What does the confidentiality duty require when a migration agent uses AI?
What does the Code of Conduct's confidentiality duty require when a registered migration agent uses AI tools in client work?
Section 35 of the Code of Conduct already answers the question. A migration agent must not disclose, or allow to be disclosed, to a third person any personal information relating to a client or former client, or a client's or former client's affairs, without the client's written consent — and the only exception is a disclosure required by a law of the Commonwealth, a State or a Territory. OMARA did not create a new AI confidentiality rule: it applied that existing duty to AI tools, and states that sharing a client's personal details using AI tools may be in breach of section 35.
OMARA's guidance on AI does not announce a new confidentiality rule. It points at one that already existed: the general duty of confidentiality in section 35 of the Code of Conduct. The provision is short, it was drafted before generative AI was in ordinary practice, and it is quoted in full below. Read against the way agents actually use AI tools, three parts of its text do the work — the prohibition on disclosure, the separate prohibition on allowing disclosure, and the condition of the client's written consent — with a single, narrow carve-out at the front.
1. The operative provision, in full
“Except as required by a law of the Commonwealth, a State or a Territory, a migration agent must not disclose, or allow to be disclosed, to a third person any personal information relating to: (a) a client or former client; or (b) a client’s or former client’s affairs; without the client’s written consent.”
That is the whole of the provision. OMARA's statements about AI and confidentiality are addressed to this text, and the text is where the requirements come from.
2. OMARA applied the existing duty rather than writing a new one
“RMAs continue to be responsible for providing professional and competent advice in line with their general ‘Duty of confidentiality’ under section 35 of the Code.”
Every load-bearing term in that sentence points backwards rather than forwards. The phrase “continue to be responsible” is a temporal statement: the duty did not begin with the guidance. “general ‘Duty of confidentiality’” names an existing duty rather than a new one. And “under section 35 of the Code” identifies the provision that creates it. The sentence that follows it is a warning about how the existing duty lands on a new tool:
“Be aware that sharing personal details of your client using AI tools may be in breach of section 35 of the Code.”
So the structure of the regulator's position on confidentiality is: section 35 is the rule; AI use is one of the ways an agent can breach it; there is no separate AI confidentiality instrument to consult, and no AI-specific consent regime to satisfy instead. That matters operationally, because it means the compliance question is not whether a given tool is covered by an AI policy. It is whether the disclosure the tool involves is permitted by section 35.
3. Limb one: disclosure to a third person
Section 35 is engaged by disclosure “to a third person”. The provision does not require publication, publicity, or a leak to the world at large, and it does not require the information to travel any further than the recipient. Providing client personal information to someone outside the agent–client relationship is the act it describes.
An AI platform is supplied and operated by a third person. On the words of the provision, entering a client's personal information into it is a disclosure to that person, whether the tool is a general-purpose chatbot, a transcription service, or a drafting assistant embedded in practice software. The prohibition is also not conditioned on harm: nothing in section 35 requires the recipient to misuse the information, or any damage to follow, before the prohibition is engaged.
4. Limb two: allowing disclosure
The prohibition is not confined to the agent's own keystrokes. Section 35 reads “must not disclose, or allow to be disclosed”, and the second limb reaches conduct that the agent permits but does not personally perform. A practice that leaves client information flowing into AI tools through staff, contractors, or an unmanaged workflow is within the words “allow to be disclosed” even if the agent never opens the tool.
This is the limb that closes the most common answer to a confidentiality concern — that the agent did not enter anything themselves. Under section 35, what the practice permits is the agent's responsibility. A disclosure by an employee or a member of the agent's business, tolerated as a matter of routine, is not outside the provision simply because the agent was not the one at the keyboard.
5. What the duty protects: the client, the former client, and their affairs
The object of the duty is “any personal information relating to” the client. Two paragraphs define that, and each one widens the reach of the provision:
- A client or former client. The duty survives the end of the engagement. An AI workflow pointed at a closed or historical file is dealing with a former client's personal information, and section 35 still speaks to it.
- A client's or former client's affairs. This is wider than information about the person. Working notes, file summaries, application histories, and the agent's own drafting about the matter relate to the client's affairs, as do details of a spouse, a child, a sponsor, or an employer that appear in those affairs.
The qualifier “any personal information” sets no minimum quantity and no threshold of sensitivity. A single address, date of birth, or passport number is enough to bring the provision into play. And because the duty is framed around information relating to the client and their affairs, it is not limited to documents the client physically handed over.
6. Limb three: the condition is the client's written consent
Section 35 does not prohibit disclosure absolutely. It prohibits disclosure “without the client’s written consent”. The provision therefore supplies its own lawful path, and two features of that condition are worth stating plainly because they are already in the text rather than added by the AI guidance:
- It is the client's consent. A practice's own decision, a firm-wide policy, or a vendor's terms of service are not the consent the provision names.
- It is written consent. The condition as drafted is a written one. An understanding reached in a consultation, or a note that the client did not object, is not the thing the provision requires.
The point of emphasis here is structural: the written-consent condition is not an AI rule layered on top of the Code. It is the condition the Code's confidentiality provision has always carried, and AI use is simply one more disclosure that is measured against it.
7. The only exception: what a law requires
The carve-out sits at the front of the provision, and it is the only one: “Except as required by a law of the Commonwealth, a State or a Territory”. Its trigger is compulsion by legislation of that kind — a disclosure a law requires the agent to make.
It is not a general permission, and it does not extend to arrangements that merely resemble an obligation. A platform's terms of service, an internal IT policy, and a confidentiality clause in a vendor contract are not laws of the Commonwealth, a State or a Territory. Where no such law requires the disclosure, the exception does nothing, and the provision's own condition — the client's written consent — is the one that governs.
8. What the duty attaches to in practice
The consequence of breach runs through the Code, not through a separate AI process:
“Consumers with concerns about the conduct of an RMA who has used AI to give immigration assistance can lodge a complaint with the OMARA. If the OMARA has reasonable suspicions that an RMA’s conduct may have breached the Code, it can investigate the RMA and take disciplinary action where appropriate.”
Section 35 is part of the Code. A confidentiality failure involving an AI tool is therefore a Code question, with the ordinary complaint and investigation routes available — the guidance does not describe a distinct AI enforcement track.
What this requires in practice
- A map of which AI tools and features receive client personal information, because section 35 turns on information reaching a third person, not on the tool's brand or category.
- Written consent captured per client and retrievable, obtained before the disclosure rather than after it.
- The same controls applied to any third-party tool that client information passes through, since the requirement comes from section 35 rather than from the AI guidance.
- A rule that binds everyone in the practice who handles client information, because “allow to be disclosed” is breached by a permitted workflow as readily as by a deliberate act.
- A check before any AI workflow is pointed at a closed file, because the duty names former clients alongside current ones.
- No reliance on the exception unless a law of the Commonwealth, a State or a Territory actually requires the disclosure in question.
Practice takeaway. OMARA did not create an AI confidentiality rule; it applied the one the Code already had. Under section 35 an agent must not disclose, or allow to be disclosed, to a third person any personal information relating to a client or former client or their affairs without the client's written consent, except as required by a law of the Commonwealth, a State or a Territory. For AI use, the test is what the practice actually permits and what it can produce in writing.
Sources
- Office of the Migration Agents Registration Authority (OMARA) (2026-09-11)
- Federal Register of Legislation, Commonwealth of Australia (2026-09-11)
Last reviewed: 2026-09-11