Responsible AI, Disclosure & ComplianceData protection and your AI usage policy · Lesson 11 of 11
Building your AI usage policy
Video lecture
Building your AI usage policy
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Your AI usage policy
A brand's procurement team sends your agency a questionnaire. Question seven: describe your policy for the use of artificial intelligence, including data handling, disclosure and human oversight. You have until Friday. Do you have an answer, or a panic? In this lecture you'll learn why every business, even a solo creator, needs a short AI usage policy, the thirteen sections that cover everything in this course, how to make people actually follow it, and how to turn it into a public summary that wins trust.
0:37 Why write it down
Why bother? Because people are already using AI in your work, whether you've written anything down or not. A written policy turns good intentions into consistent practice. It protects clients and customers. It gives new team members and freelancers clear rules from day one. And it gives you something to send when a brand or procurement team asks how you use AI, which, as of twenty twenty-six, many of them do. Done well, it's also a sales asset.
1:11 The kitchen rules analogy
Here's the analogy. A good AI policy is like a kitchen's food safety rules. They don't tell the chef how to cook. They say which suppliers are approved, how to store things, what never goes near what, who checks the dish before it leaves the pass, and what to do if something goes wrong. Short, visible, and followed every day. Keep yours to two to four pages, with checklists that do the heavy lifting.
1:43 The 13 sections
Now the thirteen sections. One, purpose and principles. Two, scope: who and what it covers. Three, approved tools and how new ones get approved. Four, data rules, which we'll color code. Five, human review and accountability. Six, accuracy and fact checking. Seven, disclosure and labeling. Eight, likeness, voice and intellectual property. Nine, fairness and bias. Ten, automation and agents. Eleven, security. Twelve, incidents. And thirteen, training and review. You'll notice each one maps to a lesson in this course. The policy is simply this course, turned into rules.
2:21 The workhorse sections
Let's zoom into the three sections that do the most work. Data rules: red means never, like passwords, payment data, IDs, sensitive data, or client secrets without permission. Amber means approved tools only, redacted, like briefs, transcripts and performance data. Green means public information, your own drafts, anonymized data. Review: every public piece has a named reviewer; sponsored, regulated or EU deepfake content gets two. And disclosure: commercial rules by market, the AI labeling decision tree, the Article fifty screen for EU-facing work, and chatbots always say they're AI.
3:00 Often forgotten
Two sections people forget. Incidents: what happens when someone pastes client data into the wrong tool, publishes a false claim, discovers a deepfake of a client, or an automation misbehaves? Who do they tell, how fast, and what happens next? Make it no-blame, or people will hide mistakes. And training and review: an onboarding module for every new person, a refresher every six months, and a policy review at least every six months, because tools and laws in this area change that fast. Just look at how much changed in twenty twenty-six alone.
3:40 Example 1: solo creator, Karachi
First example, a solo creator. A Karachi tech reviewer with one freelance editor writes a one-page policy in an hour. Approved tools: two. Data: never paste brand contracts or follower DMs into AI. Disclosure: ad upfront, AI labels by the decision tree, and his AI voice always labeled. Likeness: his editor can't create synthetic versions of anyone without written consent. Incidents: tell each other the same day. When a brand asks about AI, he sends the one-pager and a three-sentence summary. The brand's reply: this is more than most agencies send us.
4:20 Example 2 (illustrative): 12-person agency
Second example, a realistic business scenario with illustrative details. A twelve-person creator-management agency serving clients in Pakistan and the UAE writes a three-page policy using the thirteen sections. It adds the pre-publish checklist to its project management tool, so a post can't move to scheduled until the boxes are ticked. It builds an AI tool register, a consent template for voices and avatars, and a client AI clause for proposals. Illustratively, within a month, a UAE client's procurement team asked about AI governance, the agency sent the policy and summary the same day, and the client later cited it as one reason for renewing the contract.
5:06 Watch me do it: fill the skeleton
Watch me do it. I open the policy skeleton from the lesson. Section one: we use AI to research, draft and produce faster; humans stay accountable for everything we publish. Section three: I paste in three approved tools from our register, with their plans. Section four: I fill in the red list, adding our biggest client's name so nobody pastes their strategy into a tool. Section five: public content, one named reviewer; sponsored content, two. Section seven: I link the disclosure wording library. Section twelve: report to the operations lead within four hours, no blame. Then I set the next review date six months out, and put the pre-publish checklist into our task template. Forty minutes, and version one exists.
