AI Course
Australia · policy starter

AI policy template for Australian small business

A plain-English AI policy starter covering approved uses, prohibited data, human review, transparency, accountability, incidents and staff responsibilities.

Short answerA useful small-business AI policy says who is accountable, which tools and uses are approved, what information must never be entered, when a human must review output, when customers should be told, and how staff report mistakes or incidents. Keep it short enough to use and review it regularly.

Copyable AI policy starter

Purpose. We use AI only where it supports a legitimate business outcome and can be used safely, lawfully and fairly.

Approved use. Staff may use approved tools for approved workflows. New tools or uses require the nominated AI owner’s approval.

Information. Do not enter personal, sensitive, confidential, client-owned, security or commercially restricted information unless that use has been specifically assessed and approved.

Human responsibility. A person remains responsible for checking accuracy, context, bias, intellectual property, tone and compliance before an output is used.

High-impact decisions. AI must not make unsupervised decisions about employment, safety, health, credit, eligibility, legal rights or other significant outcomes.

Transparency. We explain material AI use to customers or affected people when appropriate or required.

Incidents. Staff stop the workflow and report suspected disclosure, harmful output, material inaccuracy or unexpected behaviour to the AI owner.

Complete these fields before adoption

  • AI owner: [name / role]
  • Approved tools: [list and account type]
  • Approved workflows: [list]
  • Prohibited information: [examples specific to your business]
  • Required reviewers: [workflow and role]
  • Incident contact and immediate steps: [details]
  • Review date: [at least every six months and after material change]

Why an AI register matters

Keep a simple register with the tool, vendor, owner, purpose, information used, affected people, human control, main risks, approval date and next review. It prevents forgotten “shadow AI” and gives managers one place to see what is actually running.

Use primary guidance

The National AI Centre provides an official AI policy guide and template. Business owners should also read the OAIC’s guidance on commercially available AI products.

Important: this starter is general educational information, not legal advice. Adapt it to your privacy, employment, consumer, intellectual-property, cyber-security and industry obligations.

Frequently asked questions

Does every Australian business need an AI policy?

Not every business has a specific legal duty to use this exact document, but clear rules are a practical control wherever staff use AI.

Can staff enter customer information into an AI tool?

Do not assume so. Assess the tool, contract, purpose, consent and privacy obligations. The OAIC recommends particular caution with personal and sensitive information.

How often should the policy be reviewed?

At least every six months, and whenever a material tool, workflow, law, incident or business risk changes.

Know where AI fits before you spend money implementing it.

The four-week AI Course helps non-technical owners and managers identify the right opportunities, score ROI, manage risk and leave with a practical 90-day plan.

Join the waitlist