Tools
Will AI actually help your business?
A free, honest decision game: choose your sector, pass six doors about pattern, documentation, review, hours, data and ownership, and get a straight answer on whether AI will help your business yet.
The six doors
Is there a task that happens at least weekly and follows a recognisable pattern?
Think quoting, chasing invoices, answering the same enquiry, writing up the same report. Not "we are busy" in general.
If no: AI is a pattern machine. Without a repeating task there is nothing to automate and nothing to speed up. Chat tools might save the odd hour, but nothing worth building around.
Is the information that task needs written down somewhere, not just in someone’s head?
Emails, documents, a spreadsheet, a system. If the process lives entirely in one person’s memory, a tool has nothing to read.
If no: AI can only work with what it can read. Document the process first. A half-day writing down how the job is actually done will do more for the business than any tool, and it makes AI possible later.
Can the business tolerate occasional mistakes, and does someone check the output before it matters?
Every AI tool is wrong sometimes, and it is wrong confidently. The question is whether a mistake gets caught and whether it can be undone.
If no: Confident errors with no safety net. If a wrong answer is unrecoverable and nobody reviews it, you are not ready. Fix the review step or choose a lower-stakes task.
Does that task cost the team more than about five hours a week, or hold up something that makes money?
Be honest about the number. Setup, testing and maintenance are real hours too.
If no: The setup will cost more than it saves. Give the people who want one a chat assistant on a business plan and leave it there. Do not build anything.
Can the data involved legally and safely leave your systems, or can you afford a controlled setup where it does not have to?
Client financial records, health information, privileged material, and anything your licensee restricts all need an answer here first.
If no: The compliance question comes first. Until privacy, confidentiality or licensee rules are settled, AI is a liability rather than a help. That may mean a private deployment, or it may mean a different task.
Is there one person who will own this for ninety days?
Not a committee. One name, with the authority to switch it off if it is not working.
If no: Tools without an owner die within a quarter. This is the most common reason AI projects fail in small business. Find the owner first, or wait until you can.
Yes to all six: AI will probably help. You have a repeating task, written-down information, a review step, real hours at stake, a clear data position and an owner. That is more than most businesses can say.
What AI tools actually means
Chat assistants
A person types, the tool answers. Drafting, summarising, rewriting, brainstorming, explaining. Good for a person who already knows what good looks like and wants to go faster.
Built-in features
AI already inside software you pay for: meeting summaries, email drafts, spreadsheet formulas, photo editing. Good for nearly everyone, because the setup cost is zero and the data stays where it already is.
Workflow automation
Rules that move information between systems, with an AI step in the middle to read, classify or write something. Good for repetitive admin with a clear trigger, like "new enquiry arrives, draft a reply, log it in the CRM".
Agents
Software that takes a goal, works out the steps, uses other tools and comes back with a result. Powerful, less predictable, and needs guardrails. Good for multi-step work where a human reviews the output before it matters.
Custom and trained models
A model built or fine-tuned on your own data, or a private deployment for confidentiality. Good for businesses with a large, specific dataset and a compliance reason to keep it in-house. Rarely the right first step.
Three sensible levels
Level one: switch on what you already pay for
- Turn on the AI features inside Microsoft 365, Google Workspace, Xero or your CRM.
- Give the two or three people who write the most a paid chat assistant on a business plan.
- Write the one-page use policy. Name what is allowed in and what is not.
Stop here if nobody in the business uses these tools daily after a month. The problem is not the tool.
Level two: automate one repeating workflow
- Pick one process that happens at least weekly, follows a pattern and has a person who checks the result.
- Connect the systems it touches with an automation platform and an AI step for the reading or writing.
- Run it beside the manual process for a month before trusting it.
Stop here if the process changes every time someone new does it. Automate the process after you fix it, not before.
Level three: agents and private deployments
- Custom agents that handle multi-step work, or a private model deployment because your data cannot leave a controlled environment.
- Needs someone technical on the inside, a real budget and monitoring after launch.
- Justified when level two is running well and the volume or sensitivity demands more.
Almost nobody should start here. If a vendor proposes it first, ask what happened at levels one and two.
Compliance changes the answer
Financial advice or AFSL holder
- Anything that touches personal financial information sits under the Privacy Act and the licensee’s own data policies. Check with your licensee before a single client file goes into a public tool.
- Advice documents carry best-interests and record-keeping obligations. AI can draft, but an adviser signs off and the file must show they did.
- AI-generated marketing still has to meet financial product advertising rules. "The AI wrote it" is not a defence.
- Complaints handling needs a human owner and timeframes. Automation can triage, not resolve.
