preloader Image

Human craft. Smarter systems. See how we do it →

Most Publishers Don’t Have an AI Policy. Here’s Why That’s a Problem.

Jul 10, 2026

Last Updated: August 12, 2026
AI Policy Publishing group of professional adults in suits around a table with papers on it
Key Takeaways
  • Fewer than 30% of publishing organizations have an official AI policy, according to BISG's 2025 survey meaning most teams are improvising without organizational backing.
  • Silence is not neutrality. When no policy exists, your de facto AI policy is whatever individual staff happen to be doing today, with all the inconsistency that implies.
  • A strong policy covers four essentials: approved tools, permitted data, output review, and an escalation path.
  • Only 27% of organizations use closed or enterprise AI models, leaving the majority potentially exposing proprietary manuscripts and author data to public model training.
  • Non-adoption is a legitimate, documentable position. A clear "we don't use AI here, and here's why" is as valid as a pro-adoption stance.
  • 83% of authors prefer their work never be entered into an AI tool, so author-facing clarity carries reputational and contractual weight.

We already know that editorial, marketing, and rights teams are reaching for AI tools without any shared agreement about what those tools are for. The Book Industry Study Group's (BISG) 2025 survey tells us that roughly 43% of respondents working in book publishing use AI tools. So a publisher "without an AI policy" is not actually delaying a decision about AI use to consider things carefully--they're recklessly defaulting to a policy of trusting the judgment of whoever is sitting at the company's many keyboards. 

An AI policy in publishing has moved from a forward-thinking luxury to a baseline operational need, and the organizations that recognize this early will spend far less energy cleaning up after the ones who don't.

The Policy Vacuum in Publishing Is a Bigger Risk Than You Think

AI policy in publishing is not a nice-to-have; it's essential. When your team has no stated guidance about what AI is for, what data can go into it, or who's accountable for outputs, every individual is making those calls alone. Some will be thoughtful. Some won't. And the inconsistency will eventually cost you and the creators who entrust us with their work.

The Book Industry Study Group's (BISG) 2025 survey found that fewer than thirty percent of publishing organizations have an official AI policy in place. For libraries, the number is even lower. Service providers are more likely to have internal AI governance than the publishers they serve. That inversion should give us all pause (and a little chagrin). Publishing can do better, and the good news is that doing better doesn't require a legal department or a six-month committee process.

The absence of a policy doesn't mean the absence of AI but means the absence of oversight.

What a Publishing AI Policy Actually Needs to Cover

Publishing AI guidelines don't need to be long but they do need to be specific. The most effective policies address four things:

    • Approved tools and contexts: which AI tools are sanctioned for use, and in which situations. Drafting marketing copy is a different risk profile than categorizing the slush pile.
    • Permitted and prohibited data: what may and may not be entered into AI systems, stated plainly enough that a freelancer could understand it on day one. And therefore be accountable to it.
    • Output review and ownership: who reviews and approves AI-assisted outputs before they go external, so accountability never evaporates into "the tool did it."
    • An escalation path: exactly what someone does, and whom they ask, when they're unsure if things are going right, or if a new use case requires an update to the policy.

The data security piece is particularly urgent. BISG found that only twenty-seven percent of organizations are currently using closed or enterprise AI models the kind that don't expose your proprietary content, manuscript data, or author information to model training. Enterprise environments such as Microsoft Copilot and Claude for Enterprise are contractually structured to keep your inputs out of training data. A manuscript that touches a public AI model is a manuscript you can no longer fully promise to keep private, and that promise is the foundation of an author's trust.

Why "We're Still Figuring It Out" Is Itself a Policy Decision

You already have a de facto AI policy. It's whatever your team is doing right now, without guidance, oversight, or accountability. Thirty-one percent of individuals in BISG's survey said they're ethically opposed to AI use. Thirty-three percent said they're not interested in using it at all. Forty-six percent of teams across the book industry are actively using it. So some of these active AI users are probably in your organization, operating under different assumptions and rarely talking to each other about it.

The absence of a stated policy doesn't produce neutrality. It's not actually buying any time. It produces fragmentation. Ambiguity is not a holding pattern; it is a liability position that compounds the longer it goes unaddressed.

Of course, writing a policy too quickly can lock you into rules that age badly as tools evolve. The answer isn't to wait, but to write something deliberately revisable — dated, owned, and scheduled for review — so you're never choosing between paralysis and rigidity.

How Do You Build an AI Policy From Scratch?

