Legal & policies

Our AI policy

Version 1.1. Effective 5 October 2026. We review this policy on the first working day of every month.

We use AI every day at 21 Degrees Digital: for research, first drafts, meeting notes, design, video and audio, code and automation. This page is the public version of the internal policy our team works to. It sets out which tools we use, what we will and won't put into them, how a person checks everything before it reaches you, and what we do if something goes wrong.

The policy covers everyone who does 21 Degrees work with AI. That means our staff, contractors and freelancers, on any device, wherever they're working.

Who owns the policy

Our AI Team owns it: Rory Mason (CEO) and Rachel Scahill (Head of Client Operations). They vet and approve every tool we use, keep the approved list up to date, handle incidents and run the monthly review. The policy is binding on everyone it covers.

Our principles

We will:

  • use AI to make our work faster and more useful to clients
  • keep judgement and accountability with the person who owns the work
  • give our team company accounts for any AI tool used on client work, so nobody uses a personal account for it
  • check the contract terms we actually hold with each vendor
  • share prompts and workflows that work across the whole team
  • review this policy every month

We won't:

  • send a client anything AI produced without a person reviewing it first
  • put personal data into an AI tool without authorisation
  • approve a tool for client work without a business case and sign-off
  • assume AI-generated text, code, images or audio are free of copyright risk
  • use AI to get round review, due diligence or accountability

The tools we use

A tool can only be used for 21 Degrees work once it's on our approved list. Anything not on the list isn't approved. New tools are checked for vendor terms, data handling, cost and overlap with what we already use, and nobody uses them until our AI Team has signed them off. Signing up for a free trial counts as using a tool, so that goes through the same check.

Approved for client and internal work:

  • Adobe Firefly
  • Canva AI
  • ChatGPT, including ChatGPT image generation used through Claude
  • Claude
  • Descript
  • ElevenLabs
  • Figma Make
  • Gemini, including Nano Banana (Google's Gemini image model) used through Claude
  • Grammarly
  • Granola, TLDV and Fathom, for meeting notes
  • Lovable
  • Microsoft 365 Copilot
  • n8n
  • Opus Clip
  • Suno
  • Zapier
  • The AI features built into Ahrefs, Semrush, HubSpot and Firecrawl, under our existing contracts

Approved for internal work only: GitHub Copilot.

We don't use Grok, or AI models of Chinese origin (including Qwen, DeepSeek, ChatGLM, ERNIE, MiniMax and Kimi), for any 21 Degrees work, whoever hosts them and whatever interface they sit behind.

The list changes as we review tools. When it does, we update this page.

What goes into AI tools

We sort information into three classes.

Personal data is anything that identifies a living person, such as names with contact details, email addresses, phone numbers, customer records, photos of identifiable people, or health and financial details. It never goes into an AI tool without our AI Team's authorisation. That applies to our own people and to our clients' people, including your customers and audiences.

Client and company confidential information covers briefs, contracts, performance data, strategies, financials and unreleased campaigns. It only goes into tools approved for client documents, on a company account, with personal data removed or anonymised first.

Public information, such as published content, public websites and general research, is fine in any approved tool.

Some things never go into an AI tool, whatever the tool:

  • passwords, API keys and other credentials
  • client customer databases and CRM exports
  • anything under an NDA, until we've checked what the NDA allows
  • payroll, HR or health information about our staff
  • unredacted contracts
  • anything a client has asked us to keep away from AI

We anonymise wherever we can. "A Yorkshire-based retail client with declining organic traffic" usually works as well as a client's name. And an AI summary of a confidential document is treated as confidential too.

Client-specific rules

We work with clients under NDA and in regulated sectors, including finance, health and the public sector. We keep a record of any client rules that are stricter than this policy, such as contract clauses on data handling or subprocessors, and we check it before a client's documents go into an AI tool for the first time. Where a client contract and this policy disagree, the stricter rule wins.

If you'd like us to keep AI off your account, or off part of it, tell us and we'll record it.

Meetings, voices and images

AI meeting notes from Granola, TLDV and Fathom are a normal part of how we work, and our terms of engagement cover them. The tool announces itself, or we tell everyone at the start that the meeting is being recorded. If anyone objects, we stop and take notes by hand. For clients who signed with us before that clause was in our terms, we ask first. Recordings and AI notes are treated as confidential.

