Skip to content

Generic AI vs purpose-built NDIS AI: what actually matters

28 July 2026 · 9 min read

Most NDIS providers already have AI in the building, whether they've decided to or not. Someone in the office has a ChatGPT tab open. A team leader is using it to word an incident report. A coordinator pasted part of a plan into it last week to get a summary.

None of that is unreasonable. The tools are genuinely useful and the sector is genuinely stretched.

The question worth asking isn't "should we allow AI?" It's "if the Commission asked us tomorrow to show how we use AI safely, what would we hand them?"

This guide compares what general-purpose AI does well against what an NDIS organisation actually needs, in plain terms.

What generic AI is genuinely good at

Let's be fair to it first. For NDIS work, tools like ChatGPT are strong at:

  • drafting and tidying up general documents, position descriptions and templates
  • explaining a concept you half-remember
  • summarising something long that you've already got in front of you
  • brainstorming, rewording, and getting a first draft out of a blank page

If that's all you need, a general tool is inexpensive and perfectly adequate. Nobody needs specialist software to reword a job ad.

Where it leaves you exposed

The gap opens up the moment the work involves a participant, a funding decision, or anything an auditor might later ask about.

The table below sets out what a purpose-built NDIS tool does differently, and which part of your obligations each one supports.

What it doesWhy generic AI can'tWhat it helps you meet
Blocks participant details automatically — names, NDIS numbers and dates of birth are detected and stopped before the question is sent anywhereA general chatbot accepts whatever is typed. Your only protection is a policy asking staff not toCode of Conduct s6(b) — respecting participant privacy. Core Module: Information Management
Keeps a record of every block — you can show how many times participant details were stopped, and whenThere is no log to produce. You can describe your policy but not demonstrate it workedCore Module: Risk Management and Governance and Operational Management — controls you can evidence
Stores your documents in Australia — files, database and search index all held on Australian serversConsumer AI typically stores and processes on overseas servers, with limited visibility for youPrivacy Act APP 8 (sending information overseas) and APP 11 (keeping it secure)
Shows the source for every answer — each response cites the rule, clause or guide it came fromAnswers sound authoritative but usually can't be traced. Verifying means starting again yourselfCore Module: Quality Management — decisions made on checkable information
Stays current on Australian rules — price guides, SCHADS rates and practice standards are kept up to dateTraining data has a cut-off. It will answer confidently using last year's figuresCore Module: Quality Management — systems reviewed and updated
Trains your team before they use it — short modules staff complete first, with a completion recordAnyone with the link can start typing immediately, trained or notCore Module: Human Resource Management — identified skills and induction
Shares one approved answer across the team — managers publish a vetted answer everyone seesEvery person gets their own answer in their own private chat. Five staff, five versionsCore Module: Governance and Operational Management — consistent practice
Produces evidence you can hand over — checklists, privacy logs, training records and a transparency statement, exported as a documentNothing to export. You'd be assembling an explanation from scratch under time pressureAudit preparation, and the automated decision-making transparency duty from 10 December 2026

The difference in one sentence

Generic AI helps one person get an answer. A purpose-built tool helps your organisation give the same answer, from a source you can point to, without participant details leaving the country — and leaves a record that it happened that way.

The consistency problem nobody talks about

Ask five staff how a broken shift is paid, or when an incident becomes reportable, and you will often get five answers. Give those same five people a private AI chat and you haven't fixed that — you've industrialised it. Everyone is now confidently wrong faster, in isolation, with no shared record.

This is the part providers underestimate. The risk isn't only privacy. It's that your organisation quietly loses a single version of the truth, and you don't discover it until an auditor asks two people the same question.

A date worth putting in the diary

From 10 December 2026, organisations covered by the Privacy Act must include an automated decision-making transparency statement in their privacy policy, where personal information is used in automated decisions that could significantly affect a person's rights or interests.

If AI touches decisions about a participant's supports, that includes you. It isn't a ban and it isn't complicated — but it does have to exist, in writing, by that date.

What to ask any AI vendor

Whether or not you look at Support Logic, these are the questions worth asking anyone selling AI into the disability sector:

  1. Where is our data stored, and can you put that in writing?
  2. Is our content used to train your models?
  3. What happens if a staff member types a participant's name — does the system stop it, or just hope they don't?
  4. Can I see a record of that happening?
  5. Where do your answers come from, and can I check them?
  6. How do you keep up with price guide and award changes?
  7. What can I hand an auditor?

A vendor who can answer all seven is worth talking to. One who answers "we take privacy seriously" and moves on is not.

Where Support Logic fits

We built Support Logic around those seven questions rather than adding compliance later.

Participant identifiers are detected and blocked before anything is sent to the AI. Your documents are stored and indexed on Australian servers. Your content is never used to train the model. Answers cite their source so a person can check them. Staff complete short training modules before they get access. Managers can publish one approved answer to the whole team. And the privacy log, training records, compliance checklists and transparency statement can be exported when you need them.

To be clear about what we can't claim: the NDIS Commission does not endorse or approve any AI tool, including ours. What we can say is that the design targets each risk the Commission has named.


This guide is general information, not legal advice. Your obligations depend on your circumstances — confirm them with a qualified adviser and against the current text of the rules.

Sources: NDIS Quality and Safeguards Commission, NDIS Practice Standards — Core Module: Provider governance and operational management; NDIS (Code of Conduct) Rules 2018; OAIC, APP 8 — Cross-border disclosure of personal information; OAIC, APP 11 — Security of personal information; Privacy and Other Legislation Amendment Act 2024 (automated decision-making transparency, commencing 10 December 2026).

Get practical NDIS guides by email

Simple, practical guidance on compliance, SIL, SCHADS and AI — a few times a month. No spam, unsubscribe anytime.

Frequently asked questions

You can, and many providers do. The difficulty is proving it at audit. A policy tells an auditor what you intended; it doesn't show what actually happened. A purpose-built tool blocks identifiers automatically and keeps a record of every time it did, which is evidence rather than intention. Staff under time pressure at 9pm are exactly who the policy relies on, and exactly who is most likely to take a shortcut.

NDIS AI you don't have to worry about

Support Logic keeps your data onshore, blocks participant identifiers, and gives citation-backed answers — built for Australian NDIS providers.