Find out what is in use
Without blame, because an honest answer is the most valuable input and you only get one chance at asking for it.
AI-assisted workflows · Governance and guardrails · Sydney
Most organisations have no AI policy and a great deal of AI use, which is the worst combination available: all of the risk, none of the benefit of a decision, and no record of what anybody did.
Grab the snowball. Give it a spin, and watch it grow as you scroll. Just like the standard.
The short answer
A useful AI content policy answers four questions and no more: what these tools may be used for, what they may never be used for, who decides the cases in between, and what is recorded. Anything longer is not read, and a policy that is not read is not a policy.
The common failure is a document written by people managing risk without input from the people doing the work. It bans everything, everybody uses the tools anyway without telling anyone, and the organisation now has the same exposure plus a false belief that it is controlled.
So a good policy is more permissive than most drafts and much clearer about the small number of genuine prohibitions. It sits inside our wider AI-assisted workflows service, and because our Snowball SEO platform automates the search heavy lifting other agencies bill by the hour, more of your budget goes into the work rather than its administration.
The difference
Less than most drafts, in more places, with a much clearer line around the few things that genuinely matter.
The checking that makes the fourth prohibition enforceable is our human QA and fact-checking work.
The cost
Organisation size, regulation and how much shadow use already exists. Writing the policy is quick; agreeing it and finding out what people are already doing is not.
The document
One page, answering the four questions, written with input from the people doing the work rather than only from the people managing risk.
Adopted
The same, plus the sessions and the named decision-makers that turn it into practice rather than a file.
Ongoing
For regulated or larger organisations: records, periodic review, supplier requirements and a defensible position.
We quote after a free consult. In regulated categories we will say clearly where our work stops and legal advice begins, because that boundary matters here more than anywhere else on this site.
Every policy engagement begins with the same discovery: the tools are already in wide use, unrecorded, by people who assumed it was fine or assumed it was not and did it anyway.
That is not a disciplinary matter and treating it as one guarantees you never get an honest answer again. It is the most important input you have, because it tells you what the policy actually has to address.
So the first conversation is amnesty-shaped: what are you using, for what, and what would you like to be allowed to do. Policies written from that are followed.
The scope
One page people will read, and the decisions that make it real.
One page answering what is allowed, what is prohibited, who decides the rest and what is recorded. Longer documents are not read.
Who to ask about the grey area, with a turnaround, because unanswered questions become improvised decisions.
What you tell clients, audiences and staff, decided in advance rather than under pressure.
What agencies and contractors must comply with, since most exposure now arrives through people who do not work for you.
What gets logged, where, and for how long, so a decision can be defended a year later.
Because this area moves faster than any policy written once, and a stale policy is worse than none because it is trusted.
The return
Less than people hope and more than nothing. Its real function is to make the decisions in advance so nobody improvises them under deadline.
A policy does not stop somebody determined to do the wrong thing. What it does is remove improvisation from everybody else, so a person facing an unusual request at four o'clock has an answer rather than a judgement call.
That is worth a great deal and it is a more modest claim than most policy documents make for themselves. Presenting it honestly is also what gets it adopted, because people can tell when a document is overclaiming.
The second function is evidential. If a decision is challenged later, a record of what was allowed, by whom, on what date, is the difference between a defensible position and a difficult conversation.
The process
Three to five weeks, most of it finding out what is actually happening.
Without blame, because an honest answer is the most valuable input and you only get one chance at asking for it.
What is allowed, what is prohibited, who decides the rest, what is recorded. One page.
Against things people actually want to do, because a policy that cannot answer a real question will not be consulted twice.
For the grey area, with a turnaround they have agreed to rather than been assigned.
What is logged, where, for how long, in a way that is realistic rather than aspirational.
Agreed with the people it affects, and with a date to revisit, because this area will not hold still.
The brief
The failure mode is a document that satisfies a risk committee and changes nothing about what people do.
Without blame. A policy written without that answer usually prohibits things nobody wanted and permits things people were already worried about.
One page, or people will not read it, and an unread policy provides the appearance of control rather than control.
Most exposure now arrives through agencies and contractors. A policy covering only employees leaves the larger half unaddressed.
Decisions and their reasons. A policy with no record cannot be defended later, which is the moment anybody actually wants it.
We are happy to answer all four. In regulated categories we will also say clearly where our work stops and where you need legal advice, because that line matters more here than anywhere else.
Start here
Tell us what your team is already using, honestly. The free consult is a working session, not a sales call, and you leave with three things whether or not you book us.
Good questions
Four answers and no more: what these tools may be used for, what they may never be used for, who decides the cases in between, and what is recorded. One page. Longer documents are not read, and an unread policy is not a policy.
They are written by people managing risk without input from the people doing the work. They prohibit almost everything, the tools get used anyway without anybody saying so, and the organisation ends up with the same exposure plus a false belief it is controlled.
Less than most drafts. Most uses, such as research, outlining, transcription and checking, are genuinely low risk and should be explicitly permitted. The genuine prohibitions are few and should be stated absolutely clearly.
We quote after a consult. What moves it is how many teams are involved, how much unrecorded use already exists, how regulated the category is, whether suppliers are in scope, and what records are required.
Yes, and most policies do not cover them. A great deal of exposure now arrives through agencies and contractors, and a policy that only binds employees has addressed the smaller half of the problem.
Decide it before somebody asks. Our own position is that the named author is accountable regardless of the tools involved, and that we will say exactly how anything was made if asked. Being asked and having no position is the worst outcome.
No, and we say so explicitly. We can write a workable policy and a record standard. In a regulated category the legal review is a separate obligation, and we will tell you plainly where our work stops.
At least every six months at present. The tools, the norms and the regulation are all moving quickly, and a stale policy is worse than none because people trust it and it is quietly wrong.