Work with us
Blog / Explainer
Explainer

Fifteen Minutes and the Start of an AI Policy

Before you switch on a new AI tool, seven questions to answer and one date to put in the calendar.

Image: Nanobanana (AI-generated)

Somebody in your business has found a new AI tool and wants to switch it on.

A chatbot for the website, a notetaker for meetings, something that sorts job applications before a person reads them.

It will probably save time, and that’s a perfectly good reason to do it.

But before it goes live, it’s worth spending fifteen minutes or so thinking about and writing down answers to seven questions, then reviewing them periodically to make sure your answers still align with how the tool is actually being used.

The point is that if the tool ever causes a problem, you have accountability. You can show what you knew, who was watching, and what you checked, rather than trying to piece it together afterwards.

If liability is an issue, working through this process diligently can at least show intent to use the tool responsibly.

This also gives you a solid foundation to reverse-engineer what went wrong and find opportunities for improvement.

1. What is it for?

Write down, in one sentence, what the tool does and who will use it.

“The website chatbot answers customer questions and books appointments.”

That’s the whole answer. If it takes a paragraph, the purpose isn’t clear yet, and an unclear purpose is usually where scope creep starts. A tool brought in to draft replies quietly ends up drafting contracts.

2. What goes into it?

What information will the tool see? Customer details, financial records, health information, anything you hold under a contract or a privacy obligation.

What you need to be thinking about here is: would you be comfortable if that information left the building?

Because once it goes into an AI tool, where it goes next is set by the terms you agreed to. It’s not by how much you paid the vendor or how well known the company is.

Whether your inputs are kept, who at the vendor can see them, and whether they are used to train the next version are all answered in the terms, and the answers differ between the free, personal and business plans of the same product.

So read the terms of your plan, and understand what you signed up for.

Find the sections on data use, retention and training for the plan you’re actually on, and write down what they say. It takes ten minutes, and it means the answer is yours rather than something you heard. If the answer involves sensitive data and you don’t like what you read, the fix is often as simple as changing plans.

If you can’t find the answer at all, that’s an answer too.

3. Who owns it?

Every AI use needs one named person who is accountable for it. This is someone who keeps an eye on it and can answer three questions at any time:

It’s worth stating explicitly: this isn’t someone to blame when it goes wrong.

Generally the best person is the one who is closest to how the tool is actually used. If reception uses the chatbot, someone in reception owns it.

Most of the AI problems I hear about trace back to a tool nobody was watching, not a tool somebody was watching badly.

We’ve written separately about what that person needs from the business to do the job properly.

4. What can it reach?

Can the tool see more than it needs to?

An AI assistant with access to your whole inbox, when the job only needs one shared folder, is carrying more risk than the job requires. The same goes for a notetaker connected to every calendar in the company.

Give it the least access that still lets it do the job. If the vendor’s setup makes that hard, that tells you something about the vendor.

5. What happens when it’s wrong?

It will be wrong sometimes. Every AI tool is, and the good ones are wrong confidently.

So the question is who checks the output before it matters. A chatbot answer that goes straight to a customer, a shortlist that decides who gets an interview: what is the human step between what the AI produces and the real-world consequence?

If the honest answer is “nobody checks”, that’s the risk to fix before launch, not a reason to abandon the tool. Usually it means adding a review step for the outputs that count and letting the low-stakes ones through.

6. Who needs to know?

If the tool talks to customers, they may need to know they’re dealing with AI. If it affects staff, whether that is screening applicants, monitoring work or scoring performance, the same applies.

There are legal duties here, and they depend on where your customers are and what the tool does. If you have customers in Europe, the EU AI Act reaches you. But the practical reason matters just as much. People trust a tool they were told about, and feel tricked by one they discover.

7. Where is it written down?

This is the record of your answers to the questions listed above. Ensuring that they are kept somewhere safe and reviewed and signed off on a regular schedule moves you from “I think we’re okay” to “I can show we’re okay”.

It’s what you reach for when a client, an auditor, an insurer or your own board asks how AI is being used in the business.

It’s also the beginning of an AI policy, whether or not you ever call it that.

Then put a date in the calendar

The tool you approved in March isn’t necessarily the tool you’re running in September. Vendors change models and terms, teams find new uses for it, and the person who owned it moves on. So the answers above need a review date, and the date depends on the risk.

There are three key events to watch for which should trigger a review straight away regardless of what the calendar says:

You don’t need a compliance team

None of this needs a compliance team or a lawyer. It needs fifteen minutes, seven honest answers before the tool goes live, and a date to look again.

The AI tools that cause trouble are rarely switched on by careless people. They’re switched on by good people in a hurry, because nobody wrote anything down.

Do this for one tool and you have a habit. Do it for every tool and you have an AI register.

If you would rather have that as a standing process, with every AI tool logged, owned, reviewed and on the record without anyone having to remember the checklist, that’s what Certrak does.

Further reading

Not sure what your team is already using?

A few quick questions. No sign-up, no scanning. See where your AI risk actually is.

Find your AI risk

Questions people ask

They can. From 10 December 2026, a business covered by the Privacy Act that uses a computer program, including AI, to make or substantially inform decisions that could significantly affect a person must say so in its privacy policy and explain the kinds of personal information involved. Your answers to questions 1 and 5 tell you whether a tool does that. If it does, add it to your privacy policy before the date, and keep the record from this post as the evidence behind the wording.

Yes, and those are usually the ones with the widest gap between what the business assumes and what the terms say. If a tool touches business information, it belongs on the list regardless of who pays for it or whose account it runs under.

Nothing, once you have more than one tool. The answers for a single tool are a record. The same answers kept for every tool in the business, with an owner and a review date against each, is an AI register.

Paul Bardell
Written by
Paul Bardell · Founder, Certrak

Paul Bardell is the founder of Certrak, which gives Australian businesses one clear record of their AI use. He writes plain-language guidance for people who never signed up to be responsible for AI.