AI Policy

Purpose

This policy explains how Haley Brown and the business trading as Brand Shack, use artificial intelligence responsibly.

We use AI to support creativity, productivity, accessibility, business operations and client service. We do not use AI to replace human judgement, lived experience, professional responsibility or ethical decision-making.

Our approach is balanced: we encourage innovation, but with clear safeguards for privacy, confidentiality, accuracy, fairness, transparency and trust.

This policy aligns with the Australian Government’s responsible AI direction, including the Voluntary AI Safety Standard, which sets out guardrails for accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply-chain transparency, record-keeping and stakeholder engagement. It also reflects the Australian Government policy expectation that AI use should strengthen trust, be safe and ethical, and adapt as technology changes.

Purpose

This policy explains how Haley Brown and the business trading as Brand Shack, use artificial intelligence responsibly.

We use AI to support creativity, productivity, accessibility, business operations and client service. We do not use AI to replace human judgement, lived experience, professional responsibility or ethical decision-making.

Our approach is balanced: we encourage innovation, but with clear safeguards for privacy, confidentiality, accuracy, fairness, transparency and trust.

This policy aligns with the Australian Government’s responsible AI direction, including the Voluntary AI Safety Standard, which sets out guardrails for accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply-chain transparency, record-keeping and stakeholder engagement. It also reflects the Australian Government policy expectation that AI use should strengthen trust, be safe and ethical, and adapt as technology changes.

Who this policy applies to

This policy applies to:

  • Haley Brown;
  • Brand Shack;
  • employees, contractors, collaborators, volunteers and suppliers working with these businesses;
  • AI used internally, with clients, in customer-facing work, in AI-enabled products, and in procurement of AI tools.

The business is Australian-based and may service clients globally. Where a client operates in another jurisdiction, such as the EU, UK, New Zealand, Canada or the United States, additional client-specific legal, privacy or contractual requirements may apply.

AI tools currently approved for use

The following tools may be used, subject to this policy:

  • ChatGPT;
  • Claude;
  • Canva AI;
  • Notion AI;
  • Gemini;
  • CRM automation tools;
  • other tools approved by the founder/CEO or executive team.

New AI tools must not be used for client work until they have been reviewed for privacy, security, data use, reliability, commercial terms and suitability.

Approved uses of AI

AI may be used to support:

  • drafting emails;
  • research and summarising public information;
  • policy writing;
  • training materials;
  • meeting summaries;
  • coding and technical support;
  • data analysis;
  • customer support;
  • marketing content;
  • brainstorming and ideation;
  • accessibility improvements, such as plain-English rewriting;
  • workflow and CRM automation;
  • creation of first drafts, templates and internal resources;
  • creation and use of custom GPTs or AI assistants to support marketing copy, content creation, brand messaging, campaign ideas and related business communications.

AI-generated work must always be reviewed by a human before being sent to clients, published, relied on, or used in decision-making.

Custom GPTs and AI assistants must be designed and used as creative and productivity support tools, not as final decision-makers or replacements for professional judgement.

Our AI principles

5.1 Human-led

AI is a support tool, not the decision-maker. A human remains responsible for final judgement, quality, context and ethics.

5.2 Transparent

We will be open about our use of AI. Where AI materially contributes to content, advice, outputs, automation or client deliverables, we will disclose this in a clear and practical way.

5.3 Privacy-protective

We will not enter personal, sensitive, confidential or client-identifiable information into public AI tools unless the use has been approved, is lawful, and appropriate safeguards are in place.

5.4 Inclusive and fair

AI must be used in ways that respect diversity, accessibility, non-discrimination and the dignity of people and communities. This includes considering impacts on women, First Nations peoples, people with disability, culturally and linguistically diverse communities, LGBTQIA+ people, older people, young people, carers and other groups who may experience systemic exclusion.

5.5 Accurate and accountable

AI outputs can be wrong, biased, outdated or misleading. We check outputs before use and remain accountable for final work.

5.6 Safe and proportionate

The level of review should match the level of risk. Low-risk internal drafting may need light review. Client-facing, public, strategic or reputationally significant work needs stronger review.

These principles are consistent with the OECD AI Principles, which emphasise trustworthy AI, human rights, transparency, robustness, safety and accountability.

Data and confidentiality rules

AI tools may be used with:

  • public information;
  • general business information;
  • non-confidential internal information;
  • de-identified or anonymised examples;
  • fictional or synthetic client scenarios.

