Small-Business AI-Use Starter Policy
An editable operational policy to discuss with your team—not a compliance certificate.
- List approved tools, accounts, owners and permitted low-risk uses.
- Create a never-enter list and clarify approved data settings.
- Keep a named person responsible for factual checks and final publication.
- Require separate approval for external messages, payments, deletions and access changes.
- Tell staff how to report a mistake without blame. Set a review date and update after incidents.
Your worksheet
No confidential information. Filling this sheet does not send data to an AI provider. Blank prompts can be copied separately.
Optional prompt · use only approved inputs
Help draft an operational AI-use policy from my approved tools and low-risk uses. Include prohibited data, human review, actual permission controls, staff training, incident handling and a review date. Keep placeholders for missing facts. Flag legal questions for qualified review; do not certify compliance or assume the Privacy Act applies identically to every business.
Using this prompt in another service sends your inputs to that service. Check its settings first. It is not a tested guarantee of output quality.
Before you use the result
- Can staff identify the approved account and never-enter list?
- Are actual access controls separate from policy wording?
- Have applicable obligations and exceptions been checked?
Sources & scope
Edition 2026-10-09.3. AI-assisted editorial revision; independent specialist and reader review pending. Educational material, not legal, medical or financial advice. Examples are hypothetical unless explicitly documented.
- OAIC: when the Privacy Act covers a small business ↗
- OAIC: privacy and commercially available AI products ↗
- OAIC: automated-decision transparency, commencing 10 December 2026 ↗
- ASD: small-business cyber security guidance ↗