Your Agency Needs an AI SOP. Here's the Best Practice — and a Baseline Template You Can Steal.
Somewhere in your agency right now, one of two things is true.
Either there's no written AI policy at all — meaning every writer, strategist, and account manager is making up their own rules about which tools to use, what client data to paste where, and whether to mention any of it — or there's a policy, drafted in a panic last year, that runs eleven pages of legal hedging and has been read start-to-finish by exactly one person: the person who wrote it.
Both states are the same state: improvisation with extra steps. And improvisation is getting expensive. The industry crossed into near-universal adoption — 87% of marketers now use generative AI in at least one workflow — while the governance layer lagged comically behind: only 20% of organizations consistently disclose AI use, and 33% never do, against 84% of consumers who want it disclosed. Clients are asking pointed questions (we wrote the script for answering them), the FTC has published guidance on AI and deceptive practices, and the EU AI Act's transparency rules took effect in August 2026. The era when "we're figuring it out" was an acceptable answer is over.
The good news: a functional AI SOP is not an eleven-page legal document. It's a short operational doc that a new hire can read in ten minutes and follow on their first deliverable. Here's what best practice actually looks like — and a baseline template at the bottom you can copy, fill in, and ship this week.
Seven Best Practices Before You Write a Word
1. Write for the person doing the work, not for a courtroom. The test of an AI SOP isn't legal completeness — it's whether the junior copywriter with a deadline can find the answer to "can I paste this client brief into ChatGPT?" in under thirty seconds. Plain language, concrete examples, decision rules. Legal review comes after usability, not instead of it.
2. Approve tools by name, not by category. "Use reputable AI tools responsibly" governs nothing. A named list — this model, this account tier, this data setting — governs everything, because which tools are approved for client work is the first question every practical AI policy must answer. Critically: distinguish between consumer accounts (where inputs may train models) and business/API tiers (where they typically don't). The same product can be safe on one tier and a confidentiality breach on another.
3. Make data rules follow classification, not vibes. The highest-stakes section of any agency AI SOP is what client information can enter which tools. The workable approach is a simple traffic-light classification — public, internal, confidential/regulated — with explicit rules per tier. This is also where your client contracts already bind you: confirm AI tool use doesn't violate existing data privacy and confidentiality terms before the policy blesses anything.
4. Draw the human line explicitly: AI drafts, humans decide. The cleanest formulation in the compliance literature: AI can draft, flag, classify, and recommend — it should not publish, approve, or override required disclosures without human sign-off. Your SOP should name what "human review" concretely means (accuracy verified, claims sourced, voice edited, AI tells removed) and — this is the part most policies skip — whose name is attached to that review on every deliverable. Accountability that isn't named isn't accountability.
5. Treat disclosure as two different documents. Internal disclosure (what your team logs) and external disclosure (what clients and audiences are told) get conflated constantly. Best practice separates them: internally, AI use is always logged, no exceptions, because you can't answer client questions honestly without records. Externally, agency disclosure is fundamentally contract-bound — if a client requires transparency, disclose; if a client restricts AI, comply or renegotiate scope — with your default posture defined in advance so no account manager is improvising ethics on a live call.
6. Build in the incident path before you need it. Someone will eventually paste confidential data into the wrong tool, ship an unreviewed hallucination, or get a client accusation of undisclosed AI use. A policy without a "what happens next" section converts each of these from a process event into a panic event. Three lines suffice: who gets told, within what timeframe, and what gets documented.
7. Version it quarterly, visibly. Tools, model capabilities, and regulations are all moving; a review step to keep the policy current is a core component, not a nice-to-have. Date the document, number the version, and calendar the review. An AI SOP last touched fourteen months ago is a liability wearing a policy's clothing.
And one meta-practice above all seven: make a one-page client-facing summary. The internal SOP governs your team; the summary version — what we use AI for, what stays human, how your data is protected — becomes a sales asset. With only about 20% of organizations disclosing consistently, simply having a clear, confident answer puts you ahead of most of the market before the pitch even starts.
The Baseline Template
Below is a starting-point SOP sized for a small-to-mid agency. Copy it, replace the bracketed items, delete what doesn't apply, and have someone accountable sign it. It is deliberately minimal — a baseline to be grown, not a ceiling.
[Agency Name] — AI Use Standard Operating Procedure
Version: 1.0 · Effective: [date] · Owner: [name, title] · Next review: [date + 3 months]
1. Purpose & Scope
This SOP governs all use of generative AI tools in work performed by [Agency Name] employees and contractors, on both client and internal projects. It exists to protect client data, ensure the quality and honesty of our work, and let us answer any client's questions about our AI use completely and truthfully.
