AI CHARTER

Partner with Intelligence

WHY WE HAVE AN AI CHARTER

At BDB, we recognise the transformative potential of artificial intelligence (AI).

The pace at which it is evolving does not lend itself to rigid, fixed policies. It calls for continuous engagement, vigilance and judgement from every member of our team, plus a clear, honest conversation with every client we serve.

The applications of AI in B2B marketing and communications are diverse, and they shift from team to team, project to project and client to client. What does not shift is our underlying approach. This Charter is not a fixed set of rules. It is a framework that guides how we think, how we decide and how we deliver, so that the value we add to our clients keeps pace with the technology and our commitment to integrity, security and human accountability never wavers.

We commit to reviewing and updating it as the landscape evolves and our adoption deepens.

Our framework

Six principles anchor every decision we make about AI: what we use, how we use it, and where we draw the line.

Human in the loop

AI is not a substitute for human creativity, emotion or insight. We use it to automate, to augment and to clear the path, so our people can concentrate on the work that genuinely moves the dial for clients: counsel, judgement, lateral thinking and craft.

Trust by verification

We value what AI can surface, but we don’t accept it blindly. Every output is subject to human scrutiny. Our trust sits not in the technology, but in the intellect that oversees it.

Accountable for AI’s use

AI can be a powerful collaborator. The final output, however, is ours. We are entirely accountable for what we present to the world.

Ethical use

AI is not immune to bias or ethical blind spots. We are committed to identifying and mitigating these risks, applying equal scrutiny to the inputs we provide and the outputs we receive.

Safe use

Protecting our clients’ data, and the data of the individuals connected to it, is non-negotiable. We will not expose sensitive or confidential information to insecure networks, unapproved tools, or systems that fall short of our standards.

Continuous learning and adaptation

AI is a vehicle, not a destination. As it evolves, so do we. We invest in staying ahead of the technology and in understanding the wider socio-cultural, economic and regulatory implications it brings. This is how we keep our use of AI relevant, effective and aligned with the times.

NO ONE-SIZE-FITS-ALL

Client needs are not identical and neither are their attitudes to AI.

Some are leaning in; some are deliberately cautious; many sit somewhere in between, depending on the workstream, the regulatory environment, or the sensitivity of the information involved.  

BDB has been purposefully built to flex across that spectrum, adapting our infrastructure in line with the new opportunities and challenges AI presents. On any engagement, we can deliver:  

  • 100% human: no AI involvement of any kind across the workstream, scope or deliverable. 
  • Human-led with AI assistance: AI accelerates research, drafting and analysis; humans direct, refine and own the output.
  • AI-dominant with human oversight: AI carries more of the production load; experienced humans review, edit, sense-check and sign off everything that leaves the building.

Which model applies, and to which workstream or specific deliverable will be governed by your corporate guidelines, your risk appetite, your sector’s regulatory expectations and the sensitivity of the brief all inform the answer.

Human and artificial intelligence applied in the proportion right for you.

The tools we use and how we protect your data

We use enterprise-tier AI platforms, selected specifically for their security posture, contractual protections and alignment with our data protection obligations.

Our current core AI stack covers two large language models (LLMs) and a meeting intelligence platform. Each is reviewed, configured and governed by BDB before any team member is given access. 

Large language models (LLMs)

BDB uses two enterprise-tier LLM platforms: Claude Enterprise (Anthropic) and ChatGPT Enterprise (OpenAI). Both are selected for the strength of their data protection commitments and the breadth of their independent certifications.

Common commitments across Claude and ChatGPT Enterprise

  • No training on our data. Customer prompts, files and outputs are not used to train the providers’ models by default. 
  • Encryption. All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). 
  • Configurable retention. Retention periods are set by BDB, with Zero Data Retention (ZDR) available for sensitive workflows. 
  • Independent assurance. Both providers hold SOC 2 Type II and ISO 27001 certifications, with Data Processing Agreements (DPAs) in place to support compliance with UK GDPR, EU GDPR and equivalent frameworks. 
  • Identity and access controls. Access is governed through single sign-on, role-based permissions and audit logging that integrates with our wider security monitoring. 
  • Data residency. Where required for regulatory reasons, content is stored in-region (UK, EU or other approved jurisdictions). 
  • Memory and shared workspaces. Memory features are scoped to individual user accounts and can be disabled. Shared projects sit under the same access controls and audit logging as standard use. Staff are trained on what is, and isn’tappropriate to put into AI tools, shared spaces or memory. 
  • Oversight. Tool selectionconfiguration and ongoing review sit with our CEO Matt Smith and AI Lead Dimo Stoychev. 

