Why AI policy matters now
AI tools are already in your organisation. Your team is using ChatGPT, Gemini, Copilot, and other AI assistants to draft emails, analyse data, and solve problems. The question isn’t whether to use AI—it’s how to use it responsibly. Without clear policy, you risk data breaches, compliance violations, and inconsistent quality. With the right framework, you enable confident adoption while protecting what matters most. This guide helps leaders create practical AI policy that builds trust with teams, clients, and stakeholders.Understand requirements
Draft core principles
Set boundaries
Assign ownership
Australian regulatory landscape
Australia doesn’t have specific AI legislation yet, but existing laws apply to AI use in business. The Australian Government is taking a “voluntary framework” approach while monitoring for future regulation.What you need to know
Privacy Act 1988
Competition and Consumer Act 2010
Voluntary AI Ethics Framework
The Australian Government’s AI Ethics Principles provide guidance for responsible AI use. While not mandatory, they represent best practice expectations.Human-centred values
Human-centred values
Fairness
Fairness
Privacy and security
Privacy and security
Reliability and safety
Reliability and safety
Transparency and explainability
Transparency and explainability
Contestability
Contestability
Accountability
Accountability
Building your AI policy
Your policy doesn’t need to be perfect on day one. Start with core principles, test them with your team, and refine based on real use.At a glance: Policy fundamentals
Before diving into details, establish these foundational elements for your organisation.Approach to AI
Approach to AI
- Organisation wide: Adopt enterprise-secure tools with deliberate roll-out and self-service support
- Collaborate: Share wins, outcomes, and reflections so knowledge compounds
- Narrow use cases: Pilot specific workflows, measure results, then expand
- Stay current: Run quarterly briefings to track changes in the AI landscape
Stakeholder groups
Stakeholder groups
- Leadership Team: Executive sponsors and decision-makers
- AI Drivers: Cross-functional working group guiding programmes
- Champions Group: Innovation cohort that pilots before roll-out
- All staff: Employees and contractors using approved tools
Guiding principles
Guiding principles
- Privacy and security: Never compromise safeguards
- Employee experience: Deploy AI to remove friction and improve flow
- Customer experience: Use AI to elevate outcomes for clients
- Active driver: Lead responsible adoption rather than react to change
Step 1: Define your position
Before writing policy, answer these questions with your leadership team.What's our stance?
What matters most?
What's non-negotiable?
Who's accountable?
Step 2: Draft core principles
Here’s a starting framework. Customise the language and examples to match your organisation’s reality.Copy The Core Principle Template
Copy The Core Principle Template
Step 3: Set practical boundaries
Policy works when people know exactly what’s allowed and what isn’t. The traffic light framework below provides clear visual guidance your team can remember and apply.Traffic light guardrails
Use this simple framework to help your team make quick decisions about AI use.- OK to do
- Check first
- Never do
- Use approved enterprise AI tools on content you already have permission to view
- Leverage AI outputs after reviewing them for accuracy and tone
- Include customer or supplier names, job titles, company names, and work contact info in prompts
- Share public information, anonymised examples, and non-confidential technical questions
- Draft emails, summarise documents, and brainstorm ideas with approved tools
Detailed usage categories
The detailed framework below expands on the traffic light system. Use this when teams need specific guidance for edge cases.Copy The Practical Boundaries Template
Copy The Practical Boundaries Template
Personal information guidelines
Understanding what counts as personal information helps your team make safe decisions quickly. PII (Personal Information) is information that can identify a person on its own or when combined with other data.Allowed in approved enterprise tools (minimum necessary)
Allowed in approved enterprise tools (minimum necessary)
- Names (e.g., “Jane Smith”), company, role/title, work email, work phone, meeting details
- Business context such as project names and account IDs that are not regulated identifiers
