Back
AI Governance

AI policy template for Australian businesses (free, copy-ready)

A complete AI acceptable-use policy template built for Australian law. Copy it, fill in your company name, and have a working policy by Friday.

Short answer: You need an AI acceptable-use policy that names your approved tools, draws a hard line around personal and customer data under the Privacy Act 1988, assigns a human reviewer to every consequential output, and tells staff what to do when they are unsure. Below is the full template. Copy it, adjust the company name and tool list, and have your board or leadership sign off by Friday.

Why Australian businesses need an AI policy now

Most Australian businesses are already using AI. At Bulletproof we see it in almost every audit. The question is whether they know it, and whether anyone has decided what the rules are. When an employee pastes a customer complaint into ChatGPT to draft a reply, that is a disclosure of personal information under Australian Privacy Principle 6. If the complaint contains health information, it may also be sensitive information under the Privacy Act 1988 (Cth), which triggers stricter consent requirements.

There is no standalone AI Act in Australia yet. The federal government's approach, as of September 2026, rests on three pillars: the existing Privacy Act 1988 (amended in December 2024)1, the Voluntary AI Safety Standard2 published by the Department of Industry, Science and Resources in September 2024, and sector-specific regulation such as APRA CPS 234 for financial services. A proposals paper on mandatory guardrails for high-risk AI settings closed for consultation in October 2024, but no mandatory AI-specific legislation has passed.

That means the legal floor is the Privacy Act, not an AI-specific law. And the Privacy Act already applies to every AI use case that touches personal information. The OAIC's guidance on generative AI3 makes this explicit: the Australian Privacy Principles apply to all uses of AI involving personal information, including where information is used to train, test or use an AI system.

From 10 December 20264, the Privacy and Other Legislation Amendment Act 2024 will require organisations to disclose in their privacy policies how personal information is used in substantially automated decisions that affect individuals' rights or interests. If you do not have a policy by then, you are not just exposed to risk. You are non-compliant.

What an Australian AI policy actually needs to cover

Government guidance documents and the Voluntary AI Safety Standard describe principles. Principles are useful for a strategy document. They are not useful for the person in accounts who wants to know whether they can paste an invoice into Claude. Your policy needs to answer that question in one sentence.

Here is what must be in the document, and why:

  • Scope and applicability: who is bound (all staff, contractors, temps) and what counts as an AI tool. If you skip this, people will argue that Excel's autofill does not count.
  • Approved and prohibited tools: a named list of what your organisation has sanctioned, and a short list of what is explicitly banned. Naming tools removes ambiguity.
  • Data that must never enter an AI tool: the bright line. Customer personal information, health records, financial data, legal documents, and anything covered by a confidentiality agreement. This is where Privacy Act compliance lives or dies.
  • Human review and accountability: every AI output used in a decision that affects a person (a customer, an employee, a supplier) must be reviewed by a named human before it is sent or acted on. The Voluntary AI Safety Standard's Guardrail 5 calls this meaningful human oversight.
  • Disclosure to clients and customers: when and how you tell people that AI was involved. The Voluntary AI Safety Standard's Guardrail 6 requires user transparency about AI-enabled decisions and AI-generated content.
  • Record keeping: what you log, where, and for how long. Guardrail 9 of the Voluntary AI Safety Standard requires records sufficient for a third party to assess compliance.
  • Who to ask: a named person, not a team inbox. When someone is unsure, the friction of finding the right person is usually enough to make them guess instead.

Those seven components are one path, not seven separate rules. A staff member has a task, checks the data against Section 4, and either stops and asks or proceeds through an approved tool to review, record and disclosure.

Diagram of the AI policy obligation path: a staff task goes to a data check, which either stops for the policy owner or proceeds through an approved tool to human review, a record log and disclosure

The template

Copy the sections below. Replace [Company Name] with your organisation's name, adjust the tool list to match what you actually use, and review with your leadership team. This template aligns with the Australian Privacy Principles, the Voluntary AI Safety Standard's 10 guardrails, and APRA CPS 234 obligations where applicable.

1. Purpose and scope

This policy governs the use of artificial intelligence tools and systems by all employees, contractors, and third-party service providers of [Company Name]. It applies to any software that generates, summarises, classifies, or predicts content using machine learning or large language models, whether provided by [Company Name] or accessed independently.

