---
title: "Safe AI workflows for client and customer work"
description: "From rules to routines Knowing what not to paste is the start. The next step is building routines so that safe behavior is automatic, for you and anyone…"
url: https://optimizeall.com/learn/ai-fundamentals-for-marketers/safe-workflows-client-work
updated: 2026-10-05
---

AI Fundamentals for Marketers & Creators · Privacy, confidentiality and disclosure · lesson 8 of 16 · 12 min

# Safe AI workflows for client and customer work

## From rules to routines

Knowing what not to paste is the start. The next step is building routines so that safe behavior is automatic, for you and anyone who works with you.

## The five-question pre-flight check

Before using AI on any client or customer task, ask:

1. **Whose data is this?** Mine, a client's, a customer's or the public's?
2. **Is there an agreement that covers it?** NDA, contract clause or client AI policy?
3. **Is this tool approved for this data?** Business terms, training opt-out, access controls?
4. **Can I minimize or anonymize it?** What is the least information needed?
5. **Will a human review the output before it reaches anyone?**

If you cannot answer confidently, pause and ask the client or your manager.

## Talk to clients about AI

Many clients now have AI policies of their own. Agree up front:

- Whether you may use AI tools on their work, and which ones.
- Whether AI-generated assets (images, voices, avatars) are acceptable in their brand, and how they must be labeled.
- Who owns outputs and who is responsible for checking claims.

A simple clause in your proposal helps: "We use approved AI tools to accelerate drafting and research. All outputs are reviewed and edited by our team. We do not input your confidential information into tools that use it for model training. We will not create synthetic voices or likenesses of any person without written consent."

## Customer data in sales and support

Sales teams increasingly use AI for call summaries and follow-ups. Good practice:

- Tell customers when calls are recorded or transcribed, as required by local law and platform rules.
- Keep transcripts inside your approved CRM or note-taking tool rather than copying them into personal chat accounts.
- Delete what you no longer need.
- Do not use AI to infer sensitive traits (health, religion, finances) about individual customers for targeting.

## A team AI policy on one page

Even a two-person business benefits from written rules. A basic policy covers:

- **Approved tools** and which plan tier to use.
- **Data rules**: the red, amber and green lists.
- **Review rules**: who checks what before publishing.
- **Disclosure rules**: when you label AI-generated content.
- **Likeness and voice rules**: consent required, in writing.
- **Incident process**: what to do if someone pastes something they should not have (tell the lead, delete the chat, assess whether the client must be informed).

The Responsible AI, Disclosure & Compliance course helps you build a fuller version.

## Hands-on: your one-page AI policy (agency or team)

Copy, adapt and share with everyone who touches client work, including freelancers.

```text
OUR AI POLICY (v1, [date])
1. Approved tools: [e.g. ChatGPT Business workspace; Microsoft 365 Copilot]. Personal accounts are not used for client work.
2. Data: Red (never): credentials, payment data, IDs, sensitive personal data, customer lists.
   Amber (approved tools only, minimized): client briefs, internal plans, results.
3. Clients: we confirm each client's AI rules at onboarding and record them in the client's project.
4. Review: every AI-assisted deliverable is reviewed by a named person before it leaves the team.
5. Claims: no invented statistics, testimonials, reviews or regulated claims; facts are verified.
6. Disclosure: we follow platform labels, advertising disclosure rules and client contracts.
7. Likeness and voice: no synthetic voices or likenesses of any real person without written consent.
8. Incidents: if red/amber data goes somewhere it shouldn't, tell [name] the same day. No blame for reporting.
9. Review this policy every [6] months.
```

**Before:** everyone uses whatever AI tool they like, and nobody knows what each client allows.

**After:** one approved workspace, a client-by-client record of AI permissions inside each project, a named reviewer per deliverable, and a clear incident route. New freelancers read one page on day one.

## Client onboarding questions about AI

Add these to your onboarding form:

1. May we use AI tools on your work? Which are approved or prohibited?
2. May AI-generated images, voices or video appear in your brand's content? How must they be labeled?
3. Are there claims or topics that always need your legal or medical sign-off?
4. Do you require disclosure of AI assistance in deliverables?

## A worked example

A three-person social media agency in Karachi manages accounts for a clinic, a clothing brand and a restaurant. Their routine:

- All client work happens in one business-tier assistant with training disabled, under a shared team workspace.
- The clinic's patient messages are never pasted into AI; the team summarizes themes manually ("questions about appointment times").
- Each client has a pasted "brand brief" (voice, banned words, approved claims) with no personal data in it.
- Every post is reviewed by the account lead before scheduling, with a checklist that includes "claims verified" and "AI disclosure applied where needed".

When a new intern pasted a customer phone list into a free chatbot, the incident process kicked in: the chat was deleted, the account lead assessed the exposure, and the intern was trained. The rule became a checklist line in onboarding.

## Key habits

- Default to anonymized inputs.
- Keep sensitive work in approved tools.
- Get consent in writing for anything involving a real person's likeness or voice.
- Review before anything is published or sent.

## Video lecture: Safe AI workflows for client and customer work

Lecture coming soon · 10 chapters · about 8 minutes. Read the full transcript below.

1. Safe AI workflows for client work
2. Why routines beat rules
3. The five-question pre-flight
4. Agree AI use with clients
5. Customer data in sales and support
6. Example 1: the intern and the phone list
7. Example 2: the clinic account
8. Watch me do it
9. The one-page AI policy
10. Recap and try this now

## Lecture transcript

### Safe AI workflows for client work

Knowing what not to paste is the start. But in a busy agency or marketing team, good intentions aren't enough. People are rushing, freelancers come and go, and every client has different rules. So in this lecture we'll turn rules into routines, so safe behavior happens automatically. You'll learn a five question pre flight check, how to agree AI use with clients before it becomes a problem, and how to write a one page AI policy your whole team can follow. You'll see two examples and watch me run the pre flight check on a real style task.

