Industries
The duty is already there. AI just joined it.
Care, clinic, firm, book, agency. Different harm. Same question: who used which model, on whose data, under which policy, and where is the working.
The sectors
The duty is different. The harm is named.
Aged care already lives under the Commission. Health cannot treat a model as a clinician. Legal cannot put client matter in a prompt. Financial services already knows a customer-facing model is a control issue. Government already answers to FOI, ministers, and the auditor-general.
-
01
Read this sector
Regulated care
Aged care and disability
A roster tool or notes assistant still sits under the Commission.
-
02
Read this sector
Clinical and patient data
Health
Chatbot misuse is already a clinical hazard. A model is not a clinician.
-
03
Read this sector
Privilege and file integrity
Legal and professional services
Privilege in a prompt is a discovery problem. Hallucinated citations are a court problem.
-
04
Read this sector
Risk and conduct
Financial services
Advice, credit, or client files without a named owner will not survive internal review.
-
05
Read this sector
Public sector and citizen data
Government
FOI, ministers, and the auditor-general still ask who signed.
Regulated care
Aged care and disability. A notes assistant is still a control issue.
Residents, families, and a workforce already under the Commission. A roster tool or a notes assistant does not sit outside that duty.
Dignity, consent, and workforce already live under the Aged Care Quality Standards and the NDIS Quality and Safeguards Commission. AI joins that duty. It does not get a free pass because it is just notes.
In the building
Roster tools, progress-note assistants, and family comms bots are already on the floor. Name the model, the data, and the owner before the next quality visit.
What they must show
What a Commission or quality reviewer will ask.
-
01
Harm
Resident and family
Who is on the file when a model drafts a note, and who owns the output.
-
02
Duty
Whose data
Roster, progress notes, family comms. Name the model, the data, and the owner.
-
03
Duty
Which policy
Acceptable use, stop conditions, and who may put a client file into a tool.
-
04
Duty
The working
Keep it when the Commission or a quality reviewer asks. Not a screenshot of a chat.
What good looks like
AI joins the duty they already live under. Architecture around the tools already in the building. No free pass for a notes assistant.
Clinical and patient data
Health. A model is not a clinician.
Patient safety is not a metaphor. A language model is not a clinician, and chatbot misuse is already a named clinical hazard.
Privacy Act, clinical safety, and TGA device rules all ask the same question: who is accountable when the output is used, and where is the working.
In the building
Symptom checkers, notes copilots, coding automation, imaging tools. Publish none of them as a clinician. ECRI already ranked AI chatbot misuse a top health technology hazard.
What they must show
Privacy, safety, and device rules still ask who owns it.
-
01
Harm
The patient
A language model is not a clinician. Do not publish it as one.
-
02
Duty
Patient data
Privacy Act still applies when a model reads a record. Name the data and the owner.
-
03
Duty
Clinical safety
Human oversight, explainable output, and an owner when the output is used. TGA still asks.
-
04
Duty
The working
If you cannot show it, you do not publish a score. Architecture first. Tools second.
What good looks like
Architecture around clinical use. Tools second. A copilot is still a control issue, and a score you cannot show does not get published.
Privilege and file integrity
Legal. Client matter is not a prompt.
Privilege in a prompt is a discovery problem. Hallucinated citations are a court problem. Neither is a productivity win.
Partners need a named owner, an acceptable-use line, and an evidence pack the firm can defend. Client matter does not belong in an unmanaged tool.
In the building
Research copilots, contract review, eDiscovery. Privilege review without a trail is how waiver happens. Fabricated precedents are how sanctions happen.
What they must show
Privilege is a control issue. Not a productivity win.
-
01
Harm
The client, and the ticket
Privilege in a prompt is a discovery problem. Treat it as one. Evidence Act still applies.
-
02
Duty
Court-defensible work
Verification so fabricated precedents and hallucinated citations never leave the firm.
-
03
Duty
Conduct
LPUL and the Solicitors Conduct Rules still apply to AI-assisted research and drafting.
-
04
Duty
File integrity
What was used, on whose file, under which policy. Keep the working. Files stay off our site.
What good looks like
Architecture around the tools already on the floor. Named partner, stop conditions, files off our site.
Risk and conduct
Financial services. If it touches customers, it is a control issue.
Advice, credit, or client files without a named owner will not survive internal review. A vendor demo will not either.
If the model touches customers, credit, or advice, the board already knows. You need capability, controls, evidence, and oversight. Not a pitch deck.
In the building
Advice assistants, credit tools, client-file copilots. Unsupervised tax or finance answers have no safe harbour. Hallucinated numbers are a liability.
What they must show
Survive internal review. Not a vendor demo.
-
01
Harm
The customer, and the firm
If the model touches customers, credit, or advice, this is already a control issue.
-
02
Duty
Named owner
Who may use what, on which book, and when it stops.
-
03
Duty
Conduct
No unsupervised advice. Hallucination on finance answers is a liability, not a feature.
-
04
Duty
Explainability
AML and internal review still ask how the score was made. A demo does not survive that question.
What good looks like
Architecture around the tools you already bought. Named owner, stop conditions, and working an internal reviewer can open.
Public sector and citizen data
Government. A chatbot is not an accountable authority.
Citizens still have a right to know who signed. A constituent chatbot does not sit outside ministers, FOI, or the auditor-general.
Secretaries, accountable authorities, and risk owners must show who used which model, on whose citizen data, under which policy, and keep the working when it is asked for.
In the building
Constituent chatbots, drafting assistants, records search. If a model helped write it, FOI can still ask for the working.
What they must show
FOI, audit, and ministers still ask who signed.
-
01
Harm
The citizen
APS, local government, statutory bodies. A model does not become the decision-maker.
-
02
Duty
Citizen data
Privacy Act still applies. Name the model, the data, and the owner.
-
03
Duty
FOI and records
If a model helped write it, the working can still be asked for. Keep it.
-
04
Duty
Procurement
A vendor demo is not a control. Architecture around what the agency already bought.
What good looks like
Architecture around what the agency already bought. A chatbot is not the decision-maker. Someone still signs.
Which start
The question decides the start. Not the sector list.
Architecture first. The licensed pack is there if a reviewer needs it this week, files off our site.
- Need it named, owned, and installed in the operation?
- Book a governance call.
- Need people who can operate the controls?
- Academy.
- Need a pack a reviewer can open this week, files off our site?
- Licensed offline audit.
- Sector not listed?
- The architecture is the same. Book the call.
Governance first. No corners cut.
If your sector is not listed, the architecture is the same.
Book a governance call. Start the licensed audit only if you need a pack this week.