SECTION 01Why you need one, in one paragraph
Your staff are already using AI. Surveys keep finding the same thing, and so do we on every audit: people bring their own tools, and a large share never tell anyone. Without a policy you are not preventing AI use, you are just not seeing it. That is the worst version, because you carry the privacy exposure without any of the productivity gain being organised or shared.
Two pages. Names the tools people may use, says what data may go into each, bans a short list of things outright, and requires a human on anything consequential. Anything longer gets skimmed and ignored, and an ignored policy protects nobody.
SECTION 02Do these three things before you write a word
SECTION 03The eight clauses every AI policy needs
| Clause | What it must say | Why it is there |
|---|---|---|
| 1. Approved tools | The named list, with plan tier, and how to request an addition | Removes the excuse of not knowing, and gives people a route that is not going rogue |
| 2. Data rules | Which data tier may go into which tool | This is the clause that actually prevents privacy breaches |
| 3. Prohibited uses | A short, specific list of never | Vague bans get argued with. Specific ones do not |
| 4. Human review | Who signs off what before it goes out | Meets APP 10 accuracy obligations and stops hallucinations reaching customers |
| 5. Disclosure | When you tell customers, clients or candidates that AI was involved | Australian Consumer Law, client contracts, and basic fairness |
| 6. Attribution and IP | That raw AI output is a draft, and copyright needs human authorship | Protects your ownership claim and stops accidental infringement |
| 7. Reporting | What to do when something goes wrong, with no blame for reporting fast | You cannot meet a 30 day breach assessment window if nobody tells you for six weeks |
| 8. Review | A date and a named owner | Vendor terms change constantly. An unreviewed policy is wrong within a year |
SECTION 04The template
Copy this, replace the bracketed parts, delete what does not apply. It is deliberately short. Written for an Australian small to mid-sized business, and it assumes you have done the three steps in Section 02.
Effective [date]. Owner: [name, role]. Next review: [date, 12 months out].
1. Purpose. We use AI to work faster and better. This policy sets out how to do that without putting customer information, client confidentiality or our own reputation at risk. It applies to every employee, contractor and subcontractor.
2. Data classification. All information falls into one of three tiers.
Public: already published, or content we would happily publish. Example: our own website copy, public pricing.
Internal: ordinary business information containing no personal data. Example: draft process documents, internal templates.
Restricted: customer or staff personal information, health information, financial records, legal advice, anything under a client confidentiality clause, credentials, and unreleased commercial information.
3. Approved tools. You may use the tools listed in the AI Tool Register at [location]. Each entry states the plan tier and the highest data tier permitted. Using a tool that is not listed, or a personal account of a listed tool, is not permitted. To request an addition, contact [owner] and allow [x] business days.
4. Data rules. Public and Internal information may be used with any approved tool. Restricted information may only be used with tools marked Restricted-approved in the register. Where the task does not need identifying details, remove them before you start. If you are unsure which tier applies, treat it as Restricted and ask.
5. Prohibited uses. Do not: enter Restricted information into any tool not marked Restricted-approved; use free or personal AI accounts for any work purpose; upload client credentials, API keys or passwords; record or transcribe a meeting without telling everyone present and giving them the chance to object; use AI to make a final decision about a person's employment, credit, housing, insurance or access to a service; generate content that impersonates a real person or organisation; publish AI output as fact without verifying it; or use AI in a way that breaches a client contract.
6. Human review. A person must review and approve any AI-assisted output before it goes to a customer, is published, is relied on for a decision, or is committed to a production system. The reviewer is accountable for the content, not the tool. Verify every fact, figure, quote, legal reference and calculation.
7. Disclosure. Tell people when AI is meaningfully involved in something that affects them: when an AI system interacts with them directly, when a meeting is being recorded or transcribed, and where a client contract requires it. Never claim work is purely human when it is not.
8. Intellectual property. Raw AI output is a draft. Copyright requires human authorship, so material generated without meaningful human input may not be protected. Apply real editing and judgement to anything we intend to own. Do not paste in third-party copyrighted material for the model to rework.
9. Reporting. If Restricted information has gone into the wrong tool, if an AI output containing an error has reached a customer, or if you suspect any incident, tell [owner] the same day. Reporting quickly is treated as doing the right thing. Delay is the only thing that gets anyone in trouble, because it costs us our assessment window under the Notifiable Data Breaches scheme.
10. Consequences. Breaches of this policy are handled under our normal disciplinary process. Deliberate misuse of customer information is treated as serious misconduct.
11. Review. [Owner] reviews this policy and the AI Tool Register every [quarter or six months], and whenever a listed vendor materially changes its terms.
SECTION 05The AI Tool Register
The policy is the rules. The register is the list that makes the rules usable, and it is the document a client or regulator will actually ask for. A spreadsheet is fine.
| Column | What goes in it |
|---|---|
| Tool | Product name |
| Plan tier | Free, Pro, Team, Enterprise, API. The single most important column |
| Owner | Who inside the business is accountable for it |
| Used by | Team or role, so you know who to contact if it has to go |
| Max data tier | Public, Internal or Restricted |
| Processing location | Countries where data is processed and stored |
| Trains on our data | Yes or no, with a quote from the terms and the date you checked |
| Retention | How long prompts and outputs are kept, and whether you shortened it |
| Contract or DPA | Link to the terms you are relying on |
| Last reviewed | Date. Anything older than six months is not evidence of anything |
That last column does more work than it looks like. APP 8 asks whether you took reasonable steps. A dated register showing you checked, and kept checking, is the cleanest evidence you can produce.
SECTION 06Killing shadow AI without killing the enthusiasm
Shadow AI is unapproved tools used quietly for work. Banning your way out does not work, because the productivity gain is real and people will not give it up. Four things work.
SECTION 07Rolling it out so it sticks
SECTION 08Five ways these policies fail
SECTION 09Common questions
Is an AI use policy legally required in Australia?
No specific law mandates one. APP 1 requires practices and procedures that ensure compliance with the Privacy Act, and for a business using AI on personal information a written policy is the most obvious way to demonstrate that. It is also increasingly a procurement requirement from larger clients and government buyers.
Should we just ban AI instead?
Bans are unenforceable in practice and cost you the productivity your competitors are getting. They also make the problem invisible rather than absent, because the tools are free and on everyone's phone. Direct the use instead.
What if we are only two or three people?
Then it is a one page document and takes an afternoon. You still need it, because client contracts and insurance renewals now ask, and a small team is where an unlisted tool does the most damage relative to size.
Do contractors have to follow it?
Yes, and say so explicitly. Reference the policy in your contractor agreements and give them the register. A subcontractor pasting client data into a free chatbot is your breach, not theirs.
How often should we review it?
Every six months, and immediately when a vendor changes its terms or you add a tool. Model availability, plan tiers and data terms move faster than any other part of your compliance posture.
REFERENCESSources
[1] Privacy Act 1988 (Cth), Australian Privacy Principles 1, 6, 8, 10 and 11.
[2] OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024.
[3] Department of Industry, Science and Resources, Voluntary AI Safety Standard, September 2024.
[4] Privacy and Other Legislation Amendment Act 2024 (Cth), automated decision-making transparency from 10 December 2026.
[5] Privacy Act 1988 (Cth), Part IIIC, Notifiable Data Breaches scheme, 30 day assessment period.
Want this set up properly, not just written?
We find every AI tool running in your business, build the register, tighten the app consents at your identity provider, and hand you a policy your team will actually follow. Usually a week, start to finish.