Skip to main content

Who Approves an AI Tool in an Australian Practice, and What Do They Ask?

9 September 2026 | David and Goliath

Quick answer

Approval turns on one question: what does the tool produce that nobody said out loud. That determines whether it is a regulated medical device, which determines what you must verify before it touches a clinical workflow. The supplier's assurance is a claim, and the ARTG is a public register you can check yourself.

  • Intended purpose is the legal hinge, so get it from the supplier in writing
  • The ARTG is public, so verify a listing rather than accepting an assurance
  • A software update can change the classification after you approve it
  • Name one accountable practitioner per tool, not a committee

Mentioned: Therapeutic Goods Administration, ARTG, Ahpra, Australian Privacy Principles

Most practices approve AI tools the way they approve stationery, which is to say somebody buys one. The gap between that and a defensible approval is smaller than it looks, and it is mostly a matter of asking four questions in writing before the tool reaches a patient.

What is the first question to ask about an AI tool?

What does it produce that nobody said out loud. That single question sorts almost every healthcare AI tool into regulated and unregulated, because it is the distinction the regulator itself draws.

A tool that records what was said is doing one job. A tool that adds a conclusion is doing another, and the second one carries obligations the first does not.

Ask it before you ask about price, integration or training, because the answer changes who has to sign.

Why does intended purpose matter more than features?

Because intended purpose is the legal hinge. On 30 January 2026 the Therapeutic Goods Administration clarified that a digital scribe which only transcribes and translates a consultation is not a medical device, while one that analyses or interprets it, for example by generating a diagnosis, differential diagnosis or treatment recommendation the practitioner did not state, is a medical device and must be included in the ARTG (Source: TGA, digital scribes guidance, 30 January 2026).

A feature list will not tell you which side of that line a product sits on. Two tools with identical feature bullets can differ entirely on what they claim to do with the output.

So the artefact you want from a supplier is a written statement of intended purpose, not a demo.

How do you check a supplier's claim?

Look it up. The ARTG is a public register, so a claim that a product is included is verifiable in minutes rather than taken on trust.

This matters because the TGA has said digital scribes meeting the medical device definition without an ARTG listing are being supplied illegally, and has flagged enforcement action against non-compliant suppliers (Source: TGA, digital scribes guidance, 30 January 2026).

A supplier saying a tool does not need to be listed is a position, not a finding. Ask them to put the reasoning in writing and keep it with the approval record.

What questions belong in the approval request?

Five, and they should be answered in writing by the supplier rather than summarised by whoever is championing the tool.

  • What is the intended purpose, stated in the manufacturer's own words.
  • Is the product included in the ARTG, and if not, on what basis.
  • Where is the data processed, and where is it stored.
  • What happens to the data after processing, including whether it trains a model.
  • What is the process for notifying customers when the intended purpose changes.

The last one is the one people leave out, and it is the one that ages worst.

What happens when the tool changes after approval?

The classification can change with it. The TGA has flagged scope creep, where a software update starts generating differential diagnoses and moves a product that was not a medical device into medical device territory (Source: TGA, digital scribes guidance, 30 January 2026).

An approval that checks once at purchase is a snapshot of a product that no longer exists after the next release. Nothing in a practice notices, because nothing was watching.

A review date against each tool, and a question at renewal about what changed in the intended purpose, closes it.

Who should actually sign the approval?

One named practitioner, not a committee. Ahpra holds the registered practitioner ultimately responsible for any AI used in the course of their practice and says they cannot defer to an AI output without applying their own professional judgement (Source: Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare).

A committee approval spreads responsibility thin enough that nobody holds it. A named practitioner against each tool matches where the obligation actually sits.

That person does not need to be the most senior. They need to be the one who will notice if the output starts being wrong.

Does the practice manager or the clinician own this?

In practice it is usually shared, and the failure is assuming the other one did it. The clinician owns whether the output is safe to rely on. The practice owns whether the data path is lawful.

Both determinations have to exist before a tool reaches a patient, and they answer to different regulators.

Writing them on the same form is the simplest way to stop one being made without the other.

What does an approval record need to contain?

The tool, the supplier's written intended purpose, the medical device determination and the date it was made, the data path, the named accountable practitioner, and a review date. Six fields.

If the record cannot answer what was decided, by whom, and when, it will not help you the day someone asks. That day is usually prompted by a patient question rather than an audit.

Keep it short enough that it actually gets filled in. A form nobody completes is worse than no form, because it creates the appearance of a process.

Where do approvals go wrong?

The most common failure is approving the category rather than the product. A practice decides AI scribes are acceptable, and then three different products arrive under that decision with different intended purposes and different data paths.

The second is treating a pilot as unapproved. Tools reach real patients during pilots, and the obligations attach the moment they do.

The third is approving without a review date, which converts a considered decision into a permanent one about a product that keeps changing.

If you want the approval form written for your practice rather than a generic template, the Healthcare AI Tool Approval Request Template is written by a person within 48 hours, for the decisions you actually make. The wider framework sits in AI governance for Australian healthcare providers.

Sources: TGA, digital scribes guidance, 30 January 2026. Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare.

Ready to move from reading to shipping?

Ten business days. Four modules. One agent live by the end.