AI acceptable use policy template, free, no email required
· Updated · Written and maintained by Joaquín Trapero, Nonimo
This AI policy template is a complete acceptable use policy: 15 numbered clauses, four annexes and two downloads, free, with no email address and no watermark. Copy the clauses off this page or download the file. It is written for a small or midsize organisation adopting generative AI tools it did not build.
AI policy template: how to use it, and what it does not cover
Read it once, end to end, before editing. Then three things, in order. Fill in Annex A: the list of data your people must never paste is the only part nobody else can write for you. Decide clause 3: which tools are approved, and who approves the next one. Circulate Annex C and keep the signatures, because a policy nobody has acknowledged is hard to enforce. Delete what does not apply.
What each group of clauses settles, and the annex it relies on:
| Clauses | What they settle | Annex |
|---|---|---|
| 1 and 2 | Who and what the policy covers | None |
| 3 | Which tools are approved, and who approves the next one | B |
| 4 and 5 | What never goes in, and what may go in once reduced | A |
| 6 to 8 | Client confidentiality, privacy law and consent | None |
| 9 to 11 | Human review, disclosure and the use case register | D |
| 12 and 13 | Accounts, plans, devices and extensions | B |
| 14 and 15 | Incidents, ownership and review | C |
Before you start, a word on what this template is not. It is not legal advice, and it does not make you compliant with anything. It is a set of rules for staff behaviour. It does not perform a privacy impact assessment, tell you whether a given tool is lawful for you, or cover building models or deploying automated systems that decide things about people.
It also will not stop anyone. A policy is an organisational control: it says what to do and gives you a basis to act when people do not. It does not sit between a person and a text box. Any claim that a document prevents data leaving your organisation is a claim about paper, and paper cannot stop anyone pasting text into an AI tool.
The 15 clauses of the AI acceptable use policy
Each clause is short on purpose: a rule staff cannot recite is one they will not follow.
1. Purpose and scope
This policy governs the use of artificial intelligence tools in the course of work for [Organisation]. It applies to all employees, contractors, temporary staff, volunteers and directors, on any device including their own, and whether or not [Organisation] provided the tool. It covers tools reached through a browser, an application, a plugin, an extension, a feature embedded in another product, or an API. Where it conflicts with a client engagement term or a professional obligation, the stricter requirement applies.
Why: many incidents involve a tool nobody approved on a device nobody manages. A narrower scope would leave those out.
2. Definitions
AI tool means any system that generates, summarises, classifies, transcribes or predicts using a model, including features embedded in products you already use. Input means anything a user types, pastes, uploads, dictates or connects to one. Output means what it returns. Client information means any information relating to a client’s affairs, whether or not the client provided it. Personal information has the meaning given by the privacy law applying to [Organisation].
Why: staff read “AI tool” as “the chatbot” and miss the transcriber in the meeting app. Counting uploads and connected accounts as input closes that argument.
3. Approved tools, and how a tool gets approved
Only tools on the approved list in Annex B may be used for work, and only with input that clause 5 allows. The list names the tool, the plan or tier, the account type and the approver.
A tool is added only after a named person has checked, in writing: what the vendor does with input, whether input trains models and whether that can be switched off, where data is stored, how long it is kept, and whether the contract is with [Organisation] rather than an individual. Free and personal tiers are not approved.
Why: the plan matters more than the brand. The same vendor’s consumer and business tiers can carry different retention terms.
4. What must never go into an AI tool
The data types listed in Annex A must never be entered into any AI tool, approved or not, in any form, including inside a screenshot, a pasted table, an uploaded file or a connected mailbox. This prohibition has no approval path. If a task seems to require it, stop and escalate to the person named in clause 15.
Why: a rule with an exception process becomes a rule with an exception. Annex A is short so “never” can mean never.
5. What may go in, and on what condition
Input not listed in Annex A may be entered into an approved tool once it has been cut to the minimum the task needs and direct identifiers removed or replaced. Removing a name is not removing an identity: a matter number, a rare job title, or a date plus a location can identify a person on its own. Replacing an identifier with a code does not take the information outside privacy law for [Organisation], which holds the mapping. Keep the mapping between codes and real values outside the AI tool.
Why: for you, as the organisation holding the mapping, pseudonymised data is still personal data under the GDPR and personal information under the Privacy Act. A policy implying otherwise creates the exposure it was meant to prevent.
Staff who need more than the clause can follow what to mask before a document is pasted, in order, including the last check, which no tool runs for them.
6. Client confidentiality is a separate duty
Confidentiality obligations apply to AI tools as to any other third party. Entering client information into a tool run by another organisation is a disclosure to a third party. Where an engagement letter, retainer, professional rule or contract requires client permission before such a disclosure, that permission is obtained before the information is entered, and recorded.
Why: confidentiality and privacy are different tests, so a firm can satisfy privacy law and still breach its retainer. Australia’s Tax Practitioners Board put this in writing on 22 July 2026 in TPB(GS) 55/2026: tax practitioners must obtain client permission before divulging client information to a third party, “which can include entering client information into AI models and tools, depending on how these tools are configured and used”.
7. Personal information and privacy law
Personal information may be entered into an approved tool only where that is consistent with the purpose it was collected for and permitted by the privacy law applying to [Organisation]. [Organisation] remains responsible for it after it enters a tool, including for its security. Where the regulator recommends against a category of input, that recommendation is followed unless a named person records a reason not to.
Why: the OAIC’s guidance on commercially available AI products, published 21 October 2024 and updated 17 January 2025, recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. Guidance, not prohibition, which is why your policy records what you decided.
8. Consent, engagement letters and notices
Where clause 6 requires client permission, it is obtained in the engagement letter, a signed consent or an equivalent written record, and states what will be disclosed, to whom, where the data will be stored, and that AI tools may be used. Privacy notices and the privacy policy describe the use of AI tools in terms an individual can understand.
Why: “we may use technology providers” is not informed permission.
9. Human review before reliance
Output is a draft. No output may be sent to a client, filed, published, relied on in advice, or used to decide something about a person until a competent human has checked it against a source. The reviewer is accountable for the content as if they had written it. Citations, figures, quotations, legislative references and calculations are checked one by one against the primary source, never against another AI tool.
Why: the accuracy failure is the one that reaches your client, and “the tool said so” is no defence.
10. Disclosure and marking of AI assisted work
Where content generated or materially altered by an AI tool is published, given to a client, or filed with a court, tribunal or regulator, [Organisation] discloses that fact where a rule, contract or professional obligation requires it, and wherever a reader would otherwise be misled. Staff do not remove or defeat any marking or metadata a tool attaches to its output.
Why: under the EU AI Act the marking obligation in Article 50(2) sits on tool providers, not on you. Your duty is the deployer duty in Article 50(4): disclose deep fakes, and disclose text generated by AI that is published to inform the public on matters of public interest, unless a person takes editorial responsibility after human review or editorial control.
11. Records: the use case register
[Organisation] maintains the register in Annex D. Each approved use case records the tool, the purpose, the categories of input, who approved it, the date, and the next review. Prompts and outputs on client matters are kept in the matter file under normal record keeping rules, not only inside the tool’s own history.
Why: it answers “what are we using it for” in one page instead of one month. It is also the page an insurer’s AI question expects to find attached, next to the policy itself.
12. Accounts, plans and vendor terms
Work input is entered only through accounts held in [Organisation]‘s name, on the plan named in the approved list. Personal accounts, personal email addresses and consumer tiers are not used for work input. Where a tool offers a setting controlling whether input trains models, or how long it is retained, the setting is recorded in the approved list and checked at each review.
Why: a common gap between policy and reality, invisible unless you look at the account rather than the logo.
13. Devices, browsers and extensions
Browser extensions, plugins, desktop assistants and integrations that can read a page, a document or a mailbox are installed only from the approved list. Staff do not connect an AI tool to a mailbox, a document store, a practice management system or a code repository without approval under clause 3.
Why: read access to every tab is a far larger disclosure than a chat window.
14. Incidents
If prohibited data has been entered into an AI tool, or anything into an unapproved one, the user reports it to the person named in clause 15 the same day. Nobody is disciplined for reporting promptly.
[Organisation] records what was entered, when, into which tool and under which account; asks the vendor to delete it and records the answer; and assesses whether the incident is notifiable. Under Australia’s Notifiable Data Breaches scheme, the test includes whether a reasonable person would conclude it would be likely to result in serious harm.
Why: the hour after a paste is when the facts are still recoverable, and reporting without blame is how you hear about it in time.
15. Owner, review cycle and changes
This policy is owned by [named role]. It is reviewed at least every twelve months, and whenever a tool is added to the approved list, a regulator publishes guidance that changes a clause, or an incident under clause 14 exposes a gap. Every version carries a date and a change log. Staff are notified of material changes and acknowledge again using Annex C.
Why: a policy with no owner and no date turns up in a dispute two years out of date, contradicting what everyone actually does.
Annex A: data that must never be entered
Add rows for any sector identifier you use. The jurisdiction columns cover Australia and Spain.
| Category | Australia | Spain | Caught by a local detector? |
|---|---|---|---|
| Government identity number | Tax file number (TFN) | DNI, NIE | Yes, check digit; the TFN only after its label |
| Health identifier | Medicare number, Individual Healthcare Identifier | Número de la Seguridad Social | Yes, check digit; Medicare and Seguridad Social numbers only after their label |
| Business number tied to a person | ABN of a sole trader | NIF de autónomo | Yes, check digit; the ABN only after its label |
| Bank and card details | BSB and account number, card number | IBAN, card number | Card number yes, check digit and a known issuer. IBAN yes, check digit. BSB and account number only after the words “BSB”, “Bank State Branch” or “account number”. See how |
| Client names and matter details | Any | Any | Partly: names in a labelled field, a signature or after a title such as Mr or Dr, by position rather than by a list of ours. Matter numbers after the words “matter number”, and never the matter itself |
| Property identifiers | Title reference, full address | Referencia catastral, full address | Address yes, by position; title reference no. The cadastral reference, only after its label, is masked visibly, never replaced without telling you: its check algorithm is unofficial and fails in the four foral territories and can fail on rural parcels |
| Health information | Diagnoses, records, results | Health data (Article 9 GDPR) | Partly: record numbers after their label, never the diagnosis or result itself |
| Criminal history | Charges, convictions, police records | Criminal records | Partly: case numbers after their label, never the charge or conviction itself |
| Biometric data | Face, voice, fingerprint templates | Biometric data | No |
| Credentials | Passwords, API keys, tokens | Passwords, API keys, tokens | Some API keys and tokens yes, passwords no. Do not rely on a detector here |
Two limits, because a template that oversells the technical control undermines clause 4. A local detector reads the text you are about to send. It does not read a file you attach directly to a chat, and on its own it does not stop a paste in a browser: that needs an extension installed by policy.
Where this stands: there are signed Mac and Windows apps to download, and a firm that wants it rolled out centrally has the extension installed by policy. What the apps keep on your disk, encrypted, is set out on the security page.
Annex B: the one page sheet
Print it and put it where people work.
| Yes, with an approved tool | No, never |
|---|---|
| Rewriting your own draft with no client details | Anything in Annex A |
| Summarising a public document | Client names and matter details |
| Drafting a template letter with no client details | Uploading a client file |
| Generating test data | Pasting a whole document to “check” it |
| Explaining a concept you then verify | Anything you would not email to a stranger |
| Code with no credentials or client data in it | Credentials, keys and tokens |
Approved tools, plans and accounts: _______________________ (this list is clause 3; keep it current).
