Start with business administration, not participant decisions
The safest first AI projects are usually repetitive business tasks with clear rules, reversible actions and a person who can review the result. Think of AI as an assistant that prepares work—not an authority that decides what should happen to a participant.
The NDIS Quality and Safeguards Commission highlights privacy, overseas processing, accuracy, bias and reduced human oversight as important risks when AI is used in behaviour support. That position statement is specific to behaviour support plans, but its risk themes are a useful warning for any provider considering higher-impact AI use.
Good early candidates
- Classifying general business emails and routing them to the right team queue.
- Preparing a draft response from an approved template for a staff member to check.
- Summarising internal operational meetings that contain no participant or health information.
- Checking whether required fields are present in an administrative form without deciding whether the underlying record is correct.
- Creating draft checklists, standard operating procedures and training material from approved business documents.
- Reconciling non-sensitive operational lists and flagging exceptions for a person to investigate.
Keep high-impact work out of the first pilot
Do not begin with workflows where a wrong output could affect safety, rights, access to supports, clinical care, restrictive practices or a regulatory submission. Those uses need deeper governance, specialist advice, reliable source systems and explicit human accountability.
- No autonomous participant, clinical, safeguarding or behaviour-support decisions.
- No unsupervised changes to rosters, claims, payroll, medication or incident records.
- No sensitive information in a tool until the organisation has assessed the vendor, contracts, access controls, retention and processing locations.
- No automatic external message or system update until the pilot has proven accuracy and an approval step exists.
A simple safety test
If any answer is no, narrow the task or pause it. A small, observable workflow that saves ten minutes every day is a better starting point than an impressive agent nobody can safely supervise.
- Data: Can the task run on general business data or de-identified examples?
- Impact: If the output is wrong, can a person easily notice and reverse it?
- Control: Is a named staff member responsible for checking and approving the action?
- Evidence: Can the organisation see what the agent used, produced and changed?
- Fallback: Can staff complete the task normally if the AI is unavailable?
The practical takeaway
Choose one low-risk bottleneck, define what the AI may and may not do, test it with non-sensitive examples, and keep human approval at the decision point. Responsible implementation is less about buying a chatbot and more about designing the surrounding workflow.
Sources
Primary sources reviewed for this guide:
- NDIS Quality and Safeguards Commission — Position statement on the use of AI in behaviour support plans
- OAIC — Australian Privacy Principles
- Australian Signals Directorate — Essential Eight
Information note: This guide is general information, not legal, privacy, clinical or regulatory advice. Requirements depend on the organisation, data, workflow and provider contracts.
