Brand & Creative

Vanta's AI Writing Policy Came From Legal, Not Marketing. Yours Will Too.

September 28, 2026

Vanta's AI writing policy came from its general counsel, not marketing, and it signals where every company's rules for AI writing are headed next.

Vanta's AI Writing Policy Came From Legal, Not Marketing. Yours Will Too.
Credit:
powered by

Make State of Brand one of your go-to sources on Google

Google Icon
Add State of Brand on Google

A week ago we counted four companies with published AI writing policies and suggested the documents had become a genre. Vanta has now made it five. The security and compliance platform rolled out its policy last week, and the announcement tells you a lot about where these rules are going.

Ian Spain, Vanta's general counsel, explained on LinkedIn how it happened. Someone at a company-wide all-hands asked whether Vanta planned to do anything about "AI slop grenades." Spain launched the policy the next day. He says he wrote it "from a blank page like it was 2015," and he added a line defending the em dashes in his own post. Lawyers love them, he said, so please don't read them as a sign he used AI.

So the top lawyer at a company valued in the billions felt he had to explain his punctuation before anyone had questioned it. People who write for a living will recognize the feeling. Everyone now reads with one eye on who, or what, produced the text.

Legal, not marketing

The more interesting detail is who wrote it. Last week we argued that these policies had turned into a kind of marketing. They get posted on LinkedIn by comms and brand leaders, they collect thousands of reactions, and they tell the market that real people still work here. Heidi Health's policy was shared by its global head of communications, Emma Mackenzie. Clay's was written by an engineer, Sophie Alpert, and became one of the most shared things the company posted all year.

Vanta's came from the general counsel, and that changes what kind of document it is. A marketing team publishes a policy to say something about the company. A legal team writes a policy because someone may one day have to point to it, whether that's in an employee dispute, a customer complaint or an audit. Marketing cares whether the policy lands. Legal cares whether it holds up.

Spain still posted it on LinkedIn, and he clearly enjoyed doing it. But the pen has moved. When the lawyers start drafting the rules for how employees write, the rules stop being a statement of values and start being something the company expects to enforce. Right now Vanta is early. It probably won't be for long.

Two weeks from podcast to policy

Shopify CEO Tobi Lütke used the phrase "slop grenades" on The Knowledge Project podcast on September 15, as Fortune reported. He meant AI output that employees send to each other without reading it, leaving colleagues to sort out the mess. About a week later, an employee at a different company used the phrase in front of everyone at Vanta and didn't need to explain it.

New workplace jargon usually takes months to spread. This took about a week, which suggests people were already living with the problem and were glad to have a word for it.

Who pays for slop

Earlier policies made their case around thinking and ownership. Clay's rests on the idea that writing is thinking and that you should stand behind every sentence you send. Heidi Health's starts from I think, therefore I write.

Spain framed his differently. When someone sends a slop grenade, he wrote, the reader ends up doing the thinking the sender skipped, and that's unfair to the reader. His argument is about fairness, and fairness is a question of who carries the cost.

The cost is going up. BetterUp Labs and Stanford's Social Media Lab surveyed 962 US desk workers this year. More than half admitted to sending workslop. People on the receiving end said fixing it took 3.4 hours a month, compared with roughly two hours in last year's study. An economist would call that an externality, a cost that lands on someone other than the person who caused it. Vanta's policy tries to send the bill back to the sender.

A policy with no evidence

Vanta's whole business rests on one idea: a written policy proves nothing by itself. The platform maps a company's policies to controls, runs automated tests against them, and flags any gap between what the company says and what it does. Auditors don't give credit for owning an access control policy. They ask to see the logs.

No one can produce logs for an AI writing policy today. No test runs against it and nothing flags a violation. It holds only as long as employees choose to follow it, and Vanta has built a large company on the premise that this kind of trust isn't enough.

Vanta also sells AI that writes. Its agent drafts answers to customer security questionnaires, and the company says customers accept 95% of those answers. That doesn't make the policy hypocritical. Every company in this group draws the same line, where the software drafts and a named person takes responsibility for what gets sent. The harder test comes when the drafts are so good that the human review turns into a rubber stamp.

Where this is heading

For most companies, the policy will fade. It will get posted and praised, then drift into the handbook alongside the company values. A few managers will keep pushing back on bloated documents, and at those companies the habit will stick.

The more interesting future is the one a compliance company is well placed to see coming. Heidi Health already lists transparent attribution as a principle. Clay allows employees to share raw model output as long as they label it. The EU AI Act's transparency rules for AI-generated content took effect on August 2. Put those together and you can picture an attribution field in document tools, or a disclosure log, or a new line on vendor security questionnaires asking whether a person reviewed each answer before it went to the customer. Once buyers start asking that question, the writing policy becomes part of the sales process.

The third possibility is that these policies move outside the company. So far they cover memos, docs and Slack. Spain's fairness argument applies even more to customers, though. A prospect reading an AI-padded proposal is doing the seller's homework, and unlike a coworker, the prospect can stop reading and pick a competitor. Companies that mean what they published will extend these rules to sales emails, support replies and marketing copy. Companies that don't will get found out there first.

Handmade as a selling point

Spain's comment about em dashes may be the most telling line in the whole announcement. He wanted readers to know he wrote the policy himself, from scratch.

Expect to see a lot more of that. As handwritten work becomes a mark of care, some people will claim it who haven't earned it. Meanwhile the models will keep improving, and the habits readers use to spot AI writing today, from punctuation to certain turns of phrase, will stop working. Rules that depend on guessing who wrote something won't hold up. Rules that put a person's name behind every sentence have a better chance.

Five policies and counting

Clay, Polarsteps, Leapsome, Heidi Health and Vanta have now all published versions, and they share a vocabulary and a set of principles. Having one no longer sets a company apart. Within a year, most B2B companies that want to look serious about AI will have one.

The companies that stand out will be the ones that can show the policy working. In six months, nobody will care whether a company has an AI writing policy. They'll care whether the company's emails, proposals and support replies read like a person thought about them before hitting send. Vanta sells that kind of proof to everyone else. Its general counsel has just made his own company a test case, and handed every other legal team a draft to borrow.

Outlever Logo

If this caught your attention, that’s not accidental.


Decoration line

The best editorial systems don’t happen by accident. Outlever builds them.

Partial view of green concentric circles with a solid green dot on the outermost circle on a light background.Concentric green circles with a single solid green dot on a dashed circle on a light background.Minimalist design with faint curved lines and scattered small green dots on a white background.

Come back for the reason it lands.


Subscribe for the kind of thinking that makes people stop, read and come back.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.