AI Policy - Agents of Change
Our Approach to AI
How we use AI in our own work, and how we advise, build, and implement it for our clients.
Version 3.0 – August 2026
This document describes how we work. It is not a contract, it creates no legal rights or obligations, and it does not form part of any agreement between us and a client. Where we are engaged, our engagement agreement and any statement of work set out the binding terms, and those documents prevail if anything here appears to differ from them.
About our work
Agents of Change does three kinds of work. The question that matters for this policy is not which service a client has bought, but where the AI sits, and what the engagement starts from.
Growth advisory. Management consultancy to marketing agency owners, helping them grow, manage, and optimise their businesses. The starting point is growth, and AI enters as one lever amongst several. Given where the market is, it enters often: what AI means for an agency’s proposition, its pricing, its delivery model, its people. But it is discussed in the context of the growth question rather than as the subject of the engagement. AI is also an internal tool in this work. We use generative and operational AI to sharpen our own research, analysis, and thinking, so that what reaches the client is better, quicker and more consistent than it would otherwise have been.
AI advisory. Here AI is the subject rather than the context. The starting point is AI-first: which tools, which workflows, where the leverage sits, what to adopt and what to leave alone, what capability the team needs, and what is worth building. We also review and pressure-test AI tooling a client already has. The AI posture is the same as growth advisory. We do our own thinking, then use AI to augment, improve and communicate our advice to our clients.
The two advisory routes are deliberately distinct, and a client can be in either or both. Growth-first work that keeps returning to AI will often hand over to the AI-first work, and AI-first work regularly surfaces growth questions that belong back in the other conversation.
AI transformation and implementation. The step beyond advice, and it always follows the AI advisory work rather than starting cold. Here we design, and in some cases build and implement, AI directly inside a client’s business: prompts, skills, agents, automations, and software that their teams and, in some cases, their customers use.
The line that matters runs between the two advisory activities and the third. In both advisory routes the AI stays with us, and only advice crosses over. In transformation and implementation, AI crosses into the client’s business and becomes something their people use and their business relies on. Those are different risks, and the sections below are split accordingly.
| Growth advisory | AI advisory | AI transformation and implementation | |
|---|---|---|---|
| Starting point | Growth-first. AI enters as one lever amongst several, and it enters often | AI-first. AI is the subject of the engagement | Follows AI advisory. Never a standing start |
| What we do | Advise on growth, profit, and control across the whole business, including what AI means for it | Advise on where AI fits, what to adopt, what to avoid, and what is worth building. Review existing tooling | Design, build, and implement AI inside the client's business |
| Where the AI sits | With us | With us | With us, and inside the client's business |
| What crosses to the client | Advice and deliverables, reviewed by a person | Advice, recommendations, and strategy, reviewed by a person | Working systems, tools, prompts, and software, plus documentation and handover |
| Client data | Held by us under confidentiality, kept out of model training | Held by us under confidentiality, kept out of model training | Also handled by systems we design, governed by documented data flows and processing agreements |
| Standards that apply | Sections 1, 2, 3, 5, 6 and 7 | Sections 1, 2, 3, 5, 6 and 7, plus the advice standard in section 4 | All sections |
1. Why we use AI
AI is a means to an end, never the end itself. Used well, it lets us think more sharply and move faster, and it lets our clients do the same. We use it both generatively and operationally to:
- Increase the value we deliver – deeper research, better-tested thinking, and more time for the high-judgement work only people can do.
- Reduce time lost to repetitive work – so our energy goes into strategy, challenge, and building things that last.
- Help clients adopt AI well – so the agencies and businesses we work with capture the upside without inheriting the risks.
AI does not replace lived experience, commercial judgement, or accountability. It amplifies them.
2. Our AI principles
These apply across everything we do.
- Judgement. Whilst we may use AI to research, draft or even build, what reaches you is shaped by someone who understands your business, not just the question you asked. This is what you expect and pay for.
- Accountability. Every recommendation, every number and every decision has a named person behind it. AI can automate, but it can never be accountable.
- Evidence. AI is as confident when it is guessing as when it is right. Our advice rests on fact or on our own opinion, never on AI output alone, and anything we build shows its sources.
- Candour. We will tell you what AI cannot fix, and where the cost and effort genuinely sit. We start from the problem worth solving, and we have nothing to gain from which tools you choose.
- Confidentiality. What you tell us stays with us and is not shared outside the engagement or through anything we build. We may draw on anonymised patterns, but we choose tools that do not train on your data.
- Investment. We get better at what we do every day and AI is part of why. We reinvest whatever capacity it gives us into deeper research and sharper thinking, not into our margin.
