What an AI use policy must cover

Twelve clauses, what each one settles, and wording a practice can lift into its own document.

Written by the aurii team

An AI use policy settles which tools are on the register, who approves a new one, what may never go into a general purpose tool, who reviews and signs clinical output, and what happens when something goes wrong.

Two practice staff at a desk in a bright Australian consulting room, one turning a laptop screen towards the other, afternoon light through a window, printed pages spread on the desk between them

The clause table

The right-hand column is drafted to be lifted into a practice document, with the bracketed placeholders filled in.

  • AI use policy clauses, what each settles, and wording to lift
    ClauseWhat it settlesWording to lift
    ScopeWhich tools and which people the document covers.This policy applies to any software using artificial intelligence used in practice work, on any device, including free trials and personal subscriptions. It binds employees, contracted practitioners, registrars, locums, students and agency staff.
    RegisterThe list of approved tools and what is recorded against each.[Name] keeps a register of approved AI tools recording the tool and plan in use, who uses it and for what, whether patient information goes into it, where data is stored and processed, whether inputs train the vendor's models, retention and deletion periods, and the approval and next review dates.
    ApprovalThat a tool is assessed before it sees patient information, trials included.No AI tool is used with patient information until it is approved and entered on the register. A free trial counts as use. [Name] records the approval before first use, with the vendor's breach notification commitment and what happens to practice data when the practice stops using the product.
    Permitted and prohibited useThe tool staff use for each task, and the one prohibition.Patient information is not entered into general purpose chatbots or consumer AI tools, including de-identified cases and letters with the name removed. The approved tool for each documentation task is named on the register, and any use not listed goes to [name] before it starts.
    Consent to recordHow consent is taken and where it is recorded.Recording is explained to the patient and consent is obtained before recording starts, and the consent is recorded in the clinical record. A patient who declines is consulted without recording. State and territory listening device legislation applies.
    Review and signThe standard the signing clinician is held to.The clinician who signs AI-drafted content is its author, reads it in full, and checks it against their own recollection of the encounter before signing. A draft the clinician can no longer verify from memory is rewritten before it is signed.
    Accountable personWho owns the register, the approvals, the incidents and the review.[Name], [role], owns this policy, the register, approval decisions and the incident log, with [name] as delegate during leave. Clinical responsibility for a signed record stays with the treating practitioner.
    Patient transparencyWhat the practice publishes, and when it is updated.The practice privacy policy states that AI tools are used in producing clinical records and correspondence, where that information is stored and processed, whether any of it leaves Australia, how long audio and drafts are kept, and how a patient declines. It is updated whenever a tool joins the register.
    Non-employee practitionersWhether the policy reaches doctors under service agreements.Service and facility agreements take up practice policies as varied from time to time. The approval gate applies to any tool used against practice records. [The practice entity / each practitioner] holds the health information for Privacy Act purposes.
    IncidentsWhat is reported, to whom, and inside what time.Reportable events go to [name] in writing on the day they are found. Where there are reasonable grounds to suspect an eligible data breach, the assessment is completed within 30 days and, where the threshold is met, a statement goes to the OAIC and the affected individuals are notified as soon as practicable. A My Health Record breach is also notified to the Australian Digital Health Agency as System Operator.
    Correcting a recordHow an affected clinical record is fixed.An affected record is corrected by dated addendum that leaves the original visible, after the practice's medical defence organisation has been contacted.
    Acknowledgement and reviewThe evidence staff have read it, and when it is reopened.Each staff member signs an acknowledgement on induction and on each revision. The policy is reviewed on [date], and earlier when a tool is approved, a vendor changes its terms, sub-processors or processing location, a regulator publishes guidance, an incident occurs, or the clinical software changes.

Undeclared tools

A register built from the procurement list misses the browser extension summarising specialist letters, the consumer chatbot rewriting recall messages, and the meeting assistant inside the video conferencing account.

Run the first pass as a disclosure round in a staff meeting, principals naming their own tools first, with no consequence attached. A technical sweep finds the rest:

  • Browser extensions on shared consulting room machines.
  • Applications installed on practice devices.
  • Third-party connections and API tokens authorised inside the clinical software.
  • Add-ins on the practice mailbox and the video conferencing account.
  • Personal subscriptions appearing on expense claims.

The incident log

These go on the incident log whether or not a notification threshold is reached:

  • A drafted note attached to the wrong patient, whether or not it was signed.
  • Patient information entered into a tool that is not on the register.
  • Signed content describing something that did not happen in the consultation.
  • A recording that continued after the consultation ended.
  • A patient asking which tool was used and nobody being able to answer.

Acknowledgement records

Acknowledgement records, a dated attendance record for the session that introduced the policy, and coverage in the induction pack are what a practice hands over when asked how staff know the rules. Training the team.

aurii on the register

aurii records the consultation and drafts a structured note or letter for the treating clinician to edit and sign. The register fields:

  • Register fields, answered for aurii
    Register fieldEntry
    Tool and planA$199 + GST per clinician per month. Full pricing.
    Who signsNothing leaves aurii until a clinician signs it. Clinical safety.
    Where data is storedHosting and backups are in Australian regions. Where the data sits.
    Model trainingYour content is not used to train models.
    Retention and deletionDeletion runs on request. What is deleted and what the practice keeps.
    Evidence the review step happenedEvery action a practice user takes is written to a hash-chained audit log. How the chain works.

No Australian law names one as a mandatory practice document. Australian Privacy Principle 1 requires reasonable steps to implement practices, procedures and systems that will ensure compliance with the Australian Privacy Principles, and accreditation surveyors ask how staff know the rules.

No, and the clause is written without qualifiers, including for de-identified cases and letters with the name removed. A consumer tool carries no contract with the practice. A presentation, an age, a suburb and a referring specialist together identify a patient.

Only where their engagement picks it up. Doctors under service or facility agreements are bound where the agreement refers to practice policies as varied from time to time, and the approval gate has to reach any tool used against practice records.

This is general information about practice governance and privacy obligations in Australia. It is not clinical or legal advice.

Start the free trial

Free 30-day trial. Create an account in the iPhone app or at app.aurii.com.au/signup. A card is added at signup on Stripe's checkout page; nothing is charged until the 30 days end.

hello@aurii.com.au