Doug Hammond : How to Use AI Securely Without Risking Your Data | AI, Cybersecurity & Data Sovereignty

AI, Data Sovereignty and Cybersecurity in the Care Sector

Artificial intelligence is creating new opportunities across healthcare, aged care, disability support and childcare. It can help organisations work more efficiently, improve decision-making and reduce the administrative burden placed on staff.

However, the benefits of AI also come with important questions.

What information is being shared with AI tools? Where is that information stored? Who can access it? And how can care providers protect sensitive personal data while still allowing their teams to benefit from new technology?

For large care organisations, data sovereignty and cybersecurity can no longer be treated as purely technical concerns. They are essential parts of governance, risk management and responsible service delivery.

Why Data Sovereignty Matters in Care

Care providers hold significant amounts of personal and sensitive information. This may include health records, disability support plans, financial details, family information, behavioural notes and other confidential data.

Data sovereignty refers to the principle that information is subject to the laws and regulations of the country in which it is stored or processed.

For Australian care organisations, this creates several important considerations:

  • Where is organisational data physically stored?
  • Is sensitive information transferred outside Australia?
  • Which privacy laws apply to the data?
  • Can third-party technology providers access or reuse the information?
  • What happens to information entered into an AI platform?
  • Can the organisation maintain control over its data throughout the process?

These questions become particularly important when staff use publicly available AI tools without formal approval or oversight.

The Risks of Sharing Sensitive Data With AI

One of the greatest risks associated with AI is uncertainty about what happens to information after it has been entered into a system.

Employees may use AI to draft reports, summarise case notes, prepare emails or analyse information. While these tools can save time, entering confidential client or organisational data into an unapproved platform may create serious privacy and cybersecurity risks.

Sensitive information could be stored outside the organisation’s approved environment, processed in another country or retained under terms that do not meet the organisation’s governance requirements.

The risk is not always caused by malicious behaviour. In many cases, employees are simply trying to work more efficiently. This is why banning AI completely may not be the most effective response.

Watch the complete Podcast

Moving Beyond the “Department of No”

When new technology creates risk, the immediate reaction can be to block it. However, simply telling employees not to use AI may encourage unapproved or hidden use.

A more effective approach is to provide a safe and approved pathway.

Rather than saying no to teams that want to use AI, organisations can explain which platforms are approved, what information can be entered and how the tools should be used.

This allows the organisation to support innovation while maintaining appropriate security controls.

The goal should be to say:

“Yes, you can use these tools, but this is the secure and responsible way to use them.”

This approach helps build trust between cybersecurity teams, leadership and frontline staff. It also positions information security as an enabler of responsible innovation rather than a barrier to progress.

Classifying and Tagging Sensitive Information

A strong AI governance strategy begins with understanding the data an organisation holds.

Care providers should classify and tag sensitive information so they know:

  • What data is confidential
  • Where the information is stored
  • Who is authorised to access it
  • Which systems are permitted to process it
  • Whether it can be shared with an AI tool
  • What controls must be applied

Data classification can help organisations detect when sensitive information is being uploaded into an unapproved platform. Security systems may then warn the employee, restrict the activity or block the transfer entirely.

Without effective classification, it is difficult to protect information consistently because the organisation may not know where its most sensitive data is located.

Creating an Approved AI Pathway

Organisations can reduce risk by providing employees with approved AI tools operating within a controlled technology environment.

For example, an enterprise AI solution may allow information to remain within the organisation’s existing Microsoft tenancy or another approved cloud environment. This can give the organisation greater control over access, storage, auditing and security.

An approved AI pathway should include:

  • Clear user access controls
  • Australian data storage where required
  • Data loss prevention measures
  • Logging and monitoring
  • Restrictions on sensitive information
  • Regular security assessments
  • Staff education and training
  • Clear accountability for AI use

Technology alone is not enough. Employees must understand why the controls exist and how to use the approved system correctly.

Keeping Australian Data in Australian Data Centres

For many Australian care providers, retaining information within Australian data centres is an important part of their data sovereignty strategy.

Local data storage may help organisations maintain greater clarity around legal obligations, regulatory requirements and access to information.

However, organisations should not assume that selecting an Australian data centre automatically resolves every privacy concern. They must also examine how data is processed, backed up, accessed and managed by technology providers.

Important questions include:

  • Is the information processed only in Australia?
  • Can overseas support teams access the system?
  • Where are backups stored?
  • Does the provider use organisational data to train its AI models?
  • What happens to the data when a contract ends?
  • Can information be permanently deleted when required?

These details should be assessed before an AI platform is approved.

Building an Effective Data Management Plan

A strong data management plan should address the entire lifecycle of information, from collection and use to storage, sharing, retention and deletion.

Care organisations should consider including the following areas in their plan.

Data Ownership

The organisation should clearly identify who is responsible for different types of data and who has authority to approve its use.

Data Classification

Information should be categorised according to its sensitivity, value and regulatory requirements.

Access Management

Employees should only have access to the information required for their role. Access permissions should be reviewed regularly.

Approved Technology

The organisation should maintain a clear list of approved AI platforms, cloud services and data-processing tools.

Data Residency and Sovereignty

Policies should explain where information may be stored and processed, including any requirements for Australian data residency.

Cybersecurity Controls

Encryption, multifactor authentication, monitoring, data loss prevention and incident response processes should form part of the overall strategy.

Retention and Disposal

Organisations should determine how long different types of information must be retained and how it will be securely deleted.

Employee Education

Staff should receive practical guidance on what information they can and cannot enter into AI tools.

Third-Party Risk

Technology providers should be assessed carefully before they are given access to sensitive information.

Balancing Innovation With Responsibility

AI can deliver meaningful benefits to care organisations, but those benefits must not come at the expense of privacy, trust or safety.

The most effective organisations will not treat innovation and cybersecurity as opposing forces. They will build systems that allow both to work together.

This means providing employees with secure tools, establishing clear governance, classifying sensitive data and making responsible AI use easier than unapproved use.

When staff understand the rules and have access to safe technology, organisations can gain the benefits of AI while protecting the people whose information they hold.

The Future of AI Governance in the Care Sector

AI governance will become increasingly important as technology becomes more deeply embedded in care delivery and organisational operations.

Care providers will need to review their policies regularly, respond to new cybersecurity threats and ensure that their technology arrangements continue to meet Australian privacy and regulatory expectations.

Leadership teams must also recognise that AI governance is not solely the responsibility of the IT department. It requires input from executives, care professionals, legal teams, privacy specialists, risk managers and the people who receive services.

By bringing these perspectives together, organisations can create an approach that protects sensitive information while enabling better services and more efficient ways of working.

Continue the Conversation at the National Care Sectors Conference

These important conversations about AI, cybersecurity, data governance and the future of care will continue at the National Care Sectors Conference: NDIS, Aged Care & Childcare on 28 August 2026.

Join sector leaders, care professionals, providers and decision-makers for a moving and inspiring event focused on the challenges, opportunities and ideas shaping Australia’s care sectors.

Be part of the conversation, connect with people working across NDIS, aged care and childcare, and explore how technology, governance and human-centred leadership can help build a safer and stronger care system.

Scroll to Top