This policy takes effect on [date] and will be reviewed every six months, or immediately following a material change in Australian privacy or AI regulation.

2. Approved AI tools

The following tools are approved for use within [Company Name], subject to the conditions in this policy:

Tool Approved use Data restrictions
[e.g. Microsoft Copilot, enterprise licence] [e.g. drafting internal documents, summarising meeting notes] [e.g. no customer PII, no financial data]
[e.g. ChatGPT Team] [e.g. research, first-draft copy, code review] [e.g. no client names, no confidential project details]
[e.g. Claude for Business] [e.g. policy drafting, data analysis on de-identified data] [e.g. no raw personal information]

Any tool not on this list requires written approval from [AI Policy Owner, name and role] before use. Free-tier and personal-account versions of approved tools are not approved unless explicitly listed, because their data-handling terms differ from enterprise agreements.

3. Prohibited uses

The following uses of AI are prohibited at [Company Name], regardless of the tool:

  • Making or communicating a decision about a customer, employee, or supplier based solely on AI output, without human review.
  • Entering personal information (as defined in the Privacy Act 1988) into any AI tool, unless the tool is on the approved list with an enterprise data processing agreement and the use falls within the approved-use column.
  • Using AI to generate legal advice, regulatory filings, or financial statements without review by a qualified professional.
  • Using AI to profile, score, or rank individuals (customers, employees, or applicants) without explicit authorisation from [AI Policy Owner] and a completed impact assessment.
  • Representing AI-generated work as original human work in any client deliverable, unless disclosed under Section 6 of this policy.
  • Using AI tools to circumvent access controls, generate deceptive content, or impersonate any person.

4. Data that must never be entered into an AI tool

The following categories of information must never be entered into any AI tool, including approved tools, unless a specific exception has been granted in writing by [AI Policy Owner]:

  • Customer personal information: names, contact details, account numbers, complaint records, or any information that identifies or could reasonably identify a customer. This obligation arises from Australian Privacy Principles 3, 6, and 11.
  • Sensitive information (as defined in s 6 of the Privacy Act 1988), including: health information, genetic information, racial or ethnic origin, political opinions or political association membership, religious beliefs or affiliations, philosophical beliefs, sexual orientation or practices, criminal records, biometric information used for automated verification or identification, or trade union membership.
  • Employee personal or HR records: performance reviews, medical certificates, disciplinary records, salary details, or Tax File Numbers.
  • Financial data: bank account details, credit card numbers, transaction records, or unpublished financial results.
  • Legally privileged material: correspondence with lawyers, legal opinions, or documents prepared in anticipation of litigation.
  • Information subject to a confidentiality agreement or NDA: any material where disclosure to a third party would breach a contractual obligation.

If you are unsure whether information falls into one of these categories, do not enter it. Contact [AI Policy Owner, name] at [email/phone] first.

5. Human review and accountability

Every AI-generated output that will be used in a decision affecting a person, sent to a client, published externally, or included in a regulatory filing must be reviewed by a qualified human before use. The reviewer is responsible for the accuracy and appropriateness of the final output, not the AI tool.

For the purposes of this policy, the reviewer must:

  • Have the subject-matter expertise to assess the output's accuracy.
  • Confirm that no prohibited data was used as input.
  • Record their name, the date, and the nature of the review in [your review log, e.g. a shared register, a field in your project management tool].

This requirement reflects Guardrail 5 (human control) of the Voluntary AI Safety Standard: enable human control or intervention in an AI system to achieve meaningful human oversight.

6. Disclosure to clients and customers

[Company Name] will disclose the use of AI to clients and customers in the following circumstances:

  • When AI has been used to generate or substantially draft a client deliverable.
  • When AI is used in any automated or semi-automated decision that affects a customer's rights, access to services, or financial position.
  • When a customer or client asks whether AI was used.

Disclosure must be made in plain language, either in the deliverable itself or in accompanying correspondence. The form of disclosure is: "This [document/analysis/summary] was prepared with the assistance of AI tools and reviewed by [name, role]."

From 10 December 2026, the Privacy Act will require that your privacy policy describes how personal information is used in substantially automated decisions affecting individuals. Review your privacy policy before that date.

