What Founders Should Put In An AI Use Policy

AI use often starts a little informally.

A founder tries an AI tool to draft an email, summarise a document or brainstorm a few ideas. It works well, so the rest of the team starts experimenting too.

Before long, one person is using AI for marketing content, another is uploading customer documents for review and an AI meeting assistant is joining calls that may contain confidential information. The business is using AI in several different ways, but nobody has properly decided where it should be used, what information can be entered or who is responsible for checking the result.

That is where an AI use policy becomes useful.

An AI use policy can help make sure everyone understands where AI fits into the business, where the boundaries are and what needs to happen before AI-generated work is relied on.

What Is An AI Use Policy?

An AI use policy is an internal document that explains how people working in your business can use AI.

It may apply to employees, contractors, directors and anyone else who uses AI tools for business purposes. Depending on how your organisation operates, it could cover generative AI platforms, meeting transcription tools, chatbots, automated decision-making systems and AI features built into software your team already uses.

A useful policy should answer the questions that come up during an ordinary working day.

Can someone use AI to improve an internal email? Can they upload a customer contract for analysis? Can AI draft a response that will be sent directly to a customer? Can an employee install an AI browser extension or connect a tool to the company inbox?

There is no single answer that works for every business. The right rules will depend on what the business does, what information it handles and how much harm could result if an AI tool produces the wrong answer or exposes something it should not.

Can I Just Use An Online AI Policy Template?

A template can be a place to start.

The Australian Government has published an AI policy guide and template through the National AI Centre. It covers useful foundations such as accountability, risk assessments, fairness, transparency, security, human oversight and incident management.

The government presents it as a starting point rather than a finished policy that every organisation can adopt unchanged. That distinction matters.

A general template does not know which AI tools your team uses, what information your business collects, what promises you have made to customers or how AI is being used in practice. It may give you the right headings without giving your staff clear answers.

A design agency, for example, may be comfortable using AI to generate early creative ideas. A healthcare provider may need much stricter controls around sensitive information. A recruitment business may need additional safeguards where AI could influence decisions about candidates. A software company may be particularly concerned about source code, confidential product information and ownership of AI-assisted work.

Simply adding your company name to a template can create a policy that looks complete but is difficult to apply.

A better approach is to use the government template as a foundation, then tailor it to the tools, work and risks inside your own business.

Decide Where AI Can And Cannot Be Used

Before drafting detailed rules, founders should decide where AI is genuinely useful and where it may create more risk than value.

This does not need to become a choice between allowing AI everywhere and banning it completely. Most businesses will take a more practical approach.

You might allow staff to use AI to brainstorm ideas, reorganise non-confidential text or prepare an early first draft. You may require approval before it is used for customer communications, contract analysis, recruitment, financial information or work involving personal data.

Some uses may be inappropriate altogether. A business might prohibit staff from using AI to impersonate another person, generate deceptive content, make final decisions about employees or customers, or provide professional advice without review by someone suitably qualified.

The policy should also identify which tools may be used for each purpose.

Approving a platform does not mean approving it for every task. An enterprise AI account might be suitable for drafting an internal document but not for processing health information or assessing job candidates. Free public tools, personal accounts, meeting assistants, browser extensions and AI features built into existing software may all require different rules.

Before approving a tool, the business should understand how it handles information. This may include checking where data is stored, who can access it, whether prompts or uploads are used to train the provider’s systems, how long information is retained and what happens when an account is closed.

Staff should also know how to request approval for a new tool. Otherwise, people may simply adopt whichever platform is easiest to access, leaving the business with little idea of where its information is going.

Be Clear About What Information Can Be Entered

One of the most important parts of an AI use policy is explaining what staff may and may not enter into an AI system.

A broad instruction such as “do not upload confidential information” is rarely enough. People can have very different ideas about what counts as confidential.

The policy may need to address customer information, personal and sensitive information, internal financial records, business plans, contracts, source code, passwords, access credentials, legally privileged material and documents supplied by another party in confidence.

The rules may depend on the tool being used. Entering information into an approved enterprise account with appropriate contractual and security protections may create different risks from pasting the same information into a free public chatbot through a personal account.

Privacy law may also be relevant. The federal Privacy Act generally applies to private-sector organisations with annual turnover above $3 million, although some smaller businesses are covered because of the activities they undertake. Even where the Privacy Act does not apply, contractual, professional, confidentiality or industry-specific obligations may still restrict what can be uploaded.

The most useful policies give examples connected to the team’s actual work. Telling a sales team not to upload unannounced pricing information, or telling a customer support team not to enter identifiable complaint records, is much clearer than relying on a general warning about sensitive data.

Explain How AI-Generated Work Must Be Reviewed

AI can produce useful work, but it can also generate information that is inaccurate, outdated, incomplete or entirely invented.

Using an AI tool does not transfer responsibility for the final result to the technology or its provider. If AI helps prepare a customer email, marketing claim, report or recommendation, the business still needs to make sure the result is appropriate before it is used.

The policy should explain what review is required and who is qualified to carry it out.

A requirement that “a human must check the output” may sound reassuring, but it is only useful if that person can recognise when the answer is wrong. Someone without legal, medical, financial or technical expertise may not provide meaningful oversight simply by reading the result before sending it.

