
Responsible AI Usage Policy
How we use AI responsibly across everything we do.

Responsible AI Usage Policy
How we use AI responsibly across everything we do.

Responsible AI Usage Policy
How we use AI responsibly across everything we do.

Responsible AI Usage Policy
How we use AI responsibly across everything we do.

Responsible AI Usage Policy
How we use AI responsibly across everything we do.
Owner: Alex Holliman, Managing Director
Version: 1.1
Last reviewed: June 2026
Next review: April 2027, or sooner if the technology or regulations change
1. Purpose and scope
We use AI to do better work, more efficiently. That means smarter analysis, sharper insights, and more time spent on the things that actually move the needle for our clients. What it does not mean is replacing human judgement, or cutting corners on quality or ethics.
This policy sets out how we use AI responsibly across everything we do. It applies to:
How we work internally, across drafting, summarising, researching, and organising.
The work we deliver to clients, including paid search, paid social, affiliate, SEO, content, digital data analysis, and beyond.
The third-party tools and platforms we rely on to do that work.
One thing never changes, regardless of what AI is involved: our team remains accountable for every output and every decision. AI helps us; it does not replace us.
2. Core principles
These are the values that guide how we approach AI. They sit alongside our wider B Corp commitments and reflect who we are as an agency.
Human oversight. A real person reviews anything that matters, we don’t copy and paste from Claude, Gemini, ChatGPT, Perplexity or Ask Jeeves.
Transparency. We are open with clients about when and how we use AI.
Fairness. We actively look out for bias or harm in AI outputs.
Privacy first. We use the appropriate amount of data necessary and protect it properly.
Integrity. We use AI because it adds genuine value, not simply because we can.
Environmental awareness. We are mindful of the energy footprint of the tools we use.
Processing. We do not send long AI-generated transcripts or documents to clients or colleagues without editing them first. That just shifts the work of finding the key points on to them.
Client work. Presenting AI-generated work to clients as original team output, without human checking, proofing, or amendment, is not acceptable. Where this leads to client complaints or loss of business, a formal disciplinary process will be initiated for the team members involved.
3. Risk classification
Not all AI use carries the same level of risk. We classify it into three tiers, each with its own requirements for review, approval, and documentation.
Low risk
Internal productivity tasks such as drafting, summarising, or organising information. These need standard good judgement, but no formal sign-off.
Medium risk
Client-facing outputs that are not particularly sensitive, such as ad copy, keyword clustering, and research summaries. These need a human review before anything is shared.
High risk
Anything that involves personal data, automated decision-making, regulated industries, or large-scale content published without a full review. High-risk use needs explicit approval, documented oversight, and a clear record of the checks applied.
4. Data protection and privacy
We take data protection seriously. Here is how we approach it when AI is involved:
We do not enter client data into AI tools without their explicit approval.
Where possible, we use enterprise-grade tools with appropriate data protections, rather than free public tools.
We never input personally identifiable information (PII) or sensitive commercial data into tools that may use it for model training.
The tools we use comply with GDPR and other relevant data protection frameworks.
We apply appropriate encryption and access controls to all AI-generated outputs that contain sensitive information.
We have clear rules on how long AI-related data is kept, and how it is deleted.
If you are unsure whether it is safe to input specific data into an AI tool, check first. When in doubt, leave it out.
5. Security and compliance
We maintain a list of approved AI tools. Using a tool that is not on the approved list needs a risk assessment first.
All approved tools are password-protected and, where applicable, require multi-factor authentication (MFA, a second verification step beyond just a password).
Before approving a new tool, we assess the vendor’s security posture, including their published security credentials where available.
We regularly review our approved tools list to make sure it stays current.
We have an incident response plan for data breaches and AI misuse. If something goes wrong, we know what to do.
6. Legal and ownership
AI raises some genuinely novel legal questions. Here is where we stand:
AI and human-generated outputs created as part of client work are typically owned by Climbing Trees. We make this clear in our contracts.
We are transparent about the limitations that may apply to IP (intellectual property) protection for AI-generated content.
We never knowingly use AI to produce content that infringes copyright or misuses trademarks.
Any AI-generated content that will be published goes through a human originality check.
Our client agreements include clear language around AI use, so there are no surprises.
7. Ethical considerations
Being ethical is not just one of our values. It is the lens through which we make every decision. When it comes to AI, that means:
We do not use AI to create harmful, misleading, or manipulative content.
We do not generate fake reviews, deceptive ads, or content that impersonates individuals or brands.
We actively look for bias in outputs, whether in language, audience targeting, or data interpretation, and we act on what we find.
We prefer tools from providers who are transparent about how their models are trained.
Everything we do with AI reflects our B Corp values: honest, caring, and built for long-term good.
8. Responsible use in marketing
This is the bit that matters most for us as a marketing agency. AI can be a brilliant tool for client work, but only when it is used thoughtfully. Here is the starting point for what we will do, and what we will not do.
What we use AI for
Drafting ad copy, with human review before anything goes live.
Identifying patterns in data and surfacing insights.
Ideation, research, and exploring new approaches.
What we do not do
Set-and-forget AI optimisation. We always keep human oversight of campaign decisions.
Fully automated client deliverables without a person checking and signing off.
Sensitive audience targeting without proper scrutiny of the approach and the outputs.
AI is here to enhance our thinking, not replace it. The strategy, the judgement, and the accountability stay with our team.
9. Transparency with clients
We are open about how we work. That includes being upfront about when AI plays a role.
We tell clients when AI is used in their work, what it was used for, and why.
Clients can ask us not to use AI on their account, and we will respect that.
