1. Guiding Principles

Indigo’s principles are:

  • Excellence is our goal.
  • We always start with people.
  • We consider privacy, equity and sustainability by design.

These company principles have guided the development of this AI policy and our guiding principles in relation to our use of AI, both for business efficiency and client delivery.

AI is human-centred

  • AI supports our thinking and work. It does not replace professional judgement or expertise. Indigo remains accountable for all outputs.

We use AI proportionately

  • We use AI where it clearly adds value, not for its own sake.

We use AI knowingly

  • Anyone using AI at Indigo should understand what it does, what data it handles and what its limitations are, before using it on client work. We provide training and guidance to support this.

We are transparent

  • We will be open with clients where and howAI has been used in analysis or to create outputs, especially where it affects findings or recommendations.
  • Our contracts state that we use AI in line with this policy, and link to it.
  • Where AI is central to how we will do a piece of work, we say so in the proposal.

We respect creative practice

We will not:

  • use AI to replace creatives we would normally commission, particularly photographers, artists or graphic designers;
  • use AI-generated music.

We protect data

  • We will only use approved AI tools for client, organisational or audience data, and only where the provider commits contractually not to use our inputs to train their models.

We avoid personal data

  • We will not put personal data into AI tools as a default.
  • Any exception would need clear justification, safeguards and approval.

We check AI outputs

  • AI-generated content will always be reviewed before it is shared or used in decision-making, and where AI has been used to produce or summarise data, it is checked back against the source.
  • We are alert to the risk that AI can under-represent or misclassify particular groups, and apply the same scrutiny to AI-assisted analysis that we would to our own.

We are mindful of impact

  • We will be proportionate in our use of AI, including considering environmental impact.

2. Acceptable use: what we will use AI for

Indigo administration

Supporting routine admin tasks, such as:

  • drafting or summarising notes;
  • organising information;
  • preparing internal materials.

Project work and client delivery

  • Supporting analysis, synthesis, pattern spotting and sense-checking.
  • Assisting with drafting, structuring or refining outputs, where these are reviewed and owned by Indigo staff.
  • Exploring and working with data or code.
  • Preparing and presenting data, including tables, charts and dashboards.

Indigo Share

  • Using AI to help aggregate and analyse audience insight at scale, where this adds value and supports collaboration.
  • Developing models or tools that draw on aggregated insight, without including personal or identifiable data.
  • Where we generate synthetic or modelled data, we agree it with the client in advance, keep a record of how it was produced, and make synthetic elements identifiable in any dataset or output.

3. Prohibited use: what we will not use AI for

Indigo administration

We will not:

  • video or audio record meetings using AI tools unless all participants have explicitly agreed;
  • use more than one AI note-taking tool in a single meeting, to avoid unnecessary duplication and environmental impact;
  • retain AI-generated meeting records for longer than necessary or outside agreed storage arrangements.

Project work and client delivery

We will not:

  • input client, audience or personal data into AI tools that do not meet our data protection standards;
  • present AI-generated content as fully human-produced or allow AI to replace professional judgement;
  • use AI to create outputs that undermine creative or research expertise we would normally commission.

Indigo Share

We will not use AI within Indigo Share to:

  • process identifiable audience data;
  • create models that obscure provenance, bias or limitations;
  • replace the collaborative and interpretive nature of the offer.

General prohibitions

We will not:

  • use AI tools “for their own sake” or simply because they are available;
  • use AI systems that we do not understand or that have not been approved;
  • use AI in ways that conflict with our values, client trust or MRS obligations.

4. Tools and Compliance

Which AI tools we use, and how they are approved

Indigo uses a number of AI tools, either as core tools or in trial, to support administration, analysis and delivery.

We do not list individual tools in this policy. They change too quickly for a policy document to stay accurate, and our particular combination of tools is part of how we work. The tools we use are recorded in Indigo’s AI Tools / Platforms Log, and clients may ask us which we have used on their project.

No AI tool is considered “approved” for team use unless it appears on Indigo’s AI Tools / Platform Log. New AI tools are not adopted informally. Tools are tested in a limited, controlled way, using low-risk data, then logged and assessed against agreed criteria, and a clear decision is recorded.

Indigo’s AI Tools / Platform Log:

  • captures all AI tools in use or under review;
  • assigns a status;
  • records risks, mitigations and decisions;
  • is reviewed and updated every three months.

Cyber security, data protection and GDPR risks

AI platforms present data protection, security and compliance risks, particularly where tools:

  • store or reuse user inputs;
  • train models on uploaded data;
  • make data deletion or correction difficult.

To manage these risks, Indigo will:

  • assess tools against UK GDPR and MRS requirements before use;
  • limit data inputs and avoid personal or sensitive data by default;
  • use tools with appropriate security and privacy controls;
  • document risks, mitigations and decisions centrally;
  • review tools regularly as platforms and terms change.

High-risk uses or tools will require additional safeguards or be prohibited.

Recording AI use on projects

We use AI routinely across our work and do not log every use. What we record is enough to answer questions about how a piece of work was produced.

  • At project close, we note in the project file what AI contributed to the outputs, and anything that limits confidence in it.
  • We record at the time, rather than at close, where something is out of the ordinary, where synthetic or modelled data has been used, where a limitation or risk has been identified, or where a client has their own requirements about AI use.
  • Together with the AI Tools / Platforms Log, this lets us answer client, audit or quality queries, and supports internal review and learning.

Last reviewed July 2026