Skip to content

NDIS providers and AI: what the rules actually say

21 July 2026 · 10 min read

Artificial intelligence has moved into NDIS back-offices faster than the guidance has followed. Support workers draft incident reports with it. Coordinators use it to interpret the Practice Standards. Managers paste policies in and ask for summaries.

In February 2026 the NDIS Quality and Safeguards Commission put its position in writing. This guide sets out what that statement says, what the underlying law requires, and what it means for how your organisation uses AI.

The Commission has named the risk

The Commission's position statement, Use of artificial intelligence in the development of behaviour support plans, was issued in February 2026. It is framed around behaviour support plans, but the obligations it draws on — particularly the Code of Conduct — apply to every registered and unregistered provider and worker delivering NDIS-funded supports.

The statement identifies five risks associated with providers' use of AI:

  • disclosure of personal participant information to third parties
  • processing or storage of personal information overseas
  • a lack of transparency about how data is stored, secured or used once entered into an AI system
  • inaccurate or misleading content or advice generated by AI
  • automated decision-making without appropriate human oversight or clinical judgement

It then makes the consequence explicit: unless mitigated, these risks may lead to breaches of the NDIS (Code of Conduct) Rules 2018. The statement gives a direct example — that disclosing sensitive personal information to a third-party AI platform, such as ChatGPT, without appropriate safeguards may breach section 6(b) of the Code, which requires providers to respect the privacy of people with disability.

What the Commission expects providers to do

The statement is not a prohibition. It says plainly that the current legislative framework does not explicitly prohibit the use of AI, and that providers may use it so long as that use complies with their legal obligations.

But it sets a clear expectation:

The NDIS Commission expects that, if a provider decides to use AI, all information is appropriately de-identified and that no personal information of participants is disclosed to AI systems.

And it attaches a consequence: if a provider doesn't do this, they may be breaking the law, including their obligations under the NDIS Act.

Two points are worth being precise about. First, the Commission states it does not endorse or approve the use of AI tools — no product, including ours, can claim Commission approval. Second, "appropriately de-identified" is doing the heavy lifting. In practice it means participant identifiers should not reach the AI system at all.

The privacy law underneath

The Code of Conduct is not the only obligation in play.

Australian Privacy Principle 8 — cross-border disclosure. When you send personal information to an AI provider whose systems sit overseas, that is a cross-border disclosure. Before doing so you must take reasonable steps to ensure the overseas recipient does not breach the APPs, and you generally remain accountable for what they do with that information. This is why the Commission lists overseas processing as a distinct risk.

APP 11 — security. You must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access or disclosure. Pasting participant details into a consumer chatbot with no contractual protections is difficult to defend as reasonable steps.

OAIC guidance. The OAIC's guidance on privacy and the use of commercially available AI products recommends, as a matter of best practice, that organisations do not enter personal information — particularly sensitive information — into publicly available AI chatbots. Disability status and health information are sensitive information, which attracts a higher level of protection.

A dated deadline: 10 December 2026

From 10 December 2026, entities covered by the Privacy Act must include an automated decision-making transparency statement in their privacy policy, where personal information is used in automated decisions that could significantly affect a person's rights or interests.

It is a disclosure obligation, not a ban. You must describe the kinds of personal information used and the kinds of decisions made by automated means. The OAIC can issue infringement notices and compliance notices where a privacy policy does not meet the requirement.

If AI touches decisions about a participant's supports, this is a live obligation with a date attached — and your privacy policy likely needs updating before then.

What good practice looks like

Drawing the threads together, a defensible approach to AI in an NDIS setting has five features:

  1. Identifiers never reach the AI. De-identification should be automatic and enforced by the system, not left to a support worker remembering to remove a name at 9pm.
  2. You know where the data lives. Storage and indexing of your documents should be onshore, and you should be able to say so in writing.
  3. Your content isn't training someone's model. Confirm contractually that your data is not used to train the provider's models.
  4. Answers are verifiable. The Commission lists inaccurate or misleading AI content as a risk. Citations to the source let a human check the answer rather than trust it.
  5. A human decides. AI can support a decision. Under the Code of Conduct and the Behaviour Support Rules, a qualified person must make it.

Where Support Logic fits

We built Support Logic around these obligations rather than retrofitting them.

Every message passes through a privacy gate before it reaches the AI: participant identifiers such as NDIS numbers and names are detected and either stripped or the message is blocked. Your uploaded documents are chunked, de-identified and indexed on our Australian servers, and stored in a Sydney database. Your content is never used to train the AI model. Answers are citation-backed so a human can verify them, and the product is decision-support only — it does not make decisions about participants.

To be clear about what we cannot claim: the NDIS Commission does not endorse or approve any AI tool, including this one. What we can say is that the design targets each risk the Commission has named.


This guide is general information, not legal advice. Obligations depend on your circumstances — confirm them with a qualified adviser and with the current text of the rules.

Sources: NDIS Quality and Safeguards Commission, Position statement — Use of artificial intelligence in the development of behaviour support plans (February 2026); NDIS (Code of Conduct) Rules 2018; National Disability Insurance Scheme Act 2013; OAIC, Guidance on privacy and the use of commercially available AI products; OAIC, APP 8 — Cross-border disclosure of personal information; Privacy and Other Legislation Amendment Act 2024 (automated decision-making transparency, commencing 10 December 2026).

Get practical NDIS guides by email

Simple, practical guidance on compliance, SIL, SCHADS and AI — a few times a month. No spam, unsubscribe anytime.

Frequently asked questions

No. The Commission's February 2026 position statement says the legislative framework does not explicitly prohibit AI, and that providers may use it so long as the use complies with their legal obligations. However, the Commission does not endorse or approve any AI tool.

NDIS AI you don't have to worry about

Support Logic keeps your data onshore, blocks participant identifiers, and gives citation-backed answers — built for Australian NDIS providers.