Most small firms I talk to already have staff using AI, usually ChatGPT or Copilot, and very few have anything written down about it. That's common, but it's worth fixing before a client, an insurer or the Privacy Act asks you about it.
Start with what's already happening
Before writing any rules, find out which AI tools your people actually use, on which accounts, and what they put into them. The usual gap is free versions on personal logins, where the firm has no control over the account and, depending on the tool's settings, what staff type in can be used to train the model.
A short list is enough to start: the tool, who uses it, what for, and whose account it's on. That list becomes your AI register, and most of the policy follows from it.
What the policy should cover
For a firm of 10 to 100 people this doesn't need to be long. The areas I'd expect to see:
One named person owns AI use, usually a partner or the practice manager. "IT" isn't a person.
Organisation-managed accounts with multi-factor sign-in, so you can switch access off when someone leaves.
Plain rules by type of information (public, internal, client, and sensitive such as health or financial details). Most firms can do this in a single table.
Anything that goes to a client, or feeds a decision about a person, gets reviewed by someone who could have done the work themselves.
Before a new AI tool goes in, ask where the data is stored, whether it's used for training and who can access it. Ask your practice management vendor the same questions when they switch on AI features, because they will.
A one-page summary people will actually read, and ten minutes at a team meeting to go through it.
Who to tell, how to contain it, and how to decide whether it's a notifiable data breach.
If you're on Microsoft 365 and looking at Copilot, point 3 extends to everything Copilot can reach in SharePoint, OneDrive and Teams, which is a permissions question more than a policy one. That's what our AI readiness assessment covers.
Use the free template
The National AI Centre publishes a free AI policy template as part of its Guidance for AI adoption, and for a lot of small firms it's the right place to start.
The template gives you the document. What it can't tell you is which clauses matter for your firm, because that depends on what tools you use and what information goes into them. That's the part most firms skip, and it's why I'd do the register first and the policy second.
"Unsure" is an answer
When I built the free check I gave every question an "Unsure" option, because for a lot of firms that's the true answer to half of them. If nobody can say whether client information goes into AI tools, that's a finding in itself, and usually the first one to fix. Unsure still counts against you in the score for the same reason.
The Privacy Act change in December
From 10 December 2026, if the Privacy Act applies to your business, your privacy policy has to say when personal information is used in automated decisions that could significantly affect someone. That includes decisions where an AI tool does part of the work.
For most professional-services firms that'll be a short list, possibly an empty one, but you can't say either way without knowing what tools are in use. The Act generally applies to businesses turning over more than $3 million and to any business providing a health service, whatever its size. If you're not sure whether it covers you, the OAIC website explains the tests, and its guidance on using commercially available AI products covers the privacy side in more detail.
Where to start
If you want to see where your firm sits, the free 12-question check gives you a screening score and the main gaps, and you can choose Unsure wherever you don't know. If you then want the documents, the AI Trust Pack turns a longer assessment into a draft policy, AI register, data handling matrix and incident procedure for A$195 including GST, for you to review and adopt.
Either way, I'd rather see a one-page policy the whole team has read than a twenty-page one sitting in a shared folder.
Twelve questions to see where your firm's AI rules need work.
Start the free 12-question check