This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your staff are using AI tools at work, your business already has an AI policy question to answer, whether you have a written policy or not. The absence of a policy is itself a position, and it's usually the riskiest one. Without something in writing, your team is making up their own rules about what data they can share with AI tools, which tools they're allowed to use, and what they do with AI-generated outputs.
The good news is that an AI policy for an Australian small or medium business does not need to be a legal document. It needs to be clear, practical, and cover the areas where things go wrong. This checklist covers the 15 elements that belong in any business AI policy, with notes on why each one matters under Australian law and for a team of your size.
If you want to skip straight to the template, the free Australian AI staff policy template is ready to download and customise.
In short: An AI policy for an Australian business should cover which tools are permitted, what data staff can and cannot share with AI tools, how AI-generated outputs are reviewed before use, and what the consequences are for misuse. Privacy Act 1988 obligations apply whenever AI tools handle personal information, and most cloud-based AI tools send data to servers outside Australia, which triggers cross-border disclosure rules under APP 8.
This article is general information, not legal advice. For advice on your specific obligations, consult a qualified privacy professional or employment lawyer.
Why Your Business Needs an AI Policy Now
Most Australian SMBs have reached the point where at least some staff are using AI tools, whether the business officially knows about it or not. ChatGPT, Microsoft Copilot, Google Gemini, and dozens of category-specific AI tools are accessible to anyone with a browser and a free account. The question is not whether AI is happening in your business. The question is whether it is happening within boundaries you have set.
From a compliance perspective, this matters immediately. Under the Privacy Act 1988, your business is responsible for how personal information is handled, including when a staff member pastes client data into a third-party AI tool to get a quick summary. The fact that it was the employee's idea, not a formal business process, does not reduce the business's exposure.
An AI policy closes the gap between what staff are doing informally and what the business has actually sanctioned. It does not need to ban anything. It needs to be clear about what is permitted, what requires approval, and what is off-limits entirely.
The 15-Point AI Policy Checklist for Australian Businesses
The checklist below is structured in the order a policy document typically flows: purpose and scope first, then permitted and prohibited uses, then data handling, then outputs and accountability, then ongoing governance. Each item includes a short note on why it belongs in your policy and what to think about when writing it.
1. Purpose and Scope
State plainly what the policy is for and who it applies to. This means naming whether it covers full-time employees only, or also contractors, casual staff, and anyone with access to business systems. If your business uses labour hire or subcontractors who access client data, they need to be in scope.
A purpose statement also signals intent: this policy exists to help the business use AI tools responsibly, not to punish people for using technology. Framing matters for adoption.
2. Definition of AI Tools Covered
Define what counts as an AI tool for the purposes of this policy. This sounds basic, but it is genuinely important. Staff need to know whether the AI writing assistant in their email client is covered. Whether the chatbot on a software vendor's website is covered. Whether an AI feature built into an existing tool they already use (like Xero, Salesforce, or Adobe) is covered.
A workable definition: any tool that uses machine learning or generative AI to create, summarise, classify, or respond to content, whether standalone or embedded in another product. You may want to explicitly list your currently approved tools alongside this definition so there is no ambiguity.
3. Approved Tools List
List the AI tools staff are currently approved to use, the purpose each tool is approved for, and any conditions attached (for example: approved for drafting internal communications, not approved for use with client data). Keep this list current, which means having a process to add tools as the landscape changes.
An approved list also implicitly signals that tools not on the list require approval before use. This is the mechanism that prevents staff from signing up to random AI tools on their work email without anyone knowing.
4. Data Classification Rules
Define what categories of data exist in your business and which categories can or cannot be used with AI tools. Common categories for an Australian SMB: internal only (meeting notes, draft documents), client data (names, contact details, financial information), sensitive personal information (health information, tax file numbers), and confidential commercial information (pricing, contracts, IP).
For each category, specify whether it can be used with approved AI tools, whether it can be used with any AI tool (approved or not), or whether it must not be entered into any AI tool under any circumstances. This is the heart of the policy from a Privacy Act perspective.
5. Personal Information and Privacy Act Obligations
If your business is subject to the Privacy Act 1988, this section is not optional. The Privacy Act applies to businesses with annual turnover above $3 million, and to some smaller businesses in specific sectors (health service providers, credit reporting bodies, businesses that trade in personal information).
The key obligation here is Australian Privacy Principle 8 (APP 8), which governs cross-border disclosure of personal information. Most cloud-based AI tools process data on servers outside Australia, typically in the United States. Disclosing personal information to an overseas recipient means the business must either take reasonable steps to ensure the overseas recipient handles the information consistently with the APPs, or obtain the individual's consent. This obligation should be named explicitly in your policy.
The Office of the Australian Information Commissioner (OAIC) has published guidance on AI and privacy that is worth reading alongside this checklist. See the Privacy Act reform deadline guide for the current state of Australian privacy law and what changes are coming.
APP 8 applies when you use cloud AI tools. If a staff member pastes client personal information into ChatGPT, that information is being disclosed to an overseas recipient (OpenAI, US-based). Your business is responsible for this disclosure under the Privacy Act, even if the staff member did it without explicit authorisation. The policy should make this consequence clear.
6. Prohibited Uses
State explicitly what staff are not allowed to do. A prohibited uses list removes ambiguity and is more useful than a general instruction to "use AI responsibly." Common prohibitions for Australian SMBs include: entering client personal information into non-approved AI tools, using AI tools to generate legally binding documents without review by a qualified person, representing AI-generated content as the original work of the staff member, and using AI tools for purposes not related to the business.
You may also want to address industry-specific prohibitions. A legal practice has different obligations around privileged information than a marketing agency. A health service provider has obligations under the Privacy Act and potentially the My Health Records Act that require specific attention.
7. Output Review Requirements
AI tools make mistakes. They generate plausible-sounding content that is factually wrong. They cite sources that do not exist. They produce outputs that reflect biases in their training data. Your policy should specify that AI-generated outputs must be reviewed by a staff member before use, and that the reviewing staff member is responsible for the accuracy of the final output.
The level of review required should be proportional to the risk of the output. A first draft of an internal email needs a light read. A client-facing financial summary, a legal document, or a public-facing piece of content needs a more thorough check. Consider defining review tiers in your policy rather than applying a single standard to everything.
8. Accuracy and Hallucination Acknowledgement
The term "hallucination" is used to describe when an AI tool generates confident but incorrect information. This is a known limitation of current AI tools, not an edge case. Staff who are new to using AI tools often do not realise that a fluent, well-structured output can be entirely wrong.
Your policy should acknowledge this limitation by name, in plain language. Something like: AI tools can generate information that sounds correct but is not. Staff are responsible for verifying any facts, figures, legal references, or specific claims before using AI-generated content in work that goes to clients or is used to make business decisions.
9. Intellectual Property Considerations
There are two intellectual property questions your policy should address. First, who owns the content that AI tools generate when staff use them for work? Most AI tool terms and conditions assign ownership to the user, but this varies by tool and is worth confirming. Second, could the AI tool have used copyrighted material to generate the output, and does that create any risk for the business?
Australian copyright law does not yet have settled positions on AI-generated content. The safe position for most SMBs is to treat AI-generated content as a draft that staff have substantially reviewed and modified, rather than publishing it verbatim. Your policy should note that staff should not submit AI-generated content to clients or for publication without meaningful review and revision.
10. Confidentiality and Business Information
Even when client personal information is not in play, business-confidential information can be. Pricing strategy, unreleased products, acquisition plans, and commercially sensitive client relationships are all examples of information that could cause real harm if shared with an AI tool whose training data policies are not completely clear.
Check the terms of service for each approved AI tool to understand whether data submitted by users is used to train the model. Many enterprise tiers of major AI tools offer explicit no-training commitments. Many free tiers do not. Your approved tools list should note which tier is approved and why, and the policy should prohibit using free personal tiers of tools with business-confidential information.
11. Disclosure and Transparency Requirements
Should staff disclose to clients when AI was used in work delivered to them? There is no universal Australian legal requirement to do this today, but the position may change as AI regulation develops, and some professional and industry bodies already have their own requirements.
The practical position for most SMBs is to decide in advance rather than reactively. If your business uses AI tools to assist with work for clients, consider whether your engagement terms or standard communications should note this. Some clients will expect it. Others will not care. The worst outcome is having it discovered that AI was used in a context where the client assumed everything was human-produced, which is a trust issue even if it is not currently a legal one.
12. Staff Training Requirements
A policy that staff have not been trained on is not much better than no policy at all. This section should specify what training is required before staff are permitted to use AI tools, how that training is delivered (induction, online module, team session), and how often training is refreshed as tools and the policy evolve.
Training does not need to be extensive. A 30-minute session covering what the policy says, why the data rules exist, and how to check whether an output needs review is enough to reduce the most common mistakes. What matters is that it happens and is documented.
13. Breach Reporting and Consequences
What happens when someone does the wrong thing? Your policy should specify how a potential breach is reported (to whom, by what means), how breaches are assessed, and what the range of consequences looks like from additional training through to formal disciplinary action depending on severity.
Equally important: what happens when the business becomes aware of a possible data breach that involves an AI tool? Under the Notifiable Data Breaches (NDB) scheme, eligible data breaches must be reported to the OAIC and to affected individuals. A staff member entering client health information into an unapproved AI tool that later has a security incident could constitute a notifiable data breach. Your breach response process should include AI tool incidents as a named scenario.
14. Approval Process for New Tools
The AI tool landscape changes quickly. New tools appear, existing tools add AI features, and staff will come across things they want to try. Your policy should include a lightweight process for requesting and approving new AI tools before they are used for business purposes.
The approval process does not need to be bureaucratic. A named approver (owner, operations manager, IT contact), a short checklist of what to assess (data handling terms, whether it uses data for training, cost, AU availability, whether a business-tier account is required), and a record of approved tools updated as decisions are made is sufficient for most SMBs. What matters is that it is consistent and that staff know not to just sign up and start using things.
15. Policy Review and Version Control
AI tools and the laws that govern them are both changing. A policy written today may need updating within 12 months as new tools are adopted, as the Privacy Act reforms take effect, or as the business's own use of AI matures. The policy itself should specify when it will be reviewed (at minimum, annually), who is responsible for reviews, and how staff are notified when the policy changes.
Include a version number and effective date on the policy document. This is basic document management, but it matters when you need to demonstrate that staff were operating under a specific version of the policy at a specific time.
Australian-Specific Considerations by Industry
The 15-point checklist above applies to most Australian SMBs. Some industries have additional obligations that should be reflected in the policy, or that make certain checklist items more urgent than they might otherwise be.
Health and allied health: The Privacy Act's health information provisions and the My Health Records Act impose stricter obligations on health service providers than on general businesses. AI tools should not be used to process patient health records without specific assessment of that tool's compliance with Australian health privacy requirements. The health information category should be explicitly called out in the data classification section.
Legal practices: Legal professional privilege applies to communications between lawyers and clients. Entering privileged communications into a third-party AI tool could compromise that privilege. Legal practices should take advice on how to frame the policy for privileged materials specifically, and should not treat this as equivalent to general confidentiality.
Accounting and financial services: ASIC-regulated entities and those operating under Australian financial services licence conditions may have specific obligations around record-keeping and advice quality that interact with AI-generated outputs. AI-generated financial summaries or advice drafts should be subject to the same quality review requirements as any other advice produced by the business.
Education: Schools and training organisations holding student information are subject to specific privacy protections. The use of AI tools to process student data, generate assessments, or personalise learning content should be assessed against the applicable state and federal privacy frameworks before being added to an approved tools list.
Getting the Policy Written and Into Your Team's Hands
The most common reason SMBs do not have an AI policy is not that they do not see the need. It is that writing one from scratch feels like a large task, and there is always something more urgent competing for time. A template removes that friction by giving you the structure and the standard language, so the work becomes filling in your business's specifics rather than starting from a blank page.
