Skip to content

Free resource for internal AI governance

Free AI policy template for Australian businesses

An editable acceptable use policy for Australian organisations. It covers approved tools, data handling, human oversight, security and review, without turning a small business policy into a legal manual.

Reviewed September 2026. Name and work email are required for the browser download. You are not added to a mailing list. General information only, not legal advice.
File
Editable Word documentBrowser download
Contents
Eleven policy sectionsPrepared structure
Adaptation
Designed for an afternoonReplace the prompts
Email
No mailing listPrivacy terms stay visible

Get the resource

Start with the policy already structured

The useful work is deciding your boundaries. The document should not be the hard part.

AI policy template

An editable starting point for real staff use

The template gives small and midsized organisations a clear starting point for approved tools, acceptable use, data handling, review and accountability.

The download starts in your browser. We also try to email a copy, but do not add you to a mailing list. Submitted details are handled under our privacy policy.

  • Word document
  • Eleven editable sections
  • Australian context
  • Plain language prompts
Name and work email required. Have the policy reviewed against your obligations before relying on it.

Get the Word template

Enter your details and the file starts downloading in this browser.

Download
Starts in your browser
Mailing list
You are not added

Free starting template. General information only, not legal advice.

Inside the document

Eleven sections with a job to do

The structure moves from permission to safeguards, then assigns the work needed to keep the policy current.

Foundation

Purpose and reach

Purpose
Why the policy exists and the behaviour it is meant to support.
Scope
Who and what the policy applies to across the organisation.

Rules

Permission and limits

Approved tools
Which tools may be used for work and under what account type.
Acceptable use
The work staff may complete with approved AI tools.
Prohibited use
The uses and information categories that remain off limits.

Safeguards

Data and decisions

Data and privacy
Rules for personal, client, confidential and sensitive information.
Accuracy and oversight
Where a person must check output before it is used.
Transparency and disclosure
When AI use should be made clear to affected people.
Security
Account, access and incident handling expectations.

Operations

Keeping it current

Training
How staff learn the rules and ask for help.
Review cycle
Who owns the policy and when it is reviewed.

Adapt the policy

Five decisions before it goes to staff

Work through the prompts with the people responsible for operations, privacy and technology. Keep the answers specific enough to use.
  1. Tools

    List your approved tools

    Decide which AI tools are approved for work, and for which kinds of data.

  2. Use

    Set acceptable and prohibited use

    Spell out what staff may do with AI and what is off limits.

  3. Data

    Add data and privacy rules

    State what can and cannot be entered into AI tools, including the privacy obligations that apply to the organisation.

  4. Review

    Require oversight and disclosure

    A person reviews AI output in decisions; disclose AI use where it affects individuals.

  5. Ownership

    Assign an owner and review cycle

    Name who owns the policy and review it at least yearly.

Australian context

Useful governance, with the legal boundary left visible

An internal policy can make responsible AI use easier to manage. It does not replace advice about the laws, contracts or sector rules that apply to your organisation.

The National AI Centre's Guidance for AI Adoption is the current Australian Government starting point for organisations adopting AI. Published in October 2025, it simplified and replaced the earlier Voluntary AI Safety Standard. The guidance is voluntary, but its practices around accountability, risk, people, transparency and safe operation are useful inputs to an internal policy.

The Privacy Act does not cover every small business. OAIC guidance explains the small business exemptions and exceptions. Where the Privacy Act applies to your organisation, its obligations can apply to personal information handled through AI tools. From 10 December 2026, APP entities also have defined privacy policy obligations for certain automated decisions. That public disclosure is separate from this internal policy. Our ADM disclosure template explains the distinction.

FAQ

Frequently asked questions

Yes, it is free. Enter your name and email to start the download. It is provided by VibeZero as a starting point, not legal advice, so have it reviewed against your obligations before relying on it.

Make the policy operational

The document sets the rules. Visibility and training make them stick

Pair the policy with a view of the tools staff already use and practical training on the data boundaries.
General information only, not legal advice