The Australian Small Business AI Acceptable-Use Policy: A Practical Template
Jack Amin
Digital Marketing & AI Specialist

Quick Answer
An AI acceptable-use policy should name approved tools, classify information that may or may not be entered, define tasks requiring human review, prohibit deceptive or unlawful uses, assign record-keeping and incident responsibilities, and explain how exceptions are approved. Tailor the policy to your systems and risk profile. This practical template is operational guidance, not legal advice.
Why a One-Page Rulebook Beats an Unwritten Ban
Employees are already using AI to draft, analyse, summarise, code and research. A policy that simply says “do not use AI” often pushes the activity out of sight. A policy that says “use AI responsibly” gives nobody enough direction.
A useful acceptable-use policy answers five questions at the moment of work:
- Which tools may I use?
- What information may I enter?
- Which tasks need approval?
- What must a human verify?
- What do I do if something goes wrong?
The Australian Government's guidance for AI adoption recommends establishing governance foundations and implementation practices appropriate to the organisation. The OAIC emphasises privacy due diligence and cautions against entering personal information into publicly available generative AI tools without appropriate assessment.
The template below is a practical starting point, not legal advice.
AI Acceptable-Use Policy Template
1. Purpose
This policy enables responsible use of artificial intelligence while protecting customers, employees, confidential information, intellectual property and the reputation of [Organisation].
It applies to employees, contractors and other people using AI systems for organisation work, whether through organisation-provided or personal devices and accounts.
2. Approved tools
Only tools listed in the Approved AI Register may be used for organisation work. Approval applies to the named product, plan and configuration—not automatically to every service from the same vendor.
The register records the owner, permitted uses, prohibited data, authentication requirements, contractual status, retention settings and review date.
New tools require approval from [role] before business information is entered.
3. Information classification
Green—permitted: public information, approved marketing copy, generic examples and de-identified material that cannot reasonably be re-identified.
Amber—approval required: internal operational information, unpublished commercial plans, customer context without direct identifiers, source code, research data and draft contracts.
Red—prohibited unless a specifically approved system and workflow exist: passwords, API keys, authentication tokens, sensitive personal information, health or financial information, identifiable customer records, employee relations material, privileged legal advice, confidential partner data and regulated information.
Removing a name may not make information anonymous. Context, job title, location or account details can still identify a person.
4. Permitted uses
Within approved tools and data rules, staff may use AI to:
- brainstorm and outline
- improve grammar or structure
- summarise approved non-sensitive material
- generate first drafts
- assist with code or formulas in a controlled environment
- classify or transform approved datasets
- support research that is independently checked
AI output is a draft or decision-support input unless an approved automated workflow states otherwise.
5. Prohibited uses
Staff must not use AI to:
- make final hiring, disciplinary, credit, health, legal or similarly consequential decisions without an approved governance process
- impersonate a real person or fabricate a testimonial
- create deceptive evidence, reviews or endorsements
- bypass security, privacy, copyright or contractual controls
- upload information they are not authorised to share
- publish factual claims without verification
- conceal a material error or incident
- use unapproved browser extensions or personal accounts for organisation data
6. Human review
The person using AI remains responsible for the result. Before external use, they must check factual accuracy, calculations, sources, bias, tone, confidentiality, intellectual-property risk and compliance with the original brief.
High-risk outputs require approval from [role]. Examples include public claims, customer advice, contracts, employment material, financial analysis, production code and realistic generated depictions of people or products.
7. Transparency
Disclose AI assistance where a customer, colleague or regulator would reasonably expect to know how the output was created, or where an organisation, platform or contractual rule requires it.
Do not describe an output as independently expert-reviewed unless that review occurred.
8. Records
For material work, retain the tool, date, purpose, source material, relevant prompt or instructions, reviewer, approval and final output according to the records schedule.
Do not copy prohibited information into the record merely to document the incident.
9. Incidents
Immediately stop and report suspected disclosure of protected information, harmful output, security weakness, rights issue or material factual error to [contact].
Preserve relevant evidence and do not attempt to hide, delete or independently remediate an incident unless directed.
10. Ownership and review
[Role] owns this policy. It is reviewed every six months and after any material tool change, incident, legal development or process change. Exceptions must be documented and approved before use.
Turn the Template into a Working System
A policy without implementation becomes shelfware. Add four supporting controls.
Approved AI Register: one row per product and configuration, with allowed tasks and data.
Task risk assessment: a short decision tree based on data sensitivity, audience, impact and autonomy.
Review checklist: factual, privacy, rights, security, bias and brand checks appropriate to the task.
Incident route: one contact and a simple reporting form that staff can find quickly.
Train with realistic examples from the business. Show what a safe marketing prompt looks like, how to de-identify a document and when to stop.
A 30-Day Implementation
Week 1: inventory tools already in use and identify sensitive workflows.
Week 2: approve a small toolset, configure accounts and customise the policy.
Week 3: train staff with role-specific examples and require acknowledgement.
Week 4: audit a sample of real use, correct unclear rules and schedule the next review.
The goal is not perfect prediction. It is visible responsibility: people know what is allowed, important outputs have an owner and incidents reach the right person quickly.
Official Sources
Frequently Asked Questions
Let's discuss your project
Need this template adapted into a workable AI governance system for your team?


