Skip to main content

We use cookies to improve your experience and measure traffic. Decline to opt out of analytics and advertising cookies. Cookie preferences

For Australian managers whose staff are already using AI tools

Writing an AI Acceptable Use Policy for Your Staff

Someone in your team has already pasted something they should not have into a free AI chatbot. A client list, a draft contract, a payroll export, a patient note. They were not being malicious, they were trying to get through a Tuesday faster. An AI acceptable use policy is how you turn that from a recurring, invisible risk into a set of rules people can actually follow: which tools are approved, which data may never be entered anywhere, when a human has to check the output before it leaves the building, what you tell clients, who owns what comes out, and what happens when someone gets it wrong.

Drafted for Australian conditions: the Privacy Act and the Australian Privacy Principles, the confidentiality and offshore processing clauses already sitting in your client contracts, and the procedural fairness Fair Work expects before you discipline anyone over a rule. Plain English, a one page card people will read, and a full policy sitting behind it.

Realistic ROI

1 to 2 weeks
From first conversation to a signed policy
Most Australian SMEs get a surveyed tool list, a drafted policy and a rollout plan inside a fortnight
One page
The version staff actually carry
A short do and do not card sits on top of the full policy, because nobody re-reads a twelve page PDF at 4pm
Fewer leaks
Confidential material kept out of public tools
People stop guessing, because the banned data classes and the approved tools are both named
Hours per week
Kept rather than driven underground
A policy that permits sensible use keeps the productivity gain visible instead of pushing it onto personal phones

Why Write This Policy With Yes AI

You can download an AI policy template in about four seconds. The problem is that a template does not know which tools your team already opened accounts on, which of your client contracts forbids sending their material to an overseas service, or which jobs in your business should never have an AI anywhere near them. Four things make the difference between a document that sits in a folder and a policy that changes what people do on Monday.

We start by finding out what is already in use

You cannot write rules for a workforce you have not surveyed, and a proper survey almost always turns up tools nobody in management knew about. We do it as a no-blame amnesty, and we ask by task rather than by product name, because people do not say the name of the tool, they say the writing thing in Word, or the browser add-on that summarises pages, or the note taker that joins their meetings. We also check the AI features quietly switched on inside the software you already license, which is where a lot of the real exposure sits.

We draft it against your obligations, not a generic checklist

Your actual constraints are usually tighter than the general law. Client agreements routinely restrict disclosure to third parties, some government and health contracts forbid processing offshore altogether, and professional obligations bite before any privacy regulator does. So we read what you have signed, work out whether the Privacy Act applies to your business, classify your data properly, and write rules that match your real exposure rather than a national average of it.

We write it for the people who have to follow it

A policy written to protect the company from its own staff reads like one, and gets treated like one. We write in the second person, use examples drawn from the jobs your team actually does, and reduce the whole thing to a card that answers the only question anyone asks in the moment, which is can I paste this into that. The full policy still exists for the auditor and the insurer. The card is what changes behaviour.

We stay past the signature

This is the fastest ageing policy in your business. Tools change their terms with little notice, vendors switch on new AI features inside products you already pay for, and your team finds something new every month. We set a review cadence, keep the tool list as a living document with a named owner and a review date on every entry, and stay on hand when someone reports an incident and you need a fast, calm answer rather than a panic.

The Policy, Section by Section

This is the outline we use, and you are welcome to lift it. Six sections, in this order, because it moves from what is covered, through what is allowed, to what happens when it goes wrong. Keep the body under about six pages and push every long list into an appendix you can update without re-approving the whole document.

Section 1

Scope, definitions and who is covered

Name who it binds: employees, contractors, labour hire, work experience students, volunteers and board members. Name where it applies: company devices, personal devices used for work, and anything touching company data at home. Then define generative AI in plain, function-based language rather than by naming three chatbots, because the most common failure we see is a policy that covers the chat window and misses the AI features already switched on inside your CRM, your email, your meeting recorder and your accounting package.

Section 2

Approved tools, in three tiers

Approved means a business tier account under your own administration, with sign-on you control and terms that say your inputs are not used for training. Approved with limits means a named tool for named tasks, with conditions such as no personal information and mandatory review of output. Banned means consumer free accounts, anything that trains on inputs, and anything asking for broad access to your mailbox or file storage. Publish the list separately from the policy body with an owner and a review date on every row, because the list changes monthly and the policy should not.

