BREVORA
AI & Technology services

Client guide

Use AI with confidence. Know the risks and prevent them.

We help your organisation understand AI and put practical controls in place, so your team can use it productively and prevent privacy, security, accuracy and reputational mistakes.

Please note: Everything here is guidance and general information. We recommend that, once your AI and automation advice has been implemented, it is reviewed and certified by a qualified legal or AI governance expert. Your obligations depend on your business. Last reviewed 7 October 2026.

Our approach

AI governance isn't about slowing innovation

It's about knowing where AI creates risk, keeping important decisions accountable, and helping businesses adopt AI with confidence.

  1. Make AI smarter.Use AI where it genuinely helps, with good information, clear instructions and the right tools.
  2. Keep decisions accountable.A named person stays responsible for important decisions, even when AI helps make them.
  3. Make AI decisions explainable.If an AI system influences an important decision, your business should be able to explain why.

01 · How we work

From first review to ongoing improvement

Eight steps, in order. Each one is simple on its own, and together they put real controls around AI.

  1. 01

    Assess

    Find out which AI tools your people already use and where your information goes.

  2. 02

    Train

    Give your team the knowledge to spot risks, through realistic, hands-on scenarios.

  3. 03

    Govern

    Agree who is accountable and write clear rules everyone can follow.

  4. 04

    Protect

    Put sensible access, data and AI checks in place, and guide your team on safe use.

  5. 05

    Approve

    Choose and approve the right tools for your business and your information.

  6. 06

    Test

    Try everything out before launch, and record the results.

  7. 07

    Launch

    Go live with clear owners and an incident process ready.

  8. 08

    Monitor

    Review how AI is used and keep improving, on a regular schedule.

This isn't about teaching your staff to use ChatGPT. It's about giving your business the rules, tools, training and human oversight to use AI confidently.

02 · Security basics

Safe AI use is layers, not one product

No single tool makes a business safe. It takes several simple protections working together, so that one mistake doesn't become a serious problem. We explain these basics so you know what to ask for.

Only the right people get in

Every person has their own login, protected by two-step verification. People only see what their job needs, and access is removed the day someone leaves.

How we help: Simple checklists for accounts, two-step login and regular access reviews.

Sensitive information stays protected

Clear rules about what can and can't be put into AI tools, backed by settings that stop confidential files being shared by accident.

How we help: Clear rules about what can be shared, and questions to ask your IT provider.

Only approved tools are used

Business-grade AI accounts replace free personal ones, so you know where your information is stored and who can see it.

How we help: Tool assessments, an approved tools list, vendor checks.

AI conversations are screened

Prompts and AI answers can be checked for things like confidential data, harmful instructions and unsafe content before they reach people.

How we help: Planning and setting up Google Cloud Model Armor to screen prompts and responses.

You can see what's happening

Activity is logged and reviewed, and everyone knows what to do if something goes wrong.

How we help: An incident procedure and a regular review routine.

Your people know the rules

Security fails when staff don't understand it. Short, practical training turns the rules into everyday habits.

How we help: Role-based training, quick reference sheets, training records.

03 · Australian guidance

What businesses need to know about AI rules

The short version, in plain English.

There is no single “AI Act”

Australia doesn't currently have one general AI law. Instead, AI use is covered by laws that already exist:

  • Privacy
  • Consumer law
  • Workplace law
  • Copyright and IP
  • Contract law
  • Negligence
  • Online safety
  • Industry-specific rules

The Government's AI adoption guidance helps organisations use AI responsibly. It doesn't replace any of those legal obligations.

Documentation matters

The guidance encourages organisations to write down their AI governance, so they can audit, review, learn and improve. We help you keep clear records of:

  • AI registers
  • Risk assessments
  • Policies
  • Test records
  • Training records
  • Approvals
  • Review records

You don't need a perfect system first. The guidance recommends starting across all six practices below and improving as you go.

The six essential practices

From the Australian Government's Guidance for AI Adoption (National AI Centre, October 2025). We build our service around them.

  1. 1

    Accountability

    Decide who owns AI in your business, and set the policies and skills to support them.

    We help with: An AI owner, named responsibilities, an AI policy.

  2. 2

    Understand impacts

    Work out who or what each AI use could affect, and how.

    We help with: An AI inventory and impact notes for each use.

  3. 3

    Manage risk

    Identify, assess and control the risks before AI is used.

    We help with: An AI risk register with a green, amber and red rating.