AI tools must not be used with:

  • client-identifiable information;
  • confidential client documents;
  • personal information;
  • sensitive information;
  • passwords, API keys or credentials;
  • unpublished business strategy;
  • legal, financial, health or employment records;
  • private community or member data;
  • information covered by a non-disclosure agreement;
  • information a client has not authorised us to use in AI tools.

Where client information is needed to complete work, the preferred approach is to remove identifying details first. For example, instead of entering a client’s real name, business name, customer list or private strategy, use neutral placeholders such as [Client A], [industry], [target audience] or [campaign objective].

Client-facing AI use

Because transparency is one of our commitments, we will disclose AI use to clients where AI materially contributes to the work.

Examples of appropriate disclosure include:

“AI tools may be used to support drafting, research, summarisation, ideation or workflow efficiency. All client-facing work is reviewed by a human before delivery.”

For substantial AI-assisted outputs, the disclosure may be more specific:

“This resource was developed with the assistance of AI tools and reviewed, edited and approved by Haley Brown.”

AI must not be presented as a human expert, employee, lawyer, therapist, financial adviser or other regulated professional.

Human review requirements

All AI outputs must be reviewed before use.

Human review must check:

  • accuracy;
  • tone and brand fit;
  • bias or exclusion;
  • privacy and confidentiality;
  • copyright and attribution risks;
  • accessibility and plain English;
  • factual claims;
  • suitability for the client or audience;
  • whether AI use should be disclosed.

For client deliverables, marketing, training, policy, coding, customer support or public-facing content, human review is mandatory.

Prohibited uses

The businesses must not use AI to:

  • make high-risk decisions about people, including employment, health, legal rights, credit, housing, insurance, education or access to essential services;
  • provide final legal, financial, medical or psychological advice;
  • create misleading testimonials, fake endorsements or deceptive content;
  • impersonate a real person without consent;
  • generate deepfakes or manipulated media without clear disclosure;
  • scrape private communities or confidential client data;
  • upload confidential client files into unapproved AI systems;
  • generate discriminatory, harassing, hateful or exploitative content;
  • bypass copyright, privacy, security or contractual obligations;
  • make automated decisions that significantly affect a person without human review.
AI product and automation rules

Where AI is used in client-facing products, websites, automations, CRM workflows or customer support, the following rules apply:

  • the purpose of the AI must be clear;
  • the user must know when they are interacting with AI or AI-assisted automation;
  • the AI must not make final high-impact decisions;
  • there must be a human escalation pathway;
  • outputs must be tested before launch;
  • customer data must be protected;
  • logs or records should be kept where practical;
  • the automation must be monitored for errors, bias, poor experience or unexpected outcomes.

For example, a CRM automation may be used to route enquiries, send reminders or personalise communications, but it should not make final decisions about whether a person is “worthy”, “high value”, “problematic” or excluded from a service without human review.

Custom GPTs and Client AI Assistants

The businesses may create, configure and use custom GPTs or AI assistants for internal use and for clients.

These tools may be used to help users:

  • draft marketing copy;
  • create social media captions;
  • brainstorm campaign ideas;
  • adapt copy for different audiences;
  • generate brand-aligned content prompts;
  • improve tone, clarity and accessibility;
  • repurpose existing content;
  • create draft emails, web copy, lead magnets, blogs, ads or training content.

Custom GPTs and client AI assistants must be designed with clear boundaries. They must not be presented as lawyers, accountants, doctors, therapists, financial advisers or other regulated professionals.

Where a custom GPT is created for a client, the client should be informed that:

  • the tool generates draft content only;
  • outputs may be inaccurate, biased, generic or unsuitable;
  • the client remains responsible for reviewing, editing and approving all outputs before publication;
  • confidential, sensitive, personal or third-party information should not be entered unless the client has appropriate safeguards and permissions;
  • the tool should not be used to make high-risk decisions about people;
  • AI-generated content should be checked for accuracy, originality, copyright risk, tone and brand suitability.
Procurement and vendor checks

Before adopting a new AI tool, the founder/CEO or executive team should consider:

  • What data does the tool collect?
  • Is client or personal information used to train the provider’s model?
  • Can training on our data be turned off?
  • Where is data stored?
  • What privacy and security protections apply?
  • Can data be deleted?
  • Does the tool create copyright or ownership risks?
  • Does the vendor explain limitations clearly?
  • Is the tool suitable for Australian privacy and consumer expectations?
  • Is the tool accessible and inclusive?
  • What happens if the tool produces harmful or inaccurate outputs?

