Free AI policy template for Australian businesses: a plain-English Word document covering Privacy Act duties, approved tools, data rules and the AI6 practices.

An AI policy template gives your team written rules for which AI tools they can use, what data can go into them, and who answers for the output. For an Australian business, the policy should also reflect the Privacy Act, including the new automated decision-making disclosure that starts on 10 December 2026. Our free template is a Word document you can adapt in an afternoon.

TL;DR: Your staff are already using AI, so the real choice is between an unwritten policy and a written one. A workable AI policy runs to about five pages and covers approved tools, data that must never be entered, human review, incidents and a review date. Download the free Word template below and tailor it, or have us tailor it with you.

Why a small business needs an AI policy

The strongest argument is not regulation. It is that the policy already exists in every business, in the form of whatever each employee has decided on their own. One person pastes a client email into a free chatbot. Another connects a note-taking app to a meeting with a customer. Nobody wrote any of it down, so nobody can check it. We cover the mechanics in our piece on shadow AI and the business risk you can’t see.

Regulation adds a second reason. The Office of the Australian Information Commissioner published guidance on privacy and commercially available AI products in October 2024. It recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. It also says that when an AI tool generates or infers personal information, that is a collection under APP 3, and that the APP 10 accuracy duty applies to personal information you collect, use or disclose with AI. Staff will not read OAIC guidance. They will read a policy they have to sign.

Then there is the date. From 10 December 2026, new APPs 1.7 to 1.9 apply. If an APP entity has arranged for a computer program to make a decision, or to do something substantially and directly related to making it, and the decision could reasonably be expected to significantly affect someone’s rights or interests, its privacy policy must describe the kinds of personal information the program uses and the kinds of decisions involved. The OAIC published a fact sheet, a flowchart and updated APP 1 guidelines on 30 September 2026. The catch, as Allens noted of the OAIC’s consultation paper, is that a human in the loop does not automatically take you outside the rule: a scoring tool that a manager relies on can still count.

A caveat: the Privacy Act generally does not cover businesses with annual turnover of $3 million or less, with exceptions that include health service providers, businesses that trade in personal information, and Commonwealth contractors. If you are exempt, the ADM disclosure duty does not bind you. Your clients’ contracts and your reputation still do, and we would still write the policy.

For the wider picture, see our AI regulation in Australia overview and the AI compliance checklist for SMBs.

What goes in an AI acceptable use policy

The National AI Centre released its Guidance for AI Adoption in October 2025, built around six essential practices (the “AI6”): decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It updates the 2024 Voluntary AI Safety Standard and, like that standard, is voluntary best practice rather than regulation. We mapped each section of our template to these practices, which gives you a ready answer when a client or insurer asks how your responsible use of AI policy lines up with national guidance.

SectionWhat it coversWhy it matters
Purpose and scopeWho the policy covers, including contractors, and which toolsStops “it’s only a trial” and “that’s a personal app” as excuses
DefinitionsAI tool, approved tool, personal, sensitive and confidential informationEveryone reads the rules the same way
Approved tools registerNamed tools, who owns each, what data each may touchThe single most useful page in the document
Data classificationWhat may never be entered, and what needs an approved toolPuts the OAIC’s warning about public tools into staff language
Permitted and prohibited usesDrafting, summarising and research versus decisions about peopleDraws the line where harm actually happens
Human review and accountabilityA named person signs off external outputCovers AI6 practices 1 and 6
Transparency to customersWhen you say AI was usedProtects trust; covers AI6 practice 4
Automated decision-makingA list of automated decisions, feeding the privacy policy from 10 December 2026You cannot disclose what you have not listed
IP and copyrightOwnership of output, third-party materialAvoids publishing something you cannot defend
SecurityCompany accounts, single sign-on, no personal accounts for business dataCloses the most common leak
IncidentsWhat to report and how fastYou cannot fix what you never hear about
Training, vendor assessment, reviewOnboarding, due diligence, six-monthly reviewKeeps the policy alive past week one
Printed approved AI tools register pinned beside an office monitor, from an AI policy template

In our view the register and the data rules carry most of the value. A policy with fifteen tidy sections and no list of approved tools will be ignored. A short one with a clear “these tools, these data types, never these” page gets used. The vendor side of that register is worth doing properly, and our checklist of what to ask an AI vendor before you sign shows how.

