Compliance · Stay in Control
AI Guardrails for Dealerships: Compliance, Legal & Data Rules
AI in a dealership isn't risky because the technology is wild. It's risky when nobody wrote down the rules. Write them down. Here's the framework.
Why guardrails come before scale
A dealership runs on regulated conversations: advertising claims, financing terms, privacy-protected customer data. AI accelerates whatever it's aimed at, so it accelerates compliant output or non-compliant output. The difference is whether the boundaries were encoded before you hit the gas. Guardrails aren't the brakes on your AI program — they're what makes it safe to drive fast.
Layer 1: Data boundaries — what never goes in
- Never: Social Security numbers, credit applications, credit bureau data, driver's license images, bank details, or any nonpublic personal information covered by the FTC Safeguards Rule and GLBA obligations your store already carries.
- Careful: customer names and contact info — only in tools whose commercial terms and data handling your store has actually reviewed (understand whether inputs are used for model training and how long they're retained).
- Free: inventory data, your own marketing content, public competitor information, anonymized reports.
Make the "never" list physical. Print it. Every person with an AI login signs it.
Layer 2: Output rules — what AI never says
These belong written into every customer-facing Skill and agent as hard constraints, not remembered by whoever's prompting:
- No payment or rate quotes — payment advertising is regulated (Reg Z territory); keep it human and disclosed
- No availability, price-match, or delivery promises
- No warranty or mechanical-condition claims beyond documented facts
- No superlative claims your store can't substantiate ("lowest prices in the state")
- Required disclaimers preserved wherever your ads carry them today
This is exactly what a rules knowledge file is for: write the constraints once, and every prompt, Skill, and agent inherits them.
Layer 3: Review policy — who approves what
| Output type | Review level |
|---|---|
| Internal analysis, summaries, drafts | Use freely — inspect like any employee's work |
| Customer-facing messages (email, SMS, chat) | Human reviews every send until a track record exists; spot-check forever |
| Advertising, pricing, offers | Manager approval, same as pre-AI |
| Anything touching financing terms | Human-only, full stop |
Layer 4: A written AI policy (one page is enough)
Approved tools and accounts · the data "never" list · output rules · review requirements · who owns the policy · what happens when something goes wrong. One page, signed, revisited quarterly. The stores that skip this step don't avoid AI incidents — they just discover them later, without a paper trail.
The counterintuitive part: tight guardrails make teams use AI more, not less. People hold back when the rules are fuzzy. Clear boundaries remove the fear of stepping on a landmine.
Where this fits in your learning path
Guardrails are step four of the foundation — after prompts, knowledge files, and context, before agents run anything real. At the Intensive, legal and AI considerations get a dedicated session before the first agent team goes live, and every build that follows inherits the rules. See the agenda.
Build It Safe. Build It Fast.
Guardrails, legal considerations, and working systems — all in two hands-on days.
Save My Seat — $500 Off by Aug 1 →