Skip to content

Guides

Is it legal for an AI to answer your business calls in Australia?

Yes — no Australian law prohibits an AI answering your inbound business calls. Your real obligations sit in existing law: privacy (the APPs), call-recording rules, and consumer law.

In short: yes — it is legal for an AI to answer your inbound business calls in Australia. There is no law against it and no licence required. Your actual obligations come from laws that already applied to your phone before AI arrived: the Privacy Act and its Australian Privacy Principles, state rules on call recording, and consumer law’s ban on misleading conduct. Meet those and you’re on solid ground.

This question comes up on almost every audit call, usually phrased as “are we even allowed to do this?” — so here’s the plain-English version. One caveat up front: I run AI4SMB, an Australian AI automation agency, and I’ve spent 32 years in business IT — but I’m not a lawyer, and this is general information, not legal advice for your situation.

Which laws actually apply?

As at the time of writing, Australia has no AI-specific statute governing something like an AI receptionist. What the government publishes instead is guidance — the OAIC’s privacy guidance on commercial AI products, and the ai.gov.au safe-and-responsible-AI materials — layered on top of existing law. The laws doing the real work are:

  • The Privacy Act 1988 and the Australian Privacy Principles (APPs) — how you collect, use, store and disclose the personal information callers give you.
  • State and territory surveillance and listening-devices laws — whether and how calls can be recorded.
  • The Australian Consumer Law — no misleading or deceptive conduct, which covers what your AI says and how it presents itself.
  • The Do Not Call Register Act — but note, this governs outbound telemarketing. More below.

Do we have to tell callers they’re talking to an AI?

There’s no statute that says “an AI on the phone must announce itself” — but transparency is where every piece of official guidance points, and it’s where we’d tell you to land regardless. The OAIC’s guidance on commercial AI products says public-facing AI tools should be “clearly identified as such” to the people interacting with them, and that businesses should update privacy policies with “clear and transparent information about their use of AI”.

Beyond compliance, there’s a consumer-law angle: an AI that actively pretends to be human when asked is flirting with misleading conduct. And practically? Callers handle “you’re speaking with the practice’s assistant” fine. What they don’t forgive is feeling tricked. Every receptionist we configure discloses that it’s an assistant.

Can the calls be recorded?

Recording is the part with real state-by-state variation. Surveillance and listening-devices legislation differs across Australian states and territories — some permit a party to record their own conversations, others require all parties to consent to recording a private conversation. The practice that satisfies the strictest jurisdictions is the one you already hear everywhere: announce it at the start of the call (“this call may be recorded…”). A caller who stays on the line after a clear announcement is taken to have consented.

If your AI receptionist produces recordings or transcripts — most do, and they’re genuinely useful — announce it, and then treat those recordings as personal information under the APPs: know where they’re stored, who can access them, and when they’re deleted.

What if we handle health information?

Then the bar is higher, and here’s the detail many practices miss: the Privacy Act’s small-business exemption does not apply to health service providers. A dental or medical practice is covered by the APPs regardless of turnover. Health information is “sensitive information” under the Act — the strictest category.

The OAIC’s AI guidance is blunt on the adjacent risk: it recommends organisations “do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”. A receptionist stack built for a clinic needs to be architected for that — controlled infrastructure, documented data flows, and ideally an option to keep voice data onshore or fully self-hosted. That’s exactly why we offer a self-hosted option for clinics and dental practices, and document data handling in writing at onboarding.

Doesn’t the Do Not Call Register ban robocalls?

It regulates outbound calls — telemarketing and research calls to numbers on the register, including automated ones. An AI answering your inbound calls is not telemarketing and isn’t what that regime covers. The distinction matters because “robocall” headlines make businesses assume voice AI is restricted generally. It isn’t: the caller rang you.

(If you later want the AI making outbound calls — reminders, callbacks, follow-ups — that’s a different conversation with its own rules, and consent becomes the central question. Handle it as a separate project.)

What could actually get a business in trouble?

The realistic risks aren’t “using AI” — they’re the ordinary failures, automated:

  1. Recording without announcing it in a state that requires consent.
  2. An AI that misleads — pretending to be human, or confidently giving wrong answers about your prices, services or availability. Under the APPs you’re expected to take reasonable steps to keep the personal information you use accurate; under consumer law, what your systems tell customers is on you. This is why an unsupervised, untested bot is a liability — and why we run ours with monitoring, transcripts and explicit hand-off rules rather than set-and-forget.
  3. Sloppy data handling — recordings on some overseas platform nobody vetted, no privacy-policy mention of AI, no deletion story. All fixable with boring, documented operations.

The practical checklist

  • Disclose that it’s an AI assistant; never let it claim to be human.
  • Announce recording at the start of every recorded call.
  • Update your privacy policy to mention AI call handling and where data lives.
  • Know your data flow: storage location, access, retention, deletion.
  • Health providers: assume full APP obligations apply to you — they do.
  • Keep a human escalation path, and review transcripts — accuracy is your job.

None of this is exotic. It’s the same discipline as any other system that touches customer data — which is exactly how an AI receptionist should be run: as infrastructure, not a gadget. If you want your specific setup sanity-checked, that’s part of what an audit call is for.

Sources: OAIC, Guidance on privacy and the use of commercially available AI products; ai.gov.au — AI and Australian law; Do Not Call Register — industry standards. General information only — get advice on your specific circumstances.

Not sure where AI actually pays back?

Start with an AI Opportunity Audit. You get a prioritised map of where automation earns its keep in your business — and a roadmap you own, whether you build it with us or not.