Writing an AI policy that staff will actually follow
A policy that prohibits AI without providing an alternative does not reduce your exposure. It reduces your visibility of it.
Published 26 July 2026
Most AI policies we see share a structure: a definition section, a prohibition on entering confidential information into AI tools, a reminder about professional obligations, and a signature block. Circulated once, acknowledged by everyone, filed.
They almost never work, and the reason is not that staff are careless.
Why prohibition fails
A policy changes behaviour when following it is easier than not following it, or when the risk of being caught is real. AI policies satisfy neither condition.
The tools are free, work on personal devices, require no procurement, and leave no trace on your network. Detection is effectively zero. Meanwhile the benefit to the individual is immediate and substantial — an hour saved on a summary, a draft that would have taken until midnight finished by nine.
You are asking a tired person to voluntarily do an hour of extra work, tonight, for an abstract organisational risk, with no chance of anyone noticing either way. Policies do not win that argument. They never have, on any subject.
What the policy does achieve is a reduction in disclosure to you. Before the policy, someone might mention that AI helped with a draft. After it, they will not. The behaviour persists; your visibility of it does not.
There is a sting in that. A documented policy establishes that the firm was on notice of the risk. If a disclosure later has to be assessed, the existence of an ignored policy is not the protection people assume — it can cut the other way.
What a policy can realistically achieve
It is still worth having one. Just be clear-eyed about what it does.
A good AI policy sets a standard of expected conduct, gives staff a defensible position when they are unsure, creates a route for people to ask rather than guess, and documents the firm’s considered position. Those are real benefits.
What it cannot do is act as a technical control. If the only thing standing between a client file and an overseas server is a document in the staff handbook, you do not have a control. You have a preference.
A structure that works better
1. Start by acknowledging reality
Open with a line stating that the firm understands staff are already using AI tools and that this policy is intended to make that safe rather than to pretend it is not happening.
This single sentence changes how the document is received. A policy that opens from a false premise is read as theatre, and everything after it is discounted.
2. Classify information, do not blanket-ban
Blanket prohibitions get ignored wholesale. Tiered rules get followed selectively, which is a much better outcome.
Something like:
- Tier 1 — never leaves the firm. Client documents, patient information, financial records, anything under an NDA, anything identifying a person. No external AI tool, no exceptions, no anonymising-and-hoping.
- Tier 2 — approved tools only. Internal non-client material, general drafting, research where no client facts are included.
- Tier 3 — unrestricted. Public information, general knowledge questions, learning how the tools work.
Give real examples for each tier drawn from your own work. Abstract categories get interpreted generously by people who want a particular answer.
3. Name the approved tools and the exact tier
“Use approved AI tools” is not actionable. Which product, which plan, which account, accessed how.
If your firm has an enterprise arrangement, say so explicitly and explain how to log in — including what to do when the session has expired, because that specific friction point is where compliance dies.
4. Address personal devices directly
This is the clause most policies omit, and it is where most of the actual exposure sits. Say plainly whether firm information may be entered into AI tools on a personal phone. If the answer is no, say it in those words.
5. Make the review obligation explicit
AI output must be checked before it is relied upon or sent. The professional responsible remains responsible. Say this clearly — it protects the firm and it protects the individual who might otherwise assume a plausible-sounding output was verified.
6. Provide a way to ask
A named person, and an explicit statement that asking is encouraged and never held against anyone. Most breaches of this kind come from people who were not sure and did not want to look behind the times by asking.
7. Review it on a fixed schedule
Six or twelve months. This field moves quickly and a policy referencing tools that no longer exist teaches staff that the whole document is stale.
The part policies cannot solve
Every structure above manages the risk. None removes it, because all of them ultimately depend on individual judgement under time pressure.
There are two ways to close that gap.
Provide a sanctioned tool good enough to be the default. If your firm has an enterprise AI arrangement that is genuinely easy to reach — already logged in, one click, no friction — a substantial share of the risky usage moves onto it voluntarily. Not because of the policy, but because it is easier. This is the cheapest meaningful improvement most firms can make, and if you do nothing else, do this.
Or make the disclosure architecturally impossible. If the AI runs on hardware in your own office, Tier 1 information can be used freely, because it never leaves the building. The policy stops being a restriction people work around and becomes a description of a system that already behaves correctly.
The second is a bigger commitment and it is not proportionate for every firm. A small practice where two people occasionally use AI for non-client work does not need it. A firm of thirty handling privileged material daily is a different calculation entirely.
The honest test
Take your current policy and ask one question:
If a staff member breached this tonight, on their phone, with a client document, would we ever find out?
If the answer is no, the policy is not a control. It may still be worth having — for the standard it sets and the position it documents — but you should stop counting it as protection, and start thinking about what actual protection would look like.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.