The free AI staff policy template for Australia covers all 15 items in this checklist, with plain-English placeholder text you can adapt for your business. It is designed for a business without a legal or HR department to manage the process, which means it avoids legal jargon while covering the areas that matter.
Once you have a draft, the companion guide on rolling out an AI policy to your team covers how to communicate the policy, run a short training session, and make it stick rather than having it sit unread in a shared drive.
Practical starting point: If your business has not started yet, begin with items 3 (approved tools list), 4 (data classification), and 6 (prohibited uses). These three items address the most immediate risks and can be documented in a single page. The full 15-item policy can follow once the basics are in place and your team is used to the idea that AI tool use has rules.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our can staff upload customer data to AI tools and our AI and the Privacy Act guide.
Related reading: our Claude AI review for Australian business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Try our free AI Policy Generator to generate a customised AI policy for your business.
Related reading: our free AI acceptable use policy template and our AI governance by region.
Once your checklist is complete, see our AI staff policy hub for templates and rollout guidance.
Does my small business legally need an AI policy in Australia?
There is no specific Australian law that requires a business to have a written AI policy. However, if your business is subject to the Privacy Act 1988, the Privacy Act already requires reasonable steps to protect personal information, and the OAIC's guidance indicates that documenting how AI tools are used with personal information is part of meeting that expectation. A written policy is the most straightforward way to demonstrate you have taken those steps. Businesses below the Privacy Act turnover threshold ($3 million) may also face sector-specific obligations depending on their industry.
What is APP 8 and why does it matter for AI tools?
Australian Privacy Principle 8 governs cross-border disclosure of personal information. It requires that when your business sends personal information to an overseas recipient, you take reasonable steps to ensure that recipient handles the information consistently with the Australian Privacy Principles. Most major AI tools (ChatGPT, Microsoft Copilot, Google Gemini) process data on servers in the United States, which makes them overseas recipients under APP 8. This applies even if staff are using these tools informally. Your AI policy should address APP 8 directly by specifying which tools are approved for use with personal information and under what conditions.
Can I use a free AI policy template, or do I need a lawyer to draft one?
A template is a practical starting point for most SMBs, and it is significantly better than having nothing in place. The free Australian AI staff policy template on this site covers the standard compliance and operational elements an SMB needs. If your business operates in a highly regulated sector (health, financial services, legal), or if you handle sensitive personal information at scale, it is worth having a lawyer review the final version before it goes to staff. For most other businesses, a well-structured template adapted for your specific context is sufficient.
How often should we update our AI policy?
At minimum, review the policy annually. In practice, you should also review it when: you adopt a significant new AI tool, when Australian privacy law changes (reforms to the Privacy Act are currently in progress, with some changes taking effect in late 2025 and 2026), or when a near-miss or actual incident reveals a gap in the current policy. The AI tool landscape is changing quickly enough that a policy written in 2024 may already be missing tools or scenarios that are now commonplace in your business.
What should staff do if they are not sure whether using a particular AI tool is allowed?
Your policy should name a specific person to ask, not just a role or a department. For most SMBs, this is the owner or the operations manager. The policy should also set a default position for situations where that person is unavailable: if in doubt, do not use the tool with business data until you have checked. A clear default prevents staff from either paralysing themselves over minor decisions or proceeding with something risky because they could not reach the approver in time.
Do we need to tell clients we are using AI tools?
There is currently no universal Australian legal requirement to disclose AI use to clients, though this may change as AI-specific regulation develops. Some professional bodies (legal, financial advice) already have their own guidance on this. The practical recommendation for most SMBs is to decide proactively: if AI is involved in producing work for clients, consider whether your engagement terms or service descriptions should note this. The risk of not disclosing is reputational, not currently legal, but it is a real risk if a client discovers AI was used in a context where they assumed otherwise.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.
The free AI staff policy template for Australian businesses covers all 15 items in this checklist, with plain-English placeholder text ready to customise. Download it, adapt it for your business, and have something in place before your next team meeting.
Get the Free AI Policy Template