AI-assisted workflows · Governance and guardrails · Sydney

Governance and guardrails

Most organisations have no AI policy and a great deal of AI use, which is the worst combination available: all of the risk, none of the benefit of a decision, and no record of what anybody did.

Grab the snowball. Give it a spin, and watch it grow as you scroll. Just like the standard.

4questions a policy has to answer
1page people will actually read
Permissivewhere the risk is genuinely low
Recordedso it can be defended later

The short answer

What should an AI content policy actually say?

A useful AI content policy answers four questions and no more: what these tools may be used for, what they may never be used for, who decides the cases in between, and what is recorded. Anything longer is not read, and a policy that is not read is not a policy.

The common failure is a document written by people managing risk without input from the people doing the work. It bans everything, everybody uses the tools anyway without telling anyone, and the organisation now has the same exposure plus a false belief that it is controlled.

So a good policy is more permissive than most drafts and much clearer about the small number of genuine prohibitions. It sits inside our wider AI-assisted workflows service, and because our Snowball SEO platform automates the search heavy lifting other agencies bill by the hour, more of your budget goes into the work rather than its administration.

The difference

How much should a policy actually restrict?

Less than most drafts, in more places, with a much clearer line around the few things that genuinely matter.

How a workable AI policy is shapedThree tiers narrowing upward. At the base, the large majority of uses that are permitted without asking, because the risk is genuinely low. In the middle, uses that need a conversation with a named person. At the top, a small number of genuine prohibitions that are absolute and clearly stated.Prohibited, absolutelya short and clear listAsk a named personthe genuine grey areaPermitted, no permission neededmost of itPolicies that invert this shape, prohibiting most things, are ignored in practice and leave an organisation with the exposure and no record.
A policy shaped this way is followed. A policy shaped the other way up, where most things require permission, is routed around within a month and leaves you worse off than having none.

Usually fine, and should be stated as such

  • Research, summarising and finding sources
  • Outlining, structuring and first-draft scaffolds a person then rewrites
  • Transcription, translation drafts and format conversion
  • Checking: consistency, gaps, things left out

Genuine prohibitions, and there are few

  • Publishing anything unedited under a person's name
  • Putting confidential or personal data into tools that retain it
  • Generating people, testimonials or results
  • Claims of fact that no person has verified

The checking that makes the fourth prohibition enforceable is our human QA and fact-checking work.

The cost

What drives the price of governance work?

Organisation size, regulation and how much shadow use already exists. Writing the policy is quick; agreeing it and finding out what people are already doing is not.

A policy

The document

One page, answering the four questions, written with input from the people doing the work rather than only from the people managing risk.

Policy and rollout

Adopted

The same, plus the sessions and the named decision-makers that turn it into practice rather than a file.

Governance programme

Ongoing

For regulated or larger organisations: records, periodic review, supplier requirements and a defensible position.

We quote after a free consult. In regulated categories we will say clearly where our work stops and legal advice begins, because that boundary matters here more than anywhere else on this site.

What moves the number, in order

  • How many teams and how much existing unrecorded use there is
  • How regulated the category is
  • Whether suppliers and contractors are in scope, which they should be
  • What records are required and for how long
  • Whether a disclosure position has to be developed
  • Whether periodic review is included

Find out what people are already doing

Every policy engagement begins with the same discovery: the tools are already in wide use, unrecorded, by people who assumed it was fine or assumed it was not and did it anyway.

That is not a disciplinary matter and treating it as one guarantees you never get an honest answer again. It is the most important input you have, because it tells you what the policy actually has to address.

So the first conversation is amnesty-shaped: what are you using, for what, and what would you like to be allowed to do. Policies written from that are followed.

The scope

What you receive

One page people will read, and the decisions that make it real.

The policy

One page answering what is allowed, what is prohibited, who decides the rest and what is recorded. Longer documents are not read.

Named decision-makers

Who to ask about the grey area, with a turnaround, because unanswered questions become improvised decisions.

A disclosure position

What you tell clients, audiences and staff, decided in advance rather than under pressure.

Supplier requirements

What agencies and contractors must comply with, since most exposure now arrives through people who do not work for you.

A record standard

What gets logged, where, and for how long, so a decision can be defended a year later.

A review date

Because this area moves faster than any policy written once, and a stale policy is worse than none because it is trusted.

The return

What does a policy actually prevent?

Less than people hope and more than nothing. Its real function is to make the decisions in advance so nobody improvises them under deadline.

