Practical AI and SaaS for Business

AI Acceptable Use Policy Template: Free Download for Small Business

If your team has started using AI tools at work and you're not sure what rules should apply, you're not alone. This free template gives small businesses a practical starting point for an AI acceptable use policy covering approved tools, prohibited data, and review requirements.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You're the operations lead who's been told to sort out an AI usage policy before your team's DIY experiments turn into a real problem. Right now nobody knows what's off-limits, and one wrong paste into a chatbot could leak client data or land you in a mess you didn't see coming. In five minutes you'll have a plain-English policy template you can hand to your team this week. No legal background required.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

If your team is using AI tools at work and there are no written rules about how, that is a risk your business is carrying right now. It does not need to be a complicated fix. A short, plain-language AI acceptable use policy is enough to set expectations, reduce liability, and make sure staff understand where AI is and is not appropriate in your business.

In short: An AI acceptable use policy tells your staff which AI tools they can use, what data they must not put into those tools, and what standards apply to AI-generated outputs before they go to a client or customer. This page explains what the policy needs to cover, and provides a free template you can adapt in under an hour.

Why a small business needs an AI use policy

Most small business owners did not set out to create an AI policy. They set out to save time, and one or two staff members started using ChatGPT or a similar tool to draft emails, summarise documents, or answer customer questions. That is a sensible use of the technology. The problem is that without any rules in place, staff make their own judgements about what is acceptable, and those judgements vary.

One person pastes a client's full name and address into an AI tool to speed up a letter. Another uses AI to generate advice they do not check before sending. A third downloads an AI browser extension that quietly sends snippets of your screen to an overseas server. None of these people are being reckless on purpose. They just have no policy to consult.

An AI acceptable use policy does not need to be long. It needs to answer three questions clearly: which tools are permitted, what information must not be shared with those tools, and what review is required before AI-generated content is used in your business.

What an AI acceptable use policy covers

A well-structured AI use policy for a small business typically covers six areas. You do not need to write an essay for each one, but every area should appear in the document so staff know where the lines are.

Approved tools. A list of AI tools the business has evaluated and permits for work use. This does not need to be exhaustive, but it signals that staff should check before adding a new tool to their workflow. A simple "approved tools" list also tells you, as the owner, exactly what your team is using and what data those tools might see.

Prohibited data types. Clear categories of information that must never be put into an AI tool, regardless of which tool it is. This typically includes client personal information, tax file numbers, medical records, financial account details, and any information your business is expected to protect under applicable laws. The more specific this list is, the easier it is for staff to apply without needing to ask every time.

Output review requirements. AI tools generate plausible-sounding text that is sometimes wrong. For anything that will be sent to a client, published publicly, or used to make a business decision, the policy should require a human review before use. The level of review needed will depend on the stakes. A draft social media caption needs a different level of scrutiny than a quote, a contract, or a medical summary.

Disclosure obligations. Some industries and clients expect, or are legally entitled to know, when AI has contributed to work they have received. Your policy should state when disclosure is required and what that disclosure should say. This is particularly relevant for professional services businesses in law, accounting, financial planning, and healthcare.

Intellectual property and confidentiality. When you put information into an AI tool, you may be sharing it with a third-party system. The policy should remind staff that confidential business information, trade secrets, and client-specific data must be treated as confidential even when using AI. Most AI tools do not guarantee confidentiality of inputs by default, and some use inputs to train future model versions.

Accountability and breach reporting. If a staff member realises they have accidentally shared information they should not have, who do they tell and what happens next? A policy that includes a clear escalation path means problems get surfaced quickly rather than quietly ignored.

Free AI Acceptable Use Policy Template

The template below is designed for a small business with no dedicated legal or compliance team. It is written in plain English and covers the six areas above. Copy it into a Word document or Google Doc, fill in the bracketed sections, and review it with your team. You should also have it reviewed by a solicitor if your business operates in a regulated industry.

