Privacy Act expectations for AI
The Information Privacy Principles apply to personal information in training data, prompts and outputs. In practice that means a privacy impact assessment before launch, telling people when they are dealing with AI, checking accuracy before AI output is used to make decisions about someone and being able to answer access requests about information the system holds. This is general information, not legal advice.
Technically we support this with redaction of personal details before text reaches a model, logging of prompts and responses, configurable retention and hosting choices that avoid unnecessary offshore disclosure.
