Do you have an AI policy?
Most business owners don’t — and that’s a real risk. An AI policy is a simple document that tells your staff how to use AI tools safely and appropriately at work.
What is “Shadow AI” — and why should you care?
Shadow AI refers to staff using AI tools — like the free version of ChatGPT — for work tasks, without the business owner’s knowledge or approval.
It happens more than you’d think. An employee might paste a client email into ChatGPT to get a quick reply, or use it to summarise a contract. They’re trying to be productive — but they may be sharing confidential information with a public AI system in the process.
You are still responsible for how your business handles client data — even if an employee was the one who shared it.
What can go wrong without an AI policy
Client data leaving your business
Client details or financial information entered into free AI tools may be used to train public AI models — exposing confidential data outside your business owner’s control.
Confidential documents exposed
Staff may upload internal documents, contracts, or financial records to AI tools without realising the data may be retained or used externally.
Privacy obligation breaches
Under Australian privacy law, businesses are responsible for the personal information they hold — even if an employee accidentally shared it through an AI tool.
Incorrect AI output acted on
Without guidance, staff may act on AI-generated content that is confidently wrong — sending incorrect information to clients or making decisions based on bad data.
What does an AI policy actually cover?
A clear AI policy sets out simple rules for your staff. It doesn’t need to be complicated — a single page of plain-language rules is enough to protect your business and give your staff confidence about what’s acceptable.
Approved tools
Which AI tools are approved for business use — and which are not (e.g. public ChatGPT vs Microsoft Copilot).
What not to enter
What types of information must never be entered into AI tools — client data, financial records, passwords, confidential documents.
Review requirements
How to review and check AI-generated content before using it or sending it to clients — so errors don’t slip through.
Responsibility
Who is responsible if something goes wrong — making clear that AI output doesn’t remove personal or business accountability.
Reporting issues
How to report it if something goes wrong — so problems are caught and dealt with rather than hidden.
Review cadence
How often the policy will be reviewed — AI is moving fast and your policy should keep pace with new tools and risks.