Skip to content

Guide

A one-page AI policy template for Australian organisations

By , APAC Lead & Board Member, AIREUpdated

Most Australian organisations need an AI policy that fits on one page. It names the approved tools and what each may be used for, sorts your information into classes that may or may not go into them, and requires a person to check AI output before it reaches a customer, commits money or is published. It also says when clients are told, who owns AI risk and who to ask, how new tools get approved, how mistakes get reported, and when the policy is next reviewed. The template below does that in plain language, with square brackets for your details. It follows the OAIC's advice on personal information and AI, and covers each point the National AI Centre says a policy should settle. It is general information, not legal advice.

The one-page AI policy template

Copy everything from the policy's heading to its review date into your own document. Replace each [square bracket] with your details, and delete any bracketed option that doesn't apply. It is written to fit on one page once your details are in.

General information, not legal advice. This is a starting point for a rule your staff will follow. It doesn't replace advice on your own obligations, and organisations in regulated industries, such as financial services, health and legal practice, may need more.

[Organisation name] AI policy

Version [1.0], approved by [name, role] on [date]. It applies to everyone who works for [organisation name], including contractors [and volunteers]. Breaches are handled under [our code of conduct].

  1. Approved tools. Use these AI tools for work, signed in with your [organisation name] account, for the uses listed:
    • [Tool and plan, for example ChatGPT Business]: [drafting, summarising and research on public information].
    • [Tool and plan, for example Microsoft 365 Copilot]: [email, meeting notes and documents inside our Microsoft 365].
    • [Tool and plan]: [what it may be used for].

    A personal or free account may be used for public information only (clause 2). Any other tool, or any other use, needs approval under clause 6.

  2. What may go in. All information fits one of five classes. If something fits more than one, the stricter rule applies.
    • Public: anything already published, by us or anyone else. Any AI tool.
    • Internal: procedures, internal emails and drafts with no client or personal details. Approved tools only.
    • Confidential: financials, pricing, strategy, contracts, board papers and anything marked confidential. Only [tools approved for confidential data].
    • Personal information: anything about an identifiable person, including customers, staff and job applicants. [Only tools approved for personal information / Not in any AI tool.] Sensitive information, such as health details, never goes in without [AI owner]'s written approval.
    • Client data: anything a client gives us or we produce for them. Only [tools approved for client data], and only where the client's contract allows it.

    Passwords, access keys and card or bank details never go into any AI tool. If you can't tell which class something is, treat it as the stricter one and ask [AI owner].

  3. Check before it leaves. A person reads and checks AI output before it reaches a customer, commits money or is published. Check the facts, figures, names and anything quoted. The person who sends it is responsible for it. AI never makes a decision about a person, such as hiring, performance or [eligibility], on its own.
  4. Telling clients. Tell a client when AI did a material part of work they are paying for, when their contract requires it, or when they might think they are dealing with a person. [Our chatbot tells people it is AI.] Our privacy policy says how we use AI with personal information.
  5. Who owns AI risk. [Name, role] owns AI risk and this policy. If you are unsure about anything in it, ask them at [email or channel] before you go ahead. [Name, role] manages the settings on each approved tool.
  6. New tools and new uses. Ask [AI owner] before you use a new AI tool, switch on an AI feature in software we already use, or use an approved tool for something not listed in clause 1. Free trials count. They check where the data goes, whether the vendor trains on it and who can see it, and reply within [five working days]. Any use that makes or shapes a decision about a person needs their approval [and a written risk assessment].
  7. Mistakes and incidents. If something went into a tool that shouldn't have, or AI output caused a problem that reached someone outside [organisation name], tell [AI owner] [the same day]. Report it even if you're not sure it matters. [AI owner] decides what happens next, including whether it is a notifiable data breach.
  8. Review. [AI owner] reviews this policy every [six months], and sooner after an incident, a new tool or a change in the law. Next review: [date].

End of template. The approved tools in clause 1 will change more often than the rules do, so keep that list current between reviews.

What each clause is for

Approved tools

Name the tool and the plan, because the plan decides what the vendor does with your data and what your admins can control. For ChatGPT, our ChatGPT for business guide sets out how each plan handles data.

Write the use next to each tool. "ChatGPT Business for drafting and summarising" tells people what yes looks like. A bare list of tools leaves them guessing. List the AI built into software you already pay for as well. The National AI Centre's register guidance says to capture AI features embedded in common software, and they are easy to miss.

