Ask most Sydney business owners whether their team uses AI, or whether they have an AI policy, and you’ll get a shrug. Ask the team and you’ll get a very different answer.

Someone is using ChatGPT to tidy up client emails. Someone else drops meeting notes into a free summariser. The bookkeeper asked an AI tool to explain a spreadsheet, and pasted the spreadsheet in to do it.

None of them think they’re doing anything wrong. Most of them are trying to get through the day faster. That’s what makes it a problem: it’s invisible, and it’s everywhere.

This is “shadow AI”: AI tools your business never chose, never set up and can’t see, being used with your business’s information.

What actually gets pasted in

When we talk to staff (not owners) about how they use AI, the same things come up:

  • Client emails, complete with names, phone numbers and the full thread
  • Quotes, invoices and pricing
  • Staff matters: performance notes, rosters, a tricky email to an employee
  • Contracts and agreements “just to check the wording”
  • Spreadsheets of customer data to “clean up” or summarise

Why it matters

You lose control of the data. Free consumer AI tools are run under the provider’s terms, not yours. Depending on the tool and its settings, what’s typed in may be stored, reviewed or used to improve the product. Once it’s in, you’ve lost control of what happens to it.

The privacy regulator has said it plainly. The Office of the Australian Information Commissioner’s guidance on commercial AI products recommends that businesses don’t put personal information into publicly available AI chatbots, because of how hard it is to control what happens to it afterwards. If your business is covered by the Privacy Act, that’s a direct steer.

Clients expect you to protect their information. For accountants, lawyers, health practices and anyone handling client files, “a staff member pasted it into a chatbot” is not a conversation anyone wants to have.

AI gets things confidently wrong. A reply drafted by AI and sent without a proper read can promise something you can’t deliver, or get a figure wrong.

A new rule starts 10 December

From 10 December 2026, businesses covered by the Privacy Act that use a computer program, including AI, to make or substantially help make decisions that could significantly affect people must say so in their privacy policy. That means listing the kinds of personal information used and the kinds of decisions involved.

It isn’t only fully automated decisions. If staff are using AI to help shortlist job applicants, assess customers, or set pricing or credit terms for individuals, it may be covered. The OAIC is finalising guidance on exactly where the line sits, so now is a good time to find out how AI is actually being used in your business and put an AI policy in place.

Banning it doesn’t work

The instinct is to block AI altogether. In our experience that just pushes it onto personal phones, where you have even less visibility. People use these tools because they genuinely save time.

The better approach is a simple AI policy: give your team a safe way to use AI, and clear rules about what never goes into it.

A one-page AI policy you can adopt this week

An AI policy for a small business doesn’t need to be a 20-page document. Most need five rules:

  1. Use the approved tool only. If you’re on Microsoft 365 Business, Copilot Chat is included and, when staff sign in with their work account, it runs with Microsoft’s enterprise data protection rather than consumer terms. Make that the default.
  2. Never paste in personal information about clients, staff or suppliers into any tool that isn’t approved.
  3. Never paste in passwords, bank details, contracts or anything marked confidential.
  4. A human checks everything before it goes to a client.
  5. If in doubt, ask. Name a person to ask.

Then tell your team about it, in person, and explain why. That conversation does more than the AI policy itself.

Where to start

Find out what’s already happening. Ask your team, without judgement, which AI tools they use and for what. You’ll learn more from that conversation than from any audit.

If you want help setting up approved AI tools properly, reviewing which apps have access to your Microsoft 365 data, or writing an AI policy that fits your business, our team can help. We look after businesses across Sydney with managed IT services, Microsoft 365 support and cybersecurity.

Get in touch or call us on (02) 8212 4722.