Recently the Prime Minister of Australia announced an Office of AI to be established within the Department of Prime Minister and Cabinet. Healthcare was not included, nor was the health data already being processed by AI systems across the country.
In his speech, the Prime Minister highlighted that the Government would introduce a set of standards for AI use in Australia. These are expected in draft early 2027 after the government considers the proposed announcement in August. In the meantime, AI roars ahead and there is no telling where we will be by next year.
In the statement, the Prime Minister focussed on data centre establishment and protecting copyright for Australian artists and media. Then the Australian consumer. No mention of healthcare or any industry sectors, or patient data.
Leaders in healthcare have voiced their concerns regarding governance, liability, feasibility and data protections in response to the Government announcement.
Governments and agencies are setting up multiple AI committees and sub-committees with parallel work underway in the non-government sector. This is leading to fragmentation of policy and application across a multitude of industries, not just healthcare.
AI has already been deployed without adequate monitoring of what it actually does in practice.
Listening to marketing chatter, you would believe that every practice needs AI in their clinical practice immediately. Clinical note taking – done by AI. Filling in forms – done by AI. Diagnosis of imaging – done by AI. Radiologists? Entire career trajectory pronounced DOA.
The proof of day-to-day application of these functions is missing, it’s presumed to be awesome, correct at all times, and another billion dollar opportunity.
AI is already widely implemented in Australian industry and business including healthcare. The horse has not only bolted, it has picked up a pack of brumbies and are tearing up the mountain, laying claims and building houses.
The clinical AI conversation cannot wait for standards in 2027. Neither can the administrative AI already deployed in healthcare billing and payment systems. Both are live. Both are consequential. Both are ungoverned.
Health data is among the most sensitive personal information that exists. When AI systems are deployed in healthcare, clinical or administrative, they process that data. The question of what those models do with the information, how it is stored, who has access, whether it leaves Australian jurisdiction and what happens when there is a breach is a legitimate governance question that the Office of AI has not addressed.

Every Medicare transaction contains a patient’s identity, their diagnosis, the procedure performed, the provider who treated them, their insurance status and the financial details of their care. Multiply that by 650 million transactions annually and you have the largest concentration of sensitive personal data in Australia which is processed digitally, touched by AI systems, and governed by frameworks designed before AI existed. Patients have a right to know when AI is processing their health data, what it does with that information, whether it leaves Australian jurisdiction and who is accountable if it is wrong. Currently they have no such assurance.
The AI systems processing Australian health data are not all Australian. The models being trained on patterns in Australian billing, diagnosis and treatment data may be owned, operated and housed overseas. Australia has no mandatory requirement for health administrative AI to be sovereign, transparent or subject to Australian law. The Croakey series on AI governance raised the spectre of health data colonialism, patient data collected under the banner of efficiency, processed by foreign models, generating commercial value for overseas interests. Australian health data is among the most valuable data in the world. Its governance cannot be an afterthought.
The Royal Australasian College of Physicians has already warned that regulatory gaps in clinical AI leave doctors exposed to liability for patient harm they did not cause. Nobody has asked the equivalent question about administrative AI.
When a private health fund’s AI system incorrectly rejects a legitimate claim who is accountable? When AI trained on ambiguous MBS rules generates systematic errors across thousands of claims simultaneously, who answers for the consequences?
Governance of AI in healthcare cannot begin and end at the clinical layer. The financial infrastructure that makes clinical care possible deserves the same scrutiny, the same transparency obligations and the same accountability frameworks. Without it, 650 million health data transactions will continue to flow through ungoverned systems.
The Office of AI’s mandate must include healthcare, not as an afterthought but as a priority. Within healthcare, it must look beyond the clinical layer to the financial infrastructure that makes clinical care possible and the safety of patient data.
AI in healthcare is not a hot topic for future consideration. It is a cold reality operating right now.
