
When AI enters your practice
Representing over half of all doctors in Australia, Avant probably has a better sense of the emerging issues than any other medical defence organisation. Our risk advisory experts are coming across increasing numbers of situations that may cause concern. Here are some recommendations on how to handle these and minimise the risk of falling foul of privacy regulations, or being held accountable for AI-based decisions you were not responsible for.
Scenario 1: The patient who already 'knows' what’s wrong with them
Situation
Your patient arrives at their appointment having consulted an AI health tool: a symptom checker, a chatbot, or a consumer diagnostic app. They're confident of the diagnosis they’ve been given, and even how it needs to be treated.
Risks
- After listening to your patient describe their symptoms, you also examine them. You don’t agree with the AI diagnosis and recommend a different treatment path. If the AI diagnosis later proves correct, you are at risk, both clinically and in terms of the patient relationship.
- Even where your diagnosis is sound, the patient may have unrealistic expectations about treatment. If you refer them for tests that confirm what the AI already told them, they may well express frustration, both at the expense they incurred and any delay in starting treatment.
- Patients anchored to an AI recommendation may be less receptive to your clinical reasoning. This could create friction and a risk that important advice is ignored.
Recommendation
Ask patients, early in the consultation, whether they’ve already used an AI tool or online resource to seek advice. This doesn't need to be adversarial; it's simply good history-taking in a world where patients increasingly arrive with information they have obtained online about their health.
Whether you agree or disagree with what the AI tool has suggested, explain your clinical reasoning clearly to the patient. If you have a different opinion, say why. If you think the AI diagnosis is valid, acknowledge that and explain the next steps.
Document everything in the patient record, including that the patient presented with an AI-generated opinion, what it said and how you responded. This protects you if the clinical picture changes later.
Scenario 2: The pre-screened patient
Situation
Some patients are now arriving at an appointment – particularly one using telehealth – having already completed a screening questionnaire or responded to prompts from a chatbot. These AI-powered ‘triage tools’ may be provided by your own practice or generated through a third party. The AI-generated notes that accompany the patient often summarise their responses.
Risks
- AI tools aren’t good at picking up the nuances in a patient’s answer or delving deeper if a response seems incomplete or inconsistent with the non-verbal information.
- AI-generated summaries may omit clinically relevant information the patient disclosed in the original interaction. If you rely on the summary rather than a thorough consultation, you may miss something important.
- It’s unclear whether the doctor is responsible for reviewing all information the patient initially provided to the AI screening tool, or only the summary it generated. This distinction is important and is not yet clearly settled.
Recommendation
Treat any AI-generated summary as a starting point, not a substitute for clinical assessment. Review what has been provided, but conduct your own thorough history-taking and document your findings independently.
Any information provided by the patient, whether to you, an AI tool, or both, that is relevant to their care, should be captured in the medical record. If you identify errors or omissions in an AI-generated summary, correct the errors by documenting in your medical record, and note that you have done so.
Where practices are using AI triage tools, ensure there is a clear protocol for how AI-generated outputs feed into the clinical encounter. Be clear about who is responsible for reviewing AI generated information.
Scenario 3: AI tools recording meetings outside patient consultations
Situation
AI meeting tools, often bundled into platforms like Microsoft Teams or Google Meet, can automatically record, transcribe and summarise meetings. This output is often useful and saves time. But when the meeting involves a discussion of a patient case, referral, or outcome, there can be significant privacy implications.
Risks
- Patient information discussed in the meeting may be captured by the transcription tool and stored on overseas servers, outside Australian privacy frameworks.
- Participants in the meeting, including external consultants or specialists, may not have consented to being recorded by the AI tool, and may not even know that the meeting is being recorded.
- Many of these tools are enabled by default as part of standard software packages. Users often don't realise they have accepted terms that permit this data capture.
Recommendation
Consent to AI recording cannot be assumed, even among colleagues. If a meeting is being recorded by any AI tool, all participants must be informed, and consent before it begins.
