Is Feeding Company Information Into AI Safe? What Australian Businesses Need to Know

AI is now part of everyday business work, from drafting emails and summarising documents to analysing spreadsheets and creating content.

But getting useful results often means giving AI more context, and that context can include company, customer or employee information.

AI privacy for Australian business is no longer just a question of what an AI tool can do, but how organisations collect, use, disclose and protect the information they give it. 

On 31 August 2026, the Australian Government released a Privacy Reform Consultation Paper and exposure draft legislation proposing further changes to how organisations handle personal information. The consultation closes on 18 September 2026.

The proposed reforms are not yet law, but they make one thing worth examining now: how much information should your business actually be giving AI?

Why are Companies Feeding Their Information Into AI?

Admin writing AI code on laptop.
The more context AI has, the more useful its output can become. The challenge is making sure that context doesn't include information your business should never have shared.

AI is most useful when it has something to work with.

Ask a vague question and you will usually get a generic answer. Give AI a document, spreadsheet, meeting notes or business context and the output can become far more relevant.

That is why employees are feeding company information into AI.

A marketing employee might upload a campaign brief to create content. An operations employee might paste an internal procedure to make it clearer. An accountant might use AI to analyse a spreadsheet.

The problem is that the information making AI more useful can also be information the business has a responsibility to protect.

A client document, for example, could contain a person’s name, address, financial position, superannuation information, insurance details, health information and family circumstances.

An employee may only want AI to rewrite one paragraph, but uploading the entire document may seem like the easiest option.

The motivation is productivity. The risk comes from the information being used to achieve it.

How to Use AI Without Putting Company Data at Risk

Using AI does not automatically mean putting your business at risk. The bigger issue is treating every AI tool the same or assuming anything entered into an AI system is automatically private.

The OAIC recommends organisations conduct due diligence, consider privacy by design, update policies and understand how AI providers handle information.

Before employees give company information to an AI tool, businesses should consider three things:

What information is actually being entered?

There is a significant difference between asking AI to rewrite a paragraph and uploading an entire customer database.

Personal information, sensitive information and confidential business information should all be treated carefully.

Does AI actually need the information?

Often, it does not. Names, addresses, account numbers and other identifying details can sometimes be removed or replaced with generic labels without affecting the task.

This is data minimisation, using only the information necessary to complete the task.

Which AI tool is being used?

A public AI chatbot, enterprise AI platform and AI tool operating within a controlled business environment may have different privacy, security, retention and access arrangements.

Businesses should understand how the specific tool stores and handles information, who can access it and what happens to information after it has been submitted.

Insight

The safest AI prompt is often the one containing less information.

If an AI tool can complete the task without a person’s name, address, account number, financial details or other identifying information, there may be no reason to provide them.

Protect Sensitive Information Before Giving It to AI

Sensitive information deserves a higher level of caution.

For businesses in financial advice, accounting, mortgage broking, HR and other professional services, a single client or employee file can contain highly revealing information.

Financial and client information

This may include income, expenses, superannuation, investments, insurance, tax information, addresses, family circumstances and financial goals.

Employee information

Internal records may include salaries, performance notes, personal contact details, leave information, employment records or health-related information.

Confidential business information

The risk is not limited to personal information.

Businesses should also protect source code, intellectual property, contracts, customer lists, pricing, financial forecasts, internal procedures and commercial strategies.

Privacy law is only part of the picture. A business could avoid a privacy breach while still exposing valuable confidential information.

What Happens to Company Data When You Put It Into ChatGPT?

AI products can have different settings, account types, data handling arrangements, retention periods and security controls.

Employees should not assume that information disappears simply because they close the browser.

The OAIC has highlighted that organisations may have limited ability to track, control or remove information submitted to commercially available AI tools, depending on how the service operates.

AI can also generate or infer information

AI does more than store information. It can summarise, classify, analyse and infer information from what it receives.

Businesses should therefore consider privacy implications not only for the information they provide, but also for personal information generated through AI processing.

Real-World AI Data Breaches Businesses Can Learn From

Cyber criminal exploiting a system vulnerability.

The risks of putting company or personal information into AI are not theoretical. Several incidents show how quickly a routine productivity task can become a data or confidentiality issue.

NSW Reconstruction Authority and ChatGPT

Between 12 and 15 March 2025, a former contractor working on the NSW Reconstruction Authority’s Northern Rivers Resilient Homes Program uploaded program information to ChatGPT.

The NSW Government later confirmed 2,031 people were affected, with the data including names, contact details, addresses, dates of birth, sensitive health information and limited financial commentary. Banking and financial account details were not included.

It is a clear example of how using AI for a legitimate work task can still create a privacy incident without the right controls.

Samsung and confidential source code

In 2023, Samsung restricted employees’ use of generative AI after employees entered confidential information into ChatGPT, including sensitive source code.

