What does this topic cover?
This topic covers the security and privacy questions partners should settle before AI touches client work: which tools staff are using, where those tools keep data, what Australian privacy law expects, and what rules staff should follow. The guides are written for managing partners and practice managers, not security specialists, and they focus on decisions a firm can make itself.
What is shadow AI, and why start there?
Shadow AI is staff using AI tools the firm has not approved or configured, often personal accounts on free plans. It is the right place to start because a firm cannot secure tools it does not know about. Shadow AI in professional firms explains how to find out what is in use and move people onto approved tools.
Where does our data go when staff use AI?
It depends on the tool, the plan and the settings, not just the brand. Consumer and business plans of the same product can differ on how long data is kept, what administrators can see and whether inputs can be used to train models, and processing locations vary by vendor and plan. Where does ChatGPT store your data? sets out the position as at September 2026 and the alternatives for firms that need more control.
What do the Australian Privacy Principles mean for AI use?
The Australian Privacy Principles set how organisations covered by the Privacy Act 1988 collect, use, disclose and protect personal information. The OAIC’s guidance on commercially available AI products says privacy obligations apply to any personal information entered into an AI system, and to AI output that contains personal information. AI and the Australian Privacy Principles translates the principles that matter most for AI into plain English, with examples from professional firms.
What should an AI acceptable-use policy cover?
An AI acceptable-use policy should say which tools are approved, what information must never go into them, who reviews AI output before it reaches a client, and how staff report a mistake. Keep it short enough that people read it. AI acceptable-use policy: what it must cover walks through each clause and links to our free template.
How does Pylon Digital handle client data?
Our security and data residency page explains how client data in the systems we build and run is stored, who has access, and how the AI providers we use handle your data. For work that cannot go into public tools, Private AI and knowledge assistants store client data in fully GDPR-compliant data centres, and your firm chooses which matter and client documents they can search.
This is general information, not legal advice.