7. Record keeping

[Company Name] will maintain the following records relating to AI use:

  • A register of all approved AI tools, including the vendor, the data processing agreement, and the date of last review.
  • A log of human reviews conducted under Section 5, retained for [period, e.g. 7 years, or as required by your industry regulator].
  • A record of any AI-related incidents (data entered in error, inaccurate outputs acted upon, client complaints), including the remediation steps taken.
  • An annual review of this policy, with a record of changes made and the reasons for those changes.

This aligns with Guardrail 9 of the Voluntary AI Safety Standard: keep and maintain records to allow third parties to assess compliance.

8. Who to ask

The AI Policy Owner for [Company Name] is [Name, Role, email, phone]. This person is responsible for:

  • Approving or rejecting requests to use new AI tools.
  • Granting exceptions to the data restrictions in Section 4.
  • Investigating and responding to AI-related incidents.
  • Conducting the six-monthly policy review.
  • Reporting to [the board / senior leadership / the compliance committee] on AI use, risks, and incidents.

If the AI Policy Owner is unavailable, contact [Backup Name, Role, email].

9. Consequences of breach

A breach of this policy will be treated as a breach of [Company Name]'s Code of Conduct. Consequences may include retraining, formal warning, or termination, depending on the severity and intent. A breach that results in unauthorised disclosure of personal information may also trigger notification obligations under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988).

10. For APRA-regulated entities

If [Company Name] is regulated by APRA (banks, insurers, superannuation funds), AI systems that process, store, or transmit information assets fall within the scope of Prudential Standard CPS 2345 (Information Security). This means:

  • The board is ultimately responsible for ensuring AI-related information security is commensurate with the size and extent of threats.
  • AI-related information assets must be classified by criticality and sensitivity.
  • Security controls for AI tools and outputs must be tested systematically.
  • Material AI-related security incidents must be notified to APRA within 72 hours, and material control weaknesses within 10 business days.

If you operate in financial services, treat this section as mandatory and have your compliance team review it against your existing CPS 234 framework.

How to roll this out in a week

A policy that sits in a shared drive unread is worse than no policy, because it creates the illusion of governance without the substance. Here is a realistic five-day rollout for a business of 20 to 200 people.

Day 1 (Monday): Copy the template above. Replace every placeholder. Name the AI Policy Owner. List your actual approved tools, not the ones you wish you used. If you do not know what tools your team is already using, send a one-question survey before you do anything else: "Which AI tools have you used for work in the last month?"

Day 2 (Tuesday): Have the AI Policy Owner and one senior leader review the draft. Check it against your existing privacy policy and any client contracts that mention data handling or confidentiality. If you are APRA-regulated, run Section 10 past your compliance team.

Day 3 (Wednesday): Circulate the policy to all staff with a short note explaining why it exists and when it takes effect. Do not bury it in a 40-page handbook. Send it as a standalone document with a subject line that says what it is.

Day 4 (Thursday): Run a 30-minute briefing (in person or over video) with each team. Walk through three scenarios relevant to their work. For a finance team: "Can I paste this invoice into ChatGPT to extract the line items?" For a customer service team: "Can I use AI to draft a reply to this complaint?" For HR: "Can I use AI to summarise these interview notes?" The answer to most of these is "it depends on what data is in it," and the point is to make people comfortable asking the question.

Day 5 (Friday): Leadership signs off. The policy takes effect. Set a calendar reminder for the six-month review. Log the date in your governance register.

If you are starting from nothing, that is genuinely enough to have a defensible policy in place. It will not be perfect. You will revise it after a month when someone asks a question the policy does not answer. That is fine. A living policy that improves is better than a perfect document that arrives six months late.

If you have already started integrating AI into your workflows, you are past the point where a policy is optional. The tools are in use. The question is whether the rules catch up before something goes wrong.

What the government frameworks actually say

Three federal instruments matter for most Australian businesses. None of them are mandatory AI-specific laws (yet), but the Privacy Act is mandatory and it applies to AI whether or not you have a policy.

The Privacy Act 1988 (Cth), amended December 2024. The Privacy and Other Legislation Amendment Act 2024 passed Parliament on 29 November 2024 and received Royal Assent on 10 December 2024. It progressed 23 proposals from the Privacy Act Review. Key changes include a statutory tort for serious invasions of privacy, a Children's Online Privacy Code framework, and (from 10 December 2026) a requirement to disclose automated decision-making in privacy policies. The existing Australian Privacy Principles (APPs 3, 6, 11 in particular) already govern how personal information may be collected, used, and secured in AI systems.

