30 Tage Risikoerkennung für generative KI:Jetzt starten
Zum Hauptinhalt springen
Free AI Policy Template · Australian Edition

AI Acceptable Use Policy Template for Australia

Download the editable policy base, then use the Australian clauses below to adapt it for your organisation. Review the finished draft with your security, privacy and legal owners.

Start with the file. Adapt the clauses.

The DOCX download is the editable global policy base. Read or copy the Australian clauses below, replace the bracketed placeholders, and confirm which obligations apply to your organisation before approval.

  1. 01Choose your approved tools
  2. 02Localise the data rules
  3. 03Name the policy and review owners

The policy template, localised for Australia

Six sections, ready to customise. Expand each one to read the Australian-edition clauses. Bracketed [placeholders] are yours to fill in.

The DOCX is an English starting point. You can also copy the policy text from this page.

1. Purpose and scope

This policy sets out how [Organisation Name] permits and restricts the use of artificial intelligence tools at work. It applies to all employees, contractors and third parties who access company systems or handle company information, and it covers standalone AI tools (such as chatbots and coding assistants) as well as AI features embedded in approved software. It is designed to keep our use of AI consistent with the Privacy Act 1988 (Cth), the Australian Privacy Principles, guidance from the Office of the Australian Information Commissioner, and, where applicable, the expectations of sector regulators such as APRA.

2. Approved AI tools and permitted uses

Only AI tools on the approved list maintained by [Owner, e.g. IT Security] may be used for company work. Approved tools are assessed before listing for:

  • Where the vendor stores and processes data, and whether an Australian (Sydney region) data residency option is available where our data handling commitments require it
  • Whether prompts and uploads are used to train the vendor's models, and whether an enterprise tier with a no-training commitment is available
  • The vendor's security posture and certifications, and its breach notification terms
  • Compatibility with our obligations under the Privacy Act 1988 and our contracts

Requests to approve a new AI tool go to [contact or channel]. Free consumer tiers of generative AI tools are not approved for any work involving personal information or confidential company information.

3. Data rules: what may and may not enter AI tools

Never enter into any AI tool without written approval

  • Personal information as defined in the Privacy Act 1988, including names, contact details, and any information about an identifiable individual
  • Sensitive information under the Privacy Act, including health, biometric, racial or ethnic origin, and criminal record information
  • Tax file numbers, Medicare numbers and other government-issued identifiers
  • Customer records, credit-related information and financial account details
  • Confidential commercial information, unreleased financial results and information subject to contractual confidentiality
  • Credentials, API keys, security configurations and unpublished source code containing secrets

May be used in approved AI tools

  • Publicly available information and published company material
  • General drafting, research and brainstorming that contains no personal or confidential information
  • Code that contains no secrets, credentials or proprietary algorithms, within the approved tool's terms
  • De-identified data, only where re-identification is not reasonably possible and the use has been approved

This rule implements the OAIC's October 2024 guidance, which recommends that organisations do not enter personal information into publicly available generative AI tools, and our obligations under APPs 6, 8 and 11.

4. Prohibited uses

The following uses of AI are prohibited regardless of the tool:

  • Generating content that is discriminatory, harassing or unlawful, including content that would breach Australian anti-discrimination law
  • Creating deepfakes or impersonating real people, inside or outside the organisation
  • Making decisions that significantly affect an individual (hiring, credit, claims, discipline) on a solely or substantially automated basis without documented human review
  • Presenting AI-generated content as human work where disclosure is required by this policy, a client or a regulator
  • Entering another person's personal information into an AI tool without authority to do so
  • Using AI to circumvent security controls, access restrictions or this policy

The human review and disclosure rules track guardrails 5 and 6 of the Voluntary AI Safety Standard, and prepare us for the Privacy Act's automated decision-making transparency requirement, which commences on 10 December 2026.

5. Accountability and incident reporting

Every employee is responsible for their use of AI tools. If you enter, or suspect you have entered, personal information or confidential information into an unapproved AI tool, report it immediately to [Privacy Officer / Security contact]. Unauthorised disclosure of personal information to an AI tool may be an eligible data breach under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a breach is likely to result in serious harm, we are required to notify the OAIC and affected individuals, so speed of internal reporting matters. Breaches of this policy may result in disciplinary action.

6. Review and maintenance

This policy is reviewed at least annually by [Owner], and sooner when something material changes: a new tranche of Privacy Act reform is legislated, the automated decision-making transparency requirement commences in December 2026, the OAIC issues new AI guidance, APRA or another sector regulator updates its expectations, or an AI tool on the approved list changes its data handling terms. The approved tools list sits in an appendix so it can be updated without reissuing the policy. Record the version, review date and owner.

