← All guides
Business · Leadership ·ChatGPT, Claude

Set an AI Policy for Your Team (Brand-Safe and Data-Safe) in One Page

A usable team AI policy fits on one page and comes down to five rules: AI drafts, humans approve, no sensitive data, approved tools only, a human owns every output. Here is the whole thing, and how to write yours this afternoon.

Most teams are already using AI. The only question is whether they are doing it with rules or without them. If you have not written anything down, the answer is without, and that is where brand and data problems come from.

Here is the fix. A team AI policy that fits on one page, in plain language, that people will actually follow. It comes down to five rules. I run AI across a real marketing team, I wrote these rules for that team, and I am going to hand them to you.

One note before we start. This is educational, not legal advice. It is how a marketing leader sets working rules for a team. When you are ready to make it official company-wide, loop in legal and IT. But you can write the working version yourself, today.

Why one page, and why now

A policy nobody reads is not a policy. It is a liability with a title on it.

The mistake most leaders make is reaching for a long document full of legal language, or reaching for nothing at all. Both fail the same way. People use AI anyway, and they guess at the rules. Some guess well. Some paste a customer list into a chatbot to “clean it up.” You do not want the second kind guessing.

So the rules have to be short enough to hold in your head while you work. Five of them. One page. That is the whole idea.

The Five Rules

This is the framework. I call it the Five Rules, and it is the entire policy. Not five sections. Five sentences you could tape to a monitor.

  1. AI drafts. Humans approve and publish. Nothing AI makes goes out without a person reviewing it first. AI gives you a starting point, never a finished product.
  2. Never paste sensitive data. No customer records, no employee information, no financial specifics, no anything you would not want on the front page. When in doubt, it is sensitive.
  3. Approved tools only. Use the AI tools the team has vetted. Not a random new app someone found this morning. Approved tools are approved for a reason.
  4. A human owns every output. Every piece of work has a name attached. If it ships, a person is responsible for it, not the tool.
  5. When unsure, leave it out. If you are not sure a fact is right, a claim is safe, or a detail is yours to share, cut it. Certainty ships. Doubt waits.

That is the policy. Everything else is explanation.

What each rule looks like in practice

Rules stay abstract until you show them working. Here is the same five, filled in.

The ruleWhy it mattersWhat it looks like in practice
AI drafts, humans approveAI is confident even when it is wrong. A human is your last line of defense.The AI writes the first pass of a blog post. An editor reads every line before it publishes.
Never paste sensitive dataOnce data leaves your walls, you cannot pull it back. This is the rule that protects you.You want to analyze customer feedback? Strip names and account numbers first. Paste the anonymized version.
Approved tools onlyVetted tools have terms you have read. Random apps have terms you have not.The team uses the two AI tools leadership signed off on. A shiny new one goes through review before anyone touches real work with it.
A human owns every output”The AI did it” is not an answer anyone will accept. Ownership keeps quality high.Every campaign, report, and post has one named person accountable, whether AI helped or not.
When unsure, leave it outMost brand and accuracy misses come from shipping a thing you were not sure about.The AI drafts a stat you cannot verify. You cut the stat, not ship it and hope.

Copy-paste: the one-page policy

Here is the actual document, ready to adapt. Change the tool names to yours and send it to your team.

OUR TEAM AI POLICY (one page)

We use AI to work faster and better. Here are the five rules that
keep us brand-safe and data-safe while we do.

1. AI drafts. Humans approve and publish.
   AI gives us a starting point. A person reviews everything before
   it goes out. No exceptions for external work.

2. Never paste sensitive data.
   No customer records, employee information, or financial specifics
   into any AI tool. Anonymize first. When in doubt, it is sensitive.

3. Approved tools only.
   Use [Tool A] and [Tool B]. New tools go through review before we
   use them on real work.

4. A human owns every output.
   Every piece of work has one named person responsible for it.
   "The AI made it" is never the answer.

5. When unsure, leave it out.
   Not sure a fact is right or a detail is ours to share? Cut it.
   Certainty ships. Doubt waits.

Questions about a specific situation? Ask before you act.
This is how we keep moving fast without breaking trust.

That is it. No legal language. Nothing a coordinator on their first week could not follow.

Common mistakes

These are the traps I watched leaders fall into, in the order they usually fall into them.

  1. Banning AI entirely. This feels safe and does the opposite. People do not stop. They move to personal accounts on their phones, where you have no visibility and no guardrails. A ban drives AI into the shadows. That is the least safe outcome there is.
  2. No policy at all. The default state for most teams. Everyone invents their own rules, and the person with the worst judgment sets your actual risk level. Silence is not neutral here. It is a decision to let people guess.
  3. A policy too long to read. Twelve pages of legal language is the same as no policy, because nobody finishes it. If your team cannot recite the gist, you wrote it for a compliance file, not for humans.
  4. No data rule. Some policies cover tone and quality and forget the one rule that actually protects you. Data is the thing you cannot take back. It comes first, not last.
  5. No named owner. Without rule four, “the AI did it” becomes a real excuse people use. Ownership is what keeps standards high when the drafting gets easy. Name a human on everything.

How this connects to the rest of your rollout

A policy is the guardrail. It is not the whole plan. It pairs with how you actually get AI into the team’s hands and which tools you put there.

If you are building AI into how your team works, this is the safety layer on top of the system. I wrote about the system itself in how I built a 35-agent AI marketing workforce, and the policy is what keeps that workforce from creating risk instead of removing it.

The data rule leans hard on tool choice, because approved tools are only as safe as their terms. If you have not decided which tools your team is allowed to use yet, start with which AI tool marketers should actually use. And before you write rules for a task, it helps to know which tasks AI should touch at all, which is exactly what an AI marketing audit sorts out.

Your next step

Block thirty minutes this afternoon. Copy the one-page policy above, swap in your tool names, and send it to your team with one line: “This is how we use AI here, so we can all do it out in the open.” That is a real policy shipped in half an hour.

Want the version I actually use, with the notes on how to introduce it so it lands as permission and not a crackdown? My one-page team AI policy template is the upgrade on this guide. Grab it, adapt it, and you are done by end of day.

Common questions

How long should a team AI policy be?

One page. If it does not fit on a page, nobody reads it, and a policy nobody reads is not a policy. Five plain rules beat five pages of legal language every time. The goal is a document your team can actually hold in their head while they work.

Should I just ban AI to be safe?

No. Banning AI does not stop people from using it. It just pushes them to their personal accounts on their phones, where you have zero visibility and zero guardrails. A clear yes with rules is far safer than a no everyone quietly ignores.

What is the single most important rule?

Never paste sensitive customer, employee, or financial data into an AI tool. That is the one that protects you. Everything else is about quality and ownership. The data rule is about trust, and trust is the thing you cannot get back once you lose it.

Who owns what the AI produces?

A named human owns every output, always. AI drafts, a person approves and publishes. If something goes out wrong, the answer to who is responsible is never the tool. It is the person whose name is on the work. That single line prevents most of the trouble.

Do I need legal to write this?

You can write a usable working policy yourself this afternoon. It sets how your team operates day to day. When you are ready to make it official across the company, loop in legal and IT to pressure-test it. Start simple, then formalize.

What if my team is already using AI without any rules?

Then you need this more, not less. Do not open with a crackdown. Open by naming the five rules as the safe way to keep doing what they are already doing. You are not taking the tool away. You are making it safe to use out in the open.

The Newsletter

One practical AI idea, every week.

Real ways I use AI at work and at home. No hype, no jargon, no tech background needed. Coming soon for subscribers: the free course, 5 Days to Actually Using AI.

Free forever. Unsubscribe anytime.