AI Governance for Australian Healthcare Providers: What You Actually Need
9 September 2026 | David and Goliath
Quick answer
An Australian healthcare provider needs four things: a named human accountable for each AI tool, a check on whether the tool is a regulated medical device, a data path that satisfies cross-border disclosure rules, and a privacy policy that discloses automated decision-making. Ahpra holds the practitioner responsible regardless of what the software did.
- Ahpra holds the registered practitioner ultimately responsible for any AI used in their practice
- A scribe that only transcribes is not a medical device; one that interprets must be in the ARTG
- Health information is sensitive information under the Privacy Act and carries the highest protection
- Privacy policies must disclose significant automated decision-making by December 2026
Mentioned: Ahpra, Therapeutic Goods Administration, ARTG, Privacy Act 1988, Australian Privacy Principles, Voluntary AI Safety Standard
Most governance advice for healthcare is written for hospitals with a chief risk officer. Plenty of Australian providers deploying AI right now are a practice manager, a privacy officer and one clinician who asked a question nobody else wanted to ask. This is the version for them.
What AI governance does an Australian healthcare provider actually need?
Four things: a named human accountable for each tool, a check on whether the tool is a regulated medical device, a data path that satisfies cross-border disclosure rules, and a privacy policy that discloses automated decision-making. Everything else is elaboration.
The temptation is to build a framework first and deploy second. That order fails, because the framework gets written against imagined risks rather than the ones the first tool actually creates.
Start with one tool already in use, document those four things for it, and let the second tool reuse the shape.
Who is accountable when an AI tool affects a patient?
The registered practitioner. Ahpra's guidance, Meeting your professional obligations when using Artificial Intelligence in healthcare, makes practitioners ultimately responsible for any AI used in the course of their practice and says they cannot defer to an AI output without applying their own professional judgement (Source: Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare).
That has a practical consequence most policies miss. Accountability does not transfer to the vendor, to the practice, or to the person who approved the purchase.
So a governance document that lists tools without naming a responsible practitioner for each has not allocated anything. It has made a list.
When does an AI tool become a medical device?
When it interprets rather than records. On 30 January 2026 the Therapeutic Goods Administration clarified that a digital scribe which only transcribes and translates a consultation is not a medical device, while one that analyses or interprets it, for example by generating a diagnosis, differential diagnosis or treatment recommendation the practitioner did not state, is a medical device and must be included in the ARTG (Source: TGA, digital scribes guidance, 30 January 2026).
This is the single most useful line in Australian healthcare AI regulation, because it is testable. Ask what the tool produces that nobody said out loud.
The TGA has also said scribes meeting the medical device definition without an ARTG listing are being supplied illegally, and has flagged enforcement against non-compliant suppliers (Source: TGA, digital scribes guidance, 30 January 2026).
What happens if the tool changes after you approve it?
The classification can change with it. The TGA has flagged scope creep, where a software update starts generating differential diagnoses and moves a product that was not a medical device into medical device territory (Source: TGA, digital scribes guidance, 30 January 2026).
An approval process that checks once at purchase and never again will miss this entirely. The vendor ships a feature, the classification shifts, and nothing in the practice notices.
The fix is unglamorous: a review date against each tool, and a question at renewal about what changed in the intended purpose.
Why is health information treated differently?
Health information is sensitive information under the Privacy Act and attracts the highest level of protection under the Australian Privacy Principles, which govern its collection, use, disclosure and security (Source: OAIC, Australian Privacy Principles, Privacy Act 1988). Ordinary personal information does not carry the same standard.
Any AI tool touching a clinical record inherits that standard. The tool does not get a lower bar because it is new, or because it is only summarising.
Providers also remain accountable for what happens to patient data once it reaches an AI system, including systems not operated in Australia.
Can patient data go to an overseas AI service?
Not without meeting cross-border disclosure requirements first. Australian Privacy Principle 8 governs disclosure of personal information to overseas recipients, and health data carries additional obligations under the My Health Records Act 2012 and state health records legislation (Source: OAIC, Australian Privacy Principles, Privacy Act 1988).
