Most AI policies are either missing or unreadable. This one is a page and a half, written for Australian SMBs, and free to use with no email gate. The highlighted fields are yours to fill in; delete anything that doesn't fit how you work.
A policy on its own doesn't stop data leaving – it tells honest people what right looks like. Pair it with the technical controls (business accounts, single sign-on, access rules) described on the secure AI rollout page, and it becomes real. This template is general information, not legal advice; if you operate under specific regulatory obligations, have your adviser review the adapted version.
AI tools make parts of our work faster and better, and we encourage using them well. They also make it easy to send business and client information to systems we don't control. This policy exists so everyone knows which tools are approved, what can and can't go into them, and what to do when something goes wrong. It applies to everyone who works for [BUSINESS NAME], including contractors, on any device used for work.
The following AI tools are approved for work use, on business accounts only:
Anything not on this list is not approved for work information. If a tool would help you, ask [OWNER] – the list is meant to grow, and asking takes a day, not a committee.
If work or client information ends up in an unapproved tool or a personal account – yours or anyone's – tell [OWNER] the same day. The goal is fixing it fast, not blame; the only career-limiting move is hiding it.
LICENCE: COPY AND ADAPT THIS FREELY FOR YOUR OWN BUSINESS. NO ATTRIBUTION NEEDED. GENERAL INFORMATION, NOT LEGAL ADVICE.
The AI-Ready 365 assessment maps what your people are already using, sets the technical controls this policy assumes, and tailors the policy to your business – $990 + GST, fee waived if you're already AI-ready.