How do I set an AI use policy for my agency?
An agency AI policy should answer three things without making the team read a legal novella: which tools are approved, what client information may go into them, and where human review is required. Keep the core policy to one page. Name the tools and account types the team can use, draw a hard line around confidential and NDA-covered material, and give every AI-assisted Deliverable a human owner. Your team is already making these choices. The policy makes sure they are not making ten different versions of them.
Why every agency needs a written AI policy
Without a written policy, every person invents one during the work. One teammate treats client materials as completely off limits. Another pastes a confidential brief into a tool because it makes drafting faster. A contractor uses a personal account with different data handling than the firm’s account. Nobody set out to create a mess. The rules just showed up one task at a time.
A short policy gives employees and contractors the same starting point. It also makes questions easier to raise. People can compare a planned use with the rule, or ask for an exception before client data has already gone somewhere it should not.
Focus on behavior the team can follow. “Use AI responsibly” sounds nice and answers almost nothing. Approved tools, protected information, required review, and a named owner answer the questions that come up while a deadline is moving.
Pick approved tools before everyone picks their own
Create a simple approved list. For each tool, name the account or plan people should use, what kind of work it may support, and any required settings. If personal accounts are off limits for client Jobs, say that without burying it on page four.
An off-limits list can name tools, but it should also describe categories. The agency may prohibit tools that reuse submitted content for training, browser extensions that can read client systems, or unapproved services that require uploading source files. Category rules survive longer than a list of product names.
Give one person or role authority to approve a new tool. The review does not need a committee and a ceremonial ribbon cutting. It needs answers about data handling, access, account terms, and whether the proposed use fits the firm’s promises to clients.
Set clear rules for client data and confidentiality
Use the safest default: client information stays out of an AI tool unless that tool is approved for the information and the client’s terms allow the use. Then explain what protected information means inside your firm.
That can include personal data, credentials, internal financial information, unreleased plans, source code, private research, customer lists, health information, legal material, and anything covered by an NDA. Client-owned content can be confidential even when it looks ordinary.
Removing the client’s name may not be enough. A detailed brief can identify the company through its facts. If the task does not require real information, use a generic example or a sanitized summary instead.
Tell people what to do after a mistake too. Stop using the material, preserve the facts, notify the designated owner, and follow the firm’s incident process. Hiding an accidental upload because it feels embarrassing makes the response harder.
Decide where a person must review the work
Every client-facing Deliverable needs a named human owner. That person owns the result whether AI suggested one line or produced the first draft of the whole thing.
Set the minimum checks. Verify factual claims. Confirm that sources exist and support the statement. Review voice, originality, recommendations, client context, and confidentiality. “It read smoothly” is not a quality-control process.
Some work needs more scrutiny. Strategy, legal or medical subjects, public claims, and anything that can affect a client’s customers deserve deeper review than an internal meeting summary. The policy can name those categories without turning into a manual nobody opens.
For the detailed workflow, see How do I keep quality control when the team uses AI tools?.
Put it in writing and keep it to one page
A practical one-page policy can use five sections:
- Purpose and scope.
- Approved and prohibited tools.
- Client data rules.
- Required human review.
- Questions, exceptions, and incident reporting.
Write direct rules. “Do not paste NDA-covered material into a tool unless both the tool and the use are approved” helps more than a paragraph about risk awareness. Include employees and contractors, and keep the policy somewhere the team already looks for working procedures.
Put the rules into the workflow too. If a person must review the output, add a review task or approval step to the Job template. A policy that lives only in a handbook gets very quiet when the deadline gets loud.
Review the policy as tools and clients change
Review the policy on a schedule and when something meaningful changes, such as a new tool, different account terms, a stricter client contract, or a use the original policy did not anticipate.
Keep a visible exception log. If a client approves one use or prohibits AI entirely, record that where the account and delivery teams can see it. One person’s memory is not a reliable contract-management system.
Update the approved list and examples when the evidence changes, then tell the team what moved. For the client-facing side, read Should I tell clients when my team uses AI?. The policy also works better when it connects with your approach to standardizing project workflows across the team.
FAQ
What should never go into an AI tool?
Treat confidential and NDA-covered material as off limits unless the tool and use are explicitly approved. That includes client financial details, unreleased plans, personal data, credentials, and proprietary material. When unsure, stop and ask before uploading.
Does a small studio really need a formal policy?
Yes, but formal does not have to mean long. One clear page can prevent the quiet inconsistencies that damage client trust, such as one person uploading sensitive material while everyone else assumes that is prohibited.
Where should human review always stay required?
Require it anywhere accuracy, originality, rights, or confidentiality matters. Final copy, factual claims, creative assets, code, recommendations, and anything sent to a client need a person who owns the review and the final decision.
See your work before it drifts.
Net Net keeps plan and effort side by side, so you catch the slip while there is still time to act.
Start your free trial