Guide · 5 min read
AI Policy for a Marketing Team: What to Write and Why
By Fredrika Frenkiel, Head of Studio & AI Creative Operations at Lunar, founder of Code of Alfred. About my work
Short answer
A useful AI policy for a marketing team is short, specific and operational. It names the approved tools, the data that may never be entered into them, who signs off on AI-assisted output, when disclosure is required, and how often the policy is reviewed. Long legal documents written for compliance rather than for daily use are ignored under deadline pressure, which is exactly when the risk appears.
1. Write it for the person under deadline, not for the audit
The test of a marketing AI policy is whether a producer at 17:30 with a launch tomorrow can read it in two minutes and know what to do. That means one page, plain language, concrete examples from your own work, and a named person to ask. A twenty-page document attached to an intranet page changes nothing.
2. Name approved tools and the route to add one
List the tools people may use for client or brand work, and the process for getting a new one approved. Without this, teams either freeze or use whatever they have personally. Include who pays, who owns the account, and what happens to the data in each tool's default settings.
3. Be exact about data
State plainly what may never be pasted into a general-purpose model: unpublished financials, personal data, customer records, unreleased product information, client material under NDA, and anything covered by regulatory rules in your category. Give the alternative for each case, an approved enterprise instance or a manual route, so the rule does not simply block the work.
4. Define human sign-off and accountability
The policy should say that a named human is accountable for every published output, regardless of how it was produced. AI is never the author of record. Map sign-off to the stages that already exist in your workflow rather than inventing a parallel approval chain.
5. Decide your disclosure position
Decide when AI involvement is disclosed: to clients, in production credits, in imagery, in synthetic voice or likeness. Regulated categories and public-sector clients often require it. Take a position deliberately rather than discovering one during a crisis.
6. Set a review date
Models, vendors and regulation change quarterly. Put a review cadence and an owner in the document itself. A policy without a named owner and a next review date is out of date within a season.
How to do it, step by step
- 01
Keep it to one usable page
Write for a person under deadline: plain language, concrete examples, a named person to ask.
- 02
List approved tools and the approval route
State which tools are sanctioned, who owns them, and how a new one gets added.
- 03
Specify forbidden data, with alternatives
Name what may never be entered into a model and give an approved route for each case.
- 04
Assign human accountability
Make a named person accountable for every published output, mapped to existing approval stages.
- 05
Take a disclosure position
Decide when AI involvement is disclosed to clients, in credits, imagery, voice or likeness.
- 06
Set an owner and a review date
Name who maintains the policy and when it is next reviewed.
Governance is infrastructure, not paperwork. The policies that work are the ones encoded into the tools and templates people already use every day. See how I approach this in practice.
Common questions
- What should an AI policy for marketing contain?
- Approved tools, forbidden data, human sign-off and accountability, a disclosure position, and a named owner with a review date. One page is usually enough.
- Who owns the AI policy in a marketing organisation?
- Operationally it belongs with marketing operations, written together with legal and IT. If legal owns it alone, it tends to be written for the audit rather than for daily use.
- Do we have to tell clients we used AI?
- It depends on category, contract and market. Regulated and public-sector clients often require disclosure. Decide the position deliberately and write it down rather than handling it case by case.
Last updated:
