Skip to content

Published 18 July 2026

AI use policy for Australian small business: a template

Someone on your team is already using AI at work. That's not an accusation — it's the 2026 baseline. The pattern is consistent across workplaces: staff adopt AI tools long before anyone writes down the rules, usually through personal accounts, usually with the best intentions, and occasionally with a paste of exactly the customer data that should never leave your systems.

An AI use policy is the one-page fix. Here's what an Australian small-business version needs to cover, why it's newly relevant this year, and a section-by-section outline you can draft from today. (Not sure you even need one? Start with does your small business need an AI policy? — this article assumes you've decided you do.) One caveat up front, and again at the end: this is a practical guide, not legal advice.

Why AI policies became a 2026 compliance item

Three Australian triggers turned "nice to have" into "asked about":

  1. The Privacy Act follows the data. If staff put personal information about customers or staff into a public AI tool, that's a disclosure your business is responsible for — the Privacy Act's "reasonable steps" expectation doesn't pause because the recipient is a chatbot. The Office of the Australian Information Commissioner (oaic.gov.au) has published guidance on AI and privacy making clear the existing principles apply.

  2. Certification standards now name it. SMB1001:2026 — a private, tiered cyber-security certification standard aimed at Australian SMBs — lists a responsible-AI-use policy among its Gold-level controls. It's not law, but it's a signal of where "what good looks like" is heading for small businesses.

  3. Questionnaires are starting to ask. Insurer proposal forms and big-customer vendor questionnaires evolve by accretion: once a risk is common, a question appears. AI use questions are beginning to show up the way MFA questions did a few years ago. A written policy turns that question from awkward to easy.

Worth noting for the forward-looking: the Australian Signals Directorate (cyber.gov.au) has flagged a possible chapter on AI for the Essentials series, the framework replacing the Essential Eight over the next two years. The direction of travel is more scrutiny, not less.

The risk in plain terms

Most AI-tool risk in a small business is one scenario: confidential information leaving your control through a helpful employee. A staff member pastes a customer complaint thread into a chatbot to draft a reply. The thread contains names, contact details, an account history. Depending on the tool and account type, that content may be retained, reviewed, or used to train models — and it has definitely left your systems.

The second risk is quieter: confidently wrong output. AI tools produce plausible text, including plausible mistakes. Without a "human reviews before it ships" rule, those mistakes go to customers under your name.

A policy doesn't eliminate either risk. It makes the safe path explicit, which for a small team is most of the battle.

What an Australian AI use policy must cover

Five things, none of which need more than a paragraph:

  • Approved tools and accounts. Which AI tools the business has approved, and that they're used through business accounts — not personal ones. Personal accounts are where data-handling terms are weakest and visibility is zero. This pairs naturally with restricting administrative privileges: the fewer people who can install unvetted tools, the smaller the shadow-AI problem.
  • Data rules. What must never be entered: customer or staff personal information, credentials and access keys, commercially confidential material. This is the section that earns the policy its keep.
  • Human review. AI output is a draft. A person checks facts and owns the result before it's relied on or sent outside the business.
  • Access and identity. Where an AI tool connects to systems that hold your data, it should sit behind the same controls as any other login — including multi-factor authentication on the accounts involved.
  • Decisions about people. Hiring, credit, complaints — decisions that significantly affect a person are made by a human, not delegated to a tool.
  • Review cadence. The policy is reviewed at least annually, because the tools change faster than most software.

A section-by-section outline

Draft from this directly — it's the same structure our generated AI Use Policy uses:

  1. Purpose — one paragraph: AI tools save time; used carelessly they can leak confidential information or produce wrong output; this policy sets the boundaries.
  2. Scope — applies to all staff and contractors, on any device used for work.
  3. Approved use — the approved-tools list, business accounts only, prefer tools/settings that don't train on your data.
  4. Prohibited inputs — the data rules above, as a short bulleted list.
  5. Accuracy and accountability — human review before reliance; no automated decisions about individuals.
  6. Review — owner, and an annual review date.

That's genuinely it. A page, not a binder. This outline is general information, not legal advice — if your business handles sensitive categories of data (health, legal, financial), have a professional look over your draft.

Keeping it current

Two habits keep the policy alive rather than laminated:

  • Tie it to your annual security review. If you already re-assess your Essential Eight controls before insurance renewal, review the AI policy at the same sitting — same meeting, one extra agenda item.
  • Keep the approved-tools list honest. The list, not the prose, is what goes stale. When a new tool arrives in the team's workflow, the policy either approves it or it shouldn't be in use.

If you'd rather not start from a blank page: our free Essential Eight self-assessment takes about 20 minutes, and the paid document pack generates an AI Use Policy alongside your security policies — personalised to your business, with the boundaries above built in.

FAQ

Is an AI use policy legally required in Australia? No law requires a stand-alone AI use policy. But if staff put customer or staff personal information into AI tools, the Privacy Act's obligations follow that information — and a written policy is the practical way to stop the problem before it happens. Some frameworks, such as the SMB1001:2026 private certification standard at its Gold level, also list a responsible-AI-use policy as an expected control.

What should an AI use policy ban? The short list: personal information about customers or staff, passwords and access keys, and commercially confidential information — none of these should go into AI tools unless a specific tool has been approved for it and is covered by an appropriate agreement. Most of the policy's value is in making that list explicit.

Does the Privacy Act cover what staff type into ChatGPT? The Privacy Act governs how a business handles personal information, wherever it goes. If an employee pastes customer records into a public AI tool, that can be a disclosure the business is responsible for — similar to emailing them to an outside party. The OAIC's guidance on privacy and AI takes this view; whether it applies to a specific situation is a question for a privacy professional, not something this article can decide.

How often should we review an AI policy? At least annually, and whenever the tools your team uses change materially. AI products change faster than most business software — a tool that didn't train on your data last year may this year. ASD has also flagged a possible AI chapter for its upcoming Essentials series, so expect Australian guidance to keep moving.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).