AI Governance · 10 min read

How to Write an AI Use Policy Your Team Will Actually Follow

Your staff are already using AI, and a good share of them have not told you. A two page policy plus a tool register fixes that without killing the productivity. Here is the template, the register, and how to roll it out so it sticks.

Published 19 Aug 2026
By Automatrix
Topic AI Policy · Governance · Templates
Applies to Australian businesses
0 Pages, maximum, if you want it read
0 Data tiers that drive every rule
0 Clauses every AI policy needs
0 Day breach assessment window you protect

SECTION 01Why you need one, in one paragraph

Your staff are already using AI. Surveys keep finding the same thing, and so do we on every audit: people bring their own tools, and a large share never tell anyone. Without a policy you are not preventing AI use, you are just not seeing it. That is the worst version, because you carry the privacy exposure without any of the productivity gain being organised or shared.

The policy that works

Two pages. Names the tools people may use, says what data may go into each, bans a short list of things outright, and requires a human on anything consequential. Anything longer gets skimmed and ignored, and an ignored policy protects nobody.

SECTION 02Do these three things before you write a word

Find out what is actually in use
Check third-party app consents in Microsoft Entra ID or the Google Workspace admin console, look through expense claims for AI subscriptions, and ask the team directly with an explicit amnesty. You want the truth more than you want to be cross about it. Anyone punished for admitting a tool will just hide the next one.
Classify your data into three tiers
Public, meaning material already published or that you would happily publish. Internal, meaning ordinary business information with no personal data in it. Restricted, meaning customer personal information, health, financial, legal, HR and anything under a client confidentiality clause. Every rule in your policy hangs off these three words, so agree them first.
Buy the tools you are about to mandate
A policy that says "do not use the free version" without funding the paid one is a policy that gets ignored by lunchtime. Business plans for the main AI tools cost a fraction of one compliance incident. Fund the sanctioned path before you close the unsanctioned one.

SECTION 03The eight clauses every AI policy needs

ClauseWhat it must sayWhy it is there
1. Approved toolsThe named list, with plan tier, and how to request an additionRemoves the excuse of not knowing, and gives people a route that is not going rogue
2. Data rulesWhich data tier may go into which toolThis is the clause that actually prevents privacy breaches
3. Prohibited usesA short, specific list of neverVague bans get argued with. Specific ones do not
4. Human reviewWho signs off what before it goes outMeets APP 10 accuracy obligations and stops hallucinations reaching customers
5. DisclosureWhen you tell customers, clients or candidates that AI was involvedAustralian Consumer Law, client contracts, and basic fairness
6. Attribution and IPThat raw AI output is a draft, and copyright needs human authorshipProtects your ownership claim and stops accidental infringement
7. ReportingWhat to do when something goes wrong, with no blame for reporting fastYou cannot meet a 30 day breach assessment window if nobody tells you for six weeks
8. ReviewA date and a named ownerVendor terms change constantly. An unreviewed policy is wrong within a year

SECTION 04The template

Copy this, replace the bracketed parts, delete what does not apply. It is deliberately short. Written for an Australian small to mid-sized business, and it assumes you have done the three steps in Section 02.

AI Use Policy, [Business Name]

Effective [date]. Owner: [name, role]. Next review: [date, 12 months out].

1. Purpose. We use AI to work faster and better. This policy sets out how to do that without putting customer information, client confidentiality or our own reputation at risk. It applies to every employee, contractor and subcontractor.

2. Data classification. All information falls into one of three tiers.
Public: already published, or content we would happily publish. Example: our own website copy, public pricing.
Internal: ordinary business information containing no personal data. Example: draft process documents, internal templates.
Restricted: customer or staff personal information, health information, financial records, legal advice, anything under a client confidentiality clause, credentials, and unreleased commercial information.

3. Approved tools. You may use the tools listed in the AI Tool Register at [location]. Each entry states the plan tier and the highest data tier permitted. Using a tool that is not listed, or a personal account of a listed tool, is not permitted. To request an addition, contact [owner] and allow [x] business days.

4. Data rules. Public and Internal information may be used with any approved tool. Restricted information may only be used with tools marked Restricted-approved in the register. Where the task does not need identifying details, remove them before you start. If you are unsure which tier applies, treat it as Restricted and ask.

5. Prohibited uses. Do not: enter Restricted information into any tool not marked Restricted-approved; use free or personal AI accounts for any work purpose; upload client credentials, API keys or passwords; record or transcribe a meeting without telling everyone present and giving them the chance to object; use AI to make a final decision about a person's employment, credit, housing, insurance or access to a service; generate content that impersonates a real person or organisation; publish AI output as fact without verifying it; or use AI in a way that breaches a client contract.

6. Human review. A person must review and approve any AI-assisted output before it goes to a customer, is published, is relied on for a decision, or is committed to a production system. The reviewer is accountable for the content, not the tool. Verify every fact, figure, quote, legal reference and calculation.

7. Disclosure. Tell people when AI is meaningfully involved in something that affects them: when an AI system interacts with them directly, when a meeting is being recorded or transcribed, and where a client contract requires it. Never claim work is purely human when it is not.

8. Intellectual property. Raw AI output is a draft. Copyright requires human authorship, so material generated without meaningful human input may not be protected. Apply real editing and judgement to anything we intend to own. Do not paste in third-party copyrighted material for the model to rework.

