03 · AI Governance

AI governance for SMEs in Hong Kong and Australia.

AI governance for an SME is the rules for agents and tools after you know what you are deploying. We start with the stack, then write acceptable use, accountability, and alignment to Australia's Privacy Act and Hong Kong's PDPO.

What happens without a policy

Right now, someone in your organisation is pasting sensitive data into an AI tool. Do you know where that data goes?

Employee
ChatGPT / ClaudeNo policy in place
Customer DataSent externally
Third-party serversRetention unknown
?No visibility. No control.

Every prompt is a data decision. Is yours governed?

Our process

How we work

A structured engagement from first conversation to working framework, shaped by the stack you actually run. Typical timeline: 2–4 weeks.

Typical engagement: 2–4 weeks end-to-end. Monitoring phase optional.

Our client base

Company Size

Typically 20–100 staff. Large enough to have meaningful AI adoption across departments, small enough that governance has fallen through the cracks. No dedicated compliance or legal team.

What's at stake

These organisations learned the hard way. Without governance, AI risk becomes business risk.

What we actually do

Governance follows the stack. For an Australian manufacturer with around one hundred staff, a readiness audit decided what was worth building and governing before a single policy was written.

The rules only matter once you know what your infrastructure looks like and which agents will act in your name. Read what AI for an SME actually means →

Rules shaped by how you deploy.

We scope every engagement before any commitment. Tell us about your organisation and we'll respond within 2 business days.

The 3 Peat AI Framework Builder produces a first-draft framework in under an hour. Free to complete.

FAQ

AI governance is the set of policies, processes, and accountability structures that determine how your organisation uses AI, covering data handling, risk classification, staff responsibilities, and regulatory compliance. For an SME it should be shaped by what you actually deploy, not written as a standalone policy PDF.

Shadow AI in a law firm is fee earners putting client matter data into ChatGPT, Copilot, or a consumer AI tool the firm has not approved. That is a confidentiality problem under the Australian Solicitors' Conduct Rules, a Privacy Act exposure, and a question your PI insurer will ask at renewal.

Any organisation using AI tools with staff or customer data. In Australia that means the Privacy Act 1988 and the AI Ethics Principles. In Hong Kong, the PDPO and the PCPD’s AI guidance. If your team uses ChatGPT, Copilot, any AI-assisted tool, or an agent that takes action on its own, you need a framework.

The self-service 3 Peat AI Framework Builder produces a first-draft framework in under an hour. For organisations requiring bespoke consulting, a full implementation typically takes two to four weeks depending on complexity.

Our framework work is structured around the EU AI Act as the global benchmark, with modules for Australia’s Privacy Act and AI Ethics Principles, Hong Kong’s PDPO and HKMA guidance, Singapore’s PDPC Model Framework, and UK GDPR. We update coverage as regulations evolve.

Regulatory fines under the EU AI Act reach up to €35 million or 7% of global annual turnover. Beyond fines: data breach liability, reputational damage, loss of enterprise contracts that require vendor AI policies, and personal liability exposure for directors in some jurisdictions. With autonomous agents, ungoverned AI also means actions taken in your name with no accountability trail.