Key clauses in plain English

A few clauses do most of the work. These are the ones we would fight to keep when someone asks to trim the document.

Never enter: tax file numbers, health information, customer or staff personal details, credit card numbers and passwords, unless the policy owner has approved that specific tool for that data in writing. Client confidential material goes only into tools the register lists for it.

Personal accounts: company data goes into company-managed accounts only. A free personal login to a chatbot is not an approved tool, however good the chatbot.

A human answers for it: you own everything you send out under your name, whether or not AI drafted it. “The AI wrote it” is not a defence with a client.

No unreviewed decisions about people: AI can help prepare a hiring shortlist or a credit assessment. It does not make the decision, and you tell the policy owner before you use it that way, because that use may belong in your privacy policy.

Tell us when it goes wrong: pasted the wrong thing into the wrong tool? Report it the same day. The template promises no blame for prompt reporting, because the alternative is silence.

Download the free AI policy template

It is a Word document, so you can edit it, add your logo and send it to your lawyer as is. Enter your details below and we will email it to you.




    Rolling it out so it sticks

    Publishing the policy is the easy part. Three things decide whether it changes behaviour.

    First, run a 30-minute session with the whole team. Walk through the data rules using real examples from your own work, such as a client brief, a payroll spreadsheet and a meeting transcript. People remember cases better than clauses. Our note on building AI literacy in business teams goes further.

    Second, build the approved-tools register before you announce anything. If nobody has sanctioned a chatbot, staff will use a personal one. Ask the team what they already use, approve the tools that pass your checks, and offer a safe alternative for the rest.

    Third, set a review date. AI products change their terms and features often, and the OAIC only published its ADM guidance on 30 September 2026. We recommend a review every six months, plus an immediate review whenever you add a tool or a regulator publishes something new. If you are unsure where you stand first, start with the AI readiness assessment.

    Tailoring the policy to your business

    An AI policy template is a starting point. It cannot know which of your workflows touch customer data, which tools your finance team already pays for, or whether you make decisions that trigger the new disclosure. That is where most policies stall.

    Our AI Quick-Win Audit is a fixed $2,950 (AUD) paid audit. It maps a workflow, identifies automation opportunities and shows a live working demonstration, and the fee is credited toward any build of $10,000 or more commissioned within 3 months. It starts with a free 30-minute fit call. For a broader governance piece, including the register, vendor reviews and training, our Strategy & Advisory service covers it. Our founder, Neville Gotla, has spent more than 20 years leading technology and transformation programs for organisations including NSW Government, Telstra and Woolworths. His view is that the rules that stick are the short ones people helped write.

    Frequently Asked Questions

    Do small businesses in Australia need an AI policy?

    There is no law that says every business must have a written AI policy. Practically, any business where staff use AI tools with client or employee information should have one, because that is where the privacy and confidentiality risk sits. The Privacy Act may not cover a business with turnover of $3 million or less, but client contracts often impose confidentiality duties regardless.

    What should an AI acceptable use policy include?

    At minimum: scope, an approved tools register, data that must never be entered, permitted and prohibited uses, human review, incident reporting, training and a review date. If you make decisions about individuals using automated tools, add a disclosure clause for your privacy policy.

    What is the automated decision-making requirement starting on 10 December 2026?

    From that date, an APP entity that has arranged for a computer program to make, or substantially and directly help make, decisions that could significantly affect an individual’s rights or interests must describe in its privacy policy the kinds of personal information used and the kinds of decisions involved. The OAIC released a fact sheet, flowchart and updated APP 1 guidelines on 30 September 2026. Read them before you finalise your wording.

    Is the AI6 guidance mandatory?

    No. The National AI Centre’s Guidance for AI Adoption is voluntary. Your existing legal duties, including privacy, consumer and employment law, still apply to anything you do with AI. Mapping your policy to the six practices simply makes your approach easy to explain to clients, insurers and auditors.

    Is the template legal advice?

    No. It is general information for Australian small and medium businesses. Have a lawyer review the final version, particularly if you handle health information, work under government contracts or make automated decisions about people. An AI policy template only works once someone adapts it, signs it and reviews it every six months. Download the free Word document above, fill in your register first, and contact us if you want a second pair of eyes.