Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

AI Governance Policy for Marketing Teams: The 12-Section Template (2026)

In this blog post I'm going to give you the 12-section AI governance policy template I use with clients, the practical version for marketing teams, not the 60-page enterprise version that nobody reads.

Most "AI governance policy" content in 2026 is written for Fortune 500 legal departments. It assumes you have a Chief AI Officer, a compliance team, and three quarters to roll out the policy. None of that applies to a 5-30 person marketing team trying to use AI responsibly without slowing themselves down.

This template is different. Twelve sections. About 6 pages of actual policy. Covers what matters. Skips what doesn't. Designed to be readable, enforceable, and updateable.

I've been a marketing consultant for twenty-one years. I went all in on AI in 2024. I've helped clients write AI governance policies that their teams follow. The template below is built from real use.

By the end of this blog you'll have the structure, the language patterns, and the decision tree for adapting it to your team.

TL;DR

12 sections:
1. Scope
2. Definitions
3. Roles and ownership
4. Approved tools
5. Data handling rules
6. Disclosure requirements
7. Output review and quality bar
8. Prohibited use cases
9. Vendor evaluation requirements
10. Incident response
11. Update cadence
12. Sign-off

Total length: 5-7 pages. Should fit in a single Google Doc or Notion page. Avoid policies that sprawl beyond that, they don't get read.

Section 1: Scope

What to include:

This policy applies to all use of AI tools by [marketing team / company] employees, contractors, and freelancers in connection with [company] work. It covers AI tools used to generate content, analyse data, communicate with prospects/customers/partners, or make decisions on behalf of [company].

What NOT to include:
- Personal AI use outside work
- AI used in non-marketing functions (those have their own policies)
- Customer-facing AI features in your product (separate policy)

Why this matters: Without explicit scope, every conversation about AI in the company gets tangled up in this policy. Tight scope keeps the policy applicable.

Section 2: Definitions

What to include:

  • "AI tool": software that uses machine learning or large language models, including ChatGPT, Claude, Gemini, Midjourney, and similar
  • "AI output": any content, decision, or data produced by an AI tool that is then used in our work
  • "PII": personally identifiable information about customers, prospects, employees, or any individual
  • "Approved tool": an AI tool that has been evaluated and approved per Section 4

What NOT to include:
- Technical definitions (transformer, embedding, RAG), irrelevant for policy

Why this matters: Definitions stop arguments. Without them, "AI" can mean different things to different team members.

Section 3: Roles and ownership

What to include:

  • Policy owner: [Named person]. Updates this policy. Approves new AI tools. First contact for AI-related questions.
  • Tool evaluators: [Named person(s)]. Evaluate new AI tools per Section 9.
  • Incident responders: [Named person(s)]. Investigate and respond to AI-related incidents per Section 10.
  • All team members: Responsible for following this policy and flagging concerns.

What NOT to include:
- Committee structures (too much overhead for marketing team scale)

Why this matters: Named individuals, not committees. When something needs decision, you need one name, not a forwarding chain.

Section 4: Approved tools

What to include:

A specific list. For marketing teams in 2026, typical approved list:

  • ChatGPT (OpenAI), text generation, research, summarisation
  • Claude (Anthropic), text generation, long-form work, structured analysis
  • Granola or Fireflies, meeting transcription
  • Midjourney or DALL-E (via approved subscription), image generation
  • [Your CRM's AI features], depending on your stack
  • [Your email platform's AI features], depending on your stack

For each tool, list:
- What it's approved for (specific use cases)
- What it's not approved for
- Account/login (shared team account vs personal)
- Cost (so the team knows the budget)

What NOT to include:
- Open-ended "or similar tools"
- Tools the policy owner hasn't evaluated

Why this matters: Without a list, team members use whatever they want. With a list, governance is concrete.

Section 5: Data handling rules

What to include:

  • Customer/prospect PII: Do not paste into any AI tool unless it's specifically approved for that purpose with a signed DPA. Currently approved: [list]. Currently NOT approved: [list].
  • Company financial data: Do not paste into AI tools.
  • Employee personal data: Do not paste into AI tools.
  • Public information: Fine to use.
  • Internal documentation: Fine if the AI tool is approved per Section 4 AND the data is not PII/financial/personal.

What NOT to include:
- Lengthy data classification frameworks (too complex for execution)

Why this matters: This section gets the most violations because it's the most tempting to skip. Make it short, clear, easy to remember.

Section 6: Disclosure requirements

What to include:

  • Public content (blog, social, ads): AI assistance is permitted; explicit disclosure is not required IF a human substantively edited the work. AI-generated content with no human editorial pass must be disclosed.
  • Customer-facing comms (emails, support): AI assistance is permitted for drafting; final send must be human-reviewed. No disclosure required.
  • Sales outreach: AI-generated outreach requires explicit disclosure. AI-assisted research informing human-written outreach does not.
  • Press / journalist outreach: AI-generated outreach prohibited. No exceptions.
  • Legal / regulatory communications: AI assistance not permitted. Human-written only.

What NOT to include:
- Disclaimer language for AI-assisted content (encourages disclosure where not needed)

Why this matters: Disclosure rules are increasingly required by law (EU AI Act, various US state laws). Get this right early.

