Skip to content

Published 18 July 2026

Does your small business need an AI policy?

Straight answer first. If anyone on your team uses AI tools with business or customer information, or might, then yes, you need an AI use policy. If genuinely nobody does, you don't. Anyone telling you otherwise is selling ceremony.

That word "might" is doing real work, though. Most owners who say "we don't use AI" with total confidence are describing their own habits, not their team's. Staff pick these tools up quietly, on personal accounts, because they make the job faster. So the real question isn't whether you've rolled AI out. It's whether you can rule out that anyone is using it. Few businesses can.

The three Australian triggers in 2026

Until recently, an AI policy for a five-person business was enterprise theatre. Three things changed that this year.

1. The Privacy Act follows the data. If an employee pastes customer records into a public chatbot, that's a disclosure of personal information your business is responsible for. Same as sending it to any outside party. The Privacy Act's "reasonable steps" expectation applies to how personal information is handled wherever it ends up, and the Office of the Australian Information Commissioner (oaic.gov.au) has published guidance applying the existing principles to AI. Reforms have been steadily narrowing the small-business exemption too, so "the Act doesn't apply to us" gets weaker every year.

2. Standards started naming it. SMB1001:2026, a private, tiered cyber security certification standard for Australian SMBs, includes a responsible-AI-use policy among its Gold-level controls. It's not law. It is a clear marker of where expectations for small businesses are heading. The Australian Signals Directorate (cyber.gov.au) has also flagged a possible AI chapter for the Essentials series, the framework succeeding the Essential Eight.

3. Questionnaires are catching up. Insurer proposal forms and big-customer vendor questionnaires are starting to ask how businesses govern AI use. MFA questions followed the same path a few years ago. When the question lands, "here's our policy" is a one-line answer.

Do you actually need one? What having a policy involves

Less than you'd think. A workable small-business AI policy runs to about a page:

  • An approved-tools list. Which AI tools are okay, used through business accounts.
  • Data rules. Personal information, credentials and confidential material never go into AI tools. This is the section holding everything up.
  • Human review. AI output is a draft. A person checks it and owns it before it goes anywhere.
  • A review date. Once a year, because these tools change faster than other software.

It sits comfortably next to the security baseline most Australian small businesses are already being asked about. If you're working through the Essential Eight (MFA, backups, patching, restricting admin access), the AI policy is the same kind of job: a recognised control, written down and reviewed each year before your insurance renewal. Do it in the same sitting and it costs you an afternoon. Not a project.

Want the full section-by-section outline? We've published one: AI use policy for Australian small business: a template. It's written so you can draft your own, and nothing is gated.

When you can skip it

Being honest earns more trust than an upsell, so here it is. A solo operator who doesn't use AI tools, or a team whose work never touches customer or personal information, gets very little from a stand-alone policy. A two-line rule inside your acceptable use policy covers the future without the paperwork: AI tools may not be used with business or customer information without the owner's approval.

Everyone else? It's a page. It takes an afternoon. And it turns your biggest new data-leak channel from unmanaged into managed.

A quick worked example

Picture a six-person accounting practice. Nobody "rolled out AI." But one bookkeeper drafts client emails in ChatGPT, another summarises meeting notes with an AI transcription app, and the office manager trialled an AI tool that reads invoices. That's three tools on three personal logins, with client financial details flowing into all of them. The owner can't see any of it, and none of it breaks an agreed rule, because there isn't one.

Nobody here is doing anything malicious. It's ordinary time-saving. But if a broker's proposal form asks "how does your business govern staff use of AI tools?", the honest answer today is "it doesn't." A one-page policy changes that answer to "here's our approved-tools list and our data rules." More to the point, it gives those three staff a rule that stops client data going somewhere it shouldn't. That's the whole value. Not paperwork. A decision made once instead of improvised sixty times a year.

If you'd rather have it generated than write it yourself, our document pack produces an AI Use Policy alongside the security policies insurers ask about. It's personalised from the same free 20-minute self-assessment that gives you your Essential Eight snapshot. Everything here is general information, not legal advice. If your data is unusually sensitive, get a professional to read whatever you adopt.

FAQ

Is an AI policy required by law in Australia? No. No Australian law requires a business to have an AI use policy. The legal exposure is indirect: the Privacy Act governs personal information wherever staff send it, and that includes AI tools. A policy is how you manage that exposure. It isn't a legal obligation in itself.

What happens if we don't have an AI policy? Nothing, until something does. The realistic failure is an employee pasting customer information into a public AI tool, which can be a disclosure your business is responsible for under the Privacy Act if it involves personal information. Without a policy there's no agreed rule saying not to, and no answer when an insurer or big customer asks how you govern AI use.

Is one page really enough? For most small businesses, yes. The policy needs an approved-tools list, rules on what data never gets entered, a human-review requirement and a review date. Extra length adds ceremony, not protection.

We don't use AI at all. Do we still need one? If genuinely nobody uses AI tools for work, a policy adds little. A two-line rule in your acceptable use policy ("AI tools may not be used with business information without approval") still future-proofs you for the day someone quietly starts.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).