5:58 The public summary
Now the public summary. Keep it to a short paragraph. Something like: we use approved AI tools to speed up research, drafting and production. Every piece of content is reviewed by our team, and every claim is checked. We don't put your confidential information into tools that train on it. We never create synthetic voices or likenesses without written consent, and we label AI-generated content in line with platform rules and advertising law, including EU transparency rules where they apply. Put it on your website, your media kit and your proposals.
6:38 Common mistakes
Common mistakes. Copying a big company's policy that doesn't match how you actually work. Banning AI completely, which usually pushes use underground rather than stopping it, so you lose oversight. Writing a fifteen-page document nobody reads. Writing the policy and never training anyone on it. Forgetting freelancers and creators you manage. And never reviewing it, so it still quotes twenty twenty-four rules in twenty twenty-seven.
7:06 Measure it
How do you measure whether the policy works? Four signals. Training completion: everyone in scope has done onboarding and the latest refresher. Checklist use: the share of published pieces with a completed pre-publish checklist. Incident reporting: a small, steady number of reported near misses is healthy; zero usually means people aren't reporting. And client questions: how quickly you can answer an AI governance questionnaire. Aim for the same day.
7:36 Recap + try this now
Recap. A short AI usage policy turns good intentions into consistent, defensible practice. Cover the thirteen sections, lean on checklists and templates, train people, and review it at least every six months. Then share a public summary; it builds trust and wins work. Try this now: copy the policy skeleton from the lesson, fill in version one today, even if it's rough, and turn section five and section seven into a one-screen pre-publish checklist. Congratulations on finishing the course. The final assessment is next.
Why every business needs one
Whether you are a solo creator with a freelance editor or a 30-person agency, people are already using AI in your work. A written AI usage policy turns good intentions into consistent practice, protects clients and customers, and gives you something clear to share when a brand or client asks, "How do you use AI?"
Keep it short enough that people actually read it: typically two to four pages, plus checklists.
The policy structure
1. Purpose and principles Why you use AI and the values that guide it. For example:
We use AI to work faster and more creatively, while keeping humans accountable for everything we publish. We are honest with our audiences and clients, respect people's rights and data, and never use AI to deceive.
2. Scope Who it applies to (staff, freelancers, creators you manage) and which activities (content, sales, customer service, operations).
3. Approved tools A list of approved tools and plan tiers, who can approve new ones, and the evaluation criteria (data terms, commercial rights, security, regional requirements).
4. Data rules
- Red (never): passwords, payment data, government IDs, sensitive personal data, customer lists in non-approved tools, client confidential material without permission.
- Amber (approved tools only, minimized): client briefs, strategy, call transcripts, performance data.
- Green: public information, your own drafts, anonymized data.
5. Human review and accountability Risk tiers and required review (for example, all public content reviewed by a named person; sponsored and regulated content by two people). A named person is accountable for every published output.
6. Accuracy and fact-checking All facts, statistics, quotes and claims verified against primary sources; no invented statistics or testimonials.
7. Disclosure and labeling
- Commercial disclosure rules by market.
- AI labeling rules (the decision tree from Module 3), Article 50 screening for EU-facing work (Module 4) and standard wording.
- Chatbots and agents identify as AI.
- Content Credentials kept on export; asset register updated.
8. Likeness, voice and IP
- Written consent for any real person's voice or likeness, with scope, duration and deletion terms.
- No prompts imitating living artists, protected characters or other brands.
- Licensed inputs only; records for key assets.
9. Fairness and bias Representation review for campaigns; no AI-only decisions about people (hiring, creator selection, credit-like decisions); no inference of sensitive traits for targeting.
10. Automation and agents Automation register, least privilege, human approval for sensitive actions, kill switches, testing after changes.
11. Security Business accounts, two-factor authentication, access reviews and prompt offboarding.
12. Incidents How to report mistakes such as data pasted wrongly, a false claim published, a deepfake discovered or an agent misbehaving: who to tell, how fast, and what happens next. Encourage reporting without blame.
13. Training and review Onboarding training for new team members; policy reviewed at least every six months given how fast tools and laws change.
Making it real
- Checklists over prose: a one-page pre-publish checklist and a one-page data checklist get used; long documents do not.