We explain the benefits, the limitations, and the risks in plain language. No jargon, no spin.
We will never present AI-generated work as purely human-created.
Building trust with our clients means being honest, even when the answer is a little more complicated than ‘we did it all ourselves’.
10. Accuracy and quality control
AI can get things wrong. Our process is designed to catch that before it reaches a client.
Nothing produced with AI goes live without a human review.
Facts, data, and insights are verified before they appear in client-facing work.
Every output has a named owner. Someone who has checked it and takes responsibility for it.
We document where AI was used and what checks were applied, so there is a clear record.
11. Bias and fairness
AI systems can reflect biases from the data they were trained on. We take that seriously.
We review outputs for language, targeting, and messaging that could be inadvertently discriminatory.
Where it is relevant, we bring diverse perspectives into the review process.
We monitor our campaigns for unintended bias on an ongoing basis, and act quickly when we spot it.
12. Environmental considerations
AI has an energy cost, and as an agency with genuine environmental commitments, we do not ignore that.
We prefer efficient AI tools and avoid unnecessary large-scale content generation.
We use AI proportionately. Only where it genuinely adds value, not just because it is available.
We factor environmental impact into our vendor assessments alongside security and capability.
We will report on the carbon impact of our activities and work with our supply chain on the issues that shape sustainability.
13. Training and internal governance
This policy only works if everyone understands it. We invest in making sure they do.
Every team member completes mandatory training on safe, ethical AI use and data handling.
We provide clear internal guidelines and practical playbooks for using AI in day-to-day work.
We have a named AI lead who is responsible for keeping this policy current and championing good practice.
Alex Holliman, Managing Director, will review this policy at least every 12 months, or sooner if the technology or the regulations change significantly.
14. Tooling and vendor management
We are thoughtful about which AI tools we use. Before anything makes it onto our approved list, it goes through a proper assessment.
Our approved tools list includes a risk rating and a clear note on what each tool should and should not be used for.
Any new tool needs a risk assessment before we bring it into our workflow.
We monitor vendor policies and update our assessments when providers make significant changes.
We do not approve tools just because they are popular. They have to be right for how we work and for the people whose data we are handling.
15. Monitoring, auditing, and continuous improvement
We hold ourselves accountable. That means regularly checking that what we say we do is what we actually do.
We audit AI usage across client work on a regular basis.
We log where AI is used and keep records of any incidents or concerns that arise.
We gather feedback from the team and from clients to understand what is working and what needs to improve.
This policy evolves as the technology evolves. We will never treat it as a document that just sits on a shelf.
16. Prohibited uses
Some things are simply off the table. Being explicit about this helps everyone understand where the line is.
Inputting confidential client data into unapproved AI tools.
Generating misleading, deceptive, or manipulative marketing content.
Producing content that infringes copyright or misuses trademarks.
Delivering client work that has been fully automated, without any human oversight or sign-off.
Using AI to impersonate individuals, brands, or real people.
If you are ever unsure whether something falls into this category, ask before you proceed.
17. Escalation and risk management
When something does not feel right, we want people to say so. Here is how that works:
Any team member can raise a concern about AI use. There is no wrong time to do that.
High-risk use cases must be escalated to the AI lead for approval before work begins.
Named decision-makers are responsible for approving or rejecting applications that fall into the high-risk category.
We would rather pause and check than move quickly and get something wrong.
18. Documentation and record keeping
Good governance needs good records. Here is what we keep track of:
The AI tools used across different projects and clients.
Risk assessments carried out before adopting new tools.
Client’s requesting to opt out of AI usage or any part of it.
Any incidents, concerns, or escalations that have been raised.
This policy is version controlled. Every update is dated and recorded so we always know what version we are working from.
Owner: Alex Holliman, Managing Director
Version: 1.1
Last reviewed: June 2026
Next review: April 2027, or sooner if the technology or regulations change
1. Purpose and scope
We use AI to do better work, more efficiently. That means smarter analysis, sharper insights, and more time spent on the things that actually move the needle for our clients. What it does not mean is replacing human judgement, or cutting corners on quality or ethics.
This policy sets out how we use AI responsibly across everything we do. It applies to:
How we work internally, across drafting, summarising, researching, and organising.
The work we deliver to clients, including paid search, paid social, affiliate, SEO, content, digital data analysis, and beyond.
The third-party tools and platforms we rely on to do that work.
One thing never changes, regardless of what AI is involved: our team remains accountable for every output and every decision. AI helps us; it does not replace us.
2. Core principles
These are the values that guide how we approach AI. They sit alongside our wider B Corp commitments and reflect who we are as an agency.
Human oversight. A real person reviews anything that matters, we don’t copy and paste from Claude, Gemini, ChatGPT, Perplexity or Ask Jeeves.
Transparency. We are open with clients about when and how we use AI.
Fairness. We actively look out for bias or harm in AI outputs.
Privacy first. We use the appropriate amount of data necessary and protect it properly.
Integrity. We use AI because it adds genuine value, not simply because we can.
Environmental awareness. We are mindful of the energy footprint of the tools we use.
Processing. We do not send long AI-generated transcripts or documents to clients or colleagues without editing them first. That just shifts the work of finding the key points on to them.
Client work. Presenting AI-generated work to clients as original team output, without human checking, proofing, or amendment, is not acceptable. Where this leads to client complaints or loss of business, a formal disciplinary process will be initiated for the team members involved.
3. Risk classification
Not all AI use carries the same level of risk. We classify it into three tiers, each with its own requirements for review, approval, and documentation.
Low risk
Internal productivity tasks such as drafting, summarising, or organising information. These need standard good judgement, but no formal sign-off.
