Skip to main contentSkip to footer

How to Tell Whether an AI Writing Tool Is Safe for Your Practice

Every marketing tool sold into Australian healthcare now says it is AHPRA compliant. Almost none of them explain what they mean by it, and there is no agreed definition to hold them to.

That is a problem, because the phrase is doing a lot of work. It is the difference between a tool that will refuse to write something and a tool that will write it beautifully and leave you carrying the consequence. Those two products look identical in a demo.

We have been asking vendors the same questions for a while now, and there are four that separate them. None of them are technical. You can ask all four in a ten minute call and you will know more than most buyers do after a month of trials.

1. Where do your compliance rules live, and when are they applied?

There are two architectures behind every claim of compliance, and only one of them can actually stop a breach.

In the first, the tool looks the rules up. It has been told to consider the advertising guidelines, it may even have been given a copy, and it does its best. In the second, the rules are inside the program and the output has to satisfy them before it is released.

Our co founder Anthony Middlemiss put the distinction plainly on the podcast:

Those latest compliance docs are built into the program, so they have to be used. And those guardrails are incredibly important. We can’t afford hallucinations, where it just makes stuff up because it thinks it’s compliant.

A tool that looks the rules up produces content and hopes. A tool that has the rules inside it can refuse. Ask which one you are being sold, and ask specifically when in the process the check happens. If the answer is vague, or if compliance is described as something the tool “considers”, you are buying the first kind.

The follow up worth asking: what happens when the output fails the check? A tool with no answer to that has no check.

2. If it is instant, what did it check?

This is the question that reverses a selling point, which is why it is useful.

Speed is the headline metric in this entire category. Instant blog posts, instant social, instant email. It is the first thing on every landing page, and for unregulated marketing it is a reasonable thing to want.

For regulated marketing it is a warning.

Content that appears instantly was produced in one pass and released. Nothing was rejected, because rejecting something and generating a replacement takes time. Anthony described the loop behind Trilbii AI as prompt, then a check on the output, then a rejection and a regeneration if it fails, running until it passes. The consequence is that generation takes thirty seconds to a minute.

We had quietly filed that as a limitation until he explained it on camera. It is not. It is the only observable evidence that anything is being checked at all.

So ask how long generation takes, and if the answer is instant, ask what was verified in that time. You are not looking for slowness for its own sake. You are looking for a vendor who can tell you what the delay is buying.

3. Two data questions, not one

Vendors answer one of these and let you assume the other. They are different protections and you need both.

Can another practice see our data? This is about isolation. The technical answer you want is that each practice sits in its own tenancy in the database, so nothing can leak sideways between clients. It is a structural property, not a policy, and a vendor with it will describe it structurally.

Does our data train your models? This is a completely different question and a good answer to the first tells you nothing about it. The strongest possible answer is that practice data is never sent to the model in the first place. Anthony’s version:

With the LLMs, we’re pointing the LLMs at the content creation, not at their data. So their data stays safe.

Notice what that does. It is not a promise about how the data is handled once the model has it. It is an architecture in which the model does not receive it.

Ask both. Write down both answers. A vendor who conflates them either has not thought about it or is hoping you will not.

4. Where is the data physically stored?

Ask at country level and accept nothing less specific.

For anything touching patient data in Australia, the answer has to be Australia. That is not a preference and it is not a nice to have.

You want a named location, not a region and not a vendor name. Trilbii AI runs on Australian servers, currently two in Sydney, with Perth and Melbourne as later additions. That is the shape of answer to hold out for: a country, a city, a number.

“Enterprise grade cloud infrastructure” is not an answer to this question. Neither is naming the cloud provider, because every major provider has regions all over the world and the one your data sits in is a configuration choice the vendor made.

What none of this tells you

These four questions tell you whether a tool is architecturally capable of being safe. They do not tell you whether it writes anything worth publishing, and they do not transfer your liability.

That last part matters. Whatever a tool produces, the advertising is yours. The maximum penalty for unlawful advertising of a regulated health service is $60,000 per offence for an individual and $120,000 for a body corporate, and it lands on the practice, not on the software company. No vendor answer changes that, which is why the questions are worth asking properly rather than politely.

Do this before your next demo

Write the four questions on one page and take them into the call. Ask them before you look at the interface, because once you are watching content appear on a screen the conversation moves to features and never comes back.

Then ask the vendor to put the answers in writing. Not a marketing page, an email. Every vendor who can answer these will be happy to. The ones who cannot will move you back to the demo.

We should be straight about our position here. Trilbii AI is one of the tools in this category, and we have used it as the worked example throughout because we know exactly how it answers these four. These questions are not written to make us win. If a competitor gives you better answers than we do, buy theirs. What matters is that somebody in this market starts asking, because at the moment the phrase AHPRA compliant is being defined by whoever says it loudest.

Anthony Middlemiss is co founder and Head of Customer Success at Trilbii AI. He ran allied health practices for around twenty years before returning to IT and completing post graduate study in AI and machine learning. The full conversation is on AI Your Practice.

Related: what an AHPRA advertising breach actually costs, and why it is not one fine.

Source for the penalty figures: AHPRA, Advertising and the law.

Frequently asked questions

No. It depends entirely on whether the compliance rules are built into the system or looked up afterwards, and on whether the output is checked before it is released.

Because the output is being checked and regenerated until it passes. Instant generation means nothing was rejected.

Only if the vendor has not isolated practices from each other. Ask whether each practice sits in its own tenancy in the database.

Ask specifically whether practice data is sent to the model at all, rather than whether it is stored securely. Those are different answers.

For anything touching patient data in Australia, it should be stored in Australia. Ask for a country and a city, not a region or a cloud provider name.

The practice. The advertising is yours regardless of what produced it, which is why the architecture questions are worth asking before you buy.

Watch it again

The full conversation is on YouTube: watch it here.

Anthony Middlemiss, co founder of Trilbii AI

We can’t afford hallucinations, where it just makes stuff up because it thinks it’s compliant.

Anthony Middlemiss, Trilbii AI

From the AI Your Practice podcast with Carolyn S Dean.

Early access. Limited pilot spaces