We only clone a voice, with ElevenLabs or Descript, when we have documented consent from the person whose voice it is. That includes our own staff. We don't generate images of identifiable people without their consent.

A person checks everything

Every piece of work that leaves 21 Degrees has a named person who has reviewed it and stands behind it, whether it's a report, an ad, a piece of content, code, video or audio. "The AI got it wrong" is never an acceptable answer. Before anything ships:

  • facts, statistics, quotes and citations are checked
  • copy is edited to your brand voice and standards, so what you get is finished work
  • code is reviewed by someone competent to review it, tested, and kept free of hard-coded credentials
  • the depth of review matches the stakes, so a quick internal summary gets a skim and a strategy document gets a full review

Being open about AI

We're open about using AI. It's part of how we deliver, and it's in our terms of engagement. We don't present AI-generated work as entirely handmade, and we don't pass off unreviewed AI output as advice. If you ask how AI was used on your work, we'll tell you plainly.

Work we deliver to clients is assigned to them under the client agreement, the same as any other work.

We don't prompt image, video or music tools with "in the style of" a living artist, photographer or studio, or with characters, logos or brand assets we don't have the rights to. Your own brand assets, used for your work, are fine.

Every client deliverable has meaningful human input in the selection, editing, arrangement and direction, and we keep drafts and working files as a record of it. Before AI-generated music, voice or images ship, we check them against the vendor's commercial-use terms for the tier we hold. AI-generated code is checked for licence problems before it ships to a client. Passing off reworded third-party content as original work is plagiarism, whether a tool was involved or not, so we cite our sources.

Any copyright complaint goes to our AI Team the same day.

Law and regulation

UK GDPR and the Data Protection Act 2018 apply to AI exactly as they apply to any other processing. If personal data goes into an AI tool, we are responsible for it as the data controller. The ICO expects organisations using AI to have documented rules on approved tools, prohibited uses, data classification and staff responsibilities, and this policy is ours.

If AI output ever feeds into a decision that materially affects a person, such as screening job applicants or excluding people from an offer, our AI Team reviews it before any work starts and puts extra safeguards in place. That can include a Data Protection Impact Assessment.

We follow guidance on the Data (Use and Access) Act 2025 as it comes into force. The EU AI Act can apply to UK businesses whose work touches the EU, and some of our clients operate there, so we assess it before any work involving EU residents' data or the EU market begins. Where we're unsure, we take external advice before we act.

This policy is not legal advice, and it doesn't replace the law or anything in a client contract.

Accounts and access

Our team uses company accounts for every AI tool, never personal ones. Two-factor authentication is switched on wherever the vendor supports it, and nobody stores client passwords, API keys or credentials in AI tools. When someone leaves, their AI access is removed as part of our offboarding. Contractors and freelancers don't get AI access by default. When they need it, it's limited to the engagement and has an end date.

AI spend runs through a set budget with a named approver and an audit trail. Anything that would take us beyond that budget goes to our Exec Board.

If something goes wrong

Our team reports AI incidents to the AI Team the same day. An incident includes personal data going into a tool it shouldn't have, an AI error reaching a client or being published, a suspected account compromise, or a tool being used that isn't approved. We would much rather have a fast, honest report than a polished late one, and nobody is punished for reporting honestly.

We contain an incident first, by revoking access, deleting data where the vendor allows it, or pausing the tool. If personal data is involved, we assess whether the ICO and the people affected need to be told, within the 72-hour window that applies to reportable breaches. If a client is affected, the AI Team or the account lead contacts them directly. Every incident is logged, and what we learn feeds into the next policy review.

Training

Everyone on the team takes our internal AI skills assessment, which covers prompting, brand voice, quality control, and tools and workflow. We run monthly team training using real client scenarios with the details anonymised, and we offer one-to-one training on request. New starters complete the assessment and a briefing on this policy in their first month.

Keeping it current

Our AI Team reviews this policy formally on the first working day of every month. Between reviews, it's updated when a tool, a vendor's terms or the law changes. Every change is logged and the team is briefed on it, and we update this page to match.

Questions about how we use AI? Get in touch through our contact page.