On paid business and API plans, the major AI providers do not train on your data by default. Consumer plans are a different story. Most processing happens outside Australia, which makes it a cross-border disclosure under Australian Privacy Principle 8, and that means you stay accountable for what happens to that information after it leaves. You do not need to stop using AI. You need to know which plan you are on, what you are sending, and to have written it down.
That is the answer. Below is the detail, because this is the question that stalls more AI projects in Australian businesses than cost, capability or appetite combined, and it usually stalls them on a vibe rather than a fact.
The confusion is real and it is not your fault
Almost everything written about AI and privacy is American, and it talks about regulations that do not apply here. Meanwhile the vendor pages that do answer the question are split across four different documents, and the answer genuinely differs depending on which plan somebody in your business signed up to on a Tuesday afternoon with a company card.
So a well-meaning ops lead asks "is this safe" and gets three contradictory answers. The project stops. Nobody is wrong, everybody is guessing.
Who trains on your data
The single most important distinction: consumer plan or business plan. It matters more than which vendor you picked.
| Plan type | Typical position on training | What to check |
|---|---|---|
| Free and personal plans | Often used to improve models unless you opt out | The setting is usually buried. Assume it is on until you have looked. |
| Team, business and enterprise plans | Generally excluded from training by default | Get it in the contract, not from a marketing page. |
| Direct API access | Generally excluded from training by default | Check retention periods separately. Not training is not the same as not stored. |
Verify it at the source rather than taking ours or anyone's word: Anthropic on whether your data is used for training, and OpenAI on how your API data is handled. These pages change. Re-read them at contract renewal.
The practical risk in most businesses is not the vendor. It is that half the team is using a personal account for work because it was faster than asking. That is where customer data actually leaks, and no amount of enterprise contract fixes it. Which is a policy problem, and we wrote about that separately.
Where the processing happens
Mostly not in Australia. Some providers offer regional processing on higher tiers, and availability changes often enough that any specific claim here would be out of date by the time you read it. Ask the vendor for their current position in writing and put the answer in your own records.
What matters is what that triggers. Under APP 8, when you disclose personal information to an overseas recipient, you have to take reasonable steps to ensure they will not breach the Australian Privacy Principles, and in most cases you remain accountable for what they do with it. The OAIC's guidance on cross-border disclosure is the authority, and it is more readable than you would expect.
Read plainly: sending a customer's details to an overseas AI provider is not automatically a problem, and it is not automatically fine. It is a disclosure with obligations attached, and pretending it is neither is the actual risk.
What the OAIC has actually said
In October 2024 the OAIC published guidance on privacy and commercially available AI products. Three things in it are worth your attention.
Be transparent. If you use AI on personal information, your privacy policy should say so. Most do not, and updating it is an afternoon.
Take extra care with sensitive information. Health, biometrics, and similar categories carry a higher bar. Do not put them into a general purpose assistant without advice.
Accuracy is your obligation. If an AI output about a person is wrong and you act on it, that is your problem. "The model said so" is not a defence anyone will accept.
Four questions to ask any vendor before you sign
- Is our data used to train or improve your models, on our specific plan? Not on any plan. Ours.
- How long do you retain inputs and outputs, and can we shorten it? Retention for abuse monitoring is normal. Indefinite retention is not.
- Where is it processed, and who are your sub-processors? A vendor who cannot produce a sub-processor list is a vendor who has not thought about this.
- What happens on termination? Deleted when, verified how.
Get the answers in the contract. A support article is not a commitment and can be edited without telling you.
What we do on client builds
Four rules, and they cover most of the exposure without slowing anything down.
Send the minimum. The most common thing we find is a prompt shipping an entire contact record when the task needed a job title and a company name. Cheaper, faster and less exposed all at once. There is rarely a trade-off here.
Strip what you do not need. If the job is "summarise this call", it does not need the customer's phone number or address. Remove identifiers before the call, not after.
Business plans only, no exceptions. Nobody uses a personal account for client data. This is a policy line, and it needs to be one because the alternative is invisible.
Write down what goes where. One page: which system, which data, which vendor, which country, which plan. It takes an hour and it is the document that turns a nervous conversation into a short one. It is also the first thing anyone asks for if something does go wrong.
If something does go wrong
Australia has a mandatory notifiable data breaches scheme. If a breach is likely to result in serious harm you must notify the OAIC and affected individuals. That applies to data disclosed to a vendor as well as data on your own servers, which is exactly why the one page above matters. Working out what you sent, to whom, while the clock is running, is not a position anyone wants to be in.
The short version for the person blocking your project
You are not being asked to trust a black box. You are being asked to do what you already do with every other overseas processor you use, and you already use several. Pick business plans, send less, write down what goes where, update the privacy policy.
That is a week of work, not a strategy review. Most of the businesses stuck on this have been stuck for months on something that would take an afternoon to resolve properly.
This article is general information, not legal advice. If you handle health data, financial data, or work in a regulated sector, get advice specific to your situation. That is not a. disclaimer to be polite. Those sectors genuinely have different answers.
Is a privacy question holding up your AI project?
It is usually the thing standing between a stalled project and a live one.
We are Neighbourhood. We build the AI and the revenue system it runs on. AI and RevOps engineering for Australian teams. Diamond HubSpot Partner, 17 HubSpot Impact Awards.
Give us a shout and tell us what's broken.