Section 7: Output review and quality bar

What to include:

  • Every AI output going to external audiences must be reviewed by a human before publication/sending
  • Reviewer responsibility: factual accuracy, brand voice, legal/compliance check
  • Quality bar: outputs must meet the same standard as fully human work
  • Specific NO-PUBLISH triggers: hallucinations, brand voice mismatch, factual errors, biased outputs, anything embarrassing

What NOT to include:
- Mandatory reviewer ratios (creates bottleneck)

Why this matters: Without explicit quality bar, AI outputs vary wildly by reviewer.

Section 8: Prohibited use cases

What to include:

The following AI uses are prohibited regardless of tool or workflow:

  1. Generating fake testimonials or reviews
  2. Impersonating real people (customers, employees, journalists, public figures)
  3. Generating images of identifiable real people without consent
  4. Auto-sending AI-generated outreach without human review
  5. Making employment, hiring, or HR decisions based solely on AI output
  6. Customer service responses on sensitive topics (complaints, refunds, escalations) without human handling
  7. Financial advice generation
  8. Legal advice generation
  9. Medical claims (if applicable to your products)
  10. Any use that violates a tool's terms of service

What NOT to include:
- Use cases that are restricted but not prohibited (cover those in Section 5 or 6)

Why this matters: The "never" list is what protects you from worst-case scenarios.

Section 9: Vendor evaluation requirements

What to include:

New AI tools must be evaluated before approval per [Section 4]. Evaluation must address:

  • Data handling (where data lives, who can access, retention policy)
  • Compliance (SOC 2, GDPR readiness, EU AI Act if applicable)
  • Vendor stability (company age, funding, customer base in our segment)
  • Pricing (total cost of ownership, exit terms)
  • Integration (works with our existing stack)

Use the AI Vendor Evaluation Checklist for the full process.

What NOT to include:
- Procurement bureaucracy (sourcing, RFP processes)

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

Why this matters: Tools get added without evaluation by default. This section creates the gate.

Section 10: Incident response

What to include:

If an AI output causes harm (customer complaint, public embarrassment, regulatory issue, data exposure):

  1. Pause the relevant workflow immediately
  2. Notify [policy owner] within 4 hours
  3. Document: what happened, which tool, who was involved, what data was exposed if any
  4. Contain: pull the offending output if public, contact affected parties if relevant
  5. Investigate: root cause analysis within 1 week
  6. Remediate: update workflow, tool, or policy as needed
  7. Post-mortem: written summary, distributed to team

What NOT to include:
- Generic incident response (this is AI-specific)

Why this matters: When something goes wrong, you don't want to be deciding what to do under pressure.

Section 11: Update cadence

What to include:

This policy will be reviewed:
- Quarterly (scheduled review by policy owner)
- Whenever a new AI tool is approved or removed
- Whenever a relevant law changes (EU AI Act phases, US state law updates)
- Whenever an incident reveals a policy gap

Major updates require [appropriate sign-off]. Minor updates (typo fixes, contact info) don't.

What NOT to include:
- Lengthy approval workflows

Why this matters: Policies that don't get updated become stale and irrelevant. Update cadence built into the policy ensures it stays alive.

Section 12: Sign-off

What to include:

This policy is in effect as of [date]. All current employees, contractors, and freelancers acknowledge they have read and understand it via [mechanism, could be email confirmation, HR system, signed agreement].

New hires acknowledge before being granted access to approved AI tools.

Violations of this policy will be addressed per [your standard escalation process].

[Policy owner signature/name + date]

What NOT to include:
- Punitive language (rarely useful, often counterproductive)

Why this matters: Sign-off creates accountability. Without it, "I didn't know about that policy" is a valid defence.

How to adapt this template

Step 1: Read all 12 sections. Identify which are immediately relevant vs which can wait.

Step 2: Customise the lists (approved tools, prohibited use cases, sign-off process) to your business.

Step 3: Get input from 2-3 team members before publishing. They'll spot gaps a single author misses.

Step 4: Run by your legal counsel if you have one. Adjust based on their input.

Step 5: Publish, announce to team, schedule first quarterly review.

Step 6: Treat as living document. Update as you learn.

Total adaptation time: 4-8 hours for the first version. 2 hours per quarterly review after.

What this template deliberately doesn't include

  • Long ethical principles: "We commit to using AI responsibly" sections that don't constrain behaviour
  • Aspirational language: Goals without enforcement mechanisms
  • AI use cases not relevant to marketing: Hiring AI, legal AI, customer-product AI (separate policies)
  • Detailed technical compliance: Cover that in your tool evaluations, not the policy

Frequently asked questions

Do small marketing teams really need this? If you have 3+ people using AI for company work, yes. The policy prevents the easy mistakes.

Should this be public or internal? Internal. Public-facing AI usage statement is separate.

How does this interact with our existing IT/security policies? This sits alongside them. AI governance is specific enough to warrant its own policy, not an addendum.

Should AI governance be in the employee handbook? As a reference. Full text in a separate document so it can be updated independently.

Do contractors and freelancers need to sign this? Yes. Include in their onboarding.

What if the team pushes back on the prohibition list (Section 8)? Listen to specific objections. The prohibitions should map to real risks, not bureaucratic caution.

What if my company already has a generic IT policy that mentions AI? This is more specific. Add or replace as appropriate.

Want help building yours?

If the conclusion is "your existing IT policy already covers this, don't add another doc," that's the conclusion.

Book an AI governance session →

I'm Lilach Bullock. I've been a marketing consultant for twenty-one years. I went all in on AI in 2024. I work with founders and marketing leaders who want AI to move their numbers, not just their tool stack.


I go much deeper on this in the AI marketing guide.

Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.