Writing an Internal AI Usage Policy for Client Image Work

August 10, 2026 · 7 min read

Somebody on your team is already using an AI editor on client images. That is not a problem in itself, and it is not something you can meaningfully ban. The problem is that nobody has written down which clients agreed to it, which categories of image should never go near it, and whether uploading an unreleased campaign asset to a third-party service breaches the confidentiality clause you signed. A policy fixes that, but only if it fits on one page and answers questions in the order people actually hit them. A twelve-page document produced by committee is functionally the same as having no policy at all.

Write it as decisions, not principles

Policies fail when they are made of values. Use AI responsibly and with human oversight tells a freelancer at eleven at night precisely nothing. What they need is a list they can scan: this is fine, this needs a message to the account lead, this is off limits for this client. Decisions, in the order they arise, with a named person attached to the ambiguous cases.

Keep it to one page and version it with a date. If it takes more than one page, the extra material belongs in a per-client note rather than in the general policy. The general policy should be the same for everyone; the variation lives in the client record.

Make one person the owner. Policies without an owner drift out of date within a quarter as tools change, and an out-of-date policy is worse than none because people follow it and are wrong.

Three tiers that cover most of the work

The first tier is routine correction that a human retoucher would have done anyway: exposure, colour balance, sharpening, straightening, removing a stray cable or a dust mark, replacing a background on a product shot where the product itself is unchanged. For most clients this needs no special approval, because the resulting image still shows what was there.

The second tier is anything that changes how a viewer reads the scene. A new environment behind a product, a materially different lighting mood, removing an object that was part of the setting, anything involving a recognisable person. These go to the account lead before they ship. The check takes a minute and it catches most of the incidents that would otherwise become client calls.

The third tier is prohibited by category rather than by technique. Regulated categories where images carry claims, medical and clinical imagery, news and documentary content, before-and-after imagery in any category, and any image where the edit would alter a subject rather than a photograph. The universal rule underneath all of it: editing changes the photograph, never the subject. A product's real colour, condition, size and material, a person's actual identity and appearance, a property's real features and a clinical result all stay as they were.

  • Tier 1, no approval needed: exposure, colour balance, crop, sharpening, dust and cable removal, clean background swap on a product shot
  • Tier 2, account lead approves: new environments, significant lighting or mood changes, removing scene elements, any image containing a recognisable person
  • Tier 3, prohibited without written client and legal sign-off: regulated and medical imagery, news and documentary, before-and-after claims, anything altering a subject's real characteristics

Track opt-in status per client, not per agency

Clients differ enormously on this, and their position is often set by their own compliance team rather than by the marketer you talk to. Some are enthusiastic. Some permit it for internal comps but not for published assets. Some, particularly in finance, healthcare and public sector work, will have a blanket prohibition you need to know about before an editor discovers it by accident.

Put a single field in the client record with four possible values: approved, approved with conditions, not yet asked, and prohibited. Include the date and the name of who confirmed it. Not yet asked is a legitimate state and should default to treating the client as tier two for everything until answered.

Ask the question during onboarding rather than mid-campaign. It is a neutral, professional question at kickoff and an alarming one halfway through a project. If the client has conditions, write them into the same field in one sentence, for example approved for product and environment work, not for imagery containing employees.

Confidentiality and what leaves your network

Uploading a client's unreleased packaging, an embargoed campaign asset or an image containing identifiable customers to any third-party service is a disclosure. Whether it breaches your NDA depends on the wording, and NDA wording varies enormously. Some permit disclosure to subcontractors and service providers used in performing the work. Some do not, and a few require prior written consent for each one.

Read the confidentiality clause on your largest accounts specifically for this. If the clause is silent or ambiguous, ask the client and get the answer in writing. This is not a legal opinion and the treatment of confidentiality, data protection and cross-border transfer varies by jurisdiction and contract, so where the stakes are high, take advice from someone qualified where you operate.

Separately, set a practical rule about pre-release material regardless of the contract: unreleased assets go through the account lead before touching any external tool, every time. It is a five-word rule that prevents the incident nobody recovers from gracefully.

Vetting a tool before you approve it

Before a tool goes on the approved list, someone has to read its terms rather than its landing page. The questions that matter are narrow: what rights does the provider take over uploaded images, is content used to train models and can that be turned off, how long is data retained, where is it processed, who can access it, and is there a business or enterprise tier with different terms from the consumer one.

Record the answers with the date you checked them, because terms change and a screenshot from eighteen months ago is not a defence. Re-check annually and whenever a provider announces a policy update. Keep the approved list short; every additional tool is another set of terms to track and another place client material lives.

Be precise in the policy about what each approved tool actually does, since overstated capability inside your own documentation causes its own problems. Flora, for example, is a per-image editor for iOS, Android and web: you upload a photo you already have and either apply a named look or describe the edit in words, with results typically back in under a minute. It is not a text-to-image generator, and there is no bulk or batch mode. Writing that accurately in the policy stops anyone building a process around automation that does not exist.

Keep a lightweight record of what was edited

If a client ever asks whether a specific published image was AI-edited, you want to answer in a minute, not spend an afternoon reconstructing it. The record does not need to be elaborate. Filename, date, tool, tier, and a one-line description of the change is enough, kept alongside the job rather than in a separate system nobody opens.

The record earns its keep in three situations: a client compliance review, a platform or regulator query about advertising imagery, and an internal dispute about who approved something. In all three, the absence of a record is what turns a small question into a long one.

Where advertising rules apply to how images are labelled or disclosed, the requirements differ by country, by platform and by product category, and they change. Treat the record as your ability to answer questions accurately rather than as a compliance judgement in itself, and check the current rules with your own regulator or adviser for the markets you work in.

Frequently asked

Do we have to tell clients we used an AI editor?

You should tell them as a matter of professional practice, and many contracts and client compliance policies require it. Beyond that, whether any disclosure is legally required depends on the market, the platform and the product category, and the rules change. Get the client's position in writing at onboarding and check current requirements with your own adviser or regulator.

Can freelancers on our bench use their own tools?

Only tools on your approved list, and the subcontract should say so. A contractor using an unvetted service puts client material somewhere you have no visibility of and no terms for. Include the approved list in the subcontract and require confirmation that the client's material was not uploaded elsewhere.

Which client categories should be off limits by default?

Commonly regulated or sensitive ones: healthcare and clinical imagery, financial services where images support claims, news and documentary, public sector, and anything using before-and-after or transformation imagery. The safe default is tier three until the client, and where relevant their compliance team, says otherwise in writing.

How often should the policy be reviewed?

At least annually, plus whenever an approved tool changes its terms, whenever you take on a client in a regulated category, and whenever an incident happens. Date the document and put the owner's name on it, so it is obvious when it has gone stale.

Try it on your own photo

Flora runs this kind of edit in about a minute — upload a photo, pick a look or describe the change you want, and see the result before you pay for anything.