Could an AI disclosure be a notifiable data breach?
The obligation is to assess suspected breaches within 30 days. That is very difficult when the disclosure happened on a personal phone and left no trace.
Published 26 July 2026
The Notifiable Data Breaches scheme requires organisations covered by the Privacy Act to notify the OAIC and affected individuals when an eligible data breach occurs — broadly, unauthorised access to or disclosure of personal information that is likely to result in serious harm.
Whether an AI disclosure triggers it depends on the facts. What follows is how the analysis runs, and where it tends to break down.
Is it a breach at all?
An eligible data breach generally requires unauthorised access to, unauthorised disclosure of, or loss of personal information, and a likelihood of serious harm to any affected individual.
The word doing the work is unauthorised.
If your firm has a properly assessed enterprise AI arrangement, staff use it within policy, and the disclosure falls within the purposes you have documented — that is authorised. It may raise APP 8 questions, but it is not obviously a breach.
If a staff member pastes client information into a consumer chatbot on a personal account, contrary to policy or in the absence of any policy, that is much harder to characterise as authorised. The organisation did not sanction it, did not assess the recipient, and has no agreement with them.
This is the uncomfortable conclusion many firms arrive at: the informal usage they have the least visibility of is the usage most likely to constitute a breach.
Is serious harm likely?
The second limb, and it is genuinely fact-dependent. Relevant considerations include the kind of information, its sensitivity, whether it was protected, who could obtain it, and the nature of the harm that could follow.
Some rough guides:
More likely to reach the threshold: health information, financial details, information about vulnerable people, material that could enable identity theft, information whose exposure carries reputational or safety consequences, and anything about family law, criminal or child protection matters.
Less likely, though not automatically excluded: business contact details already in the public domain, information about a company rather than an individual, genuinely de-identified data.
Where people go wrong: assuming that because the AI provider is reputable, harm is unlikely. The test is not whether you trust the recipient. It concerns the nature of the information and the potential consequences of it being outside your control. A well-run recipient reduces some risks and eliminates none of the analysis.
The 30-day problem
Where you suspect an eligible data breach may have occurred, you must carry out a reasonable and expeditious assessment, and the scheme contemplates that being completed within 30 days.
Here is where AI disclosures become genuinely difficult.
To assess the breach, you need to establish what personal information was disclosed, whose information it was, when, and to whom. For a lost laptop or a misdirected email, this is usually knowable. For an AI disclosure it frequently is not.
If a staff member used a personal account on a personal device:
- There is no network log, because the traffic never crossed your network.
- There is no record on your systems at all.
- The conversation history sits in an account you do not control and cannot compel access to.
- You are relying entirely on the individual’s recollection of what they pasted, possibly weeks earlier.
- If they have deleted the conversation — perhaps upon realising it was a problem — even that is gone.
You are required to assess a breach whose scope you cannot determine. There is no satisfactory way to do this, and “we could not establish what was disclosed” is not an outcome that reflects well on the organisation.
What notification would involve
If you conclude an eligible data breach occurred, you must prepare a statement for the OAIC and notify affected individuals — describing the breach, the information involved, and what those individuals should do in response.
Consider what that notification says in practice: a member of our staff disclosed your confidential information to an overseas AI service. We are unable to confirm precisely which information was disclosed or what has become of it.
For a professional services firm, the client relationship consequences of sending that letter substantially exceed the regulatory ones.
The reasonable steps question underneath
Beyond the specific breach, a regulator considering the matter will look at APP 11 — whether the organisation took reasonable steps to protect the information.
The likely questions:
- Did you have an AI policy?
- Did you provide a sanctioned alternative, or only a prohibition?
- Did you train staff on it?
- Did you have any technical controls, or only the policy?
- Did you know this usage was occurring?
- If you did not know, what steps had you taken that would have told you?
A policy alone is a partial answer at best. “We told them not to” is a weaker position when the organisation provided no compliant way to do the work and had no means of detecting non-compliance.
Reducing the exposure
Provide a sanctioned tool. If staff have an approved AI service that is genuinely easy to use, most usage moves onto it, and that usage is authorised, logged and assessable. This is the highest-value single change available to most firms.
Log what you can. Where AI use runs through firm systems, you have records. Records make assessment possible. Assessment makes notification decisions defensible.
Ask, without consequences attached. A one-off amnesty conversation about what staff have actually been doing is uncomfortable and considerably better than discovering it during an assessment. You cannot manage an exposure you have not measured.
Or remove the disclosure entirely. Where the AI runs on hardware inside your office, there is no disclosure to any third party, so there is no unauthorised disclosure, so there is no eligible data breach arising from AI use. Staff can use it on the most sensitive material you hold, because the information never leaves.
That last option is a capital commitment and it is not proportionate for every organisation. But it is worth understanding what it actually changes: it does not improve your ability to assess an AI-related breach. It removes the category.
The test question
Ask whoever is responsible for privacy in your organisation:
If we learned tomorrow that a staff member had pasted a client file into a chatbot three weeks ago — could we complete a defensible assessment within 30 days?
If the answer is no, that is not a hypothetical gap. It is the position you are in right now, and it stays that way until something structural changes.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.