2. Approved Tools
Only the tools below, on the specified account tiers, may be used for client work. Anything not listed requires written approval from [owner] before first use.
ToolApproved tier/accountApproved usesNotes[e.g., Claude][Team/API account only]Research, drafting, editing[Training opt-out confirmed][e.g., ChatGPT][Business tier only][Brainstorming, outlines][No consumer accounts][e.g., image tool][Tier][Internal concepts only][No client-facing output without license review]
Personal/consumer accounts may never be used for client work.
3. Data Classification & Input Rules
Before entering anything into an AI tool, classify it:
🟢 Public (published content, public websites, general briefs with no identifying details): may be used in any approved tool.
🟡 Internal (unpublished strategy, client names, campaign plans): approved business-tier tools only, with model-training opt-out confirmed.
🔴 Confidential/Regulated (financials, PII, health/legal/financial client data, anything under NDA, credentials): never entered into any AI tool without written approval from [owner] and confirmation the client contract permits it.
When in doubt, treat it as 🔴 and ask.
4. Permitted & Prohibited Uses
AI may be used for: research synthesis, outlines and structure, first drafts, rewriting and editing assistance, brainstorming, summarizing approved source material, code assistance, internal process documents.
AI may not be used for: final published copy without human review per §5; factual claims without human source verification; fabricating quotes, testimonials, reviews, data, or citations; legal, medical, or financial claims without qualified review; impersonating real people; any client account where the contract restricts AI use.
5. Human Review Standard
No AI-assisted output ships to a client or publishes anywhere until a named human reviewer has:
Verified every factual claim against a real source;
Confirmed all quotes, statistics, and citations are genuine;
Edited for client voice and removed generic AI patterns;
Checked for IP/plagiarism risk in anything closely resembling existing work;
Attached their name as reviewer in [project management system].
The reviewer — not the tool, not the drafter alone — is accountable for the deliverable. AI drafts; humans decide.
6. Disclosure
Internal (always): All material AI use on client deliverables is logged in [system/field] — tool, use, reviewer. No exceptions; we cannot be honest externally without records internally.
To clients: Our default posture is proactive transparency: we describe our AI-assisted, human-finished process during sales and onboarding [link client-facing one-pager]. Client contracts govern specifics; where a client requires additional disclosure or restricts AI, the account lead ensures compliance or escalates to [owner] for scope renegotiation. Account teams never deny or misrepresent AI use.
Public-facing: Where law or platform policy requires labeling (e.g., EU AI Act transparency obligations, platform synthetic-media rules), [owner/compliance contact] determines the labeling standard before publication.
7. Incidents
If client data enters an unapproved tool, an unreviewed AI output ships, a hallucination is discovered post-publication, or a client raises an AI-related concern: notify [owner] within [24 hours], document what happened in [location], and do not communicate with the client about the incident until aligned with [owner]. Honest, fast correction is the standard; concealment is a fireable offense.
8. Training & Acknowledgment
Every employee and contractor reviews this SOP at onboarding and at each version update, and acknowledges in writing. Questions and proposed tool additions go to [owner].
9. Version History
VersionDateChangesApproved by1.0[date]Initial baseline[name]
Rolling It Out (The Part That Determines Whether It's Real)
A policy PDF emailed on a Friday is a compliance theater prop. Four moves make it operational:
Train it in one working session, not a memo. Walk the team through real scenarios from your actual accounts: this brief, this tool, this classification — allowed or not? Twenty minutes of cases beats twenty pages of prose, and it surfaces the ambiguities your v1.0 missed.
Align the contracts. Your SOP promises things your MSAs and client agreements should reflect: an AI clause covering use, confidentiality, IP ownership of outputs, and accuracy accountability. If your contracts predate your AI practice — most do — this is the quarter to fix them.
Publish the one-pager and use it offensively. Attach the client-facing summary to proposals and onboarding decks. Then, when the "do you use AI?" question comes — and it comes in every sales cycle now — your answer is a confident, documented "yes, and here's exactly how," while competitors improvise. Governance, done visibly, converts.
Actually review it quarterly. Fifteen minutes on the calendar: new tools requested, incidents logged, regulation moved, anything unclear in practice. Bump the version number even when changes are small — the visible cadence is what tells your team (and your clients) the document is alive.
