Skip to main content
Service

AI policy — because your staff are already using it

Not whether to allow AI, but on what terms. A short, enforceable policy covering what may be put in, what must be checked, and who is accountable when it is wrong.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

A practical AI acceptable use policy and governance framework — short enough to be read, specific enough to be followed, and matched to controls that make it real.

It is already happening

The question is not whether to allow AI in your business. Your staff are using it — on personal accounts, on personal devices, with company information — because it saves them time on real work.

Every AI policy conversation should start from that position rather than from a hypothetical decision. What you are choosing is whether that usage is governed and visible, or ungoverned and invisible.

Why prohibition fails

A ban with no alternative does not stop usage. It moves it somewhere you cannot see.

The same client information goes into the same models, from a personal account with consumer terms rather than a business account with commercial data protection, on a device you do not manage, by someone who now cannot ask for help because they are not supposed to be doing it.

That is a materially worse position than sanctioned use, and it is the predictable outcome of a policy that only prohibits.

What a workable policy contains

What must never go in. Specific categories rather than a vague instruction to use judgement: client and customer personal information, anything under a confidentiality obligation, credentials, unreleased financial data, health information. The test we suggest to staff is whether they would be comfortable with it in a competitor’s hands.

Which tools are approved. Named, with the reason. This is the part that makes the restriction workable, because it gives people a route rather than only a wall.

What must be verified. Anything going to a client, into a record, into a financial figure, or into a decision. With the person accountable for checking it named rather than implied.

Where accountability sits. Explicitly: with the person who used the tool and the business that relied on the output. Not with the vendor, not with the model. This is the point most often misunderstood and it is worth stating in plain words.

Two pages, not twenty

For a business of 10 to 200 staff, a short readable policy that people follow beats a comprehensive framework that satisfies an auditor and changes nothing.

The measure of a policy is whether the person drafting a client email at 4pm knows what they are allowed to do. That requires them to have read it, which requires it to be short.

Back it with controls where it matters

A rule nobody can enforce is a suggestion.

Where the risk justifies it, the policy is supported by configuration — providing a licensed tool with commercial data protection terms, and where appropriate restricting access to consumer AI services on managed devices. That is a judgement call rather than a default; heavy-handed blocking has its own costs.

The related work is awareness training, because the behaviours a policy describes are learned rather than announced.

Review it, because the ground moves

AI tooling changes on a timescale of months. A policy naming specific products and specific terms will be partly out of date within a year.

Building in a review cycle is more useful than trying to write something durable. So is writing the policy around principles — what kind of information, what kind of verification — with the tool names in an appendix that is cheap to update.

What you get with JTIT

Concrete deliverables, not vague promises.

Addresses what is already happening

Staff are using AI tools now, on personal accounts, with company information. A policy that acknowledges this beats one that pretends otherwise.

Clear rules on what goes in

Specific categories of information that must not be entered into external tools — client data, personal information, anything under confidentiality obligations.

Verification made someone's job

Who checks output before it goes to a client, into a record, or into a decision. Accountability named rather than assumed.

Approved tools, so there is an alternative

A policy that only prohibits drives usage underground. Providing a sanctioned tool is what makes the restriction workable.

Short enough to be read

A two-page policy people follow beats a twenty-page framework nobody opens. We write the version that gets used.

Backed by technical controls

Where it matters, the policy is supported by configuration rather than trust alone — because a rule with no enforcement is a suggestion.

How it works

A predictable, no-surprises process.

  1. 01

    Find out what is actually in use

    Which tools staff are already using and for what. This is almost always broader than management expects and it is the real starting position.

  2. 02

    Decide the boundaries

    What information may never leave the business, what may be used in approved tools, and what requires verification before it is relied on.

  3. 03

    Provide a sanctioned option

    An approved tool with appropriate data protection, so the policy offers a route rather than only a prohibition.

  4. 04

    Communicate and support

    Explained to staff with reasoning, not circulated as a compliance document. Reviewed as the tooling changes, which it does constantly.

Frequently asked questions

Should we just ban AI tools?

You can, and it will not work. Staff are using these tools because they save time on real work, and a prohibition without an alternative moves that usage onto personal accounts and personal devices where you have no visibility at all. That is a worse position than governed use: the same company information goes into the same models, and you no longer know it is happening. A ban is only defensible if paired with a sanctioned alternative, at which point it is not really a ban.

What should staff never put into an AI tool?

The categories that matter most are client and customer personal information, anything covered by a confidentiality obligation or NDA, credentials and access details, unreleased financial information, and health or other sensitive personal data. The practical test we suggest is whether you would be comfortable with the information appearing in a competitor's hands — if not, it does not go into an external tool. Tools operating inside your own tenant, such as Microsoft 365 Copilot, sit in a different category with different terms.

Is our data used to train the models?

It depends entirely on the tool and the plan. Consumer tiers of public AI services have historically been more permissive about using inputs for improvement than enterprise and commercial tiers, which typically contract not to. Microsoft 365 Copilot operates within your tenant boundary under commercial data protection terms. The practical implication is that the distinction between a personal free account and a properly licensed business tool is significant, and it is a good reason to provide the second.

Who is responsible when AI produces something wrong?

The person who used it and the business that relied on it. There is no meaningful sense in which responsibility transfers to the tool or its vendor, and this is the single most important thing for staff to understand. Advice given to a client, a figure in a report, a statement in a contract — the accountability sits exactly where it did before. A policy should say this explicitly, because the intuition that the tool is somehow responsible is common and wrong.

How long should an AI policy be?

Two pages, and readable. The purpose is that staff know what they can and cannot do, which requires them to have read it. A comprehensive governance framework may be appropriate for a large regulated organisation; for a business of 10 to 200 people it produces a document that satisfies an auditor and changes nobody's behaviour. Short, specific, and paired with an approved tool is what actually works.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote