Artificial Intellegence Policy
Baby Lion Design Co. Responsible Use of Artificial Intelligence Policy
Policy owner: Kim King
Business: Baby Lion Design Co.
ABN: 75 525 256 871
Location: Alstonville, New South Wales, Australia
Version: 1.0
Effective date: 28 July 2026
Review date: 28 July 2027
1. Purpose
Baby Lion Design Co. uses creativity, strategy and technology to help purpose-led businesses develop distinctive brands and effective digital experiences.
Artificial intelligence can assist with research, planning, administration, accessibility, ideation, website development and content refinement. It can also create risks involving privacy, confidentiality, inaccurate information, bias, intellectual property, cybersecurity, environmental impact and loss of human judgment.
This policy establishes how Baby Lion Design Co. will select, use, monitor and disclose artificial intelligence responsibly.
Our approach is guided by the following commitments:
- people remain responsible for all professional decisions and deliverables;
- client relationships, trust and informed collaboration come before convenience;
- confidential, personal and commercially sensitive information is protected;
- AI-generated material is checked, refined and approved by a human;
- intellectual property and creative integrity are respected;
- AI is used proportionately and only where it creates genuine value;
- people affected by AI-assisted work can ask questions or raise concerns; and
- environmental and societal impacts are considered when selecting and using technology.
This policy supports the Australian Voluntary AI Safety Standard’s expectations concerning accountability, risk management, data governance, testing, human oversight, transparency, record-keeping and stakeholder engagement.
2. Scope
This policy applies to:
- Baby Lion Design Co.;
- the owner, employees, contractors, freelancers, interns and collaborators;
- AI tools used for internal business activities;
- AI tools used when delivering services to clients;
- AI-enabled features incorporated into client websites or digital products;
- third-party suppliers using AI on Baby Lion’s behalf; and
- generative AI systems producing text, images, code, audio, video, recommendations, summaries or other outputs.
It applies throughout the AI lifecycle, including selection, purchasing, configuration, prompting, testing, use, review, publication, monitoring and retirement.
This policy does not authorise any activity prohibited by a client agreement, confidentiality obligation, privacy requirement, licence condition or applicable law.
3. Definitions
Artificial intelligence or AI means a machine-based system that uses inputs to generate outputs such as content, predictions, recommendations or decisions.
Generative AI means AI that produces new material, including text, images, designs, code, audio or video.
AI-assisted work means work in which AI supports a human-led process but the final result is reviewed and approved by a person.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive information includes information concerning matters such as health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or biometric information.
Client confidential information means non-public information supplied by or created for a client, including business plans, customer information, credentials, unpublished designs, content, analytics, commercial information and intellectual property.
High-impact use means an AI use that could materially affect a person’s rights, access to services, reputation, safety, employment, finances or opportunities.
4. Responsible AI principles
4.1 Human-led creativity
AI may support Baby Lion’s creative process, but it will not replace strategic thinking, professional design judgment, client listening or meaningful human authorship.
Final brand concepts, website designs, recommendations and client deliverables must be intentionally shaped and approved by a person.
4.2 Fairness and inclusion
AI must not be used in a way that unjustly discriminates against, stereotypes, excludes or disadvantages people or communities.
AI-assisted content and imagery must be reviewed for:
- gender, racial, cultural, disability and age-related stereotypes;
- exclusionary language or assumptions;
- accessibility barriers;
- harmful representations;
- culturally inappropriate material; and
- unrealistic or misleading depictions of people.
Where relevant, Baby Lion will seek input from people with appropriate lived, cultural or professional expertise rather than assuming an AI system can represent their experience.
4.3 Privacy and confidentiality
Privacy, confidentiality and data minimisation apply to all AI use.
Only the minimum information genuinely needed for an approved purpose may be entered into an AI system.
4.4 Transparency
Baby Lion will be open about material uses of AI where disclosure would reasonably matter to a client, website user or other affected person.
AI must not be presented as a qualified professional, human employee or independent decision-maker.
4.5 Accuracy and safety
AI output must be treated as an unverified draft. It must not be assumed to be accurate, current, complete, secure, lawful or original.
4.6 Accountability
The person using AI remains responsible for the resulting work. Responsibility cannot be transferred to an AI provider or blamed on an AI system.
