AI is transforming the health and life sciences sector, from supporting diagnostic decision-making to streamlining operational workflows. However, rapid adoption brings significant legal, ethical and operational risks that organisations must understand and manage. In this resource, our team explores the key risks organisations should be aware of when developing or deploying AI in a health and life sciences context.

We examine how Australia's existing regulatory framework applies to AI tools in this space and consider what further regulation may be on the horizon. We also set out practical mitigation strategies organisations can implement to deploy AI responsibly and in a manner that supports, rather than undermines, patient safety, medical innovation and health outcomes.

Whether you are developing AI-enabled technologies, procuring them, or advising on their implementation, this guide offers a practical framework for understanding your obligations and managing risk in this fast-moving area.

Download the industry guidance and standards

Introduction

During the BioMelbourne Network’s BioForum hosted by Gadens, AI in Clinical Trials: Intelligence by Design, Michelle Gallaher (Chief Executive Officer, Cerulea Clinical Trials) flagged that AI is already actively operating at every stage of the clinical trials and regulatory affairs pipeline. Further, Dr Jane Leong (Director and Chief Operating Officer, Australian Centre for AI in Medical Innovation) underlined that AI is creating real opportunities to accelerate clinical development. At Gadens, our Health and Life Sciences practice advises on the interface between AI and innovation on a daily basis.

This reflects the reality that AI is already deeply embedded across the health and life sciences ecosystem, supporting patients from research, clinical and product development through to preventative health, treatment and operational management. Indeed, a recent McKinsey survey found almost 50% of respondents in the healthcare sector had already implemented generative AI in their organisations, which McKinsey read as a sign that hesitation to use the technology is receding. In the same survey, administrative efficiency and clinical productivity were identified as the areas with the greatest potential for generative AI and multi-agent workflows in healthcare.

These diverse applications of the technology underscore both AI’s genuine potential to improve health outcomes and the importance of responsible design, deployment and oversight. Below, we set out the key legal, ethical and operational risks that can arise depending on architecture and integration decisions, in respect of risk-based use cases, and how operating in the health and life sciences context can compound those risks for organisations developing and deploying AI alike.

Risks

We see risks cropping up in three key areas across AI workflows – the architecture of the AI tool an organisation chooses to implement, the integration of that tool with other systems, and the context within which the integrated tool will be used, including the scope of likely use cases.

Architecture risks

The Federal Government’s October 2025 Guidance for AI Adoption identifies that AI tools can be either ‘general purpose’ AI systems (GPAI) or ‘narrow’ AI systems (Narrow AI). Although voluntary, this guidance offers a helpful framework for identifying broad risks across each category of tools.

GPAI systems are more flexible, trained to handle a broad range of tasks (like ChatGPT, Gemini, Claude and Copilot). However, this breadth and flexibility may pose a number of challenges, including in respect of:

By contrast, Narrow AI systems are more targeted, trained to perform specific tasks (like a tool that generates a risk rating or employment suitability decision, based on certain datapoints). These tools carry unique risks, including regarding:

Integration risks

Regardless of whether a system is better classified as GPAI or Narrow AI, the way that AI system is integrated into an organisation’s workflow can introduce further risks, including those flagged by health and life sciences sector regulators and peak bodies:

Contextual risks

The risks for the use of AI tools in the health and life sciences sector are compounded by the contexts the tools are used in. This includes the use of AI tools to support:

Developing and deploying AI in health and life sciences

Regulatory framework

Australia does not have an AI-specific regulatory framework for any sector. Rather, several existing mechanisms have been retro-fitted to apply with broad effect.

In particular:

Given that the rapid integration of AI across the sector has outpaced the development of a comprehensive regulatory framework, we anticipate that government and regulators will move to introduce sector-specific laws and regulations in the near term.

That expectation is consistent with broader community sentiment. A recent UK survey found almost 75% of the public believed government and regulators should oversee AI safety, and 88% considered it appropriate that they should have the power to halt the use of an AI tool where it poses a risk of serious harm to individuals.

We summarise the most recent industry standards and guidelines relevant to the health and life sciences sector below.

Privacy Act considerations

AI tools routinely ingest and process personal information – both during training and ordinary use. The Privacy Act regulates the collection, use and disclosure of such personal information generally, but applies additional restrictions for ‘sensitive information’ (such as health information and biometric templates) due to the unique harm individuals can experience when this information is misused.

Processing personal information via an AI tool – whether to summarise consultations, support analysis or aid in clinical decision-making – will typically constitute both a use of that information by the relevant organisation and a disclosure of it to a third-party AI provider. Organisations therefore need to handle these privacy risks with care, having regard to why the relevant personal information was collected – and therefore how it can be used and disclosed.

