Home  /  Insights  /  AI & Automation
AI & Automation

How to write an AI usage policy for a small business in Australia

Alpha Vault7 min readAustralia

The short answer

A workable AI usage policy for a small business doesn't need to be a legal treatise. It needs to say, in plain language, which AI tools staff may use, what information must never be typed into them, who checks AI-generated work before it goes out the door, and who is accountable when something goes wrong. One page that people actually read beats a forty-page document that sits in a shared drive nobody opens.

Most small Australian businesses already have an AI usage problem, in the sense that AI is already in use — just without anyone having decided the rules. Someone in the team is drafting emails with ChatGPT, summarising a contract with Gemini, or asking Copilot to tidy up a spreadsheet, and nobody thought to check whether that was fine first. That's not a criticism; it's simply what happens when a genuinely useful tool becomes free and instant. The businesses getting real value from AI aren't the ones avoiding it, as we've covered in why most businesses are underutilising AI — they're the ones using it constantly, deliberately, and with clear boundaries around what's off-limits.

A policy exists to draw those boundaries before an incident forces the conversation, not after. The good news is that for a business with a handful of staff, this is an afternoon's work, not a compliance project.

Why does a small business need an AI usage policy?

Without a policy, everyone in the business is quietly making their own judgement call about what's acceptable, and those judgement calls will not all be the same. One person assumes it's fine to paste a client's contact details into a free tool to draft a follow-up email. Another assumes the opposite. Neither is malicious — they simply have no shared reference point. The risk isn't AI itself; it's inconsistency, because inconsistency is exactly what allows sensitive information to leave the business without anyone noticing until it's too late to undo.

There's also a commercial upside to getting ahead of this. A written policy signals to clients, partners and (if you ever need it) insurers that the business treats data handling seriously, which matters more every year as AI use becomes something clients ask about directly rather than assume.

What should an AI usage policy actually cover?

A useful policy is built from a small number of sections, each answering one practical question. The detail sits in the examples, not the legal language.

SectionWhat it addressesExample rule
Approved toolsWhich AI tools staff may use for work"Only tools on the approved-tools list may be used with company or client data"
Data boundariesWhat can and can't be typed into an AI tool"Never enter customer details, financial data or unreleased pricing into a public AI tool"
VerificationHow AI-assisted output is checked before use"AI-drafted client communications must be reviewed by a human before sending"
Ownership & accountabilityWho owns the output and who answers for mistakes"The staff member who used the tool is accountable for the accuracy of the final output"
Incident reportingWhat to do if something goes wrong"Report any accidental data exposure to the owner within 24 hours"

Notice what's absent: a list of banned tools, or a blanket "don't use AI" instruction. Those approaches tend to fail quietly, because staff keep using the tools anyway, just without telling anyone. A policy that legitimises sensible use while drawing a hard line around data is far more likely to actually be followed.

What information should never go into a public AI tool?

The clearest rule to give staff is to treat a public AI tool as a third party the business is disclosing information to, because in most practical cases, that's exactly what's happening. If your business handles personal information, the Australian Privacy Principles already require you to think about who you're disclosing it to and why — a free AI tool is no exception just because the disclosure feels informal.

In practice, keep these categories out of any tool that isn't on your approved list: customer names, contact details or order history; financial records and banking details; contracts and supplier terms; unreleased pricing, products or marketing plans; source code, passwords or access credentials; and anything covered by a confidentiality clause with a client. If a task genuinely requires working with that kind of data, either use a business-tier tool with a proper data agreement in place, or do it without AI assistance for now.

How do you deal with "shadow AI" when staff are already using it?

"Shadow AI" is the term for staff using AI tools for work without the business knowing — often on a personal account, a personal device, outside any approved list. Banning AI outright almost always creates more shadow AI, not less, because the underlying need for the tool doesn't disappear, it just goes somewhere you can't see it.

The more effective starting point is an honest, blame-free audit: ask the team directly what they're already using AI for, rather than assuming you know. You'll usually find a handful of genuinely useful, low-risk habits worth keeping (drafting, summarising, tidying data) alongside one or two that need a boundary drawn around them fast. Turning that shadow use into approved, visible use is most of the value of writing the policy in the first place, and it pairs naturally with deciding which business tasks to automate first in a more structured way.

Who owns AI-generated work, and who's accountable when it's wrong?

Ownership and accountability are two different questions, and a policy should answer both. Ownership is straightforward: anything a staff member produces with AI for work purposes belongs to the business, the same as anything else they produce on the job. Accountability is the part that trips people up — the tool having generated the error doesn't transfer responsibility away from the person who used it and the business that published it.

This is precisely why the verification line in the earlier table matters more than any other. A customer-facing chatbot response, an AI-drafted contract clause, or AI-summarised financial figures should each have a defined human checkpoint before they're relied on externally — the same principle covered in automating customer support, where what stays human is as important as what gets automated.

How long should the policy be, and how often should you review it?

Aim for one page. A policy nobody can hold in their head while working is a policy nobody follows, and the small businesses that get this right tend to write something closer to a checklist than a contract. Put it somewhere staff will actually see it — onboarding documents, a shared wiki, a printed copy near the desk — rather than a folder reserved for compliance paperwork.

Because the tools and the ways staff use them keep changing quickly, review the policy every quarter or two rather than treating it as a one-off document. Assign one person — often the owner in a small business — to own updates, so the review actually happens instead of quietly lapsing.

Where to start

Don't wait for a perfect policy before writing anything down. Start with the five sections above, fill in your own approved tools and your own data boundaries, run it past your team for fifteen minutes so they understand why it exists, and revisit it next quarter. The businesses that come unstuck with AI are rarely the ones using it too much — they're the ones who let the rules stay unwritten until a mistake wrote them instead. If you want a second opinion on where your business's real AI risks and opportunities sit, book a consultation and we'll work through it together.

Frequently asked questions

Do small businesses actually need a written AI policy, or is a verbal understanding enough?

Once more than a couple of people are using AI tools for work, a verbal understanding drifts fast — each person forms their own idea of what's fine. A short written policy costs an afternoon and gives you something to point to when a new hire starts or a question comes up.

What is "shadow AI" and why does it matter?

Shadow AI is staff using AI tools for work without the business knowing or approving it — often on personal accounts, on personal devices. It matters because you have no visibility into what data has been typed into which tool, which is exactly the exposure a policy is meant to close.

Can staff use free tools like ChatGPT for work tasks?

Often yes, for low-risk tasks like drafting or summarising, provided no confidential or personal information goes into the prompt. Many free consumer tiers use conversations to train future models, so treat anything typed into one as potentially non-confidential from that point on.

Who is responsible if AI-generated content is wrong or breaches someone else's copyright?

The business, in almost every practical sense — a tool having generated something doesn't shift responsibility away from the person who used it and published it. This is why a verification step before anything AI-assisted goes external is the single most important line in the policy.

How often should an AI usage policy be updated?

Every quarter or two is a reasonable starting cadence, since the tools staff reach for and the tasks they use them on both change quickly. Treat it as a living one-pager you revisit, not a document you file away once and forget.

Do we need a lawyer to write one?

Not for a first version. A clear, practical one-pager covering approved tools, data boundaries, verification and accountability will cover most small businesses. Involve a lawyer once you're handling sensitive client data under contract, or operating in a regulated industry.

Get AI working for your business, safely

A complimentary 30-minute consultation — direct, substantive, and focused entirely on your business.

Book a free consultation →