AI usage review, find out first
An AI usage review is an interview-based engagement for Australian organisations that want to know what AI tools their staff are actually using and what data is going into them. Most AI tools arrived inside organisations through the side door. The OAIC's Notifiable Data Breaches reports consistently flag misconfigured access and human error as leading causes of breaches. Before you write the policy, find out what is actually happening. We talk to your team, surface real usage, and give you a risk picture you can act on.
Not sure if you need this yet? Take the free self-check for an indicative risk score first.
AI arrived through the side door, no one wrote it down
Staff started using ChatGPT to draft emails. Someone tried Copilot. Another team uses Gemini through their personal Google account. None of it shows up in any IT system you can see.
You cannot describe your current AI exposure. You do not know what data has been put into which tools. Any policy you write in a vacuum will be ignored or out of date by the time it lands. And you cannot answer "how are you managing AI risk" with a straight face. We give you the honest picture, in plain language, without anyone needing to admit fault.
The five areas we cover
Tool inventory
Which AI tools are in use across the team. Sanctioned, paid, free or personal accounts. How often, for what tasks. Browser extensions and plug-ins that bring AI into existing workflows.
Data exposure
What kinds of information staff are putting into AI tools. Whether client names, health information, support notes, incident reports, financial or commercial data has been entered. Whether files have been uploaded.
Awareness and practice
What guidance staff currently have, formal or informal. Whether they understand what their tools do with the data. Where confusion is leading to risky behaviour. What would actually help.
Policy position
What an AI usage policy needs to cover for your organisation. A practical first draft you can adapt. The shortest path to making the policy something staff will actually follow. Our Privacy Act 2026 compliance guide sets out the regulatory context.
Visibility going forward
How to gain proper visibility over AI use without locking everything down. Tooling options for your environment (Microsoft Defender for Cloud Apps, Purview, alternatives). What your IT provider can help with.
Recommendations and owners
Risks rated low, medium or high. Recommendations with the right owner indicated. A short list of what to do this month, this quarter and this year.
How the engagement runs
Confirm scope and framing
Short call with the project sponsor to confirm priorities, who we will speak to and how the review is introduced to staff.
Talk to a sample of staff
Short, non-judgemental interviews (15 to 30 minutes each) with a representative slice of the team. The goal is honesty, not enforcement.
Draft the AI usage policy
We draft an AI usage policy outline based on what we have heard, ready for the organisation to adapt. It reflects how staff actually work.
Risk-rated draft report
Findings, risks rated low, medium or high, and practical recommendations with the right owner indicated. Issued for your review.
Final report and plan
Walkthrough session with the leadership team. Final report incorporating any clarifications. Policy outline finalised.
Engagement runs over a few weeks of elapsed time, depending on staff availability. We rely on what staff tell us. With the right framing, people are remarkably honest, especially when they know the goal is to make their working lives easier rather than to catch them out.
What you walk away with
Findings from the interviews, risks rated low, medium or high, and practical recommendations with the right owner indicated.
- ✓Findings by area
- ✓Risk-rated issues
- ✓Recommendations
- ✓Owners indicated
A first draft policy outline built from what your team is actually doing, not from a template. Designed to be usable, not aspirational.
- ✓First-draft policy
- ✓Acceptable use
- ✓Approval and review
- ✓Ready to adapt
A session with the leadership team to step through the report, agree priorities and discuss any sensitive findings privately.
- ✓Leadership walkthrough
- ✓Stakeholder Q&A
- ✓Priority agreement
- ✓Confidential delivery
fixed price quote agreed before any work starts.
What this engagement is not
A technical audit
We do not scan Microsoft 365, devices or networks to verify usage.
A penetration test
If you want technical visibility, we will tell you what to ask your IT provider for.
A staff investigation
This is not a disciplinary process. The framing is supportive.
A formal compliance audit
This is advisory. We point at standards and where you sit against them.
A legal review
We are not lawyers. We will tell you where to get one if you need one.
When to call us in
Suspect AI is everywhere
Leadership has realised AI use is happening across the team but has no idea of the scale or what data is involved.
Something happened
A staff member did something with AI that prompted a closer look. You want a structured picture, not a witch hunt.
Writing the policy
An AI usage policy is being drafted and the executive wants it grounded in reality, not a template downloaded from the internet.
How are you managing AI risk?
A board, funder, auditor or insurer has asked the question and you cannot answer it confidently right now.
About to roll out Copilot
Microsoft 365 Copilot or another sanctioned tool is about to be rolled out and the executive wants to understand the existing landscape first.
Sensitive data, real consequences
Disability, aged care, allied health, education, legal, finance, NFP. Sectors where shadow AI use carries real consequences.
The full capability list
Consulting, automation, security and training, plus the build and fix work when you need it. These are the eight we lead with; 32 in total. Your AI consultant in Perth, working nationally.
AI Consulting
Map your ops, find where AI makes sense, build an implementation plan your team can follow.
Learn moreAutomation
n8n, Make, Power Automate, custom integrations. The boring weekly tasks, automated.
Learn moreAI Security & DLP
Stop data leaking into AI tools. Usage policy, M365 controls, Privacy Act and Essential Eight aligned.
Learn moreAI Training
Train your whole team to use AI well. Role-based programs, workshops and coaching across Claude, ChatGPT and Copilot.
Learn moreApp Development
Apps, tools, MVPs and internal systems built with AI-assisted dev, with senior engineering oversight.
Learn moreVibe Code Audit & Fix
Built with Claude, Cursor, Bolt or Lovable? We find what's broken, patch it, hand it back production-ready.
Learn moreAI Agents
Custom agents for CRM, accounting, project management. Built with Claude, GPT and MCP.
Learn moreAgentic Coding
Autonomous coding agents build features end-to-end. We review, steer, and ensure production quality.
Learn moreWe ran this exact engagement for an Australian health services business. We surveyed the team on how they really use AI, mapped the platforms in use, and handed back a policy-first adoption path leadership could act on.
Read the case studyFrequently asked questions
A technical audit gives you a list of accounts and licences. It does not tell you what staff are doing with personal accounts, paid subscriptions out of expense cards, or browser plug-ins. The interview approach is the only way to surface those. If you want technical visibility on top, we will tell you exactly what to ask your IT provider for.
Yes, with the right framing. We open every interview by saying we are not here to catch anyone out, the leadership team has agreed nothing said becomes a disciplinary issue, and the goal is to make their working lives easier. People are remarkably honest under those conditions, especially compared to a formal audit.
No. The engagement is interview-based and document-light. We do not log into Microsoft 365, devices, networks or any other system. That is a deliberate choice: it keeps the engagement low-friction and keeps the interviews honest.
It is a starting draft, not a final legal document. We design it to be practical, plain-English and aligned to how your team actually works. You will want to run it past HR and legal before it is signed off, but it will be much closer to usable than what most policy templates produce.
Yes. We work with not-for-profits, allied health, disability and aged care providers regularly. The data sensitivity in those sectors is exactly why a usage review matters before a policy is written.
That is a separate scope, and often we recommend your existing IT provider does it because they already manage your environment. We will tell you exactly what to ask for, and we are happy to brief them. Implementation is independent of the review.
Want to know what your team is actually doing? Start with a 30 minute scoping call
we will tell you whether this engagement is the right fit. No pitch deck.