Annex C: acknowledgement
I have read the [Organisation] AI acceptable use policy dated [date]. I understand that it applies to any device I use for work, including my own, and to AI features inside tools I already use. I understand which data I must never enter, that my work is checked before it is relied on, that I must report a mistake the same day, and that reporting promptly will not be held against me.
Name: ______________ Signature: ______________ Date: ______________
Annex D: use case register
| Use case | Tool and plan | Input categories | Approved by | Date | Next review |
|---|---|---|---|---|---|
If you are in Australia: what the Privacy Act asks of your policy
If the Privacy Act covers your organisation, this policy answers to the Australian Privacy Principles, and two do most of the work. If you have approved Microsoft Copilot, do not rely on the licence alone: what the Privacy Act asks is a separate question.
APP 11 requires an APP entity to take such steps as are reasonable in the circumstances to protect personal information. APP Guidelines chapter 11, version 1.3, updated 3 October 2025, says at paragraph 11.10 that those steps “include both technical and organisational measures”, and at 11.9 that they should cover governance, culture and training, internal policies and ICT security, among others. So this policy is an organisational measure, and the guidelines do not treat those as the whole answer.
APP 1 requires a privacy policy that is clearly expressed and up to date, and from 10 December 2026 it can require more. A practice whose AI provider sees personal information should name it there too, in the same words as the recipients clause of its engagement terms.
If you are a law firm, an accounting practice or a conveyancer
For these practices, the date that may matter is 1 July 2026.
Schedule 3 of the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia’s AML/CTF regime to designated services commonly provided by real estate professionals, dealers in precious metals and stones, lawyers, conveyancers, accountants, and trust and company service providers. It commenced on 31 March 2026, and item 11 of its Part 4 deferred the core obligations (AML/CTF programs, customer due diligence, reporting and record keeping) to 1 July 2026.
The privacy consequence gets misstated, so here it is precisely. Section 6E(1A) of the Privacy Act 1988 provides that where a small business operator is a reporting entity because of something done in the course of its small business, the Act treats it as an organisation, with any prescribed modifications, but only for the activities it carries on for the purposes of, or in connection with, the AML/CTF Act.
Not the whole business: the AML/CTF activities. A practice under the turnover threshold that sat outside the Privacy Act, and now provides one of those designated services, is inside the Act for its customer due diligence records, exactly the kind of material staff paste into a chatbot.
Two things you will read elsewhere that are wrong or out of date today
Both appear on pages you would have found by searching in Australia on 30 July 2026: kmtech.com.au for “ai compliance australia” and mintegrity.com.au for “ai policy template”.
Both are still live: one is still wrong, the other still out of date.
The Voluntary AI Safety Standard’s “10 mandatory guardrails”
The standard is voluntary, and it has moved on. On 21 October 2025 the Department of Industry, Science and Resources published Guidance for AI Adoption and its six essential practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, maintain human control.
The department’s own Voluntary AI Safety Standard page, last updated 2 December 2025, says the new guidance “evolves” the standard, and its ten guardrails are still published, so the older framing is superseded rather than wrong. Calling any of it mandatory is simply wrong.
Checked on 15 September 2026: kmtech.com.au, whose AI compliance page says it was last edited on 5 August 2026, still says the “Voluntary AI Safety Standard” outlines “10 mandatory guardrails”; and aona.ai’s Australian template page still presents the ten guardrails with no mention of the 2025 guidance.
A template whose title says 2024
mintegrity.com.au still carried “Aug 2024” in its heading and in its own URL on 15 September 2026. The AML/CTF change, the automated decisions change, the OAIC guidance, the 2025 Guidance for AI Adoption and the 2026 EU amendment all came after it. A date in a title is useful only if someone keeps it current.
When this template has to change: two dates for your calendar
Both have been checked against their primary sources, and each affects a clause of this template.
2 December 2026, European Union
Regulation (EU) 2026/1744 of 8 July 2026 added a paragraph 4 to Article 111 of the AI Act: providers of AI systems generating synthetic audio, image, video or text content “that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026”.
