
Three Steps to Using AI Safely in Your Business
Here is the uncomfortable starting position for most Perth businesses I walk into: AI is already in use. It is on personal accounts, on phones, in browser tabs, with no policy and no record. Nobody signed off on it and nobody can tell you what has been pasted into it.
You do not get to decide whether your business uses AI. You get to decide whether it uses AI safely. Three steps, and the order matters.
Step one: choose one provider
One. Not a shortlist, not a trial of four, not "whatever people prefer."
The moment you have three AI tools in the business you have three sets of terms, three places your data might live, three billing relationships and no way to answer the question what did we send to whom. Consolidating is the single largest safety improvement available to most businesses, and it costs nothing but a decision.
The three that come up in nearly every conversation:
- Copilot — the obvious pick if you are already deep in Microsoft. It sits inside the tools people already have open, which does more for adoption than any training session will, and your data stays inside a tenancy you already govern.
- Claude — where I would go if raw quality of thinking is the priority, particularly for anything involving writing, analysis or working through a problem properly.
- ChatGPT — the balanced option, and the enterprise subscription is worth the money specifically because it changes how your data is handled.
That last point applies across all three and it is the one to hold onto: the enterprise or business subscription is not an upsell, it is the control. Free and personal tiers are a different product with different data handling. If your staff are using AI on personal accounts today, the fix is not a ban. It is giving them a business account so the same behaviour happens somewhere you can see it.
Step two: write the policy
Short. One page. Written so a person can read it once and know what to do.
The mistake is writing a policy that only says no. A policy of pure prohibition gets ignored on day two, and now you have shadow AI and a document that proves you knew about it.
Say clearly what is fine:
- Drafting reports, letters and proposals
- Summarising a long document you already have
- First-pass checking of work a person will review
- Rewriting something for a different audience
And say clearly what is not, with the reason attached:
- No clinical diagnosis or clinical decision-making. For anyone in health, this is the line. AI can draft the letter about the patient; it does not decide about the patient.
- No recording or transcribing a conversation without consent. This one catches people out constantly. The meeting-notes tools are excellent and they are also, in the wrong room, a privacy problem you have created for yourself.
- No pasting client, patient or personal information into a tool that is not the approved one. Which is only enforceable because you did step one.
If you handle health information, the Privacy Act applies to you regardless of turnover, and "an employee pasted it into a chatbot" is not a defence anybody has successfully run. Write the policy accordingly.
Step three: train people individually, not corporately
This is the step that gets skipped, and it is the one that decides whether the other two hold.
Start by finding out what is actually happening. Ask people what they are already using and what for. You will get a more honest answer than you expect, provided the question is genuinely curious rather than an audit — and what you learn tells you exactly where the risk is and where the value is.
Then frame the training around one question: how can we make your job easier?
Not how we make the business more efficient. Nobody has ever been motivated by that sentence. The person in front of you cares about the report that takes them until 6pm on a Thursday, and if AI takes that to twenty minutes, they will use it correctly and enthusiastically for the rest of their career.
This matters most for later-career staff, who are frequently written off in these conversations and should not be. They are not resistant to the technology. They are resistant to being told their experience is now a rounding error — which is what "efficiency" sounds like from where they are sitting. Show them the tedious part of their own job disappearing and the resistance goes with it. They also tend to be the people who spot a wrong AI answer fastest, because they know what right looks like.
The order is the point
Choose the tool, so there is one place to govern. Write the policy, so people know the edges. Train individually, so the policy is followed by people who want to follow it rather than people who have been told to.
Do it in the other order and you get a policy about tools you have not picked, taught to people who already had their own workaround.
If you want help getting this in place — the tool decision, the one-page policy, and training that people actually turn up to — come and have a chat with us. Or get this kind of thinking weekly.