In the space of a few weeks, two Australian industries with almost nothing in common got the same warning.
The Finance Brokers Association of Australasia told mortgage brokers to keep client and company data out of public AI tools. Around the same time, aged care providers started working under a new rights-based Aged Care Act that expects them to show how their people and systems handle sensitive resident information.
Different pressures but the same direction. If you use AI in your business, you need to be able to say where your data goes, how it gets processed and what protects it at each step. Taking a software vendor's word for it is no longer enough.
None of this means you should avoid AI but it means the way you build it matters.
Once your data is out, it is out
The FBAA drew a clear line for its members. Personal and commercially sensitive information should not be pasted into public generative AI tools.
There is a technical reason behind it, and the Australian Information Commissioner has made the same point. Once personal information lands in a public AI platform, getting it back, tracking it or deleting it becomes hard.
Brokers already lean on automation for document processing, loan matching and client updates, which is the ground covered in how independent brokers catch the AI-native ones. So the problem is not the technology. The problem is what happens to private information when it is handled without proper controls.
Aged care is being pushed the same way but through law and regulation rather than a memo. The rights-based Aged Care Act 2024 took effect in late 2025, alongside strengthened Quality Standards and the Support at Home program. Providers have to be ready to show how their systems and staff collect information, process it and keep it safe.
Technology is spreading across the sector at the same time, from companion robots and behaviour monitors to virtual nursing trials and pain management apps. The Aged Care Quality and Safety Commission has published its own AI transparency statement, which signals that disclosure and oversight are expected to travel with adoption.
Resident records hold sensitive medical and personal history. Put that into a public chatbot and you create the same risk as uploading a borrower's bank statements to a consumer AI service. You lose real control over data you are still responsible for protecting.
A policy is not a control
People talk about artificial intelligence and public consumer apps as if they are the same thing but they are very different.
AI is a capability. It runs in all sorts of environments. A public chatbot is one way to deliver it, built for broad consumer use, not for the privacy, security and audit needs of a regulated business.
When a staff member drops client data into one of these tools, that data leaves your controlled environment. You have no reliable way to pull it back, no full record of how it was processed and little sight of which systems touched it. If something leaks, or a regulator asks, the responsibility is still yours.
This is why telling staff to be careful with ChatGPT does so little. A rule you cannot enforce, monitor and back with evidence is hard to stand behind in an audit or an investigation.
A blanket ban brings its own problems. Staff quietly reach for tools you have not approved, while competitors use well governed automation to move faster and cut administrative work.
In mortgage broking, the big groups are already wiring AI into how they operate. Lendi Group has rolled agentic tools across more than 1,300 brokers for valuations, serviceability checks and client follow-ups. In the same Australian Broker survey, 39 per cent of brokers said they treat AI as core to their work or are integrating it, and 54 per cent of brokers under 50 use it, against 27 per cent of those over 50.
Ageing Australia has made a similar case on the care side, that the sector needs to pick up modern digital tools faster to manage workloads and protect the quality of care.
What a defensible setup looks like
A defensible AI setup does not mean every business runs its own model. It means you know where your information goes, you limit what the AI can reach, and you hold evidence your safeguards are working.
The workflow layer
The workflow engine moves information between your existing systems and the AI model. A platform like n8n runs self-hosted on Australian infrastructure, so you decide which systems the workflow reaches, what gets sent to the model and where a human has to sign off.
Take a mortgage example. The workflow pulls an application status from your CRM, asks the model to draft a client update, and drops it into the broker's approval queue. The orchestration layer holds that sequence and records what happened, instead of leaving a staff member to copy documents between systems by hand.
Where the data lives
Client and resident records stay in your approved systems of record, the CRM, the document store, the care management system. Those systems, plus any databases, vector indexes, logs and backups behind them, sit in an approved Australian data centre or cloud region where you need that.
Encrypt the information, protect it with the access permissions you already run, and keep it only as long as you need it. The workflow pulls the few fields or passages a task needs, rather than shifting the whole record into the AI platform or spawning a second copy of it. This is also where the data groundwork most businesses skip starts to pay for itself.
The separation is the point. Your systems stay the authoritative record, the workflow controls movement, and the model sees only the minimum it needs to do the job.
Choosing the model
One option is an open-weight model, something like Llama, Gemma or Mistral, running inside infrastructure you control. The parameters can be downloaded and deployed privately, so prompts and documents never go to the model developer. You get more control. You also take on the security, maintenance, testing and licensing yourself.
Most businesses will instead reach for Gemini, OpenAI or Claude through an enterprise service or API. Check the contract and the settings. Confirm that prompts, files and outputs are not used to train the provider's models, and switch off any optional data sharing or feedback programs. Check retention periods, human review arrangements, subprocessors and deletion rights too. Training is off by default in many commercial API products, but confirm it and write it down rather than assume it.
Deploy the whole stack in an Australian region. The application, the workflow engine, the databases, the document and vector stores, the logs and the backups. Fix the region in your infrastructure configuration, and set access controls and network rules so information is not quietly routed through an unapproved service or an overseas region. Where the AI provider offers an Australian endpoint, use it.
There is a trade-off here, and it is worth naming. The Australian regions from the big AI providers do not always carry every model or feature their global services do, especially in the first weeks after a new frontier model ships. You then choose between the newest capability and tighter control over where your data sits. Reaching for a global endpoint should be a deliberate, risk-assessed call, not an automatic fallback.
Regional storage is not the same as regional processing. If the information has to stay in Australia at every step, get a contractual commitment covering both storage and processing, or run an open-weight model in your own Australian-hosted environment.
The Privacy Act does not force every organisation to keep all personal information inside Australia. What APP 8 does is make you accountable when information goes to an overseas recipient. So treat the service, the contract and the configuration as part of a Privacy Impact Assessment, and check them against your legal, regulatory and contractual obligations.
Data isolation starts inside your business
Even the best vendor contract cannot fix an internal system that hands AI more access than it needs. Give the system only the data the task in front of it requires, pulled from an approved source under the permissions the staff member already has.
A broking workflow drafting a client update needs the customer's name, the application status and the next action. It does not need their whole financial history. In aged care, a system preparing a care plan summary pulls a limited set of authorised notes and leaves the full record in the care management platform. Strip out or mask the sensitive details before anything is processed.
Send critical outputs through a person before they reach a client, change a resident's care or land in an official record. Have the workflow log what was retrieved, which model ran, and who approved the result. Those records are your evidence that access stayed limited, the approved process was followed, and a human stayed in the loop.
Build governance in and it pays off
Build governance into an AI workflow from the start and it lifts efficiency without costing you trust. A controlled system pulls approved information, follows the same steps every time, stops for human review and keeps a record of what it did. That makes it more useful than ad hoc use of a public chatbot, and far easier to defend.
You do not have to automate everything at once. Start with one well-scoped workflow, prove the controls, then extend. As regulators and industry bodies sharpen their focus on AI, the businesses that can show exactly how their systems handle data are the ones ready to answer questions from regulators, clients, residents and families.
Start with one workflow. If you want to work out the first client-facing workflow to move into a private, governed and compliant setup, and how to document the safeguards around it, email me at pete@autocognition.com.au.
Not sure which workflow to move into a governed setup first?
Get your free AI Assessment. We'll map where your time is actually going, which workflow is worth automating first, and what it takes to run it without sensitive data leaving your control.