friday, september 18, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

What to do when a client bans AI

Find out where each client stands before it matters, pick the account tier their rules require, and answer the disclosure question without losing the work.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

The message arrives without warning. A client forwards an updated vendor agreement with a new clause about generative AI. A platform you publish on adds a checkbox asking whether the content was AI-generated. A buyer you have been courting for eight months stops taking meetings about the whole category. None of these are debates you get invited to. They are procurement decisions, made two or three levels above the person who briefs you, and they show up finished.

New York City published the most public version of this on 2 September 2026, when it put a moratorium on student-facing generative AI for grades 2-K through 8 and prohibited companion chatbots across all grades for the 2026-2027 school year [1]. The city describes it as “the most expansive student-facing AI moratorium in the nation” [1]. That is one institution and one category, but the shape of it is the shape of every AI restriction you are likely to meet: sudden from the outside, specific on the inside, and decided by someone weighing a risk you never see. This guide is about what to do in the week one lands on your desk, and what to set up beforehand so it costs you a conversation instead of a contract. It is not for people running district-scale procurement or student data compliance, and it is not legal advice about your particular agreement.

A buyer’s rule is narrower and stranger than its headline

Read as a headline, the policy is that New York banned AI in schools. Read as a document, it says something more useful. Teachers continue to be permitted to use AI for instructional planning and operational tasks, provided the tools meet the school system’s safety standards [1]. Exceptions are written in for assistive technology used by students with disabilities, for multilingual learners, and for students in career readiness programs such as computer science [1]. High schoolers did not lose access; they got capped pilots, a maximum of 50,000 high school students in general education classes, no more than five classes per high school, five named pilot programs, plus two 45-minute AI literacy modules available to all high school students twice a year [1]. The city also recommended daily one-to-one screen time caps of 30 minutes for grades 3 through 5 and 45 minutes for grades 6 through 8, which tells you the concern was never AI alone [1]. A Technology in Schools Coalition convenes throughout the 2026-27 school year to assess the impact of the moratorium and the limited pilots, and will publish a report with recommendations for future school years [1].

Read only the headline and you write off a buyer that is still purchasing teacher tools, accessibility software and literacy curriculum. Read the document and you find a list of the uses that survived. That list is the actual information, and the same is true of the vendor agreement your client just sent you. The clause almost never says “no AI”. It says no AI for a named activity, or no client data in a named category of tool, or disclosure required under a named condition. Before you rearrange your business, find the sentence and read it twice.

What gets restricted is unsupervised access and unaccounted data

Two questions run under nearly every institutional AI rule. Who is answerable for the output, and where did the material go. New York’s answer to the first was an adult in the room: pilots run in classes, under teachers, with literacy instruction attached, and the mayor’s framing was that “Children need teachers and human connection in order to learn and grow” [1]. The second question is the one you control directly, and it has a factual answer per tool and per account.

The vendors publish it. On consumer Claude, chats are used to improve models if you choose to allow it or otherwise explicitly opt in, such as by joining the Trusted Tester Program, and incognito chats “are not used to improve Claude, even if you have enabled Model Improvement in your Privacy Settings” [2]. Anthropic’s commercial terms state that “Anthropic may not train models on Customer Content from Services” [3], and Team and Enterprise plans are sold with no model training on your content by default [4]. OpenAI’s enterprise privacy page says “We do not train our models on your data by default”, and its business documentation states that “OpenAI does not train on your workspace data” [6][5]. Google’s commitment for Workspace is that it “does not use customer data for training models without customer’s prior permission or instruction”, and that your content is not human reviewed or otherwise used for generative AI model training outside your domain without permission [7].

So when a client asks whether their documents went into an AI, the honest answer has two halves, and only the second one is interesting to them. Which tool, and which account. A freelancer pasting a client contract into a personal chat with model improvement switched on is in a different position from the same freelancer doing the same thing on a business workspace, and the difference is a settings page and $20 to $25 a seat a month [4][5].

The account tier answers most client policies before you have to argue

The tier you are on is the cheapest compliance work available to a small operation. On Claude, a Team standard seat is $25 per seat per month billed monthly or $20 billed annually, for teams of 2 to 150; premium seats are $125 and $100 on the same terms; the individual Pro plan is $20 a month, or $17 a month when billed annually at $200 up front [4]. ChatGPT Business is priced the same way, at $25 per user per month monthly or $20 annually for standard seats and $125 or $100 for premium seats, with a minimum of two paid seats and a maximum of 200 combined seats per subscription, though workspaces created before 24 August 2026 retain their previous seat limit [5]. Two seats is the floor on both, which for a solo operator means buying one seat you do not strictly need.

