Why marketing needs its own rules
Many organisations have a company-wide AI policy written by IT or legal. It usually covers security and data well, and says little about what marketers actually do: write public claims, generate images of people, run chatbots, handle customer lists and brief agencies.
A marketing AI policy fills that gap. It sits beneath the company policy and translates it into marketing decisions. Without it, each person makes their own rules, and the most cautious and the least cautious both slow the team down in different ways.
A good policy makes the safe path the fast path.
What the policy should cover
- Purpose and scope. Who it applies to, including agencies and freelancers.
- Approved tools. Which tools are allowed, under which account types, and how to request a new one.
- Data rules. What categories of data may go into which tools.
- Use rules. Which tasks AI may do, assist with or must not touch.
- Review and approval. Who checks what before publication.
- Disclosure. When and how AI use is disclosed to customers or platforms.
- Rights and likeness. Rules on images, voices and people.
- Incidents. How to report and respond to mistakes.
- Ownership and review. Who maintains the policy and how often it is updated.
Keep it short. Two to four pages that people read beat twenty pages that nobody opens. Put detail in appendices: the approved tools list, the approval matrix and the review checklist.
How to write it, step by step
Fig. 01 · Process
Tap to explore
Writing a marketing AI policy
Step 1: inventory current use
Ask everyone, including agencies, which AI tools they use and for what. Make it explicit that this is not a disciplinary exercise. You cannot govern what you cannot see, and people hide use when they expect punishment.
Step 2: classify data
Four simple classes work for most teams. Public: already published material. Internal: plans, drafts, non-sensitive performance data. Confidential: unreleased launches, pricing strategy, client or partner information. Personal: anything identifying a customer, lead or employee. Personal data deserves the strictest rules, and in India the DPDP Act sets obligations on its use. See DPDP Act for marketers.
Step 3: set the approval matrix
Combine how sensitive the input is with how public the output will be. The matrix below gives a starting point that most teams can adapt in an afternoon.
Fig. 02 · Matrix
Tap to explore
The AI approval matrix
Step 4: draft rules and roles
Write rules as plain instructions with examples. 'Do not paste customer names, emails or phone numbers into any AI tool not on the approved list' is clearer than 'ensure appropriate data handling'. Name roles: a policy owner, tool approvers, data owners and reviewers.
Step 5: test with real tasks
Before publishing, run a week of genuine work through the draft. Where people get stuck or the rule is ambiguous, rewrite it. This step catches most of the problems that would otherwise surface as quiet non-compliance.
Rules that work in practice
Compare scenarios
Example rules by area
Rules about inputs should be the strictest part of the policy, because data mistakes are the hardest to undo.
- Personal data only in tools approved for it, for purposes customers were told about
- No confidential plans in consumer accounts of any tool
- Use anonymised or sample data for experiments
- Check the tool's training and retention settings before first use
Rules about outputs focus on what reaches customers.
- Every factual claim checked against a source by a person
- Only approved claims in ads and product copy
- Brand voice guide supplied for public-facing drafts
- A named reviewer approves every public AI-assisted piece
Rules on likeness and rights protect both the brand and real people.
- No generated images resembling real people without consent
- No prompting in the style of named living artists or other brands
- Real photography for products
- Log tool, prompt and approver for published images
Disclosure rules should follow law, platform policy and your own values.
- Chatbots state they are automated
- Follow platform labelling rules for synthetic media
- Disclose AI use where a reasonable customer would expect to know
- Check current rules per market and platform
Vendor and tool approval
New AI tools appear weekly, and each one is a possible data route out of your organisation. A light approval process, answered in days rather than months, keeps people from using unapproved tools out of impatience.
Checklist
0/8Questions before approving an AI tool
Making the policy stick
Policies fail through friction, not defiance. If the approved route is slower than the unapproved one, people take the shortcut. Make approved tools easy to access, keep the review checklist short and answer tool requests quickly.
- Walk the team through the policy in a short session with real examples.
- Put the approval matrix and checklist where people work, not in a shared drive folder.
- Include the policy in agency and freelancer briefs and contracts.
- Treat early mistakes as learning, and fix the process before blaming people.
- Celebrate good practice, such as a reviewer catching an invented claim.
Review and update
Review the policy quarterly and after any incident. Tools change their terms and capabilities, regulations evolve, and your team's use matures. Each review should ask: what has changed in tools, in law, in our use, and in our incidents? Update the appendices often and the principles rarely.
For the risks the policy guards against see AI and brand safety, and for the values behind it see AI ethics in marketing. For the plan the policy supports, see AI marketing strategy.
Key takeaways
- 01A marketing AI policy translates company-wide rules into decisions about claims, images, chatbots, customer data and agencies.
- 02Classify data and combine sensitivity with output exposure in a simple approval matrix.
- 03Write rules as plain instructions with examples, and test them on a week of real work before publishing.
- 04Approve tools quickly with a short checklist so people are not tempted by unapproved shortcuts.
- 05Review quarterly and after incidents, updating appendices often and principles rarely.
Frequently asked
- What is an AI governance policy for marketing?
- It is a short document that sets how a marketing team uses AI: approved tools, which data may go into them, which tasks AI may do or assist with, who reviews output, when to disclose AI use, rules on images and likeness, and how incidents are handled. It sits beneath any company-wide AI policy.
- What should a marketing AI policy include?
- Scope, approved tools, data classification rules, an approval matrix, use rules by task, review and approval responsibilities, disclosure requirements, rules on rights and likeness, incident reporting, ownership and a review schedule. Keep the main policy brief and place detailed lists in appendices.
- How long should an AI policy be?
- Short enough that people read it, typically two to four pages for the main policy. Put the approved tools list, approval matrix and review checklist in appendices that can be updated frequently without rewriting the principles.
- Does an AI policy need to cover agencies?
- Yes. Your brand carries the risk regardless of who used the tool. Include AI rules in briefs and contracts, covering approved tools, data sharing, disclosure of material AI use and review before publication. Ask partners to tell you when AI was used significantly in a deliverable.
- How often should an AI policy be updated?
- Review it at least quarterly and after any incident. AI tools change terms and features frequently, and laws such as data protection and advertising rules evolve. Appendices such as the approved tools list may change monthly while core principles stay stable.
Published by Fabulous.Media, a network of specialist marketing agencies. Updated 9 October 2026. Platform features change often; check current official documentation before acting on platform-specific detail.





