An internal AI policy that people actually follow is short enough to read over a coffee, sorts work by how sensitive the data is rather than by which tool is fashionable, names the specific tools and account types that are approved, and has one named owner who reviews it on a schedule. The forty-page framework, the principles poster and the blanket ban all tend to meet the same fate: people nod, then quietly route around them.
Most organisations writing their first AI policy are not setting rules for a technology about to arrive. They are catching up with behaviour that is already happening, mostly unrecorded. The job is to bring that use into the light and make the safe path the easy one.
Shadow AI Is Already the Baseline
Microsoft and LinkedIn's 2024 Work Trend Index, drawn from a survey of 31,000 people across 31 countries, found that 75 per cent of knowledge workers were using AI at work, and that 78 per cent of those users were bringing their own tools to work.[1]
The 2025 global study from KPMG and the University of Melbourne, which surveyed more than 48,000 people in 47 countries, looked harder at behaviour. Almost half of employees admitted to using AI in ways that contravene company policies, including uploading sensitive company information into free public tools. Fifty-seven per cent said they hide their use of AI and present AI-generated work as their own. Only 40 per cent said their workplace had any policy or guidance on generative AI.[2] The Australian numbers are less flattering still: just 30 per cent of Australian employees said their organisation had a generative AI policy, and only 24 per cent of Australians surveyed had undertaken any AI-related training or education, against 39 per cent globally.[3]
The best-known cautionary tale remains Samsung, which in 2023 temporarily restricted generative AI tools on company computers after staff uploaded sensitive code to ChatGPT.[4] The obvious lesson is "ban it". The more useful one is that the ban arrived after the code had left the building, and that restricting company machines does nothing about the phone in everyone's pocket.
Why Most AI Policies Get Ignored
Policies fail for fairly boring reasons. They are written in the abstract, often by legal or IT, for a version of the business that does not yet use AI. They run long because every stakeholder added a paragraph. They are generous with principles ("use AI responsibly") and stingy with instructions, which leaves the account manager holding a spreadsheet of customer data and a Friday deadline no better informed than before.
The hiding figure above is the tell. People conceal their use when they are not sure it is allowed, and they are not sure because nobody has told them in terms they can apply at their desk. A policy that makes the sanctioned route slower or more confusing than the unsanctioned one will lose every time.
The fix starts with length: a core document of two pages or fewer, in plain language, with worked examples from real tasks in your business. Vendor assessments and incident procedures can live in appendices that the policy owner reads and everyone else is spared.
Tier by Data Sensitivity, Not by Tool
The question every employee actually has is: can I paste this into that? A policy organised by tool answers half of it. A policy organised by data answers all of it, because people usually know what they are holding even when they have never read a vendor's terms of service. Three tiers are enough for most organisations.
Open: Public or Non-Sensitive Information
Published material, public research, general drafting, brainstorming, tidying up your own emails. Any tool on the approved list, with a person reviewing anything before it leaves the organisation.
Internal: Confidential Business Information
Strategy documents, unreleased campaigns, internal financials, commercial terms. Approved tools only, on company-managed business accounts whose terms exclude your data from model training. Personal accounts are out, even for the same product.
Restricted: Personal, Sensitive and Client-Confidential Information
Customer records, employee information, anything under NDA, live deal material. Not in general-purpose AI tools at all, unless a specific system has been assessed and approved for that exact use. This tier lines up with the Office of the Australian Information Commissioner's best-practice recommendation that organisations not enter personal information, and particularly sensitive information, into publicly available generative AI tools.[5]
One more rule does more work than a page of definitions: if you cannot tell which tier something belongs in, treat it as the tier above.
Name the Tools, and the Account Type
"ChatGPT is approved" is not a policy. The same brand can sit under quite different data terms depending on which plan someone is logged into. In August 2025, Anthropic asked Claude Free, Pro and Max users to choose whether their conversations could be used to improve models, with retention extended to five years for those who opted in; the change did not apply to Claude for Work or the API.[6] OpenAI says it does not train on data from ChatGPT Business, ChatGPT Enterprise or its API platform by default.[7] The line that matters runs between a personal subscription and a company workspace.
So the approved list should name the product, the plan and how people sign in: a company workspace accessed through single sign-on, say, rather than a personal account on a work laptop. It should also include a request route for new tools with a turnaround measured in days. If approval takes a quarter, people will use the tool anyway and simply stop mentioning it.
The OAIC expects similar discipline at the procurement end: due diligence before adopting a commercial AI product, including how it has been tested, where human oversight fits and who will have access to personal information, followed by ongoing review.[5]
Two further rules earn a place on the page: a named person is accountable for any AI-assisted output that leaves the organisation, and there is a clear line on when AI-generated content has to be disclosed. Beyond that, resist the urge to add more.
The Australian Context
For organisations covered by the Privacy Act, the OAIC's guidance on commercially available AI products, published in October 2024 and updated in January 2025, is the place to start. It is clear that privacy obligations apply to personal information going into an AI system and to what comes out, that generating or inferring personal information with AI counts as a collection under APP 3, and that privacy policies should explain how the organisation uses AI.[5]
There is also a date for the diary. From 10 December 2026, APP entities that use personal information in automated decision-making with the potential to affect individuals' rights or interests will have to set out in their privacy policies the kinds of personal information used and the kinds of decisions made.[8] If any part of your business uses AI to score, screen or prioritise people, your AI policy and your privacy policy need to agree before then.
