Skip to content

Published 18 July 2026

Does your small business need an AI policy?

Here's the straight answer, up front: if anyone on your team uses AI tools with business or customer information — or might — then yes, you need an AI use policy. If genuinely nobody does, you don't, and anyone telling you otherwise is selling ceremony.

The honest version of "might" matters, though. Most owners who confidently say "we don't use AI" are describing their own habits, not their team's. Staff adopt these tools quietly, through personal accounts, because they make work faster. The question isn't whether you've rolled AI out; it's whether you can rule out that anyone is using it. Few businesses can.

The three Australian triggers in 2026

Until recently, an AI policy was enterprise theatre for a five-person business. Three things changed that this year:

1. The Privacy Act follows the data. If an employee pastes customer records into a public chatbot, that's a disclosure of personal information your business is responsible for — the same as sending it to any outside party. The Privacy Act's "reasonable steps" expectation applies to how personal information is handled, wherever it goes, and the Office of the Australian Information Commissioner (oaic.gov.au) has published guidance applying the existing principles to AI. Reforms have been steadily narrowing the small-business exemption, so "the Act doesn't apply to us" is a weaker position every year.

2. Standards started naming it. SMB1001:2026 — a private, tiered cyber-security certification standard for Australian SMBs — includes a responsible-AI-use policy among its Gold-level controls. Not law, but a clear marker of where expectations for small businesses are heading. The Australian Signals Directorate (cyber.gov.au) has likewise flagged a possible AI chapter for the Essentials series, the framework succeeding the Essential Eight.

3. Questionnaires are catching up. Insurer proposal forms and big-customer vendor questionnaires are starting to ask how businesses govern AI use — the same pattern MFA questions followed a few years ago. When the question arrives, "here's our policy" is a one-line answer.

Do you actually need one? What having a policy involves

Less than you'd think. A workable small-business AI policy is about a page:

  • An approved-tools list — which AI tools are okay, used through business accounts.
  • Data rules — personal information, credentials, and confidential material never go into AI tools. This is the load-bearing section.
  • Human review — AI output is a draft; a person checks it and owns it before it ships.
  • A review date — annually, because these tools change faster than other software.

It sits comfortably alongside the security baseline most Australian small businesses are already being asked about. If you're working through the Essential Eight — MFA, backups, patching, restricting admin access — the AI policy is the same kind of exercise: a recognised control, written down, reviewed each year before your insurance renewal. Tackle it in the same sitting and it costs you an afternoon, not a project.

If you want the full section-by-section outline, we've published one: AI use policy for Australian small business: a template. It's drafted so you can write your own; nothing is gated.

When you can skip it

Honesty builds more trust than upsell, so: a solo operator who doesn't use AI tools, or a team whose work never touches customer or personal information, gets marginal value from a stand-alone policy. A two-line rule inside your acceptable use policy — AI tools may not be used with business or customer information without the owner's approval — covers the future without the paperwork.

Everyone else: it's a page, it takes an afternoon, and it converts your biggest new data-leak channel from unmanaged to managed.

A quick worked example

Picture a six-person accounting practice. Nobody "rolled out AI." But one bookkeeper drafts client emails in ChatGPT, another summarises meeting notes with an AI transcription app, and the office manager trialled an AI tool that reads invoices. Three tools, three personal logins, and client financial details flowing into all of them — none of it visible to the owner, none of it against any agreed rule.

Nothing here is malicious; it's ordinary time-saving. But if a broker's proposal form asks "how does your business govern staff use of AI tools?", the honest answer today is "it doesn't." A one-page policy changes that answer to "here's our approved-tools list and our data rules" — and, more importantly, gives the three staff a rule that stops client data going somewhere it shouldn't. That's the whole value: not paperwork, but a decision made once instead of improvised sixty times a year.

If you'd like it generated rather than drafted, our document pack produces an AI Use Policy alongside the security policies insurers ask about — personalised from the same free 20-minute self-assessment that gives you your Essential Eight snapshot. General information throughout, not legal advice; if your data is unusually sensitive, get a professional read of whatever you adopt.

FAQ

Is an AI policy required by law in Australia? No. There is no Australian law requiring a business to have an AI use policy. The legal exposure comes indirectly: the Privacy Act governs personal information wherever staff send it, including into AI tools. A policy is how you manage that exposure, not a legal obligation in itself.

What happens without an AI policy? Nothing — until something happens. The realistic failure is an employee pasting customer information into a public AI tool, which can be a disclosure your business is responsible for under the Privacy Act if it involves personal information. Without a policy there is no agreed rule that says not to, and no answer when an insurer or big customer asks how you govern AI use.

Is one page really enough? For most small businesses, yes. The policy needs an approved-tools list, rules about what data must never be entered, a human-review requirement, and a review date. Length adds ceremony, not protection.

We don't use AI at all — do we still need one? If genuinely nobody uses AI tools for work, a policy adds little — though a two-line rule in your acceptable use policy ("AI tools may not be used with business information without approval") future-proofs the position for the day someone quietly starts.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).