Write a One-Page AI Usage Policy Before You Scale Any Tool
Six months ago a mid-sized UK financial services firm asked their content lead to audit AI usage across the marketing function. She expected to find ChatGPT. She found ChatGPT (three separate accounts, two personal), Jasper on a lapsed trial that had rolled to a £468 annual plan, Claude via a browser extension nobody could name the publisher of, Descript for podcast edits, two Notion AI seats, Grammarly’s generative features switched on across eleven users, and a freelance designer running client brand guidelines through Midjourney to generate “inspiration” moodboards.
Eleven tools. Four of them processing customer case study material. None of them with a named owner. The unpicking took until March.
That audit is the cheapest version of the story. The expensive version is the one where the audit happens because Legal asked, or because a client asked, or because someone spotted a fabricated statistic with a fabricated source in a published whitepaper and the person who wrote it had left. An ai content policy for marketing is not a compliance artefact you build once you’re big. It’s the thing that stops your tool stack from forking in nine directions while you’re busy hitting your publishing cadence.
One page. Five decisions. Write it in week one, before the second tool arrives.
Why the first week is the only cheap week
Shadow stacks don’t form through negligence. They form through enthusiasm. Your best writer finds a tool that cuts their research time by forty minutes an article, they expense it at £18/month, and they’re right that it works. The problem isn’t the tool. The problem is that there is now no answer to “which tools do we use and who decided?”, and the absence of an answer is what makes every subsequent question expensive.
Count the actual costs. Duplicate subscriptions: a five-person team with no approved list typically runs two to three overlapping tools at £20 to £60 per seat per month, so £500 to £2,000 a year in redundancy. Rework when output has to be re-verified because nobody knows which draft was AI-assisted: at 10 hours of a senior’s time at £45/hour loaded, that’s £450 per incident. The genuinely nasty cost is data. If a customer’s unpublished revenue figures went into a free-tier consumer tool with training-on-by-default, you cannot retract that. You can only disclose it.
Then there’s the audit itself. Unpicking a six-month shadow stack means interviewing everyone, reconciling card statements, checking each tool’s data processing terms and retention windows, working out what was fed where, and rewriting anything that can’t be traced. Budget three to five days of a content lead’s time, plus whatever Legal charges you for attention.
A page of A4, written before any of that accrues, costs ninety minutes.
Decision one: the approved tool list
Name the tools. Actual product names, actual tiers, actual owner.
Not “approved LLM providers” — that’s a category, and categories are how eleven tools happen. Write it like this:
| Tool | Tier | Approved for | Owner |
|---|---|---|---|
| ChatGPT Team | Team (training off by default) | Research, outlining, reformatting, alt text | Priya |
| Claude Pro | Pro | Long-document analysis, brief interrogation, editing | Priya |
| Perplexity Pro | Pro | Source-finding (links must be opened and checked) | Dan |
| Descript | Creator | Podcast and video editing, transcripts | Dan |
| Surfer SEO | Essential | Brief structure, entity coverage | Priya |
Five tools. Two owners. Anything not on the list is not approved, and the route to getting it added is a named person and a two-week trial with a written note on what it replaced.
The tier matters more than the tool. ChatGPT’s free and Plus tiers default to using your conversations for model improvement unless you turn it off; Team and Enterprise don’t train on business data. Claude’s consumer plans now offer a training opt-in, so the setting is per-account and needs checking rather than assuming. Notion AI, Grammarly, Canva and your CMS may all have generative features enabled that nobody has audited, because nobody bought them as an “AI tool”. Include the features-inside-tools you already pay for. That row is the one most policies miss.
Decision two: data classes
Three buckets, written plainly, because this is the decision that creates actual liability.
Green: goes in freely. Published material. Your own live blog posts, public pricing, press releases, anything already on the open web. Competitor content you could have read anyway.
Amber: goes in approved tools only, with training off. Draft copy, internal briefs, keyword research, unpublished campaign plans, anonymised performance data, your own strategy documents.
Red: never goes in, any tool. Customer personal data of any kind. Client material under NDA. Unpublished financials. Employee information. Anything a customer gave you in confidence for a case study before they signed off the final version. Anything covered by a client contract that restricts processing to named subprocessors.
Red is where UK GDPR stops being abstract. Pasting a customer list into a prompt is a transfer of personal data to a third-party processor, and if your privacy notice and your DPAs don’t cover it, you’ve got a problem that predates any AI-specific regulation. The ICO’s position is not exotic: existing data protection law applies to AI inputs and outputs, so lawful basis, purpose limitation and transparency all still bite. For the wider picture on where UK obligations, the EU AI Act’s transparency provisions and voluntary disclosure standards intersect, our governance, disclosure and UK compliance pillar goes considerably deeper than one page can.
