Guide · AI governance

AI policy for small business: a practical guide

If you run a business in Newcastle or the Hunter, you already know your team is using AI. This guide is for the owner who is nervous rather than technical. It sets out, in plain words, what a good AI policy needs to cover and why it matters now.

Why this matters now

AI has moved from an experiment a few people were trying to something your staff reach for every day. The problem is that it moved faster than the rules around it. Most small businesses have people putting work into AI tools with no shared understanding of what is allowed, where the data goes, or who is responsible when something goes wrong.

A policy exists to close that gap. Its job is to move a business from AI as an experiment to AI as adopted infrastructure, so everyone, from directors to employees to contractors, is on the same page. Without one, your exposure is real. With one, AI becomes something you can answer for instead of something happening in the background.

The personal-accounts risk, explained plainly

This is the single biggest risk, and it is worth slowing down for. Free and personal AI plans can train on whatever is typed into them. That means a staff member pasting a client email, a quote or a patient note into a free account may be handing that information to the AI company to learn from. This is where the client-data horror stories come from. The data leaves your business, you lose control of it, and you may not even know it happened.

The fix is not to ban AI. It is to give people one approved place to use it that does not train on your data, and to make personal accounts off-limits for anything work-related. Most staff are not trying to do the wrong thing. They are trying to get work done quickly, and a free account is the fastest path in front of them. A good policy removes that temptation by giving them a safe one instead.

The big four, free vs business

How the major AI tools treat your data depends on which tier you are on. Here is how ChatGPT, Claude, Gemini and Copilot handle training on free and personal plans versus their business tiers.

ChatGPT (OpenAI)

Free and personal plans. On Free, Plus and Pro, conversations are used for model training by default. Users can opt out via Settings > Data Controls > "Improve the model for everyone".

Business tier. ChatGPT Business, Enterprise and Edu are not used for training by default.

Claude (Anthropic)

Free and personal plans. On Free, Pro and Max, chats are only used for training if you opt in to model improvement. Allowing it means up to five-year retention, declining means about 30 days.

Business tier. Claude for Work (Team and Enterprise), Government, Education and API are not used for training.

Gemini (Google)

Free and personal plans. On personal accounts with the default "Keep Activity" setting on, chats are used to improve Google's AI and a subset is reviewed by human reviewers. Reviewed chats can be kept up to three years.

Business tier. Gemini in Google Workspace (business) is not used to train models outside your organisation.

Copilot (Microsoft)

Free and personal plans. On the consumer version, conversations are used for model training by default with an opt-out in settings. Users signed in with a work (Entra ID) account are excluded.

Business tier. Microsoft 365 Copilot for business does not use your prompts or organisational data to train models.

These policies are accurate as at August 2026 and change over time. Check the vendor's current documentation or ask us before relying on them.

Which one should your business run?

If your business lives in Microsoft 365, the business Copilot tier fits naturally. If it lives in Google Workspace, Gemini for Workspace is the match. Claude's business plans are the strongest fit for teams building their own AI tools and agents, which is where we do most of our work. Whichever you choose, the rule is the same: the business-grade tier with training off, never personal accounts for work data.

What a good policy covers

A good AI policy names what needs to exist, clearly enough that anyone in the business can follow it. These are the elements it should cover.

One approved business-grade AI environment. A single, organisation-controlled account with a no-training data agreement, so the tools your team uses cannot learn from what you put into them.

A hard rule against personal AI accounts for work data. Free and personal plans are off-limits for anything that touches the business, because that is where data leaks.

Clear rules on what data can and cannot go into AI tools. Client information, commercial details and anything protected by law or contract stays out unless the approved environment and the client allow it.

Human review of anything AI produces before it goes out. AI output is a draft, not a finished product. A person checks it before it reaches a client, a file or a decision.

A written record of where AI is used across the business. A simple register of the tools, who uses them and what they touch. This is also the direction ISO 42001 points, and it makes the difference between governing AI and hoping for the best.

Being upfront with clients about how AI is used on their work. No surprises. Clients know where AI is in the process and where a person is still in charge.

Training staff on the rules. A policy nobody has read is not governance. Your people need to understand what is allowed, what is not, and why, so the policy holds in practice rather than only on paper.

What to do about it

If you have read this far, you already have the picture. The next step is to make it real for your business. That means setting up the one approved environment, writing the policy to fit how your team actually works, and making sure the people who rely on it understand it.

You do not have to do this alone, and you do not have to start from a blank page. Helm sets up AI policies for businesses across Newcastle and the Hunter. If you want a policy that fits your business and a team that knows how to follow it, that is where we come in.

Helm sets up AI policies for Hunter businesses

If you are ready to move from experiment to adopted infrastructure, book an intro call with Ryan and Oliver. We will look at how AI is already being used in your business and what a policy needs to cover. We can also take it further with ISO 42001 readiness, or train your team so the policy holds in practice.

Frequently asked questions

Do I legally need an AI policy in Australia?

There is no single law that says every small business must have a written AI policy. But the obligations you already carry, privacy law, confidentiality, professional duty and client contracts, apply just as much to AI as to anything else. A policy is how you show you are meeting them on AI use specifically. If you hold client data, supply to government, or answer to insurers, a written policy moves you from exposed to organised.

Can staff put client information into ChatGPT?

Not into free or personal accounts. Consumer plans of most major tools use conversations for training by default or depending on settings, while business tiers like ChatGPT Business, Claude for Work, Gemini for Workspace and Microsoft 365 Copilot do not train on your data.

What is ISO 42001?

ISO/IEC 42001 is the first internationally recognised standard for managing AI systems. It gives a business a structured, auditable way to govern AI: a clear policy, a register of tools, risk assessments and defined responsibilities. It is voluntary and certified by independent accredited bodies. Helm prepares your business for it rather than certifying it. Read more on our ISO 42001 readiness page.

What counts as a business-grade AI environment?

A paid, organisation-controlled account with a vendor that contractually agrees not to train on your data, set up under your own tenant so you control access and retention. It is the opposite of a staff member signing into a free personal account on their phone. The policy names which environment is approved and makes anything else off-limits for work data.

Where do I start?

Start by talking to Helm. We will look at how AI is already being used in your business, where the real exposure sits, and what a policy for your business needs to cover. From there we can set up the approved environment, write the policy, and train your team. Book an intro call with Ryan and Oliver to begin.

This guide is general information, not legal advice. For advice specific to your business, talk to Helm or your legal advisor.