How to build an AI playbook for your team

A Brisbane accounting firm we work with had three different staff members using three different AI tools to draft client correspondence, none of them approved, none of them documented. One was pasting client tax summaries directly into a public chatbot. Nobody had told them not to. There was no policy.
That situation is more common than most business owners realise. Getting AI working properly in your business starts well before you pick a tool. It starts with a clear set of rules your team can actually follow. That’s what an AI playbook gives you.
This article walks you through what to put in one. At the end, there’s a short checklist you can use as a starting template.
What an AI playbook actually is
An AI playbook is a short internal document that tells your team three things: which AI tools they’re allowed to use, what data they can put into those tools, and who checks the output. It doesn’t need to be long. A one-page policy and a one-page approved tools list will cover most businesses with fewer than 50 people.
The goal isn’t to restrict your team. It’s to stop the patchwork of unmanaged AI use that’s already happening. “Shadow AI” — staff using tools on their own without any oversight — is the biggest practical risk for small and mid-sized businesses right now. One team member pasting client data into a public AI tool can create a real problem under the Privacy Act 1988.
The National AI Centre released updated guidance in October 2025, called the Guidance for AI Adoption (GfAA). It sets out six governance practices for businesses using AI and includes editable AI policy templates you can download directly. It’s a good starting point if you want something government-aligned.
Step 1: Audit what your team is already using
Before you write a word of policy, find out what’s already happening. Ask your team directly. Run a short survey. Check your browser management logs if you have them. You’ll likely find tools being used that you didn’t know about.
Make a simple list with three columns: the tool name, what it’s being used for, and whether it handles any client or business data. That list becomes the foundation of your approved tools register.
Common tools you’ll find in a typical South-East Queensland SME include:
- Microsoft Copilot (built into Microsoft 365 — the most common starting point).
- ChatGPT or Claude, used for drafting emails, reports, or summaries.
- AI features inside accounting, CRM, or project management software.
- Image or document tools your marketing or admin team picked up independently.
Once you know what’s in use, you can make clear decisions about what stays, what gets replaced with a controlled version, and what gets removed entirely.
Step 2: Decide which tools are approved
Not all AI tools handle your data the same way. The key question is whether the tool uses your inputs to train its models. Some public tools do this by default unless you opt out. That matters if your inputs include client information, commercially sensitive data, or anything covered by confidentiality obligations.
For most businesses running Microsoft 365, Microsoft Copilot is the natural first approved tool. It operates inside your existing Microsoft tenancy, your data stays within your environment, and it inherits the same access controls your team already has. That’s a meaningful difference from a public browser-based tool.
When assessing any AI tool, ask:
- Where does my data go, and does it stay in Australia?
- Does the vendor use inputs for model training?
- Is there a business or enterprise tier that gives us stronger data controls?
- Does it integrate with our existing identity and access management?
Your approved tools list should name each tool, the approved use cases, and the data handling conditions that apply.
Step 3: Set clear data rules
This is the section most playbooks skip, and it’s the most important one. Your team needs to know exactly what they can and can’t put into an AI tool.
A simple tiered approach works well for most SMEs:
- Green — fine to use: publicly available information, internal drafts with no personal data, your own brainstorming and ideation.
- Amber — approved tools only: internal business documents, non-sensitive correspondence, meeting notes without personal details.
- Red — never into any AI tool: client personal information, financial records, passwords or credentials, anything under a confidentiality agreement.
Write this out simply. Put it on one page. The clearer and shorter it is, the more likely people are to actually follow it. If your team works in professional services, law, finance, or medical — sectors that carry heightened privacy obligations — the red category needs to be broad and well explained.
Step 4: Establish a human review rule
AI tools produce confident-sounding output that can still be wrong. This is especially true for anything technical, legal, numerical, or client-facing. Your playbook needs to be explicit: AI output is a draft, not a final product.
Set a simple rule: any AI-generated content that goes to a client, gets filed formally, or makes a business decision must be reviewed by a person with relevant knowledge before it’s used. That person takes responsibility for the output. The AI doesn’t.
This matters for compliance reasons too. Australian regulators are increasingly focused on human accountability in AI use. The National AI Centre’s guidance is built around the idea that someone in your organisation must own the outcome of every AI-assisted decision. Document who that person is for each use case.
Step 5: Name an AI owner
Someone in your business needs to be responsible for keeping the playbook current. AI tools change quickly. New capabilities, new risks, and new versions appear regularly. A playbook written in January can be out of date by July without someone watching it.