Article 50(2) requires synthetic output to be marked in a machine-readable format. The deadline is the vendor’s, not yours. What changes for you is that the marks then exist on older tools too, which gives clause 10 more to do. Whether the Regulation reaches your firm at all is a separate question, and it depends on where your output is used, not where you are based.
10 December 2026, Australia
Part 15 of the Privacy and Other Legislation Amendment Act 2024 commences, adding subclauses 1.7, 1.8 and 1.9 to APP 1.
Where an entity has arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person’s rights or interests, and personal information is used in the program, the privacy policy must state which kinds of personal information are used and which kinds of decisions are made that way.
The commencement table puts that at the day after 24 months from Royal Assent: 10 December 2026. This template gains clause 16 that day.
Download it
No email, no watermark, no conditions on reuse.
- Google Docs: upload the Word file to your Drive and open it with Docs; the tables survive.
The clauses are on this page too, so you need not download anything to reuse them.
Sources
Checked 15 September 2026.
- Tax Practitioners Board, TPB(GS) 55/2026, issued 22 July 2026. Client permission before divulging client information to a third party, which can include AI tools.
- OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024, updated 17 January 2025. What it recommends as best practice for personal and sensitive information.
- OAIC, APP Guidelines chapter 11, version 1.3, updated 3 October 2025. Paragraphs 11.9 and 11.10 on reasonable steps.
- Privacy Act 1988 (Cth), s. 6E(1A). A small business reporting entity, covered for its AML/CTF activities.
- Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, Schedule 3 and item 11 of Part 4. Commencement on 31 March 2026, core obligations deferred to 1 July 2026.
- Privacy and Other Legislation Amendment Act 2024, Schedule 1, Part 15. APP 1.7 to 1.9, and their commencement on 10 December 2026.
- Regulation (EU) 2024/1689, the AI Act, Article 50. The provider duty in 50(2) and the deployer duty in 50(4).
- Regulation (EU) 2026/1744, 8 July 2026. The new Article 111(4) and its 2 December 2026 deadline.
- Department of Industry, Science and Resources, Guidance for AI Adoption, 21 October 2025. The six essential practices.
- Department of Industry, Science and Resources, Voluntary AI Safety Standard, updated 2 December 2025. The word “evolves”, and the guardrails as voluntary.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Is this AI policy template really free, with no email required?
Yes. Both files download with one click, with nothing to fill in first, and the 15 clauses are in full on this page, so you can copy them without downloading anything.
Can I adopt this as my own organisation's policy?
Yes. Adopt it, rename it, edit it, delete clauses, charge for advice based on it. No watermark, no attribution, no conditions on reuse. It is a starting point rather than legal advice, so have someone who knows your obligations review it.
How do I use AI safely at work if my employer has no policy?
Assume anything you paste may be read by a reviewer and kept. Do not enter client names, government identity numbers, health information or account numbers. Check output against a source before relying on it, and tell your manager which tool you used.
What is the difference between an AI policy and an AI governance framework?
A policy tells your people what they may and may not do. A framework tells your board how AI decisions get made and escalated. This template is the first; Australia's Guidance for AI Adoption, published 21 October 2025, is a start on the second.
How often should an AI policy be reviewed?
Clause 15 sets a review at least every twelve months, and whenever a tool is approved, new guidance calls for a change to a clause or an incident exposes a gap. Two dates already call for one: 2 December 2026 in the European Union and 10 December 2026 in Australia.
Do tax practitioners need client permission before putting client information into AI tools?
In Australia, sometimes. The Tax Practitioners Board's TPB(GS) 55/2026, issued 22 July 2026, says that, unless there is a legal duty to disclose, practitioners must obtain client permission before divulging client information to a third party, which can include AI tools, depending on how they are configured and used.
Does the EU AI Act require us to label text generated by AI?
In some cases. Under Article 50(4), a deployer must disclose text generated by AI that is published to inform the public on matters of public interest, unless a person takes editorial responsibility after human review or editorial control. The machine-readable marking in Article 50(2) is the provider's duty.