In most small businesses the AI policy conversation happens in the wrong order. Staff started using ChatGPT, Gemini or Copilot months ago, on personal accounts, on their own phones, with whatever text was handy. Some of that text was client names, quotes, contract clauses and complaint emails. The policy question is not whether to allow AI. It is already in the building. The question is whether anyone has written down the rules.
Below is a complete AI use policy for an Australian small business. It is published in full on this page, no email address required, no download gate. Copy it, replace the bracketed placeholders, have a director sign it, and you have a defensible policy this week. The sections after the policy explain how to adapt it and why naming one sanctioned tool makes the whole thing enforceable.
Why a two-page policy beats no policy
The risk in a small business is rarely the AI tool itself. It is unmanaged input. A free consumer chatbot account may use whatever is typed into it to improve the service, sits outside the business's control, keeps history on a personal login, and leaves no record the business can produce later. When the person leaves, the history leaves with them. None of that is visible to the owner until something goes wrong.
A short written policy fixes the part of this that can be fixed on paper: it names the tools staff may use, draws a bright line around the data that must never be pasted into any of them, and makes a human responsible for anything AI-written that leaves the business. Increasingly it is also simply asked for. Supplier questionnaires from larger customers, cyber insurance proposals and tender responses now routinely ask whether an AI use policy exists. "No" is becoming an expensive answer.
The policy, in full
Replace the bracketed placeholders, delete any clause that does not apply, and put a real name against clause 8. It is written for a business using Microsoft 365; swap the tool names if that is not you.
1. Purpose and scope
This policy sets out how [Business Name] and its people use artificial intelligence (AI) tools, including generative AI assistants and chatbots. It applies to all directors, employees and contractors, on any device, wherever work is performed, including work done on personal devices or personal accounts. Using AI for [Business Name] work in a way this policy prohibits is a breach of this policy even if the tool itself is free or personal.
2. Approved tools
The following AI tools are approved for business use, using a [Business Name] work account only: [Microsoft 365 Copilot / Copilot Chat, signed in with a work account]. Any other AI tool, and any approved tool accessed through a personal account, may not be used for business information. Staff may request approval of an additional tool from [role]; the request must cover what data the tool will receive and where that data is stored.
3. Information that must never be entered into an AI tool
The following must not be entered into any AI tool, including approved tools, unless [role] has approved the specific use in writing:
- Personal information about clients, staff or any individual: names combined with contact details, dates of birth, addresses, financial details, government identifiers such as TFNs or Medicare numbers.
- Health information about any individual, which the Privacy Act treats as sensitive information carrying stricter obligations.
- Client-confidential material: contracts, pricing, disputes, legal advice, or anything received under a non-disclosure agreement.
- [Business Name] financial records, credentials, passwords, API keys or security configurations.
- Any information subject to a court order, regulatory investigation or legal professional privilege.
Where a task genuinely needs AI help with material like this, the approved path is the sanctioned work tool under clause 2, which keeps the data inside [Business Name]'s Microsoft 365 environment, and only with the data minimised to what the task needs.
4. Privacy Act obligations
[Business Name] [is / may be] covered by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the Act applies, personal information may only be used for the purpose it was collected for, or a related purpose an individual would reasonably expect. Entering personal information into an AI tool that stores or learns from it can amount to a disclosure to the tool's operator. Staff must treat any use of personal information in an AI tool as a use or disclosure that needs a lawful basis, and ask [role] before proceeding rather than after.
5. Confidentiality
Obligations of confidence to clients, suppliers and staff apply in full when using AI tools. Entering confidential information into an unapproved tool is treated as an unauthorised disclosure, in the same way emailing it to a personal address would be. Contractual confidentiality clauses in client agreements bind [Business Name] regardless of which tool a staff member used.
6. Human review of AI output
AI output is a draft, not an answer. Before AI-generated content is sent to a client, published, or relied on for a decision:
- A named person must review it and takes responsibility for it as if they wrote it.
- Factual claims, figures, names, dates and legal or regulatory statements must be checked against a source other than the AI tool.
- AI must not be the decision-maker for matters significantly affecting an individual, including recruitment, performance and credit decisions; it may assist, a person decides.
7. Incident and breach reporting
Anyone who becomes aware that information covered by clause 3 has been entered into an unapproved tool, or that an AI tool has produced output that may have caused harm, must report it to [role] the same day. Reporting an honest mistake promptly will not attract disciplinary action; concealing one will. Where personal information is involved, [role] will assess whether the incident is a data breach requiring assessment under the Notifiable Data Breaches scheme and act on that assessment.
8. Ownership and review
This policy is owned by [name, role]. It will be reviewed every six months, or sooner if the business adopts a new AI tool or the law changes. Questions about whether a specific use is permitted go to the owner before the use, not after. Adopted on [date]. Signed: [director].
Adapting the template to your business
The template is deliberately conservative on privacy. Whether the Privacy Act formally covers your business turns mostly on turnover: businesses with annual turnover of $3 million or less are generally outside it, but there are important exceptions, including private health service providers and businesses that trade in personal information, and any business can opt in. Two practical notes on tailoring clause 4:
- If your turnover exceeds $3 million, or you handle health information, state plainly that the Act applies and keep clause 4 as written. There is no judgement call to make.
- If you sit under the threshold, resist the urge to delete the clause. Client contracts, professional obligations and plain commercial sense still require the same handling, larger customers increasingly flow privacy obligations down through supplier terms, and privacy reform has been moving in one direction. A policy built on the exemption is a policy you may have to rewrite; one built on good handling is not.
Beyond privacy, the clauses that most often need local tailoring are clause 2 (name the tools people actually have licences for) and clause 3 (add the specific data types your industry handles: patient records, trust account details, student information). The federal government's Voluntary AI Safety Standard is a useful checklist if you want to go further than this template, particularly its guardrails on accountability and record-keeping.
Why naming Copilot as the approved tool changes enforcement
A policy that only bans things loses to convenience. If the sanctioned path is slower than pasting into a free chatbot, the free chatbot wins quietly. The reason this template names Microsoft 365 Copilot as the approved tool is that it changes the enforcement problem from policing to defaulting: staff get an assistant inside Word, Excel, Outlook and Teams that is genuinely more useful for work tasks than a consumer tool, because it can see their files and mail, and the business gets commercial data protections that consumer accounts do not offer. Prompts and responses stay within the Microsoft 365 service boundary and are not used to train the underlying models.
It also makes clause 3 workable rather than aspirational. Inside the tenant, what Copilot can reach is governed by the permissions, sensitivity labels and audit trail the business already runs, so "never put client data in an AI tool" becomes "client data stays in the tenant, where the controls are". Frontrow has written separately on what that looks like in practice at /insights/is-microsoft-365-copilot-safe-company-data, and on the buying decision itself at /insights/copilot-for-business-australia.