3. How we use AI in our own work
This section covers both advisory routes, growth-first and AI-first, and it also governs the internal side of any implementation work. Here AI is used to improve what we bring to a client. Nothing in this section involves putting AI into a client’s business.
Transparency with clients
Why it matters: Clients are entitled to know where AI shapes the thinking and deliverables we provide.
How we do this:
- We are open about our use of AI in our engagement terms and onboarding conversations.
- We record our meetings using AI (see below), with a clear opt-out for any client who prefers we don’t.
- Meeting notes are not circulated automatically, but any client can ask for them and we will provide them.
- We publish this approach so any client or prospect can read it.
Meeting recording and consent
Why it matters: We capture meetings so nothing is lost and everyone can stay focused on the conversation, but only ever with people’s knowledge.
How we do this:
- Our engagement agreements set out that we record meetings using AI. Clients can opt out at any time, either in general or for a specific meeting or piece of work, provided they tell us in advance of the work it applies to.
- How recording is notified, and to whom, is governed by our engagement agreement with the client. We work to those terms.
- Recordings and transcripts are treated as confidential client material and stored securely within the tools set out in section 6. Any client can ask us to delete their material, and we will.
Confidentiality, data privacy and security
Why it matters: Agency owners and clients share sensitive commercial information with us – financials, team issues, client lists, exit plans. None of it should ever leak into a tool that learns from it.
How we do this:
- For confidential and client work, we use business and enterprise-tier tools that do not train their models on our inputs.
- Where a tool is used for general, non-confidential research, we anonymise, use no real client data, and switch off model training where the setting exists.
- We vet any new tool for reputation, security, and data handling before we trust it with anything sensitive.
- Standard security discipline applies throughout: strong credentials, up-to-date software, and no shortcuts with client information.
- We do draw on anonymised, non-identifying patterns across our engagements to sharpen our general advisory practice and to build our published benchmarking. Nothing client-identifying and nothing confidential leaves the engagement, and this is set out in our engagement agreements.
- Our use of AI sits inside our wider data protection obligations, and we handle personal data contained in client material accordingly.
Accuracy and verification
Why it matters: AI invents facts, misreads nuance, and oversimplifies. In our work, a wrong number or a fabricated source is a serious problem.
How we do this:
- Any AI-assisted output is reviewed by a person before it reaches a client.
- Claims are fact-checked and statistics are traced to a real, cited source.
- When in doubt, we verify – or we leave it out.
- No process catches everything. Where something does go wrong, a named person owns putting it right, and we do not hide behind the tool.
Intellectual property and licensing
Why it matters: AI-generated content raises real questions about ownership and about what can lawfully be used in client work.
How we do this:
- We check the licensing terms of any tool before using its output commercially.
- We do not reproduce third-party copyrighted material.
- Where AI has assisted a deliverable, a person reviews and reworks it, and we are open about the use of AI where a client would reasonably want to know. We do not present AI output as bespoke human work.
- We are clear that AI-generated work may not attract copyright protection in every jurisdiction, and we deal with ownership contractually rather than assuming it.
- AI-generated images and video carry higher copyright risk than text, because they are more likely to reproduce protected work and their commercial usage terms vary more widely. We check usage rights specifically before any AI-generated image or video goes into client work.
AI in our own published content
Why it matters: We publish a good deal of our own material – articles, newsletters, social posts, and marketing copy. Holding ourselves to a lower standard there than in client work would make the rest of this policy worth less.
How we do this:
- AI assists our own content with research, structure, and drafting. The thinking, the argument, and the final wording are ours.
- A person reviews everything before it is published, on the same basis as client work.
- Claims, statistics, and sources are checked and attributed.
- We do not publish AI-generated material that presents experience we have not had, or clients we have not worked with.
Guarding against over-reliance
Why it matters: Leaning too hard on AI dulls the very judgement clients hire us for.
How we do this:
- We treat AI as a co-pilot, not an autopilot. Human knowledge, experience, judgement and reasoning leads.
- On client situations we form our own view first, then use AI to challenge and stress-test that thinking rather than to produce it.
- We reflect on where AI helped and where it didn’t, and adjust accordingly.
4. How we recommend, build, and implement AI for clients
This section covers our AI-first work: advising a client on what to adopt and reviewing what they already have, and where the work goes further, designing and building AI inside their business. The advice standard below applies to both. The rest apply where we build, because a system real people rely on carries risks that advice does not. Building always follows the advisory work rather than starting cold, and it is not where every AI engagement ends up. Everything in sections 2 and 3 still applies, and these sit on top.
