How to Write an AI Policy for Your Business (Free Template)

How to Write an AI Policy for Your Business (Free Template)

September 21, 2026

Here is a question I ask every business owner in the first week we work together: "What are your staff allowed to put into AI?"

The answer is almost always a pause, then "Well, nothing sensitive, I assume." That assumption is the gap. Your team is already using AI to write emails, summarise documents and draft quotes. Without written rules, every one of them is making their own call about what is safe, every single day.

An AI policy fixes that in a few pages. This guide shows you how to write an AI policy for your business in an afternoon, what must go in it, the mistakes that make policies useless, and a free template you can copy and adapt today.

Quick answer: An AI policy is a short, plain-English document that tells staff which AI tools they can use, what information must never go into them, when a human has to check the output, and who owns the rules. For a small business, two to four pages is enough. Start with approved tools, data rules and human review.

What is an AI policy?

An AI policy is your staff-facing rulebook for artificial intelligence at work. It answers the practical question every employee has: "Can I use AI for this, and if so, how?"

It is different from an AI charter. A charter sits above the policy and sets leadership principles and accountability (we covered that in why your business needs an AI charter). The policy is the everyday layer: which tools, which data, which checks.

AI charter AI policy
Audience Owners and leadership Every staff member
Answers "Who decides, and on what principles?" "Can I do this, and how?"
Length 1 to 2 pages 2 to 4 pages
Changes Once or twice a year Whenever tools or risks change

Small businesses can start with the policy alone. It delivers the fastest risk reduction because it changes what people do on Monday morning.

Why your business needs an AI policy now

Your staff are already using AI, whether you approved it or not

Staff reach for whatever tool is closest: a free chatbot on their phone, a browser extension, the AI button that quietly appeared in software you already pay for. This is often called shadow AI, and it is the normal state of most businesses we assess. (Our guide on what not to paste into ChatGPT covers the common leaks.)

A ban rarely works. People keep using AI because it saves them time, they just stop telling you. A good policy says yes to the useful work and draws clear lines around the risky work.

The regulator has already told you what good looks like

You do not have to invent this from scratch. Australia's National AI Centre published its Guidance for AI Adoption in October 2025, which sets out six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, and maintain human control. It recommends organisations using AI develop and maintain an AI policy, and it published an AI policy guide and template to help.

The Office of the Australian Information Commissioner also recommends organisations do not enter personal information, particularly sensitive information, into publicly available AI tools.

Privacy obligations are tightening

If your business is covered by the Privacy Act (generally businesses with annual turnover above $3 million, plus health service providers and some other categories regardless of size), new automated decision-making transparency rules start on 10 December 2026. From then, if you use personal information in automated decisions that could significantly affect someone's rights or interests, your privacy policy must explain the kinds of personal information used and the kinds of decisions made.

Even if your business is below the threshold, your larger clients may be covered, and they will increasingly ask their suppliers how AI is used with their data. A written policy is the easiest answer to that question.

What to include in an AI policy: the 8 essential sections

Every workable small business AI policy covers these eight areas. Anything more is optional.

# Section The question it answers
1 Purpose and scope Who does this apply to, and why do we have it?
2 Approved tools Which AI tools can we use for work?
3 Data rules What information can and cannot go into AI?
4 Acceptable and prohibited uses What is AI good for here, and what is off limits?
5 Human review When must a person check AI output before it is used?
6 Transparency When do we tell clients or customers AI was involved?
7 Incidents What do I do if something goes wrong?
8 Ownership and review Who owns this policy and when is it updated?

1. Purpose and scope

Keep it to two or three sentences. State that the business supports using AI to work smarter, and that the policy exists to protect clients, staff and company information. Make it apply to everyone: employees, contractors and anyone with access to your systems.

2. Approved tools

This is the section that does the most work. List the specific AI tools staff may use for work, and make the rule simple: if it is not on the list, ask first.

The key distinction is between business accounts (managed by the company, with admin controls and data protections) and personal or free accounts (no visibility, and conversations may be used to train the vendor's models unless a setting is changed). Company data belongs in company accounts only.

3. Data rules

Use a traffic-light system. People remember colours far better than clauses.

Level Examples Rule
Green Public information, your own marketing copy, general research, anonymised examples OK in any approved tool
Amber Internal documents, pricing, non-sensitive business data Approved business accounts only
Red Client personal information, health, financial or identity details, passwords, contracts, anything under a confidentiality agreement Never, unless a specific, approved system is set up for it

4. Acceptable and prohibited uses

Give real examples from your business. "Drafting a first version of a client email" is acceptable. "Making a final decision about a tenant application, a loan or a job candidate using AI alone" is not. Specific examples beat abstract principles every time.

5. Human review

AI gets things wrong with total confidence. Your policy should require a person to check AI output before it is sent to a client, published, used in a decision about a person, or relied on for anything legal, financial or safety related. The person who uses the output owns it.

6. Transparency

Decide when you disclose AI use. A sensible default: tell people when they are talking to an AI (for example, an AI receptionist), and when AI materially shaped a decision that affects them.

7. Incidents

Make it easy to own up. If someone pastes something they should not have, they should report it straight away to a named person, without fear of being punished for reporting. Early reporting turns a potential breach into a quick fix.

8. Ownership and review

Name one person who owns the policy, and set a review date. Every six months is realistic for most small businesses, because AI tools change quickly.

