Accountants, financial advisers, lawyers and consultants sit on a mountain of confidential and privileged client information, and generative AI now reaches into drafting, research, advice and due diligence. Australian professional services firms carry cross-cutting privacy duties plus sector rules from ASIC, APESB, AUSTRAC and the professional bodies. This matrix maps the verified obligations that shape safe AI adoption, so client trust, privilege and licence conditions stay protected as automation spreads across the practice.
9 obligations across the professional services regulators. Map every AI system you run against each.
Firms that handle client and staff personal information are APP entities and must comply with the 13 Australian Privacy Principles: collect only what is needed, secure it, be transparent, and allow access and correction. Feeding client records, tax data or matter files into AI tools is a use and disclosure that must fit the APPs, and offshore or third-party AI processing engages the cross-border disclosure rules under APP 8.
Source: OAIC: Australian Privacy PrinciplesFrom 10 December 2026 the Privacy and Other Legislation Amendment Act 2024 requires APP entities to update privacy policies where a computer program uses personal information to make, or substantially help make, decisions that could significantly affect an individual. Firms using AI to triage clients, score risk or screen candidates must disclose the kinds of information used and the kinds of decisions made. Map every automated decision now.
Source: OAIC APP 1 guideline: automated decisionsThe Voluntary AI Safety Standard, refreshed in October 2025 as the Guidance for AI Adoption, sets six essential practices for safe and responsible AI: govern, map, measure and manage risk, keep an AI inventory, assign accountability, test, and stay transparent with people affected. It is not law, but regulators and clients increasingly treat it as the baseline of reasonable care, and it prepares firms for future mandatory guardrails.
Source: DISR: Voluntary AI Safety Standard guardrailsMembers of CPA Australia, Chartered Accountants ANZ and the Institute of Public Accountants must comply with APES 110, whose confidentiality principle in Section 114 bars disclosing client information acquired through work without proper authority. Putting client data into a public AI tool risks a breach if the provider can view, retain or train on inputs. The June 2024 technology revisions confirm the code applies squarely to AI and technology use.
Source: APESB: APES 110 Code of EthicsFrom 1 July 2026 anti-money-laundering obligations extend to designated services provided by accountants, lawyers, conveyancers and trust and company service providers. Affected firms must enrol with AUSTRAC, maintain an AML/CTF program, and conduct customer due diligence before providing a designated service. Where AI supports identity checks, customer risk scoring or transaction monitoring, the outputs must be reliable, explainable and overseen, and false negatives carry regulatory and criminal exposure.
Source: AUSTRAC: professional designated servicesSolicitors owe duties of confidentiality and competence under the Legal Profession Uniform Law and the Australian Solicitors Conduct Rules 2015, and must protect legal professional privilege. The Law Society of NSW January 2026 guide on responsible AI use warns that entering matter information into external AI tools can waive privilege or breach confidentiality, and that practitioners remain responsible for accuracy, including verifying that AI has not fabricated cases or authorities.
Source: Law Society of NSW: AI guidance for solicitorsFinancial advisers giving personal advice to retail clients must act in the best interests of the client under section 961B, provide appropriate advice, and prioritise client interests. AFS licensees must also ensure services are provided efficiently, honestly and fairly under section 912A. Where AI drafts statements of advice, scopes needs or models portfolios, the adviser stays accountable for suitability, and unchecked AI output that misstates the client position breaches these duties.
Source: ASIC: acting in the best interests of the clientRelevant providers must comply with the Financial Planners and Advisers Code of Ethics 2019 under section 921E, which demands integrity, competence and acting in each client best interest above the minimum in the law. Standard obligations require advisers to understand and be able to explain the advice they give. Reliance on opaque AI models that an adviser cannot interrogate or justify risks breaching the competence and honesty standards in the Code.
Source: ASIC: financial advisers Code of EthicsAFS licensees serving retail clients must hold adequate professional indemnity insurance, or ASIC-approved alternatives, to compensate clients for losses from breaches of their Chapter 7 obligations, as set out in RG 126. AI-driven errors in advice, calculations or client communications can trigger claims, so firms should confirm their PI policy responds to technology and AI-related failures rather than excluding them, and keep records that evidence human oversight.
Source: ASIC RG 126: compensation and PI insuranceEach obligation links to its primary or official source. Verified against OAIC, ASIC, AUSTRAC, APESB and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Build an AI inventory listing every tool touching client, financial or matter data, and classify each by confidentiality and privilege risk before wider rollout.
Block confidential, privileged or personal client information from public AI tools; route work to enterprise instances with no-training, data-residency and retention controls.
Map all automated or AI-assisted decisions affecting clients or candidates and update privacy policies ahead of the 10 December 2026 ADM transparency start.
Enrol eligible accounting and legal practices with AUSTRAC and stand up an AML/CTF program before designated services begin on 1 July 2026.
Require documented human review of AI output in advice, statements of advice, opinions and filings, and verify every AI-cited authority or figure before it reaches a client.
Adopt the six Voluntary AI Safety Standard practices and align firm policy with APES 110, the solicitor conduct rules and the advisers Code of Ethics.
Confirm professional indemnity cover responds to AI and technology-related errors, and keep audit trails that evidence oversight for licence and insurer scrutiny.
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check