### Why routines beat rules

Why routines? Because rules get forgotten exactly when they matter most: on a deadline, late at night, when a client needs something in an hour. A routine is different. It's a short, automatic step that happens every time, like checking your mirrors before you change lanes. And increasingly, clients expect it. Many clients now have their own AI policies, and some contracts specify which tools may touch their data and how AI assisted work must be disclosed. An agency that can show a clear, simple AI routine wins trust. One that can't may lose the account.

### The five-question pre-flight

Here's the pre flight check. Five questions before using AI on any client or customer task. One: whose data is this? Mine, a client's, a customer's, or the public's? Two: is there an agreement that covers it? An NDA, a contract clause, or the client's AI policy. Three: is this tool approved for this data? Business terms, training settings, access controls. Four: can I minimize or anonymize it? What's the least information needed? And five: will a human review the output before it reaches anyone? If you can't answer all five confidently, pause and ask the client or your manager. It takes thirty seconds once it's a habit.

### Agree AI use with clients

Next, talk to clients about AI before it becomes an issue. Agree which tools you may use on their work. Agree whether AI generated assets, like images, voices or avatars, are acceptable in their brand, and how they must be labeled. And agree who owns the outputs and who's responsible for checking claims. A simple clause in your proposal helps. Something like: we use approved AI tools to accelerate drafting and research. All outputs are reviewed and edited by our team. We don't input your confidential information into tools that use it for model training. And we won't create synthetic voices or likenesses of any person without written consent. Then record each client's answers in their project, where everyone will see them.

### Customer data in sales and support

Sales and support teams handle the most personal data, so they need the clearest routine. Keep customer records inside approved systems, like your CRM or help desk, and use their built in AI features where your organization has approved them. When you use a general assistant, give it aggregated or anonymized data: complaint themes, not complaint lists. For personalization, you can write a template with placeholders, like first name and last product purchased, and let your email platform fill them in, rather than pasting customer records into a chatbot. You get personal emails without moving personal data around.

### Example 1: the intern and the phone list

A simple example. An intern at a Dubai events company pastes a list of customer phone numbers into a free chatbot to format them for a campaign. What's the best first response? Not a lecture. Delete the chat, check the settings, and tell the manager, who decides whether anything needs to be reported under the company's obligations. Then give the intern a safe route: in this case, the formatting job belongs in a spreadsheet, not a chatbot, and the team's approved assistant is for anonymized work only. The fix is a better system, not a scared intern.

### Example 2: the clinic account

Now a realistic business case, with illustrative details. A healthcare marketing agency in London manages social content for a private dermatology clinic. The clinic offers to send patient enquiries so the agency can find content ideas. The agency's pre flight check flags a problem immediately: health data about identifiable people. So they agree a better route. The clinic's own staff summarize the enquiries into anonymous themes, like questions about recovery time or cost ranges, and share only those. The agency uses AI to turn the themes into educational post ideas. And every post with a medical statement goes back to the clinic's clinician for sign off. The content is better, because it answers real questions, and nobody's health data leaves the clinic.

### Watch me do it

Let me run the pre flight on a real style request. A retail client emails their customer satisfaction survey export and asks for a summary deck by Friday. Question one: whose data? Customers', and it includes names and emails, so partly red. Question two: agreement? Our contract allows AI in approved tools, and requires disclosure in deliverables. Question three: approved tool? Our business workspace, yes. Question four: minimize? I delete the name and email columns before uploading and keep the ratings and comments. Question five: who reviews? The account lead, before it goes to the client. Route decided: anonymized file, approved workspace, a note on the method slide about AI assistance, and account lead review. Ninety seconds, and I can defend every step.

### The one-page AI policy

Finally, write it down. A one page AI policy makes safe behavior automatic for everyone, including freelancers on their first day. It covers approved tools, and that personal accounts aren't used for client work. The red and amber data rules. That you confirm each client's AI rules at onboarding. That every AI assisted deliverable has a named human reviewer. No invented statistics, testimonials, reviews or regulated claims. Disclosure in line with platform rules, advertising law and client contracts. No synthetic voices or likenesses of real people without written consent. An incident route, with no blame for reporting. And a date to review the policy. The template is in the lesson text.

### Recap and try this now

Let's recap. Run the five question pre flight before AI touches client or customer work. Agree AI use with clients up front, including tools, AI generated assets, labeling and who checks claims. Keep customer data in approved systems and work with anonymized or aggregated data. And write a one page policy that makes the safe route the easy route. Here's your try this now. Adapt the policy template from the lesson text for your team or your freelance business, and add the four AI questions to your client onboarding form. Share both with one colleague or client this week and ask for feedback.

## Key takeaways

- Run the five-question pre-flight: whose data, which agreement, which approved tool, can I minimize, who reviews?
- Agree AI use with clients up front: tools, AI-generated assets, labeling, ownership and responsibility for claims.
- Keep customer data in approved systems; use AI on anonymized or aggregated data for insights.
- A one-page team AI policy with approved tools, data rules, review, disclosure and an incident route makes safe behavior automatic.

## Try it

Draft a one-page AI policy for your business covering approved tools, data rules, review, disclosure, likeness consent and incidents.

- [Previous: What never to paste into an AI tool](https://optimizeall.com/learn/ai-fundamentals-for-marketers/what-not-to-paste)
- [Next: Disclosure, AI labels and consent: marketing with AI honestly](https://optimizeall.com/learn/ai-fundamentals-for-marketers/disclosure-and-ai-labeling)
- [All lessons of AI Fundamentals for Marketers & Creators](https://optimizeall.com/learn/ai-fundamentals-for-marketers)