Most consumer AI products are overseas services by default. That is the quiet failure in a lot of current practice: the tool was never approved, so the data path was never assessed.
The question to ask of any tool is where the data is processed and where it is stored, in writing, from the supplier.
What has to change by December 2026?
Privacy policies must disclose whether the organisation uses automated decision-making that significantly affects individuals (Source: OAIC, Privacy Act reforms, in effect December 2026). If an AI tool influences a clinical or administrative decision about a patient, that disclosure obligation is live.
This is the nearest hard deadline in the stack, and it is a documentation change rather than a technical one. Most providers can meet it in an afternoon once they know which tools are in use.
Knowing which tools are in use is usually the harder half.
What does the Voluntary AI Safety Standard ask for?
Ten voluntary guardrails covering accountability, risk assessment, data governance, testing, human oversight, transparency, contestability, supply chain, records and stakeholder engagement (Source: DISR, Voluntary AI Safety Standard, September 2024). It is not law.
Its practical value is as a structure a board or practice principal can be shown, rather than as a compliance obligation. Mapping your four essentials onto its guardrails takes an hour and makes the governance legible to people who have to sign it off.
Do not build the whole standard before deploying anything. That is the failure the standard itself warns against.
Which workflows should a provider start with?
The ones where the AI does not interpret and a mistake is visible. Documentation, summarising, drafting correspondence and rostering all keep a practitioner between the output and the patient, which is also the side of the TGA's line that does not require an ARTG listing.
Volume is the wrong first filter. Starting with the highest volume task puts the least tested tool closest to the most decisions.
Start where checking is realistic, learn how the tool behaves, then move it nearer to anything clinical.
Where do healthcare providers get this wrong?
The most common pattern is discovering the tools after the fact. Staff adopt a scribe or a chatbot individually, nobody approves anything, and the first governance conversation happens after a patient asks a question.
The second is treating the supplier's assurance as the assessment. A supplier saying a tool does not need to be listed is a claim, not a finding, and the ARTG is public.
The third is writing the policy and stopping. A register with no review date describes the day it was written, and in a field where a software update can change a tool's regulatory classification, that ages badly.
What does a working governance document contain?
A register of tools in use, a named accountable practitioner against each, the medical device determination and its date, the data path including where processing happens, and a review date. Five columns, honestly filled in, beat a forty page framework nobody applies.
If you want the version written for your role rather than a generic template, we publish four working documents for Australian healthcare providers. Each is written by a person within 48 hours, for the decisions you actually make.
- AI Governance Playbook for Healthcare, the working governance model for organisations that already have staff using AI tools.
- Healthcare AI Tool Approval Request Template, the questions to put to a supplier before a tool reaches a clinical workflow.
- Patient Policy Flowchart, what to tell patients and when.
- AI Triage Assessment, which workflows are safe to put AI near first.
Sources: Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare. TGA, digital scribes guidance, 30 January 2026. OAIC, Australian Privacy Principles, Privacy Act 1988. OAIC, Privacy Act reforms, in effect December 2026. My Health Records Act 2012. DISR, Voluntary AI Safety Standard, September 2024.
Keep reading
Related guides and next steps
solution
AI Governance
The governance framework every deployment runs through, including the healthcare specific obligations.
solution
Resources
resource
Who Approves an AI Tool in an Australian Practice, and What Do They Ask?
The approval conversation for healthcare AI: pinning the intended purpose, checking the ARTG yourself, the questions to put to a supplier in writing, and who signs.
resource
What Do You Have to Tell Patients When AI Touches Their Care?
Which Australian Privacy Principles apply when AI touches a clinical record, when consent is required rather than notification, and how to introduce it to existing patients.
resource
Which Clinical Workflows Should AI Touch First?
A sequencing method for healthcare AI: sort work by whether the tool interprets, whether a mistake is visible, and whether checking is realistic, rather than by volume.
sector
Healthcare Organisations
Privacy first intelligent systems for healthcare organisations. Clinical knowledge retrieval, documentation assistance, and administrative automation.
Ready to move from reading to shipping?
Ten business days. Four modules. One agent live by the end.