Artificial Intelligence (AI) Policy
Positive Moods is committed to delivering safe, ethical and person-centred Behaviour Support services. As part of our continuous improvement approach, we use Artificial Intelligence (AI) in limited, controlled and transparent ways to support the quality, clarity and efficiency of our documentation.
This policy explains how AI is used within Positive Moods, how we protect participant information, and the safeguards we apply to ensure AI supports — but never replaces — professional judgement, evidence-based practice and participant choice.
Our Approach to AI
Positive Moods recognises that the NDIS Quality and Safeguards Commission does not endorse or approve the use of AI tools in the development or review of Behaviour Support Plans. AI is not prohibited, but any use must comply with Positive Moods’ legal, ethical and registration obligations, including privacy, consultation, human oversight and clinical judgement requirements.
AI is used only as a drafting, summarising, quality-checking and administrative support tool. AI must never be treated as an approved clinical tool, a decision maker, or a substitute for practitioner assessment, evidence-informed practice, participant consultation or professional accountability.
All final Behaviour Support Plans are written, reviewed and approved by qualified Behaviour Support Practitioners.
Any AI-assisted content must be checked against the participant’s circumstances, current evidence, practitioner observations, consultation feedback and relevant NDIS requirements before it is included in a plan.
Approved AI Tools
Positive Moods uses two approved systems:
Splose AI
Splose applies proactive cybersecurity measures to protect healthcare and NDIS practice data. Its published security information states that data is encrypted in transit using SSL/TLS and encrypted at rest using industry-standard AES-256 encryption. For Australian users, Splose states that data is stored in Australia, with encrypted hourly backups stored securely off-site and data stored redundantly in AWS data centres to support availability.
Splose also provides workspace-level security controls, including a dedicated workspace URL, strong password requirements, optional two-factor authentication, custom roles and permissions, activity change logs, session management and Single Sign-On using SAML. These settings support Positive Moods to limit access to authorised users, separate access by role, monitor changes and strengthen account security.
Splose’s security and privacy materials also refer to compliance with the Australian Privacy Principles and GDPR, and its AI privacy information states that client data is not retained or used for AI model training through its OpenAI business arrangements. Positive Moods still applies its own safeguards when using Splose AI, including de-identification, participant choice, practitioner review and compliance checks against NDIS Commission expectations.
Used to assist with:
Positive Moods Bespoke PBSP AI Application
This is a bespoke application built by Positive Moods using Claude Code. It is a non-generative AI application: it does not independently create new clinical decisions, determine supports, justify restrictive practices or replace practitioner judgement. Instead, it supports structured review and organisation of de-identified information according to predefined workflows and practitioner-controlled inputs.
Claude Code was used as a development environment and coding assistant for building the application. Anthropic’s published Claude Code security information describes a permission-based architecture, read-only defaults in manual mode, configurable organisation permissions, sandboxing options, working-directory boundaries, security review features and human approval for production changes. These controls support safer software development; however, Positive Moods remains responsible for reviewing, testing and approving the application before use.
Used to assist with:
Both systems operate under strict de-identification and privacy controls.
Protecting Participant Privacy
Positive Moods applies strict safeguards to ensure participant information is protected at all times.
We do not enter personal or identifiable participant information into AI systems. This includes names, addresses, dates of birth, contact details, plan numbers, provider details, unique life events, health information or any combination of information that could reasonably identify a participant. We do not use AI tools that store, train on, reuse or disclose participant information without appropriate safeguards.
All information entered into approved AI tools must be appropriately de-identified before use. Staff must consider whether details could identify a person either directly or indirectly, including through contextual clues, rare events, locations, service arrangements or combinations of information.
AI must not be used where the storage location, security controls, data retention arrangements or overseas processing arrangements are unclear or inconsistent with Positive Moods’ privacy and information security obligations.
What AI Never Does at Positive Moods
AI is never used to:
- make decisions about supports or strategies
- determine or justify restrictive practices
- predict behaviour
- diagnose conditions
- replace practitioner consultation
- store or train on participant information
- generate incident reports containing identifiable information
AI supports our practitioners — it does not replace them.
Participant Choice and Control
We inform participants when AI may be used to assist with drafting parts of their Behaviour Support Plan. Participants may request that AI not be used. We will always respect this choice without any impact on service quality.
Behaviour Support Plans must remain person-centred, evidence-informed, reflective of the participant’s needs, and developed in consultation with the participant, their family, carers, guardian, NDIS providers and support workers as appropriate.
Staff Responsibilities
All Positive Moods staff using AI tools must:
- complete annual AI governance and privacy training
- follow de-identification requirements
- review and validate all AI-generated content
- ensure documentation remains person-centred, trauma-informed and culturally safe
- document how AI-assisted content was reviewed, validated and adapted to the participant’s needs
- escalate any suspected privacy, accuracy, bias, safety or compliance concern before AI-assisted content is used
Quality and Safety
Positive Moods maintains strong governance over AI use, including:
- quarterly audits of AI-assisted BSPs
- monitoring accuracy, bias and safety
- maintaining an AI risk register
- reviewing AI systems annually
- updating this policy when technology or regulation changes
- checking AI use against Australia’s AI Ethics Principles and current NDIS Commission guidance
Legal and Guidance Framework
- National Disability Insurance Scheme Act 2013
- NDIS Code of Conduct Rules 2018, including the obligation to respect participant privacy
- NDIS Provider Registration and Practice Standards Rules 2018
- NDIS Restrictive Practices and Behaviour Support Rules 2018
- Australian Privacy Principles
- Australia’s AI Ethics Principles
- NDIS Commission position statement: Use of artificial intelligence in the development of behaviour support plans, February 2026
Additional Resources
Our Commitment
Positive Moods uses AI responsibly, ethically and transparently. AI strengthens our documentation, but your practitioner remains responsible for your plan. Your rights, dignity and privacy are always our highest priority.
If you have questions about how we use AI, our team is here to help — contact us.