
What Your AI Policy Should Say About Client Work
A page your team will actually read, covering the four situations that come up. Most policies fail because they were written to satisfy a lawyer rather than to be used on a Friday afternoon.

Most businesses of this size do not need an AI governance framework. They need one page that somebody reads once and remembers.
A twelve page document produced by a lawyer gets filed, and the behaviour it was written to control continues exactly as before.
1. What never leaves your systems
Name the categories specifically rather than describing them.
Not sensitive information, which means nothing to somebody at four on a Friday. Client contracts. Anything containing personal information about an identifiable individual. Financial records. Documents covered by a confidentiality agreement. Anything relating to an active dispute.
Then say where those may be processed, which is usually inside systems you control rather than in a general tool.
One thing worth checking before writing this: your own client agreements may already constrain you. Many contracts in professional services and regulated work contain terms about where information may be processed and who may access it. Feeding that material into a third party tool can breach an agreement signed years ago without anybody involved realising.
2. What must be reviewed before a client sees it
Draw this line by consequence rather than by volume.
An internal summary being wrong costs nothing. A quote, a date, a commitment or a professional recommendation being wrong creates an obligation you did not intend. Anything that creates an obligation goes to a person first.
Be specific about who reviews what, by role. A policy saying output should be reviewed appropriately will not survive a busy week.
3. What you tell clients
Decide the position and give everybody the same words, because your staff will be asked.
Something plain works: we use it for drafting and research, a person reviews everything that reaches you, and here is what we never put into it. Delivered without defensiveness that usually ends the conversation.
What damages you is three people in the business giving three different answers, which is what happens when nobody decided. Evasion converts genuine curiosity into suspicion faster than any admission would.
4. Which tools are approved
Name them. Consumer and business versions of the same product often have completely different terms about whether your input may be used to improve a model, and the interface is identical, so people have no idea which they are on.
Then provide something better than what they found themselves. People use whatever helps them finish the day. If the approved route is slower or more awkward, they will keep using theirs on a personal account where you have no visibility. A ban without a replacement produces the same activity and less oversight.
Where regulation is heading
The European Union’s AI Act entered into force on 1 August 2024 and applies in phases, with prohibitions and AI literacy obligations from 2 February 2025 and further stages through 2026 and 2027.
For a business in Quebec or the United States that is not directly binding unless you place systems on the European market. It matters as a signal of direction, and because your clients may be subject to it, which can make your systems part of their compliance picture.
None of that changes the underlying point, which is that accountability does not transfer. If something goes out with your name on it, it is yours regardless of what produced it or what your supplier’s terms say.
What to log
The record is what protects you when something goes wrong, and it cannot be created retrospectively.
What was asked, what material the system drew on, what it produced, who approved it and when. That costs nothing to build at the start. Businesses without it end up reconstructing events from individual inboxes, which is slow and unconvincing.
Keep it to a page
The test of this document is whether somebody could summarise it accurately a month after reading it.
Four sections, plain language, given to everybody, revisited twice a year because the tools genuinely change. Anything longer is a document written to protect the business from its own staff rather than to help them, and people can tell the difference.
The situations people actually ask about
A policy is judged by whether it answers the questions that come up, and the same four come up everywhere.
Can I paste a client email in to help me draft a reply? Usually yes in an approved system, usually no in a general tool, and the difference needs stating explicitly because it is invisible to the person asking.
Can I use it to summarise a recorded call? Depends entirely on what was recorded and whether the other party knew, which is a separate obligation many businesses have not settled.
Can I use it for something going to a client under my name? Yes, with review, and the review has to be real rather than a glance.
What if I already did something the policy now prohibits? Answer this one in advance and answer it generously. A policy people are afraid to admit breaching produces silence rather than compliance.
Write it with the people who will follow it
Policies written by management and issued downward get read once. Policies written with the two or three people doing the most client work get followed, because those people have already encountered the edge cases.
Half an hour with them will surface situations that would not occur to anybody senior, and it converts the document from a rule imposed into an agreement made.
Review it twice a year
The tools change genuinely and quickly. A policy naming approved products is out of date within a year, and an out of date policy is worse than none because people notice it is stale and stop treating any of it as current.
Twenty minutes, twice a year. What changed, what is now possible that was not, and what mistakes have come up internally since last time. That last item is the most valuable and costs nothing to collect if somebody is paying attention.
Sources
European Commission, Regulatory framework for AI. The AI Act entered into force 1 August 2024; prohibitions and AI literacy obligations applicable from 2 February 2025.
AI Optimize builds the review boundaries, the permissions and the logging into the system itself, so the policy describes what the software already enforces. That work sits under Custom AI Integrations.
Related reading

What AI Literacy Actually Means for Your Team
Europe made it an obligation in February 2025. Whether or not it binds you, the underlying problem is real: most staff using these tools have never been told what they can and cannot rely on.

Who Is Responsible When AI Gets It Wrong
Regulation is arriving on a schedule and most of it will not apply to you directly. The accountability question underneath it will, and it is worth settling before anything goes wrong.
WHAT WE BUILD





