Short answer: an AI use policy tells your staff which AI tools they can use, what information must never go into them, when a person has to check the output, and who to call when something goes wrong. The free template (Word document) linked above gives Australian mid-market businesses all of that, ready to adapt.
The most common gap I see in mid-market companies isn’t a lack of AI. It’s that staff are already using it, often on personal accounts, with no rules about company or client data. A policy fixes that quickly, and it’s the first thing I put in place as a fractional Chief AI Officer.
I wrote this template for Australian businesses of roughly 50 to 500 people. It’s long enough to cover what matters and short enough that people will read it.
This is general information, not legal advice. Adapt the template with your own legal, privacy and security advisers before you adopt it.
Why have an AI use policy at all
For most businesses there’s no AI-specific law that requires one. The National AI Centre’s Guidance for AI Adoption, published in October 2025, is voluntary. It condenses the 10 guardrails of the Voluntary AI Safety Standard into six essential practices, starting with deciding who is accountable. And the National AI Plan, released in December 2025, says the government will build on existing legal and regulatory frameworks rather than start from scratch.
That last point matters. The Privacy Act, consumer law, anti-discrimination law and work health and safety law already apply to how you use AI. A policy is how you turn those obligations into rules your staff can follow on a busy Tuesday.
There’s also a firm date coming. From 10 December 2026, under APP 1.7 to 1.9, organisations covered by the Privacy Act must explain in their privacy policy when they use computer programs, using personal information, to make or substantially inform decisions that could significantly affect people’s rights or interests. The OAIC published guidance on this on 30 September 2026, and its updated APP guidelines say generative AI tools and chatbots can fall within “computer program”. You can’t write that part of your privacy policy if you don’t know where AI is being used.
What’s in the template
The template has 17 short sections and a sign-off block. Replace anything in [square brackets] with your own details. These are the parts that do most of the work.
Roles. One accountable executive owns AI use, usually the CEO or COO. One AI owner runs the policy day to day. Each AI system has its own owner, and the board receives a regular report. If nobody senior has time for this, that’s the first problem to solve.
Approved tools. Staff can only use tools on an approved list, through company accounts. New tools, and new uses of existing ones, go through a simple request. There are three approval levels: low risk, which the AI owner can approve; medium risk, which needs privacy and security checks; and high risk, such as anything involving decisions about people, which needs the accountable executive’s sign-off. AI features that appear inside software you already pay for count as new tools.
A traffic-light guide to data. This is the section staff will use most:
- Green: public or non-sensitive information. OK in any approved tool.
- Amber: internal, confidential or limited personal information. Approved company tools only, for an approved purpose, and only where client contracts allow it.
- Red: sensitive information, tax file numbers, financial details, passwords and API keys, privileged advice, and client data where the contract prohibits it. Never, without written approval.
Human review. You’re responsible for anything you produce with AI, just as if you’d written it yourself. The level of checking matches the stakes, and AI never makes a final decision that significantly affects a person without someone reviewing it.
Transparency. Chatbots are labelled as AI. Customers are told when AI makes or substantially informs a decision about them, and anyone affected can reach a person.
Privacy. The template follows the OAIC’s guidance on using commercially available AI products, including its best-practice recommendation not to put personal information, and particularly sensitive information, into publicly available generative AI tools. It also covers the 10 December 2026 obligation, using the AI register to keep the privacy policy up to date.
Security, intellectual property and fair treatment. No unapproved AI plug-ins or agents connected to company systems, care with AI-generated code, checks before publishing AI output commercially, and testing for unfair outcomes before AI is used in decisions about people.
The AI register. A simple record of every approved tool and use: what it does, who owns it, what data it touches and how a person can override it. A spreadsheet is fine.
Incidents, training, breaches and review. A clear way to report mistakes, with no penalty for an honest one reported promptly. Training within 30 days. An annual review, or sooner if something significant changes.
The template is designed to sit alongside the National AI Centre’s guidance and its free AI policy and AI register templates, and alongside your existing privacy and security policies. It doesn’t replace them.
How to roll it out in 30 days
A policy only works if people know it exists. This is the rollout I’d suggest for a mid-market company.
Week 1: find out what’s happening. Name the accountable executive and the AI owner. Run a short, no-blame survey asking staff which AI tools they use and what for. Check which of your existing software platforms have switched on AI features. You’ll almost always find more than you expected.
Week 2: decide the rules. Pick the one or two tools you’ll approve, ideally business versions with training on your data switched off. Fill in the template, starting with the approved tools list and the traffic-light table. Check client contracts for restrictions on AI. Ask your privacy officer to look at sections 5 and 8.
Week 3: approve and set up. Have the accountable executive approve the policy and take it to the board or audit and risk committee. Start the AI register with what you found in week 1. Set up company accounts, and plan how you’ll move people off personal ones.
Week 4: launch and train. Run a short session for all staff, with real examples from your business, and ask everyone to sign the acknowledgement. Give managers a one-page summary. Then put the first review in the diary for three months’ time, and check your privacy policy against the 10 December 2026 obligation.
Don’t wait for perfect. A clear, short policy in place this month beats a comprehensive one in six months, while staff carry on without rules.
Where this fits
An AI use policy is one of four basics I suggest every mid-market company starts with, alongside a named owner, an AI register and a risk check before anything new goes live. My AI governance checklist for Australian boards covers the rest, in the form of questions the board should be asking.
The policy should also support delivery, not slow it down. When I moved a global brand’s translation onto an AI-first platform across 14 languages, saving around US$1M a year, the key control was simple: people reviewed and refined the AI’s work rather than translating from scratch. Clear rules about what goes in and who checks what comes out are what let you move faster. That matters even more once AI starts taking actions rather than just drafting, which I cover in agentic AI workflows for the mid-market.
To see where you stand across governance and the other four areas of AI readiness, take my free AI Readiness Scorecard. It takes about five minutes. If you’d like help adapting the policy and getting AI into production safely, I work with mid-market leadership teams as a fractional Chief AI Officer, or you can get in touch to talk it through.
Common questions
Do Australian businesses legally need an AI use policy?
There is no general law that requires one, and the National AI Centre's Guidance for AI Adoption is voluntary. But the Privacy Act, consumer law, anti-discrimination law and work health and safety law all apply to how you use AI, and a short policy is the simplest way to show staff how to stay within them.
Can staff use ChatGPT or other free AI tools at work?
That's your call, but set the rules first. The OAIC recommends, as best practice, that organisations don't put personal information, and particularly sensitive information, into publicly available generative AI tools. Most mid-market companies approve a business version of one or two tools and restrict free accounts to public information.
How long should an AI use policy be?
Long enough to cover the essentials and short enough that people read it. For a company of 50 to 500 people, a few pages plus an approved tools list and an AI register is usually enough. You can add detail as your use of AI grows.
How is this template different from the National AI Centre's AI policy template?
The National AI Centre's free template is a good general starting point for any organisation. Mine is narrower and more prescriptive, written for Australian mid-market businesses, with a traffic-light data guide, three approval levels and a section on the new automated decision transparency obligation already filled in. You can use either, or both.