Strong fit for internal drafting and admin, only with an enterprise or private deployment and licensee approval.
Health or allied health
- Health information is "sensitive information" under the Privacy Act, with stricter collection and use rules than ordinary personal data.
- Registered practitioners remain personally responsible for clinical decisions and records, however they were produced.
- AI scribes are becoming common but need patient consent, secure storage, and a clinician reviewing every note.
Good fit for note-taking and admin with a health-specific, Australian-hosted tool. Avoid general chat tools for anything identifying a patient.
Legal or accounting
- Client confidentiality and legal professional privilege can be put at risk by pasting material into a tool whose terms allow training on inputs.
- Tax agents and accountants carry professional obligations. Advice generated by a tool is still the agent’s advice.
- AI is prone to inventing citations, case names and section numbers. Anything that references law needs verification, every time.
Useful for research starting points, summaries and correspondence. Never the final word on anything with a section number in it.
Retail, ecommerce or hospitality
- Customer data is still personal information, and marketing automation must respect the Spam Act’s consent and unsubscribe rules.
- Never let a tool handle raw card details. Payment systems exist for that.
- AI-generated product claims and reviews are covered by Australian Consumer Law. Fake or misleading content is the business’s problem.
Lowest compliance friction of any sector. Product descriptions, customer replies and inventory forecasting are all sensible early uses.
Trades, construction or professional services
- Quotes and contracts generated with AI need the same care as any template. The tool does not know your margins, your insurer’s wording or the state’s building rules.
- Client and site data is generally low-sensitivity, so the main risk is accuracy rather than privacy.
- If you hold personal information on employees or subcontractors, ordinary Privacy Act rules apply.
Strong fit for quoting, scheduling and chasing invoices. Keep a human on anything with a dollar figure or a legal clause.
Something else
- Using AI to screen candidates or assess performance can create discrimination risk if the criteria are opaque. Keep a person in the decision.
- Tell staff what tools are approved and what data must never go into them. Most breaches are a well-meaning employee pasting a client email into a free tool.
- Check whether the tool uses your inputs to train its models. Business and enterprise plans usually do not; free plans often do.
Write a one-page AI use policy before anything else. It costs nothing and covers most of the risk.
AI and compliance, common questions
- Is it safe to put company or customer information into an AI tool?
- Only with the right controls. Consumer chatbots may use what you type to improve their models and may store it offshore, which can put your privacy and confidentiality obligations at risk. Use business-grade tools with a data agreement, data handling you are comfortable with, and model training turned off. As a rule, do not paste customer-identifying or confidential information into any tool you have not checked first.
- Who is responsible if AI gets something wrong?
- Your business is. AI can draft, summarise and suggest, but whoever sends the output to a customer, a regulator or a decision owns it. Treat AI output as a first draft and keep a person accountable for reviewing anything that leaves the building. Build that review step into the workflow rather than trusting the tool.
- What are the main compliance risks of using AI in a business?
- The common ones are: confidential or customer data leaving your control; AI errors or invented facts reaching a customer unchecked; gaps in your records and audit trail; and AI output being used as a final answer without a person reviewing it. Each is manageable with a clear policy, tools you have vetted, and a human review step before anything goes out.
- Do we need an AI policy?
- For most businesses, yes, even a short one. A single page that says which tools are approved, what may and may not go into them, who reviews AI output before it is used, and who to ask when unsure prevents most of the problems above. It also gives your team the confidence to use AI well, rather than quietly or not at all.
- Do regulated industries have extra rules?
- Yes. If you work in a licensed or regulated field, such as financial services, health or law, your existing obligations still apply to AI-assisted work, and your regulator or professional body may have specific guidance to check before AI touches regulated decisions or advice. As one example, in financial services, providing financial product advice needs an Australian Financial Services Licence whether a person or an AI helped prepare it. GBX Professional Services does not hold an AFSL and does not provide financial advice; we help you adopt AI operationally, with the regulated decisions staying inside your licensed business.
- Where should a business start with AI, safely?
- Start with low-risk, high-repetition tasks that do not touch confidential data or make final decisions: internal drafting, meeting notes, summarising public research, first-draft marketing. Put a short AI policy and an approved-tools list in place, add a human review step, then expand from there. The guide above and our AI Readiness Assessment help you find a sensible first use case.
- Does GBX Professional Services give legal or compliance advice on this?
- No. We help you adopt AI with discipline: readiness, tooling, governance guardrails, process and training. This is general information, not legal, compliance or financial advice. Your own advisers, and where relevant your licensee or professional body, remain the source of truth on your specific obligations.