Privacy
Personal information should be collected, used, disclosed and retained only with appropriate controls and notices.
AI use must be managed within existing obligations, including privacy, consumer law, discrimination, workplace safety, cyber security, copyright and employment law.
Personal information should be collected, used, disclosed and retained only with appropriate controls and notices.
Where automated decisions significantly affect people, transparency and review pathways become important.
AI should be assessed for unfair or discriminatory outcomes.
AI and automation can create new or changed work health and safety risks if oversight is weak.
AI can increase phishing, deepfake, data leakage and access-control risks.
AI-assisted communication or decisions should not mislead people or create unfair outcomes.
Generated content, training data and confidential information can raise intellectual property issues.
AI can affect tasks, monitoring, performance and job design, so consultation may be needed.
Important AI-assisted decisions should be documented so they can be reviewed.
Workplaces should connect AI governance with privacy, cyber security, procurement, workplace relations, data governance, risk management and incident response.