Guide
Glossary
AI acceptable use policy
An AI acceptable use policy is a short internal document that sets out which AI tools staff may use, what they may use them for, and what information must never be entered into them. A good policy for a professional firm also covers who approves new tools, how AI output is checked before it reaches a client or a court, when clients are told AI was used, and how staff report a mistake. The OAIC recommends that organisations set policies and procedures for using AI systems, and says personal information, especially sensitive information, should not be entered into publicly available generative AI tools.
Also called AI usage policy, AI policy, generative AI policy
Last updated:
Example
In a law firm
Before rolling out a business AI plan, a 25-person commercial law firm adopts a two-page AI acceptable use policy. It lists the approved tools, bans entering client details into anything else, requires a lawyer to check every citation and reflects court practice notes on generative AI, such as the NSW Supreme Court's Practice Note SC Gen 23. Staff sign it at onboarding.
Where does the OAIC guidance come from?
The OAIC’s guidance on privacy and the use of commercially available AI products, published in October 2024, sets out the policy and data-entry recommendations above. For a starting draft, see the free AI acceptable use policy template in our templates and downloads.
Guides that explain it in context
Secure by design. Set up correctly. Fully managed.
Talk to us before you commit to anything
Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.