Medium risk
Client-facing outputs that are not particularly sensitive, such as ad copy, keyword clustering, and research summaries. These need a human review before anything is shared.
High risk
Anything that involves personal data, automated decision-making, regulated industries, or large-scale content published without a full review. High-risk use needs explicit approval, documented oversight, and a clear record of the checks applied.
4. Data protection and privacy
We take data protection seriously. Here is how we approach it when AI is involved:
We do not enter client data into AI tools without their explicit approval.
Where possible, we use enterprise-grade tools with appropriate data protections, rather than free public tools.
We never input personally identifiable information (PII) or sensitive commercial data into tools that may use it for model training.
The tools we use comply with GDPR and other relevant data protection frameworks.
We apply appropriate encryption and access controls to all AI-generated outputs that contain sensitive information.
We have clear rules on how long AI-related data is kept, and how it is deleted.
If you are unsure whether it is safe to input specific data into an AI tool, check first. When in doubt, leave it out.
5. Security and compliance
We maintain a list of approved AI tools. Using a tool that is not on the approved list needs a risk assessment first.
All approved tools are password-protected and, where applicable, require multi-factor authentication (MFA, a second verification step beyond just a password).
Before approving a new tool, we assess the vendor’s security posture, including their published security credentials where available.
We regularly review our approved tools list to make sure it stays current.
We have an incident response plan for data breaches and AI misuse. If something goes wrong, we know what to do.
6. Legal and ownership
AI raises some genuinely novel legal questions. Here is where we stand:
AI and human-generated outputs created as part of client work are typically owned by Climbing Trees. We make this clear in our contracts.
We are transparent about the limitations that may apply to IP (intellectual property) protection for AI-generated content.
We never knowingly use AI to produce content that infringes copyright or misuses trademarks.
Any AI-generated content that will be published goes through a human originality check.
Our client agreements include clear language around AI use, so there are no surprises.
7. Ethical considerations
Being ethical is not just one of our values. It is the lens through which we make every decision. When it comes to AI, that means:
We do not use AI to create harmful, misleading, or manipulative content.
We do not generate fake reviews, deceptive ads, or content that impersonates individuals or brands.
We actively look for bias in outputs, whether in language, audience targeting, or data interpretation, and we act on what we find.
We prefer tools from providers who are transparent about how their models are trained.
Everything we do with AI reflects our B Corp values: honest, caring, and built for long-term good.
8. Responsible use in marketing
This is the bit that matters most for us as a marketing agency. AI can be a brilliant tool for client work, but only when it is used thoughtfully. Here is the starting point for what we will do, and what we will not do.
What we use AI for
Drafting ad copy, with human review before anything goes live.
Identifying patterns in data and surfacing insights.
Ideation, research, and exploring new approaches.
What we do not do
Set-and-forget AI optimisation. We always keep human oversight of campaign decisions.
Fully automated client deliverables without a person checking and signing off.
Sensitive audience targeting without proper scrutiny of the approach and the outputs.
AI is here to enhance our thinking, not replace it. The strategy, the judgement, and the accountability stay with our team.
9. Transparency with clients
We are open about how we work. That includes being upfront about when AI plays a role.
We tell clients when AI is used in their work, what it was used for, and why.
Clients can ask us not to use AI on their account, and we will respect that.
We explain the benefits, the limitations, and the risks in plain language. No jargon, no spin.
We will never present AI-generated work as purely human-created.
Building trust with our clients means being honest, even when the answer is a little more complicated than ‘we did it all ourselves’.
10. Accuracy and quality control
AI can get things wrong. Our process is designed to catch that before it reaches a client.
Nothing produced with AI goes live without a human review.
Facts, data, and insights are verified before they appear in client-facing work.
Every output has a named owner. Someone who has checked it and takes responsibility for it.
We document where AI was used and what checks were applied, so there is a clear record.
11. Bias and fairness
AI systems can reflect biases from the data they were trained on. We take that seriously.
We review outputs for language, targeting, and messaging that could be inadvertently discriminatory.
Where it is relevant, we bring diverse perspectives into the review process.
We monitor our campaigns for unintended bias on an ongoing basis, and act quickly when we spot it.
12. Environmental considerations
AI has an energy cost, and as an agency with genuine environmental commitments, we do not ignore that.
We prefer efficient AI tools and avoid unnecessary large-scale content generation.
We use AI proportionately. Only where it genuinely adds value, not just because it is available.
We factor environmental impact into our vendor assessments alongside security and capability.
We will report on the carbon impact of our activities and work with our supply chain on the issues that shape sustainability.
13. Training and internal governance
This policy only works if everyone understands it. We invest in making sure they do.
Every team member completes mandatory training on safe, ethical AI use and data handling.
We provide clear internal guidelines and practical playbooks for using AI in day-to-day work.
We have a named AI lead who is responsible for keeping this policy current and championing good practice.
Alex Holliman, Managing Director, will review this policy at least every 12 months, or sooner if the technology or the regulations change significantly.
14. Tooling and vendor management
We are thoughtful about which AI tools we use. Before anything makes it onto our approved list, it goes through a proper assessment.
Our approved tools list includes a risk rating and a clear note on what each tool should and should not be used for.
Any new tool needs a risk assessment before we bring it into our workflow.
We monitor vendor policies and update our assessments when providers make significant changes.
We do not approve tools just because they are popular. They have to be right for how we work and for the people whose data we are handling.
15. Monitoring, auditing, and continuous improvement
We hold ourselves accountable. That means regularly checking that what we say we do is what we actually do.
We audit AI usage across client work on a regular basis.
We log where AI is used and keep records of any incidents or concerns that arise.
We gather feedback from the team and from clients to understand what is working and what needs to improve.
This policy evolves as the technology evolves. We will never treat it as a document that just sits on a shelf.
16. Prohibited uses
Some things are simply off the table. Being explicit about this helps everyone understand where the line is.
Inputting confidential client data into unapproved AI tools.
Generating misleading, deceptive, or manipulative marketing content.
Producing content that infringes copyright or misuses trademarks.
Delivering client work that has been fully automated, without any human oversight or sign-off.
Using AI to impersonate individuals, brands, or real people.
If you are ever unsure whether something falls into this category, ask before you proceed.
17. Escalation and risk management
When something does not feel right, we want people to say so. Here is how that works:
Any team member can raise a concern about AI use. There is no wrong time to do that.
High-risk use cases must be escalated to the AI lead for approval before work begins.
Named decision-makers are responsible for approving or rejecting applications that fall into the high-risk category.
We would rather pause and check than move quickly and get something wrong.
18. Documentation and record keeping
Good governance needs good records. Here is what we keep track of:
The AI tools used across different projects and clients.
Risk assessments carried out before adopting new tools.
Client’s requesting to opt out of AI usage or any part of it.
Any incidents, concerns, or escalations that have been raised.
This policy is version controlled. Every update is dated and recorded so we always know what version we are working from.
Owner: Alex Holliman, Managing Director
Version: 1.1
Last reviewed: June 2026
Next review: April 2027, or sooner if the technology or regulations change
1. Purpose and scope
We use AI to do better work, more efficiently. That means smarter analysis, sharper insights, and more time spent on the things that actually move the needle for our clients. What it does not mean is replacing human judgement, or cutting corners on quality or ethics.
This policy sets out how we use AI responsibly across everything we do. It applies to:
How we work internally, across drafting, summarising, researching, and organising.
The work we deliver to clients, including paid search, paid social, affiliate, SEO, content, digital data analysis, and beyond.
The third-party tools and platforms we rely on to do that work.
One thing never changes, regardless of what AI is involved: our team remains accountable for every output and every decision. AI helps us; it does not replace us.
2. Core principles
These are the values that guide how we approach AI. They sit alongside our wider B Corp commitments and reflect who we are as an agency.
Human oversight. A real person reviews anything that matters, we don’t copy and paste from Claude, Gemini, ChatGPT, Perplexity or Ask Jeeves.
Transparency. We are open with clients about when and how we use AI.
Fairness. We actively look out for bias or harm in AI outputs.
Privacy first. We use the appropriate amount of data necessary and protect it properly.
Integrity. We use AI because it adds genuine value, not simply because we can.
Environmental awareness. We are mindful of the energy footprint of the tools we use.
Processing. We do not send long AI-generated transcripts or documents to clients or colleagues without editing them first. That just shifts the work of finding the key points on to them.
Client work. Presenting AI-generated work to clients as original team output, without human checking, proofing, or amendment, is not acceptable. Where this leads to client complaints or loss of business, a formal disciplinary process will be initiated for the team members involved.
3. Risk classification
Not all AI use carries the same level of risk. We classify it into three tiers, each with its own requirements for review, approval, and documentation.
Low risk
Internal productivity tasks such as drafting, summarising, or organising information. These need standard good judgement, but no formal sign-off.
Medium risk
Client-facing outputs that are not particularly sensitive, such as ad copy, keyword clustering, and research summaries. These need a human review before anything is shared.
High risk
Anything that involves personal data, automated decision-making, regulated industries, or large-scale content published without a full review. High-risk use needs explicit approval, documented oversight, and a clear record of the checks applied.
4. Data protection and privacy
We take data protection seriously. Here is how we approach it when AI is involved:
We do not enter client data into AI tools without their explicit approval.
Where possible, we use enterprise-grade tools with appropriate data protections, rather than free public tools.
We never input personally identifiable information (PII) or sensitive commercial data into tools that may use it for model training.
The tools we use comply with GDPR and other relevant data protection frameworks.
We apply appropriate encryption and access controls to all AI-generated outputs that contain sensitive information.
We have clear rules on how long AI-related data is kept, and how it is deleted.
If you are unsure whether it is safe to input specific data into an AI tool, check first. When in doubt, leave it out.
5. Security and compliance
We maintain a list of approved AI tools. Using a tool that is not on the approved list needs a risk assessment first.
All approved tools are password-protected and, where applicable, require multi-factor authentication (MFA, a second verification step beyond just a password).
Before approving a new tool, we assess the vendor’s security posture, including their published security credentials where available.
We regularly review our approved tools list to make sure it stays current.
We have an incident response plan for data breaches and AI misuse. If something goes wrong, we know what to do.
6. Legal and ownership
AI raises some genuinely novel legal questions. Here is where we stand:
AI and human-generated outputs created as part of client work are typically owned by Climbing Trees. We make this clear in our contracts.
We are transparent about the limitations that may apply to IP (intellectual property) protection for AI-generated content.
We never knowingly use AI to produce content that infringes copyright or misuses trademarks.
Any AI-generated content that will be published goes through a human originality check.
Our client agreements include clear language around AI use, so there are no surprises.
7. Ethical considerations
Being ethical is not just one of our values. It is the lens through which we make every decision. When it comes to AI, that means:
We do not use AI to create harmful, misleading, or manipulative content.
We do not generate fake reviews, deceptive ads, or content that impersonates individuals or brands.
We actively look for bias in outputs, whether in language, audience targeting, or data interpretation, and we act on what we find.
We prefer tools from providers who are transparent about how their models are trained.
Everything we do with AI reflects our B Corp values: honest, caring, and built for long-term good.
8. Responsible use in marketing
This is the bit that matters most for us as a marketing agency. AI can be a brilliant tool for client work, but only when it is used thoughtfully. Here is the starting point for what we will do, and what we will not do.
What we use AI for
Drafting ad copy, with human review before anything goes live.
Identifying patterns in data and surfacing insights.
Ideation, research, and exploring new approaches.
What we do not do
Set-and-forget AI optimisation. We always keep human oversight of campaign decisions.
Fully automated client deliverables without a person checking and signing off.
Sensitive audience targeting without proper scrutiny of the approach and the outputs.
AI is here to enhance our thinking, not replace it. The strategy, the judgement, and the accountability stay with our team.
9. Transparency with clients
We are open about how we work. That includes being upfront about when AI plays a role.
We tell clients when AI is used in their work, what it was used for, and why.
Clients can ask us not to use AI on their account, and we will respect that.
We explain the benefits, the limitations, and the risks in plain language. No jargon, no spin.
We will never present AI-generated work as purely human-created.
Building trust with our clients means being honest, even when the answer is a little more complicated than ‘we did it all ourselves’.
10. Accuracy and quality control
AI can get things wrong. Our process is designed to catch that before it reaches a client.
Nothing produced with AI goes live without a human review.
Facts, data, and insights are verified before they appear in client-facing work.
Every output has a named owner. Someone who has checked it and takes responsibility for it.
We document where AI was used and what checks were applied, so there is a clear record.
11. Bias and fairness
AI systems can reflect biases from the data they were trained on. We take that seriously.
We review outputs for language, targeting, and messaging that could be inadvertently discriminatory.
Where it is relevant, we bring diverse perspectives into the review process.
We monitor our campaigns for unintended bias on an ongoing basis, and act quickly when we spot it.
12. Environmental considerations
AI has an energy cost, and as an agency with genuine environmental commitments, we do not ignore that.
We prefer efficient AI tools and avoid unnecessary large-scale content generation.
We use AI proportionately. Only where it genuinely adds value, not just because it is available.
We factor environmental impact into our vendor assessments alongside security and capability.
We will report on the carbon impact of our activities and work with our supply chain on the issues that shape sustainability.
13. Training and internal governance
This policy only works if everyone understands it. We invest in making sure they do.
Every team member completes mandatory training on safe, ethical AI use and data handling.
We provide clear internal guidelines and practical playbooks for using AI in day-to-day work.
We have a named AI lead who is responsible for keeping this policy current and championing good practice.
Alex Holliman, Managing Director, will review this policy at least every 12 months, or sooner if the technology or the regulations change significantly.
14. Tooling and vendor management
We are thoughtful about which AI tools we use. Before anything makes it onto our approved list, it goes through a proper assessment.
Our approved tools list includes a risk rating and a clear note on what each tool should and should not be used for.
Any new tool needs a risk assessment before we bring it into our workflow.
We monitor vendor policies and update our assessments when providers make significant changes.
We do not approve tools just because they are popular. They have to be right for how we work and for the people whose data we are handling.
15. Monitoring, auditing, and continuous improvement
We hold ourselves accountable. That means regularly checking that what we say we do is what we actually do.
We audit AI usage across client work on a regular basis.
We log where AI is used and keep records of any incidents or concerns that arise.
We gather feedback from the team and from clients to understand what is working and what needs to improve.
This policy evolves as the technology evolves. We will never treat it as a document that just sits on a shelf.
16. Prohibited uses
Some things are simply off the table. Being explicit about this helps everyone understand where the line is.
Inputting confidential client data into unapproved AI tools.
Generating misleading, deceptive, or manipulative marketing content.
Producing content that infringes copyright or misuses trademarks.
Delivering client work that has been fully automated, without any human oversight or sign-off.
Using AI to impersonate individuals, brands, or real people.
If you are ever unsure whether something falls into this category, ask before you proceed.
17. Escalation and risk management
When something does not feel right, we want people to say so. Here is how that works:
Any team member can raise a concern about AI use. There is no wrong time to do that.
High-risk use cases must be escalated to the AI lead for approval before work begins.
Named decision-makers are responsible for approving or rejecting applications that fall into the high-risk category.
We would rather pause and check than move quickly and get something wrong.
18. Documentation and record keeping
Good governance needs good records. Here is what we keep track of:
The AI tools used across different projects and clients.
Risk assessments carried out before adopting new tools.
Client’s requesting to opt out of AI usage or any part of it.
Any incidents, concerns, or escalations that have been raised.
This policy is version controlled. Every update is dated and recorded so we always know what version we are working from.
Owner: Alex Holliman, Managing Director
Version: 1.1
Last reviewed: June 2026
Next review: April 2027, or sooner if the technology or regulations change
1. Purpose and scope
We use AI to do better work, more efficiently. That means smarter analysis, sharper insights, and more time spent on the things that actually move the needle for our clients. What it does not mean is replacing human judgement, or cutting corners on quality or ethics.
This policy sets out how we use AI responsibly across everything we do. It applies to:
How we work internally, across drafting, summarising, researching, and organising.
The work we deliver to clients, including paid search, paid social, affiliate, SEO, content, digital data analysis, and beyond.
The third-party tools and platforms we rely on to do that work.
One thing never changes, regardless of what AI is involved: our team remains accountable for every output and every decision. AI helps us; it does not replace us.
2. Core principles
These are the values that guide how we approach AI. They sit alongside our wider B Corp commitments and reflect who we are as an agency.