On governance, the federal government's Voluntary AI Safety Standard and its ten guardrails, published in September 2024, were replaced on 21 October 2025 by the simpler Guidance for AI Adoption and its six essential practices.[9] The first of those is deciding who is accountable, and the foundations guidance is plain about the basics: create an AI policy, assign a senior leader as the overall AI governance owner, make a specific person accountable for each AI system, and keep a register of the AI systems in use.[10] The National AI Centre's AI policy guide and template, released the same month, is a sensible skeleton to build from.[11]
None of this is legal advice, and compliance wording belongs with your counsel. It is a useful signal, though, that Canberra is asking for much the same things a usable policy needs anyway.
Give It an Owner and a Review Date
An unowned policy starts decaying the day it is published. Name one person, not a committee, as the owner, and give them authority to update the approved tools list without a board paper. The government template suggests an annual review followed by formal approval, with approved AI systems recorded in a register.[11] Treat annual as the floor. Vendor terms can shift well inside a year, as the Anthropic change showed, so the tools list and register deserve a lighter check every quarter.
Then train people by role, briefly. Executives need to know what they are accountable for, managers need to know how to approve a new tool, and everyone else needs the tiers and the list. Our AI policy work starts with an audit of where AI is already being used, because a policy drafted from observed behaviour lands in a way one drafted from first principles rarely does. Where the real answer is a sanctioned internal assistant rather than a patchwork of personal accounts, a custom Claude build can be the cleaner fix.
The One-Minute Test
There is a simple way to tell whether an AI policy will be followed. Ask a new starter, on their second day, whether they can paste a particular document into a particular tool, and time how long it takes them to reach a confident answer. Under a minute, and the policy works. If they have to email someone to find out, it doesn't, and before long they will stop emailing.
Your teams have already decided to use AI. The policy's job is to catch up with them. If you want one built from how your people actually work, start the conversation.
Frequently asked questions
What should an internal AI policy include?
A usable internal AI policy covers which data can go into which tools (ideally sorted into a small number of sensitivity tiers), a named list of approved tools and account types, a fast process for requesting new ones, rules on human review and disclosure of AI-generated output, and a named owner with a review date. Detail such as vendor assessments and incident procedures can sit in appendices so the core document stays short enough for people to actually read.
Should we ban ChatGPT and other public AI tools at work?
A blanket ban is hard to enforce and tends to push use onto personal accounts and devices where you have no visibility. KPMG and the University of Melbourne's 2025 global study found almost half of employees admit to using AI in ways that contravene company policies. A more effective approach is to approve specific business-grade tools, restrict what data can go into them, and make the sanctioned route easier than the workaround.
Can employees put customer personal information into ChatGPT in Australia?
The Office of the Australian Information Commissioner recommends, as a matter of best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. Privacy Act obligations apply to personal information put into AI systems and to what they generate. Organisations should get jurisdiction-specific advice from their own legal counsel before approving any tool for personal data.
How often should an AI policy be reviewed?
The Australian Government's AI policy guide and template suggests an annual review followed by formal approval. Because AI vendors change their plans and data terms more often than that, it is sensible to check the approved tools list and AI register quarterly, and to give one named owner the authority to update them between full reviews.
Is Australia's Voluntary AI Safety Standard still current?
No. The Voluntary AI Safety Standard and its ten guardrails, published in September 2024, were replaced on 21 October 2025 by the Guidance for AI Adoption, which sets out six essential practices for responsible AI governance. The first practice is deciding who is accountable, and the foundations guidance recommends creating an AI policy and maintaining an AI register.
References
- [1] Microsoft, "Microsoft and LinkedIn release the 2024 Work Trend Index on the state of AI at work", news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work
- [2] KPMG, "Global study reveals trust of AI remains a critical challenge reflecting tension between benefits and risks", kpmg.com/xx/en/media/press-releases/2025/04/trust-of-ai-remains-a-critical-challenge.html
- [3] KPMG Australia, "Trust in AI: Global insights 2025", kpmg.com/au/en/insights/artificial-intelligence-ai/trust-in-ai-global-insights-2025.html
- [4] CNBC, "Samsung bans use of A.I. like ChatGPT for employees after misuse of the chatbot", cnbc.com/2023/05/02/samsung-bans-use-of-ai-like-chatgpt-for-staff-after-misuse-of-chatbot.html
- [5] Office of the Australian Information Commissioner, "Guidance on privacy and the use of commercially available AI products", oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- [6] Anthropic, "Updates to Consumer Terms and Privacy Policy", anthropic.com/news/updates-to-our-consumer-terms
- [7] OpenAI, "Enterprise privacy at OpenAI", openai.com/enterprise-privacy
- [8] Office of the Australian Information Commissioner, "Consultation on guidance for transparency in automated decision making", oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
- [9] Department of Industry, Science and Resources, "Voluntary AI Safety Standard", industry.gov.au/publications/voluntary-ai-safety-standard
- [10] Department of Industry, Science and Resources, "Guidance for AI Adoption: Foundations", industry.gov.au/publications/guidance-for-ai-adoption/guidance-ai-adoption-foundations
- [11] Department of Industry, Science and Resources, "AI policy guide and template", industry.gov.au/publications/guidance-for-ai-adoption/ai-policy-guide-and-template