Write one or two pages that cover six things: which marketing jobs AI may do, what it must never produce (fake reviews, invented quotes, realistic images of real people without consent), how every draft gets checked and signed off, when you label AI content, what data may go into AI tools, and who owns and records the output.
Build it from how your team actually uses AI, not from a template. A general AI usage policy covers tools and data. A marketing policy also has to govern what gets published under your name, which is where AI's habits cause real trouble: confident statistics with no source, testimonials nobody gave, and images that look like real customers. Those are exactly the clauses generic templates leave vague.
List what marketing already asks AI to do
Spend an hour asking each person what they use AI for, how often, and in which tool. The answers are usually more varied than the owner expects, and they become the backbone of the policy. Here is the inventory for an illustrative six-person PR consultancy with 14 retained clients:
| Use | Volume | What goes wrong | Policy treatment |
|---|---|---|---|
| First drafts of press releases | About 6 a month | Invented figures or quotes reach journalists under a client's name | Allowed; quotes written or approved word for word by the speaker |
| Pitch emails to journalists | About 120 a month | Wrong name or beat, flattery about articles the journalist never wrote | Allowed; personal details checked against the journalist's recent work |
| Coverage report summaries | 14 a month | Reach or sentiment misreported | Allowed; every figure copied from the monitoring tool, not the summary |
| Captions for the agency's own social accounts | About 20 a month | Off-brand tone, unlabelled AI images | Allowed; labels follow platform rules |
| Images for pitch decks | About 15 a month | Realistic "people" read as real clients | Allowed internally; anything published follows the likeness rule |
| Spokesperson bios and award entries | About 4 a month | Inflated claims, out-of-date job titles | Allowed; every claim needs an entry in the evidence file |
| Voice-over for a client explainer video | Occasional | A voice used without its owner's consent | Only with written consent from the voice owner and the client |
| Crisis statements | Rare | Any error becomes the story | No AI drafting; a senior person writes from scratch |
Two things fall out of an inventory like this. First, the risk sits in a handful of uses, so the policy can be relaxed about pitch-email drafts and strict about quotes. Second, you find the uses nobody would have admitted to in a meeting, such as the account executive who pastes whole client strategy documents into a free chatbot account. Those shape the data section later.
If you don't yet have a general policy covering approved tools, accounts and data, write that first or at the same time; how to write an AI usage policy for your small business covers it. The marketing policy can then point to it rather than repeat it.
Red lines: what AI never produces under your name
Put the prohibitions near the top, in plain words, with the reason for each. People remember a short list of never-dos far better than a long list of shoulds.
- No fake reviews, ratings or testimonials. Consumer-protection rules in several major markets now ban fake reviews and testimonials outright, and at least one regulator's rule names AI-generated fake reviews explicitly. This covers "sample" testimonials that are meant to be replaced but never are.
- No words attributed to a real person unless they approved those exact words in writing. That includes client spokespeople, customers and your own staff.
- No realistic image, video or voice of an identifiable real person without their written consent. This includes "a customer who looks a bit like" someone real, and any competitor's staff or products.
- No statistic, survey finding or "research shows" without a source in the evidence file. AI produces convincing numbers on request, and journalists and regulators ask where they came from.
- No publishing anything a person hasn't read in full. Scheduled posts included.
- No AI drafting of crisis statements or replies to legal complaints. A senior person writes these, because tone and precision matter more than speed.
The second rule usually earns its place the hard way. Here is how it tends to happen. A junior account executive asks the AI for a launch press release, and the draft includes a warm quote from the client's founder: "We're thrilled to bring this to market and can't wait for customers to try it this spring." The junior assumes the client will rewrite the quote; the client skims the release and replies "fine". A trade title runs it word for word. The founder then emails, unhappy, because she never said it and "this spring" commits to a launch window the company hadn't announced. Nothing was invented maliciously, yet the agency now has a quote in print that its client disowns. After that, the policy says quotes are either written by the speaker or sent to them for approval as a separate item, never buried in a full draft.
Rewriting vague clauses into ones staff can follow
Most first-draft policies fail on wording, not intent. A clause works when someone halfway through a busy afternoon can tell, without asking, whether the thing in front of them is allowed. Seven common clauses, before and after:
- Before: "Staff should use AI responsibly." After: "You may use AI for the tasks listed in section 3, using only the business accounts in section 2. Anything else needs the managing director's written OK first."