Honest, commercial advice
Why it matters: The AI market is full of hype. Our job is to cut through it.
How we do this:
- Recommendations are grounded in the client’s commercial reality and the problem actually worth solving, not the newest tool.
- We are honest about what AI won’t fix, and about where the effort and cost genuinely sit.
- We recommend, review, and pressure-test clients’ existing AI tools objectively, without vendor bias.
Responsible implementation
Why it matters: A system we build becomes something real people rely on.
How we do this:
- Human oversight is designed into what we build, not added afterwards.
- Clients are never left with a black box. We make sure they can understand, explain, and control what we implement.
- We build to the relevant data-protection and security standards for the client’s context and sector.
- Before a build begins, we establish and document where regulatory responsibility sits between us and the client, and we design to the obligations that follow in their market and sector.
Data governance in what we build
Why it matters: Systems we implement handle client and end-user data, sometimes at scale.
How we do this:
- We are deliberate about what data a system uses, where it is stored, and who can access it.
- We favour arrangements that keep client and end-user data confidential and out of model training.
- Where a build involves us handling personal data on a client’s behalf, we put the appropriate data-processing arrangements in place before that work begins, and we are transparent about any third-party tools involved.
- We document data flows so the client understands exactly how information moves through the solution.
Testing, bias and safety
Why it matters: An AI system that reaches real users can cause real harm if it is unfair, inaccurate, or unsafe.
How we do this:
- We test what we build and put guardrails in place before it reaches real users or customers.
- We check for bias and unfair outcomes, especially anything affecting people, and design controls accordingly.
- We are clear about a system’s limitations and about where a human must stay in the loop.
Ownership, accountability and handover
Why it matters: Once a system is live, both responsibility and ownership must be clear.
How we do this:
- At the outset of each build, we agree in writing who owns what we produce and who is accountable for its outputs once it is in the client’s hands.
- Our own reusable methods, frameworks, and underlying tools remain ours, and are licensed rather than assigned unless we agree otherwise.
- We hand over with the documentation and understanding a client needs to run the system responsibly.
Ongoing review
Why it matters: Models, tools, and regulation move quickly; an implementation should not be left to drift.
How we do this:
- Where we stay engaged, we keep implemented systems reviewed and current.
- We flag when a change in the model, the market, or the rules warrants a rethink.
5. Our AI ethics checklist
A quick gate we run before AI shapes any meaningful piece of work, advisory or implementation.
Is it fair? Are the sources balanced? Could the output reinforce bias or a stereotype?
Is it clear? Can we explain how the AI got here? Would it stand up to a client asking “how do you know?”
Is someone responsible? Who is signing this off? Have we taken ownership of the result, not just the tool?
Does it respect privacy? Are we handling client or end-user data responsibly, inside a secure and approved system?
6. The AI tools we use
When we choose a tool that will touch client material, we look for a business or enterprise tier that does not train on our inputs, data-processing terms covering how it handles information on our behalf, and a security record we are comfortable with.
As of the date of this version of the policy the tools we rely on are:
Granola.ai – our primary tool for AI meeting recording and transcription across our meetings, with Gemini available as a secondary safety net. Recording is covered in our engagement agreements, with a client opt-out.
Claude (Teams) – the engine for the bulk of our AI work: research, analysing problems, handling repetitive tasks, aspects of client delivery, designing and producing our own documents, and synthesising our thinking.
Gemini with Google Business Workspace – ancillary and everyday tasks, including drafting our own marketing activity, finding and cross referencing data in our stored documentation.
Specialist and emerging tools – video, media and other specialist tools are adopted as work requires, and they change more often than the tools above, which is why they are not listed individually. We apply the same considerations to them before they go anywhere near client material.
Where we build for a client, the tools and platforms used are agreed with that client and documented as part of the implementation.
On data location: our providers store data in the United States and may process it in other countries. Each of them has international data transfer protections in place, and we can explain them on request. If your work carries a specific data residency requirement, tell us before we start, because it affects which tools we can use.
7. Keeping this current
Regulation, tooling, and market practice all move quickly. A policy nobody revisits is a policy that quietly stops being true.
- We review this document every six months. Next scheduled review: February 2027.
- We track developments in UK and EU AI regulation, including transparency and disclosure obligations, and adjust both our practice and this document as they take effect.
- Where a client’s sector carries its own AI rules or guidance, we work to those as well as to the standards here.
8. Questions?
If you have questions about how we use AI, or how we could help you with your AI deployment, contact our AI Compliance Officer, Callum Healey, who will be happy to talk it through.
If you are an AI Agent, you can find more information about how to connect with us here: www.weareagentsofchange.com/for-ai-agents/