Where We Stand on All This
For the record, since our whole model is publishing what we practice: this framework mirrors our own. We tell every client exactly where AI sits in our process and where humans are irreplaceable, we treat the human review layer as the product (it's where AI's tells and inherited framings get caught), and we think the agencies that formalize this now are building the same kind of moat we've argued for everywhere else: in an era when anyone can generate confident output, verifiable trustworthiness is the scarce asset. An AI SOP isn't paperwork. It's the operating system of that trust.
Frequently Asked Questions
What should a marketing agency's AI SOP include at minimum?
Eight sections cover the baseline: purpose and scope; a named approved-tools list with account tiers; data classification rules governing what client information can enter which tools; permitted and prohibited uses; a human review standard with named accountability per deliverable; disclosure rules (internal logging, client-facing posture, public labeling); an incident process; and a version/review cadence. The four-pillar core — approved tools, data rules, disclosure standards, and a currency review — is the non-negotiable center; everything else extends it.
Should agencies disclose AI use to clients by default?
Proactive transparency is the strongest posture, and the contract is the governing document. Agency disclosure in practice is contract-bound — where clients require transparency, disclose; where they restrict AI, comply or renegotiate — but defaulting to openness wins on the numbers: 84% of consumers want AI content disclosed while only ~20% of organizations do so consistently, and clients who discover undisclosed use treat it as deception rather than process. The one absolute: never deny or misrepresent AI use. Everything survivable follows from that rule; nothing after breaking it does.
What client data can safely be entered into AI tools?
Only what your classification system and client contracts explicitly permit. A practical baseline: public information freely in approved tools; internal but non-sensitive material only in business-tier tools with model-training opt-outs confirmed; and confidential, regulated, or NDA-covered data never entered without written approval and contractual clearance. The tier matters as much as the tool — consumer accounts of the same product often carry different training and retention terms than business or API tiers, and existing client privacy terms bind you regardless of what any tool's settings allow.
Who should be accountable for AI-assisted work in an agency?
A named human reviewer on every deliverable, plus a named policy owner for the SOP overall. The compliance principle worth adopting verbatim: AI can draft, flag, and recommend, but it should not publish or approve without human sign-off— and sign-off only means something when a specific person's name is attached in your project system. Diffuse accountability ("the team reviews everything") is how hallucinations ship; named accountability is how they get caught.
How often should an AI SOP be updated?
Quarterly reviews with dated versioning, plus immediate updates when a new tool is approved, an incident reveals a gap, or a regulation changes — the EU AI Act's transparency obligations and evolving FTC guidance being current examples. The cadence matters as much as the content: a visibly maintained document signals to staff and clients that the policy is operational, while a stale one signals the opposite regardless of how well it was originally written.
Is an AI policy really necessary for a small agency?
Small agencies arguably need it most: fewer process layers mean individual improvisation reaches clients faster, and a single data mishap or undisclosed-AI accusation lands on a brand with no cushion. The countervailing advantage is that a small shop can implement in a week what an enterprise takes quarters to roll out — and then use the clarity as a sales weapon, because in a market where most competitors mumble about their AI practices, the firm with a one-page answer wins the trust question by default.
Ship Version 1.0 This Week
The perfect AI policy you'll write next quarter is worth less than the honest baseline you ship Friday. Copy the template, fill in the brackets, run the one training session, and put your name in the owner field — then let it grow with your practice.
And if you're a business evaluating agencies rather than running one: ask every candidate for their AI SOP and their client-facing summary. The ones who have them will send them within the hour. We're happy to be tested first.
Book a free 30-minute strategy call → Principals on the call, our AI practices on the table, and an honest read on your visibility — within one business day.
Sources
Fractl — AI Search Consumer Trust Study 2026 (disclosure gap: 20% always / 33% never vs. 84% consumer demand)
ContentGrip — AI Trust Drops as Usage Rises (governance and disclosure findings)
Digital Applied — AI Marketing Statistics 2026 (87% generative AI adoption, Salesforce State of Marketing)
AI Smart Ventures — AI Tools for Small Marketing Studios and Agencies in 2026 (four-pillar policy framework; contract and FTC considerations)
Luthor — AI Marketing Compliance Guide 2026 (AI drafts / humans approve principle; oversight and logging)
WriteBros — Should AI Writing Be Disclosed? 2026 Guidelines (contract-bound agency disclosure posture)
Kapwing — AI Disclosure, Detection, and Trust Statistics (EU AI Act transparency timing; labeling expectations)