Guides / How-to

A one-page AI policy for a small marketing team

Why even a marketing team of one needs an AI policy, what belongs in it, and a complete fill-in-the-blanks one-page template you can copy and adapt.

· 6 min read · By DGTL

If you are the only marketer in the business, an AI policy can sound like paperwork for its own sake. You know what you use and what you would never paste into a chatbot. Why write it down?

Because at the moment those rules live in your head. The sales team is using free tools on personal accounts. The freelancer you hired last month has their own habits. And when the CEO asks “is it safe?”, you would like to hand over a page they have already signed.

It takes about an hour. The template is further down.

What a policy does for you

  • It answers the safety question once. You stop having the same conversation every quarter. See how to answer your CEO’s AI questions.
  • It covers people who are not you. Colleagues, freelancers, agencies and whoever holds the job after you.
  • It protects you personally. If something goes wrong, there was an agreed process and you followed it.
  • It forces a few decisions. Writing it down exposes the things nobody has decided, such as whether you tell customers when an image was generated.

What goes in

Six sections. Each should be a few lines.

Approved tools

List the specific tools and the type of account. This matters because the terms on how your inputs are stored, and whether they may be used to train future models, often differ between a free personal account and a paid business one. Read the terms for the accounts you hold and record what you found. Anything not on the list needs approval before use.

Data that never goes in

The section that matters most. Be explicit, because “be careful with sensitive data” means something different to everyone.

A sensible starting list:

  • Personal data about customers, prospects or staff (names with contact details, order histories, CRM exports)
  • Anything covered by a confidentiality agreement
  • Contracts, pricing agreements and legal correspondence
  • Unreleased financial information
  • Passwords, access keys and login details

On UK GDPR, in general terms: if you put personal data into an AI tool, you are processing it, and the usual obligations apply. You need a lawful reason, you need to know where the data goes, and the supplier’s terms need to be suitable. That is a decision for whoever is responsible for data protection in your company, not something to settle alone on a Tuesday afternoon. The simplest rule for a marketing team is to keep personal data out unless that person has approved the specific tool and use. This is a general pointer, not legal advice. The ICO publishes guidance, and your solicitor can advise on your situation.

Review and sign-off

State that nothing customer-facing is published without a named person reading, fact-checking and approving it. Say who. This is what “human in the loop” means in practice, and this guide explains the standard.

Disclosure

Decide when you tell people AI was involved. There is no single right answer, but there should be an answer. A common position: no label needed for AI-assisted text that a person has edited and approved, a clear label on any generated image that could be mistaken for a real photograph of your people, products or premises, and always an honest reply if a customer asks.

Images and rights

Generated images raise questions that text does not. Who owns the result, whether it resembles a real person or an existing work, and whether the tool’s terms allow commercial use. The law here is still developing. Keep the rules cautious: no generated images of real people, no imitating a named living artist or a competitor’s brand, no generated images presented as your actual product or work, and a record of which tool made what.

Accountability

One name for who owns the policy, one for who approves exceptions, and a line on what to do when something goes wrong. Mistakes reported quickly are fixable. Mistakes hidden are not.

The template

Copy this, fill in the brackets, delete what does not apply and get it signed. It is written to fit on one side of A4.

[Company name]: Use of AI in marketing

Version [1.0] | Agreed [date] | Next review [date, six months on] | Owner [name, role]

1. Purpose We use AI tools to work faster and to improve our marketing. We remain responsible for everything we publish. This page sets out how.

2. Who this covers Everyone producing marketing material for [company name], including staff, freelancers and agencies.

3. Approved tools

  • [Tool], [account type], used for [purpose]
  • [Tool], [account type], used for [purpose]
  • [Tool], [account type], used for [purpose]

Tools not listed here must be approved by [name] before use. Company work is not done on personal accounts.

4. What never goes into an AI tool

  • Personal data about customers, prospects or staff
  • Information covered by a confidentiality agreement
  • Contracts, pricing agreements or legal correspondence
  • Unreleased financial information
  • Passwords or access details
  • [Anything specific to your business]

Exceptions require written approval from [name of person responsible for data protection].

5. Review and sign-off Nothing customer-facing is published until a named person has read it in full, checked every fact, figure, name and link against a reliable source, and approved it. For [company name] that person is [name]. In their absence, [name].

6. Disclosure

  • AI-assisted text that has been edited and approved by a person: [no label required]
  • Generated images that could be mistaken for real photographs of our people, products or premises: [not used / clearly labelled]
  • If a customer asks whether AI was used, we answer honestly.

7. Images

  • We do not generate images of real, identifiable people.
  • We do not prompt tools to imitate a named living artist or another company’s brand.
  • We do not present generated images as our real products, premises or work.
  • We keep a record of which tool produced each generated image we publish.

8. Suppliers Agencies and freelancers working for us must follow this policy and tell us where AI was used in work they deliver.

9. When something goes wrong If confidential or personal data has been entered into a tool by mistake, or something inaccurate has been published, tell [name] the same day. We would rather know.

10. Accountability [Name] owns this policy and reviews it every six months. [Name, director] has approved it.

Signed: ____________________ Date: ____________

Getting it agreed

A short route that works:

  1. Fill in the template yourself. Do not start with a meeting.
  2. Check sections 3 and 4 with whoever handles data protection and IT.
  3. Send it to your CEO with a two-line note: “This is how we use AI in marketing and what we keep out of it. Can you approve it by Friday?”
  4. Share it with anyone who produces material for you, including agencies.
  5. Put the review date in your calendar.

Keeping it alive

A policy nobody reads is worse than none, because it gives false comfort. Keep it to one page. Update the tools list whenever you add or drop one. Use section 8 when you brief suppliers, and ask them the questions in the human in the loop guide linked above.

If you are also tightening up the technical side, website security basics covers the related ground. And if you want a second pair of eyes on your draft, we are happy to look.

Next step

Time for some support?

You do not have to do all of this alone. Tell us what is on your list, and we will tell you honestly where we can help.