All templates
Privacy Act / APPs · APP 1, 6, 8 & 11

AI Acceptable Use Policy Template for Australian Medical Practices

The internal policy deciding which AI tools staff may use, in what tier, with what patient information, and what patients are told. Built from the OAIC's guidance on commercially available AI products and APP 1, 3, 6, 8, 10 and 11, with an approved-tools register and a 13-step vendor assessment procedure. The same evidence RACGP 6th edition criterion F11 will ask for when the accreditation transition lands.

Privacy Act 1988Australian Privacy PrinciplesRACGP Standards for general practices (6th edition)10 pages, Word format

Download this free template

Enter your email and we'll send you a download link for the AI Acceptable Use Policy template in Word format.

No spam. We'll only send you compliance tips relevant to your practice. Unsubscribe any time.

What's in this template?

This is the internal policy that decides which AI tools your practice team may use, in what configuration, with what patient information, and what patients are told about it. It is built from the OAIC's Guidance on privacy and the use of commercially available AI products, the Privacy Act 1988 (APP 1, 3, 6, 8, 10 and 11), and criteria F10 and F11 of the RACGP Standards for general practices (6th edition).

The OAIC's expectation is direct: organisations using AI should "establish policies and procedures for the use of AI systems to facilitate transparency and ensure good privacy governance." This template is that document.

The template has 12 numbered sections and two fillable appendices:

  1. Purpose: why a decision about AI has to be recorded rather than left to whoever found the tool first
  2. Scope: all staff including contractors and locums, every AI tool that touches practice information, and AI features a vendor switches on inside software you already use
  3. How this relates to the Computer and Information Security Policy and the Privacy Policy: the boundary table, restated below
  4. Approved AI tools and configurations: only what is on the register at Appendix A, in the tier it was approved in
  5. Prohibited uses: the explicit list of what must never be entered into an unapproved tool, covering names, dates of birth, Medicare and IHI numbers, clinical details, referral content, consultation notes, plus AI output used as clinical advice without clinician review
  6. Patient disclosure and consent: what the privacy policy must say, consent where AI is involved in care, AI scribes handled as the highest-risk case, chatbots identified as AI
  7. Assessing a new AI tool before adoption: a 13-step procedure covering the data processing agreement, model-training opt-out, data residency, sub-processors, breach notification, security certifications, privacy impact assessment and the ARTG question
  8. De-identification standard: why removing a name is not de-identification, and what to do when in doubt
  9. Monitoring, review and incidents: annual review of the register and tool settings, post-implementation evaluation, and what happens when someone pastes the wrong thing into the wrong tool
  10. Roles and responsibilities: practice owner, privacy officer, clinicians, all staff, IT provider
  11. Related documents
  12. Approval and review: with a signature block

Appendix A: Approved AI tools register. A fillable table (tool and vendor, approved tier or plan, permitted uses, prohibited uses, data residency, DPA review date, approved by, next review), printed landscape so it is usable.

Appendix B: Staff acknowledgement and training log. A fillable log of who has read the policy and who has had tool-specific training.

Editable placeholder fields

The template uses yellow-highlighted {{placeholder}} fields:

  • {{practice_name}}, {{abn}}, {{practice_address}}
  • {{privacy_officer}}: the person accountable for the register, the assessments and incident reports
  • {{approved_by}}: who signs off the policy and every tool added to the register
  • {{effective_date}}, {{next_review_date}}, and the sign-off dates in the signature block

Grey italic notes mark the places that need your judgement rather than a find-and-replace, including the one most practices need to hear: an empty register alongside this policy is a compliant position for a practice that uses no AI, and it is better evidence than a register listing tools nobody has assessed.

Three documents, three different questions

Practices often have one of these documents and assume it covers the others. It does not.

DocumentThe question it answers
AI acceptable use policy (this template)Which AI tools may be used, by whom, with what information, and how patients are told
Computer and Information Security PolicyHow practice systems are secured generally: access control, passwords, backups, malware, devices
Privacy PolicyThe public-facing APP 1 document telling patients how the practice handles their information, including that it uses AI

This policy feeds the privacy policy and relies on the security policy. It does not replace either.

The security policy sets the baseline controls any software sits on top of, and it covers general email and internet acceptable use. It does not answer whether a clinician may run an AI scribe in a consultation, or whether reception may paste a referral into a chatbot to tidy up the wording. The privacy policy is where patients are told AI is in use, but a public document cannot tell your staff which tier of which product they are allowed to open. The gap between those two is exactly the space this template fills, and it is the space most practices are operating in right now.

A worked example. A practice has a strong security policy: MFA everywhere, tested backups, patched endpoints. A GP starts using an AI scribe on a personal trial account. Nothing in the security policy is breached, because the laptop is patched and the account has MFA. What has happened is that consultation audio is now going to an overseas vendor whose terms permit training on inputs, no patient has been told, and the privacy policy says nothing about it. That is an APP 6, APP 8 and APP 1 problem, and only the AI acceptable use policy would have caught it before it started.

