Guides · Updated 2026-09-06

AI Usage Policy for Agencies and Consultants: Client-Safe Rules

Agencies and consultants have a harder AI policy problem than most businesses because the data in their AI tools belongs to somebody else. A marketing agency drafting campaigns, an MSP summarising client tickets and an HR consultant reviewing grievance files are all handling information under contractual confidentiality obligations that were written before generative AI existed. This guide covers the rules that protect client relationships, how to handle disclosure in deliverables, and how firms that advise clients can turn their own policy into a service.

Generate your own firm policy with the free generator first, then see how the Consultant Licence lets you deliver the same kit to clients under your brand.Start the free generator

Client confidentiality is the whole game

Every client contract you hold contains a confidentiality clause, and most of them prohibit disclosing client information to third parties without consent. A public AI service is a third party. If its terms allow the vendor to store, review or train on inputs, pasting client material into it may be a breach even if nothing bad ever happens. The first job of an agency AI policy is to make that connection explicit for every member of staff, because most people do not think of a chat window as a disclosure.

The practical rule is a two-tier approach. Client confidential material may only be used in tools that the firm has contractually confirmed do not train on inputs, that hold data in an acceptable location and that sit within the firm's own managed accounts. Everything else, including public research, the firm's own templates and anonymised scenarios, may use the wider approved list. Keep a per-client note of any stricter requirements the client has imposed, and treat those as overriding the default.

Reading your NDAs and client contracts

Go through your active client agreements and look for three things. First, confidentiality clauses that restrict third-party processing, which most AI usage will trigger. Second, explicit AI clauses, which are becoming common in enterprise agreements and may prohibit AI use outright, require disclosure, or require that outputs be human-reviewed. Third, subcontractor and data processing terms that require you to list or seek approval for sub-processors, since an AI vendor that processes client personal data is a sub-processor in data protection terms.

Where a contract is silent, you have a judgement call. The defensible position is to use only tools with strong data terms for that client's material and to disclose AI use if asked. Where a contract prohibits AI use, the policy must make it easy for staff to know, which is why a client-specific restrictions list belongs in your tool register or project management system, not in a lawyer's inbox.

Disclosing AI in deliverables

Clients increasingly ask, and sometimes contractually require, that you tell them how AI was used in their work. The honest answer is rarely a problem; the discovered answer often is. Set a firm-wide standard on what gets disclosed and how. For most agencies that means a short statement in proposals describing the tools you use and the safeguards around client data, a note in deliverables where AI generated a substantial part of the content, and mandatory labelling of AI-generated images, audio and video that depict real people or events, which is a legal requirement for EU audiences under the AI Act transparency rules.

Disclosure also protects your pricing. If a client learns after the fact that a piece of work they paid for as bespoke was largely generated, the conversation is about trust, not about quality. If they knew from the start and agreed the process, the conversation never happens.

  • State in proposals which AI tools you use and how client data is protected.
  • Note in deliverables where AI produced a substantial part of the content.
  • Label AI-generated or manipulated images, audio and video that could be mistaken for real.
  • Never present AI-generated research, quotes or statistics as verified unless a person has verified them.
  • Keep a record of AI use per project so you can answer a client question accurately later.

Rules specific to each type of firm

Marketing agencies face the most public exposure. Their outputs are published, so fabricated statistics, accidental plagiarism and unlabelled synthetic imagery are the main risks. Verification of any factual claim and a clear rule on labelled visuals belong on the one-page summary. Agencies should also address ownership of prompts and outputs in client contracts, since clients may reasonably expect to own what they paid for.

MSPs and IT consultancies hold the most sensitive access. Client credentials, network diagrams, ticket contents and logs must never enter a general-purpose AI tool, and coding assistants must be configured not to retain client code. The policy should treat any AI integration with client systems as a change requiring client approval. HR consultants handle personal data of the most sensitive kind: grievances, health, performance and dismissal files. Their rule should be that identifiable employee information does not enter AI tools at all, and that any AI-assisted drafting works from anonymised summaries.

Reselling AI policies to your clients

If you advise businesses, you are already being asked about AI policy, and you can turn that from a free conversation into a billable service. The firms doing this well use a repeatable process: run a short discovery with the client on tools, data and use cases, produce a policy and the supporting documents, deliver a short staff briefing and set a review date. The whole engagement can fit in half a day and is a natural add-on for HR consultants, MSPs and compliance advisers.

The Consultant Licence for AI Policy Kit exists for this purpose. It allows you to generate policies for multiple client engagements from one licence and to present the output under your own branding as a white-label kit. That lets you focus your time on the discovery and the briefing, which are the parts clients value, rather than on drafting. Whatever tool you use, be clear with clients that the documents reflect general good practice and that specific legal exposure still warrants review by a qualified adviser.

Your own policy first

A firm that sells AI policy advice without a signed policy of its own is exposed the first time a prospective client asks to see it. Write your own before you write anyone else's. Make it the example you show in the sales conversation, keep the acknowledgement records current, and be ready to describe the one incident you handled well. Nothing sells governance like evidence that you practise it.

Frequently asked questions

Do we need client consent to use AI on their work?
Check the contract. If it restricts third-party processing or contains an AI clause, you likely need consent or must use tools that keep data within your own controlled environment. Where it is silent, use tools with strong data terms and disclose if asked.
Who owns AI-generated deliverables?
Ownership of AI outputs varies by jurisdiction and by the tool's terms. Address it expressly in your client agreement: assign whatever rights you have in the deliverables to the client, and be clear about any third-party or open-licence material included.
Should each client have a different set of AI rules?
Keep one firm policy and record client-specific restrictions in a short list linked from the project. That is easier to maintain than multiple policies and easier for staff to follow.
Can we use AI meeting transcription on client calls?
Only with the client's knowledge and, where personal data is involved, appropriate lawful basis. Tell participants at the start of the call, and check the transcription vendor's data terms before using it for client work.
What does the Consultant Licence allow?
It allows you to generate policies and kit documents for multiple client engagements and to deliver them under your own branding. It is a one-time payment of 149 dollars. It does not include legal advice, which remains the responsibility of a qualified adviser where needed.

Generate your own in about four minutes

Generate your own firm policy with the free generator first, then see how the Consultant Licence lets you deliver the same kit to clients under your brand.

Generate my policy free

Related guides

This guide is general information, not legal advice.