Copyable AI policy starter
Purpose. We use AI only where it supports a legitimate business outcome and can be used safely, lawfully and fairly.
Approved use. Staff may use approved tools for approved workflows. New tools or uses require the nominated AI owner’s approval.
Information. Do not enter personal, sensitive, confidential, client-owned, security or commercially restricted information unless that use has been specifically assessed and approved.
Human responsibility. A person remains responsible for checking accuracy, context, bias, intellectual property, tone and compliance before an output is used.
High-impact decisions. AI must not make unsupervised decisions about employment, safety, health, credit, eligibility, legal rights or other significant outcomes.
Transparency. We explain material AI use to customers or affected people when appropriate or required.
Incidents. Staff stop the workflow and report suspected disclosure, harmful output, material inaccuracy or unexpected behaviour to the AI owner.
Complete these fields before adoption
- AI owner: [name / role]
- Approved tools: [list and account type]
- Approved workflows: [list]
- Prohibited information: [examples specific to your business]
- Required reviewers: [workflow and role]
- Incident contact and immediate steps: [details]
- Review date: [at least every six months and after material change]
Why an AI register matters
Keep a simple register with the tool, vendor, owner, purpose, information used, affected people, human control, main risks, approval date and next review. It prevents forgotten “shadow AI” and gives managers one place to see what is actually running.
Use primary guidance
The National AI Centre provides an official AI policy guide and template. Business owners should also read the OAIC’s guidance on commercially available AI products.
Important: this starter is general educational information, not legal advice. Adapt it to your privacy, employment, consumer, intellectual-property, cyber-security and industry obligations.