The template lets people use a personal or free account for public information only. That keeps harmless jobs, such as rewording a media release you have already published, out of the approval queue.

What may go in

This clause is the one-page data-handling rule, and the core of any AI policy. Five classes are few enough to remember and cover most of what an organisation holds.

The five data classes and where each may go
ClassExamplesWhere it may goWhy
PublicAnything already published, by you or anyone else: website copy, annual reports, media releasesAny AI tool, including a personal accountIt is already public. Nothing is lost if a vendor sees it.
InternalProcedures, internal emails, meeting notes and drafts with no client or personal detailsApproved tools, on your organisation's accountsLow harm if exposed, but it was never meant for outsiders.
ConfidentialFinancials, pricing, strategy, contracts, board papers, anything marked confidentialOnly the tools you approve for confidential dataExposure would hurt the business or break a promise to someone else.
Personal informationCustomer records, staff files, job applications, anything that identifies a personOnly the tools you approve for personal information, or noneThe Privacy Act applies, and the OAIC recommends keeping it out of public generative AI tools.
Client dataAnything a client gives you or you produce for themApproved tools, and only where the client's contract allows itThe client's contract and your professional duties apply as well as privacy law.

Where information fits more than one class, the stricter rule applies. A published article that names one of your customers is public and personal information, so it follows the personal information rule.

Personal information is where the law bites. The OAIC says privacy obligations apply to any personal information put into an AI system, and to output that contains it. As a matter of best practice, it recommends against entering personal information, and particularly sensitive information, into publicly available generative AI tools. That is why the template keeps personal information out of personal accounts and asks for written approval before sensitive information goes anywhere.

The OAIC also lists cross-border disclosure (APP 8) among the obligations to consider when personal information goes into an AI chatbot. Client data carries the client's contract as well: a confidentiality clause can rule a tool out even where privacy law would allow it.

Check before it leaves

The three triggers are the points where a mistake stops being private. Before a customer sees it, money moves or it goes public, a wrong draft costs nothing. After that, someone has acted on it.

Naming the sender as responsible matters more than any checklist. The OAIC says a human should be responsible for verifying any personal information obtained through AI, and able to overturn decisions made with it. The National AI Centre's guidance calls for mandatory human review of high-stakes decisions, which is why the clause keeps AI from deciding anything about a person on its own.

Telling clients

Disclose where it matters. The clause names three cases: the client is paying for work AI did a material part of, their contract requires it, or they could mistake AI for a person.

The last case is the OAIC's own advice: public-facing AI tools such as chatbots should be clearly identified as AI, and privacy policies should explain how the organisation uses AI. From 10 December 2026, organisations covered by the Privacy Act that use personal information in automated decisions with the potential to affect people's rights or interests must also set out in their privacy policy the kinds of personal information used and the kinds of decisions made.

Who owns AI risk

One named person, senior enough to say no. The National AI Centre's guidance starts there: assign a senior leader as the overall AI governance owner, with enough authority and understanding to oversee all AI use in the organisation. In a smaller organisation it can be whoever already looks after technology or operations.

The contact line matters as much as the name. The policy works when asking is quicker than guessing.

New tools and new uses

The OAIC's guidance says due diligence on an AI product should consider whether it has been tested for the use you have in mind, how human oversight fits into the process, the privacy and security risks, and who will have access to the information that goes in or comes out. The clause asks the owner to check the same things in plainer words.

Set a turnaround and keep it. If approval takes a month, people use personal accounts in the meantime. Uses that shape decisions about people get the extra step because the same tool carries different risks in different uses. The National AI Centre's example: drafting marketing emails with AI is different from using it to assess job applications.

Mistakes and incidents

The clause is there to get the report made early, while a mistake is still cheap to fix. A wrong figure in a proposal is fixed by telling the client and correcting it. Personal information in the wrong tool may be more than that.

Under the Notifiable Data Breaches scheme, an organisation covered by the Privacy Act must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to someone whose personal information is involved. Whether a slip reaches that bar is the owner's call, with advice if they need it, which is why the report goes to them quickly.