Where Claude and ChatGPT differ in detail

Both platforms sit at parity on what matters most to us: no training on customer data by default, strong encryption, configurable retention (including ZDR), the major certifications, GDPR support with DPA, and HIPAA-readiness if needed. A few specifics worth noting: 

  • Claude Enterprise is certified to ISO 27001:2022 and ISO/IEC 42001:2023 (AI management systems), with FedRAMP certification in progress. Bring Your Own Key (BYOK) configurations are all planned. 
  • OpenAI’s Enterprise platform offers data residency across the US, Europe, UK, Japan, Canada, South Korea, Singapore, Australia, India and the UAE, with Enterprise Key Management available. 
  • Both providers offer DPAs, and BAAs where health data is in scope. 

Fireflies

We use Fireflies as our meeting intelligence platform. It records, transcribes and summarises meetings so our team can stay present, ask better questions and capture every action without splitting attention between the conversation and the keyboard.

The value is straightforward: less time consumed by admin, more time on the value-add services clients are actually paying us for. Actions and next steps are captured the moment they’re agreed. A human team member then reviews the notes to confirm accuracy and confirm the key priorities / next steps. Delivery speeds up. Nothing gets lost in someone’s notebook.

We have made deliberate choices about how Fireflies is configured at BDB to protect client confidentiality and personal data.

What Fireflies provides

  • SOC 2 Type II certified, with an independent annual audit of security controls. GDPR compliant and listed on the EU–US Data Privacy Framework. 
  • All data is encrypted at rest and in transit, using the same industry-standard encryption you would expect from online banking. 
  • Meeting data is never used to train non-proprietary AI. Fireflies uses underlying AI providers (such as OpenAI) to generate summaries, but those providers are contractually required to delete the data immediately after processing. Nothing is retained on their side. 
  • Fireflies staff cannot access our meetings. If access is ever needed, for example to troubleshoot a support issue, they have to ask us first. 
  • Data is hosted on Google Cloud and AWS. BDB has agreed UK/EU data residency with Fireflies under our Enterprise contract, so client meeting data sits within the UK / EU region. 

How BDB has configured Fireflies

  • Sign-in is through our Microsoft 365 credentials, so there are no separate passwords to manage. When a team member leaves BDB or is removed from the security group, Fireflies access is revoked automatically. 
  • Auto-join is enabled for meetings with a conference link. Individual users can toggle the bot off for specific meetings from their dashboard. 
  • Recording captures audio, full transcript and AI summary. Video recording is disabled. 
  • Consent: when the bot joins a Teams meeting, it posts a message in the meeting chat confirming that recording is taking place. Pre-meeting email notifications are available as an additional option. 
  • Access is restricted to people on the meeting’s calendar invite. This is enforced at admin level and cannot be overridden by individual users. 
  • Client separation: each client has its own private channel inside Fireflies. Meetings are routed automatically based on participants. Only team members assigned to that client can see the content. 
  • Email summaries are sent only to @bdb.global addresses. Clients do not receive these automated emails. 
  • External sharing is disabled. Users cannot generate a link to share a transcript outside BDB. 
  • Anyone on a Teams call can remove the Fireflies bot at any time from the participants panel. Admin-level rules can also skip sensitive meeting types (e.g. HR one-to-ones) automatically. 

If you would prefer that Fireflies is not used in your meetings, whether at all or for specific sessions, please tell us. 

We will switch it off. Our default settings exist to make BDB more useful to you, not to override your preferences. 

Where your data lives: hosting and segregation

Client information sits on Microsoft Azure, hosted within UK / EU regions in line with our data protection commitments. Azure is the backbone of how we store, share and collaborate on client work, and it is governed by Microsoft’s enterprise-grade security infrastructure, including the full suite of ISO, SOC and GDPR-aligned certifications.

Client segregation

BDB operates strict logical separation between client environments. Each client has its own dedicated workspace, with access controlled at user and group level. Team members can only see the clients they are working on. This matters most when clients operate in the same sector, or are direct competitors. Our agency has long worked across complementary and sometimes overlapping industries; the segregation model is what allows us to do that with absolute confidence. 

