Enterprise marketing teams have an AI policy, a legal team to write it, and a compliance function to enforce it. Most lean teams have a Slack channel called #ai-tools and a general sense that someone should probably write something down but too mnay other things to worry about actually doing it. That gap was once ok, but the rules are changing very quickly.
Why this is suddenly not optional
The EU AI Act’s transparency rules (Article 50) come into force on 2 August 2026. They require AI-generated content to be marked in a machine-readable way and, for certain categories like deepfakes and content published to inform the public, clearly and visibly labelled. There’s a grace period for systems already on the market, but the direction of travel is clear: “we didn’t think about it” is no longer ok.
In the US, FTC guidance now expects two separate disclosures on AI-involved content: one for the commercial relationship (it’s an ad or sponsored content) and one for the AI involvement (it was created or substantially modified by AI). A hashtag reading #ad doesn’t cover the AI disclosure, and “AI-generated” on its own doesn’t cover the commercial one. Both need to be there.
What enterprise teams have that you don’t
A big team’s AI policy usually runs to several pages, with sign-off workflows, a tool approval committee, and a compliance officer to chase exceptions. A small team doesn’t need that version, and trying to build it is how the policy never actually gets written. What a lean team needs is the smallest document that explicitly guides people on the rules to follow to stay compliant.
The one-pager
Here’s where I would start. Four sections, fit it on one page.
1. Approved tools. Name them specifically. If it’s not on the list, it’s not approved for company work, full stop. This alone closes most of the actual risk, because most AI incidents start with someone using a personal, consumer-tier account for something that should never have left a sanctioned tool.
2. What never goes near a consumer-tier tool. Customer data, anything under NDA, unreleased product information, anyone’s personal information beyond a first name. Write the actual list. “Be careful with sensitive data” isn’t a policy, be specific.
3. A disclosure standard. Decide, in advance, what gets an AI disclosure and what doesn’t. A reasonable lean-team line: anything published externally that was substantially drafted or generated by AI gets a disclosure; internal drafts and AI-assisted editing of your own original writing don’t. Write the line down so nobody’s guessing case by case.
4. An editorial review step before anything ships externally. One person (named), or one set rule: no AI-assisted external content goes out without a human read-through against the source material first. This is the step that catches both compliance problems and the plainer risk of publishing something confidently wrong.
The real risk isn’t legal
Here’s the part worth remebering. The realistic risk for most lean teams isn’t a regulator, and it’s unlikely to be the first thing that goes wrong. It’s brand erosion from quietly shipping flat, generic AI output that reads like nobody actually cared, at a volume that makes the pattern obvious to your audience. Regulation is the reason to write the policy down sooner rather than later. Protecting your brand and audience trust is the reason to do it well and follow it.
Dom O'Brien
CMO at MATE and author of The Startup Marketing Playbook. Fifteen years building lean marketing teams that punch above their weight.
Work with Dom →