01
Purpose and scope
State which workers, business units, systems, data, suppliers and AI uses the policy covers, including embedded features and custom agents.
Google analytics are off.
Australian AI governance guide
Build a policy that defines approved AI use, accountable owners, privacy and security controls, human oversight, monitoring and incident response.
An Australian workplace AI policy should define approved uses and tools, prohibited data and actions, accountable owners, privacy and security checks, human review, monitoring, incident response and a review cycle. Exact legal duties depend on the organisation, data, decisions, sector and jurisdiction, so privacy and legal owners should validate the policy against current practice and applicable law.
Policy need
There is no single universal rule in the cited federal sources requiring every Australian business to publish a standalone AI policy. Coverage and duties depend on the entity, sector, information and use case. Australian Government agencies and organisations with annual turnover above $3 million are generally covered by the Privacy Act, subject to exceptions; some smaller businesses are also covered.
For covered entities, APP 1 requires reasonable steps to implement practices, procedures and systems that support compliance and inquiries or complaints. The OAIC’s commercial AI guidance says organisations should establish policies and procedures for AI use, conduct due diligence and a privacy impact assessment, train staff and monitor systems throughout their lifecycle.
The practical conclusion is broader than minimum compliance: if staff, suppliers or products use AI, a concise operational policy gives people a shared rulebook and gives governance owners a basis for approval, monitoring and response.
Policy structure
Use these headings and decision prompts to describe what the organisation actually does and identify the owner who can verify it.
01
State which workers, business units, systems, data, suppliers and AI uses the policy covers, including embedded features and custom agents.
02
Name the executive sponsor and the Security, Privacy, Legal, IT, Procurement, People and business owners responsible for decisions and review.
03
Define approved tools, accounts and purposes, plus prohibited data, decisions, integrations and external actions.
04
Record each system, provider, purpose, owner, users, information classes, integrations, limitations, risk treatment and review date.
05
Set rules for personal and sensitive information, collection notices, use and disclosure, overseas recipients, retention, deletion and access.
06
Cover identity, least privilege, provider settings, data leakage, prompt injection, tool permissions, logging and incident response.
07
Define triage criteria, unacceptable uses, stakeholder impacts, legal and security review, treatment plans and approval authority.
08
Specify when a trained person must review, intervene, override or stop a system and how affected people can challenge an outcome.
09
Set acceptance criteria, pre-deployment tests, performance measures, change triggers, incident reporting and periodic review.
10
Explain role-based training, how exceptions are requested and approved, their expiry, and the consequences of using AI outside policy.
Operating model
The National AI Centre’s Guidance for AI adoption recommends scaling governance to each use’s complexity and risk. Applicable laws still determine legal duties.
Assign authority, resources and skills across the organisation and AI supply chain.
Identify affected people, intended use, foreseeable misuse, potential harms, feedback routes and ways to challenge outcomes.
Use AI-specific criteria, assess material use cases, treat identified risks and document incidents and residual risk.
Maintain an AI register and explain capabilities, limitations, risks, AI-generated content and supply-chain responsibilities.
Test before deployment, monitor performance and apply proportionate privacy, data and cybersecurity controls.
Give trained people the ability to oversee, intervene and decommission systems, with alternatives for critical functions.
Inventory and evidence
An AI register is the operational source of truth behind the policy. Include procured systems, public tools, embedded features, internally built models, automations and AI-supported decisions. Combine procurement and owner records with staff reporting and supported technical observations so systems outside any one discovery method are not omitted.
For each entry, record the accountable owner, provider, purpose, users, affected stakeholders, information classes, integrations, decision role, capabilities and limitations, risk and impact assessments, controls, tests, incidents, approval state and review dates. Record protection status separately: observed, inspectable and enforceable are different claims.
An observed AI destination proves that a signal was seen. It does not prove that prompt or response content was inspected, that policy was active, or that the interaction could be blocked.
Learn how to verify Shadow AI coveragePrivacy and significant decisions
When the Privacy Act applies, personal information entered into an AI system and personal information in its output remain subject to the APPs. The OAIC recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools as a matter of best practice.
For controlled uses, assess necessity, purpose, collection, use or disclosure, consent where required, notices, provider access, overseas recipients, data quality, security, retention and deletion. A privacy policy statement does not by itself authorise collection, use or disclosure.
From 10 December 2026, APP entities have additional privacy-policy obligations for qualifying computer-program-supported decisions that use personal information and could reasonably be expected to significantly affect an individual’s rights or interests. The test is technology-neutral and can include conventional automation as well as AI.
Implementation
Policy controls
Promptective helps Security, Compliance and IT discover recognised and suspected AI activity across managed browser profiles and apply organisation policy on supported paths.
Promptective’s supported browser protection depends on the application, provider, connection, browser and deployed extension. Coverage records distinguish observed activity from actively protected paths, and routine evidence excludes prompt and response plaintext.
Questions and answers
The cited federal sources set duties according to each business’s circumstances and do not impose a universal standalone AI policy requirement. Entities covered by the Privacy Act must comply with the Australian Privacy Principles. The OAIC recommends policies and procedures for AI use, while the National AI Centre recommends an AI governance framework. Organisations should also check sector, contract, workplace and state or territory requirements.
It should define scope, accountable owners, approved and prohibited uses, an AI system register, privacy and security rules, risk assessment, human oversight, testing, incident response, training, exceptions and a review cycle. The detail should reflect each organisation’s systems, data, decisions, risks and legal obligations through organisation-specific policy wording.
The OAIC recommends, as a matter of best practice, keeping personal information and particularly sensitive information out of publicly available generative AI tools. Any controlled use requires an assessment of Privacy Act coverage, purpose, use or disclosure, consent where applicable, data minimisation, provider access, security and overseas data flows.
Record the system and provider, accountable owner, purpose, users, affected stakeholders, data classes, model or service origin, integrations, capabilities, limitations, decision role, risk and impact assessments, controls, tests, incidents, supplier responsibilities, approval status and review dates. Keep enough detail to support decisions without turning the register into a store of prompts or responses.
Review it at least annually and earlier when a law, regulator guidance, provider, model, feature, data flow, integration, use case, incident or risk changes materially. Higher-risk systems still need continuous monitoring between policy reviews.
From 10 December 2026, an APP entity must add specified information to its privacy policy when it has arranged for a computer program to use personal information to make, or substantially and directly support, a decision that could reasonably be expected to significantly affect an individual’s rights or interests. The test is broader than generative AI and requires case-specific assessment.
Source transparency
These sources were checked on 21 August 2026. Recheck regulator guidance and legislation before relying on a legal or deadline claim.
Australian Government, National AI Centre
Six essential practices for AI accountability, impact assessment, risk management, transparency, testing and human control.
Office of the Australian Information Commissioner
Current OAIC guidance on due diligence, personal information, transparency, accuracy, security and ongoing assurance.
Office of the Australian Information Commissioner
APP 1 requirements and the automated-decision privacy-policy obligations commencing on 10 December 2026.
Office of the Australian Information Commissioner
Coverage overview for Australian Government agencies, organisations and qualifying small businesses.
Federal Register of Legislation
The statutory source for the APP 1 automated-decision amendments.