Somewhere in your organisation right now, someone is probably pasting something into ChatGPT. A support worker drafting a progress note. A coordinator summarising a report. You, tidying up an email to a plan manager. AI tools are too useful for busy people to ignore, and pretending your team isn't using them doesn't make it true.

So the real question isn't whether NDIS providers should use AI. It's whether the way you're using it would survive scrutiny from a participant's family, the NDIS Quality and Safeguards Commission, or an auditor. Here's the honest picture.

The short answer

AI tools like ChatGPT and Claude are safe for NDIS work under one condition: no participant-identifiable information ever goes into them. No names, no addresses, no NDIS numbers, no dates of birth, no photos, no combination of details that could identify a person.

That single rule changes everything. "Write a progress note about Jane Nguyen's shift at 14 Smith Street" is a privacy problem. "Draft a progress note for a participant who attended a community access shift, engaged well for the first hour, then became fatigued" is not. The AI writes the same quality note either way. The identifying details get added afterwards, inside your own systems, by your own people.

Providers who work this way get the benefit of AI without the exposure. Providers who don't are making disclosures they can't take back.

Why this matters legally

NDIS providers sit under two overlapping frameworks here:

  • The Privacy Act 1988 and the Australian Privacy Principles. Participant information is personal information, and health and disability information is generally treated as sensitive information, which attracts stricter handling requirements under the APPs. Typing it into a third-party AI tool is a disclosure. If that tool stores data overseas, the cross-border disclosure rules apply on top. "I was just drafting a note" is not a defence.
  • The NDIS Practice Standards. Registered providers must protect participant privacy and dignity, and manage information properly. An auditor who asks "how do you control what goes into AI tools?" is asking a Practice Standards question, and "we don't really know" is the wrong answer to give during a recertification audit.

One important nuance: no AI tool is "compliant" or "non-compliant" on its own. Compliance lives in how your organisation uses the tool. The same ChatGPT account can be used perfectly safely or recklessly on the same afternoon.

What actually happens to what you type

Where does your text go once you hit enter? It depends heavily on which plan you're on:

  • Consumer plans (the free and personal paid tiers most people use) may use your conversations to train future models unless you find the setting and opt out. Treat the default as "assume it may be kept and used".
  • Business and enterprise tiers generally do not train on your data by default and offer stronger contractual protections. This is why "which plan are we on" is a genuine compliance question, not an IT detail.
  • Where the data lives matters too. Most major AI tools store data overseas. That's manageable, but it's exactly the kind of thing you should know and be able to say out loud before an auditor asks.

The practical conclusion: even on a well-configured business plan, the de-identification rule stays. It's the difference between a system that depends on vendor settings staying favourable and one that's safe regardless.

Safe vs not safe: the practical list

Safe with de-identified content

  • Drafting progress notes, shift notes and incident report narratives ("the participant", "P1", "the worker")
  • Summarising your own policies, or drafting new ones
  • Writing emails, letters and service communications before names are added
  • Preparing audit evidence descriptions and continuous improvement notes
  • Building templates: intake checklists, onboarding packs, meeting agendas

Never, on any plan

  • Pasting anything containing participant names, addresses, NDIS numbers or dates of birth
  • Uploading participant files, plans, medical reports or photos
  • Entering worker screening details or HR records
  • Letting AI make care decisions, risk assessments or anything touching mandatory reporting - those are human judgement, full stop

How to make this stick: the four-part setup

A rule that lives in your head isn't a system. Here's the minimum that makes AI use defensible:

  1. A written AI-use policy. One page is enough: the de-identification rule, the approved tools list, human review before anything is sent or filed, and what to do if identifiable data goes in by mistake (stop, tell the manager, record it).
  2. Worker sign-on. Every worker and subcontractor signs the policy. This is what turns "we have a rule" into evidence.
  3. An automation register. A simple list of every AI tool and automation in use, who owns it, what data it touches, and how to switch it off. Auditors respond well to this because almost nobody has one.
  4. Human review, always. AI output is a draft. A person checks every note, letter and report before it becomes a record. This is both good practice and your protection against AI's habit of confidently making things up.

If you want the deadline side of compliance handled with the same discipline, see our guide to how NDIS providers stop missing compliance deadlines - it covers the obligations register method and includes a free template.

The upside once the rules are in place

None of this is a reason to avoid AI. Providers that set these rules up properly then get to use AI aggressively where it shines: drafting, summarising, template building, audit preparation. The admin load in NDIS work is real, and this is the most effective tool that has ever existed for reducing it. The full picture of what's worth automating is in our complete guide to AI and automation for NDIS providers.

At Workvolve we build this properly for NDIS organisations: the policy pack, the de-identified AI workspace, and the automations around it. Fixed-price, and you own everything we build. If you want a clear starting point, our free 30-minute call will tell you what's safe to do first in your setup.