Sovereign

Your staff are already using AI. You just do not have a policy.

Josh Horneman2026-08-20

Walk the floor of almost any Australian SME and ask a simple question. Who here has used ChatGPT for work in the last fortnight? Then watch the hands go up. Then watch the owner's face.

We ran this exercise with a 40-person professional services firm in Perth. Eleven hands. The managing partner had no idea. Two of those eleven had pasted client engagement letters in to "tidy up the wording." One had uploaded a spreadsheet of debtor balances to get a summary. Nobody had done anything malicious. Every one of them thought they were being efficient.

That is the situation in most businesses right now. AI is already inside. It came in through the side door, on personal accounts, with nobody watching.

What is actually at risk

Start with the boring, expensive stuff.

Client confidentiality. If you are a law firm, an accountant, a consultant, or anyone who signs engagement letters, your clients assume their information stays with you. Free-tier AI tools generally reserve the right to use what you type to train their models. You do not get to decide that after the fact.

Privacy Act obligations. Customer data, employee data, health information. The Australian Privacy Principles do not have a carve-out for "but it was just ChatGPT." If personal information leaves your control without a basis for it, you have a problem that an apology does not fix.

Contracts. Plenty of client agreements now include clauses about where data can be processed and by whom. A lot of them were written before anyone thought about AI. Some of them were written after. Either way, you probably have not checked.

And then the less boring risk. Someone on your team builds a workflow around a tool, it works, it becomes load-bearing, and one day the tool changes its terms, doubles its price, or goes away. You find out when the work stops.

Why "we will sort it out later" costs more every month

I understand the instinct. You have a business to run. AI governance is not urgent until it is, and when it is, it is very urgent.

The problem with waiting is that usage compounds. Every month without a policy, more people adopt more tools for more tasks. More client data flows into places you have not vetted. More processes quietly start depending on things nobody has approved. The cleanup gets bigger. The conversation with the client who asks "what AI tools do you use with our data?" gets harder.

A policy written today covers eleven people and a handful of use cases. The same policy written in 12 months has to untangle 40 people and a dozen tools that are already woven into how work gets done. Same document. Much harder rollout.

What a usable policy looks like

Most AI policies I have read are 30 pages long, written by someone who has never used the tools, and ignored by everyone from day two.

A policy that works in an SME is short enough to read in one sitting and specific enough that your staff know what to do on Tuesday morning. It answers five questions:

  1. Which tools can we use, and on which accounts? Personal ChatGPT and a company Claude workspace are not the same thing. Name them.
  2. What can go in, and what cannot? Be concrete. "Client names and identifying details stay out. Anonymised process descriptions are fine." Staff can follow that.
  3. Who checks AI output before it leaves the building? Drafting is fine. Sending unreviewed AI-written advice to a client is not.
  4. What do we do when something goes wrong? Someone will paste the wrong thing. Have a step. Make it blameless or nobody will tell you.
  5. Who owns this? Name a person. Policies owned by "the business" are owned by nobody.

That is the whole skeleton. The rest is tailoring to your industry, your data, and your risk appetite.

The first 5 minutes

You do not need a lawyer to take the first step. You need a draft that a lawyer can review, and you need it this week rather than next quarter.

We built a free tool that does exactly that. Twelve questions about your business, your industry, the data you handle, and how much freedom you want to give your team. It generates a tailored policy draft with a reviewer checklist at the end flagging the clauses your lawyer or risk adviser needs to look at. Takes about 5 minutes. It is not legal advice, and it says so, repeatedly. What it is, is a starting point that beats the blank page.

Build your AI policy draft

Then have it reviewed, put a name on it, and tell your team. The eleven hands are going up either way. You may as well know what they are doing.