Do not index
What do you say when a client asks how your agency uses AI in their account? Most operators improvise the answer, and clients can tell. The fix is not a compliance binder. It is one page that answers where client data goes and who reviews AI output before it ships. A Forbes piece from July 19 argues small businesses adopted AI one subscription at a time and never wrote the rules, and the numbers behind it are blunt. Intuit's 2026 AI Impact Report, built on more than 34,000 SMB surveys, found 77% use AI daily. A BlackFog and Sapio study found 49% of employees use unapproved AI tools. Adoption outran governance in almost every small shop, probably including yours.
I build AI workflows for agency operations, so this is not an argument against the tools. It is an argument against running them with nothing written down, because the blank page where your policy should be is now costing you deals you never knew you were in.
This is for agency owners between $200k and $2M in revenue, for ghostwriters and content shops charging $5k to $30k per month, and for any 3 person team where client material touches an AI tool every day. If client data moves through your workflows and a renewal conversation is ever on your calendar, this applies to you.
This is not for anyone hoping a policy will let them quietly ban AI and go back to 2022. That fight is over, 77% daily usage says so. Skip this if what you want is ten pages of legal boilerplate to file away and never read. The Forbes piece has a line for that document: "A ten-page policy that has never been reviewed is fiction with a header." If you are still pretending your team does not paste things into chatbots, this article will not change your model.
Shadow AI is already inside your agency
The 49% figure means roughly half of employees are using tools nobody approved, on personal accounts, on free tiers where inputs become training data. In an agency that means client positioning docs, unreleased launch plans, and revenue numbers flowing into accounts you cannot see or audit. The failure mode is not malicious. It is a writer under deadline pasting a client brief into a personal account because the approved route was never defined. There is a quality version of the same problem. When one writer drafts with one model, a second uses a different one, and a third writes cold, the client's account develops three different accents. No client churns over an accent on day one. They churn when the voice they hired you for stops being recognizable, which is why output review belongs in the same conversation as data handling. It is the same principle behind a quality control system that prevents client churn, applied to a new failure point.
Here is the standard I hold my own systems to, what I call the Two Question Test. Question one, where does client data go. Question two, who reviews AI output before it ships. If anyone on your team can answer both in under a minute for any deliverable, you pass. If the answer to either is a shrug, that shrug is your actual AI policy, and eventually a client will hear it. The one page policy is nothing more than the written record of those two answers. Which tools are approved and on which accounts. What client material never leaves your controlled environment, said in plain sentences. Whose name is on the review step for every deliverable type. A name, not a team.
Why your AI policy is now a sales document
The freshest part of the Forbes argument is where these questions now come from. Enterprise clients face AI governance pressure from their own boards and insurers, and they push it down the vendor chain. The questions land in security reviews, procurement forms, and renewal calls. When a client asks how you handle their data in AI tools and you send one clear page within the hour, you read as institutional. When your competitor asks for a week to get back to them, they read as the risk. Same tools, same work, entirely different signal. For a shop billing $10k to $30k per month, that signal shows up at the exact moment the client is deciding whether to keep paying, and it is one of the few trust levers you can build in a single afternoon.
The strategic implication is bigger than any single renewal. AI questions are moving from nice to ask toward standard diligence, the same road security questionnaires traveled a decade ago. The agencies that treat governance as an operating habit will spend the next few years compounding trust while everyone else improvises under pressure. Client trust behaves like content. It compounds quietly, then all at once, and it accrues to whoever wrote things down first.