9. Reporting. If Restricted information has gone into the wrong tool, if an AI output containing an error has reached a customer, or if you suspect any incident, tell [owner] the same day. Reporting quickly is treated as doing the right thing. Delay is the only thing that gets anyone in trouble, because it costs us our assessment window under the Notifiable Data Breaches scheme.

10. Consequences. Breaches of this policy are handled under our normal disciplinary process. Deliberate misuse of customer information is treated as serious misconduct.

11. Review. [Owner] reviews this policy and the AI Tool Register every [quarter or six months], and whenever a listed vendor materially changes its terms.

SECTION 05The AI Tool Register

The policy is the rules. The register is the list that makes the rules usable, and it is the document a client or regulator will actually ask for. A spreadsheet is fine.

ColumnWhat goes in it
ToolProduct name
Plan tierFree, Pro, Team, Enterprise, API. The single most important column
OwnerWho inside the business is accountable for it
Used byTeam or role, so you know who to contact if it has to go
Max data tierPublic, Internal or Restricted
Processing locationCountries where data is processed and stored
Trains on our dataYes or no, with a quote from the terms and the date you checked
RetentionHow long prompts and outputs are kept, and whether you shortened it
Contract or DPALink to the terms you are relying on
Last reviewedDate. Anything older than six months is not evidence of anything

That last column does more work than it looks like. APP 8 asks whether you took reasonable steps. A dated register showing you checked, and kept checking, is the cleanest evidence you can produce.

SECTION 06Killing shadow AI without killing the enthusiasm

Shadow AI is unapproved tools used quietly for work. Banning your way out does not work, because the productivity gain is real and people will not give it up. Four things work.

Make the sanctioned path better
If the approved tool is slower or worse than what people found themselves, they will keep using theirs. Buy the good plan. It is cheaper than the incident.
Run an amnesty
Two weeks, no consequences, tell us everything you use. You will get a far more accurate picture than any audit tool produces, because the people know things the logs do not.
Make requests fast
If adding a tool takes three weeks of committee, people route around you. A 48 hour turnaround on requests kills more shadow AI than any policy clause.
Control it at identity
Restrict third-party app consent in Entra ID or Google Workspace so a single click cannot hand a new vendor access to a mailbox or calendar. This is the one technical control that pays for itself immediately.

SECTION 07Rolling it out so it sticks

One session, 30 minutes, real examples
Do not read the policy aloud. Walk through five things people actually do: summarising a customer email, drafting a quote, transcribing a meeting, cleaning a spreadsheet of client records, writing code. For each, say which tool and why. People remember examples and forget clauses.
Get a signature or an acknowledgement
An acknowledged policy is enforceable. An emailed PDF nobody opened is not. Include it in onboarding for new starters from day one.
Name one person to ask
Most breaches of a policy like this are people guessing rather than deciding to break a rule. A named person who answers within a day removes almost all of the guessing.
Review it on a date, not a feeling
Put the review in the calendar with an owner. Vendor terms, plan tiers and model availability all change, and the December 2026 automated decision-making disclosure requirement is coming whether the policy is current or not.

SECTION 08Five ways these policies fail

Check yours against these
It bans AI generally, so people either ignore it or lose the productivity entirely
It is twelve pages of legal drafting nobody in the business has read to the end
It names no tools, so every decision is a judgement call made by someone under time pressure
It mandates paid plans the business never actually bought
It was written once in 2024 and never reviewed, so half the tool names are wrong

SECTION 09Common questions

Is an AI use policy legally required in Australia?

No specific law mandates one. APP 1 requires practices and procedures that ensure compliance with the Privacy Act, and for a business using AI on personal information a written policy is the most obvious way to demonstrate that. It is also increasingly a procurement requirement from larger clients and government buyers.

Should we just ban AI instead?

Bans are unenforceable in practice and cost you the productivity your competitors are getting. They also make the problem invisible rather than absent, because the tools are free and on everyone's phone. Direct the use instead.

What if we are only two or three people?

Then it is a one page document and takes an afternoon. You still need it, because client contracts and insurance renewals now ask, and a small team is where an unlisted tool does the most damage relative to size.

Do contractors have to follow it?

Yes, and say so explicitly. Reference the policy in your contractor agreements and give them the register. A subcontractor pasting client data into a free chatbot is your breach, not theirs.

How often should we review it?

Every six months, and immediately when a vendor changes its terms or you add a tool. Model availability, plan tiers and data terms move faster than any other part of your compliance posture.

REFERENCESSources

[1] Privacy Act 1988 (Cth), Australian Privacy Principles 1, 6, 8, 10 and 11.
[2] OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024.
[3] Department of Industry, Science and Resources, Voluntary AI Safety Standard, September 2024.
[4] Privacy and Other Legislation Amendment Act 2024 (Cth), automated decision-making transparency from 10 December 2026.
[5] Privacy Act 1988 (Cth), Part IIIC, Notifiable Data Breaches scheme, 30 day assessment period.

Written by Automatrix

Want this set up properly, not just written?

We find every AI tool running in your business, build the register, tighten the app consents at your identity provider, and hand you a policy your team will actually follow. Usually a week, start to finish.

0% read