How to write your AI policy in 5 steps

  1. Find out what is actually being used. Ask your team, anonymously if needed, which AI tools they use and for what. You cannot write rules for a reality you have not seen.
  2. Pick your approved tools. Choose one or two business-grade AI platforms and switch off or restrict the rest.
  3. Set your data rules. Adapt the green, amber and red table above to your actual client data.
  4. Write it in plain English. If a new starter cannot understand it in five minutes, it is too long. Use the template below.
  5. Roll it out properly. Walk the team through it, get a signed acknowledgement, and add it to onboarding. A policy sitting in a shared drive changes nothing.

Free AI policy template

Copy this, replace everything in [square brackets], and delete anything that does not fit your business.


[Business Name] AI Acceptable Use Policy

Version: 1.0 | Owner: [Name, role] | Approved: [Date] | Next review: [Date + 6 months]

1. Purpose. [Business Name] supports using artificial intelligence to save time and serve our clients better. This policy sets clear rules so we do that safely, legally and in a way our clients can trust.

2. Scope. This policy applies to all employees, contractors and anyone using [Business Name] systems or information.

3. Approved tools. Staff may use the following AI tools for work, signed in with their company account only: - [Tool 1, business plan] - [Tool 2, business plan]

Any other AI tool, browser extension or AI feature must be approved by [Owner] before it is used with company information. Personal or free AI accounts must not be used for company or client information.

4. Data rules. - Green (OK in approved tools): public information, marketing drafts, general research, anonymised examples. - Amber (approved company accounts only): internal documents, pricing, non-sensitive business data. - Red (never, unless an approved system exists for it): client or customer personal information, health, financial or identity information, passwords and access details, contracts and confidential client material.

5. Acceptable uses. Drafting and editing, summarising non-red documents, brainstorming, research, and [add business-specific examples].

6. Prohibited uses. Making final decisions about a person (for example [hiring, credit, tenancy, eligibility]) using AI alone; entering red information into any unapproved tool; presenting AI-generated work as checked when it has not been; using AI to create misleading or harmful content.

7. Human review. A person must review AI output before it is sent to a client, published, or used in any legal, financial, safety or people-related decision. The person using the output is responsible for it.

8. Transparency. We tell people when they are interacting with an AI system, and when AI has materially shaped a decision that affects them.

9. Incidents. If you think information has been put into AI in breach of this policy, or AI has produced something harmful, tell [Owner] immediately. Reporting quickly is always the right call.

10. Review. [Owner] reviews this policy every six months or when we adopt a new AI tool.

Acknowledgement: I have read and understood this policy. Name: __ Signature: _ Date: ___


This template is a starting point, not legal advice. If you work in a regulated industry (legal, health, finance, property), have your policy checked against your industry obligations.

Common AI policy mistakes to avoid

Mistake Why it fails Do this instead
Banning AI outright Staff keep using it, just secretly Approve safe tools and set clear limits
Copying a 30-page corporate policy Nobody reads it, nobody follows it Two to four pages, plain English
Rules with no approved tools People do not know what "yes" looks like Name the exact tools and account types
Writing it without asking staff It misses how AI is really used Survey the team first
Set and forget Tools change monthly Six-monthly review with a named owner
Policy with no security setup behind it Rules on paper, open doors in the system Match the policy with access controls and account settings

That last one is where most policies quietly fail. A policy says "keep client data out of unapproved tools." Security settings make it hard to do anything else. After 25 years in IT and security, my view is simple: a policy without the technical controls behind it is a hope, not a safeguard. You need both.

Frequently asked questions

Does a small business need an AI policy?

Yes, if anyone in the business uses AI at work, which is now most businesses. A short AI policy reduces the risk of client data leaking into AI tools, sets clear expectations for staff, and shows clients you take their information seriously. Two to four pages is enough for a small team.

Is an AI policy a legal requirement in Australia?

There is no general law requiring private businesses to have an AI policy. However, Privacy Act obligations still apply to how AI handles personal information, the National AI Centre recommends organisations using AI maintain one, and new automated decision-making transparency rules start on 10 December 2026 for businesses covered by the Act.

What is the difference between an AI policy and an AI charter?

An AI charter is a leadership document that sets principles, ownership and direction for AI in the business. An AI policy is the staff-facing rulebook that covers approved tools, data rules and human review. The charter decides who makes the rules; the policy is the rules.

How long should an AI policy be?

For a small or medium business, two to four pages. Long enough to cover approved tools, data rules, acceptable and prohibited uses, human review, incidents and ownership. Short enough that a new starter can read and understand it in five minutes.

How often should you update an AI policy?

Review it at least every six months, and whenever you adopt a new AI tool or AI feature. AI products change quickly, so a policy written a year ago may not cover tools your team uses today.

Can I use ChatGPT at work if we have an AI policy?

Only if your policy approves it and you are using a business account that your company manages. Free and personal accounts give the business no control over data, so client or personal information should stay out of them.

The bottom line

Knowing how to write an AI policy is not about paperwork. It is about giving your team a clear green light to use AI where it helps, and a clear red line where it could hurt your clients and your reputation. Survey the team, pick your tools, set traffic-light data rules, and use the template above to get version one done this week.

If you want a policy built around how your team actually uses AI, backed by the security settings that make it stick, that is part of the Safe AI Foundation we set up through our AI consulting work. The easiest first step is a free AI Game Plan Session: 60 minutes to find where AI will save you the most time, and where your data is exposed right now.

Back to Blog