4.7 Environmental responsibility
Baby Lion will use AI deliberately rather than automatically. Where practical, preference will be given to efficient tools, limited iterations, proportionate model use and suppliers that provide credible information about environmental performance.
5. Governance and responsibilities
The business owner is the Responsible AI Lead.
The Responsible AI Lead will:
- approve AI tools and significant AI use cases;
- maintain an AI tool register;
- assess privacy, security, intellectual property and client risks;
- decide when client disclosure or consent is required;
- manage incidents and complaints;
- review this policy and related procedures;
- ensure contractors understand their responsibilities; and
- monitor significant legal, regulatory and technology developments.
Every person working for or with Baby Lion must:
- use only approved AI tools for business work;
- comply with this policy and relevant client agreements;
- protect credentials and confidential information;
- verify AI output before using or sharing it;
- disclose mistakes, suspected data exposure or unsafe output promptly; and
- stop using an AI system where its risks cannot be adequately controlled.
6. Approved and prohibited uses
6.1 Generally permitted uses
Subject to human review and the other controls in this policy, AI may be used for:
- brainstorming early-stage ideas;
- developing questions for strategy workshops;
- summarising non-confidential notes;
- improving grammar, structure, readability or tone;
- generating internal checklists and draft project plans;
- creating draft metadata, image descriptions or accessibility text;
- researching broad industry themes using non-confidential inputs;
- supporting code drafting, troubleshooting or documentation;
- identifying potential usability, SEO or accessibility issues;
- creating internal administrative templates;
- organising information supplied in a de-identified form; and
- generating low-risk mock-ups or exploratory concepts that will be substantially reviewed and refined.
6.2 Uses requiring specific approval
The Responsible AI Lead must approve:
- uploading any client files to an AI platform;
- generating material intended to form a substantial part of a final client deliverable;
- using AI-generated people, testimonials, case studies or product depictions;
- connecting AI tools to email, cloud storage, analytics, customer management systems or websites;
- installing AI-enabled WordPress plugins;
- using AI to analyse website visitor or customer behaviour;
- using a client’s content to configure, fine-tune or train a system;
- deploying an AI chatbot, recommendation system or automated customer interaction;
- processing personal information using AI;
- using AI-generated code in a production website;
- automated publishing to websites, email or social platforms; or
- using an AI supplier that retains prompts or outputs for model training.
6.3 Prohibited uses
Baby Lion must not use AI to:
- make final decisions about hiring, firing, client acceptance, pricing disputes or complaints without meaningful human review;
- create fake testimonials, reviews, qualifications, performance claims or case-study results;
- impersonate a client, employee, customer, competitor or real person;
- create deceptive imagery or content without appropriate labelling;
- fabricate website statistics, research, citations, legal claims or SEO results;
- reproduce a living artist’s distinctive style for a commercial client deliverable where doing so could be misleading, exploitative or infringing;
- upload passwords, API keys, authentication codes or security credentials;
- upload payment-card details or complete financial account information;
- upload sensitive information to a general-purpose AI tool;
- upload unpublished client strategies, customer lists, design files or proprietary information without documented approval and suitable protections;
- use client content to train a public or shared AI model;
- bypass copyright, licence, privacy or website access restrictions;
- scrape protected website content contrary to applicable terms or law;
- create unlawful, discriminatory, abusive, sexually exploitative or harmful material;
- generate content exploiting or endangering children;
- publish AI-generated code, factual claims or advice without human verification; or
- allow an AI system to communicate autonomously with a client about a dispute, legal issue, security incident or binding commitment.
7. AI risk assessment and approval workflow
Before adopting a new AI tool or material use case, Baby Lion will assess:
- Purpose: What business or client need does the tool address?
- Necessity: Can the outcome be achieved reasonably without AI?
- Information: What data will be entered, accessed, generated or retained?
- People affected: Could the use affect a client, customer, worker or community?
- Accuracy: What could happen if the output is wrong?
- Bias and inclusion: Could it stereotype, exclude or disadvantage anyone?
- Privacy: Will personal or sensitive information be processed?
- Confidentiality: Will the system receive client or commercially sensitive information?
- Intellectual property: What are the input and output ownership and licensing conditions?
- Security: What access, integration, retention or cyber risks exist?
