Handles client or personal data
Staff pasting client details, contracts or personal information into AI tools creates a Privacy Act exposure without anyone intending it. A policy sets the boundary in advance.
Free resource · internal AI policy
An editable acceptable use policy written for Australian organisations. It covers approved tools, data handling, human oversight and review, with reference to the Voluntary AI Safety Standard and the Privacy Act.
Why this matters
Staff have adopted AI tools faster than most businesses have written rules for them. A written AI policy is how a business closes that gap. It sets out which tools are approved, what data can go into them, and who is accountable when something goes wrong. Without one, AI use tends to happen ad hoc, tool by tool, person by person, with no one able to say what data has gone where.
Australia does not yet have AI-specific legislation for private businesses, but two developments make a written policy a practical necessity rather than a nice to have. The federal government's Voluntary AI Safety Standard sets out ten guardrails for organisations deploying AI, including accountability, human oversight, and transparency with people affected by AI assisted decisions. It is voluntary, but it is the closest thing Australia has to an official reference point for what responsible AI use looks like, and a written policy is a direct way to put several of its guardrails into practice.
The second is the Australian Privacy Act 1988. It does not mention AI tools specifically, but its obligations apply in full to any data staff type into an AI system. If that data includes personal information, the usual rules on collection, use, storage and disclosure still apply, regardless of which tool is handling it. A policy that spells out what can and cannot be entered into AI tools is one of the most direct ways a business demonstrates it is meeting those obligations. From 10 December 2026, businesses that use automated processes in decisions affecting individuals also face a separate disclosure obligation under the Privacy and Other Legislation Amendment Act 2024, which is a public facing requirement distinct from this internal policy.
Who it is for
Any business where staff use AI tools in their work benefits from a written policy. That now covers most small and midsized Australian businesses. It is especially relevant if your organisation:
Staff pasting client details, contracts or personal information into AI tools creates a Privacy Act exposure without anyone intending it. A policy sets the boundary in advance.
If people are using ChatGPT, Copilot or similar tools without guidance, a policy turns ad hoc use into something the business can account for.
New starters need a clear answer on day one about which tools are approved and what the rules are, rather than picking it up informally from colleagues.
Procurement processes and larger clients increasingly ask suppliers to demonstrate basic AI governance. A policy is the first artefact most of them expect to see.
How to use it
The template is structured so you can adapt it in an afternoon. Work through these five steps, replacing anything in square brackets with your own details.
Step 01
Decide which AI tools are approved for work, and for which kinds of data.
Step 02
Spell out what staff may do with AI and what is off limits.
Step 03
State what can and cannot be entered into AI tools, in line with the Privacy Act.
Step 04
A person reviews AI output in decisions; disclose AI use where it affects individuals.
Step 05
Name who owns the policy and review it at least yearly.
What's inside
AI policy template
A complete AI acceptable use policy you can adapt in an afternoon. It covers every section a small or midsized Australian business needs:
Put it into practice
A document on its own does not change behaviour. The businesses that get AI right pair the policy with a quick look at how staff actually use AI today, and training so the rules make sense in practice.
FAQ
Make the policy operational