How do I set an AI use policy for my agency?
An AI use policy for your agency needs to answer three questions in plain language: which tools your team may use, what client information is allowed to go into them, and where human review stays mandatory before work reaches a client. Keep it to a single page. Name the approved and off-limits tools, draw a clear line around confidential and NDA-covered client data, and require a person to check every AI-assisted deliverable for accuracy, originality, and quality. A strong policy is not about whether your team uses these tools, but about using them in a way that protects client trust and keeps the effort behind your work genuinely yours.
Why every agency needs a written AI policy
Without a written policy, each person creates one. One teammate may treat client materials as completely off limits. Another may paste a confidential brief into a tool because it makes drafting easier. A contractor may use a free account with different data handling than the account your staff uses. Nobody intends to create risk, but the boundaries are being invented task by task.
A short policy gives the team a shared default. It also makes questions easier to raise. Instead of wondering whether a practice is acceptable, someone can compare it with the rule or ask for an exception.
The policy should focus on behavior the team can follow. Broad statements such as “use AI responsibly” sound sensible but do not answer the moment-to-moment questions that matter. Approved tools, protected information, required review, and accountable ownership do.
Decide which tools are approved and which are not
Create a simple approved list. For each tool, identify the account or plan the team should use, the types of work it may support, and any settings that must be enabled. If personal accounts are not allowed for client work, say that directly.
An off-limits list can name specific tools, but it should also describe categories. You might prohibit tools that reuse submitted content for training, browser extensions that can read client systems, or unapproved tools that require uploading source files. Category rules keep the policy useful when new products appear.
Give someone responsibility for approvals. A team member who wants to try a new tool should know whom to ask and what information to provide. The reviewer does not need to conduct a huge process. They need to understand how the tool handles data, who can access it, and whether its intended use fits the firm’s commitments.
Set clear rules for client data and confidentiality
Start from the safest default: client information does not enter an AI tool unless the tool is approved for that information and the client’s terms allow it. Then make the protected categories concrete.
Protected information includes personal data, access credentials, internal financial information, unreleased plans, source code, private research, customer lists, health information, legal material, and anything covered by an NDA. Client-owned content can also be confidential even when it looks ordinary.
Explain that removing a client’s name may not be enough. A detailed brief can still identify the client through its facts. If the task does not require real data, use a generic example or a sanitized summary.
The policy should also tell the team what to do after a mistake. Stop using the material, preserve the facts, notify the designated owner, and follow the firm’s incident process. Hiding an accidental upload makes the problem harder to handle.
Define where human review is always required
Every client-facing deliverable needs a named human owner. That person is responsible for the work whether AI contributed one sentence or the first draft of the whole piece.
Define the minimum review checks. Factual claims need verification. Sources need to exist and support the statement. Copy needs to match the client’s voice. Creative work needs an originality check. Recommendations need to reflect the actual client context. Sensitive material needs another confidentiality check before delivery.
Some uses may require deeper review. Strategy, legal or medical subject matter, public claims, and anything that can affect a client’s customers deserve more scrutiny than an internal meeting summary. The policy can set those categories without becoming a long manual.
For a detailed workflow, see How do I keep quality control when the team uses AI tools?.
Put it in writing and keep it to one page
A useful one-page policy can follow five headings:
- Purpose and scope.
- Approved and prohibited tools.
- Client data rules.
- Required human review.
- Questions, exceptions, and incident reporting.
Use direct statements. “Do not paste NDA-covered material into any tool unless that tool and use are explicitly approved” is better than a paragraph about risk awareness. Include the policy in onboarding for employees and contractors, and keep it somewhere the team already looks for working procedures.
Connect the rule to the workflow. If review is required, add a review task or approval state to the project template. A policy that lives only in a handbook will be forgotten under deadline pressure. A required step in the workflow is visible when the work is moving.
Review the policy as tools and clients change
Review the policy on a regular schedule and whenever a meaningful condition changes. That includes adopting a new tool, changing account terms, taking on a client with stricter requirements, or learning that the team is using AI in a way the policy did not anticipate.
Keep an exception log. If a client authorizes a particular use or prohibits AI entirely, record that boundary where the account team can see it. Do not rely on one person remembering a contract detail.
The policy should evolve, but frequent changes should not make it confusing. Update the approved list and clarify the rules when evidence calls for it. Then tell the team what changed in plain language. For the client-facing side of the same issue, read Should I tell clients when my team uses AI?. A consistent internal workflow also helps, which is why the policy should connect with your approach to standardizing project workflows across the team.
FAQ
What should never go into an AI tool?
Anything confidential or covered by an NDA: client financial details, unreleased plans, personal data, and proprietary material. When in doubt, treat client information as off limits unless you have explicit permission and know how the tool handles what you put in.
Does a small studio really need a formal policy?
Yes, and it can be short. Even a one-page policy prevents the quiet inconsistencies that erode client trust, like one person pasting sensitive material into a tool while another assumes that is off limits.
Where should human review always stay required?
Anywhere accuracy, originality, or client confidentiality is on the line: final copy, anything factual, and any deliverable going to a client. A person should own the quality of the work regardless of how it was produced.
See your work before it drifts.
Net Net keeps plan and effort side by side, so you catch the slip while there is still time to act.
Start your free trial