Use AI with confidence. Know the risks and prevent them.
We help your organisation understand AI and put practical controls in place, so your team can use it productively and prevent privacy, security, accuracy and reputational mistakes.
Please note: Everything here is guidance and general information. We recommend that, once your AI and automation advice has been implemented, it is reviewed and certified by a qualified legal or AI governance expert. Your obligations depend on your business. Last reviewed 7 October 2026.
It's about knowing where AI creates risk, keeping important decisions accountable, and helping businesses adopt AI with confidence.
Make AI smarter.Use AI where it genuinely helps, with good information, clear instructions and the right tools.
Keep decisions accountable.A named person stays responsible for important decisions, even when AI helps make them.
Make AI decisions explainable.If an AI system influences an important decision, your business should be able to explain why.
01 · How we work
From first review to ongoing improvement
Eight steps, in order. Each one is simple on its own, and together they put real controls around AI.
01
Assess
Find out which AI tools your people already use and where your information goes.
02
Train
Give your team the knowledge to spot risks, through realistic, hands-on scenarios.
03
Govern
Agree who is accountable and write clear rules everyone can follow.
04
Protect
Put sensible access, data and AI checks in place, and guide your team on safe use.
05
Approve
Choose and approve the right tools for your business and your information.
06
Test
Try everything out before launch, and record the results.
07
Launch
Go live with clear owners and an incident process ready.
08
Monitor
Review how AI is used and keep improving, on a regular schedule.
This isn't about teaching your staff to use ChatGPT. It's about giving your business the rules, tools, training and human oversight to use AI confidently.
02 · Security basics
Safe AI use is layers, not one product
No single tool makes a business safe. It takes several simple protections working together, so that one mistake doesn't become a serious problem. We explain these basics so you know what to ask for.
Only the right people get in
Every person has their own login, protected by two-step verification. People only see what their job needs, and access is removed the day someone leaves.
How we help: Simple checklists for accounts, two-step login and regular access reviews.
Sensitive information stays protected
Clear rules about what can and can't be put into AI tools, backed by settings that stop confidential files being shared by accident.
How we help: Clear rules about what can be shared, and questions to ask your IT provider.
Only approved tools are used
Business-grade AI accounts replace free personal ones, so you know where your information is stored and who can see it.
How we help: Tool assessments, an approved tools list, vendor checks.
AI conversations are screened
Prompts and AI answers can be checked for things like confidential data, harmful instructions and unsafe content before they reach people.
How we help: Planning and setting up Google Cloud Model Armor to screen prompts and responses.
You can see what's happening
Activity is logged and reviewed, and everyone knows what to do if something goes wrong.
How we help: An incident procedure and a regular review routine.
Your people know the rules
Security fails when staff don't understand it. Short, practical training turns the rules into everyday habits.
How we help: Role-based training, quick reference sheets, training records.
03 · Australian guidance
What businesses need to know about AI rules
The short version, in plain English.
There is no single “AI Act”
Australia doesn't currently have one general AI law. Instead, AI use is covered by laws that already exist:
Privacy
Consumer law
Workplace law
Copyright and IP
Contract law
Negligence
Online safety
Industry-specific rules
The Government's AI adoption guidance helps organisations use AI responsibly. It doesn't replace any of those legal obligations.
Documentation matters
The guidance encourages organisations to write down their AI governance, so they can audit, review, learn and improve. We help you keep clear records of:
AI registers
Risk assessments
Policies
Test records
Training records
Approvals
Review records
You don't need a perfect system first. The guidance recommends starting across all six practices below and improving as you go.
The six essential practices
From the Australian Government's Guidance for AI Adoption (National AI Centre, October 2025). We build our service around them.
1
Accountability
Decide who owns AI in your business, and set the policies and skills to support them.
We help with: An AI owner, named responsibilities, an AI policy.
2
Understand impacts
Work out who or what each AI use could affect, and how.
We help with: An AI inventory and impact notes for each use.
3
Manage risk
Identify, assess and control the risks before AI is used.
We help with: An AI risk register with a green, amber and red rating.
4
Share information
Make sure the right people understand your AI systems and how they're used.
We help with: Plain-English notices, staff guidance and customer information.
5
Test and monitor
Test before launch, then keep watching after it.
We help with: Test records, monitoring checks and a review schedule.
6
Keep human control
Keep people able to oversee, step in and override AI.
We help with: Human review points and clear approval steps.
From 10 December 2026, some organisations must add extra information to their privacy policy when software helps make decisions that significantly affect people.
Does this apply to you? The rules apply to “APP entities”. Most small businesses with an annual turnover of $3 million or less are currently exempt from the Privacy Act, with some exceptions (for example, health service providers and businesses that trade in personal information). We can help you work out where you stand, but for a formal answer, ask a qualified legal expert.
When it applies: all three
1A computer program makes a decision, or does something substantially and directly related to making one.
2The decision could reasonably be expected to significantly affect someone's rights or interests.
3Personal information about that person is used in how the program works.
It's broader than AI. The law refers to a “computer program”. That can include rule-based software, machine learning, generative AI and chatbots. It isn't a “ChatGPT law”.
What the privacy policy must then say
The kinds of personal information the program uses, for example employment history, account details or payment history.
The kinds of decisions made solely by the program, for example automatically approving or rejecting a request.
The kinds of decisions where the program does something substantially and directly related to the decision, for example ranking applicants before a person chooses.
A person checking doesn't automatically remove this
The OAIC says a decision can still be covered where a person reviews the program's output. For example, if AI ranks job applicants and HR makes the final choice, the ranking step may still need assessing.