Human oversight. A real person reviews anything that matters, we don’t copy and paste from Claude, Gemini, ChatGPT, Perplexity or Ask Jeeves.
Transparency. We are open with clients about when and how we use AI.
Fairness. We actively look out for bias or harm in AI outputs.
Privacy first. We use the appropriate amount of data necessary and protect it properly.
Integrity. We use AI because it adds genuine value, not simply because we can.
Environmental awareness. We are mindful of the energy footprint of the tools we use.
Processing. We do not send long AI-generated transcripts or documents to clients or colleagues without editing them first. That just shifts the work of finding the key points on to them.
Client work. Presenting AI-generated work to clients as original team output, without human checking, proofing, or amendment, is not acceptable. Where this leads to client complaints or loss of business, a formal disciplinary process will be initiated for the team members involved.
3. Risk classification
Not all AI use carries the same level of risk. We classify it into three tiers, each with its own requirements for review, approval, and documentation.
Low risk
Internal productivity tasks such as drafting, summarising, or organising information. These need standard good judgement, but no formal sign-off.
Medium risk
Client-facing outputs that are not particularly sensitive, such as ad copy, keyword clustering, and research summaries. These need a human review before anything is shared.
High risk
Anything that involves personal data, automated decision-making, regulated industries, or large-scale content published without a full review. High-risk use needs explicit approval, documented oversight, and a clear record of the checks applied.
4. Data protection and privacy
We take data protection seriously. Here is how we approach it when AI is involved:
We do not enter client data into AI tools without their explicit approval.
Where possible, we use enterprise-grade tools with appropriate data protections, rather than free public tools.
We never input personally identifiable information (PII) or sensitive commercial data into tools that may use it for model training.
The tools we use comply with GDPR and other relevant data protection frameworks.
We apply appropriate encryption and access controls to all AI-generated outputs that contain sensitive information.
We have clear rules on how long AI-related data is kept, and how it is deleted.
If you are unsure whether it is safe to input specific data into an AI tool, check first. When in doubt, leave it out.
5. Security and compliance
We maintain a list of approved AI tools. Using a tool that is not on the approved list needs a risk assessment first.
All approved tools are password-protected and, where applicable, require multi-factor authentication (MFA, a second verification step beyond just a password).
Before approving a new tool, we assess the vendor’s security posture, including their published security credentials where available.
We regularly review our approved tools list to make sure it stays current.
We have an incident response plan for data breaches and AI misuse. If something goes wrong, we know what to do.
6. Legal and ownership
AI raises some genuinely novel legal questions. Here is where we stand:
AI and human-generated outputs created as part of client work are typically owned by Climbing Trees. We make this clear in our contracts.
We are transparent about the limitations that may apply to IP (intellectual property) protection for AI-generated content.
We never knowingly use AI to produce content that infringes copyright or misuses trademarks.
Any AI-generated content that will be published goes through a human originality check.
Our client agreements include clear language around AI use, so there are no surprises.
7. Ethical considerations
Being ethical is not just one of our values. It is the lens through which we make every decision. When it comes to AI, that means:
We do not use AI to create harmful, misleading, or manipulative content.
We do not generate fake reviews, deceptive ads, or content that impersonates individuals or brands.
We actively look for bias in outputs, whether in language, audience targeting, or data interpretation, and we act on what we find.
We prefer tools from providers who are transparent about how their models are trained.
Everything we do with AI reflects our B Corp values: honest, caring, and built for long-term good.
8. Responsible use in marketing
This is the bit that matters most for us as a marketing agency. AI can be a brilliant tool for client work, but only when it is used thoughtfully. Here is the starting point for what we will do, and what we will not do.
What we use AI for
Drafting ad copy, with human review before anything goes live.
Identifying patterns in data and surfacing insights.
Ideation, research, and exploring new approaches.
What we do not do
Set-and-forget AI optimisation. We always keep human oversight of campaign decisions.
Fully automated client deliverables without a person checking and signing off.
Sensitive audience targeting without proper scrutiny of the approach and the outputs.
AI is here to enhance our thinking, not replace it. The strategy, the judgement, and the accountability stay with our team.
9. Transparency with clients
We are open about how we work. That includes being upfront about when AI plays a role.
We tell clients when AI is used in their work, what it was used for, and why.
Clients can ask us not to use AI on their account, and we will respect that.
We explain the benefits, the limitations, and the risks in plain language. No jargon, no spin.
We will never present AI-generated work as purely human-created.
Building trust with our clients means being honest, even when the answer is a little more complicated than ‘we did it all ourselves’.
10. Accuracy and quality control
AI can get things wrong. Our process is designed to catch that before it reaches a client.
Nothing produced with AI goes live without a human review.
Facts, data, and insights are verified before they appear in client-facing work.
Every output has a named owner. Someone who has checked it and takes responsibility for it.
We document where AI was used and what checks were applied, so there is a clear record.
11. Bias and fairness
AI systems can reflect biases from the data they were trained on. We take that seriously.
We review outputs for language, targeting, and messaging that could be inadvertently discriminatory.
Where it is relevant, we bring diverse perspectives into the review process.
We monitor our campaigns for unintended bias on an ongoing basis, and act quickly when we spot it.
12. Environmental considerations
AI has an energy cost, and as an agency with genuine environmental commitments, we do not ignore that.
We prefer efficient AI tools and avoid unnecessary large-scale content generation.
We use AI proportionately. Only where it genuinely adds value, not just because it is available.
We factor environmental impact into our vendor assessments alongside security and capability.
We will report on the carbon impact of our activities and work with our supply chain on the issues that shape sustainability.
13. Training and internal governance
This policy only works if everyone understands it. We invest in making sure they do.