If you're starting with nothing, the path is more approachable than it looks. Here's the sequence I recommend to publishers who want momentum without overengineering:

    1. Inventory current usage. Find out what AI tools are already in play and in which departments. People will need to feel comfortable "coming out" as AI users--so think this through carefully.
    2. Map your highest-risk exposure points. For most houses, that's manuscript data, contracts, and author personal information. Assign someone to oversee the protection of these exposure points throughout departments like legal, editorial, and sales so everyone is working from the same playbook.
    3. Choose your sanctioned environment. Decide whether you'll move sensitive work into enterprise or "walled garden AI" models.
    4. Align with established frameworks. Lean on BISG's best practices and the OECD AI Principles so you're not reinventing governance from first principles.
    5. Involve every major department. AI governance in publishing requires everyone on in the room. Editorial, marketing, production, rights, and legal each see different risks.
    6. Date it, assign an owner, and schedule review. A policy without a named owner is a policy nobody maintains.

Having an AI Policy Is Not For Adoption but for Clarity

One of the most common mistakes publishing leaders make is treating AI policy as a binary: full adoption or complete refusal. The BISG report explicitly validates a third path. A clear stance of non-adoption for ethical reasons is legitimate and should be documented the same way a pro-adoption policy would be. 

The goal is clarity rather than a particular direction. A well-constructed policy states here is what we do, here is what we don't, here is why, and here is who owns those decisions. It gives your team a framework instead of forcing everyone to improvise. It signals to authors, agents, and partners that you've thought this through, which increasingly functions as a competitive differentiator in acquisitions conversations. And when the regulatory environment shifts, which it will, as disclosure requirements continue to firm up across jurisdictions you'll be updating a living document rather than scrambling to build one under pressure.


At Next Chapter AI, we believe the heart of publishing has always been human craft, an editor's judgment, an author's voice, the relationship of trust between the two. A thoughtful AI policy exists to protect exactly that. By drawing clear lines around what data is safe, which tools are sanctioned, and who stays accountable for every output, you free your people to use AI for the drudgery that drains creative energy while keeping the creative decisions firmly in human hands. The goal was never to hand the work to a machine; it was to give skilled people more room to do the work only they can do.

If your organization is still operating without a stated policy, you have a real opportunity in front of you. Start the inventory this week, gather the people who touch your most sensitive content, and write down even a single page of shared agreement. The publishers who lead this moment with intention rather than reacting to it later will be the ones authors trust, partners respect, and regulators never have to chase. We'd be glad to help you write that next chapter with confidence.

FAQ

What should a publishing AI policy include?

 At minimum: which AI tools are approved and for what purposes; what data may and may not be entered into AI systems; who reviews AI-assisted outputs before they go external; and a clear escalation process for uncertain situations. The policy should be accessible to all staff including freelancers and contractors and revisited at least annually as tools and regulations evolve.

What is a walled garden or enterprise AI model?

A walled garden or enterprise AI model is a closed system where your data is not used to train the underlying model. Unlike consumer-facing tools, enterprise versions of platforms like Microsoft Copilot or Claude for Enterprise are contractually required to keep your inputs private. BISG recommends publishers use these environments to protect proprietary content and author data.

How do we start building an AI policy from scratch?

Start with an inventory of what AI tools are already in use and in which departments. Then identify your highest-risk exposure points typically manuscript data, contracts, and author information. Align with existing frameworks like BISG's best practices or the OECD AI Principles, and involve stakeholders from every major department so the finished policy reflects how work actually happens.

Should our AI policy address AI-generated submissions from authors?

Yes. Many publishers are developing explicit submission guidelines around AI-assisted or AI-generated content. The policy should state your current stance, reflect your author agreements, and be publicly accessible so authors can make informed decisions before submitting. BISG's survey found that 83% of authors prefer their work never enters an AI tool, so author-facing clarity is important.

What's the consequence of not having an AI policy?

Without a policy, your team makes individual judgment calls with no organizational backing. That creates inconsistent practices, potential data exposure, and reputation risk if AI-assisted work is later discovered and disclosed. It also leaves your organization unprepared for a regulatory environment moving toward mandatory AI disclosure and governance standards.

How often should we revisit our AI policy?

At least once a year, and sooner whenever a major tool, contract, or regulation changes. AI capabilities and legal expectations are shifting faster than most internal documents are designed to keep up with, so build review into the policy itself rather than treating it as a one-time project.

Written by Meredith

Meredith Barnes is a creator-career strategist with 15 years of experience across the publishing industry and its ancillaries. She founded Queen Mab Media to help creators build confident, sustainable career strategies. Meredith brings insider knowledge of how publishing houses, literary agencies, and independent publishers actually operate — and where AI creates the most leverage without the most risk.

Pin It on Pinterest

Share This