AHPRA and AI

AHPRA and AI

The Australian Privacy Principles changed in July 2025, and the additions were specific to artificial intelligence. For dental practices, that means new obligations. For practices using AI tools, those obligations are non-negotiable.

The mistake most practices make is treating compliance as a feature to add later. It is not. Compliance is the foundation that safe AI adoption sits on.

## What actually changed in July 2025

The regulatory amendments address AI systems specifically because general privacy law was written before AI existed. The changes cover several areas: how you handle patient data when it flows through AI systems, where responsibility sits when an AI system produces an output, and how you document the decisions you made about using AI in the first place.

The effect is simple: you cannot use an AI tool in your practice and treat patient privacy as someone else’s problem. You own it. AHPRA expects you to own it.

## The AHPRA fine framework is real

Practices hear about the $50 million fine figure and assume it does not apply to them. That assumption is dangerous. AHPRA’s fine framework for privacy breaches starts lower, but it compounds. A single breach affecting multiple patient records gets counted as multiple breaches. Fines can run into millions for small practices. More damaging than the money is the investigation itself: AHPRA can examine years of your patient records, your staff practices, your systems, and your documentation.

The practices most at risk are the ones using AI tools without being able to explain why, or how they chose the tool, or what safeguards are in place. AHPRA investigations start with a patient complaint and move outward from there.

## Compliance does not mean avoiding AI

The worst interpretation of the July 2025 changes is that practices should avoid AI altogether. That is not the message. The message is: do not use AI without safeguards.

The safeguards are not mysterious. They are:
– Knowing what data is flowing into the AI system and where it is stored
– Choosing tools where the vendor has designed compliance in from the start, not added it later
– Documenting your decision to use the tool and your reasons for choosing it
– Having a process to check the output before it affects a patient

That is not restrictive. It is foundational design.

## Where to start

The first step is knowing what tools you are currently using that involve AI. Many practices do not realise they are using AI at all. Some systems that update patient records, send appointment reminders, or flag clinical patterns now use AI under the hood. You need to know what you have.

The second step is asking one question of every tool: where does my patient data go, and who has access to it. If the vendor cannot answer that clearly, you should not be using it.

The third step is reading the contract. Tools that comply with AHPRA’s expectations will say so explicitly. Tools that avoid the topic entirely are tools to be sceptical about.

## Building a compliance-first culture

Practices that adopt AI successfully are the ones where compliance is a conversation, not a checkbox. That means frontdesk staff understand why they are not pasting patient names into free AI tools. It means clinicians understand what data matters and why.

Centaur Software has been serving dental practices for 34 years. Their position on AI integration reflects that history: build compliance in from the start. Do not retrofit safeguards onto a system already in use. The costs are higher, the risks are greater, and the adoption is slower.

Your patients trust you with their health information. AHPRA expects you to protect it. Compliance-first AI adoption is how you do both.