Skip to main content

Most agencies that have an AI policy at all keep it the same place they keep the PTO policy: in an internal doc nobody outside the building will ever read. That made sense when AI use was a back-office question. It stopped making sense the moment your clients, your regulators, and your audiences started asking what your process actually is.

A policy nobody can see isn't a credibility asset. It's just paperwork.

If you haven't yet built the actual review steps that happen before anything under your agency's or your executive's name goes live or, if you are wondering why you need to, we've covered how to build that credibility review layer here. This piece picks up from there: once you have a process, the next question is whether anyone outside your organization should get to see it.

Why showing your AI governance policy is the new industry standard

Newsrooms are the organizations with the longest track record of thinking about editorial accountability and they are leading the new industry standard, publishing their AI governance policies to provide transparency and foster ongoing trust and credibility with their audiences.

A global YouGov/Meltwater survey of nearly 10,000 consumers found that while 58% believe they can spot AI-generated content, 87% are still concerned that people (including themselves) won't be able to tell what's real from what's been fabricated by AI. The same survey found 86% say it's important that content explicitly discloses when generative AI was used to create it.

When confidence and reality are this far apart, a published standard is one of the few things left that can reassure people. This is the trust problem a hidden policy can't solve, no matter how good the internal process behind it is.

The Associated Press updated its newsroom standards to spell out when generative AI can be used and to require disclosure whenever it materially shapes published content. The BBC went further: stating that the use of AI must “always be transparent and accountable with effective and informed human oversight”. This rule was adopted after research with the European Broadcasting Union found AI assistants misrepresented news content, finding that 45% of all AI answers had at least one significant issue. Reuters is pioneering the use of AI in numerous business operations including scanning the internet for financial and business updates, to allow them to issue real-time alerts for customers and journalists at a scale that was not previously possible. Each of these organizations are making public statements about how they operate precisely because they know that "trust us" has long stopped being sufficient on its own.

It isn't only the wire services. Smaller outlets are doing the same thing at a scale most agencies could realistically match. Independent outlet Indy Politics publishes its AI policy outright: what AI tools may assist with, who holds final editorial approval, and what happens if AI-assisted content contributes to an error - including a commitment that corrections will say so. Chicago Public Media's WBEZ and Sun-Times newsroom did the same, publishing a plain-language policy stating that while generative AI may assist with tasks like summarizing documents, editorial and design content is created and shaped by humans.

Regulators are now formalizing what these publishers already figured out. Since August,2026, the EU AI Act's Article 50 has required disclosure of AI-generated text published to inform the public on matters of public interest unless it has received substantive human review or editorial control and a natural or legal person bears editorial responsibility for its publication.

The industry direction is clear: having a policy is no longer enough. The expectation is increasingly that it is visible.

Why publishing your AI governance policy matters just as much as having one

When PR and communications leaders were asked what would rebuild trust in AI-assisted content, the top answers were transparent data sources, cited by 45% as the number one trust builder, followed by human oversight at 41%. Both of those are, at their core, disclosure asks. People don't just want you to have a good process. They want to be able to see it.

An internal-only AI policy can satisfy the first half of that equation. It cannot satisfy the second. If a client, a journalist, or a regulator asks how you're managing AI-assisted content and the answer is "we have a document, but it's not something we share," you've missed a crucial opportunity to build trust and credibility.

Publishing the policy flips that script. It turns something that was purely a risk-management exercise into a positioning asset the same way a security certification or a data-handling policy becomes something that demonstrates trustworthiness and genuine care for clients. For an agency competing for a client in a regulated industry, or a comms team fielding questions from an executive's board, "here's our published standard for AI-assisted content" is a materially stronger answer than "we're careful."

What belongs in an AI governance policy?

A policy written to sit in a drawer and a policy written to be read by a client look different. The published versions above share a few things in common:

  • A plain statement of scope: what AI is allowed to help with, and what it explicitly isn't (Indy Politics and WBEZ both lead with this).
  • Named accountability: who holds final approval, stated as a role or a person, not "the team".
  • A disclosure commitment: when and how AI involvement gets flagged to the audience or client, not just tracked internally.
  • A stated correction protocol: what happens, and what gets said publicly, if something gets through anyway.
  • A review cadence: a stated commitment to revisit the policy as tools and standards change, so it doesn't read as a one-time document.

None of this requires the infrastructure of a national organization. Indy Politics is a small, independent outlet, and its policy covers all five points in language a client could read and understand in under two minutes.

The credibility payoff

The agencies and outlets doing this well aren't publishing their AI policy because a regulation told them to. They're publishing it because, in a moment where the unnamed use of AI is hurting reputations, being able to show an actual, specific, named standard is the difference between asking for trust and demonstrating it. And demonstrating your trustworthiness goes a long way towards building long-term credibility.


Sources

Jennifer Best
Post by Jennifer Best
10/1/26, 3:25 PM
I work with mission-driven businesses to help grow demand, standardize processes, and differentiate brand value within crowded markets. My core values are trust, authenticity, partnership, and transparency, and they exist in everything I do, personally and professionally.