What an AI policy should cover
A good AI policy is short enough for staff to read and clear enough to use on a busy day. Here is what it should cover, drawing on guidance from the National AI Centre, the OAIC and the Australian Cyber Security Centre.
An AI policy is a short document that tells your people how they may use artificial intelligence at work, what is off limits, and who to ask. It does not need to be long or technical. It does need to be specific enough that a staff member can answer “am I allowed to do this?” without calling a meeting.
The National AI Centre puts it simply: if your organisation uses AI, have a clear policy that explains how it can be used, who’s responsible and what rules people need to follow. It also notes that without clear rules, teams might use AI inconsistently, which creates unnecessary risk.
This article covers what to include, and where the Australian guidance can help.
The Australian context
There is no single AI law that tells a private business exactly what its policy must say. Instead, there is a mix of existing laws (such as privacy law) and voluntary guidance.
The Voluntary AI Safety Standard, first published in September 2024, set out ten voluntary guardrails for organisations using and developing AI. The same page now notes that on 21 October 2025 the National AI Centre published the Guidance for AI Adoption, which outlines six essential practices and “evolves the Voluntary AI Safety Standard”.
The foundations version of that guidance lists creating an AI policy as one of the first “getting started” actions, alongside assigning a senior leader as the overall AI governance owner.
For comparison, the federal government has its own Policy for the responsible use of AI in government. Version 2.0 took effect on 15 December 2025 and applies to non-corporate Commonwealth entities, with some exceptions. It requires things like accountable officials, transparency statements, internal use case registers and staff training on AI. It does not apply to private businesses, but it is a useful picture of what a mature approach looks like.
This article is general information, not legal advice. You should get legal advice for your own situation, particularly if you handle health, financial or children’s information.
The sections your policy needs
The National AI Centre’s policy guidance says that before you finalise your policy, check it clearly outlines:
- what AI can and can’t be used for
- who approves higher-risk use cases
- what data staff can put into tools
- when staff need to oversee AI use
- how staff should report issues or misuse
- when the policy will be reviewed.
Those six points make a sensible skeleton. Here is how to fill each one in.
1. Purpose and scope
Say why the policy exists and who it applies to: employees, contractors, volunteers and anyone else using your systems. Define “AI” broadly enough to cover chatbots, writing assistants, transcription tools and AI features built into software you already use.
2. Approved tools and uses
List the tools staff may use, and for what. Be concrete. “Drafting internal emails and summarising public documents” is clearer than “general productivity”. Also list uses that are not allowed, or that need approval first, such as anything that makes or influences decisions about customers, job applicants or staff.
The foundations guidance gives a helpful contrast: using AI to draft marketing emails is different to using it to assess job applications. Your policy should treat them differently too.
3. Data rules
This is the section staff will rely on most. Spell out what information must never go into an AI tool.
The Office of the Australian Information Commissioner (OAIC) recommends, as a matter of best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved. “Sensitive information” is a category of personal information that gets a higher level of protection, and the OAIC’s examples include health information, race, political opinions and religious or philosophical beliefs.
The Australian Cyber Security Centre similarly advises that businesses establish an internal AI use policy or process, and clearly define what data can’t be uploaded into AI platforms. It also suggests removing or changing personal details so information cannot be linked back to an individual.
A simple traffic-light table works well here:
- Green: public information, your own drafts with no personal details.
- Amber: internal business information, only in approved tools with data-sharing for training turned off.
- Red: personal, health, financial or confidential client information, never in public AI tools.
4. Checking outputs
AI tools can produce answers that sound right but are wrong. This is often called a “hallucination”. Your policy should say that a person is responsible for checking any AI output before it is used, sent or relied on, and that the person, not the tool, owns the result.
The ACSC recommends training staff to verify AI outputs and having a human involved in decisions, especially in high-stakes or sensitive operations.
5. Roles and approvals
Name who owns the policy and who approves new tools or higher-risk uses. In a small organisation this may be one person. In a larger one, it might be a manager plus someone responsible for privacy and IT.
6. Telling people when AI is involved
The OAIC says organisations should update their privacy policies with clear information about their use of AI, and make sure any public-facing AI tools such as chatbots are clearly identified as AI. The foundations guidance makes the same point: people should know when they are interacting with AI.
7. Buying and switching on new tools
Set a simple rule for anything new: check what data the tool collects, where it is stored, whether your data is used to train the vendor’s models, and how the vendor handles security incidents. The ACSC’s checklist covers each of these questions. The OAIC adds that due diligence should not be “set and forget”.
8. Reporting problems
Tell staff exactly what to do if something goes wrong: a wrong answer sent to a customer, personal information pasted into the wrong tool, or a tool behaving strangely. Give them a name or inbox, and make it clear that early reporting is welcome.
9. Training
State what training staff receive before using AI tools, and how often it is refreshed.
10. Review
AI tools change quickly. Set a review date, such as every six or twelve months, and review sooner if you adopt a significant new tool.
Keep it usable
The National AI Centre suggests testing the draft with the people who will use, review or oversee it, and using terms your team already knows. A two-page policy that people read beats a twenty-page one that sits in a folder. The Centre also offers a free AI policy template on the Create an AI policy page.
Checklist
Before you publish your AI policy, check that it:
- names an owner and an approver for new uses
- lists approved tools and uses, and uses that need approval
- has clear data rules, with personal and sensitive information kept out of public tools
- requires a person to check AI output before it is used
- explains how customers will be told when AI is involved
- sets out how to report problems
- includes training and a review date
- has been read by the people who will follow it.
A final word
A clear AI policy protects your people as much as your organisation, because it gives them confidence about what is allowed. If you would like help working out where your organisation stands, try our free AI maturity assessment or contact our team with Melora Digital.
Sources
- Create an AI policy (opens in a new tab) — National Artificial Intelligence Centre. Accessed 3 October 2026.
- Guidance for AI adoption: foundations (opens in a new tab) — National Artificial Intelligence Centre. Accessed 3 October 2026.
- Voluntary AI Safety Standard (opens in a new tab) — Department of Industry, Science and Resources. Accessed 3 October 2026.
- Guidance on privacy and the use of commercially available AI products (opens in a new tab) — Office of the Australian Information Commissioner. Accessed 3 October 2026.
- Artificial intelligence for small business (opens in a new tab) — Australian Signals Directorate's Australian Cyber Security Centre. Accessed 3 October 2026.
- Policy for the responsible use of AI in government - Version 2.0 (opens in a new tab) — Digital Transformation Agency. Accessed 3 October 2026.
This article is general information, not legal or professional advice. Written with AI-assisted research and checked by a person — see how we use AI.