GuideAI at work

How to write an AI use policy for a small team, with a template

What the government's AI policy guide says a policy should cover, how to write a one-page version for your team in an afternoon, and a template to adapt.

A clipboard holding an one-page document, with a small robot figure standing beside it reading it, on a violet background. The document's title in bold reads "AI POLICY", with a few green tick boxes below.
Illustration: Digital Advisors

If your team already uses ChatGPT, Copilot, Gemini or an AI note-taker, you have an AI practice whether or not anyone wrote it down. A short written policy turns it into agreed rules: which tools and accounts are allowed, what never gets pasted in, and who checks the output before it reaches a customer.

You don’t have to start from a blank page. The National AI Centre’s Guidance for AI Adoption, published on 21 October 2025, includes a free AI policy guide and template, an AI register template and an AI screening tool. The government template includes roles such as an AI governance committee, so below we summarise it and then cut it down to one page for a small team.

Why a short written policy, and why now

AI features are arriving inside tools you already pay for, sometimes switched on by default. Google Meet’s note-taker is one example we covered in Google Meet’s AI note-taker switches on by default. A written rule about who approves new AI tools is the easiest way to keep track.

The government guide says: “An AI policy sets out your organisation’s commitment to using AI responsibly.” For a small team, the practical value is that staff know what is allowed, and you have something to show a client who asks how you handle their information.

What the government guide says a policy should cover

The AI policy guide and template (version 1.0, October 2025, with a PDF guide and Word template) is laid out in these parts:

Section What it covers
Purpose Why your business uses AI and what the policy is for
Scope Who and what the policy applies to, with a plain definition of an AI system
Policy statements Seven principles: ethical and human-centred use; clear accountability; risk and impact assessment; quality, reliability and security; fairness and inclusion; transparency and contestability; human oversight and control
Governance and compliance Roles and responsibilities, how new AI uses are screened and approved, and how incidents are handled
Policy review An annual review, plus a review after significant AI incidents, new impactful AI technologies, or changes to laws, regulations or industry standards

A few lines from the template translate directly to a small business. “Each AI system must have an accountable person.” “Humans must be able to pause, override or shut down AI systems when necessary.” All approved AI systems “must be clearly recorded in our AI register”. On transparency: “We must inform impacted parties where appropriate.”

The guide also tells you to adapt it: align the statements with your values, match roles to your existing structure, use your own terminology, and “seek feedback to ensure the AI policy is fit for purpose”. It notes that “for smaller organisations, one person may hold multiple roles”. In a small team, on our reading, that usually means the owner or practice manager approves tools, keeps the register and runs the review.

Where the law comes in, and where it’s good practice

The government policy guide is guidance, not law. Privacy law is different. The OAIC’s guidance on privacy and commercially available AI products says privacy obligations “will apply to any personal information input into an AI system, as well as the output data generated by AI (where it contains personal information)”. Those obligations apply to businesses covered by the Privacy Act. Whether yours is covered, and what changes in December, is set out in our story on Privacy Act changes for small businesses.

Among the points the OAIC makes:

  • “As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved.”
  • Businesses “should update their privacy policies and notifications with clear and transparent information about their use of AI”.
  • Public-facing AI tools such as chatbots should be “clearly identified as such to external users such as customers”.
  • It is important that “a human user should be responsible for verifying the accuracy of any personal information obtained through AI”.

Even if your business isn’t covered by the Privacy Act, on our reading these are sensible rules to adopt, because they protect client information either way.

How to write yours in an afternoon

  1. List what’s already in use (30 minutes). Ask each person which AI tools they use, on which account, and for what. Include AI features inside existing software.
  2. Decide the approved list (30 minutes). Prefer business accounts you control over personal free accounts. Note who owns each one.
  3. Write the “never goes in” list (20 minutes). Start with the OAIC’s recommendation on personal and sensitive information, then add what matters in your trade: client files, passwords, financial details, anything under a confidentiality agreement.
  4. Set the checking rule (15 minutes). Decide who checks what before it’s used. Our guide to starting small with a task you can check helps here.
  5. Decide on disclosure (15 minutes). Where customers deal directly with AI, or AI-generated work goes out under your name, decide what you tell them. Update your privacy policy if you’re covered by the Privacy Act.
  6. Name the approver and start the register (20 minutes). One person approves new tools. The register can be a simple spreadsheet.
  7. Share it, get feedback, set a review date (30 minutes). Walk the team through it, adjust, and put the review in the calendar.

Illustrative template — adapt it to your business

Based on the government guide and OAIC guidance, simplified for a small team. Replace the fields in parentheses with your own details.

(your business name) AI use policy Version (number), approved by (name) on (date). Next review: (date, no later than 12 months away).

  1. Purpose. We use AI tools to (for example, draft emails, summarise meeting notes, prepare first drafts of documents). This policy sets out how we use them safely and in line with our obligations to clients.

  2. Who it covers. Everyone who works for (your business name), including contractors, on any device used for our work.

  3. Approved tools and accounts. Only these tools may be used for work, and only through business accounts: (tool name, account type, owner). Personal accounts must not be used for client work.

  4. What must never go in. Do not enter into any AI tool unless (approver’s name) has approved that specific use: personal information about clients, staff or suppliers; sensitive information such as health details; passwords or login details; bank or payment details; (other confidential material specific to your business). Never enter these into free, publicly available AI tools.

  5. Check before use. A person reads and checks all AI output before it is sent, published or relied on. The person who sends it is responsible for it. Check facts, figures and names.

  6. Telling customers. Where a customer deals directly with an AI tool (such as a website chat), we say so. We describe our use of AI in our privacy policy (where the Privacy Act applies to us). If a client asks whether AI was used on their work, we answer plainly.

  7. New tools and features. Nobody starts using a new AI tool, or switches on a new AI feature in existing software, without approval from (approver’s name). Before approving, they check where data is stored, whether it is used to train the provider’s models, and whether the feature can be switched off.

  8. Register. (Approver’s name) keeps a register of approved AI tools in (location), recording: tool, what it’s used for, account owner, information allowed, date approved.

  9. Problems. If something goes wrong, such as the wrong information entered or incorrect output sent, tell (name) the same day.

  10. Review. We review this policy every 12 months, and sooner if we have an AI incident, adopt a significant new tool, or the law changes.

Checklist

  • Download the government AI policy guide and template and skim the seven policy statements
  • List every AI tool and AI feature your team uses, and the account behind each
  • Move work use onto business accounts you control
  • Write your “never goes in” list, starting with personal and sensitive information
  • Name one person to approve new tools and keep the register
  • Start the register using the AI register template or a spreadsheet
  • Decide what you tell customers, and update your privacy policy if the Privacy Act applies to you
  • Share the policy with the team, collect feedback, and book the review date
  • Brief staff on writing good prompts with our guide to better AI briefs