Governance, Disclosure and UK Compliance for AI Content Marketing
Most content teams write their AI policy after the incident. A freelancer submits a case study with a quote nobody can trace to a real customer. Someone pastes a client’s unreleased pricing deck into a free chatbot. A location page rollout of 340 near-identical pages gets deindexed in a week. Then the policy gets written, in a panic, by whoever is least busy.
An ai content policy for marketing is not a compliance artefact you file and forget. It is an operating document that tells a four-person team which tools they may use for which jobs, what has to be checked before publication, what gets disclosed to whom, and what evidence you keep so that a question in eighteen months has an answer. Done well it takes about 1,200 words and makes people faster, because nobody has to stop and wonder whether pasting a transcript into Claude is allowed.
This page covers the decisions the policy has to make, the five UK regimes that actually create liability, what your vendor contracts really say, and how to run the whole thing on roughly two hours a quarter.
The seven decisions a policy has to make
Vague policies fail because they describe values instead of resolving choices. “Use AI responsibly and always check the output” gives a new starter nothing. Your policy needs to settle these seven questions in writing, with names attached:
- Which tools are approved, at which subscription tier. Not “ChatGPT” but “ChatGPT Team, company SSO only. The free and Plus tiers are not approved for any client or customer data.”
- What data may go in. Published material, yes. Internal strategy documents, named customer data, unreleased financials, anything under NDA: no, unless the tool is on the approved list for that data class.
- Where AI may sit in the workflow. Research and outlining are different risk categories from generating body copy, which is different again from generating quotes, statistics or imagery of people.
- Who signs off. A named human accountable for factual accuracy per asset, logged.
- What gets disclosed, where, in what words. See the disclosure section below.
- What gets recorded and for how long. Prompt, tool, version, date, reviewer, and source verification, retained at minimum for the life of the campaign plus two years.
- What happens when someone breaches it. Including the bit people skip: what you do publicly if something wrong has already shipped.
Write each as a rule with an exception path, not a principle. “No AI-generated imagery depicting people in customer-facing assets. Exception: abstract or illustrative figures with no implied identity, approved by [name].”
A four-tier risk model that survives contact with deadlines
Blanket rules break because the risk of using Claude to compress a 40-minute interview transcript is nothing like the risk of letting it write a compliance claim. Tier the work instead. This is the model I would give a five-person team publishing 30 to 45 assets a month:
| Tier | What it covers | Approved tools | Gate before publish |
|---|---|---|---|
| T1 Assist | Transcription, summarising your own published content, reformatting, alt text drafts, subject-line variants, brief-to-outline | ChatGPT Team, Claude Team, Descript, Notion AI | Normal editorial review |
| T2 Draft | First drafts of body copy, meta descriptions, social variants, email sequences from an approved brief | Same, plus Jasper or Writer if licensed | Named editor, fact-check on every claim, plagiarism scan |
| T3 Generate | Statistics, comparisons, competitor claims, anything about pricing or regulated products, imagery, synthetic voice | Restricted list, senior sign-off required | Second reviewer, source verification logged, disclosure check, legal referral if regulated |
| T4 Prohibited | Fabricated quotes, testimonials, reviews, case-study outcomes; AI likenesses of real people; anything trained on a client’s confidential corpus without written permission | None | N/A |
Tier the asset, not the tool. The same model in the same account is T1 when it summarises your own webinar and T3 when it drafts a comparison table against a named competitor.
Put the tier in your project tracker as a required field. In Asana or ClickUp that is a single-select custom field with four options, and it takes ten seconds per brief. The payoff is that “which things need a second reviewer this month” becomes a filter rather than an argument.
The five UK regimes that actually create liability
There is no UK AI Act. What exists is a set of pre-existing regimes that apply to AI-assisted content exactly as they apply to everything else, plus one recent statute that has already bitten marketers.
UK GDPR, as amended by the Data (Use and Access) Act 2025. The moment you put personal data into a third-party model you are processing it, and you need a lawful basis, a record in your Article 30 documentation, and a processor relationship that actually exists in a contract. A concrete trigger: a team wanting to mine 2,300 Zendesk tickets for content themes. Those tickets contain names, email addresses, sometimes health or financial detail. That is new processing for a purpose customers were not told about, at scale, using a technology they would not expect. It meets the Article 35 test for a Data Protection Impact Assessment on at least two counts. A DPIA here is a genuine four-page document, not a checkbox, and the cheaper answer is usually to have a human pull 60 anonymised examples instead. ICO enforcement runs to £17.5m or 4% of global turnover, and while a content team is not the likely target, the reputational cost of a self-reported breach is real and immediate.