What the OAIC and the Privacy Act actually require

The Privacy Act applies to every use of AI that involves personal information, and the obligations bite now, with no transition period.

Privacy obligations cover outputs as well as inputs. The OAIC is explicit that privacy obligations apply to any personal information put into an AI system and to the output the AI generates where that output contains personal information. Information an AI system generates or infers about an identified or reasonably identifiable individual, including something the model has invented, is personal information the practice must handle under the APPs. If your AI tool generates or infers personal information, that is a collection under APP 3, and it has to be reasonably necessary for your functions and done by lawful and fair means.

APP 6 limits what you can put in. Health information is collected for the purpose of providing healthcare. Under APP 6 you can only use or disclose it for that primary purpose, unless the patient has consented or the secondary use is one they would reasonably expect and is directly related to the primary purpose. Vendor model training on your consultation content is a secondary purpose, and the OAIC notes that given the privacy risks AI presents, it may be difficult to establish that a secondary AI-related use was within a patient's reasonable expectations at all. Where you cannot clearly establish that, seek consent or offer a meaningful opt-out.

Due diligence before adoption, and it is not set and forget. The OAIC expects organisations to check that a product is suitable for the use they intend: whether it has been tested for that use, how human oversight is built into the process, the privacy and security risks, and who gets access to the information going in and coming out. It also expects regular review of the product's performance, staff training and monitoring across the whole lifecycle of the tool. Section 7 of the template is that due-diligence procedure; Section 9 is the review loop.

Transparency, in the privacy policy and at the point of use. Update your privacy policy and collection notices with clear information about the practice's use of AI, and make sure any public-facing AI tool such as a chatbot identifies itself as AI to the people using it.

Accuracy under APP 10. Generative AI is probabilistic and produces false results. APP 10 requires reasonable steps to keep personal information accurate, and the OAIC's position is that those steps scale with the higher risk of an AI context. In a practice, that means a clinician reads and corrects the note before it is saved.

Public generative AI tools. The OAIC recommends, as a matter of best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. Health information is sensitive information. That recommendation is why Section 5 of the template is a hard prohibition rather than a caution.

The RACGP F11 forward view

The RACGP published the Standards for general practices (6th edition) on 26 August 2026. It is the first edition to name artificial intelligence directly.

  • F11.A requires that where the practice uses AI, it does so safely and securely and consistent with existing standards. That includes obtaining and documenting informed patient consent when aspects of care will be delivered using AI, de-identifying data where AI tools process patient data, keeping identified patient data out of AI tools unless its use is clinically necessary and explicitly authorised, establishing governance processes for AI use, and documenting clinical oversight of AI outputs. Clinicians remain accountable for care decisions supported by AI tools.
  • F11.B requires the practice to assess and evaluate its use of AI: a risk assessment before implementation, and monitoring, review and quality improvement afterwards.
  • F10.A sits alongside them and covers the governance of digital health technologies more broadly.

Status, stated plainly: practices are still accredited against the 5th edition. The transition under the National General Practice Accreditation Scheme is a matter for the Australian Commission on Safety and Quality in Health Care, which has not yet announced the arrangements. F11 is not assessable today, and it applies only to practices that use AI at all.

That gap is the reason to do this now rather than later. The register, the vendor assessments, the consent process and the review loop are the same evidence F11.A and F11.B will ask a surveyor to see. Completing this policy answers the Privacy Act duty that applies today, and puts the accreditation evidence on the shelf before the transition date lands. Our RACGP 6th edition migration guide covers what else changes.

How to customise this template

  1. Download the Word document and open it in Microsoft Word or Google Docs
  2. Replace each {{placeholder}} with your practice details, and decide who holds the {{privacy_officer}} role for AI purposes. In most practices this is the existing privacy officer or the practice manager, not a new appointment
  3. Fill in Appendix A before you circulate the policy. Section 4 has no meaning until the register lists the tools your practice actually uses, with the specific plan named. Walk the practice and ask: what is the clinical team using, what has reception signed up to, and what AI features have appeared in the clinical software or the office suite since the last review
  4. Run Section 7 over the tools already in use, not only the next one. Most practices adopt an AI scribe first and assess it afterwards. Record the assessment on the date you actually did it
  5. Decide your prohibited-use additions in Section 5. Common ones: a scribe approved for consultations but not for medico-legal reports, or a general-purpose tool approved for administrative drafting but never for clinical content
  6. Update your privacy policy at the same time. Section 6 sets what staff must do; the privacy policy is where patients are told. Doing one without the other leaves the gap open
  7. Update your patient consent process if you use an AI scribe, so consent is captured and documented in the patient's record before anything is recorded
  8. Have your practice owner and privacy officer sign the approval block, then circulate and collect the Appendix B acknowledgements
  9. Set the review date. At least annually, and sooner whenever a vendor changes its terms or a new AI feature turns up in existing software

