An AI policy for an agency of fifteen
One page, enforced, beats twelve pages nobody has read. The obligations underneath it are not optional.
A small agency does not need a long AI policy. It needs a one-page document answering four questions: what client data may be sent to which tools, who approves output before it ships, when use must be disclosed, and what is recorded. The obligations underneath those answers come from Canadian privacy law rather than from vendor terms, and the Privacy Commissioner has published named principles that map cleanly onto a short internal policy.
Why the long version fails
Most agency AI policies are three pages of definitions, one paragraph of actual rules, and no enforcement mechanism. They exist to be shown to a client who asked, which is a reasonable purpose and not the same as governing behaviour.
A fifteen-person agency has a specific advantage worth using: everyone can read one page, and everyone can be told the rules in a single meeting. Spend that advantage on clarity rather than coverage.
The test for whether a clause belongs is whether a person could break it. "We use AI responsibly" cannot be broken and therefore cannot be followed. "Client personal information is never pasted into a tool outside the approved list" can be both.
Everything below is written as clauses of that shape.
The obligations the policy sits on
Start from the law rather than from vendor documentation, because the vendor's terms govern the vendor and privacy legislation governs you. Under PIPEDA, organisations are accountable for personal information under their control, including information transferred to a third party for processing, and consent, limiting collection, accuracy and safeguards are named requirements rather than good practice.
The Privacy Commissioner has published guidance specific to generative AI setting out nine principles: legal authority and consent, appropriate purposes, necessity and proportionality, openness, accountability, individual access, limiting collection use and disclosure, accuracy, and safeguards. It states directly that collection and use of personal information should be limited to what is necessary for the purpose, using anonymised or de-identified data where possible.
Two of those nine do most of the work in an agency context. Limiting collection tells you what may leave your systems. Openness tells you what must be disclosed, including that outputs with significant impacts should be meaningfully identified as AI-generated.
The broader hub the Commissioner maintains on AI, technology and innovation is worth reading once by whoever owns the policy, and re-reading when it changes. This is a moving obligation, not a settled one.
Clause one: a data classification with three tiers
| Tier | Examples | Rule |
|---|---|---|
| Red | Client customer lists, CRM exports, form submissions, call recordings | Never sent to any external tool |
| Amber | Account structure, spend, unpublished strategy, contract terms | Approved tools only, no training on inputs, named approver |
| Green | Public copy, published benchmarks, our own templates and boilerplate | Any approved tool |
| Unclassified | Anything not yet placed | Treated as Red until someone classifies it |
Three tiers, because four is where people stop remembering. The default row is the important one: unclassified means Red, so uncertainty resolves toward caution instead of toward convenience.
Red is drawn around personal information specifically, because that is where the legal obligation bites hardest and where a mistake is not recoverable. Once data has left, it has left.
The Amber row carries the condition most often skipped: whether inputs are used to improve the tool. That is a per-tool, per-tier setting, and it belongs on your approved-tools list as a column rather than as an assumption.
Keep the approved-tools list short and dated. A list with fifteen entries and no review date is a list that grew rather than one that was decided.
Clause two: technical enforcement, not just a rule
A rule people can break silently will be broken silently. Where the platform supports it, put a control behind the rule.
Power Platform makes this concrete with data policies, which classify connectors into groups so that data cannot flow between business and non-business connectors within the same flow or app. That is the shape of control worth looking for in any platform your team automates on: a boundary the tooling enforces rather than a sentence in a document.
The administrative side matters too, since data policies are managed at the environment or tenant level by an administrator rather than by whoever built the flow. Same separation as a review gate: the person doing the work does not control the boundary.
Where no technical control exists, say so in the policy rather than pretending. A clause that is honestly on the honour system gets more attention than one that implies enforcement it does not have.
Clause three: review and disclosure
Nothing produced with assistance goes to a client without a named reviewer who is not the author. That is one sentence and it is the highest-value clause in the document.
Disclosure applies to outputs with significant impact, and your policy should define which of your deliverables fall in that category rather than leaving it to judgement per document. Analysis and recommendations that inform a client's spending decision belong in it. Internal drafts and meeting summaries generally do not.
The mechanics of the gate matter more than the wording of the clause. A review standard with named checks and a recorded decision is what makes this enforceable, and knowing the specific failure modes to look for is what makes the review more than a proofread.
State the client's rights too. Some clients will prohibit assisted production entirely in their contract, and your policy should require checking the contract before the tool, not after.
Clause four: what gets recorded, and for how long
Record the production of every client-facing deliverable that used assistance: inputs, queries behind stated numbers, tool and version, reviewer, and whether disclosure applied.
Do not retain conversation transcripts by default. They are long, rarely read, and frequently contain material you would not have chosen to store, which fails the necessity principle while increasing what a breach would expose. The structured record is the useful artifact and it is a fraction of the size.
Set a retention period per record type and attach an actual deletion step. A retention policy with no deletion mechanism is a statement of intent, and intent is not a safeguard.
Where client data is shared deliberately as part of delivery, the same care applies to the ordinary channels. Sharing a dataset with a client has its own access model to get right, and an AI policy that governs tools while ignoring dataset sharing has covered the fashionable risk and left the common one open.
Clause five: what happens when it goes wrong
Include a short incident clause, because the alternative is that a mistake is concealed. Whoever notices tells the policy owner the same day, the policy owner decides whether it is reportable, and nobody is disciplined for reporting.
The reportability question has a legal answer, not an internal one. Canadian organisations subject to PIPEDA must report breaches of security safeguards involving a real risk of significant harm, and the Commissioner publishes what that obligation involves. Read it before you need it.
Name one owner for the policy, with a review date. Twelve months is the longest interval that makes sense in this area, and shorter is defensible.
The credential and access hygiene underneath all of this is not a separate topic. Recovering $41,000 in unauthorised spend after an account compromise came down to who had access to what and how quickly it could be revoked, and an AI policy that ignores access control has protected the data and left the door open. Where an agency needs this operationalised rather than written, that is delivery work: a fractional technical project management engagement should end with the policy, the tool list, the review gate and the owner all in place, not just the document.