AgentsConsultingWorkPricesFAQBook now

Home / Consulting / AI safe-use and security

AI safe-use and security, written down properly.

A safe-use policy your staff will actually read, a review of where your data goes, and settings aligned to Australian guidance. We tell you what's covered and what isn't.

What's included.

Safe-use policy and AI register

A plain-English staff policy and a register of the AI tools in use, built on the NAIC Guidance for AI Adoption templates.

Data-flow review

What staff paste into public AI tools, vendor settings, where data is stored, and what your privacy policy says, reviewed against OAIC guidance.

Access and settings

The right plan tier, multi-factor sign-in, least-access connectors, and model training on your business data turned off where the vendor allows.

Staff safe-use training

A short session so everyone knows what never goes into an AI tool, and why.

Rules for every agent

Who approves what, what each agent can touch, and a log of what it did.

When it gets it wrong

A simple procedure for AI mistakes: who to tell, what to check, how to fix it.

What this is, and what it isn't.

We help you use AI sensibly and write down how. We don't issue badges or certificates, and we won't tell you a setup can't go wrong.

What you get: a policy, an AI register, a data-flow review, sensible settings and staff training, all aligned to guidance from the National AI Centre (NAIC) and the Office of the Australian Information Commissioner (OAIC).

What we don't do: we are not auditors or lawyers. We don't hold ISO 27001, and this pack is not an assessment against it or against the ASD Essential Eight. Where a basic control looks missing, we point it out and point you to the right specialist.

Not legal advice. Nothing in this pack is legal advice. For questions about your obligations under the Privacy Act or other law, talk to a lawyer.

How the pack comes together.

1

Review

We look at the AI tools in use, how staff use them, and where the data goes.

2

Write it down

Policy, register and settings changes, in plain English, with your sign-off.

3

Train and revisit

Staff session, then a check-in as tools and guidance change.

From our own work. Our own agents run under the same kind of rules: approval before anything is sent or spent, honest AI introductions, access levels per person, and no card numbers or passwords ever typed by an agent. See how it was built.

Questions we get.

Does this cover our legal obligations?

Not on its own, and nobody honest can promise that. The pack aligns your AI use to NAIC and OAIC guidance and documents it. For legal obligations, talk to a lawyer.

Does the Privacy Act apply to us?

It depends on your turnover and what you do, and some industries are covered regardless of size. It's a question for your lawyer; we'll help you get the facts together.

We only use ChatGPT. Do we need this?

If staff paste client details, contracts or financials into any AI tool, a short policy and the right settings are worth having.

Start with a free 20-minute AI audit.

Tell us what your week looks like. We'll tell you what an agent could take off it, and what we'd leave alone.

Book now