Build your workspace

Policy checklist

An agency AI policy people can follow

Plain rules for tools, client data, disclosure, approval, records, and mistakes.

By . Reviewed August 21, 2026. 6 minute read.

An agency AI policy defines which tools the team may use, what client information they may process, which outputs need human review, when clients are told about AI use, and what happens when something goes wrong. The policy should be short enough to use during real work.

1. List approved tools and accounts

Name the AI products the agency has reviewed. State which plan and account type staff must use, whether the vendor may train on submitted data, how long data is retained, and who can approve a new tool. Personal accounts should not receive client information.

2. Classify client data

Define categories your team can recognize: public, internal, confidential, restricted, and prohibited. Give examples from agency work. Public website copy is different from an unreleased campaign. A client contact list is different from payment credentials. If a category is unclear, the default should be to ask.

3. Set access by workflow

Give an AI workflow only the information required for its assigned task. Scope access by client and role. Remove access when the workflow ends. Keep internal notes separate from client-visible records. Never treat broad access as a shortcut for poor information design.

4. Define what needs human review

Write separate rules for drafting, recommending, changing, and sending. A meeting summary may use spot checks. A client message, deadline change, scope decision, refund, contract term, campaign launch, or public claim needs approval from the owner of that decision. The reviewer should see the source material, not only the AI output.

5. Decide when to disclose AI use

Tell clients how AI affects their work in language tied to the actual service. Cover material uses, data handling, subcontractor or vendor terms, and the role of human review. Avoid vague statements that create more questions than they answer. Agency Core 2026 reports that 82% of client-side decision-makers want agencies to be transparent about AI use.

6. Check facts, rights, and brand rules

Require reviewers to verify factual claims, calculations, links, names, dates, and quoted material. Set rules for copyrighted input, licensed assets, personal data, and client brand voice. Generated content should not quietly become a source for later work unless it has been reviewed and approved.

7. Keep records

Record the workflow, source records, output, reviewer, approval, external action, and model or tool version when practical. Logs make it possible to investigate a mistake, improve the process, and answer a client question without reconstructing the event from memory.

8. Plan for incidents

Name the person who can pause a workflow. Define how staff report wrong outputs, data exposure, unauthorized actions, or harmful content. Preserve the relevant logs, contain the problem, correct any client-facing result, and review whether access or instructions need to change.

9. Assign ownership and review dates

Give each production workflow an owner. Give the overall policy an owner too. Review approved tools, vendor terms, permissions, incidents, and client expectations at a set interval. A policy that nobody updates becomes an archaeological artifact surprisingly quickly.

Copy this minimum checklist

  • Use only approved business accounts.
  • Do not submit restricted or prohibited client data.
  • Scope access to the client and task.
  • Verify facts and source material.
  • Get approval before client-facing or irreversible actions.
  • Disclose material AI use according to the client agreement.
  • Record outputs, reviews, and external changes.
  • Report incidents and pause unsafe workflows.

Reference: NIST Generative AI Profile. This checklist is operational guidance, not legal advice. Ask qualified counsel to review requirements that apply to your clients, locations, contracts, and data.