Reasonable steps and AI
AI and reasonable steps: a generated policy is not proof you took them
APP 11 asks an organisation to take reasonable steps to protect the personal information it holds. It has never asked for a document set. It asks what you put in place, whether it was appropriate to your risk, and whether it was still true when something went wrong.
Generated text can describe every one of those things convincingly. It cannot be any of them. That distinction used to be academic because writing a policy was slow enough to imply effort. It is not academic now.
General information about Australian obligations, not legal advice.
Does an AI-generated policy prove reasonable steps?
No. It proves a policy exists. A policy is a statement of what should happen. Reasonable steps are about what did happen. A document generated in ninety seconds and a document written over three weeks are equally silent on whether the control it describes was ever implemented, whether staff were told, and whether anyone has looked at it since.
This is not a criticism of AI-drafted documents. A well-drafted policy is a real improvement over no policy, and a generated first draft that a person then makes true is a perfectly sound way to work. The point is narrower and it is about what the document can carry: generated text describes an intended state, and it cannot substitute for the implementation, decision, activity or review it describes.
The reason this matters more than it used to is supply. When producing a full policy set took weeks of somebody's attention, the existence of the set was itself weak evidence that an organisation had engaged with the problem. That inference no longer holds. An organisation that generates ten excellent policies in an afternoon has improved its documented governance position. It has not thereby taken ten reasonable steps.
What are reasonable steps, and does AI change them?
Reasonable steps are the protective measures an organisation actually takes, judged against its circumstances: the sensitivity of the information, the size and nature of the business, and the harm that would follow from exposure. AI does not change the test. It changes the risk you are taking steps against, and it changes how easy it is to produce something that looks like a step without taking one.
Two things follow. First, AI use is now part of what reasonable steps have to cover, because staff can move personal information out of your systems and into somebody else's from a browser tab. Second, since 11 December 2024 APP 11.3 states that reasonable steps include technical and organisational measures, which puts the AI question squarely in the organisational half: who decided, who was told, who checks.
If you want the underlying obligation rather than the AI angle, start with APP 11 reasonable steps. This page is about the part AI makes harder.
Document, implementation, activity, evidence, review
These five are routinely collapsed into one word, "compliance", and the collapse is where most defensibility is lost. Multi-factor authentication is the cleanest illustration, so it runs through all five below.
-
Document: what the organisation says should happen
An access control policy states that multi-factor authentication is required on all business accounts. AI can write this well, and quickly. What it establishes is intent.
-
Implementation: what was actually put in place
MFA is enforced in the tenant, for every user, with no standing exclusions. This is a configuration state in a real system. No document can create it and no document can confirm it.
-
Activity: what people actually did
The policy was approved by a named person on a date, issued to staff, acknowledged, and the two accounts that could not be enrolled were escalated rather than quietly left alone. Activity is where a policy either enters the organisation or stops at the folder.
-
Evidence: what substantiates the implementation or the activity
A dated record: the tenant configuration as at a date, an acknowledgement list with names against it, the escalation and its outcome. Evidence is not the same as the artefact it describes. A policy document is evidence that a policy exists, and nothing more.
-
Review: whether anyone checked it is still true
Someone confirmed six months later that MFA is still enforced, that the new starters are enrolled, and that the exception from last year was closed. Without this, everything above describes a position that was true once. Compliance positions decay quietly, which is why the review date matters as much as the original decision.
Where AI sits in this
AI is genuinely useful at layer one and can assist at layer four, by helping draft or structure a record. It cannot produce layers two, three or five, because those are facts about the world rather than statements about it. An organisation that uses AI to accelerate the document layer and then does the other four is in a better position than one that did none of it slowly. An organisation that does the document layer and stops has bought speed at the cost of the inference its documents used to carry.
What AI can produce, and what still has to be demonstrated
The left column is legitimate and useful output. The right column is what an insurer, a larger client, an auditor or a regulator is actually asking about when they ask what you did.
| AI can help produce | What the organisation still needs to demonstrate |
|---|---|
| Policy wording | The policy was approved by someone with authority, issued, acknowledged by the people it binds, and reviewed on a date. |
| Training material | Named people completed training appropriate to their role, and the completions are current rather than four years old. |
| A risk assessment draft | The risk was genuinely considered, given an owner, and either treated or accepted as a recorded decision. |
| A supplier questionnaire | A person assessed the supplier against it, recorded the answers, and made an approve or refuse decision that someone owns. |
| A security procedure | The control is implemented in the system it describes, and was confirmed still working at a date. |
| Meeting minutes | The review actually occurred, these people were in it, and the decisions came out with names attached. |
| An incident report | The incident was assessed against the notifiable data breach criteria, and the assessment and its outcome were recorded at the time. |
| An asset or supplier list | The list reflects what the organisation actually uses, is owned by someone, and is corrected when a tool is added or dropped. |
None of this makes AI-assisted evidence improper. A summary of a review that genuinely happened, drafted with AI and confirmed by the people who were there, is a perfectly good record. What cannot happen is the record existing without the event.