The Office of the Australian Information Commissioner (OAIC) has also been unambiguous that the Privacy Act applies to the collection, use, disclosure, storage and handling of personal information to train AI tools – including training of generative AI tools, and narrower machine learning models. To support this, the OAIC’s Guidance on privacy and developing and training generative AI models sets out baseline compliance requirements as well as best practice recommendations to support responsible AI development and training.

In particular, the OAIC emphasised the need for a ‘privacy by design’ approach, highlighting:

Many organisations may also look to rely on de-identified data to mitigate privacy risks, as de-identified information is not ‘personal information’. This is on the OAIC’s radar – the OAIC recently investigated I-MED Radiology Network Limited’s (I-MED) disclosures of patient data (including medical imaging scans from a range of modalities, such as X-rays, CT scans and ultrasounds) to train a diagnostic AI model, Annalise.ai. In its preliminary report, the OAIC made clear that the development, or fine-tuning, of AI models or systems is a ‘high privacy risk activity’ and de-identification procedures must be robust.

In this case, the OAIC found I-MED's processes to be particularly robust – including robust contractual controls on use, technical measures such as data segregation and hashing techniques and a ‘Data De-identification Policy and Approach’ to guide general activities. It is critical that organisations considering similar activities do not simply replicate I-MED’s example. Rather, organisations should ensure any privacy preserving measures are genuinely tailored to the context in which they are proposing to use personal information.

TG Act considerations

As with the Privacy Act, the TG Act is technology-agnostic. Its application to AI tools therefore turns on the intended purpose and use of the relevant AI tool. For example, AI tools may be regulated under the TG Act to the extent they either:

  1. are being brought to market as a standalone medical device (typically SaMD), where the manufacturer/developer intends the AI tool to be used for certain therapeutic uses, e.g. diagnosis, prevention, monitoring, prediction, treatment or alleviation of disease
  2. notwithstanding the use of the AI tool to develop another therapeutic good, operate as a medical device – to the extent the AI tool is used for investigation of the anatomy, or of a physiological or pathological process or state
  3. otherwise meet the definition of a therapeutic good.

AI tools may also draw attention from the Therapeutic Goods Administration (TGA) when used to support development of therapeutic goods (e.g. for data analysis, literature review, trial design, manufacturing modelling/optimisation) – including to ensure trial/study results are sufficiently verifiable, to satisfy the requirements for clinical evidence and dossier integrity, be GCP-compliant and comply with good medical practice.

Noting this is a complex space, the TGA has issued guidance on Artificial Intelligence (AI) and medical device software regulation, clarifying when a medical/clinical purpose would likely bring AI-enabled tools within scope of the ‘medical device’ definition under the TG Act.

For developers, sponsors and suppliers of AI tools in the health and life sciences space, this introduces a layer of regulatory complexity that sits alongside the deployment considerations discussed above, including:

Risk mitigation strategies

Core concepts

Regulators and peak bodies have articulated a set of core concepts to address the risks above and support the safe, effective and compliant use of AI in health and life sciences.

Mitigation StrategyExplanation
Icon-magnifying-glass-chartDue diligence

Organisations and practitioners should empower relevant stakeholders to develop a clear understanding of the risks and benefits of AI tools before deployment. This includes:

  • reviewing vendor documentation regarding how tools operate, are trained and are intended to be used
  • identifying known limitations and biases so they can be mitigated or otherwise risk-accepted
  • independently testing tools to confirm they are fit for purpose in the relevant context.
Icon-lock-tickSecurity

Given the sensitivity of health information, organisations should implement or uplift security frameworks to ensure they account for the added risk from implementing a given AI tool. This includes:

  • assessing an AI tool’s privacy compliance, data handling practices, security controls, incident response capabilities and recognised standards (e.g. ISO 27001)
  • implementing controls to address risks of secondary data use (including model training), unauthorised disclosure and increased cybersecurity exposure associated with AI integration.
Icon-eye-closedTransparency

Stakeholders should be appropriately informed where AI forms part of clinical decision-making, care delivery or research, including to understand any additional risks.

Disclosure should be proportionate to the materiality and risk of the relevant AI use case. Where personal or sensitive health information is processed, informed consent should be obtained and documented in accordance with legal and ethical obligations.

Icon-three-peopleGovernance

AI use should be embedded within existing governance frameworks, with clear allocation of accountability for use. This should include:

  • an inventory of AI tools and approved use cases
  • clinician/researcher training on safe and appropriate use and output review (particularly before outputs impact health outcomes)
  • guardrails to ensure AI supports, and does not replace, professional judgement, with clinicians/researchers retaining ultimate responsibility for outcomes (including care decisions).
Icon-documentRisk management

Ongoing monitoring of AI performance is essential. Organisations should implement processes to identify and manage adverse incidents, near misses and broader model degradation.

Clear escalation and reporting processes should support this (both internally and to relevant regulators) to strengthen accountability and continuous improvement.


