AI Aged Care

Even the Regulator is Using AI - Is Your Aged Care Organisation Ready?

Gina Tresidder, Andrew Rigoni

The aged care sector has spent the past months adapting to the regulatory framework established by the Aged Care Act 2024 (Cth) and Aged Care Rules 2025 (Cth). As providers move beyond implementation and transition planning, attention is increasingly turning to operational compliance and accountability. Providers need to be honest with themselves: are privacy practices and AI governance actually embedded in day-to-day operations, or do they only exist on paper?

Meanwhile, AI use across the sector keeps growing, with providers exploring AI tools for administration, documentation, workforce management, assessments and care delivery.

What is significant is that the regulator itself is no longer treating AI as a future problem. The Aged Care Quality and Safety Commission has published an AI Transparency Statement confirming that it uses AI across a number of its own functions and has put governance arrangements in place to manage that use responsibly. If the regulator thinks this warrants a formal governance framework, providers should be asking whether their own arrangements would hold up under the same scrutiny.

Put simply: if the regulator has an AI governance framework, does your organisation? The new framework may not name AI, but that does not put it beyond the regulatory landscape. AI use still has to comply with the rights-based obligations underpinning the aged care system.

Privacy is a Key Regulatory Framework for AI

The Aged Care Act 2024 (Cth) adopts a rights-based framework that places older people at the centre of the aged care system, and privacy is a clear example of that shift. Section 23 establishes a Statement of Rights, including the right to have personal privacy respected and personal information protected. Section 168 imposes specific obligations on registered providers to protect personal information, use it only for authorised purposes, disclose it only in limited circumstances, and implement reasonable safeguards against misuse, loss or unauthorised access. The strengthened Aged Care Quality Standards reinforce the importance of privacy, information management and governance as part of delivering safe, high-quality care.

These obligations do not pause when the tool doing the collecting, storing or analysing is AI-powered. If anything, they intensify: AI systems often process larger volumes of personal and health information, in less transparent ways, than the manual processes providers are used to governing. Privacy and information governance are not a separate compliance stream from AI governance - they are the starting point for it.

The privacy landscape is also shifting at the Commonwealth level. The Privacy Act 1988 (Cth) still applies, but the Attorney-General’s Department has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 for consultation. The reforms are intended to modernise and strengthen Australia’s privacy framework and have significant implications for organisations using emerging technologies, including AI. At the same time, from 10 December 2026, new automated decision-making transparency obligations under the Privacy and Other Legislation Amendment Act 2024 (Cth) will require APP entities to disclose in their privacy policies how they use personal information in automated or AI-enabled decision-making that could significantly affect individuals’ rights or interests. For aged care providers using AI tools that inform care assessments, workforce decisions or service eligibility, these obligations are directly relevant.

The Regulator is Already Thinking About AI Governance

The Commission's AI Transparency Statement is a useful signal of where things are heading. It states publicly that it uses AI in areas including regulatory intelligence, compliance functions and workplace productivity, and stresses the need for governance, accountable officials, transparency, human oversight and responsible use.

The Commission's framework applies to itself as regulator, not to providers, but it shows AI governance is no longer a theoretical discussion. The question for the sector has moved on from whether organisations should use AI, to whether they can actually demonstrate it is being used safely, responsibly and consistently with their legal and ethical obligations. For providers, that means AI governance can no longer sit in the “future project” pile. You should be able to say what AI tools your organisation is using, what personal information is involved, what the risks are, and who is accountable for overseeing it.

AI is the Next Governance Challenge

Many providers are already using AI-enabled tools without necessarily recognising them as AI, including:
  • meeting transcription and documentation tools;
  • workforce scheduling and rostering systems;
  • automated communication platforms;
  • decision-support tools;
  • predictive analytics; and
  • generative AI products used by staff for drafting and administrative tasks.

The new aged care framework does not expressly regulate these technologies, but that silence is not a green light. The Statement of Rights, the Code of Conduct and the Aged Care Quality Standards apply regardless of whether care is delivered or supported by traditional processes or AI-enabled systems, so the real question is not whether AI is regulated but whether its use is consistent with a provider's existing obligations.

