AI is already inside most aged care organisations — whether or not anyone decided it should be. Documentation assistants and AI scribes, rostering optimisation, chatbots on the website, analytics features switched on inside clinical and care management software you already own: each is an AI use, and each carries risk that existing policies were never written to cover. What most providers are missing is not enthusiasm. It is governance.

AI is already in your organisation

The question for a governing body is rarely "should we adopt AI?" — it is "what AI is already in use, and who decided?" Typical examples across the sector:

That last category deserves particular attention. Where no sanctioned option and no acceptable-use rule exists, staff improvise — and care information can end up in tools the organisation has never assessed.

Why this is a governing-body issue

Nothing about AI suspends your existing obligations; it routes new risk through them.

The Aged Care Act 2024. Registered providers carry a statutory duty to comply with their obligations (section 179), and responsible persons — including directors — carry a personal due diligence duty (section 180) to take reasonable steps to ensure the provider complies. If an AI tool drafts clinical documentation, influences care decisions or handles personal information, it sits squarely inside the conduct those duties cover. A director cannot take reasonable steps regarding tools nobody has listed, assessed or assigned an owner.

The Strengthened Quality Standards. The Standards are outcomes-based: what matters is the care and the experience of the older person, not whether a human or an algorithm produced the input. If an AI scribe writes an inaccurate progress note, it is a care documentation problem. If a rostering optimiser produces unsafe coverage, it is a workforce problem. The Standards do not accept "the software did it" as an answer.

Privacy. Care records are among the most sensitive information any Australian organisation holds. The Privacy Act 1988 and the Australian Privacy Principles govern how that information is collected, used and disclosed — including disclosure to an AI vendor's cloud service. Where a tool trains on, retains or transmits personal information offshore, that is a privacy assessment, not an IT preference.

The medical device boundary. Some AI software is regulated by the TGA as a medical device, depending on its intended purpose — decision support that influences diagnosis or treatment can cross that line, and a vendor's feature update can move a product across it. Providers do not need to become regulatory lawyers, but procurement and review should ask the question.

Alongside the binding obligations sit voluntary frameworks worth borrowing from: Australia's AI Ethics Principles give a plain-language vocabulary for policy, and ISO/IEC 42001 — the international AI management system standard — offers a structure that scales down sensibly for a mid-sized provider. For clinical uses, the National Model Clinical Governance Framework is the anchor: clinical AI governance is an extension of clinical governance, not a separate discipline.

A practical framework in eight steps

None of this requires a transformation program. It requires the same governance discipline you already apply to medication management or infection control, pointed at a new class of tool.

1 — Build the AI inventory. List every AI use: procured tools, features embedded in existing systems, and general-purpose assistants staff use informally. For each: what it does, what data it touches, who owns it, and whether it influences care. This single artefact converts "unknown unknowns" into a governable list — and it is what makes section 180 due diligence possible.

2 — Risk-tier each use. Grade each inventory entry by its potential to affect care outcomes, rights and privacy. A meeting-notes summariser and a falls-risk prediction tool should not face the same controls. Tiering is what keeps governance proportionate — heavy where harm is possible, light where it is not.

3 — Set policy and acceptable use. A short AI policy beats a long one nobody reads: what is permitted, what is prohibited (care information in unapproved public tools, for instance), who approves new uses, and how staff raise a proposed use. Make the sanctioned path easier than the workaround.

4 — Assign ownership. Every AI use gets a named owner accountable for its performance and its incidents — the same principle as any other risk register entry. Unowned tools are ungoverned tools.

5 — Keep humans in the loop. For any use that touches care, define where human review sits and how staff escalate when the tool gets it wrong. An AI-drafted note is a draft until a human accepts it; a risk flag is an input to clinical judgement, not a replacement for it. Route these controls through your existing clinical governance framework rather than building a parallel one.

6 — Put vendors through due diligence. Ask where data goes, whether it is used for training, where it is stored, what happens on termination, how the model is updated, and how the vendor tells you when capability changes. A vendor's willingness to answer transparently is itself a signal — the same lesson the ASD draws about technology vendors generally. Build the questions into procurement and contract renewal as standing items, not one-off projects.

7 — Protect the data. Apply your privacy and security controls to AI pathways specifically: what personal information can enter which tools, de-identification expectations, retention, and offshore disclosure. If you cannot say what data a tool sends where, it has not been assessed.

8 — Monitor and report to the board. AI tools change under your feet — models drift, vendors ship new capabilities, staff find new uses. Review the inventory on a cycle, track incidents and near-misses involving AI, and report the position to the governing body on a regular cadence: what is in use, at what risk tier, what changed, what went wrong, what was done. This is where AI governance joins your broader board reporting and assurance rather than living in an IT silo.

Six questions for the board

  1. Do we have a current inventory of every AI use in the organisation — including features embedded in software we already own?
  2. Which of those uses can affect care outcomes, resident rights or personal information, and have they been risk-tiered?
  3. Does every AI use have a named owner, and a policy that staff actually know about?
  4. Where AI touches care, where exactly does human review sit — and can staff describe the escalation path?
  5. What did we ask our AI vendors about data use, training, storage and capability changes — and what did they answer?
  6. When did the governing body last see an AI report: inventory, risk position, incidents and changes?

If your board cannot answer these with documented evidence, that is not unusual — most boards cannot yet. It is, however, the gap to close, because the duties these questions map to are already in force.

What providers should do this quarter

  1. Commission the AI inventory — a focused piece of work, not a program.
  2. Risk-tier the inventory and pick the two or three highest-risk uses for immediate review.
  3. Issue an interim acceptable-use position to staff, even one page, while the fuller policy is developed.
  4. Add AI vendor questions to your procurement and contract-renewal checklists.
  5. Put AI on the governing body agenda with a standing reporting slot.

Holistic Governance provides AI governance advisory, independent vendor assessment and AI training — and for clinical settings, extends your existing clinical governance framework to cover AI, rather than bolting on a parallel structure. You can read more about our approach and experience here.

Sources

*This article is published by Holistic Governance for sector information purposes only. It reflects the position as at the date of issue and does not constitute legal, regulatory, audit or financial advice. Verify any specific provision on the Federal Register of Legislation (legislation.gov.au) and current regulator guidance before relying on it. © Holistic Governance 2026.*