- Before: "AI content must be checked." After: "Every AI-assisted piece is checked by someone other than the drafter, against the source documents, before sign-off. Figures, names, dates, prices and quotes are checked line by line."
- Before: "Disclose AI use where appropriate." After: "Label AI-generated or AI-altered images, video and audio wherever a platform requires it (table in section 7), and on any realistic depiction of people or events. Text drafted with AI help and edited by a person is not labelled unless a client or platform requires it."
- Before: "Don't put confidential data into AI." After: "Embargoed announcements, unreleased financial results and anything a client has marked confidential go only into our business AI workspaces, never into personal or free accounts, and never into image or voice tools."
- Before: "Respect copyright." After: "Pieces over 500 words get a plagiarism check before sign-off. Generated images are used only where the tool's terms allow commercial use, and each published one is recorded in the asset register with the tool and prompt."
- Before: "Follow client instructions on AI." After: "Where a client's contract restricts AI, the client's rule wins. The account lead records each client's AI permission in the client sheet as full, drafts only, or none, and every brief to a freelancer repeats it in the first line."
- Before: "Report any problems." After: "If AI-made content goes out with an error, a missing label or someone's likeness used without consent, tell the managing director the same day. Fix or remove it first, explain second, then log it."
Notice what the rewritten versions share: a named person, a named place, a threshold (500 words, same day) and an action. The second clause connects to your review process; if you haven't set one up, the draft, check and sign-off workflow for AI content gives you the stages and the check sheet to reference. The claims side, meaning what counts as evidence for "fastest" or "award-winning", is covered in how to back up every claim AI writes in your marketing.
Labelling rules your policy should point to
Your own disclosure choices are a matter of judgement, and there's a fuller discussion in whether to tell customers when you use AI in your marketing. Platform and legal labelling rules are not optional. The policy should list them in a table like this one, checked in September 2026, and name who keeps it current, because platforms revise these rules often.
| Where | What needs a label | How |
|---|---|---|
| Instagram and Facebook | Organic posts with photorealistic video or realistic-sounding audio that was digitally created or altered | Meta's AI disclosure option when posting; Meta may also add an "AI info" label itself |
| TikTok | AI-generated content showing realistic scenes or people | The AI-generated content setting when posting, or a clear caption or sticker |
| YouTube | Realistic altered or synthetic content: real people saying things they didn't, altered real events, realistic invented scenes | The "AI use" setting in YouTube Studio; not needed for AI-assisted scripts, titles, thumbnails or captions |
| Customers in the EU | Deepfakes and certain AI-generated content under Article 50 of the EU AI Act, which has applied since 2 August 2026 | A clear label; check the detail with an adviser if this applies to you |
| Google Merchant Center | AI-generated product images | Keep the IPTC TrainedAlgorithmicMedia metadata in the image file |
The practical detail that trips teams up is the last row and its cousins: editing software can strip metadata when an image is exported, so "we generated it with a tool that adds the tag" isn't the same as "the tag is still in the file we uploaded". For step-by-step labelling on each platform, see how to label AI-generated images and video on social media.
Embargoes, client secrets and what goes into a prompt
For a PR consultancy, the data section is where the policy protects the business most directly. An embargoed announcement pasted into a personal chatbot account is out of the agency's control, however unlikely it is to leak. Business plans such as ChatGPT Business, Claude Team and Gemini in Workspace don't train on business content by default; consumer plans rely on each user finding the model-training switch in privacy settings. That difference alone justifies a rule about accounts.
A traffic-light list, filled in for the consultancy, is easier to follow than a paragraph:
- Red, never in any AI tool: passwords and log-ins; material a client has marked "no AI"; advice from a client's lawyers; personal details beyond what the task needs, such as a journalist's home address or anyone's health information.
- Amber, business AI workspaces only: embargoed announcements; unreleased financial results; client strategy documents; journalist relationship notes.
- Green, any approved tool: published press releases; public coverage; the agency's own website copy; anonymised examples with client names removed.
Add one line for image and voice tools specifically: nothing amber goes into them. Those tools often run on different terms from the chat workspace, and a product photo from an unannounced launch uploaded to "just test a background" is an embargo breach waiting to happen.