- Transparency: Would a reasonable person expect to know that AI was used?
- Human control: Can a person review, correct, override or stop the system?
- Supplier risk: Does the provider offer suitable privacy, security and contractual protections?
- Environmental impact: Is the use proportionate to its value?
Uses will be classified as:
- Low risk: administrative or exploratory use involving no confidential or personal information and no direct external impact.
- Moderate risk: use contributing to client-facing work, production code, marketing material or analysis.
- High risk: use involving personal information, automated interactions, significant client reliance, security-sensitive functions or impacts on people’s rights or opportunities.
High-risk uses require a written assessment, documented safeguards and explicit approval. Baby Lion will not deploy a high-risk use where adequate human oversight, testing or risk controls are unavailable.
Use:
8. Privacy and data governance
Baby Lion’s existing Privacy Policy covers information including names, email addresses, phone numbers, postal and billing addresses, IP addresses, device identifiers, website activity, advertising interactions, cookies and analytics information. AI use involving this information must comply with the Privacy Policy and applicable privacy obligations.
The following rules apply:
- Personal information must not be entered into an AI tool merely because it is available.
- Where possible, information must be removed, generalised, anonymised or replaced with placeholders.
- Sensitive information must not be entered into general-purpose public AI tools.
- A supplier’s privacy terms, retention settings, training settings, hosting location and deletion options must be reviewed before use.
- Where available, model-training and history-retention settings must be disabled for client work.
- AI tools must not be given unrestricted access to email, drives, website databases or client platforms.
- Access must follow the principle of least privilege, meaning only the minimum necessary access is granted.
- Information must be retained only for as long as reasonably necessary.
- Client information must not be reused for another client or for Baby Lion’s own model training without clear written permission.
- Any legally required privacy notice or consent must be provided before processing begins.
OAIC guidance states that the Privacy Act applies to AI uses involving personal information where the organisation is covered by the Act, and recommends careful assessment of commercially available AI products.
Use:
9. Client confidentiality
Client materials remain subject to contractual, ethical and confidentiality obligations regardless of whether an AI provider describes uploaded information as secure.
Before using client information in an AI tool, Baby Lion must determine:
- whether the proposed use is consistent with the client agreement;
- whether the client has imposed specific AI restrictions;
- whether the supplier may retain or train on the information;
- whether the information can be de-identified;
- whether client notification or consent is appropriate; and
- whether a safer alternative is available.
Contractors and suppliers must not independently upload Baby Lion or client material into AI systems without approval.
10. Intellectual property and creative integrity
AI creates uncertainties concerning copyright, trade marks, moral rights, licensing, originality and provenance.
Baby Lion will:
- use properly licensed or authorised input material;
- avoid prompting AI tools to copy protected client work or a specific artist’s recognisable style;
- review AI outputs for similarity to existing designs, brands, copy and imagery;
- retain records of material AI contributions to final deliverables;
- conduct appropriate trade mark, image and originality checks where relevant;
- not guarantee that raw AI output is exclusive or capable of intellectual property protection;
- clarify ownership and permitted use where AI output is incorporated into client work;
- ensure stock, font, plugin, theme and software licence conditions are followed; and
- obtain client approval before using client work to demonstrate or promote an AI-enabled capability.
AI output must never be represented as entirely original human work where that representation would be misleading.
11. Design and content standards
AI-assisted client work must meet the same quality standards as non-AI work.
Before delivery or publication, a person must check:
- strategic alignment with the client brief;
- factual accuracy;
- spelling, grammar and tone;
- originality and potential infringement;
- accessibility;
- inclusive language and imagery;
- misleading or unsupported claims;
- compliance with advertising and consumer-protection requirements;
- brand consistency;
- technical suitability; and
- the presence of hidden, malicious or inappropriate material.
AI must not be used to manufacture emotional manipulation, false urgency, false scarcity or deceptive environmental claims.
12. Website development, code and cybersecurity
AI-generated code must be treated as untrusted until reviewed and tested.
Before deployment, code must be checked for:
- security vulnerabilities;
- insecure data handling;
- exposed credentials;
- licence conflicts;
- unnecessary tracking;
- accessibility issues;
- performance problems;
- compatibility with the website environment;
- maintainability and documentation; and
- unexpected connections to third-party services.