What the money buys is not better output. It is answers to procurement questions. OpenAI’s business and enterprise products carry SOC 2 Type 2, a Data Processing Addendum for Business, Enterprise and API users, a Business Associate Agreement for the API Platform, and a Student Data Privacy Agreement covering its education products; deleted Business conversations are removed within 30 days unless retention is legally required, and API data may be retained for up to 30 days [6]. Google’s Workspace commitments sit inside the Cloud Data Processing Addendum and the service-specific terms rather than in a blog post [7]. Ownership is settled in the same documents: OpenAI states you retain all rights to the inputs you provide and own the output you rightfully receive [6], and Anthropic’s commercial terms say the customer “retains all rights to its Inputs” and “owns its Outputs”, with Anthropic assigning to the customer its right, title and interest, if any, in the outputs [3].

None of that is exotic, and that is the point. When a client’s legal team asks where the material goes and who owns the result, a business account lets you send a link to a page written by the vendor’s lawyers instead of an assurance written by you. A personal account leaves you arguing from memory.

Disclosure is a definition problem before it is an ethics problem

Most disclosure fights happen because two people are using one word for two different activities. Amazon’s rule for its publishing platform is the clearest public split on a platform that has to enforce one, and it is worth borrowing whatever you sell. Content is “AI-generated” if an AI-based tool created the actual text, images or translations, and it stays AI-generated “even if you applied substantial edits afterwards” [8]. Content is “AI-assisted” if you created it yourself and used AI tools to “edit, refine, error-check, or otherwise improve” it, or used AI to brainstorm and generate ideas but wrote or made the thing yourself [8]. Amazon requires disclosure of the first category, and states “You are not required to disclose AI-assisted content” [8].

Take that distinction and write your own two-line version before a client asks for one. Something like: research, outlining and editing are AI-assisted; any section drafted by a model is marked and rewritten by me; nothing identifying your customers goes into a consumer account. Send it with your proposal. Volunteering the line converts a suspicion into a specification, and a specification is something a client can approve. It also protects you from the retroactive version of the question, which is the unpleasant one.

Do this even where nobody asks. The policies that get written eventually are written by people who were surprised once, and being the vendor who was already explicit is a durable position.

Keep the deliverable separable from the tool

The last piece is structural. If the thing you deliver lives inside a vendor’s workspace as a project, a shared thread or a hosted document, then a client’s policy change does not merely inconvenience you, it strands the work. Deliver files the client can open without an account. Keep the reusable part of your process, the briefing material, the worked examples, the constraints you have refined over 30 jobs, in your own notes rather than inside a feature that belongs to one vendor.

Done that way, a ban costs you speed and nothing else. You lose the fast path and fall back to the slow one, on a deliverable that was always going to be a document. Done the other way, you find out how much of your business was a licence agreement you did not read. The same discipline covers the cases that have nothing to do with policy, like a tool changing its plans, its limits or its owner while you are mid-project.

checklist
Before you use AI on a client's work
0 of 8 · saved in this browser only
calculator
What a compliant tier costs, as a share of the work it protects
% of the at-risk revenue

seats × monthly seat price × 12, as a percentage of the annual fees from clients whose policy requires that tier. Computed in the page; nothing is sent anywhere.

What still goes wrong

The retroactive question has no good answer. A client adopts a policy in March and asks what you used on the January project, and nothing in your account settings reaches backwards. The only defence is a habit you started earlier: a line in each job file saying which tool, which account, and which parts of the draft came from a model. That habit costs a minute per job and is worth more than any subscription tier, which is annoying, because the subscription is the part you can buy today.

A business account also does not override a contract. Some agreements bar third-party processors outright, whatever the training defaults say, and no settings page fixes that. Some clients will hear “AI-assisted” and treat it as disqualifying even though Amazon states you are not required to disclose it [8], because Amazon’s split is Amazon’s policy for its own platform, not an industry standard. Expect to meet people whose line sits somewhere else entirely, and decide in advance which of those jobs you want.

And the rules move in both directions without consulting you. New York’s moratorium comes with a coalition due to publish recommendations for future school years, which means it may loosen, tighten or be extended, and no vendor and no supplier gets a vote [1]. The vendor defaults are settings and contract terms rather than promises about the future, so the consumer model improvement toggle is worth re-checking rather than remembering [2]. Plan for a rule you did not write to change the economics of a client you did not want to lose. That is the durable version of the story, and the only part of it you can prepare for.

sources
  1. 01NYC Mayor's Office — Mayor Mamdani and Chancellor Samuels put students first with nation's broadest generative AI moratorium in schoolsnyc.gov
  2. 02Anthropic — Is my data used for model training?privacy.claude.com
  3. 03Anthropic — Commercial Terms of Serviceanthropic.com
  4. 04Anthropic — Claude pricingclaude.com
  5. 05OpenAI — ChatGPT Business general FAQhelp.openai.com
  6. 06OpenAI — Enterprise privacyopenai.com
  7. 07Google — Generative AI in Google Workspace Privacy Hubknowledge.workspace.google.com
  8. 08Amazon KDP — AI content guidelineskdp.amazon.com
next guide
Ads in AI assistants: what changes for your work
9 min · verified 2026-09-05
related guides