Market-sensitive and confidential information

Where we handle market-sensitive information, for example in support of corporate announcements, transactions or regulated disclosures, additional controls apply. Access is restricted to a named, minimum-necessary working group. AI tools are configured for that workstream specifically (including, where appropriate, Zero Data Retention). Use of AI on market-sensitive material is always explicitly agreed in advance with the client. 

Identity, access and audit

    • Single sign-on across Microsoft 365 and connected platforms. 
    • Role-based access. People see what they need to do their job, and nothing more. 
    • Audit logs for AI tool use, file access and sharing activity, integrated with our wider security monitoring. 
    • Automated offboarding: when someone leaves BDB, access across every system is removed in a single step. 

GDPR AND REGULATORY COMPLIANCE

BDB is fully committed to compliance with the UK GDPR, EU GDPR and the Data Protection Act 2018. Our use of AI sits inside that framework, not outside it. 

 

In practical terms, that means: 

  • Personal data is only processed on a lawful basis, and only to the extent necessary for the work we are engaged to do. 
  • Data Processing Agreements (DPAs) are in place with our enterprise AI providers and our wider technology supply chain. 
  • Data minimisation: we don’t pass personal data into AI tools when we don’t need to, and we don’t keep it longer than required. 
  • Where AI is used on a workstream that involves personal data, the DPIA (Data Protection Impact Assessment) implications are reviewed before work begins. 
  • Data subject rights, including access, correction and erasure, are honoured across our systems, even where AI tools form part of the processing chain. 
  • International data transfers are governed by Standard Contractual Clauses where required. 

Clients in regulated sectors (financial services, healthcare, energy, legal, professional services) should expect, and will receive, additional protocols tailored to your specific obligations. We discuss and document these at the outset of every engagement. 

HOW WE USE AI ACROSS OUR SERVICE LINES

AI shows up differently in different parts of the agency.

 

The principles in our framework (human first, trust by verification, accountability, ethics, safety, continuous learning) are constant. The application varies. This section sets out, by service line, how AI typically supports the work, and where the human stays firmly in charge. 

 

Research, strategy and planning

AI helps us move faster through the synthesis stage so we can spend more time on the thinking that genuinely shapes our insights and direction.

Where AI helps

  • Synthesising large bodies of research, such as analyst reports, customer interviews and sector news, into structured themes. 
  • Trend monitoring and signal detection across audiences, channels and competitors. 
  • Stress-testing positioning, messaging and narrative hypotheses before they are taken to a client. 
  • Modelling audience segments, personas and buyer journeys against available data. 

Where the human stays in charge

  • Interpretation, narrative judgement and the strategic recommendation itself. 
  • Anything that involves a client-specific opinion, perspective or commercial implication. 
  • Final source verification. We don’t take AI-generated facts at face value. 

PR

AI accelerates the operational rhythm of PR (research, monitoring, drafting) without ever substituting for the relationships and judgement our PR team brings to your account.

Where AI helps

  • Journalist and outlet research, including a study of each reporter’s coverage focus and a review of their recent work. 
  • Media monitoring, coverage analysis and share-of-voice reporting. 
  • First-draft press releases, statements and bylines, refined and approved by senior PR practitioners. 
  • Q&A preparation, message-house stress-testing and crisis scenario rehearsal. 

Where the human stays in charge

  • Every relationship: pitching, building rapport, sensitive briefings, off-record conversations. 
  • Final approval of any material released into the public domain, on your behalf. 
  • Crisis response in real time. Decisions sit with senior counsel, not a model. 
  • Anything market-sensitive, which is handled on agreed protocols, with restricted access and additional controls. 

Marketing consultancy

AI gives us greater depth and speed across diagnostics and benchmarking, so our consultants can spend their time where it counts: on counsel and the conversation with clients.

Where AI helps

  • Marketing audits, capability assessments and maturity benchmarking. 
  • Competitor and category landscape analysis. 
  • Synthesis of stakeholder interviews and survey data. 
  • Modelling go-to-market scenarios and channel mix options. 

Where the human stays in charge

  • The recommendation and the rationale. 
  • Boardroom-grade counsel and stakeholder management. 
  • Anything that depends on context: culture, politics, client appetite, commercial reality.

Creative

AI is an accelerant in creative. It helps us explore more directions, faster, before we commit. It does not replace the craft, taste or originality of the team.

