A small business does not need a governance framework. It needs five things written down: which tools are allowed, what must never be pasted into them, who checks the output before it leaves, when a client gets told, and who carries the responsibility. That fits on one page and takes an afternoon. The Privacy Act change commencing 10 December 2026 does not apply to most small businesses, because businesses turning over $3 million or less are generally exempt from the Act entirely — but health service providers are covered regardless of turnover, and that catches a lot of small practices.
Why the enterprise template does not fit you
Nearly every AI policy template circulating right now was written for an organisation with a compliance function. It assigns responsibilities to a Data Governance Lead and a Risk Committee, and it refers decisions to an escalation path. In a business of twelve people those roles are all the same person, and that person is busy.
The result is a document that gets adopted, filed and never opened. That is worse than having nothing, because it produces the appearance of control. If something goes wrong later, "we had a policy" is a weak position when nobody in the business can tell you what was in it.
The test for whether your policy is the right length is simple. Can a new starter read it in two minutes and then correctly answer whether they may paste a client email into ChatGPT? If not, length is not your friend.
What actually has to be in it
Everything else in a long template is either an elaboration of one of these or a description of a process you do not have.
- Which tools are approved
- Name them. Not "approved AI tools" — the actual products, and the actual accounts. A paid business account and a free consumer account of the same product are different things, because the free one usually has different defaults for how your input is handled. If a tool is not on the list, the rule is ask first.
- What never gets pasted in
- This is the clause that prevents the incident. Be specific to your business: client names and contact details, anything lifted from a client file, health information, payment details, credentials, staff records, anything covered by an NDA. Finish it with a default — if you are unsure, the answer is no.
- Who reads it before it leaves
- Nothing generated goes to a client, a regulator or the public until a person has read it end to end and is willing to put their name on it. Most of the public AI failures of the last two years were not tool failures. They were review failures.
- When you tell the client
- This one is genuinely industry-specific and you should not copy someone else’s. A design studio and a law firm owe their clients different things. Write the rule you would be comfortable reading aloud to the client it applies to.
- Who owns the output
- The person who sends the work is responsible for the work. Say it plainly, because the alternative gets tested exactly once — "the AI wrote it" is not a defence, and it should be clear in advance that it will not be treated as one.
The template — take it
Copy this, fill the brackets, delete what does not apply. It is not legal advice, and if you are in a regulated profession you should check it against your own obligations before it goes on the wall.
AI use at [business name]
- Tools you can use[List the actual products and account types.] If it is not on this list, ask before using it for work. Free personal accounts are not on this list. If you want something added, say so — the list is meant to grow.
- What never goes inClient names or contact details, anything from a client file, health information, payment details, passwords, staff records, anything under an NDA. If you are not sure whether something counts, assume it does.
- Someone reads it before it leavesNothing drafted with AI goes to a client, a regulator or the public until a person has read it in full and is happy to put their name to it. That person is responsible for it being right.
- When we tell people[Your rule. For example: we tell a client when AI was used to draft something they will rely on, and we never use it to produce anything presented as personal advice.]
- You own what you sendThe person who sends the work owns the work. "The AI wrote it" is not an explanation we will accept, and knowing that in advance is the point of this line.
- QuestionsAnything unclear, or a tool you want on the list: [name, email]. Last updated [date]. Applies to everyone who does work for us, including contractors.
The 10 December 2026 change, and whether it touches you
You are probably being emailed about this one. The Privacy and Other Legislation Amendment Act 2024 added three new provisions to Australian Privacy Principle 1 — APPs 1.7, 1.8 and 1.9 — and they commence on 10 December 2026.
What they require is narrower than the emails suggest. If a computer program uses personal information to make a decision that could reasonably be expected to significantly affect someone’s rights or interests, your privacy policy has to say so, and say what kinds of information and decisions are involved. Drafting a newsletter with ChatGPT is not that. Automating who gets approved, ranked, priced or rejected might be.
Then there is the part almost nobody selling you a policy mentions: the Privacy Act largely does not apply to small business at all. The exemption covers businesses with an annual turnover of $3 million or less, and most of the businesses being marketed to about this deadline are under that line.
The exceptions are what matter. Turnover is irrelevant if you are a health service provider — which means physiotherapists, dentists, psychologists, allied health, a one-room practice, all of it. It is also irrelevant if you trade in personal information, hold a Commonwealth contract, are a credit reporting body, are a reporting entity under the AML/CTF Act, or are accredited under the Consumer Data Right. Those businesses are inside the Act at any size, and the December change applies to them.
The OAIC flagged guidance for release by September 2026, ahead of commencement. If you are in one of those categories, that guidance is the thing to wait for rather than a vendor’s summary of it.
Being outside the Privacy Act is not the same as being safe. It only means the consequence of a bad day is commercial and reputational rather than regulatory.
Rolling it out without a staff revolt
- Do not open with the banA policy that arrives as a list of prohibitions gets read as a signal that leadership has decided AI is a problem. Use is then hidden rather than reduced, which is the outcome you least want, because you lose visibility of it entirely.
- Give people a sanctioned place to work firstThe rule "do not paste client data into ChatGPT" is much easier to follow when there is an approved tool that does the job. A ban with no alternative is an instruction to be less effective, and it will be quietly ignored.
- Write it with the people who will use itTwenty minutes with the two or three people already using AI daily will produce a better banned-data clause than an afternoon of your own drafting. They know what they have been tempted to paste in.
- Put a date on it and mean itTools and their defaults change. A policy naming a specific product needs revisiting, so set a review date and treat it as real. A policy nobody has updated in two years is read as one nobody is enforcing.
- Say what happens when someone gets it wrongIf the answer is "tell me straight away and we will sort it," write that down. People conceal mistakes when the consequence is unclear, and a concealed mistake is the one that becomes expensive.
Why we publish this
We run AI training for businesses, and a policy is usually the first thing a client asks for. We would rather hand this over than sell it, partly because a policy you wrote yourself is one you can actually enforce.
Our own position on how we use AI in client work is published at how we use AI. Where the banned-data clause is the hard part — because the work genuinely involves confidential material — the answer is sometimes a model that runs on hardware you own, which is what private AI is for.
This is general information, not legal advice. The privacy law summarised above is linked to its source below, and if it changes this page changes.
Sources
- Privacy obligations for small business — Office of the Australian Information Commissioner (2026)
- Consultation on guidance for transparency in automated decision-making — Office of the Australian Information Commissioner (2026)
- Chapter 1: APP 1 — Open and transparent management of personal information — Office of the Australian Information Commissioner (2025)
- Privacy and Other Legislation Amendment Act 2024 (Cth) — Federal Register of Legislation (2024)
Common questions
- Does my small business legally need an AI policy?
- In most cases there is no law requiring one. Businesses turning over $3 million or less are generally exempt from the Privacy Act, and no Australian law currently mandates an AI policy by itself. The reason to have one is practical rather than legal: it is what stops client information being pasted into a tool nobody vetted.
- What changes on 10 December 2026?
- APPs 1.7, 1.8 and 1.9 commence. If you are covered by the Privacy Act and you use personal information in automated decision-making that could significantly affect someone’s rights or interests, your privacy policy must disclose it. It is a transparency obligation about automated decisions, not a rule about using AI to draft things.
- I run a small health practice. Am I exempt?
- No. Health service providers are covered by the Privacy Act regardless of turnover, so the small business exemption does not help you. If you use automated decision-making on personal information in the way the new provisions describe, the December change applies to your practice.
- Should the policy ban AI outright?
- Rarely, and it usually backfires. A ban with no sanctioned alternative pushes use underground, so you lose the visibility a policy exists to give you. Naming approved tools and being specific about what must never go into them tends to hold better than prohibition.
- Can I just use a template I found online?
- As a starting structure, yes — that is why ours is on this page. The two clauses you should not copy from anyone are the banned-data list and the disclosure rule, because both depend on what your business actually handles and what your clients would expect to be told.