Internal guardrails

Internal guardrails translate these core concepts into practice when an organisation is developing or procuring AI tools. A cohesive approach ensures key risks are visible to all relevant stakeholders and managed consistently.

We recommend:

Vendor management

Organisations will engage a number of vendors, regardless of whether they are developing or procuring an AI system. For example, developers may engage third party cloud service providers, datacentres and software developers to ensure the organisation builds a system that can function as expected. Organisations procuring AI will generally engage the developing organisation itself, as well as others such as consultants (or lawyers!) to assist in transitioning key systems.

Vendors of each kind should be managed closely to mitigate risks, particularly through:

Overlap with employment law

Increased AI adoption in healthcare is set to significantly shape the sector’s workforce. That change is likely to be at pace, leaving employers to grapple with workforce implications quickly but compliantly.

The full extent and impact are yet to be determined as AI tools continue to be developed and evolved. However, apprehension about the anticipated impact on jobs and people has seen the government start to think about how to deal with the employment implications that are currently foreseeable. At the recent National Labor party’s conference, the party announced that it would establish the ‘Fair AI Taskforce’ to provide a forum for unions and workers to have a say about AI impacts in the workplace. While not a legislative reform, the announcement signals the government’s priority on workplace impacts of AI adoption as it develops its legislative response and policies.

One area that has already been the focus of attention is worker safety and how to mitigate against safety risks arising from AI related technological change. The New South Wales government has introduced reforms to its safety legislation to create specific employer duties that mitigate against risks arising from ‘digital work systems’. This includes changes to increase workloads, monitoring, performance tracking and surveillance of workers. It is likely that other states will also start to consider if additional duties and obligations are required to deal with unique risks arising from AI adoption.

Where the changing nature of work to adopt AI efficiencies and automation results in workforce structural changes (and reductions in some cases), the requirement to consult and effectively manage change will arise. This will include legal requirements from awards and enterprise agreements, and it can be expected that unions will seek enhanced consultation measures to deal with the unique changes associated with AI adoption. Unions may also seek earlier consultation rights before the decision about AI related change is made, and employers may need to prepare for those claims in bargaining.

Healthcare employers should start planning for workforce impacts, including planning how consultation and implementation will be managed. The changes may arrive quickly and leave those unprepared facing compliance risks and disputation.

The implications of AI advancements on surveillance and monitoring capability in the workplace is also likely to be the subject of legislative intervention. Current surveillance and privacy protections in employment are unlikely to adequately protect against worker surveillance and performance monitoring. It should be expected that unions will advocate for stronger employee protections, including through enterprise bargaining.

Workforce impact is inevitable as AI adoption increases, and the impact for healthcare employers will likely be significant in the coming years.


Where to next?

Keeping pace with an emerging technology is a genuine and ongoing challenge, particularly in a sector where the stakes – for patient safety, clinical integrity and regulatory compliance – are especially high.

Our team frequently advises organisations in the health and life sciences sector on how to manage AI responsibly in privacy, cybersecurity, governance, regulatory and employment matters. Please feel free to get in touch to discuss your organisation’s needs.


Industry guidance and standards

Icon-people-arrowsRegulator/peak bodyIcon-pencil-paperInstrumenticon-newspaperDateicon-newspaperSummaryicon-people-screenWho does it apply to?
Australian Health Practitioner Regulation agencyGuidance – Meeting your professional obligations when using AI in healthcareLast updated 22 August 2024Regulatory guidance clarifying how existing professional obligations in the National Boards’ codes of conduct apply when practitioners use AI in their practice.
All registered health practitioners across all 16 nationally regulated health professions in Australia.
Therapeutic Goods AdministrationGuidance – Artificial intelligence (AI) and medical device software regulationLast updated 5 February 2026Regulatory guidance explaining when and how AI-enabled software falls within the existing medical device regulatory framework under the Therapeutic Goods Act 1989 (Cth).
Suppliers of AI-enabled software products that may meet the definition of a medical device.
Medical Technology Association of Australia / Medical Software Industry AssociationIndustry code – Artificial Intelligence Governance Code1 December 2025A voluntary, self-regulatory instrument that sets minimum quality standards for organisational governance of AI systems used in the healthcare context.

MTAA and MSIA member organisations that supply AI systems for use in the healthcare context.

Australian Commission on Safety and Quality in HealthcareGuidance – AI Clinical Use GuideAugust 2025A practical guidance to support clinicians in using AI tools safely and responsibly in patient care.Clinicians using AI tools in clinical practice.
Royal Australian College of General PractitionersGuidance – Conversational artificial intelligence (AI)Last updated 16 September 2025An advisory resource designed to help general practitioners assess the potential advantages and disadvantages of using conversational AI in their practices.General practitioners.

Information for this table was last updated on Tuesday, 14 July 2026.

Download the industry guidance and standards

This update does not constitute legal advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. You should seek legal or other professional advice before acting or relying on any of the content.