Free AI policy template for Australian businesses: a plain-English Word document covering Privacy Act duties, approved tools, data rules and the AI6 practices.
An AI policy template gives your team written rules for which AI tools they can use, what data can go into them, and who answers for the output. For an Australian business, the policy should also reflect the Privacy Act, including the new automated decision-making disclosure that starts on 10 December 2026. Our free template is a Word document you can adapt in an afternoon.
TL;DR: Your staff are already using AI, so the real choice is between an unwritten policy and a written one. A workable AI policy runs to about five pages and covers approved tools, data that must never be entered, human review, incidents and a review date. Download the free Word template below and tailor it, or have us tailor it with you.
Why a small business needs an AI policy
The strongest argument is not regulation. It is that the policy already exists in every business, in the form of whatever each employee has decided on their own. One person pastes a client email into a free chatbot. Another connects a note-taking app to a meeting with a customer. Nobody wrote any of it down, so nobody can check it. We cover the mechanics in our piece on shadow AI and the business risk you can’t see.
Regulation adds a second reason. The Office of the Australian Information Commissioner published guidance on privacy and commercially available AI products in October 2024. It recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. It also says that when an AI tool generates or infers personal information, that is a collection under APP 3, and that the APP 10 accuracy duty applies to personal information you collect, use or disclose with AI. Staff will not read OAIC guidance. They will read a policy they have to sign.
Then there is the date. From 10 December 2026, new APPs 1.7 to 1.9 apply. If an APP entity has arranged for a computer program to make a decision, or to do something substantially and directly related to making it, and the decision could reasonably be expected to significantly affect someone’s rights or interests, its privacy policy must describe the kinds of personal information the program uses and the kinds of decisions involved. The OAIC published a fact sheet, a flowchart and updated APP 1 guidelines on 30 September 2026. The catch, as Allens noted of the OAIC’s consultation paper, is that a human in the loop does not automatically take you outside the rule: a scoring tool that a manager relies on can still count.
A caveat: the Privacy Act generally does not cover businesses with annual turnover of $3 million or less, with exceptions that include health service providers, businesses that trade in personal information, and Commonwealth contractors. If you are exempt, the ADM disclosure duty does not bind you. Your clients’ contracts and your reputation still do, and we would still write the policy.
For the wider picture, see our AI regulation in Australia overview and the AI compliance checklist for SMBs.
What goes in an AI acceptable use policy
The National AI Centre released its Guidance for AI Adoption in October 2025, built around six essential practices (the “AI6”): decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It updates the 2024 Voluntary AI Safety Standard and, like that standard, is voluntary best practice rather than regulation. We mapped each section of our template to these practices, which gives you a ready answer when a client or insurer asks how your responsible use of AI policy lines up with national guidance.
| Section | What it covers | Why it matters |
|---|---|---|
| Purpose and scope | Who the policy covers, including contractors, and which tools | Stops “it’s only a trial” and “that’s a personal app” as excuses |
| Definitions | AI tool, approved tool, personal, sensitive and confidential information | Everyone reads the rules the same way |
| Approved tools register | Named tools, who owns each, what data each may touch | The single most useful page in the document |
| Data classification | What may never be entered, and what needs an approved tool | Puts the OAIC’s warning about public tools into staff language |
| Permitted and prohibited uses | Drafting, summarising and research versus decisions about people | Draws the line where harm actually happens |
| Human review and accountability | A named person signs off external output | Covers AI6 practices 1 and 6 |
| Transparency to customers | When you say AI was used | Protects trust; covers AI6 practice 4 |
| Automated decision-making | A list of automated decisions, feeding the privacy policy from 10 December 2026 | You cannot disclose what you have not listed |
| IP and copyright | Ownership of output, third-party material | Avoids publishing something you cannot defend |
| Security | Company accounts, single sign-on, no personal accounts for business data | Closes the most common leak |
| Incidents | What to report and how fast | You cannot fix what you never hear about |
| Training, vendor assessment, review | Onboarding, due diligence, six-monthly review | Keeps the policy alive past week one |

In our view the register and the data rules carry most of the value. A policy with fifteen tidy sections and no list of approved tools will be ignored. A short one with a clear “these tools, these data types, never these” page gets used. The vendor side of that register is worth doing properly, and our checklist of what to ask an AI vendor before you sign shows how.