Where AI helps

  • Ideation, route generation and ‘what if’ explorations during the divergent phase. 
  • Visual reference, mood-boarding and concept visualisation. 
  • Production support, such as tidying assets, generating placeholder visuals and scaling concepts into multiple formats. 
  • Accessibility and inclusivity checks on creative output. 

Where the human stays in charge

  • The creative idea itself. Original thought is the job. 
  • Art direction, design judgement and craft. 
  • Copyright awareness and integrity. 
  • Cultural sensitivity, representation and brand fit. 

Copywriting and content

AI helps us draft faster and edit smarter. It does not write in your voice without us, and we never present AI output as finished work.

Where AI helps

  • First drafts of long-form content (articles, whitepapers, thought leadership) that human writers then shape. 
  • Headline and subject-line variations, A/B test alternatives, CTA rewrites. 
  • Tone-of-voice alignment checks against brand guidelines. 
  • Repurposing one core asset into channel-specific variants. 
  • Proofreading, fact-pattern checks and consistency reviews. 

Where the human stays in charge

  • Voice. AI can imitate; it cannot originate. 
  • Insight and point of view, the ‘so what’ that makes content worth reading. 
  • Fact-checking against primary sources. We do not publish AI-generated assertions unverified. 
  • Plagiarism and originality checks before delivery. 

Digital

Digital is where AI moves fastest, and where the discipline of measurement, governance and ethical use matters most.

Where AI helps

  • SEO research, keyword clustering, on-page recommendations and content briefs. 
  • Performance analysis across paid, organic, email and web, surfacing patterns humans would miss. 
  • Personalisation and audience modelling within client-approved data sets. 
  • Web and CRM tasks: schema generation, technical SEO checks, lifecycle email drafting, landing-page variants. 
  • Reporting automation that turns raw analytics into clear narrative for client review. 

Where the human stays in charge

  • Strategic recommendations on channel mix, investment and creative direction. 
  • Targeting decisions, especially anything touching sensitive audience attributes. 
  • Final QA on anything that goes live in a client’s name. 
  • Compliance with platform-specific advertising standards and data regulations. 

DO’S AND DON’TS FOR THE BDB TEAM

Every member of the BDB team is briefed on this Charter and trained on the practical application of it. The behaviours below are non-negotiable. 

 

Do

  • Stay informed. Engage with internal training and keep current on AI tools, capabilities and risks.
  • Be transparent. Tell clients where and how AI is being used on their account, and explain its benefits and limitations honestly. 
  • Verify. Treat AI outputs as a starting point. Check facts against primary sources before anything goes to a client.
  • Respect copyright and IP. Validate that AI-assisted creative and copy complies with copyright law and brand-licensing obligations.
  • Use approved tools only. If a tool is not on the BDB-approved list, don’t use it for client work.
  • Protect data. Do not enter personal data, market-sensitive information or client confidential material into AI tools unless the workstream is explicitly configured to handle it.
  • Seek feedback. Talk to clients about how AI is, or isn’t, helping. Their input shapes how we use it next.

Don’t

  • Over-rely on AI. It augments human creativity; it does not replace it. The human signs the work. 
  • Mislead clients. Never present AI-generated content as fully human-authored when that materially matters.
  • Ignore bias or cultural sensitivity. AI inherits the biases of its training data, so review for it.
  • Adopt new AI tools without approval. New tooling goes through a security and data protection review before it touches client work.
  • Compromise on ethics. If something feels off (bias, accuracy, transparency), escalate before you ship.

OUR PROMISE TO CLIENTS

This Charter is not a wall of compliance language. It is a working agreement between BDB and the clients who trust us with their brands, their reputations and their commercial outcomes. 

 

We will be transparent

You will always know where, why and how AI is used on your account. We will not hide behind it, and we will not pretend it isn’t there. 

We will be accountable

Whatever AI contributes, BDB owns the quality of the output. The buck stops with our people, not with a tool. 

We will be tailored

Your appetite, your risk profile and your sector all shape how we apply AI on your account. The default is the conversation, not the assumption. 

We will be vigilant

On data protection, security, copyright, ethics and accuracy. These aren’t features. They’re the floor we build everything else on. 

We will keep learning

This Charter will be reviewed and updated at regular intervals. Our adoption will evolve. Our standards will not slip. 

 

 

This Charter will be reviewed and updated at regular intervals. Our adoption will evolve. Our standards will not slip. 

 

If you have any questions about our use of AI, or want to explore the applications of AI for your business, contact us.