artificial intelligence law

Risks when implementing retrieval-augmented generation systems

by

reviewed by

Malcolm Burrows

Reading Time:

3–5 minutes

Retrieval-augmented generation (RAG) is an artificial intelligence (AI) system architecture that combines large language models (LLMs), such as GPT-4, with external data retrieval processes.  Unlike traditional AI models, RAG retrieves relevant information in real-time from external databases or document repositories with the aim of generating contextually accurate responses.  These external databases or document repositories are often a company’s private and internal resource tool that becomes shared and connected.[1]

Business use and deployment models of RAG

Businesses typically implement RAG systems to complete tasks such as customer support automation, internal knowledge management, document summarisation, compliance tracking and advanced enterprise search.

Common deployment models include:

  • cloud-based hosting; or
  • on-premise/private hosting.

The standard architecture of RAG systems include:

  • vector databases (transform different forms of data, such as text, images and video, into a common form of simple vector points, connecting based on their relevancy to each other);
  • retrieval mechanisms (identifying relevant documents); and
  • an LLM (synthesising retrieved information into natural language outputs).

RAG integration into enterprise systems, such as Customer Relationship Management (CRM), Enterprise Resource Planning (ERP) and Document Management Systems (DMS) is also common.[2]

Prominent RAG tools and frameworks

Frequently utilised RAG frameworks and tools include:

Legal risks and compliance considerations

Depending on how the RAG system is deployed and what the affected systems are used for, businesses need to consider the following legal risks:

  • compliance with the Privacy Act 1988 (Cth) (Privacy Act);
  • risks based on the particular industry sector that the business operates in (Sector Based Risks);
  • compliance with organisational information security policies;
  • compliance with the specific business’s contracts with third parties (Contractual Risk);
  • intellectual property infringement;
  • compliance with best practices for the implementation of AI systems in Australia; and
  • compliance with the Australian Consumer Law (ACL) pursuant to Schedule 2 of the Australian Competition and Consumer Act 2010 (Cth).

Privacy Act compliance

APP Entities must ensure compliance with the Privacy Act, disclosure and use of personal information.

Sector Based Risks

The compliance obligations for businesses operating in different sectors can vary greatly.  For example, the compliance obligations of businesses that operate in the health sector will vary wildly from those in the construction sector.

Information security

Deployment of RAG may also introduce cybersecurity vulnerabilities.  Organisations must comply with the Security of Critical Infrastructure Act 2018 (Cth) by implementing appropriate cybersecurity measures and monitoring them.

Compliance with third-party contracts

Automated data retrieval should adhere with an organisations’ contracts with third parties to ensure it does not cause a breach of these contracts.  It may be that express permissions and consents must be obtained to address this issue.

Intellectual property infringement

RAG systems may inadvertently incorporate third-party intellectual property (literary and artistic works) that the internal database/resource pool has provided access to, potentially breaching the Copyright Act 1968 (Cth).

Compliance with best practices for implementing AI systems

RAG systems incorporate use of LLMs and therefore, businesses should ensure RAG systems adhere to the AI Ethics Principles and Voluntary AI Safety Standard.  Businesses using RAG systems should also follow the guidance on privacy and the use of commercially available AI products published by the Office of the Australian Information Commissioner (OAIC).  Meanwhile, software developers creating RAG systems can follow the OAIC’s guidance on privacy and developing and training generative AI models.

ACL compliance

Depending on what the RAG software is implemented to do, it is possible that implementation could amount to a false and misleading statement pursuant to section 29(1)(a)-(n) of the ACL or result in misleading and deceptive pursuant to section 18 of the ACL.

