Immi Flow

Does a migration agent need written consent before using AI on client details?

Does an Australian registered migration agent need the client's written consent before entering the client's personal details into an AI tool?

Yes. OMARA's AI guidance requires a registered migration agent to have the client's written consent before entering the client's personal details into an AI platform or system, and separately requires the agent to explain the intended AI use in advance. Section 35 of the Code of Conduct attaches its own written-consent condition to disclosing a client's personal information to a third person, so the requirement has two independent sources: the regulator's AI guidance and the Code itself.

Whether an agent may use AI at all is a separate question, answered in Can an Australian migration agent use ChatGPT?. This article is about one condition attached to that use: the client's consent, the form it has to take, and when it has to exist.

OMARA states the condition in two consecutive sentences, addressed to consumers but describing duties that sit on the agent. They are not variations of one obligation. Each has its own trigger and its own timing.

1. Written consent before personal details are entered

“RMAs need your written consent before they enter your personal details into an AI platform or system.”

— OMARA, Use of artificial intelligence (AI) (guidance addressed to consumers)

Two requirements sit in that sentence:

  • Form. The consent must be written. That is part of the requirement, not a stylistic preference.
  • Timing. Consent is needed before the personal details are entered. The trigger is entry of the details into the tool — not the delivery of an AI output to the client, not the lodging of a matter, and not the client's later reaction to either.

A verbal acknowledgement in a consultation does not satisfy the form requirement. A client agreeing across the desk, however clearly, leaves the agent without written consent at the moment the details go in. If the agent later notes that the client agreed orally, that note is a record of what was said; it is not the client's written consent. Where a client will not give consent in writing, the details do not enter the tool, and the work proceeds without that processing.

2. The advance explanation is a separate duty

“If an RMA is going to use AI to give immigration assistance, they should explain this to you in advance. This ensures they comply with privacy principles.”

— OMARA, Use of artificial intelligence (AI)

Explanation and consent are two duties, and neither substitutes for the other:

  • The explanation attaches to using AI to give immigration assistance, and its timing is in advance — before the client is exposed to AI-assisted work, not disclosed afterwards.
  • The consent attaches to entering the client's personal details into an AI platform or system.

An explanation in advance does not create consent. Telling a client that AI will be used, however fully, is not the same act as the client agreeing in writing to their details being entered. Written consent does not cure a missing explanation either: consent collected before the client understands that AI is being used is a signature without context. Both duties run, in that order — explain first, so the consent is informed, then obtain the written consent, then the details can be entered.

3. Section 35 imposes the same condition independently of the AI guidance

The AI guidance points to section 35 of the Code as the provision engaged when client details are shared through AI tools. That section carries its own written-consent condition, in its own words:

“Except as required by a law of the Commonwealth, a State or a Territory, a migration agent must not disclose, or allow to be disclosed, to a third person any personal information relating to” … “without the client’s written consent.”

— Migration (Migration Agents Code of Conduct) Regulations 2021, s 35

Two things follow. First, the act OMARA's guidance describes — entering a client's personal details into an AI platform or system — is reached by section 35's own terms, because the details reach the platform's provider, a third person. Second, section 35 states one exception and one condition: disclosure required by a law of the Commonwealth, a State or a Territory, or the client's written consent. It offers no route that runs through a verbal agreement.

So the written-consent requirement does not rest on the AI guidance alone. It has a second source, in the Code itself, imposed on the same act. An agent who treats the regulator's AI page as the whole of the obligation still has section 35's condition attached to entering the details. The form word is the same in both places — written — which is why the answer does not turn on which of the two the agent had in mind.

4. The consent record belongs in the client file

A written consent is a written communication with the client. The client file must include copies of all written communications with the client, and the records made under section 55 — so the consent belongs in the file itself, alongside the engagement documents, not in a folder beside it or in a message thread the agent no longer controls. The items a compliant file must contain are set out in What must be in a compliant migration agent client file?.

The practical test is not whether consent was obtained, but whether it can be produced. If a client file is examined and the written consent is not in it, the file does not show that the condition was met before the details were entered — and it is the record, not the agent's recollection, that answers that question. The consent document stays in the file for as long as the file must be kept.

What this requires in practice

  • Written consent captured per client before the first personal detail is entered into any AI platform or system.
  • The consent identifying the platform, or the class of platform, and the purpose, so that it is a consent to something specific rather than to AI in general.
  • An advance explanation of the AI use that precedes the consent, so the client agrees to something they have been told about.
  • A clear fallback where consent is withheld: the personal details stay out of the tool, and the matter proceeds without that processing.
  • The signed consent stored in the client file, retrievable for as long as the file is kept, and visible to anyone working on the matter before they reach for a tool.

Practice takeaway. OMARA requires written consent before an agent enters a client's personal details into an AI platform or system, and an explanation in advance of using AI to give immigration assistance. These are two duties with different triggers, and a verbal yes in a consultation does not satisfy the written form. Section 35 of the Code imposes the same written-consent condition independently of the AI guidance. A consent that cannot be found in the client file is, for practical purposes, a consent the agent cannot show was ever given.

Sources

Last reviewed: 2026-09-11