Related templates and tools

  • Computer and Information Security Policy: the baseline controls this policy assumes are in place: access control, passwords, backup, malware, devices and general acceptable use
  • Privacy Policy: the patient-facing APP 1 document that must disclose the practice's use of AI. Update it whenever a tool is added to or removed from Appendix A
  • Data Breach Response Plan: where an AI incident goes. Patient information entered into an unapproved tool is assessed under the Notifiable Data Breaches scheme like any other exposure
  • Privacy Impact Assessment: step 10 of the Section 7 assessment for any AI tool that will handle health information
  • AI privacy compliance for healthcare practices: the full explanation of the APP obligations behind this policy, the highest-risk AI use cases, and what to look for in an AI vendor contract
  • RACGP 6th edition migration guide: what the 6th edition changes beyond F10 and F11, and what to do while the 5th edition still applies

Frequently asked questions

Does my practice need an AI acceptable use policy?

If anyone at your practice uses an AI tool with practice information, yes. The OAIC expects organisations deploying AI to establish policies and procedures for its use, and that expectation sits under the Privacy Act, which applies now. The harder question is whether you know what is in use. AI features arrive inside software you already pay for, and individual clinicians adopt scribes without a practice-level decision. If you cannot list your AI tools and the plan each one is on, the policy is the fastest way to find out, because filling in Appendix A forces the audit.

Does this policy ban AI?

No. It is a permission structure, not a prohibition. The template says which tools are approved, in which configuration, for which tasks. The OAIC's guidance is not that AI is off limits in healthcare; it is that a practice has to assess what it uses, understand how the tool handles health data, and document that assessment. A practice with three approved tools and a completed register is in a stronger position than a practice that has banned AI on paper while a scribe runs in room 4.

What about ChatGPT on a free account?

Prohibited for anything involving patient information, and the template says so explicitly. Consumer and free tiers generally permit inputs to be used to improve the vendor's models, which makes any patient information entered a secondary use under APP 6 and, for an overseas vendor, a cross-border disclosure under APP 8. The OAIC recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The business or enterprise tier of the same product is a different question: those plans usually come with a data processing agreement and a model-training opt-out, which is why the template approves tools by tier rather than by product name.

Do patients have to be told the practice uses AI?

Yes, in two places. Your privacy policy has to carry clear information about the practice's use of AI under APP 1, and a public-facing tool such as a chatbot has to identify itself as AI to the person using it. Beyond disclosure, where an aspect of care will be delivered using AI, F11.A of the 6th edition expects informed patient consent to be obtained and documented, and a patient may withdraw that consent at any time. For AI scribes the practical rule is simplest: tell the patient before anything is recorded, record their consent in their health record, and offer the same care without the tool if they decline.

What is RACGP criterion F11, and does it apply now?

F11 is the artificial intelligence criteria set in the Standards for general practices (6th edition), published on 26 August 2026. F11.A covers safe and secure use of AI, including patient consent, de-identification, governance and clinical oversight of AI outputs. F11.B covers assessing and evaluating AI use before and after implementation. It is not assessable today: practices are still accredited against the 5th edition until the National General Practice Accreditation Scheme transitions, and the Australian Commission on Safety and Quality in Health Care has not announced those arrangements. F11 also applies only to practices that use AI. The Privacy Act obligations in this template apply regardless, which is why the same document answers today's duty and becomes the F11 evidence when the transition lands.

How does this relate to our computer and information security policy?

They cover different ground. The security policy is about how practice systems are protected: user accounts, passwords and MFA, backups, malware protection, patching, mobile devices, and general email and internet acceptable use. This policy is about which AI tools are allowed on top of that baseline, what information may go into them, and what patients are told. A practice can be fully compliant with its security policy and still have a live privacy problem, because a patched laptop running an unassessed AI scribe is a secure device sending consultation audio somewhere nobody has checked.

What goes in the approved AI tools register?

One row per tool: the tool and vendor, the approved tier or plan, what it may be used for, what it may not be used for, where the data is stored, the date you reviewed the vendor's data processing agreement, who approved it, and the next review date. Record the specific plan rather than the product family, because the plan is what determines the data terms. Include AI features inside software you already use, since a vendor enabling one creates a new tool to assess. If your practice uses no AI, write "No AI tools in use" in the first row and date it. That is a complete register and the correct evidence for a practice that has decided not to adopt AI.

30-day free trial, no credit card

Be the practice the assessor compliments.

Set up your frameworks this weekend. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime