Artificial Intelligence Policy
ABN: 12 676 770 200
Version: 1.0
1. Purpose and Scope
This AI Policy outlines SQL Insight Solutions' commitment to the safe, ethical, and responsible use of artificial intelligence (AI) in delivering our SQL Server database management services. It applies to all AI systems and tools we deploy, develop, or integrate into our service offerings.
This Policy is aligned with:
- Australia's AI Ethics Principles (2019)
- The Australian Government's Guidance for AI Adoption (October 2025)
- The Voluntary AI Safety Standard's 10 Guardrails
- Australian Privacy Principles
- Relevant sector-specific requirements for healthcare and financial services clients
2. Our AI Philosophy
SQL Insight Solutions integrates AI to enhance—not replace—human expertise. AI assists our team in delivering more comprehensive, accurate, and timely database services. However, critical decisions affecting your systems are always subject to human review, oversight, and approval.
Core Principles:
We commit to:
- Human-Centred AI: AI augments human expertise; humans remain accountable for all decisions
- Transparency: Clear communication about how AI is used in our services
- Security: Rigorous protection of data processed by AI systems
- Continuous Improvement: Regular review and refinement of our AI practices
3. AI Systems We Use
3.1 AI Platforms
We utilise the following AI technologies:
| Platform | Provider | Use Case |
|---|---|---|
| Azure OpenAI | Microsoft | Database analysis, query optimisation suggestions, documentation assistance |
| Claude API | Anthropic | Technical analysis, pattern recognition, report generation |
| Custom Models | SQL Insight Solutions | Proprietary database health scoring and anomaly detection |
3.2 How AI Supports Our Services
AI is integrated across our service offerings:
Database Health Checks:
- Automated analysis of performance metrics
- Pattern recognition for potential issues
- Risk scoring and prioritisation
Performance Tuning:
- Query analysis and optimisation recommendations
- Index suggestions based on workload patterns
- Resource utilisation analysis
Managed Services:
- Anomaly detection in database metrics
- Predictive alerting for potential issues
- Trend analysis and capacity planning
Migrations and Upgrades:
- Compatibility analysis
- Risk assessment
- Migration planning assistance
Consulting:
- Architecture analysis
- Best practice recommendations
- Documentation generation
4. Human Oversight and Control
4.1 Human-in-the-Loop
All AI-assisted analysis and recommendations undergo human review:
| AI Function | Human Oversight Level |
|---|---|
| Data analysis | Senior DBA reviews all findings |
| Recommendations | Expert approval required before client communication |
| Automated monitoring | Alerts reviewed by on-call engineer |
| Report generation | Quality review before delivery |
| Script/code suggestions | Manual review, testing, and approval before execution |
4.2 Intervention Capability
- All AI processes can be paused or terminated by authorised personnel
- Clients can request AI-free service delivery for specific engagements
- Critical changes to production systems require explicit human authorisation
4.3 Decision Authority
AI systems at SQL Insight Solutions:
- CAN: Analyse data, identify patterns, generate recommendations, create draft documentation
- CANNOT: Execute changes on production systems, access data beyond authorised scope, make final decisions on client systems
5. Data Handling and Privacy
5.1 Data Processing Principles
When AI systems process client data:
Minimisation: We process only the minimum data necessary for the specific analytical purpose.
Anonymisation: Where possible, data is anonymised or aggregated before AI processing.
Segregation: Each client's data is logically segregated; one client's data is never used to benefit another client without explicit consent.
No Training: Client data is not used to train third-party AI models. Our use of AI platforms is limited to inference (analysis) only.
5.2 Data Categories and AI Processing
| Data Type | AI Processing | Purpose |
|---|---|---|
| Database metadata | Yes | Performance analysis, schema review |
| Query patterns | Yes (anonymised) | Optimisation recommendations |
| Performance metrics | Yes | Health assessment, anomaly detection |
| Actual business data | No | Protected - not processed by AI |
| Personal information | No | Protected under Privacy Policy |
5.3 Third-Party AI Providers
We select AI providers who maintain robust security practices. Our primary AI providers (Microsoft Azure and Anthropic) hold independent security certifications including SOC 2 and ISO 27001. Our agreements with these providers include:
- Data processing terms compliant with Australian privacy law
- Prohibitions on using our data to train their models
- Data deletion upon request
- Appropriate technical and organisational security measures
SQL Insight Solutions' own security practices are informed by industry frameworks including the Australian Cyber Security Centre's Essential Eight and ISO 27001 principles, though we do not currently hold independent certification.
6. Sector-Specific Compliance
6.1 Healthcare Clients
For clients in the healthcare sector, we additionally:
- Comply with AHPRA guidance on AI in healthcare settings
- Ensure AI does not make clinical decisions
- Maintain clear accountability for all AI-assisted work
- Support TGA compliance for any AI that may interact with medical device software
- Provide transparency about AI limitations
- Ensure data sovereignty with Australian-based processing where required
6.2 Financial Services Clients
For APRA-regulated entities and financial services clients:
- Support compliance with CPS 230 (Operational Risk Management)
- Maintain alignment with CPS 234 (Information Security) requirements
- Provide documentation supporting vendor risk assessments
- Enable appropriate oversight of AI-assisted services
- Support third-party audit requirements
- Maintain service continuity practices consistent with prudential standards
7. Risk Management
7.1 AI Risk Assessment
We conduct risk assessments for AI deployment covering:
- Accuracy and reliability of AI outputs
- Potential bias in recommendations
- Data security and privacy implications
- Impact of AI errors on client systems
- Dependency on AI provider availability
7.2 Known Limitations
We acknowledge AI limitations:
- AI can produce incorrect or "hallucinated" outputs
- AI recommendations may not account for all business context
- AI performance depends on data quality
- AI systems may have biases from training data
Mitigation: Human expertise reviews all AI outputs; recommendations are tested before implementation; we maintain non-AI fallback procedures.
7.3 Incident Response
AI-related incidents are managed through:
- Immediate escalation to senior technical staff
- Root cause analysis
- Client notification where material
- Corrective action implementation
- Policy/procedure updates as needed
8. Transparency and Explainability
8.1 Client Communication
We commit to:
- Informing clients when AI is used in their services
- Explaining the role AI plays in analysis and recommendations
- Providing non-AI alternatives upon request
- Answering questions about our AI practices
8.2 Reporting
AI-assisted deliverables will clearly indicate:
- That AI tools were used in the analysis
- What human review was conducted
- Any limitations that may apply
9. Accountability
9.1 Governance
- AI Accountability: The Principal Consultant is accountable for AI governance
- Technical Oversight: Senior Database Administrators review AI-assisted work
- Policy Review: This policy is reviewed annually or when significant changes occur
9.2 Records
We maintain records of:
- AI systems deployed and their purposes
- Significant AI-assisted analyses
- Human reviews and approvals
- Any AI-related incidents or issues
10. Ethical Commitments
Aligned with Australia's AI Ethics Principles, we commit to:
- Human, Societal and Environmental Wellbeing: AI use should benefit our clients and not cause harm
- Human-Centred Values: Respecting human rights, diversity, and individual autonomy
- Fairness: Ensuring AI systems are inclusive and accessible
- Privacy Protection and Security: Safeguarding data throughout the AI lifecycle
- Reliability and Safety: Ensuring AI operates reliably as intended
- Transparency and Explainability: Being clear about when and how AI is used
- Contestability: Enabling challenge of AI-influenced decisions
- Accountability: Taking responsibility for AI outcomes
11. Client Rights
Clients have the right to:
- Know: Be informed when AI is used in their services
- Object: Request services without AI involvement
- Access: Understand how AI analysis was conducted
- Challenge: Question AI-assisted recommendations
- Escalate: Raise concerns about AI use to senior leadership
12. Continuous Improvement
We commit to:
- Staying informed of evolving AI regulations and best practices
- Participating in industry discussions on responsible AI
- Updating this Policy as the regulatory landscape evolves
- Training our team on responsible AI practices
- Engaging with the Australian AI Safety Institute (when established)
13. Policy Updates
This Policy will be reviewed:
- Annually as a minimum
- When significant changes to AI regulations occur
- When we introduce new AI systems or capabilities
- Following any significant AI-related incident
Material changes will be communicated to clients.
14. Contact
For questions about our AI practices:
