This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your staff are using AI tools and you don't have a written policy covering how they can and can't use them, you're not alone, but you are exposed. Most Australian small businesses are in exactly this position right now. This article explains why a written AI staff policy matters in 2026, what Australian law requires, and what the free T-01 template includes so you can put something in place today.
In short: Download the free AI Staff Acceptable Use Policy Template below. It covers the Australian compliance requirements your business needs in 2026, including Privacy Act obligations, Fair Work Act context, and the December 2026 automated decision-making deadline. No email required.
Download the free T-01 AI Staff Acceptable Use Policy Template. 13 sections covering Australian legal obligations. No email required.
Download Free TemplateWhy every Australian business needs an AI staff policy now
AI tools have moved faster than most business policies. Tools like ChatGPT, Google Gemini, and Microsoft Copilot are now part of daily work life for many employees, regardless of whether their employer has said anything about it. The problem is not that these tools exist. The problem is that without a written policy, your staff have no guidance on what's appropriate, and your business has no protection if something goes wrong.
A written AI staff policy does three things. It tells staff what tools are approved for business use and how to use them safely. It protects the business if a staff member misuses an AI tool and a client or regulator asks what your policies were. And it gives you a defensible position under the Privacy Act, the Fair Work Act, and (in NSW) the Workplace Surveillance Act if your AI use is ever scrutinised.
There is also a hard deadline approaching. From December 2026, if AI is involved in decisions that affect staff or customers, your privacy policy must reflect that. Businesses that have not updated their policies by then will be behind on their obligations under the Privacy Act 1988 amendments. The window to get this in order is now, not next year.
Take the owner of a retail business with 15 staff across two stores. She used to have no idea what her staff were pasting into free AI tools between customers, customer emails, roster details, whatever saved them time. Now, instead of guessing, every new starter signs the T-01 policy on day one and gets pointed straight to the approved tools list. That's staff clarity and a paper trail, in place before it's ever tested.
What "shadow AI" is and why it matters
"Shadow AI" refers to AI tools that staff are using at work without their employer's knowledge or approval. The most common example is a staff member using their personal free ChatGPT account to help draft emails, summarise documents, or answer client queries, without their employer having any visibility over what data is being shared or how.
This is the number one AI governance risk for Australian small and medium businesses right now. It is not a hypothetical. If a bookkeeper pastes a client's financial records into ChatGPT to get a summary, that data has been sent to an overseas server operated by a US company. If a medical receptionist uses a free AI tool to draft a referral letter, patient information may have crossed an international border. Neither of these actions requires technical sophistication. They require nothing more than a browser and a free account.
A written AI policy closes this gap. It defines which tools are approved for business use, which categories of data must never be entered into any AI tool, and what staff should do if they are unsure. Without that written guidance, you are relying on individual judgement, and that creates inconsistent outcomes and real legal exposure.
The Australian legal obligations your AI policy must cover
Three pieces of Australian law are directly relevant to how your staff use AI tools. Understanding what each one requires in plain terms helps you see why a template that addresses all three is worth having.
Privacy Act 1988 and the Australian Privacy Principles
When staff use AI tools with customer or client data, the Privacy Act 1988 applies. Three of the Australian Privacy Principles are particularly relevant. APP 6 says personal information should only be used for the purpose it was originally collected. If your business collected a customer's contact details to send them an invoice, feeding those details into an AI tool for another purpose may breach this principle.
APP 8 covers cross-border disclosure of personal information. Sending personal information to an AI tool hosted on overseas servers. Which covers virtually every major AI tool currently available. Constitutes a cross-border disclosure under the Privacy Act. Under APP 8, the OAIC's guidance outlines that businesses are expected to take reasonable steps to ensure the overseas recipient handles the data consistently with Australian Privacy Principles. In practice, this means reviewing and accepting the vendor's data handling terms before using the tool for personal information. See the OAIC's APP 8 guidance at oaic.gov.au.
APP 11 requires that your business take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. An AI policy that names approved tools and bans the use of personal data in unapproved tools is one of the clearest demonstrations of "reasonable steps" you can document.
The December 2026 automated decision-making deadline
Privacy Act amendments introduce an automated decision-making (ADM) disclosure requirement that takes effect in December 2026. If your business uses AI in any process that makes or significantly influences a decision about an individual, whether that is a staff member or a customer, your privacy policy must disclose this. The requirement covers decisions about creditworthiness, eligibility for services, employment, and similar matters.
This deadline is closer than it appears. Updating a privacy policy is not an afternoon's work for most small businesses, particularly if this is the first time AI use has been documented. The T-01 template includes an ADM disclosure obligation section that gives you a starting point for this update. For a full explanation of the December 2026 requirements, see the Privacy Act December Deadline guide.
Fair Work Act 2009
Your AI policy must be fair and consistently applied to all employees. Under the Fair Work Act 2009, policies that are applied inconsistently or without proper notice can create grounds for unfair dismissal claims if an employee is later disciplined for breaching them. This does not mean you need a complicated policy. It means the policy must be communicated clearly to all staff, applied the same way regardless of seniority, and reviewed when you update it.
NSW Workplace Surveillance Act 2005
If you are in New South Wales and you plan to monitor how staff are using AI tools, including reviewing logs of what they have entered into AI systems, this may constitute workplace surveillance under the Workplace Surveillance Act 2005. The Act requires employers to give notice before conducting computer surveillance and to have a surveillance policy in place. If monitoring is part of how you plan to manage AI use in your business, seek legal advice on the disclosure requirements specific to NSW. Businesses in other states should check whether comparable legislation applies in their jurisdiction.
What the free template includes
The T-01 AI Staff Acceptable Use Policy Template has 13 sections. It is a Word document you can customise for your business. Each section is pre-written with placeholder text where your specific business details go, and explanatory notes where a section requires a decision or additional context from you.
The 13 sections cover:
- Purpose and scope of the policy and which staff it applies to
- Approved AI tools list with a table for you to populate with the tools your business has reviewed and permitted
- Banned data inputs covering customer personally identifiable information, financial records, health data, confidential commercial information, and legal documents
- Permitted use cases describing the business tasks where AI use is appropriate
- Review and approval process for staff who want to use a new AI tool not yet on the approved list
- Output review requirement stating that AI-generated content must be reviewed by a human before it is sent to a client or used in a business decision
- Accuracy and hallucination risk notice explaining that AI tools can produce incorrect information and staff are responsible for checking outputs
- Privacy Act compliance section referencing APP 6, APP 8, and APP 11 obligations specific to AI tool use
- Automated decision-making disclosure section linked to the December 2026 ADM requirement
- Incident escalation path describing what staff should do if they believe a data breach or policy breach has occurred through AI use
- Fair Work Act acknowledgment confirming the policy applies consistently to all employees
- NSW Workplace Surveillance Act notice section (with a note that this applies to NSW businesses and should be reviewed for other states)
- Policy review schedule with a prompt to review the policy at least annually or when a new AI tool is adopted
How to customise the template for your business
The template is designed to be usable by a business owner or office manager without legal training. Most sections require only that you fill in your business name, the date, and your approved tools list. A few sections require a genuine decision from you.
The most important decision is the approved tools list. Before you complete Section 2, you need to decide which AI tools your business will formally approve. For each tool, check the vendor's data handling terms to confirm where your data is stored and whether you can opt out of your data being used to train the AI. Most major providers (Microsoft Copilot for business accounts, Google Workspace AI, ChatGPT Enterprise) offer data protection terms for paid business accounts that are materially better than their free consumer terms.
The banned data inputs list in Section 3 is pre-populated with common categories but you should review it against your industry. A legal practice will have different sensitivity requirements to a retail business. A healthcare provider will need to consider additional obligations under state health records legislation alongside the Privacy Act. Add any data categories specific to your industry that are not already in the template.
Once customised, the policy should be distributed to all staff and signed (or acknowledged) before they use any AI tool for work purposes. A dated acknowledgment record is your evidence that the policy was communicated, which matters if the policy is ever tested under the Fair Work Act.
Who needs to sign and how to roll it out
Every staff member who uses, or might use, an AI tool for work should sign the policy. In practice, that means all staff in most businesses, because the definition of "AI tool" is broad enough to cover AI features built into tools they may already use, such as spelling and grammar suggestions in Microsoft Word, smart reply features in Gmail, or AI-generated summaries in project management software.
