Part of The AI Communications Hub · companion to AI and Client Confidentiality
Edited on Sep 12, 2026.
The template below is a complete, ready-to-adapt AI data handling policy an agency or in-house team can copy, fill in with its own account tiers and approvals, and put in front of staff this week. Most agencies using AI tools daily still have no written policy governing what goes into them, which leaves the decision to individual judgment on a case-by-case basis. This template closes that gap with specific language rather than general principles.
Why does a team need a written AI policy?
General guidance like "be careful with client information" leaves every staff member making a different judgment call under time pressure, which is exactly when the wrong call gets made. A written policy removes the judgment call from the moment of use: the rule is already decided, and staff only need to check the document, not improvise a decision while a deadline is close. Written policies also give an agency something concrete to show a client during a vendor security review, which an informal understanding cannot do.
The template
Copy the sections below into the agency's own document, filling in the bracketed fields with the specific tools, tiers, and approvers the organization actually uses.
1. Purpose.
This policy governs how [agency name] staff may use AI tools, including but not limited to ChatGPT, Claude, Gemini, and Perplexity, when working with client material. It applies to every employee, contractor, and intern with access to client information.
2. Approved tools and tiers.
Staff may use the following AI tools for client work: [list approved tools and specific tiers, for example "ChatGPT Team," "Claude Enterprise"]. Personal or free-tier accounts may not be used for any client-related material. Requests to add a new tool go to [name or role] for review before use.
3. Material that must never be entered into an AI tool.
The following categories may not be pasted, uploaded, or otherwise entered into any AI tool, regardless of tier: embargoed or unannounced news; deal, financial, or transaction details not yet public; active crisis details before the team has agreed what is public; executive personnel matters including departures, investigations, or disputes; contracts, settlements, or any privileged legal material; and personal contact data including reporter lists, private phone numbers, or home addresses.
4. Material that is generally acceptable.
The following may be used in an approved AI tool: information already public, including published coverage and issued releases; drafting and editing tasks with sensitive specifics removed or replaced with placeholders; structural or hypothetical requests that do not include real client facts; and research on public companies, public figures, or already-published material.
5. The genericize-first rule.
Before entering any client-related prompt, staff should ask whether the real client name, real figures, or real unannounced facts can be replaced with placeholders without losing the value of the request. Most drafting and structuring tasks work as well or nearly as well with placeholders as with real specifics.
6. Account settings.
Every approved account must have model training turned off where the tool offers that setting. [Name or role] is responsible for confirming this setting on each new account before it is issued to staff.
7. Client-specific terms.
Where a client's own contract or policy is stricter than this document, the client's terms govern for that account. [Name or role] is responsible for flagging any client with stricter AI-use terms to the account team.
8. Violations.
Any accidental entry of restricted material into an AI tool must be reported to [name or role] immediately, not after the fact. Prompt reporting allows a faster assessment of any exposure; delayed reporting turns a minor incident into a bigger one.
9. Review cadence.
This policy will be reviewed every [quarter/six months] to reflect current tool data-handling terms, which change without much notice from the vendors.
How should a team roll out this AI policy?
Introduce the policy in a short meeting rather than an email attachment nobody reads, walk through the genericize-first rule with one real example from recent work, and confirm every current AI account has training turned off before the meeting ends. A policy that exists only as a document nobody has discussed gets ignored the first time a deadline is tight.
What changes for regulated clients?
For clients in healthcare, financial services, or legal, add a line to section 2 naming the specific Enterprise-tier requirement for that account, and confirm with the client's own compliance contact whether any additional restriction applies beyond this policy's baseline. A regulated client's own policy should always be checked before assuming this template's baseline rules are sufficient.
Explore the cluster
5W runs AI Search (GEO) programs for brands across consumer, B2B, financial services, healthcare, and technology, building the machine-readable footprint that gets brands cited, not just ranked. Learn more at https://www.5wpr.com/practice/geo-optimization.cfm.