Download the editable policy base (.docx)

The download is the same editable backbone as our global template. Use the Australian clauses on this page to localise each section as you customise it.

What an Australian AI policy has to answer to

Four regulatory drivers shape AI use in Australian organisations. Each one lands somewhere specific in the template below.

Privacy Act 1988

The Privacy Act 1988 and its reform programme

The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles govern how organisations handle personal information, including information typed into or generated by AI tools. Since the December 2022 penalty amendments, a serious or repeated interference with privacy can attract a civil penalty of up to the greater of AUD 50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. The Privacy and Other Legislation Amendment Act 2024, the first tranche of the wider reform programme, added a statutory tort for serious invasions of privacy (from 10 June 2025), new mid-tier and lower-tier civil penalties, and a requirement to disclose substantially automated decisions that significantly affect individuals in privacy policies, which commences on 10 December 2026.

What it means for your policy: Your data rules must treat personal information, as the Privacy Act defines it, as a named prohibited category for unapproved AI tools, and your review schedule needs to track the reform tranches.

Voluntary AI Safety Standard

The Voluntary AI Safety Standard's 10 guardrails

Published by the Australian Government in September 2024, the Voluntary AI Safety Standard sets out 10 guardrails for organisations deploying AI. It is voluntary and creates no legal obligations, but it is the clearest statement of what good AI governance looks like to Australian regulators and buyers. The guardrails most relevant to an acceptable use policy are guardrail 1 (accountability processes, ownership and training), guardrail 3 (data governance and protection), guardrail 5 (meaningful human oversight), guardrail 6 (informing people about AI-enabled decisions, AI interactions and AI-generated content) and guardrail 9 (keeping records that let others assess your practices).

What it means for your policy: Name a policy owner, require human review of consequential AI-assisted work, require disclosure of AI-generated content where it matters, and keep an inventory of the AI tools in use.

OAIC guidance

OAIC guidance on AI and privacy

In October 2024 the Office of the Australian Information Commissioner published guidance on privacy and the use of commercially available AI products. The OAIC's position is that Privacy Act obligations apply to personal information entered into AI systems and to personal information in AI output, and that as a matter of best practice organisations should not enter personal information, particularly sensitive information, into publicly available generative AI tools. The guidance also expects organisations to update their privacy policies to reflect AI use (APP 1) and to make sure any use or disclosure of personal information through AI is permitted under APP 6.

What it means for your policy: The OAIC has effectively written your headline data rule for you: no personal information into public generative AI tools. Your policy should say so in exactly those terms.

APRA

APRA expectations for regulated entities

APRA's 30 April 2026 letter to industry told banks, insurers and superannuation trustees that existing prudential standards already apply to AI risk, and criticised entities that treat AI as just another technology without operationalising governance. The letter names data leakage and the misuse of AI agents among the changing cyber threats, and APRA has flagged an active supervisory programme with stronger action where AI risks are not adequately managed. Law firm analyses map the expectations to CPS 234, CPS 230, CPS 220 and CPS 510.

What it means for your policy: If you are APRA-regulated, an enforced AI acceptable use policy with evidence behind it is table stakes. Add a sector annex and work through the dedicated checklist below.

APRA-regulated? The letter deserves its own work programme. Our APRA AI governance checklist for CISOs translates each of APRA's four observations into concrete controls, with this policy as the enforcement anchor.

Every clause, traced to its Australian driver

Auditors, boards and customers ask why each rule exists. This mapping gives you the answer, clause by clause.

Approved tools list and vetting
OAIC guidance on commercially available AI products; Voluntary AI Safety Standard guardrail 1 (accountability) and guardrail 3 (data governance).
No personal information in unapproved AI tools
Privacy Act 1988 APPs 6, 8 and 11; OAIC best-practice recommendation against entering personal information into public generative AI tools.
Human review of consequential AI-assisted decisions
Voluntary AI Safety Standard guardrail 5 (human oversight); Privacy Act automated decision-making transparency requirement from 10 December 2026.
Disclosure of AI-generated content and AI interactions
Voluntary AI Safety Standard guardrail 6 (inform end users); APP 1 transparency expectations in the OAIC's AI guidance.
AI tool inventory and usage records
Voluntary AI Safety Standard guardrail 9 (records); APRA's expectation of evidence rather than intentions for regulated entities.
Incident reporting for AI data exposure
Notifiable Data Breaches scheme, Part IIIC of the Privacy Act; penalties up to the greater of AUD 50m, 3x benefit or 30% of adjusted turnover for serious or repeated interference with privacy.