AI Acceptable Use Policy

Business name: [Insert business name]
Policy version: 1.0
Effective date: [Insert date]
Last reviewed: [Insert date]
Next review due: [Insert date, recommended: 12 months from effective date]
Policy owner: [Insert name or role]

1. Purpose

This policy sets out how staff at [Business name] may use artificial intelligence (AI) tools in their work. It applies to all employees, contractors, and anyone acting on behalf of the business.

The goal of this policy is to allow the business to benefit from AI tools while protecting client information, meeting our legal obligations, and maintaining the quality of our work.

2. Approved AI tools

Staff may use the following AI tools for approved work purposes:

  • [Tool name 1] for [permitted use, e.g. drafting communications, summarising documents]
  • [Tool name 2] for [permitted use]
  • [Tool name 3] for [permitted use]

If you want to use an AI tool not on this list, speak to [responsible person/role] before using it for work tasks. Do not use unapproved tools for any task that involves client information, business financial data, or confidential business information.

3. Information you must not enter into AI tools

The following categories of information must never be entered into any AI tool, including approved tools, unless the business has a specific written arrangement with that provider that covers the information type:

  • Client names, addresses, phone numbers, email addresses, or any other personal information
  • Tax file numbers (TFNs), ABNs, or financial account details
  • Health, medical, or allied health information about any individual
  • Passwords, access credentials, or authentication details
  • Proprietary business information that is not publicly available
  • Contractual terms or pricing from specific client agreements
  • Any information covered by a confidentiality or non-disclosure agreement
  • Any information that would identify a specific individual (directly or in combination)

If you are unsure whether information falls into one of these categories, treat it as prohibited and ask [responsible person/role] before proceeding.

4. Reviewing AI-generated outputs

AI tools produce text, images, and other content that may contain errors, outdated information, or fabricated facts presented as real. Before using any AI-generated output in a work context, staff must:

  • Read the output in full and check it for accuracy
  • Verify any factual claims, figures, or references against a reliable source
  • Ensure the output reflects the business's own voice, standards, and advice, not just a generic AI-generated version
  • Not send AI-generated content to a client, regulatory body, or any third party without this review being completed

For documents that carry legal, financial, or professional weight (quotes, contracts, advice letters, compliance statements), a senior review is required before sending, regardless of whether AI was involved in drafting.

5. Disclosing AI involvement

Staff must disclose the use of AI in the following circumstances:

  • When a client or customer specifically asks whether AI was used
  • When the business's engagement agreement, industry code, or professional obligations require disclosure
  • When AI has been used to generate advice, recommendations, or assessments that a client will rely on

Disclosure does not need to be elaborate. A brief statement such as "This response was drafted with the assistance of AI tools and reviewed by [name/role]" is sufficient in most cases. Check with [responsible person/role] if you are unsure whether disclosure is required in a specific situation.

6. Confidentiality and intellectual property

When you enter information into an AI tool, that information may be processed and stored by the provider on servers in another country. You should treat AI tools as you would treat any third-party system: do not enter information that you would not be comfortable sharing with an external party.

AI-generated content may draw on third-party sources. Before publishing or commercially using AI-generated content, consider whether intellectual property rights are relevant to your use case. If you are unsure, speak to [responsible person/role].

7. Reporting a breach

If you realise you have accidentally entered prohibited information into an AI tool, or shared information in a way that may have breached this policy, report it to [responsible person/role] as soon as possible. Early reporting allows the business to assess and manage the situation. Delayed reporting makes it harder to manage.

The business will not penalise staff for honest mistakes reported promptly. The business will treat continued or deliberate policy breaches as a conduct matter.

8. Policy review

This policy will be reviewed at least once every 12 months, or sooner if the business adopts new AI tools, if relevant legislation changes, or if a significant policy breach occurs. The current version of this policy is always available at [location, e.g. shared drive, intranet].

This template is provided for general information purposes. It does not constitute legal advice. Businesses in regulated industries should seek legal review before adopting this or any policy document.

How to adapt this template for your business

The template above covers the core structure. Before you send it to your team, there are four things to fill in or adjust. First, populate the approved tools list with the tools your business actually uses. A list of three to five specific tools is more useful than a blank or an overly general description.

