Skip to content
Academy
Marketing Academy · Field Work●AI in Marketing
MiniBuild the Asset· 30 minutes

Build the One-Pager: Drafting an AI Usage Policy Before an Incident Forces It

Yatharth Hospital & Trauma Care Services

Objective: Given a messy list of the AI tools a marketing team already uses and the gaps in how they're governed, draft a one-page AI usage policy covering all six sections the lesson requires.

You're the marketing coordinator at Yatharth Hospital & Trauma Care Services, the NCR-and-UP hospital chain. Your team has adopted five AI tools this year for patient-facing campaign copy, none of them documented, and a regulator audit is scheduled in six weeks.

Turn the raw list of tools and gaps below into a working one-page policy using the lesson's six required sections.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeDraft and share the one-page policy with the team

Free, versioned, easy to route to a legal or privacy reviewer

The process

1 step

Step 01 of 01

Drafting the six-section one-page AI usage policy

The lesson defines six sections for a working policy: approved tools list, data classification, disclosure rules, vendor checklist, review cadence, and a named owner, and insists it must fit on one page or nobody reads it.

Given that two of the five tools in use have no signed DPA and nobody currently reviews AI-generated patient-facing copy before it publishes, which two sections of the policy need the strongest, most specific language, and which one hard gate stops both problems at once?

Google Docs— Draft directly in a shared doc using the lesson's six-section structure as headers.

Procedure

  1. List the 5 current AI tools by name under 'Approved tools list', mark the 2 without a signed DPA as 'pending review, not yet approved for patient data'
  2. Write the data-classification rule naming patient PII and unreleased campaign pricing as never-paste categories
  3. Write the disclosure rule: any AI-assisted patient testimonial or before/after content gets a visible label before publish, no exceptions
  4. Add the vendor checklist hard gate: no new AI vendor connects to patient data without a signed DPA on file first
  5. Set review cadence to quarterly and name one accountable owner by role, not by name
Sample output
Yatharth Hospital, AI Usage Policy (v1, one page)

1. Approved tools: [Tool A], [Tool B] (DPA on file). [Tool C], [Tool D] (pending review, DPA required before patient data use).
2. Data classification: never paste patient PII, unreleased pricing, or NDA content into any AI tool.
3. Disclosure: any AI-assisted patient testimonial or before/after image carries a visible label before publish.
4. Vendor checklist: no new AI vendor touches patient data without a signed DPA on file first. Hard gate, no exceptions.
5. Review cadence: quarterly, next review scheduled ahead of the regulator audit.
6. Owner: Marketing Compliance Lead.

Healthy

Every current tool is explicitly categorized as approved-with-DPA or pending, and the vendor hard gate is written as non-negotiable.

Unhealthy

A policy that lists tool names but leaves 'pending review' tools connected to real patient data while the review is pending.

What this means

The policy's value is the hard gate, not the document; a beautifully written policy that doesn't disconnect ungoverned data access hasn't fixed anything yet.

So what do I do about it?

SymptomActionEffort
Two tools with patient-data access have no DPA on file, six weeks before an auditSuspend patient-data access for both tools today; restore only once a signed DPA is on file30 min
YouYou can do this yourself, no engineering access required.

Final deliverable

A one-page AI usage policy with all six required sections, one explicit hard gate, and a named owner role.

See a reference example
Sample output
Concord Biotech, AI Usage Policy (excerpt)

4. Vendor checklist: no new AI vendor connects to regulatory-filing or customer data without a signed DPA on file first. Current gap: ad-optimization vendor added in Q1 has no DPA, access suspended pending signature.

Success criteria

You're done when you can:

  • All six required sections are present and specific to the given tool list
  • The vendor DPA gap is written as a hard, non-negotiable gate rather than a soft suggestion