AI-enabled plugins or services must be evaluated for:
- developer reputation and maintenance history;
- data collection and transfers;
- permissions requested;
- security update practices;
- incident history;
- ability to disable or remove the feature;
- effect on website speed and carbon impact; and
- ongoing subscription or vendor-lock-in risks.
Public AI tools must not receive production passwords, complete configuration files, private keys, database exports or unredacted error logs containing personal information.
13. Testing and validation
The amount of testing must reflect the level of risk.
Testing may include:
- checking factual statements against reliable sources;
- reviewing calculations and links;
- testing code in a non-production environment;
- reviewing outputs across different user scenarios;
- checking for biased or exclusionary outputs;
- accessibility testing;
- security scanning;
- comparing AI output with the approved brief;
- checking whether the system behaves differently after updates; and
- confirming that a human can intervene or disable the system.
Acceptance criteria must be defined before deploying moderate- or high-risk AI uses.
Material AI-generated content must not be automatically published without human approval.
14. Transparency and client communication
Baby Lion will provide meaningful information about AI use where it is relevant to the client’s decision, rights, confidentiality, intellectual property or final deliverable.
Disclosure may be appropriate where:
- AI generated a material part of final imagery, copy, code or analysis;
- client information will be processed by an external AI provider;
- an AI chatbot or automated assistant communicates with people;
- a person could reasonably believe they are interacting with a human;
- synthetic media depicts realistic people, products, places or events;
- the limitations of AI output may affect reliance on the work; or
- a client contract requires disclosure.
Routine use of tools such as spellchecking, layout suggestions or low-risk internal brainstorming does not ordinarily require item-by-item disclosure, provided no confidential information is exposed and human responsibility is maintained.
Suggested client notice:
Baby Lion Design Co. may use carefully selected AI-assisted tools for limited activities such as research, ideation, editing, accessibility checks, code support or administration. All client-facing work remains human-led, reviewed and approved. Confidential or personal information will not be entered into general-purpose AI systems without appropriate safeguards and, where necessary, your approval.
15. Human oversight and client approval
A suitably skilled person must remain able to:
- understand the AI system’s role;
- assess whether its output is appropriate;
- identify obvious errors or harmful results;
- correct or reject the output;
- stop the process;
- explain the final work to the client; and
- accept responsibility for the outcome.
AI must not be the final approver of a brand identity, website launch, client communication, invoice, contractual commitment, complaint response or security decision.
Client approval processes remain unchanged by the use of AI.
16. Complaints, questions and contestability
Clients and affected people may ask:
- whether AI was materially used;
- how it contributed to a deliverable or interaction;
- whether their information was provided to an AI supplier;
- for a suspected error to be reviewed;
- for inaccurate personal information to be corrected; or
- for concerns about bias, privacy, intellectual property or misleading content to be investigated.
Concerns may be directed to:
Kim King
Email: hello@kimmiek.com.au
Location: Alstonville, NSW 2477, Australia
Baby Lion will review the concern personally and will not rely solely on the relevant AI system to investigate or decide the outcome.
17. Records and documentation
Baby Lion will maintain proportionate records of:
- approved AI tools;
- the tool owner and business purpose;
- relevant supplier terms and privacy settings;
- risk assessments;
- client restrictions or permissions;
- material AI use in final deliverables;
- testing and human approvals;
- incidents, complaints and corrective actions; and
- review or retirement decisions.
Records must be detailed enough to explain how a material AI-assisted outcome was created and checked without unnecessarily retaining sensitive prompts or client information.
Use:
18. Supplier and contractor management
Before engaging a material AI supplier, Baby Lion should consider:
- privacy and security practices;
- whether prompts or outputs are used for training;
- data storage and transfer locations;
- deletion and export options;
- intellectual property terms;
- service reliability;
- accessibility;
- transparency documentation;
- incident notification;
- subcontractors;
- model-update practices; and
- exit arrangements.
Contracts with contractors or suppliers should require compliance with this policy, confidentiality obligations, security controls and notification of suspected incidents.
