The Business Advisory Blog

The Business Advisory Blog

Insight, news and updates from Alliott NZ Chartered Accountants, Auckland New Zealand. The views expressed here are the views of the author and should be discussed in further detail should an article be relevant to your individual circumstances.

While every effort has been made to provide valuable, useful information in this publication, this firm and any related suppliers or associated companies accept no responsibility or any form of liability from reliance upon or use of its contents. Any suggestions should be considered carefully within your own particular circumstances, as they are intended as general information only.

Greg Millar
Published on

Has AI crept into your business?

AI adoption doesn’t always happen through a carefully planned rollout. It can start with someone using ChatGPT to polish an email, Copilot to summarise a document, or an AI transcription tool to take meeting notes.

Before long, AI will be part of how your business operates, whether you’ve formally decided how it should be used or not.

But AI is uncharted territory, with risks ranging from data leaks to privacy issues and inaccurate information. Putting a few clear rules in place can give your team room to experiment while keeping those risks in check.

That’s where an AI health check comes in: it can help you see how AI is already being used across your business and where clearer guardrails are needed.

Find out what your team is using

Audit which AI tools are being used, what for, and by whom. You may be surprised to find AI in parts of the business you hadn’t imagined.

AI use outside a business’s formal oversight is sometimes called ‘shadow AI’. It doesn’t mean employees are breaking the rules; often, there simply aren’t any rules in place yet. But entering business or client information into tools without understanding how that information is stored or used can be risky.

Put policies into practice

While AI policies will depend heavily on your business, it’s a good idea to give staff clear guidance about what can and can’t be used, and to check the privacy and security settings of the tools you approve.

Sensitive information, customer details, employee information, financial records and other confidential material shouldn’t simply be pasted into any AI tool.

Build AI boundaries

AI tools are increasingly connected to email, company files, and internal chat channels. Review which tools have access to your systems, turn on two-step verification to secure your accounts, and opt for paid business-grade versions that can keep your information safe and confidential.

Keep a human in the loop

AI can save time, but it can also get things wrong, misunderstand the context, and sound… well, robotic. Important decisions and customer-facing work still need human review.

Be upfront about AI

You don’t need to announce every time AI helps tidy an email or brainstorm a headline, but there are times when disclosure matters. If a chatbot is talking to customers or an AI-generated person appears in your ads, say so. A simple note explaining where AI was used can help avoid confusion and protect trust.

AI health check checklist

A practical AI health check should help your business:

  • identify which AI tools are already being used
  • understand what business information those tools can access
  • establish clear AI policies and acceptable-use guidelines
  • review privacy, security and account controls
  • keep human oversight over important work and decisions
  • identify situations where AI use should be disclosed.

Regularly reviewing these areas can help your business make better use of AI while reducing avoidable privacy, security and reputational risks.

Topics: artificial intel data employees policy Privacy risk security small business technology