The AI owner doesn’t need a dedicated role. In most SMEs it’ll be the operations manager, IT lead, or a senior partner. Their job is to:
- Review the approved tools list every six months.
- Update the data rules when the business takes on new client types or enters new sectors.
- Stay across any changes to the Privacy Act or other relevant regulations.
- Field questions from staff about new tools they want to use.
If you work with a managed IT consultant, they can take on this function as part of your IT governance — flagging regulatory changes and reviewing tool selections before they get added to the approved list.
Step 6: Train your team once, then keep it fresh
A playbook nobody has read is just a document. Roll it out with a short session — 30 to 60 minutes is enough for most teams. Cover the approved tools, the data rules, the review expectation, and who to ask if something’s unclear.
Keep it practical. Use examples from your own work. Show people what a good AI-assisted draft looks like and what a bad one looks like. The goal is confident, consistent use — not fear of the tools.
After the initial session, build in a short refresh every six months. New staff should get it as part of onboarding. This doesn’t need to be formal training. A 15-minute walkthrough during induction covers it.
The regulatory backdrop — what to know for 2026
Australia doesn’t have a standalone AI Act. The current approach relies on existing laws — the Privacy Act, Australian Consumer Law, and workplace health and safety legislation — with voluntary guidance from the National AI Centre sitting alongside them.
Two things are worth noting for Queensland businesses. First, new Privacy Act changes relating to automated decision-making transparency are due to take effect in December 2026. If your business uses AI in any process that directly affects individuals — hiring, credit, service decisions — those changes will apply to you. Second, NSW has passed specific AI workplace legislation that other states may follow. Even if your business is in Queensland, the direction of travel is clear: documented AI governance is becoming a baseline expectation, not an optional extra.
Your playbook doesn’t need to be a legal document. It does need to exist and be current. That’s enough to show you’ve taken a considered approach if any questions arise. For businesses wanting to go further, TTA’s technology leadership service can help you build out a full AI governance framework that stays current as the rules develop.
AI playbook starter checklist
Use this as a working template. Add, remove, or adjust to suit your business.
- AI tools audit — document every tool currently in use across your team.
- Approved tools register — name each tool, approved use cases, and data handling conditions.
- Data classification tiers — green, amber, and red, with clear examples for your context.
- Human review rule — define what requires sign-off and who gives it.
- AI owner — name the person responsible for maintaining the playbook.
- Team briefing — at least one session to walk through the policy, with Q&A.
- Review schedule — six-monthly check of the approved tools list and data rules.
- New staff onboarding — include AI policy in your induction process.
Frequently asked questions
Do I need a lawyer to write an AI policy?
No. A basic AI playbook for internal use is an operational document, not a legal one. You don’t need legal sign-off to put a simple approved tools list and data rules in place. If you’re in a regulated sector — financial services, healthcare, or legal — it’s worth having your compliance adviser review it, but don’t let that delay getting something written down.
What if staff are already using tools I haven’t approved?
Start by understanding what they’re using and why. In most cases, people are reaching for AI tools because they’re genuinely useful. Your job is to channel that into approved tools that meet your data requirements, not to shut it down entirely. A ban without an alternative is rarely effective.
Does Microsoft Copilot keep our data private?
Microsoft Copilot for Microsoft 365 operates within your organisation’s tenancy. Microsoft states that your data is not used to train shared AI models. Your existing Microsoft 365 data governance and access controls apply. That said, you should still confirm the data handling terms in your specific subscription and ensure your Microsoft 365 environment has proper access controls configured before enabling Copilot. Our Microsoft 365 Copilot page has more detail on what’s involved in a responsible rollout.
How often should I update the playbook?
Every six months is a good starting point. The AI tool landscape changes quickly, and so does the regulatory environment. If your business takes on a new client category, enters a new sector, or adds a significant new AI tool, update it then rather than waiting for the next scheduled review.
What’s the biggest mistake businesses make with AI policies?
Writing a policy and never distributing it. The second biggest is making it so long and detailed that nobody reads it. Keep it short, clear, and grounded in the tools your team actually uses.
Where do we start if we want help?
Talk to us. We work with Brisbane and Queensland businesses across professional services, trades, and other sectors to put practical AI governance in place. That means reviewing your current tool stack, helping you build an approved tools list, and making sure your Microsoft 365 environment is set up to support AI use safely. Get in touch and we can walk through where your business currently sits.



