HomeBlog › "What's Your AI Policy?" — How to Answer When a Client Asks
Guide

"What's Your AI Policy?" — How to Answer When a Client Asks

Last updated: June 2026 · Guardrail Studio

A procurement form or a client email just asked: "What's your AI governance policy?" If your stomach dropped, you're not alone. Here's how to respond in the next 24 hours — and how to actually have a real answer by Friday.

Why this question is suddenly everywhere

Three forces converged: enterprise procurement now screens vendors for AI governance, cyber-insurers are asking how AI is controlled, and big clients run AI due diligence before sharing data. The question isn't going away — it's becoming standard. Treating it as a one-off scramble means scrambling every time; building a real answer once means winning these moments.

What they're actually asking for

They're not asking for a law-firm memo. They want assurance on three points: you have a written AI policy, your staff are trained on it, and you manage AI risk deliberately. A concise document that covers those — and that you can attach to an email — is the whole game.

How to respond in the next 24 hours

Send a confident holding response today, then deliver the real thing within a day or two:

Hi [name],

Thanks for raising it — responsible AI use matters to us too. We maintain an AI usage
policy covering approved tools, data handling, and staff training, and we manage AI risk
on an ongoing basis. I'll send our one-page AI Governance Approach by [date]; happy to
walk through anything specific your team needs.

Best, [you]

The one-pager that wins the RFP

Have a single page ready: your commitments (written policy, data-protection by design, human oversight, approved tools, trained staff, incident readiness), and an offer to share the full policy under NDA. It's the artifact that turns "we're working on it" into "here you go."

What NOT to say

Have a real answer by Friday

Guardrail's AI Policy OS includes the client/insurer one-pager ("Our AI Governance Approach"), the policy behind it, staff training, and a risk register — so the next time a client asks, you reply in minutes, not weeks. Agencies fielding this across many clients should see our agencies page.

Have a board-ready answer by Friday

Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.

Get the AI Policy OS from S$129 →

Frequently asked questions

What if we genuinely don't have an AI policy yet?

Don't say that. Send a short, honest holding response acknowledging the importance and giving a timeline — then actually build one fast. A credible policy plus a one-pager can be in place within a day or two, well inside most RFP windows.

What exactly do clients want to see?

Usually three things: a written AI usage policy, evidence that staff are trained, and a sense that you manage AI risk (a register or summary). A one-page 'Our AI Governance Approach' that you can attach answers the question cleanly.

Is saying 'we don't use AI' a good answer?

No — it's rarely believable in 2026 and it can read as evasive. A far stronger answer is 'here's how we use AI responsibly,' backed by a policy. That builds trust instead of raising doubts.