26 Feb 2025

In 2022 generative AI burst onto the scene, sparking imaginations worldwide. ChatGPT was the fastest growing app in history and now has over 400 million users. From writing emails and documents, to creating beautiful and imaginative images and videos there are literally thousands of AI apps on offer and users are coming up with more and more creative ways of using them to save time and be more productive. It’s like a science fiction story becoming reality.
Amidst all this excitement, people are voraciously rushing to use the next exciting app. But how many people are stopping and thinking - where is my data going? Where will it be stored and how will it be used? Why was ChatGPT free when it was first released (there is still a free version) and what does OpenAI get out of it?
Your data of course!
Since AI tools are often productivity tools they are just perfect for work. We have this vague sense we should probably be careful what we put into AI tools like ChatGPT, Claude and Perplexity - after all we are disclosing the data to a third party and how much do we really know about what they will do with that data or how secure their systems are? Perhaps you, like me have had that guilty feeling where we wonder if we really should have cut and pasted THAT work document or code into an AI tool!
Two or so years on it's clear generative AI is here to stay and its not just a passing fad and that it is going to continue to have a massive impact on business worldwide. You simply cannot afford NOT to use AI in your business because all your competitors are using it. Now the novelty is passing businesses are starting to consider how to incorporate AI into their operations and how to do it safely. Arguably the most important safety issue is data security. It is a fundamental and enduring priority. Whatever happens with AI innovation in coming years we will always need to keep our data private - private at a personal level, private within corporates and private between nations.
The recent release of DeepSeek has highlighted the importance of data privacy with AI. Shortly after it was released by a Chinese hedge fund the Australian federal government banned the use of DeepSeek by its employees. It is even banned at the University of Adelaide where I am Associate Professor. While the Large Language Model (LLM) itself is not of concern although it has been accused of political bias, the glaring issue that has worried the government is all the data you put into the DeepSeek-hosted app will be sent to China. The data will generally be stored and used for further model training by DeepSeek but who else might gain access to it and for what purpose?

So DeepSeek might be a bit sus for sensitive data but what about the other AI tools like ChatGPT? Most of them will potentially use your data for model training which means it could be disclosed publicly in the future unless the privacy settings are correctly configured. Most of the AI tools are hosted in the USA which means your data is being stored outside of Australia. For some organisations, particularly in health this is of concern. In fact many Australian organisations are obliged to conform to the Australian Privacy Act 1988 in which APP8 has something to say about cross-border disclosure of consumer data. Privacy Principle 8 requires that data disclosed to a third party (e.g. AI tool) overseas be guaranteed the same legal privacy protections as in Australia. This is the responsibility of Australian businesses. Clearly we don't have any say about how the laws operate in the USA let alone China! No wonder the Office of the Australian Information Commissioner (OAIC) has made the following recommendation:
"Given the significant and complex privacy risks involved, as a matter of best practice it is recommended organisations do not enter personal information and particularly sensitive information into AI chatbots."
When you input sensitive data into ChatGPT and other overseas-hosted AI tools it can be stored there, used for model training and possibly be disclosed to other third parties.
How can we use AI safely in Australia? As far as data security goes, a great start is to ensure your data stays in Australia where it can be governed by Australian privacy laws. To achieve this the AI models (LLMs) and data storage need to be hosted on cloud systems in the Australian region or for stricter security requirements, on premises. There are cloud APIs and tools that developers can use to build AI applications to help your business and ensure data privacy in Australia. But are there tools you can use off-the-shelf that are hosted in Australia?
At Inject AI we have developed a new AI tool called Hippo to suit the needs of Australian businesses. Hippo is like ChatGPT but hosted entirely in Australia, currently on Azure. Hippo keeps your data secure within Australia using Azure’s enterprise-grade security avoiding cross-border disclosure to uphold the privacy act. Hippo will never use your data to train AI models. Hippo’s aim is to be a secure AI platform for Australian businesses, not to create the next LLM. As AI is adopted into various areas of business, integration with platforms and workflows will be essential. An advantage of Hippo is that it can be customised for the needs of Aussie businesses, so the power of AI can be applied to your data.
It’s time to get serious about AI in your business - serious about data governance and privacy. A good start is to review your privacy policy to include a transparency statement about the use of AI tools in your company, or consider creating an AI Usage Policy for your organisation. Assess the risks of how AI tools are used in your business: How sensitive is the data being used? Where is the data going? Should you make the switch to an Australia-based AI tool for your confidential data? In coming years we will see AI policies, governance and regulation become commonplace.
Make your start now - and don’t be the headline for an AI data breach!
Article written by Dr Jamie Sherrah, Founder and CEO Inject AI. Jamie is a seasoned AI entrepreneur and researcher with 25 years experience deploying and commercialising machine learning and computer vision systems. Drawing on a broad and deep experience of ML research and commercial software development, Jamie is adept at taking an idea through to solution design, system prototype and deployment.