- Templates: consent forms, client AI clauses, disclosure wording and an agent spec template.
- Examples: include a few "good" and "not allowed" examples relevant to your work.
- Leadership example: owners and leads must follow the policy visibly.
Talking to clients and brands
Prepare a short public-facing summary:
How we use AI: We use approved AI tools to speed up research, drafting and production. Every piece of content is reviewed by our team, and every claim is checked. We don't put your confidential information into tools that train on it. We never create synthetic voices or likenesses without written consent, and we label AI-generated content in line with platform rules and local advertising law.
Many brands now ask for this in onboarding and procurement. Having it ready builds trust and can differentiate you.
Worked example
A three-person creator management agency serving clients in Pakistan and the UAE writes a three-page policy in an afternoon using this structure. They add a pre-publish checklist to their project tool, a consent template for avatars and voices, and a client AI clause for proposals. Within a month, a UAE client's procurement team asks about AI governance; the agency sends the public summary and policy, and the client notes it as a strength.
Hands-on: a policy skeleton you can fill in today
Copy this into your team wiki or a shared document and replace the brackets. Keep it to two to four pages; put detail in the linked checklists.
[COMPANY] AI USAGE POLICY v1.0 Owner: [name] Next review: [date, max 6 months]
1. PURPOSE We use AI to [goals]. Humans stay accountable for everything we publish.
2. SCOPE Staff, freelancers and creators we manage; content, sales, service, operations.
3. TOOLS Approved list: see AI Tool Register. New tools approved by [role] after
checking data terms, commercial rights, marking/provenance, security, region.
4. DATA RED (never): passwords, payment data, IDs, sensitive data, client
confidential info without permission.
AMBER (approved tools only, redacted): briefs, transcripts, performance data.
GREEN: public info, own drafts, anonymized data.
5. REVIEW Public content: 1 named reviewer. Sponsored/regulated/EU deepfake: 2 reviewers.
6. ACCURACY Every fact, statistic, quote and claim traced to a primary source.
7. DISCLOSURE Commercial disclosure by market; AI labels per decision tree; Article 50
screen for EU-facing work; chatbots say they are AI.
8. LIKENESS/IP Written consent for any real voice or likeness; no protected names in prompts;
licensed inputs; provenance record for key assets.
9. FAIRNESS Representation review; no AI-only decisions about people.
10. AUTOMATION Automation register; least privilege; human approval for sensitive actions.
11. SECURITY Business accounts, 2FA, quarterly access review, offboarding within 24h.
12. INCIDENTS Report within [x] hours to [role]; no-blame; log and learn.
13. TRAINING Onboarding module + refresher every 6 months; completion tracked.An AI Tool Register that backs up section 3:
tool,plan,use_cases,personal_data_allowed,dpa_signed,training_on_inputs,output_marking,data_region,owner,last_checked
Chat assistant,Business,drafting; research; summaries,amber (redacted),yes,off,n.a.,EU,Ops lead,2026-09-15
Image generator,Team,campaign visuals,no,n.a.,off,C2PA metadata,US,Creative lead,2026-09-15
Voice tool,Pro,consented voice-overs,biometric (consented only),yes,off,watermark + metadata,EU,Producer,2026-09-15And a pre-publish checklist that fits on one screen:
[ ] Facts, stats and claims sourced [ ] Commercial disclosure (market rules)
[ ] AI label decision made (tree/Art. 50) [ ] Real person? Consent record linked
[ ] No protected names/brands in prompts [ ] Representation reviewed
[ ] Content Credentials kept on export [ ] Evidence screenshot saved
[ ] Reviewer name: ________ [ ] Second reviewer (if sponsored/regulated)Pitfalls
- Copying a big company's policy that does not fit how you work.
- Banning AI entirely, which usually pushes use underground rather than stopping it.
- Writing the policy and never training anyone on it.
Key takeaways
- A short AI usage policy turns good intentions into consistent, defensible practice.
- Cover principles, tools, data rules, review, accuracy, disclosure, likeness and IP, fairness, automation, security, incidents and training.
- Use checklists, templates and examples, and review the policy at least every six months.
- Prepare a public-facing summary for clients and brands; it builds trust.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Draft your AI usage policy using the thirteen-part structure, create a one-page pre-publish checklist from it, and write a public-facing summary for clients.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.