Can I use ChatGPT or Claude with confidential client data?
Yes, with limits, as at October 2026: use ChatGPT Business or Enterprise, Claude Team or Enterprise, or the API, which are not used for model training by default, and keep sensitive details such as health information out of consumer AI tools, as the OAIC recommends. Free and personal plans can train on your chats depending on a setting. On Autopilot, a Melbourne-based AI consultancy, builds Claude agents that only see the data they need, from $497.
Can I put confidential client information into ChatGPT or Claude?
Only on a business plan, and only the information the task needs. As at October 2026, ChatGPT Business, ChatGPT Enterprise, Claude Team, Claude Enterprise and both companies’ APIs are not used to train models by default. Free and personal plans can be, depending on a setting. Even on the right plan, the OAIC recommends as best practice keeping personal information, particularly sensitive information, out of publicly available generative AI tools, so de-identify first.
Plan by plan, as at October 2026:
| Plan | Used to train models by default? | OK for client information? |
|---|---|---|
| ChatGPT Free, Go, Plus, Pro | Yes, unless you switch off “Improve the model for everyone” in Data Controls | De-identified text only |
| Claude Free, Pro, Max | Your choice in privacy settings. If you allow it, chats are kept up to five years (30 days if you don’t) | De-identified text only |
| ChatGPT Business, ChatGPT Enterprise, OpenAI API | No | Yes, minimised and covered by your privacy policy |
| Claude Team, Claude Enterprise, Claude API | No, unless you send feedback or opt in | Yes, minimised and covered by your privacy policy |
One catch: on Claude’s business plans, the thumbs up or down button sends that chat to Anthropic as feedback it may train on, so don’t rate chats containing client data. AUD prices for each plan are on our pages for what ChatGPT costs in Australia and what Claude costs per month.
How do the rules change for a sole trader, a 2–10 person team and a 10–50 person business?
The bigger the team, the more you need central control. A sole trader can manage with careful habits. A team of 2–10 needs everyone on one business workspace. A business of 10–50 is more likely to be covered by the Privacy Act outright, because the small business exemption stops at $3 million turnover, and needs a written AI policy.
- Sole trader. ChatGPT Business and Claude Team both need at least two seats, so either pay for two, or use a personal plan with training switched off and paste only de-identified text.
- 2–10 staff. Everyone who touches client data works in one workspace the business controls. No personal AI accounts for client work.
- 10–50 staff. Write a one-page AI use policy, update your privacy policy, give access by role, and check whether the December 2026 automated decision rule (below) applies.
What does On Autopilot charge to set up AI that handles client data safely?
Start with the free 30-minute AI audit, where Jenn Yang, our founder, maps what client data an AI system would touch and what it must never see. On Autopilot is a Melbourne-based AI consultancy. Builds start from $497 for a Quick Start automation, an AI Front Desk for after-hours enquiries and bookings is $1,500 to set up plus $199 a month, and managed AI starts from $1,500 a month. Prices are AUD, ex GST, month to month.
How we keep agents on a short leash:
- Claude through Anthropic’s API, under commercial terms that exclude training by default.
- Access you can revoke. Connections to your own systems, such as Xero or Cliniko, are granted from your accounts, so you can revoke them at any time. While we run an agent it uses our hosting and our Claude API account; if you stop, we move it to hosting and an Anthropic account in your name. You own the code, prompts and settings from day one.
- Scoped access per agent: read-only unless writing is the job, and only the fields the task needs.
- Sensitive work goes to a person. Anything clinical, legal or financial is handed to your staff.
- Residency checked first. If a contract says data must stay in Australia, we check hosting options before we build.
See the AI Front Desk, managed AI or book a free AI audit.
What does the Privacy Act say about using AI with client data?
If your business is covered by the Privacy Act 1988, the OAIC says the 13 Australian Privacy Principles apply to any AI use involving personal information. Most businesses with annual turnover of $3 million or less are exempt. Health service providers, businesses that trade in personal information, Commonwealth contractors, credit reporting bodies and a few others are covered at any size, and small businesses can opt in.
The OAIC’s October 2024 guidance on commercially available AI products also asks you to update your privacy policy to explain your AI use, make public-facing AI such as a website chatbot clearly identifiable as AI, and check a product’s testing, human oversight, security and data access before you choose it.
A new rule starts on 10 December 2026. Under the Privacy and Other Legislation Amendment Act 2024, covered businesses that arrange for a computer program to make or inform decisions that significantly affect people’s rights or interests must say so in their privacy policy, including the kinds of personal information used and decisions made. The OAIC published a fact sheet on 30 September 2026.
What are the practical rules for using AI with client data?
