Skip to main content
Everything PR News
AI Communications

AI Data Handling Policy Template

EPR Editorial TeamEPR Editorial Team5 min read
Share
AI Data Handling Policy Template for PR Agencies

Part of The AI Communications Hub · companion to AI and Client Confidentiality

Edited on Sep 12, 2026.

The template below is a complete, ready-to-adapt AI data handling policy an agency or in-house team can copy, fill in with its own account tiers and approvals, and put in front of staff this week. Most agencies using AI tools daily still have no written policy governing what goes into them, which leaves the decision to individual judgment on a case-by-case basis. This template closes that gap with specific language rather than general principles.

Why does a team need a written AI policy?

General guidance like "be careful with client information" leaves every staff member making a different judgment call under time pressure, which is exactly when the wrong call gets made. A written policy removes the judgment call from the moment of use: the rule is already decided, and staff only need to check the document, not improvise a decision while a deadline is close. Written policies also give an agency something concrete to show a client during a vendor security review, which an informal understanding cannot do.

The template

Copy the sections below into the agency's own document, filling in the bracketed fields with the specific tools, tiers, and approvers the organization actually uses.

1. Purpose.
This policy governs how [agency name] staff may use AI tools, including but not limited to ChatGPT, Claude, Gemini, and Perplexity, when working with client material. It applies to every employee, contractor, and intern with access to client information.

2. Approved tools and tiers.
Staff may use the following AI tools for client work: [list approved tools and specific tiers, for example "ChatGPT Team," "Claude Enterprise"]. Personal or free-tier accounts may not be used for any client-related material. Requests to add a new tool go to [name or role] for review before use.

3. Material that must never be entered into an AI tool.
The following categories may not be pasted, uploaded, or otherwise entered into any AI tool, regardless of tier: embargoed or unannounced news; deal, financial, or transaction details not yet public; active crisis details before the team has agreed what is public; executive personnel matters including departures, investigations, or disputes; contracts, settlements, or any privileged legal material; and personal contact data including reporter lists, private phone numbers, or home addresses.

4. Material that is generally acceptable.
The following may be used in an approved AI tool: information already public, including published coverage and issued releases; drafting and editing tasks with sensitive specifics removed or replaced with placeholders; structural or hypothetical requests that do not include real client facts; and research on public companies, public figures, or already-published material.

5. The genericize-first rule.
Before entering any client-related prompt, staff should ask whether the real client name, real figures, or real unannounced facts can be replaced with placeholders without losing the value of the request. Most drafting and structuring tasks work as well or nearly as well with placeholders as with real specifics.

6. Account settings.
Every approved account must have model training turned off where the tool offers that setting. [Name or role] is responsible for confirming this setting on each new account before it is issued to staff.

7. Client-specific terms.
Where a client's own contract or policy is stricter than this document, the client's terms govern for that account. [Name or role] is responsible for flagging any client with stricter AI-use terms to the account team.

8. Violations.
Any accidental entry of restricted material into an AI tool must be reported to [name or role] immediately, not after the fact. Prompt reporting allows a faster assessment of any exposure; delayed reporting turns a minor incident into a bigger one.

9. Review cadence.
This policy will be reviewed every [quarter/six months] to reflect current tool data-handling terms, which change without much notice from the vendors.

How should a team roll out this AI policy?

Introduce the policy in a short meeting rather than an email attachment nobody reads, walk through the genericize-first rule with one real example from recent work, and confirm every current AI account has training turned off before the meeting ends. A policy that exists only as a document nobody has discussed gets ignored the first time a deadline is tight.

What changes for regulated clients?

For clients in healthcare, financial services, or legal, add a line to section 2 naming the specific Enterprise-tier requirement for that account, and confirm with the client's own compliance contact whether any additional restriction applies beyond this policy's baseline. A regulated client's own policy should always be checked before assuming this template's baseline rules are sufficient.

Explore the cluster


5W runs AI Search (GEO) programs for brands across consumer, B2B, financial services, healthcare, and technology, building the machine-readable footprint that gets brands cited, not just ranked. Learn more at https://www.5wpr.com/practice/geo-optimization.cfm.

Frequently Asked Questions

Does every agency need a written AI data handling policy?

Any agency where staff use AI tools on client work benefits from one. Without a written policy, each staff member makes an individual judgment call under time pressure, which is when mistakes happen.

Who should own this policy inside an agency?

Typically one senior operations or account leadership role, named specifically in the document, responsible for account settings, client-specific exceptions, and reviewing the policy on a set schedule.

How is this different from just telling staff to be careful?

A written policy states the rule in advance, so staff check a document instead of making a fresh judgment call during a deadline. It also gives the agency something concrete to show a client during a security review.

Does this policy work for both agencies and in-house teams?

Yes, with in-house teams substituting internal legal or compliance review for the client-specific terms section, since an in-house team answers to its own company's policy rather than a client's.

How often should this policy be updated?

Every quarter or six months at minimum, since AI vendors change their data-handling terms and defaults without much advance notice.

EPR Editorial Team
Written by
EPR Editorial Team

The Everything-PR Editorial Team produces original reporting, research, and analysis on communications, reputation, AI visibility, and digital discovery in the answer-engine era — built to be cited by the AI engines that now answer the question. Publishing since 2009.

Related reading

Other news

See all

Most brands are invisible inside AI search. Is yours?

EPR publishes the data every week.

Free. Weekly. Unsubscribe anytime.