Solo AI Rules for Client Work
New to AI5 min readFreelance & Solopreneur AI

Solo AI Rules for Client Work

Before you put a client's brief, draft, or data near a consumer AI tool, write a one-page personal policy card: what you will never paste, what needs client consent, what you still price and scope yourself, and when you escalate to a human specialist. Freelancers do not inherit an employer AI policy - you need your own.

What you should be able to do

As a freelancer or solopreneur you are not covered by an employer's approved-tool list. Write a short personal AI policy for client work before the next retainer starts: hard paste bans, disclosure habits, pricing and scope ownership, and escalation triggers. The card is the decision, not the chat window.

AI Expert TeamPublished: Jul 31, 2026
Saved only in this browser.
In this article

A designer on a three-month retainer opens ChatGPT to “clean up” a client status email, pastes last week’s notes, and only later notices the notes include an unreleased product name and a competitor comparison the client marked confidential. Nobody at an employer IT desk is going to catch that. You are the policy owner, the operator, and the person whose signature sits on the NDA.

This article is for freelancers and solopreneurs who sell work to clients. It is not workplace individual literacy for employees under a company AI policy - that reader has a different first step: reading the employer’s AI policy. Your constraints are client contracts, NDAs, your own reputation, and consumer-protection rules that still apply when you advertise services. Company-wide AI strategy for teams belongs elsewhere; here the unit of judgment is you.

What a personal policy card is for

A policy card is a short written set of rules you decide once, then apply under deadline pressure. It answers four questions before any model is involved:

  1. What never goes into a consumer AI tool on client work?
  2. What requires explicit client permission or a contracted tool tier before AI use?
  3. What decisions stay human even when AI drafts the wording (price, scope, promises, legal conclusions)?
  4. When do you stop and escalate to a lawyer, accountant, collaborator, or the client?

Without that card, every late-night prompt becomes a one-off ethics decision. Those decisions drift.

Client secrets, proposal text that contains third-party data, and contract clauses are not “prompt context.” Treat them as confidential until you have a written rule and, where needed, client agreement about tools. See also do not paste client secrets into AI.

Common misconception

The misconception is that “I am my own boss, so any tool is fine.” Autonomy does not cancel confidentiality. If you signed an NDA or a confidentiality clause, the duty runs to the client, not to your preferred chat product. A second misconception is that enterprise marketing copy on a consumer login equals a client-safe data path - it does not. Check the actual product tier and data terms for the account you are logged into, on the day you use it (OpenAI Data Controls FAQ; Anthropic privacy policy; Anthropic consumer privacy center).

Illustrative scenario (labeled)

Illustrative scenario, not a measured case: A solo copywriter asks a consumer model to “rewrite this proposal more persuasively” and pastes a full draft that includes the client’s unpublished pricing table and a named partner company. The model returns smoother prose. The exposure already happened at paste time, whether or not the chat is later deleted. The policy-card fix is upstream: proposals with third-party commercial data stay out of consumer tools unless the client has approved a specific tool path.

The five rules worth writing down

1. Paste bans (hard stops)

List categories you will not paste into consumer AI: credentials, full contracts, unpublished financials, personal data of the client’s customers, security details, and anything the SOW or NDA calls confidential. Mirror the stop-check habit from work secrets guidance for employees, but remember your duty runs to the client, not an employer.

2. Allowed assists (narrow)

Allow AI for structure, grammar, outline options, and anonymized pattern questions - after you strip identifiers. Keep a note of which tool and tier you use per client if they ask.

3. You still own price and scope

Models can help organize a proposal. They do not set your rate or invent delivery promises. Proposal drafts you still price and scope change logs cover the workflows; the policy card only needs the sentence: “I never accept AI-suggested fees or deadlines without my own check.”

4. Disclosure when it matters

Where a client, platform, or jurisdiction expects you to say when AI assisted a deliverable, say so. Keeping your name on AI-assisted work and workplace-style disclosure norms are useful patterns; adapt them to client contracts rather than employee handbooks. Truth-in-advertising rules still apply to how you describe your services (FTC advertising and marketing guidance; FTC crackdown on deceptive AI claims and schemes).

5. Escalation triggers

Write the moments you will not “ask the model”: tax treatment, contract enforceability, regulated advice, medical or legal conclusions, and any situation where a wrong answer creates a client liability you cannot absorb. Treat those as risk-governance triggers, not prompt failures (NIST AI Risk Management Framework). When solo AI is not enough expands this.

Do not treat a fluent model answer as a substitute for a licensed professional when the question is legal, tax, medical, or regulated financial advice. Fluency is not a credential.

One exercise for today

Open a blank note. Title it with your name and “Client AI rules.” Fill the five sections above in under 20 minutes. Pin it next to your proposal template. The solo client AI rules card is a printable version of the same structure.

EU readers advertising to consumers should also skim how unfair commercial practices rules treat misleading claims (Directive 2005/29/EC) - the point for a solo operator is simpler than compliance theater: do not let AI-drafted marketing overstate what you deliver.

Where this sits relative to employee AI literacy

Employees ask “is this tool approved?” Freelancers ask “did I agree with the client how tools and data work, and can I defend that choice if something leaks?” Same technology, different accountability stack. Keep the card short enough that you will actually use it on a Thursday night.

Read next

Continue through the same learning path with the next practical articles.