Most Australian businesses using ChatGPT, Claude or Copilot don’t have a written AI policy. They have a Slack message from six months ago that says “be careful what you paste in.” That’s not governance — it’s a liability sitting in your chat history.
On 2 August 2026, the EU AI Act’s obligations for general-purpose AI (GPAI) models come into force. If your business has any EU customers, staff, or suppliers, this isn’t a “watch this space” issue anymore — it’s a compliance deadline. And even for businesses with zero EU exposure, the ripple effect is already visible: Microsoft’s SSPA DPR v12 now expects ISO 42001-aligned documentation from suppliers handling sensitive AI use cases, and AU Privacy Act reform is moving in the same direction.
Why “be sensible with AI” isn’t a policy
A real AI Acceptable Use Policy needs to answer specific questions your team is already asking, whether or not you’ve heard them out loud:
- Can I paste client data into ChatGPT to summarise it?
- Who approves a new AI tool before the team starts using it?
- What happens if AI-generated content turns out to be wrong in a client deliverable?
- Are we allowed to use AI to write code that touches production systems?
Without written answers, every employee is making these calls alone, inconsistently, and without anyone accountable for the outcome. That’s the exposure regulators — and increasingly, enterprise customers doing vendor due diligence — are starting to check for.
What a proper policy actually covers
A defensible AI Acceptable Use Policy isn’t a page of vague principles. It sets out:
- Approved and prohibited use cases — drafted specifically, not generically
- Data handling rules — what can and can’t be entered into third-party AI tools
- Human review requirements — where AI output needs sign-off before it’s used externally
- Tool approval process — who decides what gets adopted, and how
- Consequences and escalation — what happens when the policy isn’t followed
This is the same standard a Big 4 consultant would draft for an enterprise client — the difference is it doesn’t need to cost enterprise money to get it.
Built for Australian businesses, not adapted from a US template
Most AI policy templates circulating online are written for US or UK compliance frameworks and bolted onto Australian businesses after the fact. Madalent’s AI Acceptable Use Policy is written in plain English, structured for SMB and mid-market use, and built to align with the direction AU regulation is heading — without the enterprise-consultant price tag or the 40-page document nobody reads.
It’s a ready-to-edit Word document: import your business name, review the use-case list against your own tools, and it’s live. No workshop, no six-week engagement.
Get the AI Acceptable Use Policy — $74 AUD →
The bigger picture
This policy is the first document in a defensible AI governance stack — the same stack regulators, insurers and enterprise customers are starting to ask about. If you’re building this out properly, the next steps are usually an AI Risk Register and an AI Vendor Risk Questionnaire. Free download: our AI Governance Readiness Checklist walks you through where to start.