Every team member completes mandatory training on safe, ethical AI use and data handling.
We provide clear internal guidelines and practical playbooks for using AI in day-to-day work.
We have a named AI lead who is responsible for keeping this policy current and championing good practice.
Alex Holliman, Managing Director, will review this policy at least every 12 months, or sooner if the technology or the regulations change significantly.
14. Tooling and vendor management
We are thoughtful about which AI tools we use. Before anything makes it onto our approved list, it goes through a proper assessment.
Our approved tools list includes a risk rating and a clear note on what each tool should and should not be used for.
Any new tool needs a risk assessment before we bring it into our workflow.
We monitor vendor policies and update our assessments when providers make significant changes.
We do not approve tools just because they are popular. They have to be right for how we work and for the people whose data we are handling.
15. Monitoring, auditing, and continuous improvement
We hold ourselves accountable. That means regularly checking that what we say we do is what we actually do.
We audit AI usage across client work on a regular basis.
We log where AI is used and keep records of any incidents or concerns that arise.
We gather feedback from the team and from clients to understand what is working and what needs to improve.
This policy evolves as the technology evolves. We will never treat it as a document that just sits on a shelf.
16. Prohibited uses
Some things are simply off the table. Being explicit about this helps everyone understand where the line is.
Inputting confidential client data into unapproved AI tools.
Generating misleading, deceptive, or manipulative marketing content.
Producing content that infringes copyright or misuses trademarks.
Delivering client work that has been fully automated, without any human oversight or sign-off.
Using AI to impersonate individuals, brands, or real people.
If you are ever unsure whether something falls into this category, ask before you proceed.
17. Escalation and risk management
When something does not feel right, we want people to say so. Here is how that works:
Any team member can raise a concern about AI use. There is no wrong time to do that.
High-risk use cases must be escalated to the AI lead for approval before work begins.
Named decision-makers are responsible for approving or rejecting applications that fall into the high-risk category.
We would rather pause and check than move quickly and get something wrong.
18. Documentation and record keeping
Good governance needs good records. Here is what we keep track of:
The AI tools used across different projects and clients.
Risk assessments carried out before adopting new tools.
Client’s requesting to opt out of AI usage or any part of it.
Any incidents, concerns, or escalations that have been raised.
This policy is version controlled. Every update is dated and recorded so we always know what version we are working from.
Owner: Alex Holliman, Managing Director
Version: 1.1
Last reviewed: June 2026
Next review: April 2027, or sooner if the technology or regulations change
1. Purpose and scope
We use AI to do better work, more efficiently. That means smarter analysis, sharper insights, and more time spent on the things that actually move the needle for our clients. What it does not mean is replacing human judgement, or cutting corners on quality or ethics.
This policy sets out how we use AI responsibly across everything we do. It applies to:
How we work internally, across drafting, summarising, researching, and organising.
The work we deliver to clients, including paid search, paid social, affiliate, SEO, content, digital data analysis, and beyond.
The third-party tools and platforms we rely on to do that work.
One thing never changes, regardless of what AI is involved: our team remains accountable for every output and every decision. AI helps us; it does not replace us.
2. Core principles
These are the values that guide how we approach AI. They sit alongside our wider B Corp commitments and reflect who we are as an agency.
Human oversight. A real person reviews anything that matters, we don’t copy and paste from Claude, Gemini, ChatGPT, Perplexity or Ask Jeeves.
Transparency. We are open with clients about when and how we use AI.
Fairness. We actively look out for bias or harm in AI outputs.
Privacy first. We use the appropriate amount of data necessary and protect it properly.
Integrity. We use AI because it adds genuine value, not simply because we can.
Environmental awareness. We are mindful of the energy footprint of the tools we use.
Processing. We do not send long AI-generated transcripts or documents to clients or colleagues without editing them first. That just shifts the work of finding the key points on to them.
Client work. Presenting AI-generated work to clients as original team output, without human checking, proofing, or amendment, is not acceptable. Where this leads to client complaints or loss of business, a formal disciplinary process will be initiated for the team members involved.
3. Risk classification
Not all AI use carries the same level of risk. We classify it into three tiers, each with its own requirements for review, approval, and documentation.
Low risk
Internal productivity tasks such as drafting, summarising, or organising information. These need standard good judgement, but no formal sign-off.
Medium risk
Client-facing outputs that are not particularly sensitive, such as ad copy, keyword clustering, and research summaries. These need a human review before anything is shared.
High risk
Anything that involves personal data, automated decision-making, regulated industries, or large-scale content published without a full review. High-risk use needs explicit approval, documented oversight, and a clear record of the checks applied.
4. Data protection and privacy
We take data protection seriously. Here is how we approach it when AI is involved:
We do not enter client data into AI tools without their explicit approval.
Where possible, we use enterprise-grade tools with appropriate data protections, rather than free public tools.
We never input personally identifiable information (PII) or sensitive commercial data into tools that may use it for model training.
The tools we use comply with GDPR and other relevant data protection frameworks.
We apply appropriate encryption and access controls to all AI-generated outputs that contain sensitive information.
We have clear rules on how long AI-related data is kept, and how it is deleted.
If you are unsure whether it is safe to input specific data into an AI tool, check first. When in doubt, leave it out.
5. Security and compliance
We maintain a list of approved AI tools. Using a tool that is not on the approved list needs a risk assessment first.
All approved tools are password-protected and, where applicable, require multi-factor authentication (MFA, a second verification step beyond just a password).
Before approving a new tool, we assess the vendor’s security posture, including their published security credentials where available.
We regularly review our approved tools list to make sure it stays current.
