A good AI acceptable-use policy for a market research team lists which tools are approved for which data types, specifies what researchers can and can't input, and explains how to flag problems. It should fit on two pages. The goal is to let your team use AI productively without exposing respondent data or client information to unnecessary risk.

I haven't written these policies for teams myself, but I've studied what makes them work and what makes researchers ignore them. The pattern is clear: short, specific, practical policies get followed. Long, vague, legalistic ones get skimmed and forgotten.

Why do most AI policies fail?

Because they're written by people who don't understand how researchers actually work.

The typical policy bans everything specific and allows nothing. "Don't put client data into AI tools." But researchers handle client data all day. They need to know what's actually prohibited and what's fine. A policy that's too broad gets ignored because following it would mean doing nothing at all.

The other failure mode is length. If your policy is 15 pages, nobody reads it. The most effective policies I've seen are short enough to discuss in a team meeting and specific enough that someone knows what to do on a Tuesday afternoon.

What are the essential sections?

Four sections cover almost everything.

Section one: approved tools. List them by name and tier. ChatGPT Enterprise, yes. Consumer ChatGPT, no. Claude Team plan, yes. Free Claude, no. Be specific. Update this quarterly because the landscape changes fast.

Section two: data classification. Three buckets work well. Green for data you can put anywhere (public reports, your own prompts, non-sensitive methodology notes). Yellow for data that needs an approved tool with a data processing agreement (anonymized aggregate findings, draft deliverables). Red for data that never goes into any AI tool (raw PII, client financials, unpublished strategic findings). Give concrete examples in each bucket.

Section three: the approval process. Who can add a new tool to the approved list? What's the review process? How long does it take? If this takes six months, researchers will find workarounds.

Section four: what to do when something goes wrong. Who do you tell? What information do they need? Make this feel like a normal process, not a disciplinary procedure.

Should the policy cover how AI output is used in deliverables?

Yes, absolutely. State that AI-generated content in client deliverables must be reviewed by a human and that researchers are responsible for accuracy regardless of the source. This is becoming a client expectation, and some RFPs now ask about it directly.

How often should the policy be updated?

Every six months, or whenever a major tool changes its terms. Assign one person to own the policy. That person should be someone who uses AI regularly and stays current on the tools. Give them the authority to make minor updates without running a full approval process.

What's a workable outline?

Here's what I'd recommend:

  1. Purpose and scope (two sentences)
  2. Approved tools list (table format)
  3. Data classification guide (three buckets with examples)
  4. Input rules by data type (bullet points)
  5. Output rules (human review required, accuracy responsibility)
  6. New tool approval process (steps and timeline)
  7. Incident reporting (who, what, when)
  8. Policy owner and review schedule

If you're on page three, you're probably overdoing it. The MRS Guidance on AI and Related Technologies and the ICC/ESOMAR International Code are both worth referencing as external standards when building your policy. The Insights Association's Data Quality and Standards resources also provide useful framing, particularly around data integrity.

Go from reading to doing

Browse Classes → Free Newsletter