If you run a small business and you’ve added an AI tool to your workflow sometime in the last two years, you’re in the majority. If you’ve written down anywhere what that tool does, what data it touches, or who’s responsible if it gets something wrong, you’re in a much smaller group. A widely-cited line from this year’s coverage of the sector put it plainly: small businesses adopted AI faster than they wrote rules for it. That’s not an insult. It’s just what happens when a genuinely useful tool turns up faster than anyone’s admin cycle can keep pace with.
This guide is about closing that gap, without turning your five-person business into a compliance department. Self-governance for a small business doesn’t mean hiring a Chief AI Officer or getting ISO-certified. It means doing a handful of specific, finishable things, once, and then reviewing them a few times a year. That’s the whole job.
Why this matters now, not eventually
Australia’s regulatory settings around AI have moved from “vague guidance” to “dated obligations” over the course of 2026. You don’t need to track all of it, but three things are worth knowing because they change what “good enough” looks like:
The Australian Standards for AI are becoming mandatory. In July 2026 the federal government ended five years of voluntary AI guidelines and announced a new Office of AI, with legislation expected in Parliament in early 2027 and National Cabinet weighing in on the detail in August 2026. Voluntary is on its way out. Documented is on its way in.
Privacy Act disclosure rules land in December 2026. New provisions (APP 1.7 to 1.9) will require businesses to state, in their privacy policy, when AI makes or meaningfully influences a decision about a person, think credit, hiring, insurance, pricing or risk scoring. This is not aimed at big tech. It’s aimed at anyone using an AI tool to screen, score, or flag customers or applicants, which includes plenty of small operators who’d never think of themselves as “an AI business.”
Workplace AI safety is now a live policy thread. Victoria has proposed the toughest workplace AI and biometric surveillance laws in the country, and workplace AI safety is one of five priorities the federal government named in July 2026. If you use any staff monitoring, scheduling, or productivity software with AI features, this is heading your way regardless of which state you’re in.
None of this requires panic. It requires a paper trail that didn’t exist before. That’s genuinely the size of the task.
What “governance” actually means for a small business
Strip away the consulting-firm language and AI governance means three things: knowing what AI tools you use, knowing what they touch, and knowing who’s accountable if something goes wrong. That’s it.
You do not need:
- A dedicated AI ethics committee
- Enterprise governance software
- ISO/IEC 42001 certification (a legitimate international standard, but built for organisations with dedicated compliance teams, not a five-person business)
- A lawyer on retainer for routine use of mainstream tools
You do need a document. One page is enough to start.
The national reference point: AI6
You don’t have to invent a framework from scratch. The National AI Centre (part of the federal Department of Industry, Science and Resources) publishes the closest thing Australia has to an official small-business-friendly standard: the Guidance for AI Adoption, known as AI6, which replaced the older “10 Guardrails” Voluntary AI Safety Standard in October 2025. It comes in two tiers, Foundations for organisations just starting out, and Implementation Practices for those embedding AI more deeply, so a small business can genuinely use the beginner tier without feeling like it’s been handed an enterprise checklist.
The six essential practices, translated out of policy language:
1. Decide who is accountable. One named person per AI tool, not a committee. For a five-person business, this might be one person total. The point isn’t hierarchy, it’s that when something goes wrong, there’s a name attached to the fix.
2. Understand impacts and plan accordingly. Before adopting a tool, spend ten minutes asking what could go wrong: wrong information given to a customer, a biased hiring shortlist, a data leak. Write the answer down. That’s the plan.
3. Measure and manage risks. Not a spreadsheet of risk scores. Just: is this tool touching anything sensitive (health data, financial data, decisions about a specific person), and if so, is there a human checking its output before it reaches someone?
4. Share essential information. Tell your customers and staff when AI is involved in something that affects them. This is the practice that overlaps directly with the December 2026 Privacy Act changes.
5. Test and monitor. Check the tool’s output periodically, not just on day one. AI tools drift, get updated by the vendor, or get used for things they weren’t originally set up for.
6. Maintain human control. Someone can always override the AI’s output, and knows that they’re allowed to. This sounds obvious. It’s the practice most commonly skipped once a tool “just works” for six months straight.