We have an incident response plan for data breaches and AI misuse. If something goes wrong, we know what to do.
6. Legal and ownership
AI raises some genuinely novel legal questions. Here is where we stand:
AI and human-generated outputs created as part of client work are typically owned by Climbing Trees. We make this clear in our contracts.
We are transparent about the limitations that may apply to IP (intellectual property) protection for AI-generated content.
We never knowingly use AI to produce content that infringes copyright or misuses trademarks.
Any AI-generated content that will be published goes through a human originality check.
Our client agreements include clear language around AI use, so there are no surprises.
7. Ethical considerations
Being ethical is not just one of our values. It is the lens through which we make every decision. When it comes to AI, that means:
We do not use AI to create harmful, misleading, or manipulative content.
We do not generate fake reviews, deceptive ads, or content that impersonates individuals or brands.
We actively look for bias in outputs, whether in language, audience targeting, or data interpretation, and we act on what we find.
We prefer tools from providers who are transparent about how their models are trained.
Everything we do with AI reflects our B Corp values: honest, caring, and built for long-term good.
8. Responsible use in marketing
This is the bit that matters most for us as a marketing agency. AI can be a brilliant tool for client work, but only when it is used thoughtfully. Here is the starting point for what we will do, and what we will not do.
What we use AI for
Drafting ad copy, with human review before anything goes live.
Identifying patterns in data and surfacing insights.
Ideation, research, and exploring new approaches.
What we do not do
Set-and-forget AI optimisation. We always keep human oversight of campaign decisions.
Fully automated client deliverables without a person checking and signing off.
Sensitive audience targeting without proper scrutiny of the approach and the outputs.
AI is here to enhance our thinking, not replace it. The strategy, the judgement, and the accountability stay with our team.
9. Transparency with clients
We are open about how we work. That includes being upfront about when AI plays a role.
We tell clients when AI is used in their work, what it was used for, and why.
Clients can ask us not to use AI on their account, and we will respect that.
We explain the benefits, the limitations, and the risks in plain language. No jargon, no spin.
We will never present AI-generated work as purely human-created.
Building trust with our clients means being honest, even when the answer is a little more complicated than ‘we did it all ourselves’.
10. Accuracy and quality control
AI can get things wrong. Our process is designed to catch that before it reaches a client.
Nothing produced with AI goes live without a human review.
Facts, data, and insights are verified before they appear in client-facing work.
Every output has a named owner. Someone who has checked it and takes responsibility for it.
We document where AI was used and what checks were applied, so there is a clear record.
11. Bias and fairness
AI systems can reflect biases from the data they were trained on. We take that seriously.
We review outputs for language, targeting, and messaging that could be inadvertently discriminatory.
Where it is relevant, we bring diverse perspectives into the review process.
We monitor our campaigns for unintended bias on an ongoing basis, and act quickly when we spot it.
12. Environmental considerations
AI has an energy cost, and as an agency with genuine environmental commitments, we do not ignore that.
We prefer efficient AI tools and avoid unnecessary large-scale content generation.
We use AI proportionately. Only where it genuinely adds value, not just because it is available.
We factor environmental impact into our vendor assessments alongside security and capability.
We will report on the carbon impact of our activities and work with our supply chain on the issues that shape sustainability.
13. Training and internal governance
This policy only works if everyone understands it. We invest in making sure they do.
Every team member completes mandatory training on safe, ethical AI use and data handling.
We provide clear internal guidelines and practical playbooks for using AI in day-to-day work.
We have a named AI lead who is responsible for keeping this policy current and championing good practice.
Alex Holliman, Managing Director, will review this policy at least every 12 months, or sooner if the technology or the regulations change significantly.
14. Tooling and vendor management
We are thoughtful about which AI tools we use. Before anything makes it onto our approved list, it goes through a proper assessment.
Our approved tools list includes a risk rating and a clear note on what each tool should and should not be used for.
Any new tool needs a risk assessment before we bring it into our workflow.
We monitor vendor policies and update our assessments when providers make significant changes.
We do not approve tools just because they are popular. They have to be right for how we work and for the people whose data we are handling.
15. Monitoring, auditing, and continuous improvement
We hold ourselves accountable. That means regularly checking that what we say we do is what we actually do.
We audit AI usage across client work on a regular basis.
We log where AI is used and keep records of any incidents or concerns that arise.
We gather feedback from the team and from clients to understand what is working and what needs to improve.
This policy evolves as the technology evolves. We will never treat it as a document that just sits on a shelf.
16. Prohibited uses
Some things are simply off the table. Being explicit about this helps everyone understand where the line is.
Inputting confidential client data into unapproved AI tools.
Generating misleading, deceptive, or manipulative marketing content.
Producing content that infringes copyright or misuses trademarks.
Delivering client work that has been fully automated, without any human oversight or sign-off.
Using AI to impersonate individuals, brands, or real people.
If you are ever unsure whether something falls into this category, ask before you proceed.
17. Escalation and risk management
When something does not feel right, we want people to say so. Here is how that works:
Any team member can raise a concern about AI use. There is no wrong time to do that.
High-risk use cases must be escalated to the AI lead for approval before work begins.
Named decision-makers are responsible for approving or rejecting applications that fall into the high-risk category.
We would rather pause and check than move quickly and get something wrong.
18. Documentation and record keeping
Good governance needs good records. Here is what we keep track of:
The AI tools used across different projects and clients.
Risk assessments carried out before adopting new tools.
Client’s requesting to opt out of AI usage or any part of it.
Any incidents, concerns, or escalations that have been raised.
This policy is version controlled. Every update is dated and recorded so we always know what version we are working from.