What Does Compliant AI Use Look Like?

As AI adoption grows across the sector, providers should make sure their use of it aligns with the principles underpinning the aged care framework. In practice, that means keeping the following in mind.

Human accountability must remain. Providers should exercise caution before relying on AI to make decisions affecting care recipients without meaningful human oversight. In most circumstances, decisions affecting care recipients should remain subject to review and accountability by appropriately qualified personnel. AI can assist staff by surfacing information, generating recommendations or supporting assessments, but it should not replace the judgment and responsibility of the people delivering care.

Privacy and confidentiality must be protected. Many AI systems rely on large volumes of personal, sensitive and health information. Providers should make sure information entered into AI systems is handled consistently with their privacy obligations and organisational policies, and take particular care where personal information may be processed by third-party vendors or cloud-based AI platforms.

Dignity and autonomy must be preserved. The aged care framework is built on respect for dignity, individuality and choice, so AI should be deployed in a way that enhances, rather than diminishes, older people's autonomy and their ability to participate in decisions affecting their own care.

Human relationships should not be replaced. One of the defining features of quality aged care is the relationship between care recipients, families and carers, and AI should support those relationships rather than substitute for them.

Governance should be proportionate and ongoing. Providers should have clear governance arrangements for assessing, approving, monitoring and reviewing AI tools, including understanding what systems are in use, what information they process, what risks they create and who is responsible for overseeing them.

Moving From Policy to Practice

As the sector moves beyond implementation into a period of closer compliance scrutiny, providers should take stock of whether their privacy and AI governance arrangements are actually fit for purpose. Ask yourself:

  • Is there a clear AI use policy governing staff use of AI tools?
  • Have AI tools been subject to appropriate risk assessment and governance review?
  • Are staff adequately trained on privacy, information security and AI use?
  • Does the organisation maintain an AI register documenting what AI tools are in use, what personal information they process and who is accountable for each?
  • Have privacy impact assessments or AI impact assessments been conducted for higher-risk AI uses?
  • Have vendor contracts been reviewed to ensure they address data handling, security and compliance obligations?
  • Has the organisation mapped its automated decision-making processes in preparation for the transparency obligations commencing in December 2026?

For many providers, the real test is whether their current privacy and AI policies actually reflect the new framework, or whether they are overdue for an update. A clear, well-drafted policy is the foundation for closing the gap between what is meant to happen and what actually happens on the ground.

How Can We Help?

Russell Kennedy regularly advises aged care providers, retirement living operators and peak bodies on privacy, information governance, cybersecurity and AI governance. Our Privacy Policy and AI Use Policy templates for Commonwealth-funded aged care providers are available through RKDocsConnect, developed specifically to align with the new aged care framework and emerging AI governance expectations. These templates will be updated to reflect any changes arising from reforms to the Privacy Act, including the proposed Privacy Amendment (Personal Data Protection) Bill 2026, so providers can be confident their policies keep pace with the evolving legislative landscape.

We can also assist providers to review existing policies, assess AI deployments, develop governance frameworks and prepare for increasing regulatory scrutiny in this area.

If you’d like to stay up to date with Russell Kennedy Alerts and Events, you can subscribe to our mailing list here.

View related insights

Data Protection 3 Thumbnail

Privacy Reform Tranche 2 Arrives: Major Changes Proposed, Key Reforms Still Missing

2 Sep 2026

The Attorney-General's Department has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026: a significant step forward, but key proposals from the Privacy Act Revi ...

View
airport

Qantas passes the OAIC’s preliminary data breach test: what helped and what organisations should be doing now

30 Jul 2026

Despite a data breach affecting approximately 5.12 million Australians, the OAIC declined to open a formal investigation into Qantas, finding no evidence the airline failed to take reasonable steps to ...

View
Online subscription on phone

The New Rules for Online Sales: Unfair Trading, Subscription Renewals and Hidden Fees

12 Jun 2026

On 9 February 2026, Treasury released the Exposure Draft of the Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026 (Exposure Draft), proposing targeted amendments to the Australia ...

View