Six habits cover most of the risk at any size, need no new software and line up with the OAIC’s best-practice advice: the right plan, sensitive details kept out, identifiers stripped, access scoped by role, clients told, and one person responsible for the settings.
- Business plan or API for client work. Consumer plans are for your own drafting and research.
- Keep sensitive details out of consumer tools: health information, tax file numbers, Medicare numbers, bank details, criminal history, and anything privileged or under an NDA.
- De-identify before you paste. Swap names, addresses, ABNs and account numbers for placeholders (“Client A”), do the work, then put the real details back.
- Scope access by role. A booking agent needs a name and a time, not clinical notes or card details.
- Tell people. Cover AI in your privacy policy and engagement letters, and label any chatbot as AI.
- Own the settings. Training toggles, retention and connected apps change, so have one person review them each quarter.
For a longer walkthrough, read our guide to what’s actually safe with AI and business data.
What about health, legal and financial advice businesses?
Regulated professions carry rules on top of the Privacy Act, and they point the same way: you stay accountable for anything AI touches, and confidential client material stays out of public AI tools. AI can handle the routine layer, such as bookings, reminders and enquiry triage. Clinical, legal and financial judgement stays with a qualified person.
- Health. Ahpra says practitioners stay accountable, should know whether patient data trains a tool, and need informed consent when a tool requires patient data, which generally includes generative AI scribes. AI-written ads still follow Ahpra’s advertising rules, including no testimonials about clinical aspects of care.
- Legal. In December 2024 the Law Society of NSW, the Legal Practice Board of WA and the Victorian Legal Services Board and Commissioner jointly said lawyers cannot safely put confidential, sensitive or privileged client information into public AI chatbots.
- Financial services. ASIC’s October 2024 review of 23 licensees (REP 798) found AI adoption running ahead of governance. Existing licensee obligations apply to AI.
- Tax and bookkeeping. See whether AI can do your BAS or tax return for where AI stops and a registered agent starts.
Sources
- OAIC, Guidance on privacy and the use of commercially available AI products (published October 2024; checked 03/10/2026)
- OAIC, Small business (checked 03/10/2026)
- OAIC, New resources on transparency for use of AI and automated decision-making (30/09/2026; checked 03/10/2026)
- Anthropic, Updates to our consumer terms (28/08/2025; checked 03/10/2026)
- Anthropic Privacy Center, Is my data used for model training? (checked 03/10/2026)
- OpenAI, How your data is used to improve model performance (checked 03/10/2026)
- Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare (checked 03/10/2026)
- Victorian Legal Services Board and Commissioner, Statement on the use of artificial intelligence in Australian legal practice (06/12/2024; checked 03/10/2026)
- ASIC, REP 798 Beware the gap: Governance arrangements in the face of AI innovation (29/10/2024; checked 03/10/2026)
Other questions people ask
Is ChatGPT Plus private enough for client work?
Not for identifiable client information. Plus is a personal plan, and your chats can be used to improve OpenAI's models unless you switch off Improve the model for everyone under Settings, Data Controls. Use ChatGPT Business (two-user minimum) or the API for client records, or strip names and identifiers before you paste anything into Plus.
Does the Privacy Act apply to my small business?
Probably not if your annual turnover is $3 million or less, but the exceptions are big. Health service providers, businesses that trade in personal information, Commonwealth contractors, credit reporting bodies and businesses that opt in are covered at any size. Client contracts and professional rules often demand the same care anyway, so handle client data as if the Act applies.
Do I need client consent before using AI on their information?
It depends on your profession and what you have told clients. Ahpra expects health practitioners to get informed consent when an AI tool needs patient data, such as an AI scribe. For other businesses, the OAIC's baseline is transparency: say in your privacy policy and engagement terms how you use AI, and keep sensitive information out of public tools.
What changes on 10 December 2026?
Businesses covered by the Privacy Act must explain in their privacy policy when a computer program makes or informs decisions that could significantly affect someone's rights or interests, including the kinds of personal information used and the kinds of decisions. If AI will screen applicants or assess customers in your business, read the OAIC's new fact sheet before that date.
Can my staff use their own ChatGPT or Claude accounts for work?
Not for client work. You can't see or control the training and retention settings on a personal account, and the chat history leaves with the employee. Put anyone who handles client data on a workspace the business owns, such as ChatGPT Business or Claude Team, and write that rule into a one-page AI use policy.
Want this built for your business?
Book a free 30-minute AI audit call with Jenn Yang. We map where your time goes, name the first systems worth building and give you fixed AUD prices. No obligation.
Book a free AI auditOr have us run it for you, end to end: On Autopilot is Australia's outsourced AI department.