Check your practice's standard software suite carefully. Microsoft 365 and Google Workspace, for example, now include AI features that may be active by default. Review what has been enabled and ensure it aligns with your privacy obligations. If you are unsure, seek advice before proceeding.
Any recording of patient information needs to abide by the Privacy Act and Australian Privacy Principles. This legislation governs how personal and health information is collected, stored, used and disclosed.
Scenario 4: Reception staff using non-clinical AI tools
Situation
Practice staff, who are often under pressure to keep up with all the required paperwork, use tools like ChatGPT to help draft patient correspondence. This might include appointment reminders, test result follow-ups and referral letters.
Risks
- Patients have almost certainly not consented to their health information being used in this way.
- When patient information is entered into a non-clinical AI tool as part of a prompt, that data may be captured and stored overseas. It may then potentially be used to train or improve the AI model. Most of these tools are not configured for healthcare use and do not meet the requirements of Australian privacy law.
- Even if no harm results, a privacy breach of this kind carries regulatory and reputational consequences for the practice.
Recommendation
Practices must have a clear, written policy on which AI tools can be used by staff, and the categories of information that can and can’t be entered into them. Patient identifiable information and clinical details should never be entered into AI tools which are not approved for healthcare use.
This policy needs to be reinforced with staff regularly, including locums and temporary staff who may bring their own habits and assumptions to work at your practice.
Build a practice-wide AI policy
These scenarios share a common thread: the need for governance. AI is arriving in practices through multiple doors – brought in by patients, embedded in software or adopted informally by staff. Without a clear framework, the risks multiply.
Every practice needs a written policy that addresses which AI tools are approved for use, what information may be entered into them, and what safeguards are in place. This policy should be part of onboarding for all new staff, whether temporary or permanent. It should also be regularly revisited as the technology evolves.
Practices should conduct regular audits of which AI tools are actually in use, not just which ones have been officially sanctioned. Tabling this as a standing item in practice meetings is a practical way to stay across it.
Patients should be informed about where their data is used and what protections apply.
The hidden risk of AI adoption
The scenarios featured in this article are based on real situations. Certain information has been de-identified to preserve privacy and confidentiality. he cognitive and emotional load on doctors as they try to keep up with AI-assisted tools presents a growing concern.
When a doctor acts on, or does not act on, an AI recommendation, they carry the medico-legal risk of that decision. The responsibility has not shifted, it has simply become more complex.
At the same time, there is an emerging expectation that AI tools will allow doctors to see more patients, respond faster and handle greater administrative loads. The efficiency gains are real in places, but so is the pressure. Doctors should be conscious of this dynamic, and practices should resist the assumption that AI simply expands capacity without limit.
More information
Avant resource: Artificial Intelligence for medical documentation
This article was originally published in Connect magazine issue 26 in May 2026.
Scenarios in this article are based on Avant claims experience to date. Certain information has been deidentified to preserve privacy and confidentiality.
This publication is not comprehensive and does not constitute legal or medical advice. You should seek legal or other professional advice before relying on any content, and practise proper clinical decision making with regard to the individual circumstances. Persons implementing any recommendations contained in this publication must exercise their own independent skill or judgement or seek appropriate professional advice relevant to their own particular practice. Compliance with any recommendations will not in any way guarantee discharge of the duty of care owed to patients and others coming into contact with the health professional or practice. Avant is not responsible to you or anyone else for any loss suffered in connection with the use of this information. Information is only current at the date initially published.
The information in this publication does not constitute legal, financial, medical or other professional advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. Persons implementing any recommendations contained in this publication must exercise their own independent skill or judgement and seek appropriate professional advice relevant to their own particular circumstances. Compliance with any recommendations will not in any way guarantee discharge of the duty of care owed to patients and others coming into contact with the health professional or practice. Avant and its related entities are not responsible to any person for any loss suffered in connection with the use of this information. Information is only current at the date initially published.