AI Usage Review · Advisory
AI usage review, find out first
An AI usage review is an interview-based engagement for Australian organisations that want to know what AI tools their staff are actually using and what data is going into them. Most tools arrived through the side door. The OAIC's Notifiable Data Breaches reports consistently identify human error and compromised or misconfigured access among important breach causes. Before writing policy, we surface actual usage and produce a risk picture leadership can act on.
Not sure if you need this yet? Take the free self-check for an indicative risk score first.
The picture
AI arrived through the side door, no one wrote it down
Staff started using ChatGPT to draft emails. Someone tried Copilot. Another team uses Gemini through a personal Google account. Much of it does not appear in a central IT inventory.
That makes current exposure hard to describe, and a policy written in a vacuum easy to ignore. The review creates an honest picture in plain language, handled so staff do not feel investigated.
Scope
The six areas we cover
Data exposure
Awareness and practice
Policy position
A usable policy starting point grounded in observed work, with the Privacy Act 2026 compliance guide providing regulatory context.
Visibility going forward
Recommendations and owners
Method
How the engagement runs
Kick-off
Confirm scope and framing
The sponsor confirms priorities, interview participants and how the review will be introduced.Interviews
Talk to a sample of staff
Short, non-judgemental interviews with a representative slice of the team prioritise honesty over enforcement.Policy
Draft the AI usage policy
A policy outline reflects how staff actually work and is prepared for organisational adaptation.Draft
Risk rated draft report
Findings are rated low, medium or high and paired with recommendations and owners.Walkthrough
Final report and plan
Leadership reviews the findings, clarifies sensitive points and receives the final report and policy outline.
Deliverable status
What you walk away with
Written usage review
- Findings by area
- Risk rated issues
- Recommendations
- Owners indicated
Draft AI usage policy
- Acceptable use
- Data handling
- Approval and review
- Ready to adapt
Leadership walkthrough
- Leadership walkthrough
- Stakeholder questions
- Priority agreement
- Confidential delivery
Boundaries
What this engagement is not
A technical audit
A penetration test
A staff investigation
A formal compliance audit
A legal review
Triggers
When to call us in
Suspect AI is everywhere
Something happened
Writing the policy
How are you managing AI risk?
About to roll out Copilot
Sensitive data, real consequences
Recent work
A policy first adoption path for an Australian health services business
Related work
What tends to sit beside AI Usage Review
Practical details
Questions about AI Usage Review
Start here