Published 18 July 2026
AI use policy for Australian small business: a template
Someone on your team is already using AI at work. I'm not accusing anyone. That's just where things sit in 2026. The pattern repeats in almost every workplace: staff pick up AI tools long before anyone writes down the rules. Usually on personal accounts. Usually with good intentions. And every so often with a paste of exactly the customer data that should never leave your systems.
An AI use policy is the one-page fix. Below is what an Australian small-business version needs to cover, why it matters more this year, and a section-by-section outline you can draft from today. (Not sure you need one at all? Start with does your small business need an AI policy?. This article assumes you've already decided you do.) One caveat now, and again at the end: this is a practical guide, not legal advice.
Why AI policies became a 2026 compliance item
Three things in Australia moved this from "nice to have" to "someone's going to ask":
-
The Privacy Act follows the data. If staff put personal information about customers or staff into a public AI tool, that's a disclosure your business is responsible for. The Privacy Act's "reasonable steps" expectation doesn't switch off because the recipient is a chatbot. The Office of the Australian Information Commissioner (oaic.gov.au) has published guidance on AI and privacy that makes it clear the existing principles apply.
-
Standards now name it. SMB1001:2026, a private, tiered cyber security certification standard aimed at Australian SMBs, lists a responsible-AI-use policy among its Gold-level controls. It isn't law. It is a pretty clear signal of where "what good looks like" is heading for small businesses.
-
Questionnaires are starting to ask. Insurer proposal forms and big-customer vendor questionnaires grow one question at a time. Once a risk becomes common, a question about it turns up. AI questions are starting to appear the way MFA questions did a few years back, and a written policy makes that question easy instead of awkward.
One more for the forward planners. The Australian Signals Directorate (cyber.gov.au) has flagged a possible chapter on AI for the Essentials series, the framework replacing the Essential Eight over the next two years. The direction is more scrutiny, not less.
The risk in plain terms
In a small business, most AI-tool risk comes down to one scenario: confidential information leaving your control through a helpful employee. Someone pastes a customer complaint thread into a chatbot to help draft a reply. The thread has names, contact details and an account history in it. Depending on the tool and the account type, that content may be kept, reviewed or used to train models. Either way, it has left your systems.
The second risk is quieter. Confidently wrong output. AI tools write plausible text, and that includes plausible mistakes. Without a rule that a human checks things before they go out, those mistakes reach customers with your name on them.
A policy won't make either risk disappear. What it does is make the safe path obvious, and for a small team that's most of the battle.
What an Australian AI use policy should cover
A handful of things. None needs more than a paragraph:
- Approved tools and accounts. Which AI tools the business has approved, and a rule that they're used through business accounts, not personal ones. Personal accounts are where the data-handling terms are weakest and your visibility is zero. This fits neatly with restricting administrative privileges: fewer people able to install unvetted tools means a smaller shadow-AI problem.
- Data rules. What never goes in: customer or staff personal information, credentials and access keys, commercially confidential material. This section is the reason the policy exists.
- Human review. AI output is a draft. A person checks the facts and owns the result before anyone relies on it or it leaves the business.
- Access and identity. If an AI tool connects to systems holding your data, it sits behind the same controls as any other login, including multi-factor authentication on the accounts involved.
- Decisions about people. Hiring, credit, complaints. Decisions that significantly affect a person get made by a human, not handed to a tool.
- Review cadence. Review the policy at least once a year, because these tools change faster than most software.
A section-by-section outline
You can draft straight from this. It's the same structure our generated AI Use Policy uses:
- Purpose. One paragraph: AI tools save time, but used carelessly they can leak confidential information or produce wrong output, so this policy sets the boundaries.
- Scope. Covers all staff and contractors, on any device used for work.
- Approved use. The approved-tools list, business accounts only, and a preference for tools and settings that don't train on your data.
- Prohibited inputs. The data rules above, as a short bulleted list.
- Accuracy and accountability. Human review before anyone relies on the output. No automated decisions about individuals.
- Review. Who owns it, and the annual review date.
Honestly, that's it. A page, not a binder. This outline is general information, not legal advice. If your business handles sensitive categories of data (health, legal, financial), get a professional to look over your draft.
Keeping it current
Two habits stop the policy from becoming something you laminate and forget:
- Tie it to your annual security review. If you already re-assess your Essential Eight controls before insurance renewal, review the AI policy at the same sitting. Same meeting, one extra agenda item.
- Keep the approved-tools list honest. The list goes stale, not the prose. When a new tool shows up in the team's workflow, either the policy approves it or it shouldn't be in use.
Rather not start from a blank page? Our free Essential Eight self-assessment takes about 20 minutes, and the paid document pack generates an AI Use Policy alongside your security policies. It's personalised to your business, with the boundaries above built in.
FAQ
Is an AI use policy legally required in Australia? No law requires a stand-alone AI use policy. But if staff put customer or staff personal information into AI tools, the Privacy Act's obligations follow that information, and a written policy is the practical way to stop the problem before it starts. Some frameworks also list a responsible-AI-use policy as an expected control, such as the SMB1001:2026 private certification standard at its Gold level.
What should an AI use policy ban? The short list: personal information about customers or staff, passwords and access keys, and commercially confidential information. None of it should go into an AI tool unless that specific tool has been approved for it and is covered by an appropriate agreement. Most of the policy's value comes from writing that list down.
Does the Privacy Act cover what staff type into ChatGPT? The Privacy Act governs how a business handles personal information, wherever it goes. If an employee pastes customer records into a public AI tool, that can be a disclosure the business is responsible for, much like emailing them to an outside party. The OAIC's guidance on privacy and AI takes this view. Whether it applies to your specific situation is a question for a privacy professional, not something this article can decide.
How often should we review an AI policy? At least once a year, and any time the tools your team uses change in a meaningful way. AI products move faster than most business software. A tool that didn't train on your data last year may do so this year. ASD has also flagged a possible AI chapter for its upcoming Essentials series, so expect Australian guidance to keep shifting.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).