Shadow AI Acceptable Use Policy.
Generate one in two minutes.
Customise the fields below. We will generate a plain-English AI acceptable use policy aligned to the Voluntary AI Safety Standard, the Australian Privacy Principles and the ADM transparency rule taking effect 10 December 2026. Copy or download it. Adopt it under your existing policy framework.
Customise your policy
Live preview
ACCEPTABLE USE OF AI TOOLS [Your business name] Effective date: 12 September 2026 Review cadence: Quarterly Policy owner: [Policy owner name] ([policy owner email]) 1. PURPOSE This policy sets out how staff at [Your business name] may use generative AI tools (including but not limited to Microsoft 365 Copilot, ChatGPT, Gemini and similar services) in the course of their work. It exists to protect customer information, business information and the people who handle them, in line with the Australian Privacy Principles, the Voluntary AI Safety Standard and our obligations under the Privacy Act 1988. 2. SCOPE This policy applies to every person who accesses [Your business name] systems, including employees, contractors, interns and third-party suppliers. It covers AI tools used on business devices, personal devices used for work, and AI features embedded inside other SaaS tools. 3. APPROVED TOOLS The following AI tools are approved for business use, on the conditions stated: - Microsoft 365 Copilot (tenant licence) - ChatGPT Team or ChatGPT Enterprise (named licences only) - Google Gemini for Workspace (tenant licence) - GitHub Copilot (named licences only) Use of any other AI tool for business work requires written approval from the policy owner before adoption. 4. PROHIBITED USE Staff must not: - Free-tier ChatGPT, Claude or Gemini on personal accounts when handling work data - AI tools paid for on personal credit cards and not registered with IT - AI browser extensions installed without IT review - AI features in unapproved third-party SaaS tools where data egress is unclear 5. DATA HANDLING RULES The following data must never be entered into any AI tool that is not on the approved list above: - Personal information about customers, staff or third parties (names, contact details, financial data, health information, identity documents). - Confidential commercial information (contracts, pricing, strategy documents, board papers). - Source code or system configuration that is not already public. - Anything that would be subject to a Notifiable Data Breach assessment if it left the business. 6. HUMAN OVERSIGHT AI-generated content must be reviewed by a person before it is sent to a customer, published externally, included in a regulatory submission, or used to make a decision that affects an individual. AI-assisted decisions about people (hiring, credit, eligibility, prioritisation) require documented human review and will be disclosed in the privacy policy in line with the Privacy Act ADM transparency rule that takes effect 10 December 2026. 7. INCIDENT REPORTING If a staff member accidentally enters sensitive information into an unapproved AI tool, they must notify [Policy owner name] ([policy owner email]) within 24 hours. There is no penalty for honest disclosure. There is a penalty for not disclosing. 8. RECORD KEEPING [Your business name] will maintain a list of approved AI tools, the licences held, and the data categories each tool is approved to process. The list is reviewed every quarterly. 9. POLICY REVIEW This policy is reviewed every quarterly, and whenever a material change occurs to the AI tooling landscape, our regulatory obligations or our risk profile. 10. CONSEQUENCES OF NON-COMPLIANCE Breaches of this policy will be handled under the standard [Your business name] disciplinary process. Deliberate exfiltration of business or personal information via AI tools will be treated as a serious misconduct matter. ACKNOWLEDGEMENT I have read and understood the [Your business name] Acceptable Use of AI Tools policy and agree to comply with it. Name: ____________________________________ Signature: ________________________________ Date: ____________________________________ ------------------------------------------------------------ This template is general information, not legal advice. Confirm with your legal counsel before adoption. Generated using the Real Bytes Shadow AI Policy Generator. realbytes.au/shadow-ai-policy-generator
Optional, no obligation
Want a hardened version custom to your business?
The template above is a strong starting point. If you want it tightened for your sector, your existing policy framework, your Microsoft 365 tenant configuration and the Voluntary AI Safety Standard guardrails, an engineer can review and return a hardened version within five business days.
No sales call required unless you want one. We send the policy back as a written artefact you can adopt under your existing process.
Want help rolling it out?
Policy adoption is the easy part. The harder work is enforcing it in the tenant, training staff, and proving the controls hold. We do that work as part of an AI readiness review.
General information, not legal advice. Confirm with your legal counsel before adoption.

Remote Support