The layers that make governance workFive stacked layers from the bottom up: knowing what is actually being used, a written policy, named decision-makers for the grey area, records of what was done, and at the top periodic review. Each layer depends on the ones beneath it, and a policy written without the bottom layer usually addresses the wrong things.Know what is being usedhonestly, without blameA written policyone page, four questionsNamed decision-makersfor the grey areaRecordsso it can be defendedPeriodic reviewbecause this movesBuilt bottom upMost start at the second layer
Most policies are written starting at the second layer, without knowing what is actually being used. That is why so many of them prohibit things nobody wanted to do and permit things people were already worried about.

The point is to decide in advance

A policy does not stop somebody determined to do the wrong thing. What it does is remove improvisation from everybody else, so a person facing an unusual request at four o'clock has an answer rather than a judgement call.

That is worth a great deal and it is a more modest claim than most policy documents make for themselves. Presenting it honestly is also what gets it adopted, because people can tell when a document is overclaiming.

The second function is evidential. If a decision is challenged later, a record of what was allowed, by whom, on what date, is the difference between a defensible position and a difficult conversation.

The process

How governance gets set up

Three to five weeks, most of it finding out what is actually happening.

Week 1

Find out what is in use

Without blame, because an honest answer is the most valuable input and you only get one chance at asking for it.

Week 2

Draft the four answers

What is allowed, what is prohibited, who decides the rest, what is recorded. One page.

Week 2

Test it against real cases

Against things people actually want to do, because a policy that cannot answer a real question will not be consulted twice.

Week 3

Name the deciders

For the grey area, with a turnaround they have agreed to rather than been assigned.

Week 4

Set the record standard

What is logged, where, for how long, in a way that is realistic rather than aspirational.

Week 5

Roll out and date the review

Agreed with the people it affects, and with a date to revisit, because this area will not hold still.

The brief

What to ask before you write an AI policy

The failure mode is a document that satisfies a risk committee and changes nothing about what people do.

Have you asked what is already being used?

Without blame. A policy written without that answer usually prohibits things nobody wanted and permits things people were already worried about.

How long is the document?

One page, or people will not read it, and an unread policy provides the appearance of control rather than control.

Are suppliers in scope?

Most exposure now arrives through agencies and contractors. A policy covering only employees leaves the larger half unaddressed.

What is recorded?

Decisions and their reasons. A policy with no record cannot be defended later, which is the moment anybody actually wants it.

We are happy to answer all four. In regulated categories we will also say clearly where our work stops and where you need legal advice, because that line matters more here than anywhere else.

Start here

Ready to decide it in advance?

Tell us what your team is already using, honestly. The free consult is a working session, not a sales call, and you leave with three things whether or not you book us.

  • An honest picture of what is already in use, which is usually the surprise
  • The four answers your policy needs, drafted
  • A fixed price, with the boundary to legal advice stated plainly
Get your free policy outline

Good questions

AI governance FAQs

What should an AI content policy contain?

Four answers and no more: what these tools may be used for, what they may never be used for, who decides the cases in between, and what is recorded. One page. Longer documents are not read, and an unread policy is not a policy.

Why do most AI policies fail?

They are written by people managing risk without input from the people doing the work. They prohibit almost everything, the tools get used anyway without anybody saying so, and the organisation ends up with the same exposure plus a false belief it is controlled.

How restrictive should it be?

Less than most drafts. Most uses, such as research, outlining, transcription and checking, are genuinely low risk and should be explicitly permitted. The genuine prohibitions are few and should be stated absolutely clearly.

How much does this cost?

We quote after a consult. What moves it is how many teams are involved, how much unrecorded use already exists, how regulated the category is, whether suppliers are in scope, and what records are required.

Should suppliers be covered?

Yes, and most policies do not cover them. A great deal of exposure now arrives through agencies and contractors, and a policy that only binds employees has addressed the smaller half of the problem.

What should we disclose?

Decide it before somebody asks. Our own position is that the named author is accountable regardless of the tools involved, and that we will say exactly how anything was made if asked. Being asked and having no position is the worst outcome.

Does this replace legal advice?

No, and we say so explicitly. We can write a workable policy and a record standard. In a regulated category the legal review is a separate obligation, and we will tell you plainly where our work stops.

How often should it be reviewed?

At least every six months at present. The tools, the norms and the regulation are all moving quickly, and a stale policy is worse than none because people trust it and it is quietly wrong.