The Digital Markets, Competition and Consumers Act 2024. The unfair commercial practices provisions came into force on 6 April 2025, and this is the one most content teams underestimate. Submitting or commissioning fake reviews is now a banned practice, and businesses that publish consumer reviews must take reasonable and proportionate steps to prevent fake ones appearing. The CMA can enforce directly, with penalties up to 10% of global turnover. Now think about what “AI-assisted testimonial” means. If you take three real customer emails and have GPT synthesise them into one polished quote attributed to a named person, you have created a review that person did not write. Even with their sign-off, the paper trail matters. The safe pattern: the customer’s own words, lightly edited for length, with the edited version approved in writing by them, and that approval email retained. AI can draft the interview questions. It cannot draft the answers.
The CAP Code. Every claim in an ad needs substantiation held before publication, and misleadingness is judged on overall impression rather than literal truth. AI models produce claims that sound substantiated. “Trusted by over 500 UK firms” will appear in a draft because it is the shape of a sentence that belongs there, not because the model counted. Treat every number, superlative and comparative in an AI draft as unsourced until someone has attached a link to internal data. The testimonials and endorsement rules (3.45 onwards) require testimonials to be genuine, documented and held on file, which is the same discipline the DMCC now enforces with money behind it.
Copyright. The UK text and data mining exception in s.29A CDPA covers non-commercial research only, which means commercial AI training on copyright works sits in genuinely unsettled territory here. The Getty Images v Stability AI judgment in November 2025 narrowed rather than resolved things: Getty dropped its core training claims mid-trial over evidential difficulties about where training took place, and the court declined to treat model weights as an infringing copy. For a content marketer the practical takeaway is not case law, it is contract. Your protection comes from vendor indemnities, and from never asking a model to reproduce a specific named source.
Sector rules, if they apply to you. Financial promotions under the FCA regime (FG24/1 on social media is the relevant finalised guidance) require sign-off by an approved person and a record of it. Pharma has the ABPI Code. Legal services have SRA transparency rules. If your clients sit in any of these, your policy needs a named external reviewer and a hard prohibition on publishing AI-drafted regulated copy without it.
One more to watch if you sell into the EU: the AI Act’s Article 50 transparency duties cover synthetic content and were scheduled for 2 August 2026, although the Commission’s digital omnibus proposals put parts of the timetable back in play. Confirm the current position before you build workflow around a date. If you publish into EU markets, machine-readable marking of synthetic images and audio is the direction of travel regardless.
What your vendor contracts actually say
People assume “enterprise” means “safe” and free means “everything is training data.” Both assumptions are wrong in specific ways that matter.
ChatGPT Team and Enterprise do not train on your business data by default, and Enterprise plus the API carry OpenAI’s Copyright Shield indemnity. ChatGPT Plus is a consumer product with a training toggle a user can flip. If half your team is on personal Plus accounts, you have no contractual position at all and no audit trail. Anthropic’s commercial terms similarly exclude training on customer content and include indemnity for paid commercial use. Microsoft 365 Copilot carries Commercial Data Protection and the Copilot Copyright Commitment, though that commitment is conditional on leaving the built-in guardrails enabled. Adobe Firefly’s enterprise tier offers IP indemnification and is trained on Adobe Stock and licensed content, which is why it is the defensible choice for commercial imagery over Midjourney, whose terms put the risk on you.
Three things to check before adding any tool to the approved list, in this order:
- Training on input. Off by default, or off by setting someone has to remember? Screenshot the setting and date the screenshot.
- Retention. OpenAI’s API defaults to 30 days for abuse monitoring, with zero-data-retention available on request for eligible endpoints. Know your number.
- Indemnity scope. Output only, or training data too? Conditional on what?
Keep this as a five-column table in the policy appendix and review it quarterly, because vendors change terms and your policy is only as accurate as its last read.
Disclosure: required, useful, and counterproductive
Disclosure is where teams overcorrect hardest. There is no general UK requirement to label AI-assisted marketing copy, and a blanket “this article was written with AI” banner on every blog post buys you nothing while quietly telling readers the content is low-effort.
Disclosure is genuinely required or near-required in a narrower set of cases: synthetic imagery or video that a reasonable person would take as a real photograph of a real event or person; synthetic voice; AI-generated content presented as a person’s own words or opinion; anywhere a platform’s own terms demand a label (Meta, TikTok, YouTube all require declaring realistic synthetic media). It is also required by client contract more often than people realise, and increasingly appears in RFPs as a direct question.
Disclosure is useful, without being mandatory, where it builds trust cheaply: a one-line note in an editorial standards page explaining that AI assists with research and drafting while every piece is edited and fact-checked by a named human. That sentence answers the question once, at the right altitude, instead of on 400 individual pages. For wording you can lift and adapt, including versions for bylined articles, client SOWs, image credits and about-pages, see AI Disclosure Statement Examples for UK Marketing Teams.
Where disclosure hurts: per-asset labels on routine copy, and anything that reads as a liability disclaimer rather than an editorial standard. “Content may contain errors” is not a disclosure, it is an admission that your review process does not work.
A note on detection, since it comes up in every procurement conversation: AI text detectors are not reliable enough to be a governance control. OpenAI withdrew its own classifier in July 2023, having measured a 26% true-positive rate on AI-written text alongside a 9% false-positive rate on human writing. Third-party tools have improved but still misfire, particularly on non-native English. Do not build a freelancer policy around detector scores. Build it around contractual declaration and source verification, which are testable.
