On this page
- Artificial intelligence
- Artificial intelligence guide
- AI, privacy and cyber security
- Australian AI framework and guidance
- Common questions about artificial intelligence
Artificial intelligence
Artificial intelligence (AI) is increasingly being used by community organisations to support administration, communications, fundraising, service delivery, research and decision-making.
AI tools can help not-for-profit organisations improve efficiency, reduce administrative burdens and make better use of limited resources. However, the use of AI can also create legal, governance and operational risks.
Depending on how AI is used, organisations may need to consider:
- privacy and confidentiality obligations
- cyber security risks
- intellectual property issues
- discrimination laws
- consumer protection laws
- employment and work health and safety issues
- governance and risk management responsibilities
Before introducing an AI tool, an organisation should understand how the tool works, what information it collects and uses, and what risks it creates.
Effective governance is particularly important where an AI tool:
- processes personal, sensitive or confidential information
- influences decisions affecting individuals
- supports services provided to beneficiaries
- can interact with organisational systems or take actions with limited human involvement
Artificial intelligence guide
We have published a guide that explains the legal and governance implications of using AI in a not-for-profit organisation.
The guide covers:
- what AI is and how it is used
- the potential benefits of AI
- legal and ethical risks
- privacy, confidentiality and cyber security
- intellectual property, discrimination and consumer protection
- AI governance and organisational oversight
- Australian AI policy and regulatory developments
- responsible AI practices
- developing and implementing an AI policy
AI, privacy and cyber security
Many AI tools rely on large volumes of information, which may include personal, sensitive, confidential or commercially valuable information.
Before using an AI tool, organisations should understand:
- what information will be entered into the tool
- whether that information will be stored or retained
- whether prompts or uploaded information may be used to train or improve AI models
- who can access the information
- whether the information will be stored or processed overseas
- what security protections apply
- whether contracts, privacy laws or confidentiality obligations restrict the proposed use
Privacy obligations can apply to personal information entered into an AI tool and to AI-generated outputs containing information about an identifiable person. The Office of the Australian Information Commissioner recommends that organisations assess the suitability of commercially available AI products, embed appropriate human oversight and provide transparent information about their use of AI.
AI can also create or increase cyber security risks. Organisations should consider how AI may be used in phishing, social engineering, impersonation, fraud and other cyber attacks. Appropriate governance, access controls, staff guidance and incident-response procedures can help organisations manage these risks.
Boards, committees and senior staff should understand how AI is used within the organisation and ensure that appropriate privacy, cyber security and governance arrangements are in place.
For more information, see our privacy laws webpage, our guide to artificial intelligence and our cyber security webpage.
Australian AI framework and guidance
In July 2026, the Australian Government established the Office of AI within the Department of the Prime Minister and Cabinet. The Office will coordinate work across Australian Government agencies on the proposed Australian AI standards and related policy.
The Australian Government’s Guidance for AI Adoption provides practical guidance for organisations adopting and governing AI. It includes separate guidance for organisations starting with lower-risk uses and organisations using AI in more complex or higher-risk ways.
More information
The Australian Government’s Guidance for AI Adoption includes practical resources to help organisations adopt AI responsibly, including an AI screening tool, AI register template, and AI policy template.
Also see the Office of the Australian Information Commissioner (OAIC) website, for guidance on privacy and the use of commercially available AI products, and guidance on privacy and developing and training generative AI models.
Common questions about artificial intelligence
Does our charity need an AI policy?
There is no general legal requirement for Australian charities to have an AI policy. However, a written policy is an important governance measure for organisations that use AI tools regularly.
An AI policy can help an organisation:
- identify approved and prohibited uses of AI
- protect personal, sensitive and confidential information
- manage privacy and cyber security risks
- require review of AI-generated content
- clarify staff and volunteer responsibilities
- establish approval, oversight and incident-reporting processes
- promote lawful, ethical and responsible AI use
The policy should reflect how the organisation actually uses AI and the level of risk associated with those uses. Using AI to draft routine communications, for example, generally presents different risks from using it to assess job applicants, allocate grants or make decisions affecting beneficiaries.
The Australian Government has published an AI policy guide template.
For more information, see our guide to artificial intelligence.
What legal risks come with using AI?
The legal risks depend on the AI tool, the information it processes and how its outputs are used.
Common risks include:
- breaches of privacy law
- unauthorised disclosure of confidential information
- cyber security incidents
- discrimination or bias in AI-assisted decisions
- intellectual property infringement
- misleading, inaccurate or fabricated outputs
- breaches of contractual obligations
- negligence or consumer protection claims
- governance failures resulting from over-reliance on AI
AI-generated outputs can contain inaccurate, outdated or fabricated information. An organisation should independently review important outputs and maintain appropriate human oversight of decisions affecting individuals.
Organisations should also review providers’ terms and conditions to understand matters such as information handling, confidentiality, use of customer data, ownership of outputs, limitations of liability and service availability.
For more information, see our guide to artificial intelligence.
Can we put client information into AI tools?
Not necessarily.
Before entering information about clients, beneficiaries, members, donors, volunteers or employees into an AI tool, an organisation should consider:
- whether the information is personal, sensitive or confidential
- whether privacy laws apply
- whether the proposed use is consistent with the purpose for which the information was collected
- whether consent or notification is required
- whether a contract or funding agreement restricts disclosure
- whether disclosure could breach a duty of confidentiality
- where the information will be stored or processed
- whether it may be used to train or improve the AI model
- who can access the information
- whether the provider offers appropriate security and deletion controls
Particular care is required where information concerns children, people experiencing vulnerability or people receiving health, legal, disability or other support services.
In some circumstances, removing identifying details or using properly de-identified information may reduce risk. In other circumstances, the safest approach may be not to enter the information into the AI tool.
The Office of the Australian Information Commissioner recommends, as a matter of best practice, that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools because of the significant and complex privacy risks.
For more information, see the OAIC’s guidance on commercially available AI products, our guide to artificial intelligence and our privacy guide.
How should our board or committee oversee the use of AI?
AI is not solely a technology issue. Boards and committees should consider AI as part of their governance, risk management and compliance responsibilities.
Appropriate oversight may include:
- understanding how the organisation currently uses AI
- identifying higher-risk uses and significant potential impacts
- assigning responsibility for approving and monitoring AI tools
- approving an AI policy and related procedures
- ensuring privacy, confidentiality and cyber security safeguards are in place
- maintaining appropriate human oversight of important decisions
- monitoring legal, regulatory and technological developments
- reviewing AI-related concerns, incidents and lessons learned
The level of oversight should reflect the organisation’s use of AI. Lower-risk uses, such as preparing the first draft of a routine document, may require relatively simple controls. Higher-risk uses, such as recruitment screening or decisions affecting beneficiaries, require stronger risk assessment, monitoring and human review.
Australian Government guidance identifies clear accountability as a fundamental part of responsible AI governance. It recommends assigning responsibility for AI across the organisation and for each AI system used.
For more information, see our guide to artificial intelligence and our resources on the responsibilities of board and committee members.
The content on this webpage was last updated in September 2026 and is not legal advice. See full disclaimer and copyright notice.