Who owns an AI-made asset, and the register that proves it
Ownership is less settled than most teams assume. OpenAI's and Anthropic's terms assign you whatever rights they have in the outputs, "if any", which is a careful phrase. At least one national copyright office said in January 2025 that prompts alone are unlikely to make an output protectable, while human selection, arrangement and editing can be. Adobe Firefly's own models are trained on licensed content, but partner models offered inside the Firefly app aren't covered by that, and its IP indemnity is for enterprise customers only. The rules differ between jurisdictions, so if a client needs to own a logo or a campaign image outright, that's a question for a lawyer, and the policy should say so.
What the policy can guarantee is a record. An asset register takes about 30 seconds per item and answers the questions a client, a platform or a lawyer might later ask. Four entries from the consultancy's September register:
ID Date Client Asset Tool Human input Label Rights / consent
IMG-0412 14 Sep software client launch post header, abstract image generator cropped, recoloured not needed tool terms allow
shapes, no people (business plan) (not real) commercial use
VO-0031 18 Sep food brand 60-second explainer AI voice tool script written by noted in voice actor's written
voice-over a person description consent on file
TXT-1187 22 Sep own LinkedIn post on media ChatGPT Business about 40% rewritten none (text) n/a
relations trends
IMG-0419 25 Sep food brand recipe photo, realistic image generator food styling notes AI label on client approved;
dish, no people from the client Instagram no real product shown
The "consent on file" column only protects you if the consent says what you're actually doing. A voice actor who agreed to "an explainer video" hasn't agreed to a synthetic copy of their voice reading next year's scripts. Consent wording for a cloned voice, filled in for the explainer above, looks something like this (have a lawyer look over your version before you rely on it):
CONSENT TO A SYNTHETIC VERSION OF MY VOICE
I, [first name] [surname], agree that [agency] may create a synthetic
version of my voice from the recordings made on 12 September 2026 and
use it only for: one 60-second product explainer for [client], in
English, on the client's website, YouTube channel and event screens,
until 30 September 2027.
It will not be used for any other script, any other client, or any
political, medical or financial claim.
I may withdraw consent for future uses in writing at any time;
material published before withdrawal may stay online.
Fee: as agreed on invoice 0931.
Signed: Date:
The scope line does the work: one script, one client, named channels, an end date. The same pattern works for a photographed customer whose face appears in an AI-edited image.
Keep the prompt with each register entry. It costs nothing and settles most "where did this come from" questions in a minute. For long-form text, the policy's plagiarism check belongs here too; how to check AI content for plagiarism before you publish covers which checker to use and what it can't see.
The whole policy on one page, filled in for a PR consultancy
AI CONTENT POLICY: MARKETING AND CLIENT WORK Version 1.2, September 2026
Owner: managing director. Applies to staff, freelancers and anyone
producing content for us or our clients.
1 PURPOSE AI helps us draft faster. Every word and image we publish
is still ours, checked by a person, and true.
2 APPROVED ACCOUNTS ChatGPT Business and Claude Team workspaces; our
image generator's business plan; our AI voice tool, consent cases
only. No personal or free accounts for client work.
3 ALLOWED USES First drafts of releases, pitches, bios, captions and
reports; summaries of public coverage; brainstorming; images for
internal decks.
4 NEVER Fake reviews or testimonials. Quotes a person hasn't approved
word for word. Realistic likeness or voice of a real person without
written consent. Unsourced statistics. Crisis statements. Publishing
anything a person hasn't read in full.
5 FACTS AND CLAIMS Every figure, date, name and claim is checked
against a source in the client's evidence file. No source, no claim.
6 REVIEW Drafter, then a different checker, then sign-off. Client
sign-off names the version. Quotes go to the speaker separately.
7 LABELS Follow the platform table (maintained by the social lead).
Label realistic AI images, video and audio. Text edited by a person
is not labelled unless a client or platform asks.
8 DATA Red: never in AI. Amber: business workspaces only. Green: any
approved tool. Nothing amber in image or voice tools.
9 RECORDS Log every published AI image, video and audio asset in the
register with tool, prompt, edits, label and consent. Plagiarism
check on anything over 500 words.
10 INCIDENTS Error, missing label or consent problem: fix or remove,
tell the managing director the same day, log it.
Review: every six months, or sooner if a trigger in the appendix fires.
Signed by each team member on joining and after each revision.
That fits on one printed page at a normal font size, which matters: a policy people can read in three minutes gets read. Anything longer, such as the platform table or the red, amber and green examples, goes in an appendix that the one page points to.
