Dental AI guide
An AI Vendor Just Pitched Your Practice — What to Ask Before You Say Yes
AI scribe, receptionist, recall-bot and marketing vendors are pitching dental practices every week. The demo always looks great. These are the seven questions that decide whether your practice can actually use it safely — and who's responsible when it gets something wrong.
Just because an AI feature exists doesn't mean your practice can safely use it. When a vendor pitches you, the demo answers 'does it work?' — but the questions that matter are 'where does our patient data go, can it act on its own, and who's liable when it's wrong?' Most practices never ask them. This guide is the seven-question script that protects the practice — and your registration — before you sign.
No patient data required. Use these guides for practice workflow education, not patient-specific advice.
This is general educational material for dental practice owners and managers, not legal advice. The regulatory points below are things to review and confirm with a qualified adviser for your situation — not determinations about any specific product.
Every week, another AI tool is pitched to dental practices: a scribe that writes your clinical notes, an "AI receptionist" that answers calls and books patients, a recall bot, a marketing assistant that writes your website and social posts. The demos are slick and the time-savings are real.
But the demo only answers one question: does it work? The questions that actually decide whether your practice can use it are different — and the vendor's salesperson is rarely the person who can answer them. The core principle is the one that should sit behind every AI decision in the practice:
Just because an AI feature exists doesn't mean your practice can safely use it. Whatever the tool does, you remain responsible for patient privacy, for the clinical record, and for anything published under the practice's name.
Here is the seven-question script to run before you sign anything.
1. Where does our patient data go — and does it leave Australia?
Ask exactly where data is stored and processed, and whether any of it — or any sub-processor they use — sits overseas. Sending patient information to an overseas service is a cross-border disclosure question under the Privacy Act (APP 8), and it doesn't stop being your responsibility because a vendor is in the middle. Also ask the quieter question: is our data used to train their models? "Your data improves the product" can mean patient information becomes part of a model you can't claw back.
A good answer: clear data-residency information, named sub-processors, and a plain "no, your data is not used to train shared models."
2. Who can see it — and can you show me?
Who at the vendor can access practice or patient data, under what controls, and can you see an access log? A tool that can show you who accessed what, and when, is in a different league from one that can't. This is the security-and-accountability question (APP 11), and it's also the difference between "trust us" and "here's the audit trail."
A good answer: role-based access, encryption, and an audit log you can actually inspect.
Also in the full guide
- 3. Is it read-only, or does it *act*?
- 4. What happens to our data if we leave?
- 5. Who's liable when it gets something wrong?
- 6. Is it — or does it act like — a medical device?
- 7. Can we try it without real patient data first?
- Green flags vs red flags
- The safest first AI is usually the one you control
- Before you sign — and before you switch on
Optional — get a customised version
Request the version adapted for your practice
The guide above is free to read and download. If you would like a version tailored to your practice workflow, leave your details below. Use practice-level details only. Do not include patient names, treatment details, clinical notes, X-rays, invoices or identifiable emails.