19. Incident response
An AI incident may include:
- confidential or personal information being entered into an unauthorised tool;
- an AI output exposing protected information;
- publication of materially false or harmful content;
- discriminatory or offensive output;
- copyright or trade mark concerns;
- vulnerable or malicious generated code;
- an undisclosed automated interaction;
- unauthorised access through an AI integration; or
- loss of human control over an automated process.
Any suspected incident must be reported immediately to the Responsible AI Lead.
Baby Lion will:
- stop or contain the affected use;
- preserve appropriate evidence;
- remove or correct harmful output;
- assess affected people, clients and systems;
- consider contractual, privacy, cybersecurity and legal notification requirements;
- notify affected clients or people where appropriate;
- document the cause and response;
- improve the relevant controls; and
- decide whether the tool may be resumed, restricted or retired.
Use:
20. Training and capability
Anyone authorised to use AI for Baby Lion must understand:
- this policy;
- the limitations and common failure modes of generative AI;
- privacy and confidentiality requirements;
- intellectual property risks;
- prompt-injection and data-exposure risks;
- bias and inclusive design;
- verification and human-review expectations; and
- incident-reporting procedures.
Training must be refreshed when tools, risks or legal requirements materially change.
21. Environmental and societal impact
Baby Lion’s commitment to purpose-led and lower-impact digital design extends to AI use.
Baby Lion will:
- avoid unnecessary AI generation and repeated low-value iterations;
- use conventional tools where they provide the same result with lower risk or resource use;
- consider the environmental transparency of significant suppliers;
- avoid using AI to create deceptive sustainability claims;
- assess the effect of automation on creative workers and contractors;
- credit and compensate human contributors appropriately; and
- preserve opportunities for meaningful human creativity, learning and participation.
22. Monitoring and continuous improvement
The Responsible AI Lead will review:
- the approved tool register;
- changes to supplier terms and model behaviour;
- incidents and complaints;
- the effectiveness of safeguards;
- feedback from clients and collaborators;
- emerging accessibility, environmental and social impacts; and
- relevant legal and regulatory changes.
This policy will be reviewed at least annually and after any significant AI incident or material change in Baby Lion’s services.
23. Relationship with other Baby Lion documents
This policy should be read with:
- Baby Lion Design Co. Privacy Policy;
- Baby Lion Design Co. Terms of Service;
- client proposals, scopes and service agreements;
- confidentiality arrangements;
- website maintenance and security procedures;
- copyright and licensing requirements;
- data breach response procedures; and
- contractor agreements.
Where another agreement imposes a higher standard, the higher standard applies.
This policy does not reduce any rights or remedies available under applicable consumer, privacy, intellectual property, anti-discrimination or other laws.
24. Framework alignment
This policy has been informed by:
- Australia’s AI Ethics Principles;
- Australia’s Voluntary AI Safety Standard;
- the Australian Government Policy for the Responsible Use of AI, particularly its focus on accountability, assurance, transparency and human ownership of decisions;
- OECD AI Principles, including inclusive growth, human rights, fairness, privacy, transparency, robustness, security and accountability;
- ISO/IEC 42001 AI management-system concepts;
- the NIST AI Risk Management Framework;
- UNESCO’s Recommendation on the Ethics of Artificial Intelligence;
- the EU AI Act’s risk-based and transparency-oriented approach where Baby Lion provides services affecting people in the European Union;
- international approaches that support proportionate, risk-based AI adoption and continued human accountability; and
- principles of trustworthy AI including fairness, reliability, privacy, transparency, human oversight, accountability and wellbeing.
25. Compliance checklist
Before using AI for Baby Lion work, confirm:
- The purpose is clear and appropriate.
- The tool is approved.
- The information entered is the minimum necessary.
- No prohibited confidential, personal, sensitive or security information is included.
- Supplier retention and training settings are acceptable.
- Client terms and instructions permit the use.
- Intellectual property and licence risks have been considered.
- Bias, accessibility and inclusive-design risks have been considered.
- The output will be reviewed by a suitably skilled person.
- Factual claims, code, links and calculations will be verified.
- Any required client or user disclosure will be made.
- Appropriate records will be retained.
- A person can correct, override or stop the process.
- The use is proportionate to its environmental and social impact.
- Any issue or incident will be reported promptly.
26. Approval
This policy is approved by Kim King, Owner of Baby Lion Design Co.
Approved: 28 July 2026
Next review: 28 July 2027
