Generic vendor privacy assessments couldn't have flagged what happened at MediSecure or Latitude Financial — and that's the problem. This piece uses real breach and enforcement outcomes to show why a signed-off checklist isn't AI privacy control, and sets out the questions every organisation should be asking its AI vendors now.
A NSW Reconstruction Authority contractor uploaded flood victims' personal data to ChatGPT in 2025, echoing Samsung's 2023 source-code leak. New 2026 survey data shows most staff still use unsanctioned AI tools — here's what boards should do about it.