All insights

What should a staff AI use policy say?

5 min readBy Brendon Whiting, Founder · 19 June 2026

A staff AI use policy needs five short sections: which tools are approved, what must never be pasted into any AI tool, the requirement that a person checks and owns the output, when clients need to be told, and who to ask when unsure. One page that gets read beats ten that get filed.

The purpose is worth stating before the contents, because policies written from fear end up unusable. This document exists to let people use AI confidently, not to stop them: it draws the line between the ninety per cent of uses that are fine and the few that are not, so staff stop guessing and start asking. A policy that reads as a prohibition list will be ignored by the people most likely to find a use for the tools.

Section one: approved tools, named and dated. List what is sanctioned, for most Microsoft 365 businesses that is Copilot Chat signed in with a work account, plus any paid tools you have deliberately adopted, and add one line for how to get something new approved. Naming tools beats stating principles here, because a staff member can check a list in ten seconds, whereas interpreting a principle takes judgement they may not have and time they will not spend. Date the list, because it will change more often than the rest of the document.

Section two: what never gets pasted, and this is the section that matters most. Be concrete rather than categorical. Client and patient personal details. Financial records and payroll. Passwords, keys and system configuration. Anything covered by a confidentiality agreement. Say it in the specifics of your business, because a receptionist recognises a patient's Medicare details far more reliably than they recognise the phrase personally identifiable information. If your business has a handful of recurring examples, name those too; specificity is what makes this section usable under pressure.

Section three: a person checks and owns the output. AI produces a draft; a human reads it, corrects it and takes responsibility for it before it reaches a client, a record or a decision. Put the reason in the policy so the rule survives familiarity: these tools produce confident, plausible text that is sometimes wrong, and confidence is not accuracy. Where the output is going into anything regulated or clinical, the review requirement is absolute, and the policy should say so in those words.

Section four: client transparency, decided once rather than case by case. Recording or transcribing a conversation needs consent, always, and that includes the meeting assistant quietly joining a video call. Beyond that, set your position on when clients are told AI was involved, check it against your professional obligations and client agreements, and write it down so staff are not improvising in the moment. Section five is the shortest and the most used: who to ask, by name rather than by department. One name, and an explicit statement that asking is never a problem, because the alternative to asking is deciding alone, usually at speed, usually by the person with the least context about the risk.

Two practical notes on making it real. A rule works far better with a system behind it: sanctioned access through work accounts, sensible device management, and permissions that are actually correct do more for compliance than any paragraph, which is the same logic as the rest of your security baseline: the control does the remembering so the person does not have to. And introduce the policy in a ten-minute conversation rather than an email, including two or three examples of good use drawn from your own business, because a policy people understand gets followed and a policy people merely receive gets skimmed.

The caveats: this is not legal advice, and businesses in regulated fields, health, legal, financial services, should check their professional obligations before finalising anything. Keep it to a page, name an owner, date it, and review it twice a year, because the tools will change faster than the principles will. A policy that exists, is short and is understood beats a thorough one that arrives next year. If you want the policy backed by controls that make the sanctioned path the easy one, call 1800 456 567.

A policy backed by real controls

A written rule works better when a system supports it. We set up sanctioned AI access with the permissions and controls behind it.

Frequently asked questions

Sometimes, and the test is whether a reasonable client would want to know. Recording a conversation always needs consent. AI drafting a document a person then reviews and owns usually does not require disclosure, though some professional obligations and client agreements say otherwise. Decide your position, write it down, and apply it consistently rather than case by case.

Yes, and keep the list short and dated. Naming tools makes the rule usable, because staff can check in seconds rather than interpret principles. Add a line saying anything not listed needs a quick approval, which turns the inevitable new-tool moment into a conversation instead of a silent decision made by whoever found it first.

Write the rules about behaviour rather than products, so the substance survives the churn, and keep the tool list as a short dated appendix you can update without reopening the policy. Review it twice a year and after any significant change in what your business uses. A stale tool list is fixable; stale principles are a rewrite.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.