Free resource for internal AI governance
Free AI policy template for Australian businesses
An editable acceptable use policy for Australian organisations. It covers approved tools, data handling, human oversight, security and review, without turning a small business policy into a legal manual.
- File
- Editable Word documentBrowser download
- Contents
- Eleven policy sectionsPrepared structure
- Adaptation
- Designed for an afternoonReplace the prompts
- No mailing listPrivacy terms stay visible
Get the resource
Start with the policy already structured
AI policy template
An editable starting point for real staff use
The template gives small and midsized organisations a clear starting point for approved tools, acceptable use, data handling, review and accountability.
The download starts in your browser. We also try to email a copy, but do not add you to a mailing list. Submitted details are handled under our privacy policy.
- Word document
- Eleven editable sections
- Australian context
- Plain language prompts
Inside the document
Eleven sections with a job to do
Foundation
Purpose and reach
- Purpose
- Why the policy exists and the behaviour it is meant to support.
- Scope
- Who and what the policy applies to across the organisation.
Rules
Permission and limits
- Approved tools
- Which tools may be used for work and under what account type.
- Acceptable use
- The work staff may complete with approved AI tools.
- Prohibited use
- The uses and information categories that remain off limits.
Safeguards
Data and decisions
- Data and privacy
- Rules for personal, client, confidential and sensitive information.
- Accuracy and oversight
- Where a person must check output before it is used.
- Transparency and disclosure
- When AI use should be made clear to affected people.
- Security
- Account, access and incident handling expectations.
Operations
Keeping it current
- Training
- How staff learn the rules and ask for help.
- Review cycle
- Who owns the policy and when it is reviewed.
Adapt the policy
Five decisions before it goes to staff
- Tools
List your approved tools
Decide which AI tools are approved for work, and for which kinds of data.
- Use
Set acceptable and prohibited use
Spell out what staff may do with AI and what is off limits.
- Data
Add data and privacy rules
State what can and cannot be entered into AI tools, including the privacy obligations that apply to the organisation.
- Review
Require oversight and disclosure
A person reviews AI output in decisions; disclose AI use where it affects individuals.
- Ownership
Assign an owner and review cycle
Name who owns the policy and review it at least yearly.
Australian context
Useful governance, with the legal boundary left visible
The National AI Centre's Guidance for AI Adoption is the current Australian Government starting point for organisations adopting AI. Published in October 2025, it simplified and replaced the earlier Voluntary AI Safety Standard. The guidance is voluntary, but its practices around accountability, risk, people, transparency and safe operation are useful inputs to an internal policy.
The Privacy Act does not cover every small business. OAIC guidance explains the small business exemptions and exceptions. Where the Privacy Act applies to your organisation, its obligations can apply to personal information handled through AI tools. From 10 December 2026, APP entities also have defined privacy policy obligations for certain automated decisions. That public disclosure is separate from this internal policy. Our ADM disclosure template explains the distinction.
Make it operational
A policy works when the team can follow it
FAQ
Frequently asked questions
Yes, it is free. Enter your name and email to start the download. It is provided by VibeZero as a starting point, not legal advice, so have it reviewed against your obligations before relying on it.
Make the policy operational