AI Acceptable Use Policy Generator
Your staff are probably already using AI. This builds a plain-English, one-page acceptable use policy that says which tools are approved, what must never be pasted into them, and who stays accountable for checking the output — with clauses specific to your sector. Everything is assembled in your browser; nothing you type is sent anywhere.
Use — Guide
How to use this tool
- Enter your business name and pick your sector. The sector adds clauses that actually apply to you — healthcare gets privacy and clinical-decision wording, construction gets safety-critical sign-off wording, and so on.
- Tick the AI tools you have approved for work use. If you have not approved one yet, leave them all unticked and the policy will say so plainly rather than inventing a position you have not taken.
- Tick the categories of information staff must not paste into AI tools. Credentials are always included whether you tick them or not.
- Choose what must be reviewed by a person before it goes out. This is the clause that keeps a human accountable for AI-assisted work.
- Read the generated policy in full. It is a starting point, not a finished document — change anything that does not match how your business really works.
- Copy it, download it or print it. Nothing you type is sent anywhere; the document is assembled in your browser.
FAQ — Questions
Frequently asked questions
01Why does my business need an AI policy?
Because your staff are almost certainly already using AI, whether or not you have approved it. The National AI Centre found that 43 to 44 per cent of Australian SMEs report some level of AI adoption, and the informal use sitting underneath that number is invisible until something goes wrong. A one-page policy is the cheapest control available: it tells people which tools are acceptable, what must never be pasted into them, and who is accountable for checking the output. Banning AI outright tends not to work — it moves the behaviour somewhere you cannot see it.
02Is this legal advice?
No. This generates a practical starting point based on common obligations and sensible operational controls, and every generated document says so on its face. It has not been reviewed by a lawyer and it cannot know the specifics of your contracts, your professional body rules or your regulatory position. Read it, edit it to match how your business actually works, and have it reviewed before you rely on it — particularly if you handle health or financial information.
03Does anything I type get sent to your servers?
No. The entire policy is assembled in your browser using JavaScript that ships with the page. Your business name, sector and selections are never transmitted anywhere, are not logged, and disappear when you close the tab. That is deliberate — asking you to hand over information about your data handling in order to receive advice about your data handling would be a poor way to make the point.
04What is "shadow AI" and why does it matter?
Shadow AI is AI in use inside your business that nobody formally approved — usually staff using personal or free-tier accounts to get work done faster. It matters because consumer plans generally carry different data-handling terms to business plans, so client details, contracts, pricing or personal information can end up in a service your business has no agreement with and no visibility of. The practical fix is rarely a ban. It is giving people an approved tool that is genuinely good enough for the job, being explicit about what should never be pasted into any of them, and making it safe to report mistakes.
05How often should the policy be reviewed?
Every six months is a reasonable default, and the generator lets you choose three, six or twelve. AI capability and vendor terms are both changing fast enough that a policy left untouched for a year will describe a landscape that no longer exists. The review does not need to be lengthy — mostly it is confirming the approved tool list is still accurate and that nothing new has crept in.
06Can Peritus Digital help us implement this properly?
Yes. A policy document is the first step, not the whole job. We help businesses across Newcastle, Lake Macquarie, the Central Coast and Port Stephens work out what staff are actually using, choose and configure an approved tool with the right data-handling tier, set the permissions underneath it — which matters more than most people expect, because tools like Copilot inherit whatever file access already exists — and train the team on what the policy means in practice.
More — Keep exploring
Related free tools
Want hands-on help, not just a check? Explore ourAI Solutions service.