Examples from the OAIC
AI that screens or ranks job applications
AI tools that help draft staff performance reviews that influence promotions
Software that automatically approves or rejects refunds
Case-management software that automatically escalates certain complaints
“Significant” matters
Not every automated task counts. The decision must reasonably be expected to significantly affect someone's rights or interests, such as their contract rights, access to important services, benefits or healthcare. The effect can depend on the person's circumstances.
Third-party software still counts
“Our software provider makes the decision” isn't an answer. The OAIC expects organisations to understand and oversee third-party programs they choose to use, including when buying them, and to make responsibilities clear in contracts.
Our service
Automated Decision-Making Readiness Review
A short review to find out whether any of your systems are affected, before the deadline.
“Do any of your systems use personal information to rank, recommend, approve, decline, escalate or otherwise influence decisions about customers or employees?”
If the answer is yes or maybe, this review is for you.
3Identify the decisions or recommendations they make
4Check whether people could be significantly affected
5Record where a person is involved
6Identify third-party systems
7List the kinds of information used
8Review your existing privacy policy
9Flag where APP 1.7 to 1.9 may apply
10Refer complex legal questions to a qualified privacy or legal professional
11Update your operational documents
12Set up ongoing monitoring
Source: OAIC guidance on transparency for AI and automated decision-making. Requirements and guidance can change, so check the latest before acting. Guidance and general information. We recommend your finished setup is reviewed and certified by a qualified legal or AI governance expert.
05 · AI policies
Two different policies, and you may need both
AI governance is the set of rules and responsibilities that decide how AI can be used inside a business. That starts with your policies.
Tells your team
Internal AI policy
How your organisation allows AI to be used: which tools, what information, and who checks the results.
Tells the public
Privacy policy
How your organisation manages personal information, including (from December 2026, for organisations covered) how automated decisions use it.
See the questions a good AI policy answers16
Accountability
Who owns AI governance?
Approved use
What can AI be used for?
Prohibited use
What can't it be used for?
AI systems
Which tools are approved?
Data
What information may be used?
Privacy
How is personal information protected?
Security
How are systems and accounts protected?
Human oversight
Who checks the results?
Risk
Which uses need extra assessment?
Transparency
When should customers be told?
Buying new tools
How are new AI vendors assessed?
Testing
How do we know it works?
Monitoring
How is performance reviewed?
Incidents
What happens when something fails?
Training
What must staff understand?
Review
When is the policy reassessed?
06 · Approved tools
Know what your team is already using
Many businesses already have staff using AI tools the business never approved. That's called shadow AI, and it's the biggest gap we find.
Shadow AI
Your people may already be using these, with no idea where the information goes:
ChatGPT
Gemini
Microsoft Copilot
Claude
AI meeting assistants
Canva AI
CRM and email AI
Browser extensions
Blocking AI completely usually isn't realistic. A better approach is knowing what your people use and setting clear boundaries.
Questions we help you answer8
Who is allowed to use AI?
Which AI tools are approved?
What information can staff upload, and what is off limits?
When does a person need to check the output?
Can AI talk to customers directly, or make decisions?
Who is accountable if AI gets something wrong?
How are new AI tools approved?
What happens if confidential information is entered by mistake?
How we choose tools
We don't recommend AI platforms simply because they're popular or offer a paid plan. We assess the tools against your business needs, information sensitivity, existing technology, security requirements and governance obligations before recommending which ones your team can use.
This is also consistent with Australia's OAIC guidance, which calls for due diligence before adopting commercial AI products, including evaluation of privacy risks, access to personal information and human oversight.
We start with five tool families
ChatGPT Business and Enterprise
Google Workspace with Gemini
Gemini Enterprise
Microsoft Copilot
Claude Team and Enterprise
All product names are trademarks of their owners. BREVORA is an independent consultant and is not a reseller or partner of these providers.
07 · Staff training
Eight modules, built around your own policy
Generic online AI training doesn't know your rules. Ours finishes with exactly what your staff can and can't do in your business.
Module 1
AI at work
What AI is, where your team meets it, and what it can and can't reliably do.
Module 2
Safe information handling
What staff can share, and what stays confidential: customer and sensitive data.
Module 3
Approved AI tools
Business tools versus free consumer tools, and what shadow AI is.
Module 4
Safe prompting
Writing useful prompts without exposing information you shouldn't.
Module 5
AI errors
Made-up answers, bias, misinformation and how to verify sources.
Module 6
Human review
What always needs checking, and when a manager must approve.
Module 7
Customer-facing AI
Chatbots, AI content, being open with customers and automated decisions.
Module 8
Your company's AI policy
Exactly what staff can and can't do in your organisation.
How every session works
More than slides: people practise real decisions.
01
Understand
What is the risk?
02
See
A realistic example.
03
Decide
What would you do?
04
Teach
The correct response.
05
Practise
Work through a scenario.
06
Confirm
A short knowledge check.
07
Document
Training completion is recorded.
08 · What you receive
A complete governance pack, not just a workshop
Clear documents your whole team can use, kept simple and practical.
AI usage assessmentCurrent AI use, including unapproved tools.
AI risk registerEach use rated green, amber or red.
Approved tools registerApproved, restricted and prohibited tools.
AI acceptable use policyRules everyone can understand.
Data and AI guidanceWhat can and can't go into AI.
AI governance frameworkOwners, approvals and accountability.
AI procurement checklistHow to assess new AI tools.
AI incident procedureWhat to do when something goes wrong.
Role-based staff trainingRelevant to each job in your business.
Prompting guidePractical examples for everyday work.