Tools · Governance starter set · 1 of 3

An AI use policy you can adopt on Monday.

Most Australian small businesses have staff using AI assistants and no written statement of what may and may not go into them. This is the one page that fixes that: what is allowed, what is never allowed, what must be recorded, and who owns it. Copy it, fill in the brackets, sign it.

TemplateReviewed 4 September 2026Privacy Act 1988 · APPsNo email asked for
01

Purpose

[Business name] uses AI tools to work faster and better. This policy says how we use them without putting client, staff or business information at risk. It applies to everyone who works here, on any device used for work, for any AI tool, including free ones.

02

Approved tools

Only tools on the approved list may be used for work. The list is kept by [role] and reviewed quarterly. A tool is added only after someone has read its data terms and confirmed where prompts are stored, whether they are used for training, and in which country.

  • [Tool one, plan, account owner]
  • [Tool two, plan, account owner]
  • Free consumer plans of any tool: not approved for client or personal information
03

What may go in

  • Public information and our own published material
  • Internal drafts, plans and process descriptions that contain no personal information
  • Client information only where the client has agreed in writing and the tool is on the approved list with a business agreement
  • Personal information only after names, contact details and identifiers are removed or replaced
04

What never goes in

  • Tax file numbers, Medicare numbers, passport or licence numbers, bank details
  • Health information, including notes from appointments
  • Passwords, keys, security answers
  • Anything covered by a client confidentiality clause without that client’s written agreement
  • Another person’s information without a reason they would recognise (APP 6)
05

Checking the output

AI drafts are drafts. A person reads every AI produced document, calculation or message before it leaves the business or is acted on, and that person is responsible for it. Figures are checked against a source. Anything sent to a client says a person reviewed it if the client asks.

06

Records

Where an AI tool acts on client files or business systems (reads, writes, sends), the business keeps a record of what it did, when, and on whose instruction, for as long as the underlying record is kept. If no record can be kept, the tool is not used for that purpose.

07

Who owns this

[Owner or partner]
Responsibility
Approves the tool list and this policy; answers a client or regulator who asks
[Role]
Responsibility
Keeps the approved list and the data terms for each tool
Every person
Responsibility
Follows this policy and asks before using a tool that is not on the list
08

Review

Reviewed every six months or when a tool is added, a client asks, or the Privacy Act changes. Last reviewed [date]. Signed [name].

Want the record that goes with the policy?

A policy says what should happen. ProjxAI Attest records what did. The boundary conversation is the first hour, at no charge.