The six sections every AI policy needs
Policy structure
- Purpose and scope. Who the policy applies to (employees, contractors, third parties) and which AI systems are in scope.
- Sanctioned tools. The approved AI tool list with the business reason and the data classes each tool is permitted for.
- Data classification rules. What information may go into which tool — typically Public OK, Internal OK with care, Confidential blocked, Restricted blocked.
- Prohibited uses. Specific use cases never allowed — eg. fully automated HR decisions, deepfakes, customer-facing chat without disclosure.
- Approval and review process. How a team requests a new AI tool and what evidence is required — privacy impact, data flow, vendor due diligence.
- Monitoring and enforcement. How compliance is monitored and the consequences of breach.
Anchor frameworks
- ISO/IEC 42001:2023 — AI Management System, the dominant certification target globally.
- NIST AI Risk Management Framework — including the Generative AI Profile.
- Australia’s Voluntary AI Safety Standard — eight guardrails the Government expects organisations to adopt.
- OECD AI Principles — adopted by Australia, useful for vendor due diligence.
- Privacy Act + APPs — particularly APP 6 (use and disclosure) and APP 11 (security of personal information).
The rollout that works
Publish the policy with an approved-tool list day one, a 30-day amnesty window to declare shadow usage, training for high-risk teams (legal, HR, sales, customer support), monitoring after the amnesty, and a quarterly review of tools and usage with the AI risk owner.
FOR AI GOVERNANCE LEADS
Generate your ISO 42001 AI policy pack in one mission.
FORTE/CYBERx produces a 30+ page ISO 42001-aligned AI management policy pack with editable acceptable-use, model-risk and shadow-AI controls.
Try the AI policy packFAQ
Do we need an AI acceptable use policy?
Yes. The Australian Voluntary AI Safety Standard, ISO/IEC 42001 and most cyber insurers now expect a written, communicated, enforced AI policy. Absence is itself evidence of unmanaged risk under the AICD Cyber Governance Principles.
Should we ban ChatGPT and Copilot?
No — outright bans drive shadow AI. The defensible position is an approved-tool list with data-classification rules and monitoring, paired with a clear path to request new tools.
How long should the policy be?
Two to four pages of policy with a one-page summary employees will actually read. Long policies are unread policies.
Who owns the policy?
Usually the CISO or CIO with sign-off from the legal, HR and risk leads. Owners must include a named human, not a committee, with annual review cadence.