Write one worked example into the policy so the buckets aren’t theoretical: “The Q3 case study with Aviva: the approved published quote is Green. The interview transcript, including the interviewee’s phone number in the notes, is Red. Strip it or don’t use the tool.”
Decision three: disclosure
Pick your position and write it as a sentence anyone can read out loud. Vagueness here produces inconsistency, and inconsistency is what gets noticed.
Three workable positions:
No public disclosure, full internal traceability. Every asset carries an internal field recording AI involvement. Nothing appears on the page. Reasonable where AI is doing research, structuring and editing rather than generating published prose. Most in-house teams land here.
Blanket site-level statement. One line in your editorial standards page: “We use AI tools in research and drafting. Every article is written, edited and fact-checked by a named human author.” Cheap, honest, and it does not require per-asset decisions.
Per-asset labelling above a threshold. Anything where AI generated more than roughly half the published text carries a note. This is the hardest to operate because “more than half” invites argument, but it’s the right call if you’re in a regulated sector or publishing under expert bylines.
Whichever you pick, three things get hard rules regardless. Bylines go to humans who can defend the content in a conversation. AI-generated images get labelled, always, because synthetic imagery of people or events is where audience trust collapses fastest. Statistics, quotes and citations get checked against the primary source before publication, with no exceptions for “it looked right”.
That last one deserves a number. Across a small sample of tests our team ran on 40 AI-drafted paragraphs containing statistics, 9 included a figure that was either wrong, unattributable, or attributed to a source that didn’t contain it. Roughly one in four. Treat every generated number as unverified until you’ve opened the page.
Decision four: sign-off
Who says yes, at which stage, and what does yes actually mean.
The failure mode is not “nobody approves”. It’s that approval happens on the finished draft, so a structurally flawed piece gets waved through because the deadline is tomorrow and the alternative is a blank page. Put the gate earlier.
A workable three-gate model for a team of four:
Gate 1, brief. A human writes or approves the brief before any tool touches it. AI can help structure it, but the angle, the audience and the claim the piece is making are human decisions. Ten minutes.
Gate 2, fact and source check. Whoever didn’t draft it opens every link, checks every number, and confirms every quote exists. This is a separate pass, not part of a general edit, and it gets its own line in your workflow tool so it can’t be silently skipped. Thirty to forty minutes for a 1,500-word piece.
Gate 3, publish. One named person per channel holds the publish decision. For a four-person team that’s usually the content lead for the blog and whoever owns the channel for everything else.
Note what isn’t a gate: “does this sound like us”. Voice review is useful and it belongs in the edit, but it catches tone, not fabrication. Teams that only do voice review ship confident, on-brand, factually wrong content.
Decision five: accountability
One name, at the top of the page, with a date.
“Priya Nandra owns this policy. Reviewed 29 September 2026. Next review 29 March 2027.”
Accountability means three specific things. First, that when someone finds a tool they want, there is a person to ask, and the answer arrives within a week rather than dissolving into a Slack thread. Second, that published errors have an owner who investigates rather than a committee that discusses. Third, that the policy gets reviewed on a date, not when something goes wrong, because tool terms change quarterly and a policy naming a pricing tier that no longer exists is worse than no policy at all.
Add a two-line incident route while you’re there: “AI-attributable error in published content: tell Priya same day. She decides correct-in-place, unpublish, or notify. No blame for reporting; the only sanction is not reporting.” That last clause does real work. People hide mistakes when the cost of reporting exceeds the cost of hoping.
What the page looks like
Five headings. Under each, between three and eight lines. A table for the tool list, three bullets for data classes, one sentence for disclosure, three gates, one name and two dates. It fits on A4 at 11pt with room to spare, and it should, because a two-page policy gets skimmed and a five-page policy gets ignored.
Send it to the team as a document they can comment on, not a PDF. Give it a week. Then fix the two things they were right about and publish it to wherever your team actually looks, which is probably a pinned Slack message and your Notion wiki, not a folder in SharePoint.
The reason to do this in week one is not that you’re expecting trouble. It’s that the policy is trivially easy to write while you have one tool and one workflow, and it becomes an archaeology project the moment you have six. Priya’s audit took until March. The version she wrote afterwards took an afternoon and fits on one side of a sheet of paper, and the only difference between the two documents is when she started.