AI POLICY · 10 MIN

An AI Acceptable Use Policy Australian Employees Will Actually Read

Bans drive shadow AI. Wishlists drive nothing. This is the structure pragmatic CISOs are using to land a policy that holds.

Run your first mission free

The six sections every AI policy needs

Policy structure

  • Purpose and scope. Who the policy applies to (employees, contractors, third parties) and which AI systems are in scope.
  • Sanctioned tools. The approved AI tool list with the business reason and the data classes each tool is permitted for.
  • Data classification rules. What information may go into which tool — typically Public OK, Internal OK with care, Confidential blocked, Restricted blocked.
  • Prohibited uses. Specific use cases never allowed — eg. fully automated HR decisions, deepfakes, customer-facing chat without disclosure.
  • Approval and review process. How a team requests a new AI tool and what evidence is required — privacy impact, data flow, vendor due diligence.
  • Monitoring and enforcement. How compliance is monitored and the consequences of breach.

Anchor frameworks

  • ISO/IEC 42001:2023 — AI Management System, the dominant certification target globally.
  • NIST AI Risk Management Framework — including the Generative AI Profile.
  • Australia’s Voluntary AI Safety Standard — eight guardrails the Government expects organisations to adopt.
  • OECD AI Principles — adopted by Australia, useful for vendor due diligence.
  • Privacy Act + APPs — particularly APP 6 (use and disclosure) and APP 11 (security of personal information).

The rollout that works

Publish the policy with an approved-tool list day one, a 30-day amnesty window to declare shadow usage, training for high-risk teams (legal, HR, sales, customer support), monitoring after the amnesty, and a quarterly review of tools and usage with the AI risk owner.

FOR AI GOVERNANCE LEADS

Generate your ISO 42001 AI policy pack in one mission.

FORTE/CYBERx produces a 30+ page ISO 42001-aligned AI management policy pack with editable acceptable-use, model-risk and shadow-AI controls.

Try the AI policy pack

FAQ

Do we need an AI acceptable use policy?

Yes. The Australian Voluntary AI Safety Standard, ISO/IEC 42001 and most cyber insurers now expect a written, communicated, enforced AI policy. Absence is itself evidence of unmanaged risk under the AICD Cyber Governance Principles.

Should we ban ChatGPT and Copilot?

No — outright bans drive shadow AI. The defensible position is an approved-tool list with data-classification rules and monitoring, paired with a clear path to request new tools.

How long should the policy be?

Two to four pages of policy with a one-page summary employees will actually read. Long policies are unread policies.

Who owns the policy?

Usually the CISO or CIO with sign-off from the legal, HR and risk leads. Owners must include a named human, not a committee, with annual review cadence.

Related

Stop chasing shadow AI. Start governing it.

Two free missions. No credit card. ISO 42001-aligned policy in minutes.