Artificial Intelligence (AI) Usage Policy

1. Purpose and Scope

Steady Guide (“Steady Guide”, “we”, “our”, or “us”) provides NDIS support coordination, case management, and publishing services. We acknowledge the growing utility of Artificial Intelligence (AI) technologies and use AI carefully to improve efficiency and quality while protecting participants and maintaining trust.

This policy governs how we select, use, and supervise AI tools across our operations (including marketing, administration, operational efficiency, and publishing support). It applies to all personnel, contractors, key personnel, and anyone acting on behalf of Steady Guide.

This policy is intended to align with:

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) — specifically APP 1 (open and transparent management of personal information), APP 2 (anonymity and pseudonymity), APP 7 (direct marketing), APP 8 (cross-border disclosure), and APP 11 (security of personal information).
  • NDIS Code of Conduct, particularly Element 2 – protecting privacy and Element 4 — integrity, honesty and transparency.
  • NDIS Practice Standards, especially the Core Module — Information Management outcome.

This policy also reflects the NDIS Quality and Safeguards Commission’s position that providers remain fully responsible for all content, decisions, and actions, whether AI-assisted or not. This includes key principles consistent with tribunal/court expectations (often discussed in connection with the Ortiz v NDIA / Butler matters), namely that AI outputs are not evidence on their own, can be wrong or incomplete, and must be critically checked and supported by appropriate records and professional judgment.

2. Definitions

3. Prohibited Uses (The Red Lines)

To protect participant confidentiality, uphold the NDIS Code of Conduct, and maintain the highest ethical standards, the following activities are strictly prohibited:

4. Approved Uses

Steady Guide permits the use of secured, enterprise-grade AI tools exclusively for the following operational and creative functions:

  1. Publishing Brainstorming & Outlining: Brainstorming conceptual ideas, structural outlines, and marketing angles for educational resources, books (such as Securing the Future), and newsletters. AI used for publishing brainstorming and research must be operated in segregated environments where no participant data is accessible or processed.
  2. Administrative Efficiency: Assisting with drafting non-confidential administrative templates, general workflow structuring, scheduling organisation, and internal communications.
  3. Marketing Support: Generating general marketing copy, website frameworks, and broad educational content that contains no personal, confidential, or participant-derived data.
  4. Quality Support (Non-Confidential): Plain-language editing, spelling/grammar checks, and formatting support for non-confidential materials.

5. Publishing, Transparency, and Authorship

Steady Guide maintains transparency regarding how AI is used in our publishing and communications:

  1. AI as an Aid Only: AI may be used as a brainstorming, drafting, and editorial assistance tool. Every published word, book chapter, guide, and newsletter article is reviewed, edited, rewritten where needed, and approved by Jenny.
  2. Accuracy and Checking: Any AI-assisted content must be checked for accuracy, currency, and tone. If we refer to laws, NDIS rules, or Commission guidance, we confirm details using reliable sources before publication.
  3. Honesty and Transparency: We do not claim AI content is human-authored if it is not. We use AI in a way that supports the NDIS Code of Conduct Element 4 (integrity, honesty and transparency).

6. Automated Decision-Making (ADM) Transparency

Steady Guide does not use AI to make automated decisions about participants’ services, eligibility, funding, risk, or access.

In line with the Privacy Act 1988 (Cth) and the APPs:

  1. No AI-only decisions: We do not deploy automated decision-making programs or algorithms to make decisions that significantly affect participants’ rights, interests, NDIS funding, or service access.
  2. Upcoming December 2026 disclosure requirement: We note the upcoming requirement (commencing December 2026) to disclose certain AI-assisted / automated decision-making practices in our Privacy Policy, including what personal information is used and the kinds of decisions supported by such tools. If we introduce tools that meet this threshold, we will update our Privacy Policy before use.
  3. Right to human review: If we ever use software that meaningfully supports a decision involving a participant, we will ensure the decision can be explained, and a human remains responsible for reviewing inputs and outcomes.

7. Data Privacy, Infrastructure, and Security

Steady Guide uses a privacy-first approach to AI.

Infrastructure & hosting (participant-facing systems)

All participant emails, participant services are hosted exclusively with Microsoft in secure data centres located in Australia, with end-to-end encryption and enterprise-grade security. Secure stakeholder meetings are held on Microsoft Teams with invite-only access. Participant files, identifying information such as NDIS plan numbers, plan dates, dates of birth, reports and other participant information is hosted in Australia in the Astalty database, which has bank-grade security.

Marketing and AI segmentation

Marketing functions, tools, and publishing brainstorming tools are hosted on a separate Microsoft account, completely segregated from participant-facing systems. These functions are integrated with a team of Marblism AI bots that keep Jenny organised, assist with paid advertising, draft social media posts, draft blog posts, follow up networking contacts and create draft policies, such as this one. Steady Guide does not use Marblism’s receptionist.

Implication for AI use

Because participant systems are hosted on dedicated Microsoft enterprise infrastructure and completely segregated from marketing and AI tools, participant data is never exposed to, accessed by, or used by AI tools. This architecture reinforces the policy’s prohibition on inputting participant data into AI tools: the separation is not only a rule but is enforced by the physical/technical segmentation of the two environments.

  1. Privacy Act and APP alignment: All AI tool usage must follow the Privacy Act 1988 (Cth) and the APPs, including:
  • APP 1: We manage personal information openly and transparently.
  • APP 2: Where practical, we allow people to interact anonymously or using a pseudonym.
  • APP 7: We do not use AI tools for direct marketing in a way that breaches APP 7 (including opt-out requirements).
  • APP 8: We take care with any overseas AI providers and cross-border disclosures.
  • APP 11: We protect information from misuse, interference, loss, unauthorised access, modification, or disclosure.
  1. Data minimisation: We only use the minimum information needed for the task, and we prefer de-identified, general, or public information wherever possible.
  2. Secured infrastructure: Personnel must only utilise AI platforms integrated within our secured Microsoft enterprise environments or other approved enterprise environments where data is encrypted in transit and at rest, and where vendor agreements explicitly prohibit the use of corporate data for model training.
  3. Cross-border controls (APP 8): If an AI tool stores or processes data outside Australia, we assess privacy and security risks and only proceed where appropriate safeguards are in place and consistent with our Privacy Policy.
  4. Access control and retention: Access to AI tools is limited to authorised users, and we avoid storing AI prompts/outputs that contain sensitive business information unless required and appropriately protected.

8. Human Accountability and Professional Judgment

AI does not replace human empathy, professional qualifications, or duty of care. Steady Guide remains fully responsible and accountable for all services, communications, publications, and compliance obligations.

In line with the NDIS Quality and Safeguards Commission’s guidance and expectations:

  1. We are responsible for outcomes: Even if AI helps draft or summarise information, Steady Guide is responsible for the final content and for any decisions made.
  2. AI outputs must be treated with caution: AI can generate incorrect, incomplete, or biased information. AI output must be checked against reliable sources and our records before we rely on it.
  3. Record-keeping and explainability: Where AI contributes to a work product, we keep appropriate notes/records so we can explain what was used and how conclusions were reached (consistent with the NDIS Practice Standards — Core Module, Information Management outcome).

9. Review and Governance

This Artificial Intelligence (AI) Usage Policy will be reviewed at least annually, and earlier if laws, NDIS requirements, Commission guidance, or our technology changes. Updates will be approved by Jenny and published on our website where relevant.

Last updated: 15 August 2026