Links and further references

Legislation

Competition and Consumer Act 2010 (Cth)

Copyright Act 1968 (Cth)

Privacy Act 1988 (Cth)

Security of Critical Infrastructure Act 2018 (Cth)

Australian AI standards

AI Ethics Principles

Voluntary AI Safety Standard

Australian AI guidance

Guidance on privacy and developing and training generative AI models

Guidance on privacy and the use of commercially available AI products

Proposals paper for introducing mandatory guardrails for AI in high-risk settings

Australian AI checklists

Privacy considerations when developing or training generative AI models

Privacy considerations when selecting a commercially available AI product

Privacy considerations when using commercially available AI products

Further information about AI and RAG systems

If you need advice on risks of implementing RAG systems in your business, please contact us for a confidential and obligation-free discussion:

Doyles Recommended TMT Lawyer 2024

[1] Google Cloud, What is Retrieval-Augmented Generation (RAG), https://cloud.google.com/use-cases/retrieval-augmented-generation.

[2] IBM, What is retrieval-augmented generation, https://research.ibm.com/blog/retrieval-augmented-generation-RAG.


Related insights about AI law

  • Office of AI announced by Federal Government

    Office of AI announced by Federal Government

    On 15 July 2026, Prime Minister Anthony Albanese (Prime Minister) announced by media release an expansion of the Federal Government’s (Government) existing artificial intelligence (AI) governance framework, including the establishment of a new Office of AI as well as plans to legislate national standards governing large-scale data centres, AI training and the use of Australian…

    Read more …

  • Federal Court publishes GenAI Practice Note

    Federal Court publishes GenAI Practice Note

    On 16 April 2026, the Federal Court of Australia (Court) published the Use of Generative Artificial Intelligence Practice Note (GPN-AI) (Cth) (GenAI Practice Note). 

    Read more …

  • AI businesses should have duty of care

    AI businesses should have duty of care

    In a recent interview with InnovationAus.com, Victorian Senator Michelle Ananda-Rajah (Senator) emphasised the need to adopt digital duty of care laws for artificial intelligence (AI) companies.[1]  As a representative of the ALP and former AI start-up founder, the Senator calls for the proposed digital duty of care to apply to AI companies.  If implemented, the…

    Read more …

  • Bill to allow victims of AI deepfakes to sue for emotional damages

    Bill to allow victims of AI deepfakes to sue for emotional damages

    On 24 November 2025, Senator David Pocock introduced a private Senator’s bill, the Online Safety and Other Legislation Amendment (My Face, My Rights) Bill 2025 (Cth) (Bill) to amend the Online Safety Act 2021 (Cth) (Online Safety Act) and the Privacy Act 1988 (Cth) (Privacy Act). 

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes

    On 3 December 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss the proposed amendments to the Online Safety Act 2021 (Cth) through the introduction of the Online Safety and other legislation Amendment (My Face Rights) Bill (Cth) 2025 (My Face Rights…

    Read more …

  • Federal Gov rules out copyright text and data mining exception for AI

    Federal Gov rules out copyright text and data mining exception for AI

    On 26 October 2025, the Attorney-General, Hon Michelle Rowland MP, published a media release reiterating that the current Federal Government will not introduce a text and data mining (TDM) exception to copyright infringement in the Copyright Act 1968 (Cth) (Copyright Act).  The Attorney-General’s Department will instead engage in further consultations with members of the Copyright…

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – Can artificial intelligence give you justice?

    Malcolm Burrows on ABC’s “Legal Eagles” segment – Can artificial intelligence give you justice?

    On 22 October 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss legal issues associated with artificial intelligence and the justice system.

    Read more …

  • Malcolm Burrows on ABC’s “Legal Eagles” segment – copyright law and the Anthropic case

    Malcolm Burrows on ABC’s “Legal Eagles” segment – copyright law and the Anthropic case

    On 10 September 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss legal issues associated with copyright subsisting in artificial intelligence (AI) training data.

    Read more …

  • Claude AI agrees to pay US $1.5B to settle copyright class action

    Claude AI agrees to pay US $1.5B to settle copyright class action

    Several authors commenced class action lawsuit against Claude AI (Anthropic) in the San Francisco District Court.  The authors allege Anthropic infringed their copyright by using millions of pirated and purchased books to train its artificial intelligence (AI) chatbot, Claude AI.  Anthropic has agreed to settle the class action approximately $1.5 billion US dollars, avoiding further…

    Read more …

Send this to a friend