Review

The National AI Centre's policy template suggests an annual review, with an earlier one after a significant AI-related incident, new AI technology that matters to you, or a change in laws, regulations or standards. This template suggests six months because the tools change faster than that. The owner can update the tool list in clause 1 between reviews without re-approving the whole policy.

The Australian guidance behind it

The template is short, but each clause traces back to Australian law or government guidance. This is what applies, and to whom.

The Privacy Act 1988

The OAIC says the Privacy Act applies to all uses of AI involving personal information. Its guidance on commercially available AI products, last updated in January 2025, is the one to read before you write a policy. Beyond the points above, it says personal information that AI generates or infers is a collection under APP 3. It also says personal information may be used only for the purpose it was collected for, unless the person consents, or would reasonably expect the new use and it relates to the original purpose (APP 6).

Most small businesses, meaning an annual turnover of $3 million or less, aren't covered by the Act, though some are. The template applies the same rules either way. Your clients will expect it, and turnover can cross the threshold.

The National AI Centre's guidance

The Voluntary AI Safety Standard, published in September 2024, set out 10 voluntary guardrails. In October 2025 the National AI Centre published the Guidance for AI Adoption, which updates and simplifies the standard into six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control.

The foundations version, for organisations starting out or using AI in low-risk ways, puts a senior owner and an AI policy first. The centre also publishes its own AI policy guide and template, a longer Word document built around roles such as an AI governance committee and an owner for each AI system.

Its checklist says a policy should make clear what AI can and can't be used for, who approves higher-risk use cases, what data staff can put into tools, when staff need to oversee AI use, how they report issues or misuse, and when the policy will be reviewed. The one-page template answers each of those, in clauses 1, 6, 2, 3, 7 and 8.

Government agencies

Commonwealth agencies work under the Digital Transformation Agency's policy for the responsible use of AI in government. Version 2.0 took effect on 15 December 2025 and applies to all non-corporate Commonwealth entities, with some exceptions. Its mandatory requirements include accountable officials, transparency statements, internal registers of AI use cases, staff training on AI and impact assessments of AI use cases.

A one-page staff rule can still help inside an agency, but it sits under that policy. State, territory and local government bodies should check what their own jurisdiction asks for.

How to roll the policy out

A policy sent round by email gets skimmed and filed. The real questions come later, when someone has a client file open and a deadline. Rolling it out means answering those questions before they come up.

  1. Set up the approved tools first: the business plans, single sign-on and data settings. Then the policy describes something that exists.
  2. Test the draft with a few of the people who will follow it, including at least one cautious user and one confident one. Rewrite anything they read differently. The National AI Centre gives the same advice.
  3. Run a short session on the team's own work. Go through the five data classes with real documents, and practise what goes in and what stays out.
  4. Put the policy where people work: pinned in the team chat, on the intranet and in the onboarding pack.
  5. Go back after a month. Ask what was unclear, fix the wording and update the tool list.

That session is what our AI training for teams is built around. It includes a governance module on exactly this, practised on each person's own documents, and 96% of participants said they were likely to apply what they learned (Post-training survey, n=220, October 2025 to September 2026).

What to add as your AI use grows

The one-page policy is the floor. As AI moves from chat assistants into systems that deal with customers or shape decisions, add these.

  • A register of AI use. A table of every AI system you use, what it is used for, who is accountable and how much governance it needs, including AI features inside software you already own. The National AI Centre publishes a register template as a Word document and a spreadsheet.
  • Risk screening and assessment. A short screen for each new use that flags the ones needing more attention, then a proper risk and impact assessment for those. The centre's foundations guidance describes both.
  • A fuller policy with named roles. Once you build or buy AI systems beyond assistants, the centre's longer template adds a policy approver, a compliance monitor, a governance committee and an owner for each system.
  • Alignment with ISO/IEC 42001. The international standard for an AI management system, adopted unchanged in Australia as AS ISO/IEC 42001:2023 in February 2024. It sets requirements for the whole management system, from policy and leadership to performance evaluation, plus AI controls such as data quality, impact assessment and human oversight. Your one-page policy becomes one document inside it. See our ISO/IEC 42001 guide for Australian organisations for what the standard asks for and when certification is worth it.

If you would rather not start from a blank page, our AI governance work writes the one-page rule with you, against the Privacy Act 1988, the ACSC Essential Eight and your industry's own obligations. A draft lands within a week, and we test it with the people who have to follow it until the cautious and the confident read it the same way.

