Skip to main content
All thought leadership
Governance6 minute read

Writing an AI Marketing Policy People Will Actually Follow

Most internal AI policies are written to satisfy a risk committee and are then ignored by everyone who has actual work to ship.

Long policies fail quietly

The typical response to artificial intelligence inside a marketing function is a policy document of fifteen pages, circulated once, acknowledged by tick box, and never opened again. It fails in a specific and predictable way. Nobody breaks it deliberately. They simply cannot recall what it said at the moment they were deciding whether to paste a customer list into a chat window.

A policy that governs day to day behaviour has to be short enough to hold in your head. If a marketing coordinator cannot summarise it accurately in a lift, it is not operating as a control. Length is not thoroughness. It is usually the opposite: a long document is often a sign that nobody was willing to make the hard calls, so every position was included.

Four decisions, and the rest is commentary

A workable marketing AI policy makes four decisions and states them plainly.

  • Disclosure: what we tell customers, staff and partners about machine involvement in our work
  • Human sign-off: which categories of output cannot be published without a named person approving them
  • Data boundaries: what information may go into which class of tool, stated as categories rather than brand names
  • Escalation: who to ask when the policy does not obviously cover the situation, and how quickly they answer

Everything else, including tool selection, prompt technique and model preferences, belongs in a working document that changes monthly. Mixing the two is what makes policies stale within a quarter, because the durable principles get buried under advice that expires.

Disclosure without theatre

Disclosure arguments get stuck because teams treat the question as binary. It is not. There is a defensible position between labelling every email footer and saying nothing at all: disclose wherever a reasonable customer would feel misled if they later learned how the work was made.

That test does real work. A product photograph rebuilt by a model needs disclosure. A subject line drafted by a model and edited by a person does not. A synthetic voice in a radio ad probably does. A grammar check clearly does not. Write down your own line and the examples that sit either side of it, because the examples are what people remember.

Data boundaries in Australian conditions

Australian marketers work under privacy expectations that are stricter in practice than the letter of any single rule, largely because customers here react sharply to feeling tracked. Treat that reaction as the operating standard rather than waiting for a regulator to define the floor.

At the level of principle: do not put identifiable customer information into a general purpose tool you do not control and cannot audit. Do not build a dataset for one stated purpose and quietly reuse it for another. Do not assume a global vendor default is calibrated to Australian expectations, particularly when the local team sits a long way from the people making product decisions. If you would not be comfortable explaining the data flow to the customer whose record it is, you have your answer.

The point of a marketing AI policy is not to prevent every mistake. It is to make sure the mistakes that do happen belong to someone who can fix them.

Sign-off means a name

The weakest clause in most policies is the passive one: outputs will be reviewed prior to publication. Reviewed by whom, against what standard, with what authority to say no. If the answer is the marketing team, then nobody is accountable and the review becomes a formality performed at speed on a Friday afternoon.

Name roles instead. Claims about product capability, pricing or performance need sign-off from someone who can verify them. Anything carrying the brand into a regulated conversation needs legal review. Everything else moves at the pace of the team. Being explicit about the low risk category is what makes people take the high risk one seriously.

Revise it when reality tells you to

Set a standing date to revisit the policy, and treat every escalation as evidence. If the same question is escalated three times, the policy is unclear and the fix is a sentence, not a training session. If nothing is ever escalated, the policy is being ignored, and that is worth knowing early rather than after an incident.

Published by the Australian Centre for AI in Marketing

Free to read, free to share, and free of any vendor interest.

Join the Centre

Keep reading

Operating models6 min

The Marketing Team Is Now a Systems Team

Artificial intelligence moves marketing away from producing individual assets and towards designing, supervising and correcting the systems that produce them at volume.

Read
Creative6 min

Brand Voice at Machine Scale

When output volume rises sharply, a brand voice held in the heads of three senior people stops being a standard and becomes a bottleneck.

Read

The monthly briefing

Get the next one when it lands

One email a month, one question worked through properly. If we have nothing worth saying, we do not send.

One email a month. No vendor promotion, ever. Unsubscribe in one click.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now