EPISODE · May 15, 2026 · 36 MIN
AI Security Part 3: Why PII and the Privacy Act Are the AI Foundation Most Leaders Skip
from AI - Beyond the Hype
You can have the most secure AI stack in the country and still be in breach of the Privacy Act before lunch. Sarah and James close the series with the foundation underneath the foundation: personal information. James, now grounded on the security side, opens with a healthy push-back — surely if we own the data, we can use it however we want? Sarah, with the OAIC determinations in hand, takes that apart.What we coverAPP 6 and purpose-binding: under Australia’s Privacy Act 1988, personal information collected for one purpose generally cannot be used for another. AI training, inference, and agent actions are all “uses,” yet most organisations haven’t mapped AI use cases to APP 6.The 2024 amendments: the Privacy and Other Legislation Amendment Act introduced a statutory tort for serious privacy invasions, a children’s privacy code, and stronger OAIC enforcement, including AUD $66,000 infringement notices.OAIC determinations: cases like Clearview AI, Bunnings/Kmart (facial recognition), and I-MED (patient data shared for AI training). I-MED’s de-identification was accepted, but it became a key APP 6 risk example.The bank scenario: three walkthroughs — inference drift, indirect prompt injection, and multi-agent purpose laundering — showing how compliant data becomes non-compliant AI use.Recommended controls: purpose registers, consent provenance, retrieval scoping, agent identity, and Meta’s “Agents Rule of Two.”SourcesPrivacy Act 1988: https://www.legislation.gov.au/C2004A03712/latest/textPrivacy and Other Legislation Amendment Act 2024: https://www.legislation.gov.au/C2024A00128/asmadeAustralian Privacy Principles (OAIC): https://www.oaic.gov.au/privacy/australian-privacy-principlesOAIC — Clearview AI determination (PDF): https://www.oaic.gov.au/__data/assets/pdf_file/0016/11284/Commissioner-initiated-investigation-into-Clearview-AI,-Inc.-Privacy-2021-AICmr-54-14-October-2021.pdfOAIC — Bunnings determination: https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-toolOAIC — Kmart determination: https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-findsOAIC — I-MED preliminary inquiries report: https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-i-medEU AI Act overview: https://artificialintelligenceact.eu/California ADMT — CPPA announcement: https://cppa.ca.gov/announcements/2025/20250923.htmlMeta — Agents Rule of Two: https://ai.meta.com/blog/practical-ai-agent-security/NIST AI RMF: https://www.nist.gov/itl/ai-risk-managSend us Feedback
Embed this episode
What this episode covers
You can have the most secure AI stack in the country and still be in breach of the Privacy Act before lunch. Sarah and James close the series with the foundation underneath the foundation: personal information. James, now grounded on the security side, opens with a healthy push-back — surely if we own the data, we can use it however we want? Sarah, with the OAIC determinations in hand, takes that apart. What we cover APP 6 and purpose-binding: under Australia’s Privacy Act 1988, persona...
NOW PLAYING
AI Security Part 3: Why PII and the Privacy Act Are the AI Foundation Most Leaders Skip
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.