What an AI policy should actually do
A useful AI policy tells people what they may and may not do with AI, how to handle information, who is responsible, and what to do when something goes wrong. It should be short enough to read and specific enough to follow.
What an effective AI policy should cover
Purpose and scope
Why the policy exists and which tools, teams and use cases it covers.
Approved and prohibited use
Clear examples of acceptable use and clear red lines.
Information handling
What information may go into which tools, aligned to the Green, Amber and Red boundaries.
Human responsibility
Who remains accountable for decisions and where human review is required.
Review and escalation
How to raise questions and who decides on exceptions.
Records, exceptions and incidents
What to record so use can be reviewed and improved.
An AI policy is not the whole governance system
A policy without a use register, a risk register and workflow controls is hard to enforce. The policy is the rulebook; the rest makes the rules operate.
Turn policy into workflow controls
Editable Surfaces
Keep hard rules read-only, allow controlled policy to be proposed, and let everyday drafts be generated for approval.
Output-to-Action Boundary
Require review before AI output becomes a business action.
Evidence Before Execution
Capture the basis for material actions before they run.
Connect the policy to your AI register and risk register
Link the policy to the use register (where AI is used) and the risk register (what could go wrong and how it is controlled) so the three stay consistent.
When to review an AI policy
Review on a set cadence and whenever triggers occur, such as new tools, new use cases, incidents or updated guidance.
Australian guidance and privacy considerations
The National AI Centre publishes guidance and a template for an Australian AI policy, and privacy obligations may apply to personal information used with AI depending on the use case. This page is general information and not legal advice. To assemble a policy with its supporting controls, see the AI Governance Starter Pack.