Australia Raises Alarm Over AI Scribes Listening In on Doctor Visits
Federal health officials are warning that AI tools recording patient conversations in GP clinics may pose serious privacy risks, and regulators are now weighing whether new rules are needed.

Key points
- Australia's federal health department has formally raised concerns about AI scribe tools being used in GP surgeries.
- AI scribes, software that records and summarises doctor-patient conversations, have surged in popularity over the past 18 months.
- Australia's health regulator is actively considering whether safeguards around the technology are necessary.
- No national rules governing AI scribes in clinical settings currently exist in Australia.
Every day, patients walk into their GP's office and talk about their health, sometimes the most private details of their lives. A growing number of those conversations are now being captured automatically by artificial intelligence software known as an AI scribe, which listens in real time, turns speech into text, and generates a ready-made clinical note. Use has boomed across Australian clinics in the past 18 months.
Now the federal health department has raised concerns, and the health regulator is examining whether guardrails, rules to limit risk, are needed. Guardian Australia first reported the intervention.
What does this mean for patients?
Patients may not know their conversation is being recorded, where that recording goes, or who can access it later. That matters when the conversation covers a mental health diagnosis, a sexual health concern, or a terminal illness.
Most AI scribe products process audio on remote servers, often run by overseas companies. Once a recording leaves the clinic, Australian privacy law may offer only partial protection, and cross-border enforcement is hard. Doctors carry professional obligations to inform patients and obtain consent, but no single national standard defines what that consent must look like, how data must be stored, or how long it can be kept. It's a problem Threat Vectr has tracked in adjacent corners of Australian healthcare: our 4 July story found that Monash IVF and Medmate were ruled to have broken the law by sending sensitive patient data to social media platforms without consent.
The concern isn't that doctors are acting in bad faith. The technology moved faster than the rules did.
From a security standpoint, audio recordings and clinical summaries are high-value data. A database of GP transcripts would be exactly the kind of trove that criminal groups running ransomware attacks, where malicious software locks or steals files to extract a payment, actively seek out. Health records fetch a premium on criminal marketplaces because they can't be cancelled like a credit card: a stolen medical history follows a person for life.
Should you worry?
Ask your doctor directly if you notice a recording device or unfamiliar software running during your visit. What is it, and how is your data handled? Declining recording is your right and cannot affect your care.
Australia's health regulator hasn't announced specific rules yet. Until it does, patients and clinics sit in a grey zone, and that gap is exactly what privacy advocates and security researchers are watching.



