Admissions open Take the eligibility test & see if you can join the next batch. Take the test →
Template H7 · CMO / Head of Digital

AI Governance and Marketing Policy.

What AI may touch, what it may not, who verifies, and what we disclose. A policy you can put in front of a legal team rather than a set of good intentions.

The decision this template protects

Where AI is permitted in this function, and who remains accountable for the output.

CMO / Head of Digital Base Module · AI and intelligence systems primer Version 1.0 · 19 August 2026
Fill it in your browser → Download the PDF · 4 pages · 156 KB ↓

The browser version keeps everything on your device. Nothing you type is sent to aFactor.

Before you start, you need

What has to be true first.

  • An honest inventory of how AI is currently being used, including uses nobody has approved.
  • Legal or compliance contact.
  • The client or customer data your team touches.
What this template will not do for you

Its stated limits.

  • It is not legal advice. Take the completed policy to somebody qualified before adopting it.
  • It will go stale. Tool capabilities and settings change constantly. Check the review date on this page.
  • It cannot address model bias or output quality, only accountability and permitted use.
  • A policy nobody enforces is worse than none, because it creates documented negligence.
What is in it

5 sections, and what each one makes you write down.

01

Permission tiers

  • Tier
  • What it covers
  • Approval
  • Verification
02

Data rules

  • Data type
  • May it go into an AI tool?
  • Which tools
  • Conditions
03

Accountability

04

Disclosure

  • Context
  • What we disclose
  • Decided by
05

Review and enforcement

  • Item
  • Owner
  • Cadence
  • What happens when the policy is breached
Judgment prompts

Questions the template makes you answer.

  1. Which tier is your team already operating outside, without approval?
  2. If a customer asked whether a piece of your content was AI-generated, what would you say, and is it the same answer you would give a journalist?
  3. Who checked the retention settings on your approved tools, and when?
  4. Is there anything on the black list that somebody in your organisation would currently see as a grey area?
The defensible output

What you are left holding.

An adopted policy with four permission tiers, data rules, a named accountable human per output, and a disclosure standard set at policy level.

Published open. Copy it, adapt it, use it on client work. If you pass it on, keep the attribution line on it.

More from the library

Sixty-five instruments, eighteen published open.

Each one names the decision it protects, states what it will not do, and ends in something you could defend six months later.