AI Acceptable Use Policy
Template for Australia
Download the editable policy base, then use the Australian clauses below to adapt it for your organisation. Review the finished draft with your security, privacy and legal owners.
Start with the file. Adapt the clauses.
The DOCX download is the editable global policy base. Read or copy the Australian clauses below, replace the bracketed placeholders, and confirm which obligations apply to your organisation before approval.
- 01Choose your approved tools
- 02Localise the data rules
- 03Name the policy and review owners
The policy template, localised for Australia
Six sections, ready to customise. Expand each one to read the Australian-edition clauses. Bracketed [placeholders] are yours to fill in.
The DOCX is an English starting point. You can also copy the policy text from this page.
1. Purpose and scope
This policy sets out how [Organisation Name] permits and restricts the use of artificial intelligence tools at work. It applies to all employees, contractors and third parties who access company systems or handle company information, and it covers standalone AI tools (such as chatbots and coding assistants) as well as AI features embedded in approved software. It is designed to keep our use of AI consistent with the Privacy Act 1988 (Cth), the Australian Privacy Principles, guidance from the Office of the Australian Information Commissioner, and, where applicable, the expectations of sector regulators such as APRA.
2. Approved AI tools and permitted uses
Only AI tools on the approved list maintained by [Owner, e.g. IT Security] may be used for company work. Approved tools are assessed before listing for:
- Where the vendor stores and processes data, and whether an Australian (Sydney region) data residency option is available where our data handling commitments require it
- Whether prompts and uploads are used to train the vendor's models, and whether an enterprise tier with a no-training commitment is available
- The vendor's security posture and certifications, and its breach notification terms
- Compatibility with our obligations under the Privacy Act 1988 and our contracts
Requests to approve a new AI tool go to [contact or channel]. Free consumer tiers of generative AI tools are not approved for any work involving personal information or confidential company information.
3. Data rules: what may and may not enter AI tools
Never enter into any AI tool without written approval
- Personal information as defined in the Privacy Act 1988, including names, contact details, and any information about an identifiable individual
- Sensitive information under the Privacy Act, including health, biometric, racial or ethnic origin, and criminal record information
- Tax file numbers, Medicare numbers and other government-issued identifiers
- Customer records, credit-related information and financial account details
- Confidential commercial information, unreleased financial results and information subject to contractual confidentiality
- Credentials, API keys, security configurations and unpublished source code containing secrets
May be used in approved AI tools
- Publicly available information and published company material
- General drafting, research and brainstorming that contains no personal or confidential information
- Code that contains no secrets, credentials or proprietary algorithms, within the approved tool's terms
- De-identified data, only where re-identification is not reasonably possible and the use has been approved
This rule implements the OAIC's October 2024 guidance, which recommends that organisations do not enter personal information into publicly available generative AI tools, and our obligations under APPs 6, 8 and 11.
4. Prohibited uses
The following uses of AI are prohibited regardless of the tool:
- Generating content that is discriminatory, harassing or unlawful, including content that would breach Australian anti-discrimination law
- Creating deepfakes or impersonating real people, inside or outside the organisation
- Making decisions that significantly affect an individual (hiring, credit, claims, discipline) on a solely or substantially automated basis without documented human review
- Presenting AI-generated content as human work where disclosure is required by this policy, a client or a regulator
- Entering another person's personal information into an AI tool without authority to do so
- Using AI to circumvent security controls, access restrictions or this policy
The human review and disclosure rules track guardrails 5 and 6 of the Voluntary AI Safety Standard, and prepare us for the Privacy Act's automated decision-making transparency requirement, which commences on 10 December 2026.
5. Accountability and incident reporting
Every employee is responsible for their use of AI tools. If you enter, or suspect you have entered, personal information or confidential information into an unapproved AI tool, report it immediately to [Privacy Officer / Security contact]. Unauthorised disclosure of personal information to an AI tool may be an eligible data breach under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a breach is likely to result in serious harm, we are required to notify the OAIC and affected individuals, so speed of internal reporting matters. Breaches of this policy may result in disciplinary action.
6. Review and maintenance
This policy is reviewed at least annually by [Owner], and sooner when something material changes: a new tranche of Privacy Act reform is legislated, the automated decision-making transparency requirement commences in December 2026, the OAIC issues new AI guidance, APRA or another sector regulator updates its expectations, or an AI tool on the approved list changes its data handling terms. The approved tools list sits in an appendix so it can be updated without reissuing the policy. Record the version, review date and owner.
