New to Marqeable? See how it generates leads and wins customers. See the platform→

A One-Page AI Policy for a Marketing Team of 3 (ChatGPT, Claude, and What Never Goes In)

Search for an AI policy template and you get eight-page documents written by HR for a whole company, or by IT for a security review, or by a university for its faculty. They are fine for what they are. A marketing lead at a $20M company who has been told by the CEO “we need a policy on this” does not need eight pages. They need one, and they need it to answer the questions their team actually has: can I paste the customer list in, can I ship what it wrote, does it know how we talk, and who signs off.

This post gives that page. It also names the clause most templates spend their words on and which matters least, and the clause most templates skip which matters most.

Four questions

A marketing team’s AI policy is complete when it answers four questions. Everything else is commentary.

1. What goes in? What information may be given to a model, and what never may.

2. What comes out? What the model’s output is allowed to become. A draft? A published piece? A sent message?

3. What context must it use? What the model has to be given so its output is ours and not generic: the voice, the facts, the claims we are allowed to make.

4. Who approves? Who signs off on what, before it ships, and where that gate lives.

The four map onto the four ways AI goes wrong in marketing. Sensitive data leaks in. Fabricated content ships out. Output is on-brand by luck. Nobody was accountable. Answer the questions and the failure modes have owners.

The template

Copy, edit the bracketed parts, and keep it to a page. If a section grows past four lines, it has become a procedure and belongs in the wiki, linked from here.


AI use in marketing at [Company] Owner: [marketing lead]. Reviewed: [quarterly, next on date].

1. Approved tools and accounts

We use [ChatGPT Team / Claude Team / our marketing system’s built-in agent] on the company accounts only. Personal accounts are not used for company work. The company plan’s terms on data use are [linked]; if you are unsure whether a tool is approved, ask before using it.

2. What goes in

May go in: our public content, our brand voice document, our approved claims file, our published pricing, briefs, drafts, anonymized examples. Never goes in: customer personal data (names with contact details, conversation transcripts, lists), unreleased numbers or plans, contracts, credentials, anything under NDA, anything a customer told us in confidence. If a task needs that data, it runs inside [the marketing system], not in a chat window.

3. What comes out

Model output is a draft, a set of options, a summary, or an analysis. It is never a published piece, a sent message, or a changed record. Every draft passes review before it ships (section 5). No AI tool has write access to anything that sends, publishes, or changes a customer record. Drafting and staging, yes. Sending, never. Sends happen through [the email system / the CRM / the marketing system] after approval, under that system’s consent and compliance rules.

4. What context it must use

Every draft for public use is produced with the brand voice document and the approved claims file attached. Facts about us come from the facts file, not from the model’s memory of our website. Any number, quote, citation or comparison in a draft must trace to a source before it ships ([the review checklist]).

5. Who approves

Pieces: [marketing lead] clears the draft-to-ready gate after the review pass. Anything touching pricing, a named customer, a partner, or a health or financial claim: escalate to [founder / legal]. The founder approves the brand voice, the claims file, and the quarterly brief; not individual pieces.

6. Images and people

Generated images follow the [image QA checklist]. The logo is never generated; it is placed from the real file. No generated image of a real, identifiable person without their written consent. Disclosure of synthetic people in advertising follows the rules where we publish.

7. Records

We keep the brief, the draft history and the approval for every published piece, and note which tool produced generated images. When a question comes later, the answer is a lookup.

8. Disclosure

We do not claim human authorship where it is false. We disclose AI-generated imagery or synthetic likenesses where platform rules or law require it. Ordinary marketing copy drafted with AI and approved by a person carries no disclosure.


The clause that matters least

Most templates spend their longest section on disclosure: whether and how to tell the audience content was AI-assisted. It is the section people argue about, because it feels like an ethics question, and it is the section that prevents the least harm.

Disclosure requirements are real and specific: synthetic performers in advertising in some jurisdictions, AI-generated product imagery on some marketplaces, any false claim of human authorship. Follow them where they apply. But an eight-line disclosure clause does nothing about the email with the fabricated study or the text sent to someone who opted out. Section 8 above is three sentences on purpose.

The clause that matters most

The clause most templates skip is the second paragraph of section 3: no AI tool has write access to anything that sends, publishes, or changes a customer record.

This one line prevents the worst outcomes regardless of what else the policy gets wrong. A model that can only draft cannot send the email with the invented statistic; a person had to approve it, and the review pass had already flagged it. A model that cannot send a text cannot send one to a number that opted out; the send system enforces consent. A model that cannot write to the CRM cannot overwrite the lifecycle stage the sales team relies on.

It is also the clause that keeps section 5 honest. An approval gate is only real if the thing being approved cannot bypass it. The draft-only rule is the engineering version of this argument, and it is the reason the line reads “never” rather than “usually.”

The reversibility test for section 3. If you want to let the AI act rather than draft, apply one test per action: is it reversible, and how many people does it reach? Tagging a contact is reversible and reaches one; let it run. Sending to a list is irreversible and reaches thousands; it waits for the gate. The Air Canada post covers what happens when the line is not drawn.

Making the policy enforce itself

A policy on a page in the wiki is followed on the days people remember it. The four sections are strongest when the tooling makes them the default.

Section 2 holds when sensitive work runs inside a system that has the data, rather than in a chat window where someone has to paste it. Section 3 holds when the drafting tool has no send button. Section 4 holds when the voice document and the claims file are attached to every draft automatically rather than pasted by hand. Section 5 holds when the gate is a state the piece cannot skip.

Marqeable is built to make the page true by default: business context, brand voice and approved claims are attached to every draft; the review pass flags unsourced claims before a person looks; every piece has a draft-to-ready gate owned by an assigned person; the built-in agent and the MCP connection for ChatGPT and Claude are draft-only, so nothing they produce sends or publishes without approval; and sends run under the system’s consent and timing rules. The policy is one page because the system enforces most of it.

Frequently asked questions

What should a marketing AI policy include?

Four things: what goes in (and never goes in), what comes out (drafts, never sends), what context the model must use (voice, facts, claims), and who approves what. It fits on a page.

Do we need to disclose AI-written marketing copy?

Rarely for ordinary copy. Disclosure attaches to specific cases: synthetic likenesses in advertising in some jurisdictions, AI product imagery on some marketplaces, false claims of human authorship. Follow the rules where you publish and keep records.

What is the most important clause?

No AI tool has write access to anything that sends, publishes or changes a customer record. Models draft; people approve; systems send under their own rules.

Is it safe to put company information into ChatGPT or Claude?

Depends on the plan and the data. Name the approved company accounts, and regardless of plan exclude customer personal data, unreleased numbers, contracts and credentials.

The bottom line

A marketing team does not need an eight-page AI policy. It needs one page that answers four questions: what goes in, what comes out, what context it must use, who approves. Spend three sentences on disclosure and one unmissable line on write access, because the second prevents the harm the first only describes. Then choose tooling that makes the page true by default, so the policy is followed on the days nobody remembers it exists.


Marqeable runs your campaigns, answers every visitor, text, and email in seconds, and turns them into booked jobs and meetings - even at 9pm on a Saturday. We’re in private beta with a small early cohort. Get early access

Marqeable
© 2026 Marqeable. All rights reserved.