Using AI safely in a small business
AI governance, risk & compliance

Using AI safely in a small business

Ben Richards

Using AI safely in a small business is not a matter of trusting the tool. It rests on three unglamorous things: knowing what is actually running in your business, bounding what each thing is allowed to reach, and being able to recover when something goes wrong.

None of that requires a compliance department, and none of it starts with writing a policy.

Here is the shortest version of the whole argument: you cannot supervise what you have not written down, and you cannot recover what you never backed up.

What does safe actually mean here?

It does not mean the AI never makes a mistake. It will.

Safety is about what a mistake can reach. A tool that can draft a reply is a very different risk from a tool that can send one. A tool that can read your client list is different from one that can edit it. The question is never really do I trust this AI, it is what is the worst thing that happens if it is confidently wrong at 4pm on a Friday.

That reframing is the whole basis of how we approach it, and it is why we lean on boundaries rather than vigilance. Nobody can supervise a system carefully enough, forever, to make an unbounded tool safe. We set the argument out in guardrails, not trust.

What is actually running in your business?

Almost every owner underestimates this, and it is not carelessness.

The tools arrive one at a time. Someone switches on meeting summaries. The accounting software adds a feature and enables it by default. A staff member finds something useful and starts using it on a personal account. Each step is sensible and nobody is holding the whole picture, because the picture was never drawn.

The first governance job is therefore not a policy. It is an inventory: every AI tool in the business, who is accountable for each, and what you would do if one produced something wrong that reached a customer. One page, about an hour. We laid out the exact format in AI governance for a small business, on one page.

What should you let an AI act on by itself?

There is a real difference between AI that suggests and AI that does.

Suggesting is low risk and easy to supervise, because a person sees the output before anything happens. Acting is where the exposure is, and it is also where the value is, so the answer is not to refuse. The answer is to be deliberate: a narrow scope, read access before write access, a human check on anything that leaves the building, and a clear way to see what it did after the fact.

An agent you cannot audit is an agent you cannot trust, no matter how well it has behaved so far. The practical checklist is in using AI agents safely.

Scope starts with identity. Before you decide what an assistant may do, decide which account it does it under, because an assistant connected to the owner's login inherits everything the owner can reach and leaves no trail of its own. We work through that in what access an AI assistant should have.

What happens when it breaks, or you lose the machine?

This is the part almost nobody plans for, and it is the failure we have seen hurt people most.

A year of accumulated setup, the instructions, the context, the small refinements that made a tool genuinely useful, can live entirely on one laptop. When that laptop dies, so does the work. It is not a security breach and it does not feel like a risk until the morning it happens.

Treat the AI setup like any other business asset: it should exist somewhere other than the device it runs on. We made the case, with a real example, in backing up your AI setup.

Do you need a policy, or a standard?

Eventually a short policy is worth having. A standard, almost certainly not.

ISO/IEC 42001, published in December 2023, is the first international standard for AI management systems, covering accountability, risk management, data governance, transparency, monitoring and training. Certification is voluntary and carried out by independent bodies. It is built for organisations considerably larger than a typical Australian SME, and pursuing it is a serious undertaking.

What it is genuinely useful for is the shape of the answer. Someone has already worked out what a complete response to are you managing this properly looks like, and you can borrow that structure without buying the process. That is the practical use of a standard you will never certify against.

The order to do it in

If you do nothing else this quarter, do these three, in this order.

Make the list. Every AI tool in the business, who owns it, what you would do if it went wrong. An hour.

Set the boundaries. For each one, decide whether it suggests or acts, which account it runs under, and whether anything it produces can reach a customer without a person seeing it first.

Sort the recovery. Make sure the setup, the context and the instructions live somewhere other than one person's laptop.

Policy after that, if you still want one. It will be a better policy for having been written second.

This is the sequence we work through with clients at Handiwork, and it usually sits inside a roadmap or a retainer rather than a one-off exercise, because the list only stays useful if someone keeps it current. Our services page covers how that is structured.

Your list should also record which contract governs the tools on it. That is less obvious than it sounds, and there is a live deadline attached to it: see which Microsoft terms actually govern your business.

Ready to find out where you stand?

If you want a straight look at what AI is already running in your business and who is accountable for it, our free AI Readiness Check covers exactly that. No cost, no pitch.

Frequently asked questions

Is it safe to put client information into an AI tool?

It depends entirely on the tool and the plan you are on, and it is a question worth answering explicitly per tool rather than in general. Put the answer in column two of your inventory so it is decided once rather than re-litigated every time someone is in a hurry.

Do I need an AI policy?

Eventually, and it can be one page. Not first. A policy written before you know what is running in the business governs an imaginary version of it.

What is the most common AI risk for a small business?

Confidently wrong output reaching a customer because nobody was clearly accountable for checking it. Not a breach, not a dramatic failure. Something plausible and incorrect going out under your name.

Should staff be allowed to use their own AI accounts?

Banning it moves the usage out of sight without stopping it. Better to put those tools on the list and decide what may be entered into them.

Does any of this apply if we only use AI for drafting?

Yes, and it is simpler. Drafting is the low-risk end, so most rows on your one-pager will be quick. The value is in knowing that is genuinely all you are doing.

Ready to find out where you stand?

Take the free five-minute AI Readiness Check. There is no pitch at the end of it.

Take the AI Readiness Check
Ben Richards
Ben Richards
Co-founder, Handiwork
Co-founder of Handiwork, Brisbane's practical AI consultancy for small and medium businesses.
Connect on LinkedIn →

Sources

  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. International Organization for Standardization, published 18 December 2023, https://www.iso.org/standard/42001
August 18, 2026
August 31, 2026
Brisbane-based AI advisory & implementation© 2026 Handiwork Consulting Pty Ltd