Who Signs Off on AI? The One-Page Policy Your Team Will Actually Use
Most AI policies say nothing. Ours fits on one page: who approves a tool, what the Privacy Principles keep out of a prompt, what a human checks, and who owns it when it breaks.
The template
Copy it, fill the grey fields, publish it where people actually look. The grey is the only work this asks of you.
AI use at [your company]
The rule. AI is approved for use here. Use the tools on the approved list, do not put the restricted data below into any of them, and check anything before it reaches a customer.
Approved tools. [list them, with the plan type] Review this list quarterly, or it becomes a lie and people stop reading the page.
Getting a new tool approved. Ask [name]. They will answer within two business days. They check: business plan, whether it trains on our data, what data would go into it, and whether we already pay for something that does the job.
Never put into any AI tool: customer personal information unless the tool is approved for it, anything under a client NDA, employee records, health information, credentials or keys, unreleased financials.
A human checks it before: it goes to a customer, it changes a CRM record, it goes on the website, or it informs a decision about a person.
If something goes wrong, tell [name] the same day. You will not be in trouble for reporting it. You will be in trouble for hiding it.
Reviewed: [date]. Next review [date, six months on].
That is the whole thing. If yours is longer than that, ask what the extra pages are for and who reads them.
Where the restricted list comes from
The never-put-this-in line is not a values statement, it is the Australian Privacy Principles applied to a text box. APP 6 governs what you are allowed to use and disclose personal information for, and a prompt sent to a third-party tool is a disclosure. APP 11 makes you responsible for keeping that information secure once it has left. The OAIC published two guides in October 2024 on privacy and AI, one on using commercially available products and one on developing them, and between them they answer the prompt question for most businesses.
One more thing the page should already carry. From 10 December 2026, a business has to be able to explain an automated decision if a customer asks about it. If AI touches pricing, credit, eligibility, hiring or anything else that affects a person, name who can explain it while you are writing the page rather than the week it applies. We covered the Privacy Act change landing on 10 December 2026 separately.
The three mistakes we see
Could your team name who approves a new AI tool?
Usually it is whoever signed up first, and that becomes the policy.
Banning it. A ban does not stop usage, it stops reporting. You end up with the same risk and no visibility, which is strictly worse than where you started.
Writing it once. The tools change every quarter. A policy naming a product that no longer exists teaches people the document is decorative, and once they learn that, they stop checking it for the parts that matter.
Skipping the training. Most breaches are not malice, they are a person who genuinely did not know that pasting a customer list somewhere counted. Twenty minutes in an all-hands, once a year, with three real examples of what not to do. That is the whole training programme and it works better than the policy does.
Where this sits
If you want the formal scaffolding, Australia's AI Ethics Principles give you the language a board expects, and the NIST AI Risk Management Framework is the reference most enterprise procurement teams now use. Both are useful and neither is a policy. They are what you point at when someone asks what your one page is based on.
Write the page first. Map it to the frameworks later, if anyone asks.
Not sure what your team is already pasting into a chatbot?
Most businesses are surprised. We help work out what is actually in use, what to approve, and what to shut down, then leave you with a page people will actually follow. The bigger version of that work is on our AI Engineering service page.
Two related reads if the setup underneath is the real problem: the signs your HubSpot CRM needs an overhaul, and when you need managed HubSpot support.
We are Neighbourhood. We build the AI and the revenue system it runs on. AI and RevOps engineering for Australian teams. Diamond HubSpot Partner, 17 HubSpot Impact Awards.
Who owns it at your place when an AI output goes wrong?
Most people answer that for the first time after it happens.
Give us a shout and tell us what's broken.