  4. 4

    Share information

    Make sure the right people understand your AI systems and how they're used.

    We help with: Plain-English notices, staff guidance and customer information.

  5. 5

    Test and monitor

    Test before launch, then keep watching after it.

    We help with: Test records, monitoring checks and a review schedule.

  6. 6

    Keep human control

    Keep people able to oversee, step in and override AI.

    We help with: Human review points and clear approval steps.

Read the Government guidance

04 · Starts 10 December 2026

Automated decisions and your privacy policy

From 10 December 2026, some organisations must add extra information to their privacy policy when software helps make decisions that significantly affect people.

Does this apply to you? The rules apply to “APP entities”. Most small businesses with an annual turnover of $3 million or less are currently exempt from the Privacy Act, with some exceptions (for example, health service providers and businesses that trade in personal information). We can help you work out where you stand, but for a formal answer, ask a qualified legal expert.

When it applies: all three

  1. 1A computer program makes a decision, or does something substantially and directly related to making one.
  2. 2The decision could reasonably be expected to significantly affect someone's rights or interests.
  3. 3Personal information about that person is used in how the program works.

It's broader than AI. The law refers to a “computer program”. That can include rule-based software, machine learning, generative AI and chatbots. It isn't a “ChatGPT law”.

What the privacy policy must then say

  • The kinds of personal information the program uses, for example employment history, account details or payment history.
  • The kinds of decisions made solely by the program, for example automatically approving or rejecting a request.
  • The kinds of decisions where the program does something substantially and directly related to the decision, for example ranking applicants before a person chooses.

A person checking doesn't automatically remove this

The OAIC says a decision can still be covered where a person reviews the program's output. For example, if AI ranks job applicants and HR makes the final choice, the ranking step may still need assessing.

Examples from the OAIC

  • AI that screens or ranks job applications
  • AI tools that help draft staff performance reviews that influence promotions
  • Software that automatically approves or rejects refunds
  • Case-management software that automatically escalates certain complaints

“Significant” matters

Not every automated task counts. The decision must reasonably be expected to significantly affect someone's rights or interests, such as their contract rights, access to important services, benefits or healthcare. The effect can depend on the person's circumstances.

Third-party software still counts

“Our software provider makes the decision” isn't an answer. The OAIC expects organisations to understand and oversee third-party programs they choose to use, including when buying them, and to make responsibilities clear in contracts.

Our service

Automated Decision-Making Readiness Review

A short review to find out whether any of your systems are affected, before the deadline.

“Do any of your systems use personal information to rank, recommend, approve, decline, escalate or otherwise influence decisions about customers or employees?”

If the answer is yes or maybe, this review is for you.

Ask about this review
  1. 1List your automated systems
  2. 2Find which use personal information
  3. 3Identify the decisions or recommendations they make
  4. 4Check whether people could be significantly affected
  5. 5Record where a person is involved
  6. 6Identify third-party systems
  7. 7List the kinds of information used
  8. 8Review your existing privacy policy
  9. 9Flag where APP 1.7 to 1.9 may apply
  10. 10Refer complex legal questions to a qualified privacy or legal professional
  11. 11Update your operational documents
  12. 12Set up ongoing monitoring

Source: OAIC guidance on transparency for AI and automated decision-making. Requirements and guidance can change, so check the latest before acting. Guidance and general information. We recommend your finished setup is reviewed and certified by a qualified legal or AI governance expert.

05 · AI policies

Two different policies, and you may need both

AI governance is the set of rules and responsibilities that decide how AI can be used inside a business. That starts with your policies.

Tells your team

Internal AI policy

How your organisation allows AI to be used: which tools, what information, and who checks the results.

Tells the public

Privacy policy

How your organisation manages personal information, including (from December 2026, for organisations covered) how automated decisions use it.

See the questions a good AI policy answers16
  • Accountability

    Who owns AI governance?

  • Approved use

    What can AI be used for?

  • Prohibited use

    What can't it be used for?

  • AI systems

    Which tools are approved?

  • Data

    What information may be used?

  • Privacy

    How is personal information protected?

  • Security

    How are systems and accounts protected?

  • Human oversight

    Who checks the results?

  • Risk

    Which uses need extra assessment?

  • Transparency

    When should customers be told?

  • Buying new tools

    How are new AI vendors assessed?

  • Testing

    How do we know it works?

  • Monitoring

    How is performance reviewed?

