This is one of the most common questions we hear from NDIS providers, and it’s usually asked quietly, by someone who’s already been doing it for a while and has started to wonder if they should be. It’s a fair question. Documentation is one of the heaviest, most repetitive parts of the job, and AI tools are genuinely good at tidying up language, summarising long notes, and taking a rough draft somewhere closer to finished. The temptation is real, and it isn’t a sign anyone’s cutting corners. It’s a sign the workload is heavy and the tools are tempting.

The honest answer is that it depends entirely on what’s going into the tool, and what happens to the output afterwards. Not all AI use in documentation carries the same risk, and treating it as a flat yes-or-no question misses the part that actually matters.

What’s actually risky

The risk isn’t the technology itself. It’s what you put into it, and what you do with what comes out. Pasting a participant’s name, behaviour support detail, incident specifics, or anything else that identifies a real person into a general-purpose consumer AI tool means that information is now being processed somewhere you likely have no data agreement with, often outside Australia, in a system that wasn’t built with the Privacy Act or the NDIS Practice Standards in mind. You lose visibility over how long it’s retained, who else’s systems it might touch, and whether it’s used to improve someone else’s product down the track.

There’s a second layer too: relying on the output without a person actually checking it. An AI-generated summary can smooth over language while quietly changing meaning, dropping a detail that mattered, or introducing something that wasn’t actually said. In progress notes and incident reports, small inaccuracies aren’t cosmetic. They can affect a participant’s plan, a funding decision, or how an incident gets understood later. From 10 December 2026, the Privacy Act’s changes to automated decision-making transparency also mean organisations need to be able to explain, clearly, where automated tools have played a role in decisions that affect a person, so “I’m not sure what the AI actually did there” stops being a workable answer.

What’s genuinely lower risk

Not every use of AI carries this weight. Drafting a generic internal email, summarising publicly available information, tidying language on something that contains no participant-identifying detail, brainstorming how to phrase a difficult conversation in the abstract, these carry a fraction of the risk, because there’s nothing sensitive in the tool to begin with. The line isn’t “AI: yes or no.” It’s “does this contain information that identifies a real participant, and is a person checking the result before it’s relied on.”

The distinction that actually matters

If you’re trying to work out where your own team sits on this, two questions do most of the work: is participant-identifying or sensitive information going into the tool, and is a human reviewing the output before it’s used or acted on. If the answer to the first is yes and the second is no, that’s the combination worth fixing first, not because anyone’s done anything wrong, but because it’s the exact gap that turns an efficiency habit into a genuine compliance exposure.

This isn’t legal advice, and if you’re navigating a specific situation, it’s worth getting your own advice on it. But as a general starting point, it’s a useful filter for a conversation your team is probably already having informally.

What this looks like day to day

In practice, most providers land somewhere sensible once they think it through properly. A support worker using AI to help phrase a difficult family update, with no participant name or identifying detail in the prompt, is a different situation to that same worker pasting an actual incident description straight into a chatbot to save time. A team lead using AI to draft a general training outline is different to using it to summarise an actual behaviour support plan. The tool is the same in both cases. The risk is not.

It also helps to think about where the output goes next. A rough draft that a person reads properly, checks against what actually happened, and edits before it’s filed is a reasonable use of the technology. An AI-generated note that goes straight from tool to file with nobody checking it is where the real exposure sits, not because the AI got it wrong necessarily, but because nobody would know if it had.

Where this fits into a bigger picture

Every AI-assisted output in our own engagements is reviewed by a person before it reaches a client, and we don’t feed client information into third-party AI systems to train their models. That’s not a special policy, it’s just what “a human stays in charge” looks like in practice, and it’s the same standard worth applying to how your own team uses AI in documentation.

If you’re not sure where your organisation actually stands, the Shadow AI Quick Check is a fast, free way to find out, including exactly this question about participant documents and AI tools.

A question worth asking your own team

If you take one thing from this, make it a single question you actually put to your team this week: what are you currently using AI for, and has anything you’ve typed into it included a participant’s name or details. Most staff will answer honestly if it’s asked as a genuine question rather than an accusation, because most of them already suspect it’s worth asking. The answer tells you more in five minutes than a written policy sitting unread in a folder ever will, and it’s usually the fastest way to find out whether this is a live issue in your organisation or a hypothetical one.

Leave a Reply

Your email address will not be published. Required fields are marked *