Depending on the task, the policy may require factual claims to be checked against reliable sources, customer-facing material to be approved by a manager or specialist advice to be reviewed by a suitably qualified person. It may also identify decisions that must not be made solely by an AI system.

The higher the consequences of getting something wrong, the stronger the review process should be.

Set Rules For Customer-Facing AI

AI used behind the scenes to reorganise notes usually presents a different level of risk from AI used to communicate with customers or make decisions that affect them.

If your business uses AI for marketing, customer support, chatbots, automated emails or personalised recommendations, the policy should explain what must happen before the output reaches a customer.

Marketing claims still need to be accurate. Customer communications still need to reflect the business’s actual position. A misleading statement does not become acceptable because it was generated by AI.

The policy should also address when people need to be told that AI is being used. There is no blanket rule requiring every use of AI to be disclosed. However, disclosure may be appropriate where a customer could otherwise be misled, where they believe they are speaking to a person or where AI has materially influenced an important decision.

Customers should also have a way to reach a person, question an outcome or report an error where appropriate.

From 10 December 2026, businesses covered by the Australian Privacy Principles may also need to provide additional information in their Privacy Policies where a computer program uses personal information to make, or play a substantial and direct role in making, a decision that could significantly affect someone’s rights or interests.

An AI use policy can help a business identify these systems, but it may not be the only document that needs updating.

Cover Confidentiality, Security And Intellectual Property

AI use does not sit separately from the business’s existing legal and security obligations.

An AI use policy may need to work alongside the organisation’s Privacy Policy, cybersecurity procedures, confidentiality requirements, employment policies, data breach response plan and contracts with customers, workers and suppliers.

For example, a customer contract may limit how certain information can be used. An agreement with an AI provider may allow prompts or uploads to be retained. An AI tool connected to company email or cloud storage may have access to far more information than a standalone chatbot.

The policy should therefore address integrations, access permissions and who may connect AI tools to business systems. It should also explain what happens when a staff member leaves or when an account or integration may have been compromised.

Intellectual property needs attention too.

Staff may upload material that the business does not have permission to use, such as third-party photographs, code, articles, designs or customer documents. The business may also use an AI-generated output without knowing whether it closely resembles protected material created by someone else.

The policy can require staff to confirm they have permission to upload material, check relevant platform terms and avoid assuming every AI-generated output is automatically safe to use commercially.

It may also need to address how AI-assisted work created by employees and contractors is documented and owned. Copyright protection for many types of material requires human authorship, so substantially AI-generated work may not always receive the protection a business expects. Employment, contractor and intellectual property agreements may help allocate rights between the parties, but they cannot guarantee that copyright exists in an output.

Tell Staff What To Do When Something Goes Wrong

Even a good policy will not prevent every mistake.

Someone may upload the wrong file, send an unchecked AI-generated statement to a customer or connect a tool to more information than expected. An AI meeting assistant may record a conversation it should not have joined.

The policy should tell staff who to contact, what information to preserve and whether they should stop using the tool while the issue is assessed.

Early reporting should be encouraged. If employees are worried that admitting an AI-related mistake will automatically lead to punishment, they may delay reporting it and make the problem harder to contain.

Depending on what happened, the incident may also need to be handled under the business’s existing privacy, cybersecurity, contractual or data breach procedures.

Give Someone Responsibility For The Policy

A small business may not need an AI governance committee or a complicated approval structure. It does need someone who owns the policy and has authority to make decisions about AI use.

That person may approve new tools, review higher-risk uses, arrange staff training and coordinate the response to incidents. Other people may need to be involved when a proposed use raises legal, privacy, employment, security or operational concerns.

The policy should use roles that actually exist in the business. Copying titles such as “AI governance committee” or “compliance monitor” from a template will not help if nobody knows who those people are.

It can also be useful to keep a simple AI register recording which systems the business uses, what they are approved for, who is responsible for them and any important limitations.

The policy should be reviewed when the business introduces a significant new tool or use, after an AI-related incident or when relevant laws, guidance or supplier terms change. Staff should also be shown how the policy applies to their role rather than being expected to find and interpret it on their own.

Should A Lawyer Help Draft Your AI Use Policy?

A founder may be able to identify some obvious rules, such as banning passwords from public AI tools or requiring customer-facing content to be reviewed.

The harder part is working out how those rules should reflect the business’s legal and contractual obligations.

An AI use policy may need to account for privacy, confidentiality, intellectual property, consumer law, employment practices and agreements with customers, workers, suppliers and AI providers. It should also fit with the business’s existing Privacy Policy, employment documents, contractor agreements and security procedures.

Getting help from a legal expert can be valuable because they can identify where the business’s proposed AI uses interact with those obligations and turn them into clear, practical rules.

The goal is not to make the policy longer or more restrictive than necessary. It is to create a document that reflects how the business actually works and gives the team guidance they can use.

Key Takeaways

The Australian Government’s AI policy template is a useful starting point, but it is not a complete answer for every business.

A practical AI use policy should explain where AI can be used, which tools are approved, what information staff may enter, how outputs must be reviewed and what should happen when something goes wrong.

The best policy is not necessarily the longest. It is the one that turns the business’s actual risks and legal obligations into rules the team can understand and follow.

If you would like a consultation on an AI use policy for your small business, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.