Is your practice ready to use AI on advice? Eleven questions.
AI does not change who is responsible for advice or what a client file must hold. These questions check the obligations that already apply, as they bear on an AI tool. They apply to any tool, not to a particular product.
Checked against the law on 7 October 2026.
- 01
Client data
Do you know where client information you put into the AI tool is stored and processed, including whether it leaves Australia?
Privacy Act, APP 8.1 and APP 11.1
- 02
Client data
If client personal information is disclosed to a recipient outside Australia, have you taken reasonable steps to ensure that recipient does not breach the Australian Privacy Principles?
Privacy Act, APP 8.1 (exceptions in APP 8.2)
- 03
Client data
Have you taken reasonable steps, technical and organisational, to protect client information in the tool from misuse, loss and unauthorised access?
Privacy Act, APP 11.1 and 11.3
- 04
Client data
When client information is no longer needed and no law requires you to keep it, is it destroyed or de-identified, including any copy the tool keeps?
Privacy Act, APP 11.2
- 05
Your licensee
Does your licensee know you use the tool on advice work, and does that use fit their policies?
Licensee obligations: s912A(1)(ca) and (h)
- 06
Responsibility for the advice
Does an adviser review everything the AI produces before it reaches a client?
s961B(1); s961(2)
- 07
Responsibility for the advice
Are figures in AI-drafted documents checked against the client’s own records before the advice is given?
s961B(2)(f); s947B(2)(b)
- 08
Responsibility for the advice
Is the final SoA still clear, concise and effective, rather than lengthened by generated text?
s947B(6), s947C(6)
- 09
Responsibility for the advice
If the tool itself gives personal advice to clients, do you know who the law treats as the provider of that advice?
s961(6)
- 10
Records
Do your records show the information relied on and the steps taken for each piece of advice, including steps done with AI?
s912G(2)(a) and (b) as inserted by ASIC Instrument 2024/508
- 11
Records
Are those records kept for 7 years after the advice and accessible to your licensee?
s912G(3) as inserted by ASIC Instrument 2024/508
Sources
- Privacy Act 1988, Schedule 1 (Australian Privacy Principles)
- Corporations Act 2001 (compilation of 19 September 2026)
- ASIC Instrument 2024/508, personal advice record-keeping
This is a self-check and general information, not legal or compliance advice. The questions paraphrase the law; the exact words are in the sources above. How an obligation applies turns on your licence, your licensee's policies and the advice given. Confirm with your licensee or legal adviser.
The Australian Privacy Principles bind APP entities. Some small businesses with an annual turnover of $3 million or less are not covered by the Privacy Act (s6D), so check whether yours is. The record-keeping duty quoted as s912G was inserted into the Act by ASIC Instrument 2024/508, which is repealed at the start of 1 October 2029.