When to reopen the policy
A marketing AI policy dates quickly because the tools and platforms under it keep changing. Rather than waiting for the six-month review, reopen it when one of these happens:
- A tool on your approved list changes or retires. OpenAI will switch off custom GPTs on 11 December 2026, and Google plans to convert Gemini Gems into "skills" (personal accounts first, from November 2026; Workspace business accounts from March 2027). A policy that names either as the place where brand instructions live needs updating.
- A platform changes its labelling rules. The social lead checks the table monthly; a change means a new version number and a one-line note to the team.
- A new rule takes effect where you sell. For example, if you sell to customers in the EU, generic environmental claims such as "green" or "eco-friendly" have been banned since 27 September 2026 unless you can prove recognised excellent environmental performance. That belongs in section 5.
- An incident. Every incident should end with one of three outcomes: the policy was right and wasn't followed, the policy was unclear, or the policy was missing something.
- A new kind of use. The first time someone wants an AI video presenter or a cloned voice, the policy gets a clause before the work starts, not after.
As for effort, the consultancy in this illustration spent about four hours on the first version: an hour on the inventory, thirty minutes on the red lines, two hours on wording and the tables, and thirty minutes checking it with its two most frequent freelancers. A 45-minute walkthrough with all six staff added four and a half person-hours. Upkeep is the register, about 30 minutes a month at 60 assets, plus a short review twice a year. Against the cost of one disowned quote in a trade title, that is a small bill.
Further reads
- How to Roll Out an AI Policy So Staff Actually Follow It — Get staff and freelancers to follow the policy once it's written.
- AI Clauses for Agency Contracts: Disclosure, Ownership, Approvals — Match the policy to what your client contracts promise.
- How to Write an AI Disclosure Statement for Your Website — Turn the disclosure section into a public statement.
- Brand Guidelines for AI Images: Colours, Style and Limits — Add image-specific brand rules alongside the policy.
- What to Check in an AI Tool's Privacy Policy and Terms — Check each approved tool's data terms before listing it.
- AI Error Log: Track Mistakes and Stop Them Happening Again — Log incidents the policy asks staff to report.
- Using AI in a Yoga or Pilates Studio While Keeping Your Voice — Why AI makes every studio sound the same, and the voice sheet, before-and-after edits and teacher-bio method that keep yours recognisably yours.
- AI Content Workflow for Agencies: From Brief to Approved Draft — Six gates from client brief to approved draft, with the AI's job and the human's job at each, plus a filled-in brief, outline prompt and claims log.
- AI Marketing for Small Law Firms: Content, Reviews and the Rules — How a small law firm can use AI for guides, posts and review replies while staying inside platform, consumer-law and professional conduct rules.
- AI Listing Mistakes That Can Mislead Buyers, and How to Check — Check room counts, measurements, parking rights and altered photographs against evidence before publishing an AI-written property listing.
- 12 AI Marketing Mistakes Small Businesses Make (and the Fixes) — Twelve ways AI marketing goes wrong in small businesses, how each one shows up, and the specific fix and check that stops it happening again.
- Should You Use an AI Avatar as Your Business Spokesperson? — Stock avatar, digital twin or you on camera: a scorecard, real tool prices, consent wording for staff, and a low-risk way to trial an AI presenter.
- Can You Use AI to Write Testimonials? Where the Legal Line Is — Where the legal line sits for AI and testimonials: an allowed-grey-never table, what the rules prohibit, an approved-edit workflow and a consent email.
- Which Marketing Tasks Should a Small Business Never Hand to AI? — Fourteen marketing tasks where AI may draft but must never decide or publish, each with a real-looking failure, plus a sign-off policy you can copy.
- Do You Own the AI-Generated Content Your Business Publishes? — What AI vendors' terms really hand you, why copyright can still be thin, and the edits, checks and contract wording that make published AI content safer.
- How to Write a House Style Guide Your Team and AI Both Follow — Turn house style into testable rules with examples, keep a short AI version in a shared project, and prove it works on real drafts.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Meta newsroom and transparency pages (AI labelling of photorealistic video and realistic audio); TikTok support pages (AI-generated content labels); YouTube Help (disclosing altered or synthetic content); consumer-protection rules on fake reviews and testimonials; national copyright office guidance on AI outputs (January 2025); vendor terms summarised in our verified fact sheet.