AI Policy & Governance Standard
Instrumental perspective
We are human-led, AI-accelerated. We use AI to reduce friction, improve clarity, and create better business outcomes—not to remove judgment, accountability, or ownership. AI may assist research, analysis, drafting, workflow execution, personalization, optimization, and internal operations, but accountable humans remain responsible for strategy, approvals, and anything that reaches the market or affects the client’s brand, compliance posture, data, or customer experience.
1. Purpose and scope
• This policy explains how Instrumental uses artificial intelligence in client work and internal operations that support client work.
• It applies to AI-assisted services, AI-enabled workflows, agentic systems, custom automations, analysis, drafting, optimization, reporting, and any supporting structures used to deliver work.
• This policy should be read alongside the governing statement of work, MSA, DPA, security terms, and any client-specific compliance requirements. If a contract imposes stricter requirements, the stricter requirement governs.
2. Our operating principles
• Human-led, AI-accelerated. AI supports the work; accountable humans own the work.
• Outcomes over outputs. We use AI to improve quality, speed, clarity, and leverage—not to create more noise or less accountability.
•Transparent communication. We communicate clearly about where and how AI is used, and we maintain appropriate oversight and controls throughout.
• Momentum with rigor. We ship faster when appropriate, but we do not bypass judgment, review, or controls where risk is meaningful.
• Client-first governance. The higher the brand, compliance, operational, or reputational risk, the more deliberate the human review and approval process becomes.
3. Where AI may be used
• AI may be used to support research synthesis, insight generation, summarization, drafting, creative exploration, audience analysis, SEO/AEO support, data enrichment, structured reporting, workflow automation, personalization, internal knowledge retrieval, QA assistance, and internal productivity.
• AI may also be used inside governed automations, agents, or orchestration layers to move work between systems, trigger actions, or accelerate operational tasks.
4. Human review and approval standard
• Instrumental uses a risk-based review model. Every client-facing output receives human review before release.
• Low-risk uses may include internal summarization, brainstorming, draft structuring, or internal productivity tasks. These still require human validation before client delivery if they inform deliverables.
• Medium-risk uses may include first-draft content, campaign ideation, workflow suggestions, reporting narratives, SEO/AEO recommendations, or internal analysis that feeds a deliverable. These require qualified human review for brand fit, factual soundness, and business relevance.
• High-risk uses include public-facing copy, regulated or compliance-sensitive messaging, workflow automation that affects contacts or records, decision support with material business consequences, customer-facing AI interactions, or anything that could create legal, financial, reputational, or operational risk. These require explicit human approval and, where applicable, client stakeholder approval before go-live.
• No AI-generated or AI-assisted output is considered final solely because a model produced it. Approval authority always sits with a human. Where a client requires specific review checkpoints, approval gates, or disclosure steps, those can be defined at the engagement level.
5. Brand, compliance, and accuracy controls
• Brand alignment is maintained through client-provided materials, approved messaging frameworks, voice/tone guidance, visual rules, documented prompts/instructions, and human editorial review.
• Compliance-sensitive work is reviewed according to the engagement context. Instrumental does not represent AI output as legal, regulatory, medical, or financial advice, and does not treat model output as a substitute for subject-matter or legal review where required.
• Accuracy is maintained through human verification of material claims, cross-checking against source systems or approved source documents, structured QA, and selective testing before deployment.
• Where relevant, we use approval gates, staged environments, spot checks, test records, rollback paths, and validation steps before automation or publishing is turned on.
6. Data handling, privacy, and security
• We apply data minimization principles and use only the data reasonably necessary for the approved use case.
• We do not intentionally input confidential, regulated, or sensitive client data into tools that are not approved for that level of data use.
• Client data remains subject to the confidentiality, privacy, and security obligations set forth in the governing agreement and any applicable data processing terms.
• If a use case would require a materially different data risk profile, Instrumental will raise that before implementation.
7. Prohibited or restricted uses
• Instrumental will not knowingly use AI for deceptive, manipulative, unlawful, discriminatory, or intentionally misleading purposes.
• We do not permit unsupervised AI publishing, unsupervised deployment of high-risk automations, or unsupervised use of AI to make final decisions on behalf of a client where material business, legal, employment, compliance, or customer-impact consequences are at stake.
• We do not treat model-generated claims, citations, or factual statements as inherently reliable without review.
8. Ownership and intellectual property
• Final deliverables created for and paid for by the client are treated as client work product upon payment, consistent with the parties’ agreement. Client ownership of deliverables does not transfer ownership of Instrumental’s underlying systems, tools, or reusable operating components.
• Third-party AI models and platforms remain the property of their respective providers and are governed by those providers’ applicable terms
9. Supporting structures and governed systems
Instrumental may develop and use internal systems, frameworks, and operational infrastructure to make AI use more effective, consistent, and governed. Unless separately scoped for transfer in the governing agreement, these structures are considered Instrumental operating infrastructure, even when used to produce client deliverables.
If a client requires ownership or transfer rights for custom-built work products beyond the standard deliverable scope, that should be explicitly defined in the SOW or MSA, including scope, dependencies, and any ongoing support responsibilities.
10. Monitoring, documentation, and change management
Instrumental reserves the right to evolve its tool stack, prompts, workflows, and governance controls as technology changes, provided the core commitments in this policy remain intact.
11. Client communication standard
We are straightforward about how we use AI. Our goal is not to hide AI use or overstate it. Our goal is to operationalize it with intention and explain it clearly. Where a client requires specific disclosure language, approval checkpoints, or tool restrictions, those can be defined at the engagement level.