How to customise it for your organisation

Work through these checks with the people responsible for the policy before approval and publication.

1
Name your organisation, policy owner and privacy officer
Replace every [bracketed] placeholder. The Privacy Officer contact matters most: the Notifiable Data Breaches scheme rewards fast internal escalation.
2
Build the approved tools appendix with data residency noted
For each approved tool, record the tier in use, whether a no-training commitment applies, and where data is stored. If your customer contracts or risk appetite require it, prefer vendors offering an Australian (Sydney) region.
3
Map your data classes to Privacy Act categories
Make sure your internal labels (public, internal, confidential, restricted) explicitly say where personal information and sensitive information sit, so the AI data rules inherit them cleanly.
4
Add a sector annex if you are APRA-regulated
Banks, insurers and superannuation trustees should tie the policy into their CPS 234 and CPS 230 programmes and board reporting. Use the APRA AI governance checklist as the work programme.
5
Brief staff and collect acknowledgments
The policy only protects you if staff have seen it. Run a short briefing, collect signed acknowledgments, and keep the records with your training evidence.
6
Diarise the review against the reform timeline
Put the automated decision-making transparency commencement (10 December 2026) and any further Privacy Act reform tranches on the review calendar now.

From a rule to a check

Test one rule before a wider rollout.

A written rule and an observed control are different evidence. Pick an AI app and a supported client, then check the action your policy requires.

What to check

  1. Name the app, account, client and input path.
  2. Choose the expected action for this rule.
  3. Repeat with harmless text as a comparison.
  4. Record the response, event and any unresolved gap.
Check supported product coverage
Illustrative policy rule
Do not submit customer personal information to an AI tool unless your organisation has approved that use.
Synthetic test input
Summarise the renewal notes for Morgan Hale. Contact: morgan.hale@example.com.
Illustrative test plan, not a completed test. Product coverage and policy outcomes depend on the selected configuration.

FAQ

Australian AI acceptable use policy: common questions

Does the Privacy Act 1988 cover employee use of AI tools like ChatGPT?
Yes. The Privacy Act does not name AI, but its 13 Australian Privacy Principles apply to personal information wherever it goes, including into prompts and file uploads. The OAIC's October 2024 guidance confirms that entering personal information into an AI tool engages APP 6 (use and disclosure) and that privacy obligations also apply to personal information in AI output. The OAIC recommends, as best practice, that organisations do not enter personal information into publicly available generative AI tools at all. An unauthorised disclosure through an AI tool can also be an eligible data breach under the Notifiable Data Breaches scheme, and serious or repeated interference with privacy carries civil penalties up to the greater of AUD 50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.
Is the Voluntary AI Safety Standard mandatory in Australia?
No. The Voluntary AI Safety Standard, published by the Australian Government in September 2024, is voluntary and creates no legal obligations. The government has separately consulted on mandatory guardrails for AI in high-risk settings, but the standard itself is guidance. It is still worth aligning with: its 10 guardrails describe what regulators, enterprise customers and boards increasingly expect, and several of them (accountability, data governance, human oversight, transparency and record-keeping) are implemented directly by an acceptable use policy like this one.
What does APRA expect from banks, insurers and super funds on employee AI use?
APRA's 30 April 2026 letter to industry confirmed that existing prudential standards already apply to AI risk and called for a step-change in AI risk management. It criticised entities that treat AI as just another technology, named data leakage and misuse of AI agents among the changing cyber threats, and flagged an active supervisory programme with stronger action where AI risks are not adequately managed. Law firm analyses map the expectations to CPS 234, CPS 230, CPS 220 and CPS 510. In practice that means an enforced AI acceptable use policy, visibility of actual employee AI usage including shadow AI, and evidence you can show a supervisor.
Does our AI policy need to require data residency in Australia?
There is no general Australian law requiring all data to stay onshore. APP 8 permits overseas disclosure of personal information provided you take reasonable steps to ensure the overseas recipient handles it consistently with the APPs, and you generally remain accountable for it. Some sectors have specific localisation rules, and many government and enterprise contracts require Australian data residency regardless. Because of that accountability, many Australian organisations simplify their position by preferring AI and security vendors that offer a Sydney region, and by recording data storage location in the approved tools appendix of their policy.
Put the policy into practice

Bring one rule. Review the control.

Bring the AI app, data type and employee action you need to evaluate. We will review the supported client and the evidence to collect.

AI Acceptable Use Policy Template Australia (2026) | Aona AI