- Public business information already available through normal channels
Prohibited PII (never input to any AI)
Prohibited PII (never input to any AI)
- Tax File Numbers and other national IDs (Medicare number, passport, driver’s licence)
- Financial numbers (credit card, bank account, BSB, CVV)
- Health or biometric data, medical details, genetic identifiers
- Authentication data (passwords, MFA codes, API keys, secrets)
- Sensitive personal attributes (racial/ethnic origin, religious beliefs, sexual orientation, political opinions)
- Children’s personal data
- Home addresses and personal phone numbers for customers or employees
Practical examples
These examples show the boundaries in action. Share them with your team during training.- Good
- Not allowed
- Ask first
- “Draft a follow-up email to Sarah Lee (Acme, Head of Ops, sarah.lee@acme.com) summarising our meeting notes”
- “Summarise this statement of work for internal review (contains no restricted PII)”
- “Generate bullet points for a client-safe status update using the attached PowerPoint”
- “Help me rewrite this paragraph for a non-technical audience”
- “Suggest a formula to split full names into first and last name columns in Excel”
Step 4: Document approval and oversight
Someone needs to be responsible for AI governance. Make it official.Copy The Governance Framework Template
Copy The Governance Framework Template
Step 5: Build innovation capacity
The Champions Group approach allows controlled experimentation while maintaining security. This accelerates learning without increasing risk.Champions Group framework
Purpose
Governance
Knowledge sharing
Step 6: Create incident response process
When things go wrong, speed and clarity matter. Document your response process before you need it.Stop the activity
Notify leadership
Document the details
Preserve evidence
Wait for direction
Tool-specific guidance
Different tools require different approaches. Provide specific guidance for the tools your organisation uses.Microsoft Copilot 365 guidance
If your organisation uses Microsoft Copilot, these specific guidelines help teams use it safely.Work within your permissions
Review every output
Keep prohibited data out
Signal AI contributions
Respect meeting notices
Engineering team guidance
Technical teams need specific boundaries for code-related AI use.Use approved tools for boilerplate
Protect proprietary work
Own licence compliance
Implementation roadmap
Don’t try to implement everything at once. Follow this 90-day rollout plan.Week 1-2: Leadership alignment
Week 3-4: Draft and circulate
Week 5-6: Tooling and infrastructure
Week 7-8: Team training
Week 9-12: Launch and monitor
Month 4+: Refine and scale
Practical resources
Use these templates to operationalise your policy faster.Common use-case recipes
Common use-case recipes
Draft customer email
“Draft a polite follow-up to [Name, Company, Role, Work Email] about the action items from our 18 Sept meeting. Keep it under 150 words and propose two time slots next week.”Summarise meeting notes
“Summarise the attached Teams notes into 5 bullets and 3 risks. Highlight decisions and owners.”Rewrite for clarity
“Rewrite the paragraph for a non-technical audience at Grade 8 reading level. Keep all numbers.”Excel helper
“Suggest a formula to splitLast, First into two columns and trim spaces. Explain each step.”Code review assistance
“Review this function for security vulnerabilities and suggest improvements. Focus on input validation and error handling.”AI access request form
AI access request form
Use case (1-2 lines): [Specific business need]
Data types: [What data will be processed? Any PII? If yes, justify and confirm it excludes all prohibited PII]
Risk level: Low / Medium / High
Owner / Reviewer: [Who will oversee this use?]
Pilot duration & budget (if applicable): [Timeline and cost]
Success metric: [How will you measure if this works?]
Approval required from: [Manager / AI Policy Owner / Executive Sponsor]
PII reference table
PII reference table
Australian government resources
OAIC AI Guidance
Australia's AI Ethics Framework
ACCC AI Guidance
Australian Cyber Security Centre
Next steps
Ready to build your policy?
- Copy the principle template and customise it for your organisation
- Set up a 2-hour workshop with your leadership team to align on priorities
- Assign your AI Policy Owner and set their first 30-day objectives
- Customise the traffic light guardrails for your team’s specific tools and context
- Schedule team training for month 2 of your rollout