Generic AI vs purpose-built NDIS AI: what actually matters
28 July 2026 · 9 min read
Most NDIS providers already have AI in the building, whether they've decided to or not. Someone in the office has a ChatGPT tab open. A team leader is using it to word an incident report. A coordinator pasted part of a plan into it last week to get a summary.
None of that is unreasonable. The tools are genuinely useful and the sector is genuinely stretched.
The question worth asking isn't "should we allow AI?" It's "if the Commission asked us tomorrow to show how we use AI safely, what would we hand them?"
This guide compares what general-purpose AI does well against what an NDIS organisation actually needs, in plain terms.
What generic AI is genuinely good at
Let's be fair to it first. For NDIS work, tools like ChatGPT are strong at:
- drafting and tidying up general documents, position descriptions and templates
- explaining a concept you half-remember
- summarising something long that you've already got in front of you
- brainstorming, rewording, and getting a first draft out of a blank page
If that's all you need, a general tool is inexpensive and perfectly adequate. Nobody needs specialist software to reword a job ad.
Where it leaves you exposed
The gap opens up the moment the work involves a participant, a funding decision, or anything an auditor might later ask about.
The table below sets out what a purpose-built NDIS tool does differently, and which part of your obligations each one supports.
| What it does | Why generic AI can't | What it helps you meet |
|---|---|---|
| Blocks participant details automatically — names, NDIS numbers and dates of birth are detected and stopped before the question is sent anywhere | A general chatbot accepts whatever is typed. Your only protection is a policy asking staff not to | Code of Conduct s6(b) — respecting participant privacy. Core Module: Information Management |
| Keeps a record of every block — you can show how many times participant details were stopped, and when | There is no log to produce. You can describe your policy but not demonstrate it worked | Core Module: Risk Management and Governance and Operational Management — controls you can evidence |
| Stores your documents in Australia — files, database and search index all held on Australian servers | Consumer AI typically stores and processes on overseas servers, with limited visibility for you | Privacy Act APP 8 (sending information overseas) and APP 11 (keeping it secure) |
| Shows the source for every answer — each response cites the rule, clause or guide it came from | Answers sound authoritative but usually can't be traced. Verifying means starting again yourself | Core Module: Quality Management — decisions made on checkable information |
| Stays current on Australian rules — price guides, SCHADS rates and practice standards are kept up to date | Training data has a cut-off. It will answer confidently using last year's figures | Core Module: Quality Management — systems reviewed and updated |
| Trains your team before they use it — short modules staff complete first, with a completion record | Anyone with the link can start typing immediately, trained or not | Core Module: Human Resource Management — identified skills and induction |
| Shares one approved answer across the team — managers publish a vetted answer everyone sees | Every person gets their own answer in their own private chat. Five staff, five versions | Core Module: Governance and Operational Management — consistent practice |
| Produces evidence you can hand over — checklists, privacy logs, training records and a transparency statement, exported as a document | Nothing to export. You'd be assembling an explanation from scratch under time pressure | Audit preparation, and the automated decision-making transparency duty from 10 December 2026 |
The difference in one sentence
Generic AI helps one person get an answer. A purpose-built tool helps your organisation give the same answer, from a source you can point to, without participant details leaving the country — and leaves a record that it happened that way.
The consistency problem nobody talks about
Ask five staff how a broken shift is paid, or when an incident becomes reportable, and you will often get five answers. Give those same five people a private AI chat and you haven't fixed that — you've industrialised it. Everyone is now confidently wrong faster, in isolation, with no shared record.
This is the part providers underestimate. The risk isn't only privacy. It's that your organisation quietly loses a single version of the truth, and you don't discover it until an auditor asks two people the same question.
A date worth putting in the diary
From 10 December 2026, organisations covered by the Privacy Act must include an automated decision-making transparency statement in their privacy policy, where personal information is used in automated decisions that could significantly affect a person's rights or interests.
If AI touches decisions about a participant's supports, that includes you. It isn't a ban and it isn't complicated — but it does have to exist, in writing, by that date.
What to ask any AI vendor
Whether or not you look at Support Logic, these are the questions worth asking anyone selling AI into the disability sector:
- Where is our data stored, and can you put that in writing?
- Is our content used to train your models?
- What happens if a staff member types a participant's name — does the system stop it, or just hope they don't?
- Can I see a record of that happening?
- Where do your answers come from, and can I check them?
- How do you keep up with price guide and award changes?
- What can I hand an auditor?
A vendor who can answer all seven is worth talking to. One who answers "we take privacy seriously" and moves on is not.
Where Support Logic fits
We built Support Logic around those seven questions rather than adding compliance later.
Participant identifiers are detected and blocked before anything is sent to the AI. Your documents are stored and indexed on Australian servers. Your content is never used to train the model. Answers cite their source so a person can check them. Staff complete short training modules before they get access. Managers can publish one approved answer to the whole team. And the privacy log, training records, compliance checklists and transparency statement can be exported when you need them.
To be clear about what we can't claim: the NDIS Commission does not endorse or approve any AI tool, including ours. What we can say is that the design targets each risk the Commission has named.
This guide is general information, not legal advice. Your obligations depend on your circumstances — confirm them with a qualified adviser and against the current text of the rules.
Sources: NDIS Quality and Safeguards Commission, NDIS Practice Standards — Core Module: Provider governance and operational management; NDIS (Code of Conduct) Rules 2018; OAIC, APP 8 — Cross-border disclosure of personal information; OAIC, APP 11 — Security of personal information; Privacy and Other Legislation Amendment Act 2024 (automated decision-making transparency, commencing 10 December 2026).
Get practical NDIS guides by email
Simple, practical guidance on compliance, SIL, SCHADS and AI — a few times a month. No spam, unsubscribe anytime.
Frequently asked questions
You can, and many providers do. The difficulty is proving it at audit. A policy tells an auditor what you intended; it doesn't show what actually happened. A purpose-built tool blocks identifiers automatically and keeps a record of every time it did, which is evidence rather than intention. Staff under time pressure at 9pm are exactly who the policy relies on, and exactly who is most likely to take a shortcut.
Not usually wrong in an obvious way — which is the problem. It is confident, plausible and often out of date. Price guides, SCHADS rates and practice standards change regularly, and a general model has no reliable way to know which version applies today or to show you the clause it relied on. For everyday drafting that's fine. For a funding decision or an audit response, an answer you cannot trace back to a source is a liability.
From that date, organisations covered by the Privacy Act must include an automated decision-making transparency statement in their privacy policy where personal information is used in automated decisions that could significantly affect someone. If AI touches decisions about a participant's supports, this applies to you. It's a disclosure requirement, not a ban — but it does need to be written and published.
Yes, always. No AI tool removes your accountability under the NDIS Practice Standards or the Code of Conduct. The right question isn't whether a human checks the work — it's whether your system makes checking easy. Answers that cite their source can be verified in seconds. Answers that don't have to be researched from scratch, which is why staff stop checking.
No. The NDIS Code of Conduct applies to registered and unregistered providers and to individual workers. The Privacy Act obligations depend on your organisation's circumstances rather than your registration status. Registered providers have the additional exposure of a scheduled audit, which is where evidence matters most.
NDIS AI you don't have to worry about
Support Logic keeps your data onshore, blocks participant identifiers, and gives citation-backed answers — built for Australian NDIS providers.