The download is the same editable backbone as our global template. Use the Australian clauses on this page to localise each section as you customise it.
What an Australian AI policy has to answer to
Four regulatory drivers shape AI use in Australian organisations. Each one lands somewhere specific in the template below.
The Privacy Act 1988 and its reform programme
The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles govern how organisations handle personal information, including information typed into or generated by AI tools. Since the December 2022 penalty amendments, a serious or repeated interference with privacy can attract a civil penalty of up to the greater of AUD 50 million, three times the benefit obtained, or 30 per cent of adjusted turnover. The Privacy and Other Legislation Amendment Act 2024, the first tranche of the wider reform programme, added a statutory tort for serious invasions of privacy (from 10 June 2025), new mid-tier and lower-tier civil penalties, and a requirement to disclose substantially automated decisions that significantly affect individuals in privacy policies, which commences on 10 December 2026.
What it means for your policy: Your data rules must treat personal information, as the Privacy Act defines it, as a named prohibited category for unapproved AI tools, and your review schedule needs to track the reform tranches.
The Voluntary AI Safety Standard's 10 guardrails
Published by the Australian Government in September 2024, the Voluntary AI Safety Standard sets out 10 guardrails for organisations deploying AI. It is voluntary and creates no legal obligations, but it is the clearest statement of what good AI governance looks like to Australian regulators and buyers. The guardrails most relevant to an acceptable use policy are guardrail 1 (accountability processes, ownership and training), guardrail 3 (data governance and protection), guardrail 5 (meaningful human oversight), guardrail 6 (informing people about AI-enabled decisions, AI interactions and AI-generated content) and guardrail 9 (keeping records that let others assess your practices).
What it means for your policy: Name a policy owner, require human review of consequential AI-assisted work, require disclosure of AI-generated content where it matters, and keep an inventory of the AI tools in use.
OAIC guidance on AI and privacy
In October 2024 the Office of the Australian Information Commissioner published guidance on privacy and the use of commercially available AI products. The OAIC's position is that Privacy Act obligations apply to personal information entered into AI systems and to personal information in AI output, and that as a matter of best practice organisations should not enter personal information, particularly sensitive information, into publicly available generative AI tools. The guidance also expects organisations to update their privacy policies to reflect AI use (APP 1) and to make sure any use or disclosure of personal information through AI is permitted under APP 6.
What it means for your policy: The OAIC has effectively written your headline data rule for you: no personal information into public generative AI tools. Your policy should say so in exactly those terms.
APRA expectations for regulated entities
APRA's 30 April 2026 letter to industry told banks, insurers and superannuation trustees that existing prudential standards already apply to AI risk, and criticised entities that treat AI as just another technology without operationalising governance. The letter names data leakage and the misuse of AI agents among the changing cyber threats, and APRA has flagged an active supervisory programme with stronger action where AI risks are not adequately managed. Law firm analyses map the expectations to CPS 234, CPS 230, CPS 220 and CPS 510.
What it means for your policy: If you are APRA-regulated, an enforced AI acceptable use policy with evidence behind it is table stakes. Add a sector annex and work through the dedicated checklist below.
APRA-regulated? The letter deserves its own work programme. Our APRA AI governance checklist for CISOs translates each of APRA's four observations into concrete controls, with this policy as the enforcement anchor.
Every clause, traced to its Australian driver
Auditors, boards and customers ask why each rule exists. This mapping gives you the answer, clause by clause.
How to customise it for your organisation
Work through these checks with the people responsible for the policy before approval and publication.
From a rule to a check
Test one rule before a wider rollout.
A written rule and an observed control are different evidence. Pick an AI app and a supported client, then check the action your policy requires.
What to check
- Name the app, account, client and input path.
- Choose the expected action for this rule.
- Repeat with harmless text as a comparison.
- Record the response, event and any unresolved gap.
- Illustrative policy rule
- Do not submit customer personal information to an AI tool unless your organisation has approved that use.
- Synthetic test input
- Summarise the renewal notes for Morgan Hale. Contact: morgan.hale@example.com.
FAQ
Australian AI acceptable use policy: common questions
Does the Privacy Act 1988 cover employee use of AI tools like ChatGPT?
Is the Voluntary AI Safety Standard mandatory in Australia?
What does APRA expect from banks, insurers and super funds on employee AI use?
Does our AI policy need to require data residency in Australia?
Bring one rule. Review the control.
Bring the AI app, data type and employee action you need to evaluate. We will review the supported client and the evidence to collect.