You can build genuinely adequate self-governance on these six lines alone.
The one-page AI register (the actual deliverable)
This is the single most useful artefact a small business can produce, and it does double duty against the December 2026 disclosure rules. One row per tool:
| Tool | What it’s used for | Data it touches | Accountable owner | Human review before it affects a customer? | Customer-facing disclosure needed? |
|---|---|---|---|---|---|
| Example: AI email drafting tool | Drafting customer replies | Customer name, enquiry content | Office manager | Yes, all replies reviewed before sending | No, no decision made about the customer |
| Example: AI hiring screen | Shortlisting applicants | Applicant CV, personal details | Owner | Yes, all shortlists reviewed manually | Yes, disclose in job ad and privacy policy |
Fill this in for every AI tool currently in use, including the ones nobody thinks of as “AI”, spam filters, spell-check, scheduling assistants, and the answer for most of them will be “low risk, no disclosure needed.” The value isn’t in finding problems everywhere. It’s in being able to answer, instantly and honestly, “which of our tools could this concern involve,” when a customer, an employee, or a regulator asks.
Realistic time to do this properly for the first time: under an hour for a business with a handful of tools, half a day if you’ve genuinely lost track of what’s in use across the team.
Customer-facing disclosure, done simply
You don’t need a legal essay. A short, honest line does the job:
“We use AI-assisted tools to help draft responses and manage bookings. A person reviews all decisions that affect you before they’re finalised.”
If a tool does make or influence a decision about a specific person, credit, pricing, hiring, risk flags, say so specifically, and say what a person can do if they want that decision reviewed by a human. That second part, the right to ask for human review, is the part most draft policies skip, and it’s the part that actually matters to the person on the other end.
A staff AI use policy, in four sentences
Most small businesses don’t need a ten-page acceptable use policy. They need staff to know four things, ideally written down somewhere everyone can find it:
Which AI tools are approved for use, and which aren’t. What kind of information should never go into an AI tool (customer financial details, health information, anything confidential about another staff member). Who to tell if an AI tool gives an obviously wrong or concerning answer. That using an AI tool doesn’t remove anyone’s responsibility for the final result, if a staff member sends something an AI drafted, they own it the same as if they’d written it themselves.
Vetting a new AI tool before you adopt it
Before adding any new AI tool, five questions, answerable in one conversation with the vendor or a look at their website:
Where is our data stored, and is it used to train the vendor’s models for other customers. What happens to our data if we stop using the tool. Can we export or delete our data on request. Does the vendor have its own published AI safety or governance statement (most reputable Australian vendors now do, following the government’s own AI transparency statement pattern used by agencies like the ACCC and OAIC). Is there a human-override option built into the tool, or does it act autonomously.
If a vendor can’t answer the data questions clearly, that’s information too.
The review cadence: quarterly, not constant
Self-governance fails in one of two ways: never done, or treated as a permanent, anxious, ongoing project. Neither is necessary. A quarterly ten-minute review is enough: has anyone added a new tool. Has anyone stopped using an old one. Has any tool’s output caused a problem since last quarter. Does the register still match reality. Four questions, four times a year.
What to actually ignore (for now)
In the spirit of no hype in either direction: a small business does not currently need ISO 42001 certification unless a client or contract specifically requires it. Does not need to pre-emptively ban staff from using AI tools, an outright ban tends to just push use underground and out of the register entirely. Does not need a lawyer to review routine use of mainstream, reputable AI tools for drafting, scheduling, or admin. And does not need to treat every new government announcement as an emergency, several of 2026’s “new AI safety priorities” are existing commitments getting a fresh press release, not new law taking effect tomorrow.
The whole task, in summary
Name one accountable person per tool. Write a one-page register. Add a plain-English disclosure line to your privacy policy and customer materials. Write four sentences of staff guidance. Ask five questions before adopting anything new. Review it quarterly. That’s self-governance for a small business, done properly, and it’s genuinely achievable in an afternoon, not a project.
The businesses that get caught out over the next 18 months as disclosure rules tighten won’t be the ones using AI. They’ll be the ones who never wrote down what they were using it for.