Most marketing teams already use AI tools, often before anyone has written down how. A policy does not need to be long. It needs to answer the questions people actually have on a Tuesday afternoon: can I paste this brief in, can I publish this draft, who do I ask.
The template below is a starting point for a team or an agency. Adapt it with whoever handles legal and IT questions in your organisation. Agencies usually need one extra section per client, because clients differ in what they allow.
1. Approved tools
List the tools people may use for work, with the account type. A personal free account and a company workspace with data controls are different tools, even when the product name is the same.
- Approved: the named tools and accounts the team may use today.
- Under review: tools someone has asked for, with a named person deciding.
- Not approved: tools that must not be used with company or client material, and why.
2. What may be shared
Three tiers are enough for most teams.
- Fine to share: published material, approved briefs, general questions.
- Ask first: unpublished plans, internal figures, anything about a named client.
- Never: personal data about customers or colleagues, credentials, unreleased financial results, anything under a confidentiality agreement.
For an agency, the middle tier is where client-specific rules live. Some clients permit their brand material in an approved tool; others do not. Record the answer per client rather than relying on people to remember.
3. What needs review before use
The rule of thumb: anything that leaves the team needs a person to sign it off.
- Published content, including social posts and ads.
- Messages to customers or prospects.
- Figures, statistics and product claims, checked against the source.
- Anything sent on behalf of a client.
The review itself is a skill. This guide describes a practical way to check AI drafts and summaries before a team relies on them.
4. Disclosure
Decide when you tell people that AI was involved. A common position: internal drafts need no label, published content follows the platform’s and the client’s rules, and images generated with AI are described as such where they could be mistaken for photographs. Write down your position so nobody has to guess in the moment.
5. Ownership and questions
Name the person who owns the policy, how to ask for a new tool and when the policy will next be reviewed. A quarter is a reasonable interval; tools and client expectations change faster than most documents.
A one-page version
If the full document feels like too much for now, a single page with these lines covers most situations.
- These are the tools and accounts we use for work.
- This is what you may paste in, this is what you ask about first, this is what you never share.
- Anything published or sent to a customer is reviewed by a person first.
- Facts and figures are checked against the source before use.
- Questions and tool requests go to this person.
Keeping it alive
A policy that lives in a shared drive and nowhere else stops being read. Bring it into onboarding, mention it when a new tool is approved and revisit it after any incident, however small. Training on the team’s own tasks is the most reliable way to make the rules habitual.
We run practical AI training for marketing teams built around the tasks people already do, including how to apply a policy like this one without slowing the work down.



