The AI margin and governance check

Important note

This tool supports internal management decisions. It does not replace legal, privacy, security or regulatory advice, and it does not certify legal compliance.

EU AI Act and GDPR requirements may depend on the workflow, the data, the people affected, the agency’s role and the suppliers involved. Verify current requirements against official sources or qualified counsel before using this tool with clients or making a client-facing commitment.

Part 1: fast triage (below)

Download and complete this document.

If you select Red 🟥 or Grey ⬜, do not scale the workflow yet. Complete Part 2 to identify the issue and agree on corrective actions.

If you identify Possible regulatory exposure, obtain the relevant legal, privacy or regulatory input before scaling the workflow or making a client-facing commitment.

Part 2: Full assessement

Complete this section before:

  • scaling a workflow across the agency;

  • including it in a client offer;

  • connecting it to client or production systems;

  • allowing it to take external actions;

  • or whenever Part 1 identifies a Red, Grey or possible regulatory exposure.

Examples of workflows

  • AI-assisted content creation.

  • Automated reporting or analysis.

  • Lead qualification or prospecting.

  • Media buying or campaign optimisation.

  • Image, video or audio generation.

  • Client-service chatbot.

  • AI agent connected to business systems.

  • Internal research or knowledge management.

1. Business value

Is there a clear business case?

Main reason for using this workflow

Select the most important reason:

☐ Reduce delivery time
☐ Increase agency capacity
☐ Improve quality or consistency
☐ Improve client or customer experience
☐ Increase revenue
☐ Improve margin
☐ Enable a new service
☐ Other:

Is the intended outcome clearly defined?

🟩 We can describe the problem, outcome and beneficiary in one sentence.
🟧 The general objective is clear, but the outcome or beneficiary is not precise.
🟥 We are mainly using AI because it is fashionable, available or used by competitors.
⬜ We do not know.

Can the benefit be measured?

🟩 We have a baseline and specific metrics.
🟧 We have some indicators but no reliable baseline.
🟥 The benefit is based mainly on assumptions or enthusiasm.
⬜ We do not know.

Examples of metrics include hours saved per deliverable, cost per approved asset, rework rate, time to first draft, gross margin, error rate, client satisfaction and campaign performance.

Could a non-AI approach be better?

🟩 We have compared alternatives.
🟧 Alternatives were considered informally.
🟥 No alternative has been assessed.
⬜ We do not know.

2. Margin and delivery economics

Does the workflow remain profitable after human control?

Have you calculated the full cost?

🟩 We included software, usage, people, supervision, checking and rework.
🟧 We included direct costs but not all human or quality-control costs.
🟥 We are treating the supplier subscription as the cost of AI.
⬜ We do not know.

How much human supervision is required?

☐ Under 10% of outputs
☐ 10–25% of outputs
☐ 25–50% of outputs
☐ More than 50% of outputs
☐ Every output requires review
☐ Not yet known

What happens when the output is wrong?

🟩 Errors are usually quick and inexpensive to correct.
🟧 Errors require meaningful editing, checking or client discussion.
🟥 Errors could create significant financial, legal, contractual or reputational harm.
⬜ We do not know.

Does the workflow improve margin at realistic volume?

🟩 Yes, this has been tested with representative work.
🟧 Probably, but the assumptions have not been tested.
🟥 No, or not yet.
⬜ We do not know.

3/4. Client, data and legal exposure

Could the workflow create client, privacy or regulatory risk?

What data does the workflow use?

Select all that apply:

☐ Public information only
☐ Internal agency information
☐ Client-confidential information
☐ Personal data
☐ Customer or prospect data
☐ Financial, strategic or commercially sensitive information
☐ Sensitive personal data
☐ Credentials or access to business systems
☐ Other:
☐ Not sure

Are data-handling rules clear?

🟩 We know what is entered, where it is processed, who can access it, how long it is retained and whether it is used for model improvement.
🟧 We understand some of these points, but not all.
🟥 Users can enter information without clear rules.
⬜ We do not know.

Who could be affected if the workflow is wrong, misleading, biased or misused?

☐ No meaningful effect expected
☐ Client, brand or commercial interests
☐ Agency employees or contractors
☐ Customers, prospects or members of the public
☐ Applicants or other people subject to a decision
☐ Other:
☐ Not sure

What is the most serious plausible consequence?

☐ Minor quality issue
☐ Incorrect or misleading client deliverable
☐ Confidentiality or personal-data incident
☐ Copyright, image-rights or intellectual-property dispute
☐ Brand or reputational damage
☐ Financial loss
☐ Harm to an individual or group
☐ Regulatory or contractual breach
☐ Not sure

GDPR check

Complete this section if personal data are involved.

☐ We have identified the purpose of processing.
☐ We have identified an appropriate legal basis.
☐ We use only the personal data necessary for that purpose.
☐ We understand the roles of the agency, client and supplier.
☐ Retention and deletion rules are clear.
☐ Supplier and international-transfer arrangements have been reviewed.
☐ A Data Protection Impact Assessment has been considered where processing may create a high risk.
☐ None of these.
☐ Not applicable.

The GDPR principles of purpose limitation, data minimisation, transparency, security and accountability continue to apply when personal data are used with AI. A DPIA may be required where processing is likely to create a high risk to individuals. Verify the specific position with the relevant DPO or legal adviser.

EU AI Act check

Could the workflow:

☐ Interact directly with customers, prospects, employees or the public?
☐ Generate or manipulate public-facing text, images, video or audio?
☐ Influence decisions about people?
☐ Operate in a regulated or potentially high-risk context?
☐ Require staff to have specific AI literacy or training?
☐ Be placed on the EU market, used in the EU or produce outputs for people in the EU?
☐ None of these.
☐ Not sure.

If one or more boxes apply, obtain a specific legal or regulatory assessment before scaling.

Regulatory note

Certain EU AI Act transparency obligations under Article 50 apply from 2 August 2026. Depending on the system and use case, they may concern:

  • informing people when they are interacting with AI;

  • labelling certain AI-generated or manipulated content;

  • disclosing certain deepfakes;

  • marking certain synthetic content in a machine-readable format.

A limited transition until 2 December 2026 may apply to certain marking and detection obligations for generative AI systems placed on the market or put into service before 2 August 2026. This is not a general grace period for all Article 50 obligations. Verify the current position against official sources before relying on these dates.

Client contract check

☐ The client knows whether AI is used.
☐ The contract addresses confidentiality and data handling.
☐ Intellectual-property responsibilities are clear.
☐ Client review and approval responsibilities are clear.
☐ Disclosure or labelling requirements are addressed.
☐ Responsibility for factual accuracy is clear.
☐ None of these.
☐ Not applicable.

5. Human oversight

Can the workflow go too far?

What is the highest-impact action this workflow can perform?

Select one:

Observe — Search, collect, classify or summarise information.
Recommend — Suggest an action or decision.
Generate — Produce content, analysis or creative assets.
Decide — Select, rank, approve or reject an option.
Act — Publish, send, buy, change, delete or create something in another system.
Not sure — We do not know.

What actions can the workflow perform?

Select all that apply:

☐ Access internal or client information.
☐ Use external tools or connected systems.
☐ Create or modify content.
☐ Send messages or notifications.
☐ Publish content.
☐ Spend money or change a budget.
☐ Create, modify or delete records.
☐ Trigger another automated workflow.
☐ Make or support decisions about people.
☐ None of these.
☐ Not sure.

Is human approval required before external or irreversible action?

🟩 Always. A named person reviews, challenges and approves the action.
🟧 Sometimes. The requirement depends on the output or context.
🟥 No. The workflow can act without human approval.
⬜  We do not know.

Is the human review meaningful?

🟩 The reviewer has the competence, time and authority to question, modify or reject the output.
🟧 Review exists but may be rushed, inconsistent or limited.
🟥 Review is mainly a rubber stamp.
⬜  We do not know.