Want the policy written with you and tested on your team? The discovery call is free and takes 30 minutes.

Frequently asked questions

Do we need an AI policy?

If anyone in your organisation uses AI for work, yes. Without a written rule, cautious staff avoid the tools and confident ones paste in whatever they like. The Privacy Act already applies to personal information put into AI tools, and the National AI Centre's guidance lists an AI policy among the first steps for any organisation using AI. Non-corporate Commonwealth entities must also meet the Digital Transformation Agency's policy for the responsible use of AI in government.

What should an AI policy include?

Eight things: which tools are approved and what each may be used for, what data may go into them, who checks AI output before it reaches a customer, commits money or is published, when clients are told, who owns AI risk and who to ask, how new tools get approved, how mistakes are reported, and when the policy is next reviewed. The National AI Centre's checklist for an AI policy asks for much the same. Keep it to a page, so people read it.

Can staff put client data into ChatGPT?

Not into a free or personal account. Client data should only go into an AI tool your organisation has approved for it, on a business account your admins control, and only where the client's contract allows it. If the client data includes personal information, the Privacy Act applies, and the OAIC recommends as best practice against entering personal information, particularly sensitive information, into publicly available generative AI tools. Our ChatGPT for business guide sets out how each ChatGPT plan handles data.

Is there an AI policy template for Australian businesses?

Yes. The one-page template on this page is written for Australian organisations and the Privacy Act, with square brackets for your own details. The National AI Centre also publishes an AI policy guide and template as a Word document, aligned with the government's Guidance for AI Adoption. It is longer and built around roles such as an AI governance committee and an owner for each AI system, which suits an organisation that builds or buys AI systems, not only chat assistants.

Does the Privacy Act apply to what staff put into AI tools?

Yes, where it is personal information and your organisation is covered by the Act. The OAIC says privacy obligations apply to personal information put into an AI system and to output that contains it, and that personal information generated or inferred by AI is a collection under APP 3. Most small businesses, meaning an annual turnover of $3 million or less, aren't covered, but some are, so check before you rely on it.

Who should own AI risk?

One named senior person with the authority to say yes or no. The National AI Centre's guidance starts with assigning a senior leader as the overall AI governance owner. In a smaller organisation it can be whoever already looks after technology or operations. Staff need to know who it is and how to reach them, because the policy only works when asking is quicker than guessing.

How often should an AI policy be reviewed?

Set a date and keep it. The National AI Centre's template suggests an annual review, with an earlier one after a significant AI-related incident, new AI technology that matters to you, or a change in the law. Our template suggests every six months because the tools change quickly. Keep the list of approved tools current between reviews.

Sources

Every rule and date on this page comes from the OAIC, the National AI Centre, the Digital Transformation Agency or Standards Australia. We read each source on 30 September 2026. Guidance changes, so check the source before you rely on it.

  1. Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products (published 21 October 2024, updated 17 January 2025). Read 30 September 2026.
  2. Office of the Australian Information Commissioner, Small business. Read 30 September 2026.
  3. Office of the Australian Information Commissioner, Australian Privacy Principles quick reference. Read 30 September 2026.
  4. Office of the Australian Information Commissioner, About the Notifiable Data Breaches scheme. Read 30 September 2026.
  5. Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision Making (published 18 May 2026) (the 10 December 2026 privacy policy obligation). Read 30 September 2026.
  6. Department of Industry, Science and Resources (National AI Centre), Voluntary AI Safety Standard (published 5 September 2024, updated 2 December 2025). Read 30 September 2026.
  7. National AI Centre, Guidance for AI adoption: foundations. Read 30 September 2026.
  8. National AI Centre, Create an AI policy (and the AI policy guide and template it links, a Word document published 22 April 2026). Read 30 September 2026.
  9. National AI Centre, AI systems register. Read 30 September 2026.
  10. Digital Transformation Agency, Policy for the responsible use of AI in government, version 2.0 (last updated 1 December 2025). Read 30 September 2026.
  11. Standards Australia, Spotlight on: AS ISO/IEC 42001:2023, Artificial intelligence: Management system (5 September 2025). Read 30 September 2026.

All AIRE guides

A rule people will actually follow

Book a free 30-minute call. We'll look at how your team uses AI now and what your policy needs to say, and we can write it with you.

No obligation and no sales pitch.