Section 3

The data rules, written as classes

The section people will actually consult. List classes, not just examples: personal information as the Privacy Act defines it, health and sensitive information, tax file numbers and bank details, employee records, client material covered by a confidentiality clause, unreleased financials, credentials and keys, anything under legal privilege, and security or incident detail. Include the de-identification trap in writing, because deleting a name does not de-identify a record when the job title, the suburb and the dates still point at exactly one person. The working rule of thumb: if you would hesitate to email it to a supplier, do not paste it into a tool.

Section 4

Human review and who carries the output

State that a named person owns every AI-assisted output and that the AI wrote it is never a defence. Then tier the review by consequence rather than by volume: an internal note needs a read, a client deliverable needs a check against source, and anything with a legal, financial, safety, clinical or employment consequence needs a qualified human decision recorded with reasons. Require the reviewer to be able to independently verify names, figures, citations and legislative references, because the failure mode is not obviously broken output, it is confident, well formatted, fluent and wrong.

Section 5

Disclosure, ownership and client contracts

Set out when clients and customers are told, which is normally driven by your contracts and by whether the output is a deliverable rather than a drafting aid. Address ownership honestly: Australian copyright has historically required a human author, so purely machine generated material may attract no copyright protection at all, which matters if the output is meant to be an asset you own or license. Check what your vendor terms actually say about input retention and any indemnity, and check your client agreements for subcontracting and offshore processing clauses, because that clause is usually the first thing an AI tool breaks.

Section 6

Reporting, breach and consequences

Give one named contact, a same-day reporting expectation, and an explicit no-blame line for self-reporting, because the reporting path has to be faster and less frightening than covering it up. Set out who assesses the incident, what triggers a Notifiable Data Breaches assessment where the Privacy Act applies to you, and when a client has to be told under their agreement. Then set graduated consequences, from retraining through to formal action, and link them to your existing disciplinary process rather than inventing a parallel one.

Six Situations the Policy Has To Survive

TaskTraditionalWith Yes AINotes
Sales rep pastes the client list into a free chatbot to tidy up formattingDiscovered weeks later, no rule to point at, knee-jerk ban on everythingNamed data class, named tool tier, a fast report path and a proportionate responseThat list is personal information. The policy already says where it may go, the incident path decides within hours whether it needs assessing as a breach, and the rep gets retrained instead of made an example of.
Bookkeeper uploads a payroll export to summarise leave balancesNobody knows whether the file is retained, or where it now physically sitsPayroll data banned outright, with the approved tool for that job named insteadTax file numbers, bank details and salaries in one spreadsheet. This is the upload that turns into an OAIC conversation, so it earns its own explicit line rather than a general warning about sensitive data.
Marketing publishes AI-drafted copy containing a fabricated statisticGoes live, then gets quietly corrected after a customer questions the numberPublic content sits in the top review tier, every figure checked to a sourceThe ACCC has no interest in the fact that a machine wrote it. Misleading claims in your advertising are your problem, so the reviewer has to be able to produce the source for every number.
Developer pastes client source code into a free coding assistantBreaches a confidentiality clause nobody has read since the contract was signedCode tiered per client, an approved assistant configured, free accounts bannedClient agreements commonly restrict disclosure to third parties and processing outside Australia. In practice that contract clause, not the Privacy Act, is what an AI tool breaks first.
HR trials AI shortlisting on a stack of job applicationsCandidates filtered by a process nobody in the business can explain or defendFlagged as a high consequence use: human decides, reasons recorded, no auto-rejectRecruitment carries discrimination and Fair Work exposure, and privacy reforms are tightening transparency around automated decisions. A human decision maker with written reasons is the only defensible position.
Support agent sends an AI-written reply promising a refund you do not offerThe customer holds you to it while the team argues about who approved the wordingCustomer-facing replies checked against your actual terms before they are sentThe fastest real world loss from AI in a small business is rarely a data breach. It is a confident, wrong, perfectly worded answer going out to a customer under your logo.

Six Ways These Policies Fail, and How We Stop It

A blanket ban is the failure mode, not the safe option

Ban everything and the use does not stop, it moves onto personal phones and personal accounts where you have no visibility, no logs, no administration and no chance of finding out what went where. Worse, a rule people cannot follow teaches them the whole document is theatre, so they ignore the parts that genuinely matter. Give a permitted path that is easier than the shadow path: a business tier account, on tasks people actually need, with clear limits. You trade a small amount of permitted use for the ability to see what is happening at all.

Nobody reads a twelve page policy, and a signature does not mean they understood it

Acknowledgement records prove you distributed the document. They do not prove comprehension, and they will not impress anyone if the rule was never explained. Pair the full policy with a one page card that answers can I paste this, run a short live session using examples from your own jobs rather than abstract scenarios, put it in the induction pack, and re-run the session when the tool list changes materially. If your team cannot tell you the three banned data classes without looking, the rollout has not happened yet.

