Validation vs rewriting: two approaches to AI in NDIS notes
Tools that use AI on NDIS notes do one of two things. A rewriting tool produces or rewrites the note text. A validation tool reads the note the worker wrote and returns questions and flags, and the worker edits. Whether either is safe depends less on the technology than on five governance rules: who authors the note, whether the tool can add facts, how much personal information it receives, who signs, and what you record about its use.
Key takeaways
- Rewriting changes or generates the words in the note. Validation leaves the words with the worker and returns feedback.
- The main risk with rewriting is detail the worker did not observe entering a legal record. The main risk with validation is false reassurance.
- The provider stays responsible for complete, truthful and accurate records whichever approach it uses.
- Five governance rules apply to both approaches: worker as author, no invented facts, minimum personal information, a named person signs, and a written record of the tool.
What are the two approaches?
Rewriting. The tool takes rough input, such as a few bullet points or a voice recording, and produces the note, or takes a finished note and restates it. The wording in the saved record can differ from anything the worker wrote.
Validation. The tool reads the note the worker wrote and checks it against criteria, for example whether it says what assistance the participant needed, what they did and how it relates to their goals. It returns specific questions or flags. The worker answers from what they saw and edits their own note.
The two are not always cleanly separate. A spell-check that fixes a worker’s own words sits at the light end of rewriting. A tool that fills in a missing sentence sits at the heavy end. The useful question is what the tool is allowed to put into the record.
| Question | Rewriting | Validation |
|---|---|---|
| Who writes the words that are saved? | The tool, or the tool and the worker | The worker |
| What does the tool return? | Text | Questions and flags |
| Can new detail enter the record? | Yes, unless the tool is restricted | Only if the worker types it |
| Where does an error come from? | The tool can state something that did not happen | The check can miss a weakness, and a pass can be read as approval |
| What personal information does the tool receive? | Usually the full note or the raw input | Usually the full note |
Both approaches usually send the note to an AI service, so the privacy questions apply to both. The OAIC guidance on commercially available AI products states that the Privacy Act applies to all uses of AI involving personal information, and that incorrect or made-up information an AI system produces about an identifiable person is itself personal information. See Is it safe to use AI for NDIS case notes? for the privacy detail.
Why does the approach matter for the record?
The NDIS states that a provider needs to keep complete and accurate records of supports delivered, and that it is the provider’s responsibility to make sure claims for payment are complete, truthful and accurate. The NDIS Practice Standards require an information management system that records each participant’s information in an accurate and timely manner. Neither requirement changes when a tool is involved. Since 27 August 2026, section 45B of the NDIS Act also requires prescribed records that relate to a claim, or to the support a claim relates to, to be kept for 7 years from the claim date (see how long NDIS providers must keep records). A record that contains detail nobody witnessed is a weak record for that purpose, whichever tool produced it.
What are the five governance rules?
These are our practical rules, built on the OAIC and NDIS sources above. They are not a legal test, and they apply to either approach.
- The worker who was there is the author. The person who supported the participant writes, or dictates, what happened. A tool can help them say it clearly. It should not decide what happened.
- The tool may not add facts. Anything a tool suggests should be a question or a flag that the worker answers from what they observed. If a tool can insert detail about what the participant did, said, or needed, someone must be able to show where that detail came from.
- Send the minimum personal information. The OAIC recommends, as best practice, not entering personal information, particularly sensitive information, into publicly available generative AI tools. Ask what a tool receives, where it is processed and stored, who can see it, and whether it is kept or used for training.
- A named person signs, and owns the accuracy. Review every note before it is saved. A signature is a statement that the note is accurate, so a tool that makes review harder or shorter is working against it.
- Write down how the tool is used. Record which tool, for what, who approved it, how output is checked and which sections of your privacy notice cover it. The OAIC lists testing for the intended use, human oversight, privacy and security risks and who has access as due diligence points before adopting a product.
How do you test a tool against the rules?
Ask these of any tool, from any supplier:
- Can it change the meaning of what the worker wrote, or add a sentence the worker did not type?
- Is what it returns text for the note, or feedback for the worker?
- What exactly is sent to the AI service, and is it de-identified first?
- Does the saved record show the worker’s own final wording, and who signed it?
- Can you show an auditor how output is checked, on a real note, today?
Where does NoteGate sit?
NoteGate uses the validation approach. The worker is always the author, it never writes shift notes or incident reports, and participant data is stored in Australia. Its checks return specific guidance before a note is saved. That describes how it works. NoteGate supports documentation governance and does not determine compliance.
This guide is general information, not legal advice. Check the OAIC guidance and your own obligations before adopting any tool.
Frequently asked questions
What is the difference between validating and rewriting an NDIS note?
A rewriting tool produces or restates the text of the note. A validation tool reads the note the worker wrote and returns questions and flags, and the worker edits their own note.
Is it safe to use AI for NDIS case notes?
It can be if the provider treats it as a privacy and accuracy decision. The Privacy Act applies to all uses of AI involving personal information, and the provider remains responsible for complete, truthful and accurate records. Five rules help: worker as author, no invented facts, minimum personal information, a named person signs, and a written record of the tool.
Who is responsible if an AI tool puts something wrong in a note?
The provider. The NDIS requires complete, truthful and accurate records and the OAIC notes that incorrect information an AI system produces about an identifiable person is still personal information.
Should the worker or the tool write the note?
The worker who supported the participant should be the author. A tool can check the note or help the worker word it, but it should not decide what happened.
Sources
- Guidance on privacy and the use of commercially available AI products (published 21 October 2024, updated 17 January 2025) (Office of the Australian Information Commissioner, retrieved 25 September 2026)
- What are the record keeping requirements (NDIS) (NDIA, retrieved 25 September 2026)
- Core module: Provider governance and operational management (Information management) (NDIS Quality and Safeguards Commission, retrieved 25 September 2026)
- National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026, Schedule 2 Part 4 (section 45B) and item 86 (section 182(4)) (Federal Register of Legislation, retrieved 26 September 2026)
Related
Keep the worker as the author
See how NoteGate checks notes the worker wrote, with participant data held in Australia.
Book a 20-minute walkthroughChoose a plan