Provenance and the record you will wish you kept
The audit question, when it arrives, is specific: “where did this statistic come from, who checked it, and when?” Answer it with a log, not a memory.
Ten fields, one row per published asset, in whatever you already use:
asset URL, tier (T1 to T3), primary tool and version, date generated, prompt or prompt template reference, human editor, fact-check completed (y/n) with date, sources verified (links), disclosure applied (which statement), client approval reference.
That is a 90-second entry per asset. For a team shipping 40 a month it is an hour of admin for a permanent defensible record. If you want the technical version as well, C2PA Content Credentials are embedded by default in Firefly and Photoshop exports and survive into IPTC metadata, which gives you provenance on imagery without any extra process.
Retention: campaign life plus two years as a floor, six years if the content supports a contractual claim, and align with whatever your DPIA says for anything containing personal data.
Search, scaled content, and the line Google actually polices
Google’s position has been consistent since early 2023 and it is not the one most people quote. AI-generated content is not penalised for being AI-generated. What is penalised is scaled content abuse, added to the spam policies in March 2024: producing content at scale primarily to manipulate rankings rather than help people, whether by automation, humans, or both.
The practical test is whether a page would exist if search did not. A 340-page “AI content agency in [town]” rollout where the only variable is the town name fails that test regardless of who wrote it. A 40-page comparison library where each page contains original testing, pricing you verified this month, and a genuine recommendation passes it whether or not a model drafted the prose.
Put a numeric guardrail in the policy so this is not a judgement call under deadline pressure. Something like: any programmatic or templated set above 20 pages requires a documented differentiation plan naming the unique data, original media or first-hand testing in each page, signed off before the first page ships.
Freelancers, agencies and the contract clause you are missing
In-house teams govern their own staff and then hand 40% of production to people covered by nothing. Fix that with four lines in the SOW, not a separate policy:
- Contractor must declare AI use by tier and tool for each deliverable.
- Contractor warrants all quotes, statistics and case-study details are verifiable and will supply sources on request.
- Contractor may not input client confidential material into any tool not on the approved list.
- Contractor warrants delivered work does not infringe third-party rights, and assigns or licenses copyright in the deliverable.
That last one has a wrinkle worth knowing. Under UK law, purely machine-generated text with no human author may not attract copyright protection at all, which means there may be nothing to assign. This matters when a client wants exclusivity over a piece of copy. The practical response is substantive human authorship, documented, and a contract that assigns whatever rights do exist.
Agency side, the mirror obligation: know what your clients’ own policies say before you deliver. Several large UK brands now include AI-use declarations in supplier onboarding, and answering “we don’t have a policy” loses work.
Running it without hiring a compliance manager
A governance process nobody follows is worse than none, because it creates documented evidence of a standard you breached. Keep it to four recurring commitments:
Per asset: tier field set at brief stage, log row completed at publish. Roughly two minutes.
Per month: spot-check five published assets against the log. Pull every numeric claim and re-verify one at random. Budget 30 minutes. Expect to find something in the first two months, and to find nothing by month five, which is the signal the process has taken.
Per quarter: re-read the vendor terms table, re-screenshot the training toggles, update tool versions, review any incidents. Ninety minutes.
Per year: full policy review with whoever owns data protection, plus a refresh of the approved tool list against what people are actually using. Which, in my experience, is never quite what the list says.
One budgeting figure to hold on to when the tiers get argued about: a 1,400-word T2 draft that a model produced in 90 seconds needs 45 to 70 minutes of editor time to reach publishable standard, and most of that is fact-checking rather than prose. Teams that plan for 15 minutes are the teams that ship the unsourced statistic.
The failure modes I see most often
Policy written for engineers, not writers. If it opens with a definition of a large language model, nobody on the content team will read past the second paragraph. Start with the tier table.
Approved-tool lists that are already wrong. Someone is using Perplexity for competitor research and Gemini for spreadsheet work because both are genuinely good at those jobs. A list that pretends otherwise just moves the activity out of view. Run an amnesty: ask everyone to name what they actually use, then assess it.
Disclosure as theatre. Six variations of an AI notice across a site, none of them written by anyone who thought about the reader, is a worse outcome than one clear editorial standards statement. Pick a wording, put it in one place, reference it from everywhere else. The examples collection is there precisely so this takes an afternoon rather than a fortnight.
Treating the log as optional. The log is the only part of this that changes what happens when something goes wrong. Everything else is prevention; this is the evidence.
Here is the test I would apply to the document you end up with. Hand it to the newest person on your team with a real brief: a comparison page for a financial services client, quotes needed from two customers, hero image required, deadline Thursday. If they can work out the tier, the approved tools, who signs off, what gets disclosed and what they have to log, without asking you a single question, the policy is doing its job. If they come back with three questions, those three questions are your next edit.
In this section
The supporting pages under this subject.