Can an Australian migration agent use ChatGPT?
Can a registered migration agent in Australia use ChatGPT or other AI tools for client work?
Yes. OMARA states that Registered Migration Agents may choose to use AI while providing immigration assistance, but the agent remains responsible for that assistance regardless of the source, the Code of Conduct still applies, and the agent needs the client's written consent before entering the client's personal details into an AI platform or system.
OMARA has published guidance on AI use by Registered Migration Agents. It does not prohibit AI, and it does not create a separate AI rulebook. It applies the existing Code of Conduct to AI-assisted work and adds one explicit consent requirement. The four obligations below are the regulator's own words.
1. Using AI does not move responsibility off the agent
“RMAs maintain responsibility for the immigration assistance they give. This means that an RMA who uses AI and gives inadequate or inaccurate information to a consumer remains responsible for that information, regardless of the source.”
“Regardless of the source” is the operative phrase. A wrong criterion, a hallucinated regulation, or a mis-summarised policy is the agent's error once it reaches the client, and the agent is answerable for it.
2. There is no AI exemption from the immigration assistance offence
“There are no exemptions, including information generated through AI. Depending on the circumstances, a person who provides immigration assistance in Australia through AI may still commit an offence under section 280 of the Act.”
This matters most for unsupervised, AI-generated advice reaching a consumer directly. Immigration assistance is defined in section 276 of the Act; routing it through a model does not take it outside section 280.
3. The Code of Conduct applies unchanged, and confidentiality is the live risk
“While not specifically mentioned, the standards set out in the Code of Conduct for RMAs also apply to the use of AI technology.”
“Be aware that sharing personal details of your client using AI tools may be in breach of section 35 of the Code.”
OMARA identifies section 35 of the Code — the general duty of confidentiality — as the provision most likely to be breached by AI use. Pasting a client's passport details, relationship evidence, or financial statements into a general-purpose chatbot is the exposure it describes.
4. Written client consent is required before personal details go in
“RMAs need your written consent before they enter your personal details into an AI platform or system.”
“If an RMA is going to use AI to give immigration assistance, they should explain this to you in advance. This ensures they comply with privacy principles.”
Two distinct duties sit here: disclose the intended use of AI in advance, and hold written consent before personal details are entered. Verbal acknowledgement in a consultation does not satisfy the second.
What this requires in practice
- A recorded, per-client written consent to AI processing, captured before any personal detail is entered — and retrievable later, because the client file must hold it.
- A disclosure of AI use given in advance, not retrospectively.
- A human review step where the supervising agent approves or rejects every AI output before it reaches the client or a matter, so responsibility is exercised rather than merely assumed.
- An identifiable reviewer for each approval, so the file shows which agent took responsibility.
- Confidentiality controls over what data reaches which tool, given the section 35 exposure OMARA names.
The record-keeping side follows from the Code itself rather than the AI guidance. A client file must include copies of all written communications between the agent and the client and all records of oral communications made under section 55, and the file must be kept for a defined period:
“A migration agent who has a duty under subsection (1) in relation to a client file must take all reasonable steps to ensure that the client file is kept for a period of 7 years after the last action on the file for the relevant client.”
So an AI consent record is not a one-off checkbox. It is part of the client file, and it needs to still be produceable seven years after the matter's last action.
Separately, the Privacy Act 1988 obligations continue to apply to the personal information involved. The OAIC's Australian Privacy Principles guidelines cover security of personal information (APP 11) and disclosure of personal information overseas (APP 8) — the latter being directly relevant when an AI tool processes client data outside Australia.
Practice takeaway. The regulator's position is permissive but conditional: AI is allowed, responsibility is not delegable, the Code applies in full, and written consent precedes any personal data entering a tool. A practice that cannot evidence the consent and the human approval cannot evidence compliance.
Sources
- Office of the Migration Agents Registration Authority (OMARA) (2026-09-07)
- Federal Register of Legislation, Commonwealth of Australia (2026-09-07)
- Office of the Australian Information Commissioner (OAIC) (2026-09-07)
Last reviewed: 2026-09-07