The rollout process does not need to be complicated. Distribute the policy document, allow staff time to read it, run a brief team meeting to explain the key points and answer questions, and collect signed acknowledgments before the effective date. If your business uses an HR system, add the policy to your onboarding materials so all new hires receive it from day one.
For a step-by-step guide to rolling out an AI policy to your team, including how to handle pushback and what to do when staff ask about tools not on the approved list, see the companion guide: How to Roll Out an AI Policy to Your Team.
Last verified: June 2026 | Next review: September 2026
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: can staff upload customer data to AI tools, AI and the Privacy Act guide, AI data residency in Australia, OAIC guidance on AI for businesses, AI tools with Australian data centres, HR AI compliance in Australia, AI vendor contracts and Privacy Act, AI data breaches and the NDB scheme, Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.
Related reading: our AI acceptable use policy template, our AI policy checklist for businesses, and our HR AI policy template.
Related reading: our AI tools worth using as an Australian sole trader, our how AI saves a trades business 5 hours a week, and our AI readiness checklist for Australian businesses.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Try our free AI Policy Generator to generate a customised AI policy for your business.
Try our free AI Tool Pricing Tracker to check current AUD pricing across the major AI platforms.
For the full range of AI staff policy guides, including HR-specific and rollout guidance, see our AI staff policy hub.
Do I need a lawyer to create an AI staff policy for my business?
Not necessarily. The T-01 template is designed for use by a business owner or manager without legal training and covers the core Australian obligations in plain language. For businesses in high-risk industries such as legal, healthcare, or financial services, or for any business handling large volumes of sensitive client data, having a solicitor review the customised policy before it is issued adds a meaningful layer of protection. For most other businesses, the template as customised is a reasonable starting point that is significantly better than having no policy at all.
Does an AI policy apply if my staff are using AI tools on their personal devices?
Yes. The Privacy Act obligations apply based on what data is being used, not which device it is on. If a staff member pastes client information into a free AI tool on their personal phone during work hours, your business still has a Privacy Act exposure. Your policy should make clear that the approved tools list and banned data inputs apply regardless of whether the device is employer-supplied or personal.
What happens if a staff member breaches the AI policy?
A documented, communicated policy means you can treat a breach as a workplace conduct matter under your standard HR process. Without a policy, there is nothing to have breached, which makes it very difficult to take action consistently and fairly. The escalation section in the T-01 template gives staff a clear path to report AI-related incidents, which also helps your business identify and contain potential data breaches early before they become reportable events under the Notifiable Data Breaches scheme.
Is ChatGPT safe to use for business purposes in Australia?
It depends on the account type and what data you are entering. Free ChatGPT accounts use your inputs to train OpenAI's models by default, which means client data entered through a free account may be used by OpenAI for purposes beyond your original intent. ChatGPT Enterprise and API access offer data handling terms that exclude your data from training. If your staff are using free ChatGPT accounts for work, the safest approach is to ban the use of any client or customer data in those accounts immediately and specify an approved paid tier or alternative in your policy.
What is the December 2026 AI deadline for Australian businesses?
From December 2026, Australian businesses covered by the Privacy Act must update their privacy policy to disclose if they use automated decision-making systems, including AI tools, that make or significantly influence decisions about individuals. This applies to decisions about staff or customers. Businesses that use AI in hiring, customer eligibility assessments, or similar processes need to review their privacy policy now. See the full Privacy Act December Deadline guide for details.
Which types of businesses most need an AI staff policy?
Any Australian business with staff who could use AI tools is in scope. The risk is highest in professional services where client data sensitivity is greatest: accounting and bookkeeping practices, legal firms, medical and allied health practices, mortgage brokers, financial advisers, and HR consultancies. In these industries, a data breach involving client information entered into an AI tool can trigger obligations under both the Privacy Act and industry-specific regulatory frameworks. Retailers, trades businesses, and agencies face lower but still real exposure if staff are entering customer details or commercial information into unapproved tools.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.
Download the free T-01 AI Staff Acceptable Use Policy Template. 13 sections. Covers Privacy Act, Fair Work Act, and NSW Workplace Surveillance Act obligations. No email required.
Download Free Template