Most of what gets written about AI right now is about one-shotting a CRM or building an internal tool in an afternoon. I use these tools every day and build with them for clients, so I get the excitement.
The part that determines whether a business can use them safely gets far less attention. It’s the AI use policy, and it’s mostly numbered clauses and definitions, plus a section explaining why each rule exists so people follow it instead of just ticking a box.
I’ve written a number of these for clients this year. The rules change by industry, but the same two mistakes turn up in every first draft, including mine.
The first is writing the policy against the wrong risk. Most people worry that the provider will train its future models on their data. On business and enterprise plans the major providers have agreed in the contract not to, so that concern is mostly dealt with before you start.
The bigger problem is that the business has no record of what its staff have shared. Say thirty people are pasting client material into chat windows on their own personal accounts.
If a client or a regulator later asks how that information was handled, nobody can answer. The history also stays in each person’s account until they delete it, so anything inputted six months ago can still be read by whoever gets into that account.
A contract with the provider can’t fix that, because it’s the business losing track of its own information.
The second mistake is where the line gets drawn. First drafts usually split personal information from financial information. The test that works is whether the information can be traced back to a particular person or company.
Financial data fails that test more often than people expect. In accounting work, a company’s figures plus its industry and state can often be matched to public ASIC records in a few minutes. Remove the name and the ABN and most of that risk goes away.
Less changes between industries than I expected. Tax file numbers have their own rules under the Privacy Act. Credit information sits in a separate part of the Act again.
Legal advice on a live matter raises a privilege question as soon as it goes into any third party service, AI tools included. Those deserve proper tailoring, and the rest of the policy looks much the same everywhere.
I’ve also changed my mind about strict rules. My first instinct was to spell out what staff could and couldn’t use. A policy that fights what people do every day will lose.
Staff keep doing it and stop mentioning it, which leaves the business worse off than before. If the same task goes through a chat window every week, build it into a system the business controls and logs, with the guardrails set up for that task. Then nobody has to remember to be careful.
Two rules belong in every policy. Use the company account, because personal and company accounts look identical on screen and carry very different protection.
And report mistakes the same day with no penalty for reporting, because under privacy law the difference between a reportable breach and a non-event is often how fast it was fixed.
Most businesses I walk into have neither in place.