Key clauses in plain English
A few clauses do most of the work. These are the ones we would fight to keep when someone asks to trim the document.
Never enter: tax file numbers, health information, customer or staff personal details, credit card numbers and passwords, unless the policy owner has approved that specific tool for that data in writing. Client confidential material goes only into tools the register lists for it.
Personal accounts: company data goes into company-managed accounts only. A free personal login to a chatbot is not an approved tool, however good the chatbot.
A human answers for it: you own everything you send out under your name, whether or not AI drafted it. “The AI wrote it” is not a defence with a client.
No unreviewed decisions about people: AI can help prepare a hiring shortlist or a credit assessment. It does not make the decision, and you tell the policy owner before you use it that way, because that use may belong in your privacy policy.
Tell us when it goes wrong: pasted the wrong thing into the wrong tool? Report it the same day. The template promises no blame for prompt reporting, because the alternative is silence.
Download the free AI policy template
It is a Word document, so you can edit it, add your logo and send it to your lawyer as is. Enter your details below and we will email it to you.
Rolling it out so it sticks
Publishing the policy is the easy part. Three things decide whether it changes behaviour.
First, run a 30-minute session with the whole team. Walk through the data rules using real examples from your own work, such as a client brief, a payroll spreadsheet and a meeting transcript. People remember cases better than clauses. Our note on building AI literacy in business teams goes further.
Second, build the approved-tools register before you announce anything. If nobody has sanctioned a chatbot, staff will use a personal one. Ask the team what they already use, approve the tools that pass your checks, and offer a safe alternative for the rest.
Third, set a review date. AI products change their terms and features often, and the OAIC only published its ADM guidance on 30 September 2026. We recommend a review every six months, plus an immediate review whenever you add a tool or a regulator publishes something new. If you are unsure where you stand first, start with the AI readiness assessment.
Tailoring the policy to your business
An AI policy template is a starting point. It cannot know which of your workflows touch customer data, which tools your finance team already pays for, or whether you make decisions that trigger the new disclosure. That is where most policies stall.
Our AI Quick-Win Audit is a fixed $2,950 (AUD) paid audit. It maps a workflow, identifies automation opportunities and shows a live working demonstration, and the fee is credited toward any build of $10,000 or more commissioned within 3 months. It starts with a free 30-minute fit call. For a broader governance piece, including the register, vendor reviews and training, our Strategy & Advisory service covers it. Our founder, Neville Gotla, has spent more than 20 years leading technology and transformation programs for organisations including NSW Government, Telstra and Woolworths. His view is that the rules that stick are the short ones people helped write.
Frequently Asked Questions
Do small businesses in Australia need an AI policy?
There is no law that says every business must have a written AI policy. Practically, any business where staff use AI tools with client or employee information should have one, because that is where the privacy and confidentiality risk sits. The Privacy Act may not cover a business with turnover of $3 million or less, but client contracts often impose confidentiality duties regardless.
What should an AI acceptable use policy include?
At minimum: scope, an approved tools register, data that must never be entered, permitted and prohibited uses, human review, incident reporting, training and a review date. If you make decisions about individuals using automated tools, add a disclosure clause for your privacy policy.
What is the automated decision-making requirement starting on 10 December 2026?
From that date, an APP entity that has arranged for a computer program to make, or substantially and directly help make, decisions that could significantly affect an individual’s rights or interests must describe in its privacy policy the kinds of personal information used and the kinds of decisions involved. The OAIC released a fact sheet, flowchart and updated APP 1 guidelines on 30 September 2026. Read them before you finalise your wording.
Is the AI6 guidance mandatory?
No. The National AI Centre’s Guidance for AI Adoption is voluntary. Your existing legal duties, including privacy, consumer and employment law, still apply to anything you do with AI. Mapping your policy to the six practices simply makes your approach easy to explain to clients, insurers and auditors.
Is the template legal advice?
No. It is general information for Australian small and medium businesses. Have a lawyer review the final version, particularly if you handle health information, work under government contracts or make automated decisions about people. An AI policy template only works once someone adapts it, signs it and reviews it every six months. Download the free Word document above, fill in your register first, and contact us if you want a second pair of eyes.