The risk isn’t limited to personal information. Source code, intellectual property, internal documents and commercial information can be just as valuable to a business.

No digital system is completely risk-free, which is why businesses need controls that account for both human error and technology failures.

Insight

In March 2023, OpenAI took ChatGPT offline after a bug allowed some users to see titles from another user’s chat history. The incident was a reminder that AI privacy risks do not always come from an employee intentionally entering sensitive information.

How Australia's Proposed Privacy Law Changes AI Data Handling

Australia’s privacy framework is continuing to evolve, and the latest proposed reforms place greater emphasis on how organisations collect, use, disclose and protect personal information.

One important proposed change is a broader definition of personal information based on information that relates to an identified or reasonably identifiable individual.

This could capture information such as names, dates of birth, addresses, contact details, identifiers, characteristics, behaviours, preferences, patterns and location information where it can be linked to an identifiable person.

Greater focus on fair and reasonable data use

The proposed framework would introduce a broader fair and reasonable requirement, taking into account factors including:

  • reasonable expectations
  • transparency
  • data minimisation
  • genuine choice
  • proportionality and potential impacts

 

For AI use, this reinforces an important principle: just because information is available does not mean an organisation needs to give all of it to an AI tool.

Stronger security and breach obligations

The proposed reforms also include stronger expectations around data mapping, security assessments and destroying information when it is no longer needed.

They also propose a 72-hour notification period to the OAIC for an eligible data breach once an organisation has reasonable grounds to believe one has occurred.

These reforms are not yet law and may change as the consultation process continues.

How to Protect Company Data When Employees Use AI

Businesses do not necessarily need to ban AI. A better approach is to establish clear boundaries around how it is used.

1. Classify information

Employees should understand the difference between public, internal, confidential, personal and sensitive information.

2. Approve the AI tools employees can use

An approved tools list can help prevent employees from casually uploading business information into unknown AI applications.

3. Remove unnecessary information

Before uploading anything, ask: What can I remove without affecting the result?

Names, addresses, account numbers and other identifying details may not be necessary.

4. Set rules for sensitive and confidential data

Policies should cover more than customer information. They should also address intellectual property, source code, contracts, passwords, commercial strategies and other confidential material.

5. Keep humans responsible

AI can produce inaccurate, incomplete or misleading information.

Human review is particularly important when an AI output affects customers, employees, financial decisions, compliance or other high-stakes activities.

6. Train employees

People need to understand not just what the rules are, but why they exist. A five-minute productivity gain is not worth creating a privacy or confidentiality problem.

The 30% Rule for Safer AI Use

The 30% rule in AI has no single official definition or legal meaning. One common interpretation is that AI handles repetitive work while humans retain responsibility for judgement, quality control and accountability.

For businesses, the takeaway is simple: use AI where it adds value, keep humans in control, and only provide the information it needs.

If AI only needs a paragraph, don’t upload the entire document. If it needs a spreadsheet, consider whether every column is necessary. Less data means less unnecessary exposure.

Build AI Governance Around People, Data and Technology

AI governance is no longer just an IT issue. It sits across technology, privacy, cybersecurity, compliance, HR, operations and leadership.

This is particularly important for professional services businesses where employees may already have access to highly sensitive customer information.

ASIC has also highlighted the need for financial services businesses to consider how AI is governed and managed, identifying risks including inaccurate information, bias, customer vulnerability and weaknesses in governance.

Good AI governance should answer practical questions:

  • Who can use AI?
  • Which tools can they use?
  • What information can they enter?
  • What information is prohibited?
  • When does a human need to review the output?
  • Who is accountable if something goes wrong?

 

The answers should not sit solely with IT. They are business decisions.

Use AI Without Losing Control of Your Business Data

AI can help businesses reduce repetitive work, improve productivity and help employees get more done. But don’t give information simply because you have it. 

The smarter approach is to make AI use deliberate: understand the tool, minimise the data, protect sensitive information, set clear boundaries and keep humans accountable for important decisions.

Advice2Talent helps Australian businesses build workforce and operational models that bring together people, technology and AI. If you’re reviewing how AI could fit into your business without compromising control, privacy or accountability, contact us today..

This article provides general information only and is not legal advice. Australia’s proposed privacy reforms are not yet law and may change during the legislative process.

Articles You Might Also Like​

Full shot woman at work with coffee cup
Company Insights
Carolina Castillo

How AI Will Impact Entry-Level Jobs in Australia

AI isn’t eliminating entry-level jobs—but it is changing how careers begin. Learn how AI is reshaping graduate roles in Australia, the skills employers now value most, and why human judgement is becoming more important than ever.

Read More »

Leave a Reply

Your email address will not be published. Required fields are marked *