NDIS document store

Free AI governance guide

Safe AI implementation for NDIS providers

AI can remove repetitive work, but speed is not a substitute for authority, privacy, accuracy or professional judgement. A safe first deployment gives the tool a narrow job, limits its information and actions, and names the human who checks the result.

Free and ungatedReviewed 6 September 2026Australian provider context

Use this guide as a decision sequence.

Check the linked primary sources for your current circumstances. Record decisions, owners and evidence rather than treating general information as legal, clinical or employment advice.

1. Approve the workspace before the workflow

Record the vendor, product, plan, workspace owner, administrators, sign-in controls, retention settings, model choices and contractual data terms. Consumer and business products may have different controls, so check the current vendor documentation rather than relying on an old screenshot.

Decide whether connected apps are allowed and which administrators can enable them. A connection can expose more information or actions than a single pasted prompt.

2. Classify information and use the minimum needed

Define which public, internal, personal, sensitive and health information may enter each approved tool. Record the authority and consent basis where personal information is involved. Begin with synthetic examples and de-identified material while testing.

De-identification is more than removing a name. Combinations of service, location, dates, events or rare circumstances may still identify a participant or worker.

3. Limit permissions and external actions

Grant only the accounts, files and actions required for the approved use. Treat sending, publishing, deleting, purchasing, changing permissions and adopting a clinical or operational record as consequential actions that need an explicit control.

Keep a permission register and review it when roles, models, apps, connectors or vendor behaviour change. Remove unused access rather than leaving it available for convenience.

  • Name the workflow owner and human reviewer.
  • List the minimum data sources and permissions.
  • Define prohibited information and actions.
  • Test with synthetic data and retain the result.
  • Approve, monitor and schedule a review date.

4. Make human review specific

“Human in the loop” is useful only when the reviewer knows what to check and has time and authority to reject the output. Define checks for facts, source currency, missing context, harmful assumptions, participant voice, professional scope, privacy and final destination.

Never present AI-generated text as real observation or evidence. The accountable person must verify the record against actual work before it is adopted.

5. Start with low-risk, reversible work

Good first workflows include reorganising public information, drafting internal checklists from approved sources, improving the readability of already verified text and finding gaps in synthetic records. Avoid autonomous clinical decisions, participant eligibility conclusions or unsupervised external actions.

Record failures and near misses. An AI incident pathway should cover unintended disclosure, incorrect output used in work, unauthorised actions, permission drift and vendor changes, with containment, notification and improvement steps.

Primary sources and further reading