, but Operational Intelligence transforms entire workflows. Discover how businesses are combining AI, people, and smarter processes to unlock capacity, improve efficiency, and gain a lasting competitive advantage.

How AI Will Impact Entry-Level Jobs in Australia
AI isn’t eliminating entry-level jobs—but it is changing how careers begin. Learn how AI is reshaping graduate roles in Australia, the skills employers now value most, and why human judgement is becoming more important than ever.