  • Incidents

    What happens when something fails?

  • Training

    What must staff understand?

  • Review

    When is the policy reassessed?

06 · Approved tools

Know what your team is already using

Many businesses already have staff using AI tools the business never approved. That's called shadow AI, and it's the biggest gap we find.

Shadow AI

Your people may already be using these, with no idea where the information goes:

  • ChatGPT
  • Gemini
  • Microsoft Copilot
  • Claude
  • AI meeting assistants
  • Canva AI
  • CRM and email AI
  • Browser extensions

Blocking AI completely usually isn't realistic. A better approach is knowing what your people use and setting clear boundaries.

Questions we help you answer8
  • Who is allowed to use AI?
  • Which AI tools are approved?
  • What information can staff upload, and what is off limits?
  • When does a person need to check the output?
  • Can AI talk to customers directly, or make decisions?
  • Who is accountable if AI gets something wrong?
  • How are new AI tools approved?
  • What happens if confidential information is entered by mistake?

How we choose tools

We don't recommend AI platforms simply because they're popular or offer a paid plan. We assess the tools against your business needs, information sensitivity, existing technology, security requirements and governance obligations before recommending which ones your team can use.

This is also consistent with Australia's OAIC guidance, which calls for due diligence before adopting commercial AI products, including evaluation of privacy risks, access to personal information and human oversight.

We start with five tool families

  • ChatGPT Business and Enterprise
  • Google Workspace with Gemini
  • Gemini Enterprise
  • Microsoft Copilot
  • Claude Team and Enterprise

All product names are trademarks of their owners. BREVORA is an independent consultant and is not a reseller or partner of these providers.

07 · Staff training

Eight modules, built around your own policy

Generic online AI training doesn't know your rules. Ours finishes with exactly what your staff can and can't do in your business.

  1. Module 1

    AI at work

    What AI is, where your team meets it, and what it can and can't reliably do.

  2. Module 2

    Safe information handling

    What staff can share, and what stays confidential: customer and sensitive data.

  3. Module 3

    Approved AI tools

    Business tools versus free consumer tools, and what shadow AI is.

  4. Module 4

    Safe prompting

    Writing useful prompts without exposing information you shouldn't.

  5. Module 5

    AI errors

    Made-up answers, bias, misinformation and how to verify sources.

  6. Module 6

    Human review

    What always needs checking, and when a manager must approve.

  7. Module 7

    Customer-facing AI

    Chatbots, AI content, being open with customers and automated decisions.

  8. Module 8

    Your company's AI policy

    Exactly what staff can and can't do in your organisation.

How every session works

More than slides: people practise real decisions.

  1. 01

    Understand

    What is the risk?

  2. 02

    See

    A realistic example.

  3. 03

    Decide

    What would you do?

  4. 04

    Teach

    The correct response.

  5. 05

    Practise

    Work through a scenario.

  6. 06

    Confirm

    A short knowledge check.

  7. 07

    Document

    Training completion is recorded.

08 · What you receive

A complete governance pack, not just a workshop

Clear documents your whole team can use, kept simple and practical.

  • AI usage assessmentCurrent AI use, including unapproved tools.
  • AI risk registerEach use rated green, amber or red.
  • Approved tools registerApproved, restricted and prohibited tools.
  • AI acceptable use policyRules everyone can understand.
  • Data and AI guidanceWhat can and can't go into AI.
  • AI governance frameworkOwners, approvals and accountability.
  • AI procurement checklistHow to assess new AI tools.
  • AI incident procedureWhat to do when something goes wrong.
  • Role-based staff trainingRelevant to each job in your business.
  • Prompting guidePractical examples for everyday work.
  • Manager guideHow supervisors check AI use.
  • Quick reference sheetA one-page Don't / Check / Safe guide.
  • Training completion recordEvidence your team was trained.
  • Review scheduleWhen policies and AI use are reassessed.

09 · What we help with

We help with

  • Governance assessments
  • AI inventories and workflow mapping
  • Policy writing and implementation support
  • Staff training
  • Practical tool recommendations
  • Vendor and tool reviews
  • Risk rules and documentation
  • Testing support
  • Privacy-governance readiness reviews

Assess. Train. Govern. Protect. Approve. Test. Launch. Monitor.

Start with a free 20-minute call

Tell us how your team uses AI today. We'll point out the biggest gaps and what to do first. Custom quotes follow the call.