The Voluntary AI Safety Standard (September 2024). Published by the Department of Industry, Science and Resources, this sets out 10 guardrails6 covering accountability, risk management, data governance, testing, human control, transparency, contestability, supply chain transparency, record keeping, and stakeholder engagement. It is voluntary. It does not create new legal obligations. But it is the closest thing to an accepted national framework, and aligning your internal policy with it is a reasonable way to demonstrate due diligence if something goes wrong. In October 2025, the government published updated guidance simplifying the 10 guardrails into six essential practices.

The government's AI-in-government policy (Version 2.0, December 2025). Published by the Digital Transformation Agency at digital.gov.au7, this applies to non-corporate Commonwealth entities. It is not binding on private businesses, but it is worth reading because it reflects the direction of travel: mandatory AI impact assessments, designated accountable owners for each AI use case, and mandatory staff training within 12 months. If the government is requiring this of itself, it is reasonable to expect similar expectations to flow to regulated industries and then to government contractors.

State governments are moving independently. NSW has a mandatory AI framework for its agencies under circular DCS-2026-028 (issued July 2026), requiring AI use case registration, risk assessments, and annual attestations. If you work with NSW government clients, understanding their framework helps you anticipate what they will ask of their suppliers.

What the EU AI Act means for Australian businesses

Almost nothing, for most of you. The EU AI Act does not directly bind an Australian company unless that company places an AI system on the EU market, puts an AI system into service in the EU, or is a provider or deployer whose AI system's output is used in the EU. If you are an Australian accounting firm using ChatGPT to draft client memos, the EU AI Act is not your problem. Your problem is the Privacy Act.

Mention it in board papers if your business sells software or services into the EU. Otherwise, spend your time on the instruments that actually apply to you.

Frequently asked questions

Do Australian businesses legally need an AI policy?

There is no law requiring an AI-specific policy. But the Privacy Act 1988 already requires you to protect personal information from misuse and unauthorised disclosure (APP 11), and to use it only for its collected purpose (APP 6).9 If your staff use AI tools with customer data and you have no policy governing that use, you have a compliance gap, not a policy gap. The policy is how you close it.

Does the Voluntary AI Safety Standard apply to my business?

It is voluntary, so it creates no legal obligation. However, it represents the Australian Government's view of responsible AI practice, and aligning with its 10 guardrails is a reasonable way to demonstrate due diligence. If a regulator or court ever asks what you did to manage AI risk, "we followed the national standard" is a better answer than "we did not know there was one."

What happens if an employee pastes customer data into ChatGPT?

Under Australian Privacy Principle 6, that is likely an unauthorised disclosure of personal information to a third party (the AI provider). If the data includes sensitive information, the breach is more serious. If it meets the threshold for likely serious harm, you must complete an assessment within 30 days and notify the OAIC and affected individuals as soon as practicable under the Notifiable Data Breaches scheme. Your policy should make this scenario explicitly prohibited.

Should we ban AI tools entirely to avoid the risk?

That is a choice, but it is not a realistic one for most businesses. If you ban AI outright, people will use it anyway on personal devices and you will have less visibility, not more. A better approach is to approve specific tools under specific conditions, draw a clear line around prohibited data, and make it easy for people to ask questions. Managed use with guardrails beats an unenforceable ban.

How often should we review our AI policy?

Every six months at minimum. AI tools change their terms of service, data handling, and capabilities frequently. The Australian regulatory environment is also moving: the Privacy Act's automated decision-making disclosure requirement takes effect in December 2026, and mandatory AI guardrails are still under consultation. Set a calendar reminder for the review. Assign it to the AI Policy Owner by name, not to a committee.

Does APRA CPS 234 apply to AI tools?

Yes. CPS 234 is technology-neutral. It applies to any information asset, which includes AI systems that process, store, or transmit information within an APRA-regulated entity. If you are a bank, insurer, or superannuation fund, your AI tools and the data they handle must be classified, secured, and tested under your existing CPS 234 framework. Material incidents involving AI must be reported to APRA within 72 hours.