Where AI genuinely strengthens a reasonable-steps position
Most compliance work in a small business fails for want of time, not for want of intent. AI removes a real part of that constraint, and the organisations using it well are ahead, not behind.
Getting to a first draft
A business with no policies at all is in a worse position than one with generated policies it then adopted properly. The starting line moved forward.
Finding what you missed
Reviewing an existing policy set against an obligation, or drafting the supplier questions you would not have thought to ask, is exactly the kind of work AI is good at.
Making records legible
Turning a messy set of notes into a review summary that a director can read is useful, provided the review happened and the people in it confirm the summary.
What the gap looks like in a real business
An eight-person accounting firm
Staff use Microsoft Copilot for email drafting and ChatGPT for summarising documents. Nobody has decided whether client tax information can be submitted to either. There is no approved-tool list and no record of anyone reviewing the providers. The principal, prompted by a client questionnaire, generates a full set of policies over one afternoon, including an AI usage policy, and saves them to the shared drive.
The firm's documented position improves substantially that afternoon. Its actual position barely moves.
What changed
- An AI usage policy now exists
- The rules are written down and are sensible
- The principal has read them
- There is something to send the client
What did not
- No staff member has seen the policy
- Nobody has been made accountable for AI use
- The two tools are still unassessed and unrecorded
- Client tax information is still going into whichever account is open
- There is no date, no owner and no review on any of it
Three months later a laptop is compromised and the firm has to work out what was exposed. The policy is not the problem. The problem is that nobody can say which AI services hold client material, because that was never decided and never recorded. Closing that gap takes about a day of somebody's attention, and it is the day that turns the documents into steps.
Written but not done, and done but not recorded
These fail differently and they are fixed differently, so it is worth knowing which one you have. Most businesses have some of each.
Written but not done
- Policies exist and no staff member has acknowledged one.
- A procedure describes a control that was never configured.
- A supplier questionnaire template was created and never sent.
- An owner is named in a document and does not know they own it.
- The review cycle is stated in the policy and has never run.
This is the failure mode AI makes more likely, because it removes the effort that used to force engagement.
Done but not recorded
- MFA has been enforced for two years and nothing says so.
- The owner refused a tool last winter and there is no record of the decision.
- Training happened in a team meeting with no attendance list.
- Access was reviewed informally when someone left.
- The evidence exists across four inboxes and a shared drive.
Common in well-run businesses, and easier to fix. The work was done. It just cannot be produced on request.
What it takes to hold the difference over time
The gap between a document and a demonstrated step is not closed once. It reopens every time a staff member joins, a tool changes, a control drifts or a review falls due and nobody notices.
Adoption, not authorship
A policy in Cleverer carries an approval, an audience, an acknowledgement record and a review owner. Who wrote the first draft is not the question the record answers.
Declared and evidenced are different states
Saying a control is in place and having current evidence that it is are recorded separately, and the second is not reached by asserting the first.
Evidence has a use-by date
Records stop counting as current when their own expiry or the control's review cadence passes. Expired evidence stays in the history and stops being presented as proof.
What that produces
A dated compliance record rather than a folder: what is in place, what is only asserted, what is missing, who owns each of those, and when each was last confirmed. When someone asks what the organisation actually did, that is what gets exported. It does not guarantee legal compliance, and no platform can. It lets the organisation demonstrate the reasonable steps it took, with dates against them. How the evidence system works.
Find out which side of the line you are on
The Readiness Check asks what your business has in place and what it can produce. It takes a few minutes and it is specific enough to be uncomfortable.
Questions about AI and reasonable steps
Is it acceptable to use AI to write compliance documents?
Yes. Nothing in Australian privacy law says a policy has to be written by a person, and a generated draft that the organisation then reviews, adapts and adopts is a legitimate way to work. What matters is what happens after the draft: approval, issue, acknowledgement, implementation and review.
Is AI-generated evidence fraudulent?
No, and framing it that way misses the real issue. A record drafted with AI describing an event that genuinely happened, confirmed by the people involved, is ordinary documentation. The problem is a record that describes an event which did not occur, and that problem has nothing to do with how the text was produced.
How is evidence of implementation different from a policy?
A policy states what should happen. Evidence of implementation shows that the thing described is actually in place, at a point in time. Evidence of activity shows that a person did something on a date. A policy library answers none of those questions, which is why an organisation with a complete policy set can still have very little to show.
Does using AI to draft policies weaken our compliance position?
Not in itself. It weakens the inference that other people used to draw from your documents, which is different. Where it does create real risk is when the speed of drafting substitutes for the decisions the drafting used to force, so the organisation ends up with rules nobody chose, about tools nobody assessed.
What should we be able to produce if a regulator or insurer asks?
What was in place before the event, who owned it, when it was last reviewed, and the records that substantiate each of those. Evidence assembled after an incident is worth considerably less than evidence maintained before one, because the question being asked is about the state of the organisation at the time.