All insights
AI Security & Governance May 29, 2026 6 min read

Building an Acceptable Use Policy for AI

Most Australian organisations now have staff using generative AI, whether leadership has sanctioned it or not. An acceptable use policy is how you replace anxiety and informal habits with clear rules that protect data while still letting people benefit from the technology. Done well, it reduces shadow AI rather than driving it underground.

This guide covers what an AI acceptable use policy should contain and how to structure it so people actually read and follow it. It sits alongside broader AI governance, which sets the strategy your policy then operationalises.

Start with scope and definitions

A policy that staff cannot understand will not be followed. Open by defining what you mean by AI in plain terms: generative tools such as chatbots and image generators, AI features embedded in software they already use, and AI built into your own products. State clearly who the policy applies to, which typically includes employees, contractors, volunteers and any third party using your systems or handling your data.

Be explicit that the policy covers AI accessed on personal devices and personal accounts when used for work. Much shadow AI happens on phones and home browsers, and a policy that only mentions corporate devices leaves the biggest gap untouched.

Avoid the trap of writing the policy as if every reader is a security professional. The audience is the whole organisation, including people who have never thought about training data or model retention. Use concrete examples, define jargon the first time it appears, and lead with the few rules that matter most rather than burying them in a long document. A policy that is precise but unreadable will be ignored just as surely as one that is vague.

Define approved tools, not just prohibited ones

The most common policy failure is being all stick and no carrot. If you only list what staff cannot do, they will find their own tools. Instead, name the AI tools your organisation has approved, explain how to request access to new ones, and make clear that anything not on the list requires approval before use.

  • Maintain a living register of approved AI tools, the data they may handle, and who approved them.
  • Give staff a simple, fast path to request assessment of a new tool, so the answer is not always no by default.
  • Distinguish between enterprise AI platforms with contractual data protections and consumer tools that may train on inputs.

Set clear data handling rules

This is the heart of the policy. Staff need an unambiguous list of what information must never be entered into AI tools, particularly public ones that may use inputs for training. Spell out the categories rather than leaving people to judge sensitivity under time pressure.

  • Personal and sensitive information governed by the Privacy Act and the Australian Privacy Principles.
  • Health, financial and credential data.
  • Source code, security configurations and infrastructure details.
  • Confidential commercial, legal and board material.
  • Anything classified under government information-handling requirements.

For organisations in regulated sectors, link these rules to existing obligations. Financial services teams, for example, must reconcile AI data handling with their CPS 234 information security responsibilities, and councils should align with their state’s cyber policy.

A practical way to make data rules stick is to pair the prohibited list with a short list of clearly acceptable uses, so staff have permission as well as restriction. Drafting a generic email, summarising a public document, brainstorming ideas or generating non-sensitive code are the kinds of low-risk activities most policies should explicitly bless. When people can see what is allowed, they are far less likely to push the boundaries of what is not. The goal is to channel behaviour, not simply to forbid it.

It also helps to explain the why behind the rules. Staff who understand that public chatbots may use their input to train future models, and that sensitive data once submitted cannot reliably be retrieved or deleted, make better judgement calls in the grey areas a policy can never fully anticipate. A short paragraph explaining the underlying risks does more for compliance than a longer list of prohibitions.

Address accuracy, bias and human oversight

AI policies that focus only on data leakage miss half the risk. Generative AI produces confident, plausible output that can be wrong, biased or fabricated. Your policy should require human review of AI output before it is relied upon, used in decisions about people, or published externally.

Be specific about high-stakes uses. State that AI must not be the sole basis for decisions affecting employment, eligibility, safety or legal rights, and that staff remain accountable for any work they produce with AI assistance. This protects both the people affected and the organisation.

For government and public sector bodies this is not optional polish. Decisions that affect citizens carry transparency, fairness and review obligations that an opaque AI output cannot satisfy on its own. The policy should make clear that automated or AI-assisted decision-making in public-facing processes requires meaningful human involvement and a record of how the decision was reached. Where AI contributes to advice, the human signing off on that advice owns its accuracy.

Require disclosure and record-keeping

Decide when AI use must be disclosed. Many organisations now require staff to note when AI has materially contributed to external communications, reports or code, and to keep a record of significant AI-assisted work. This matters for accountability, intellectual property and, in government, for transparency obligations.

Calibrate the threshold sensibly so disclosure is meaningful rather than reflexive. Requiring a note every time someone uses an AI tool to fix a typo will simply train people to ignore the rule. Reserve disclosure for cases where it genuinely matters: external-facing material, work that informs a decision, code that enters production, or anything where a reader would reasonably want to know that AI was involved. Keeping the obligation focused makes it credible and far more likely to be followed.

Cover intellectual property and confidentiality

Make clear that staff must not input third-party confidential information or copyrighted material without rights to do so, and explain the organisation’s position on ownership of AI-generated output. The legal landscape here is still developing, so the policy should be conservative and direct staff to legal for anything material.

Build in enforcement and consequences

A policy without consequences is guidance, not policy. State how compliance is monitored, what breaches look like, and how they will be handled under existing disciplinary frameworks. Pair this with practical enablement: training, examples of acceptable and unacceptable use, and an easy way to ask questions. People comply with rules they understand and were helped to follow.

Assign ownership and review cycles

Name an accountable owner, ideally a CISO or Virtual CISO, with input from legal, privacy, HR and the business. AI use cuts across the whole organisation, so a policy written by IT alone tends to be technically sound but impractical, or written by legal alone and unworkable on the ground. Set a review cycle of every six to twelve months, and trigger an immediate review after any major platform change, regulatory update or incident.

A practical structure to start from

If you are writing from a blank page, a workable structure is: purpose and scope, definitions, approved tools and how to request more, data handling rules, accuracy and human oversight, disclosure and record-keeping, intellectual property, security responsibilities, enforcement, and ownership and review. Keep it to a length people will actually read, and put the data rules near the front where they belong.

An acceptable use policy is one piece of a wider programme that also includes vendor due diligence, technical controls and staff training. CISO Advisory helps Australian government and enterprise organisations write AI policies that are practical, defensible and aligned to their regulatory obligations. To discuss your situation, call 07 2112 8502 or visit our AI consulting page.

Frequently asked questions

Why do we need a separate AI acceptable use policy?

Existing IT and data policies rarely address AI-specific risks like training data leakage, model hallucination, or staff pasting confidential information into public chatbots. A dedicated AI policy makes the rules explicit, reduces shadow AI, and gives you a defensible position if an incident or regulator asks how AI use is governed.

Should we ban public AI tools outright?

Banning rarely works because staff use these tools anyway, just invisibly. A better approach is to approve specific tools, define what data may and may not be entered, and offer a sanctioned alternative. Outright bans tend to push usage into shadow AI, which is harder to monitor and far riskier.

What data should never go into a public AI tool?

Personal information, health records, financial data, credentials, source code, board papers, legal advice, unreleased commercial material and anything classified or covered by confidentiality obligations. Your policy should list these categories explicitly rather than relying on staff to judge sensitivity in the moment.

Who should own the AI policy?

Ownership usually sits with a senior accountable person such as the CISO or a Virtual CISO, with input from legal, privacy, HR and the business. AI use is cross-functional, so a single department writing it in isolation tends to miss either the technical risks or the practical realities of how staff work.

How often should the policy be reviewed?

At least every six to twelve months, and immediately after any major change such as adopting a new enterprise AI platform, a regulatory update, or an incident. AI capability and the threat landscape move quickly, so a policy left untouched for two years will be dangerously out of date.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act