Is it safe to use ChatGPT for NDIS work?
5 July 2026 · 8 min read
NDIS providers are busy, under-resourced, and drowning in guidelines — so it's no surprise that staff are quietly pasting questions into ChatGPT to get quick answers on SIL ratios, SCHADS pay, or how to word an incident report. It usually works, and it's fast.
But the useful question isn't "is AI any good?" It's "is it safe to put our participants' information into a public AI tool?" That's where NDIS work is different from most industries, and where a careless copy-and-paste can turn into a genuine privacy problem.
This guide walks through the real risks, what's actually safe versus risky, and how to get the speed of AI without breaching your obligations.
The short answer
Using ChatGPT for general, de-identified questions — "what is Supported Independent Living?", "draft a generic shift-handover template" — is generally fine. Using it with participant-identifying or sensitive information — names, health and disability details, incident reports, plan information — is where you take on real privacy and compliance risk.
The problem isn't AI. It's what you feed it, and where that data goes.
Why NDIS work raises the stakes
Two things make disability support different:
- You handle "sensitive information." Under the Australian Privacy Act and the Australian Privacy Principles (APPs), health and disability information gets a higher level of protection than ordinary personal information. Participant records sit squarely in that category.
- You're accountable under the NDIS Practice Standards. Providers must protect participant privacy and dignity and keep their information secure. That obligation doesn't disappear because a staff member used a chatbot.
So the moment participant details leave your systems and land in a third-party tool, you need to be able to answer: was that a disclosure we were allowed to make, and is that information now safe?
The three risks that actually matter
1. Privacy and offshore data. Consumer AI tools typically process and store what you type on overseas (mostly US) servers. Sending personal information overseas triggers accountability obligations under APP 8 — and pasting a participant's name and health details into a public chatbot is hard to reconcile with those obligations.
2. Data retention and model training. Depending on the tier and your settings, what you type may be retained and used to help improve the model. Business and enterprise tiers change these terms, but the default consumer experience is not built around your confidentiality.
3. Accuracy and accountability. General-purpose chatbots can sound confident and still be wrong, and they usually don't show you a source. For NDIS decisions — funding, restrictive practices, audit evidence — an unverifiable answer is a liability, not a shortcut.
What's safe vs what's risky
Generally safe:
- General knowledge questions ("what is SDA?", "explain the SCHADS sleepover provisions")
- Drafting or improving non-identifying templates, policies and position descriptions
- Summarising public NDIS material you already have
Risky — keep out of public AI tools:
- Participant names, addresses, NDIS numbers or dates of birth
- Health, disability or behaviour-support information
- Incident reports, case notes and progress notes
- Plan details, budgets and funding information
- Staff records and anything else you wouldn't email to a stranger
How to use AI safely for NDIS work
You don't have to ban AI to be compliant. You have to use it deliberately:
- De-identify first. Strip names and identifiers before asking a general question. "A participant" beats "Sarah in the Greenslopes SIL home."
- Read the data policy. Before any tool touches work information, check where data is stored, how long it's kept, and whether it's used for training.
- Prefer onshore, purpose-built tools. For anything involving participant context, choose a tool with Australian hosting, a data-processing agreement, and no model training on your content.
- Keep a human in the loop. Treat every answer as a draft to verify — especially for participant-facing or high-risk decisions.
- Write it down. A short AI use policy and a bit of staff training turns "people are secretly using ChatGPT" into a controlled, defensible practice.
Where Support Logic fits
Support Logic was built to remove this trade-off. It's an NDIS-specific AI assistant that keeps your data hosted onshore in Australia, adds privacy guardrails that detect and block participant identifiers before they ever reach the model, and gives citation-backed answers drawn from NDIS legislation, the Practice Standards, the SCHADS Award and your own uploaded policies — with an audit trail behind every conversation.
In other words: the speed of AI, without the "should we really be pasting this into ChatGPT?" question. You can see how it works or compare plans.
The bottom line
ChatGPT isn't off-limits for NDIS providers — but consumer AI tools were never designed to hold sensitive participant information, and the privacy obligations that apply to your organisation don't bend around them. Use public tools for general, de-identified questions; use a purpose-built, onshore, privacy-first tool for anything that touches a participant.
This guide is general information, not legal advice. For advice specific to your organisation's obligations, consult a qualified privacy professional or lawyer.
Get practical NDIS guides by email
Simple, practical guidance on compliance, SIL, SCHADS and AI — a few times a month. No spam, unsubscribe anytime.
Frequently asked questions
Yes — for general, non-identifying questions (like 'what is Supported Independent Living?' or drafting a generic template), consumer AI tools can be a useful starting point. The risk arises when you enter participant-identifying or sensitive information. Treat public AI tools like any other third party you might disclose information to, and keep participant data out of them.
It can be. Health and disability information is 'sensitive information' under the Australian Privacy Act, and pasting it into a consumer AI tool can amount to disclosing personal information overseas without the safeguards the Australian Privacy Principles expect. Whether it is a breach depends on your consent, your policies and how the tool handles the data — but it is a real risk, not a hypothetical one.
It depends on the tier and settings. Consumer versions have historically been able to use conversations to improve models unless you opt out or use enterprise/business tiers with different terms. Data is also typically processed and stored on overseas (mostly US) servers. Always read the current data-use and retention policy of any tool before entering work information.
A tool built for the sector can host your data onshore in Australia, provide a data-processing agreement, restrict model training on your content, add guardrails that detect and block participant identifiers, and give citation-backed answers with an audit trail — none of which come by default with a consumer chatbot.
Yes. Any AI is decision-support, not a decision-maker. Under the NDIS Practice Standards you remain accountable for the quality and safety of your services, so a qualified person should review AI output before it informs participant-facing or high-risk decisions.
NDIS AI you don't have to worry about
Support Logic keeps your data onshore, blocks participant identifiers, and gives citation-backed answers — built for Australian NDIS providers.
