You’re already using AI. The question is whether you’re using it on purpose.
Most small businesses have AI running somewhere in the background right now. A chatbot answering enquiries. A scheduling tool pulling in content. Someone on the team drafting a report in ChatGPT. Very few of those businesses have ever sat down and decided how any of it should work.
That gap between using AI and using it deliberately is what this session was about. Melanie Dancer joined us for the final August session of the Business AI + Digital Toolbox Program, and she brought something most AI governance conversations are missing: a background in human services, operations and change management rather than tech. Which means the whole hour stays anchored to what this actually means for the people doing the work.
Watch the full session below, or read the summary underneath it.
AI sits at three levels, even if you are all three
If you are a sole operator, you hold all three of these. If you have a team, they sit in different places. Either way, the three levels exist.
Business owner. The strategic call. What AI are we prepared to use? What risks are unacceptable? What laws, reputation and client trust are at stake?
Management and process. The oversight. Which tools are approved? What rules apply to staff? How do complaints and incidents get escalated?
Day-to-day use. The actual work. What information am I putting in to get a result? Should I rely on this output? Does this decision need a human to check it?
The owner needs to be aware of all three. That is different from being responsible for all three, and it is where a lot of small businesses get stuck.
A six-question temperature check
Not a pass or fail. Score each one green (1), amber (2) or red (3), and tally.
- Responsibility. Is someone clearly responsible for how AI is used in your business?
- Business purpose. Is AI included in your business or digital planning?
- Visibility. Do you know where AI is currently being used across your business?
- Tools. Do you know and manage how staff use public AI tools like ChatGPT, Copilot or Gemini?
- Risk. Have you identified any higher-risk uses of AI in your business?
- Obligations. Do you consider privacy, cyber security and legal obligations before introducing AI?
Mostly green: you have strong foundations and good habits already. The work now is consistency and review.
A mix: most businesses land here. Some things work well, some practices are still informal. A little structure makes a big difference.
Mostly amber and red: a good place to start from. You have just identified where visibility and simple guardrails would help. You do not need to fix everything at once.
Three questions that do most of the work
Who is responsible? AI can assist your business. Your business stays accountable. Every AI tool needs a human owner, and accountability cannot be automated. “The AI told me to” is not a position you want to be in.
There is a practical efficiency argument here too, not just a risk one. If three people are all editing the same AI instruction or skill, you end up with a tool that is inconsistent, unreliable, and potentially damaging. One owner per tool keeps it working.
Is it actually helping? Perceived value is not proven value. Are you overinvesting in one area? Has the tool actually reduced hours or improved the customer experience, or does it just feel like it has? Start with the business problem, not the tool.
One participant came into a one-on-one session this month expecting to leave with an AI tool. What they actually needed was a lightweight CRM. AI runs on soft, interpretive rules, which is excellent for analysis, drafting and reframing. When you need something repeated reliably and identically every time, hard rules are better, and cheaper.
Do you have guardrails? Think bumper bowling. Guardrails do not stop you playing. They keep the ball moving forward and out of the gutter.
Reliable is not the same as robust
A reliable car starts every morning. A robust car keeps running safely in difficult conditions. Good AI needs both.
An AI tool can confidently give you a legal answer that misses a change made yesterday. Reliable, not robust. Melanie shared a case where someone self-representing at a South Australian tribunal submitted a case built in ChatGPT, and the other side could not work out where the cited precedents had come from. They had been invented.
Bias is not something you introduce. It’s already there.
This is the part that gets missed. The bias in an AI tool is not primarily coming from what you type into it. These models are trained on hundreds of years of digitised material, reflecting cultural norms, gender assumptions and whatever is being said online right now.
It also gets deliberately poisoned. When the war in Ukraine started, bot farms generated fake content at scale specifically to contaminate the data that AI tools scrape and summarise. That problem is going to get more prolific, not less.
You do not need to solve this. You do need to know it is there when AI is anywhere near a decision that affects a person.
Three ways this actually goes wrong
Recruitment. A business uses AI to rank 85 applicants for two roles, prompting it to find who will “fit our team, communicate professionally and stay.” An experienced older applicant is not interviewed. Review shows the AI favoured recent qualifications, shorter employment histories and energetic, fast-paced language. The applicant alleges age discrimination. The business cannot explain the ranking or show it was tested.
Client information. A bookkeeping staff member pastes a full client email into a public AI tool. It contains identity, financial, employment and family information. Months later the client asks whether their information has ever been entered into an AI system. The business cannot say where the data went, whether it was retained, or how the provider used it.
Invented law. A property manager asks ChatGPT whether a tenant is entitled to reimbursement for an urgent repair. It returns a confident answer, cites a legislative provision, and drafts the refusal. Nobody checks the citation.
The governance question in all three is the same: at what point should a human control have intervened?
Using AI to assist a decision does not transfer accountability for that decision.
How much human oversight is enough?
It scales with impact. Not every use needs the same level.
| Impact | Oversight | Example |
|---|---|---|
| Low | Human monitors, AI acts | Product recommendations, routine content filtering |
| Medium | Human on the loop, reviewing triggers | Fraud alerts, pricing anomalies |
| High | Human in the loop, AI recommends and a human approves | Recruitment, eligibility decisions |
| Critical or rights-based | Human decides | Medical, clinical, safety-critical settings |
Oversight also has to be meaningful. A person reading an AI-drafted legal response and thinking it sounds professional is not oversight. A person checking the primary source, challenging the AI and owning the final decision is.
Design your triggers in advance, rather than relying on someone noticing something has gone wrong.
Five guardrails you can put in place this week
- Know your AI. Write down what is being used, where, and by whom.
- Know why. Link each tool to the business problem it solves. If you cannot name the problem clearly, you are probably not ready for the tool.
- Protect information. Set a rule about what never goes into a public AI tool. If you handle sensitive information regularly, a fully offline AI setup is entirely doable and keeps the data in your system.
- Check important work. Not everything. A weekly spot check on three or four outputs, or one test in every ten, is enough to catch drift. You can also use AI to check AI: a simple skill that compares published content against your source document and flags inconsistencies.
- Keep learning. Know, improve, monitor, learn. Repeat.
One last thing
Melanie built that presentation with AI doing the heavy lifting, then put a full human check over the top: language, tone, pitch, and confirming the information. Two or three mistakes still made it through to the recording. She is not saying which ones.
That is the whole argument in one slide. AI does the work, a human owns the result, and you still check.
Where to go deeper
- Guidance for AI adoption (AI6), National AI Centre. Six essential practices, with plain-language advice for small business under each one. This replaced the earlier ten-guardrail Voluntary AI Safety Standard.
- ISO/IEC 42001:2023, the international standard for AI management systems, if you want to go further into formal certification.
Want help with this?
Forge & Guild runs one-on-one sessions as part of the Business AI + Digital Toolbox Program, covering policy, governance and a lot more besides. If you have not registered, do.
The goal here is to move from default to design. Give it conscious thought instead of letting it half-happen. Most people watching this will realise they are already doing some of it, and that is exactly the point.