Second, review the prohibited data list for your industry. A bookkeeping practice will have different data sensitivities to a trades business, a physiotherapy clinic, or a real estate agency. Add any category of information that is specific to your clients or your industry, and remove any category that is not relevant to keep the policy readable.

Third, assign a named person or role to each of the decision points in the policy. "Speak to management" is too vague. "Speak to the office manager" or "speak to the practice principal" gives staff a clear path to follow. The person nominated should know they hold that role and know what questions they might receive.

Fourth, set a review date and put it in your calendar. AI tools are changing quickly. A policy written today may need to be updated when a tool your team uses changes how it stores data, when your industry body issues guidance, or when your local data protection law changes. Reviewing the policy once a year is enough for most businesses.

Rolling out the policy to your team

A policy that lives in a shared drive and is never discussed does not change behaviour. When you introduce an AI acceptable use policy for the first time, spend 20 to 30 minutes walking through it with your team. Explain the reasoning behind the prohibited data list in particular. Staff who understand why a rule exists are more likely to apply it correctly in situations the policy did not specifically anticipate.

Ask staff to confirm they have read and understood the policy in writing, whether that is a signature on a printed copy, a reply to an email, or a tick-box on your HR system. This creates a record that matters if a conduct issue arises later.

If your team is already using AI tools regularly, consider holding a short session where people share what they are currently using and how. This gives you a clearer picture of what your approved tools list should look like, and often surfaces uses (and risks) you were not aware of. For a practical walkthrough of the rollout process, see our guide on how to roll out an AI policy to your team.

Readers in Australia should use the AU-specific version of this template, which covers Privacy Act and OAIC requirements in full.

What this policy does not cover

An AI acceptable use policy covers staff behaviour, not vendor obligations. It tells your team what they may and may not do. It does not bind your AI tool providers to any particular data handling standard, and it does not replace the need to review the terms of service and privacy policy for any AI tool your business uses.

This template also does not cover every regulated industry context. If your business is in financial services, healthcare, legal services, or another regulated sector, you may face additional obligations around AI use that go beyond a general acceptable use policy. Industry-specific guidance from bodies such as ASIC, APRA, AHPRA, or the Law Society of your state may apply.

If your business uses AI in a way that directly affects customers, such as automated decision-making about loan eligibility, medical triage, or hiring, additional governance considerations apply that are beyond the scope of this template. These uses warrant specific legal advice rather than a general acceptable use policy.

Related resources

This template is the starting point. Once you have a policy in place, the next step is making sure it is complete and implemented properly. The following guides cover each part of that process:

AI Staff Policy Template (Australia) covers the same ground as this template but is tailored specifically for Australian businesses, with additional clauses addressing Privacy Act obligations, OAIC guidance, and common Australian industry requirements. If your business is Australian, start here instead.

AI Policy Checklist for Australian Businesses gives you a structured checklist to verify that your policy covers all required elements and that your implementation is complete. Use this after you have adapted the template above.

How to Roll Out an AI Policy to Your Team covers the practical process of introducing the policy to staff, handling questions, and building the habits that make a policy stick beyond the first week.

Frequently asked questions

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice.

Try our free AI Policy Generator to generate a customised AI policy for your business.

Related reading: our HR and AI compliance obligations in the EU, our what is legal in AI recruitment tools, and our AI vendor contract clauses to check.

Related reading: our ChatGPT for lawyers, our what to include in an AI policy, and our an AI readiness self-assessment.

Related reading: AI governance by region.

Related reading: our who's legally liable for AI-generated content and our honest options for privacy-first cloud storage.

Related reading: our a practical workflow for using AI to draft and review contracts.

Related reading: our when legitimate interest covers AI processing and when you need consent instead.

Related reading: our a real 2026 enforcement finding on what happens when an AI launch skips its privacy impact assessment and our what a PIPEDA-compliant AI vendor contract actually needs to cover.