Where practical, vendors should be asked to provide privacy, security, data-use, bias, audit and model-update information before approval.

This supports Australia’s voluntary guardrail on transparency across the AI supply chain.

Inclusion and accessibility commitments

AI must be used in ways that support inclusion, not reinforce exclusion.

When using AI for content, design, strategy, marketing, training or community work, we will consider:

  • whether language is accessible and plain English;
  • whether examples reflect diverse people and lived experiences;
  • whether stereotypes are being repeated;
  • whether content excludes people with disability;
  • whether First Nations peoples and cultures are represented respectfully;
  • whether gendered assumptions are present;
  • whether imagery reflects diversity without tokenism;
  • whether the output could harm or misrepresent marginalised communities.

This aligns with the Voluntary AI Safety Standard’s guardrail on stakeholder engagement, diversity, inclusion and fairness.

Research and factual accuracy

AI may be used to help with research, but AI is not a reliable source by itself.

For factual, legal, policy, technical, health, financial, regulatory or current information:

  • claims must be checked against reliable sources;
  • sources should be cited where appropriate;
  • current information should be verified;
  • AI-generated references must be checked because they may be fake;
  • uncertainty should be disclosed honestly.

AI must not be used to fabricate sources, case studies, client results, testimonials, statistics or credentials.

Intellectual property and copyright

When using AI, we will take reasonable care to avoid infringing copyright or misusing third-party intellectual property.

Staff and collaborators must not:

  • upload copyrighted client files into AI tools without permission;
  • ask AI to copy a living artist, competitor, creator or brand style too closely;
  • use AI-generated outputs that appear to reproduce protected material;
  • remove watermarks or ownership notices;
  • present AI-generated work as wholly original without review.

For brand, marketing, web and design work, AI outputs must be checked for originality, client suitability and commercial risk.

Incident response

An AI incident may include:

  • confidential information entered into an AI tool by mistake;
  • inaccurate AI output sent to a client;
  • biased or offensive AI-generated content;
  • misleading public content;
  • security or privacy concern;
  • AI automation sending the wrong message;
  • client complaint about AI use.

If an AI incident occurs, the person who identifies it must notify Haley Brown or the relevant executive lead promptly.

The response should include:

  1. pause or remove the affected AI output or automation;
  2. assess who may be affected;
  3. correct the error where possible;
  4. notify the client or affected person where appropriate;
  5. document what happened;
  6. update prompts, process, training or tool settings to reduce recurrence.
Training and staff responsibilities

Everyone using AI for these businesses must understand this policy.

People using AI must:

  • use only approved tools for business work;
  • protect client and confidential information;
  • review all AI outputs before use;
  • disclose AI use as required;
  • avoid high-risk uses;
  • report incidents;
  • ask for approval before using new AI tools or unusual AI workflows.

Contractors and collaborators should be given a copy of this policy before using AI on business or client work.

Review cycle

This policy should be reviewed:

  • every 12 months;
  • when a new major AI tool is adopted;
  • when AI is used in a new product or client-facing workflow;
  • after a serious AI incident;
  • when Australian or international AI regulation materially changes.

Because the businesses service clients globally, special review may be needed for clients in jurisdictions with stricter AI rules, such as the European Union. The EU AI Act uses a risk-based approach and places stronger obligations on high-risk AI systems and some general-purpose AI models.

Practical checklist
Before using AI, ask:
Question Required answer
Is this an approved AI tool? Yes
Am I entering confidential, client-identifiable or personal information? No, unless specifically approved
Is this a high-risk use affecting people’s rights or access to services? No
Will a human review the output? Yes
Does the client or audience need to know AI was used? Yes, disclose where AI materially contributes
Could this output be biased, exclusionary or inaccessible? Check and revise
Are factual claims verified? Yes
Is the output suitable for the brand, client and context? Yes
Are copyright and ownership risks considered? Yes
Do I need approval from Haley or the executive team? Yes, for new tools, unusual uses or client-facing automation
Summary policy statement

Brand Shack uses AI to support thoughtful, creative and efficient work. We use AI transparently, responsibly and with human oversight. We protect client trust, confidentiality, privacy, inclusion and quality. AI may help us create, analyse and automate, but people remain accountable for the final work and its impact.