Free and consumer tiers do not behave like the business tier you read about

Whether your inputs are retained, reviewed by humans or used to improve a model varies by plan, by region and by account type, and vendors change those terms with little notice. The trap is management assuming the business tier promise covers the free account someone opened with a personal email address. Read the terms for the exact plan you are actually on, record the date you checked, name the plan in your tool list, and re-check at every review. Never assume, and never let a policy quote a vendor guarantee without a date next to it.

Discipline that will not survive Fair Work scrutiny

You cannot fairly act against someone over a rule that was never communicated, never trained and enforced inconsistently across the team. Keep dated evidence of distribution and acknowledgement, apply the same standard to the manager who did it as to the junior who did it, use graduated consequences, and give people a genuine chance to respond before any decision. This page is general information rather than legal advice, so have your employment adviser review the disciplinary wording and the interaction with your existing code of conduct before you publish.

AI detection tools will not give you enforcement

Detectors that claim to identify AI-written text are unreliable in both directions, produce false positives on ordinary careful writing, and research has found they disproportionately flag people writing in a second language. Building a disciplinary process on a detector score is how you end up defending an indefensible decision. Enforce the things that are actually verifiable instead: what data was entered, which account and tool were used, whether the required review happened, and whether the output was checked before it went out.

The policy goes stale faster than anything else you have written

New AI features appear inside software you already license without anyone approving them, vendors change plans and terms, and your team keeps finding new tools. Review the tool list quarterly with a named owner, review the policy body annually or whenever something material changes, and note the review date on the document itself. Be honest in the policy about the limits too: there are jobs in your business where AI should not be involved at all, and naming them explicitly is more useful than a vague instruction to use good judgement.

How Yes AI Helps

A policy drafted against your actual stack

We survey what your team is already using, read your client contracts and privacy obligations, classify your data, then draft the full policy and the one page card in plain English. You get a document written for your business and your risks, not a template with your logo dropped on the front page.

Tool assessment and tiering

We work through the tools in play and the AI features already switched on inside software you license, check what each plan says about retention and training, and sort them into approved, approved with limits, and banned. Every entry gets an owner, an approved use and a review date so the list stays current instead of ageing quietly.

A rollout people actually remember

A policy nobody understands changes nothing. We run the staff session using examples from your own work, supply the card, the induction wording and the acknowledgement process, and brief managers on how to answer the awkward questions they will be asked in the first fortnight.

Review cadence and incident support

We set the quarterly tool review and the annual policy review, and we are on hand when someone reports something. The day a client list ends up somewhere it should not, you want a considered assessment and a clear next step, not a scramble to work out who to call.

How We Get the Policy Written and Adopted

Five steps from a first conversation to a policy your team has been trained on and can find when they need it. Most Australian SMEs are through the whole sequence in one to two weeks, depending on how many client contracts have to be read and how spread out the team is.

Find out what is already being used

A short, no-blame amnesty survey plus a quick look at browser extensions, meeting recorders and the AI features already enabled inside your existing software. We ask by task, not by product name, because that is how people describe what they do. Expect the list to come back longer than you thought, including things that arrived as a free trial and never left, and expect that inventory to be the entire basis for the policy.

Classify your data and read your obligations

We sort your information into classes that map to real rules, work out whether the Privacy Act applies to your business, and read the confidentiality, subcontracting and offshore processing clauses in your client and supplier agreements. Where you sit in health, finance, government-adjacent or professional services work, we factor in the sector obligations that bite before any general privacy rule does.

Tier the tools

Each tool is checked against what its plan actually says about input retention and training, then placed into approved, approved with limits, or banned, with the conditions written down. We publish it as a living list with an owner and a review date on every row, separate from the policy body, so you can add a tool next month without re-approving the whole document.

Draft the policy and the one page card

The full policy follows the six sections above, in plain second-person English, with examples drawn from your team's actual work. Alongside it we write the one page card that answers can I paste this, plus the induction wording and the acknowledgement text. Your employment adviser reviews the disciplinary section before anything is published.

Roll out, train and set the review

A live session for staff using your own examples, a separate briefing for managers on the questions they will get, acknowledgement collected and dated, and the card put somewhere people can reach in ten seconds. Then the quarterly tool review and annual policy review go in the calendar with a named owner, so it stays a working document.

FAQ

Get the Rules Written Before the Next Paste

Book a free call and we will work out what your team is already using, what your contracts and privacy obligations actually require, and what your policy needs to say. You will leave the call with a clear picture of your real exposure, whether or not you engage us to write it.

All discussions held in confidence. Australian-based consultants.