Related reading: our what the ICO expects before a business deploys facial recognition or biometric AI and our what UK fake review rules actually restrict when using AI for reputation management.

Related reading: our what governs AI product liability in the EU now that the AI Liability Directive was withdrawn and our the real EU AI Act support measures built specifically for smaller businesses.

Related reading: our what the ASA expects when AI generates your product images or ad copy, our what UK cyber security guidance says before giving an AI agent system access, and our why a business is liable for its AI pricing agent the same way it is for an employee.

Related reading: our how the leading AI email tools actually compare for an Australian business and our how to get consistently better business emails out of ChatGPT.

Related reading: our 5 ready-to-use Zapier workflows for Australian businesses and our the best AI meeting assistants for an Australian business.

Related reading: our our comparison of Klaviyo and Omnisend for ecommerce marketing automation, our how to automate customer support for a small ecommerce store, and our our review of Gorgias for a small ecommerce store.

Related reading: our the best AI customer support tools for ecommerce and our the best AI software stack for a small online store.

Related reading: our our review of Tidio for a small ecommerce store, our our review of Rep AI for a small online store, and our our review of Claid.ai for a small ecommerce store.

Related reading: our our review of Signifyd for a small online store, our our review of Riskified for a small online store, and our AI chatbot disclosure rules for ecommerce.

Related reading: our using AI evidence in ecommerce chargeback disputes and our the risks of automated AI refund decisions in ecommerce.

Does a small business really need a written AI policy?

Yes, if your staff are using AI tools for work. Without a written policy, every staff member makes their own judgement about what is acceptable, and those judgements will vary in ways that can expose the business to privacy breaches, professional liability, or client complaints. A short written policy is enough to set consistent expectations and give you a clear basis for addressing problems if they arise.

How long should an AI acceptable use policy be?

For most small businesses, one to two pages is the right length. A policy that is too long will not be read. The template above covers the essential ground in a format that most staff can read in under five minutes. If your business operates in a regulated industry, your policy may need to be longer to address specific obligations, but a general-purpose policy does not need to be comprehensive to be effective.

Can I use ChatGPT or other AI tools if clients have given consent?

Client consent helps, but it does not resolve all the obligations involved. Under most data protection laws, you still need to ensure that any AI tool you use to process client information has adequate data handling arrangements in place, and that you are not transferring personal information overseas without meeting your jurisdiction's requirements for cross-border data transfers. Consent from the client addresses disclosure, but it does not override your obligations as the party responsible for handling that information. Check your local data protection law for the specific requirements that apply to your business.

What happens if a staff member breaches the AI policy?

The response depends on the severity of the breach and whether it was accidental or deliberate. For accidental breaches reported promptly, the priority is assessing and managing any harm, then identifying whether the policy or training needs to be updated. For deliberate or repeated breaches, the policy breach can be treated as a conduct matter under your existing employment or contractor arrangements. The policy template above includes language that makes this expectation explicit.

How often should I update my AI acceptable use policy?

At a minimum, review it once every 12 months. Beyond that, update it whenever your business adopts a new AI tool that is not covered by the current approved list, when a tool changes how it handles data, when relevant legislation or industry guidance is updated, or after any policy breach that reveals a gap. AI tools and the regulatory environment around them are both changing quickly, so annual review is a practical minimum, not a ceiling.

Is this template suitable for a sole trader or very small business?

Yes. Even a sole trader who occasionally uses AI tools benefits from a written record of what they will and will not do with client information. If your business is covered by data protection law in your jurisdiction, a documented policy also demonstrates that you are taking reasonable steps to comply, which matters if a complaint is made to your local privacy regulator. The template above can be shortened for a sole trader context by removing the staff-facing sections and keeping the data handling, review, and reporting sections.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.

If your business is based in Australia, the AU-specific version of this policy template includes additional clauses covering Privacy Act obligations, OAIC guidance, and Australian industry requirements. It takes the same amount of time to adapt but is a better starting point for an Australian business.

Get the Australian AI Staff Policy Template