Can the workflow be stopped quickly?

🟩 A named person can pause or terminate it immediately.
🟧 It can be stopped, but not reliably or quickly.
🟥 No effective stop mechanism exists.
⬜  We do not know.

Are operating limits configured?

Select all that apply:

☐ Approved users.
☐ Approved tools and data sources.
☐ Maximum spend.
☐ Maximum number of calls or iterations.
☐ Maximum output volume.
☐ Allowed actions.
☐ Approval required before publication or sending.
☐ Access permissions are limited to what is necessary.
☐ None of these.
☐ Not sure.

Are important actions recorded?

🟩 Relevant actions, approvals, overrides and failures are logged.
🟧 Some actions are recorded, but the record is incomplete.
🟥 Important actions cannot be traced.
⬜  We do not know.

6. Fallback and supplier resilience

Could the agency continue delivering if the workflow or supplier failed?

Is there a fallback?

🟩 We have a tested manual or alternative process.
🟧 A fallback exists but has not been tested.
🟥 No workable fallback exists.
⬜  We do not know.

Could we still deliver the work if the supplier became unavailable tomorrow?

🟩 Yes, within the agreed service level.
🟧 Yes, but with delays, additional cost or reduced capacity.
🟥 No. Client delivery would be seriously affected.
⬜  We do not know.

Does the workflow depend on one supplier, model or platform?

🟩 No significant single-supplier dependency, or an alternative has been tested.
🟧 A dependency exists, but the consequences are understood.
🟥 The workflow would fail if one supplier changed its terms or became unavailable.
⬜  We do not know.

Do we understand the supplier’s key conditions?

Select all that apply:

☐ Pricing and usage limits.
☐ Availability and service levels.
☐ Data-processing and retention practices.
☐ Use of prompts, files or outputs for model improvement.
☐ Access, permission and security controls.
☐ Change-notification practices.
☐ Export and deletion options.
☐ Contractual terms and termination conditions.
☐ None of these.
☐ Not sure.

Can we recover the workflow?

🟩 Prompts, configurations, approved tools, data sources and outputs are documented and exportable.
🟧 Some key information is available, but recovery would be difficult.
🟥 The workflow could not realistically be reproduced without the supplier.
⬜  We do not know.

What happens if the supplier changes its pricing, limits or terms?

🟩 We have defined thresholds and a response plan.
🟧 We would assess the situation if it happened.
🟥 We have no practical response plan.
⬜  We do not know.

What happens if quality or availability declines?

🟩 We have defined triggers for review, fallback or suspension.
🟧 We would respond case by case.
🟥 No trigger or response process exists.
⬜  We do not know.

Have we tested the fallback?

🟩 Yes, under realistic operating conditions.
🟧 A limited or informal test has been completed.
🟥 No test has been conducted.
⬜  We do not know.

7. Accountability

Who owns the risk and the result?

Is there a named accountable owner?

🟩 Yes, with authority to approve, restrict or stop the workflow.
🟧 Someone is informally responsible.
🟥 No individual owns the decision.
⬜ We do not know.

Accountable owner:_______

Are key responsibilities clear?

Who operates the workflow? Who reviews the output? Who approves client-facing or irreversible action? Who handles incidents? Who can pause or stop the workflow? Who is accountable for the final result?

🟩 All responsibilities are clear.
🟧 Some responsibilities are clear.
🟥 Responsibilities are unclear.
⬜ We do not know.

Can we retrieve the key information about this workflow?

🟩 Yes, in a register or documented file.
🟧 Information exists but is scattered.
🟥 No reliable record exists.
⬜ We do not know.

Is the residual risk acceptable?

🟩 It has been assessed and accepted by an authorised person.
🟧 It appears acceptable, but acceptance is not documented.
🟥 It is not acceptable.
⬜ We do not know.

Executive decision

Select one outcome:

Flora Peter

I’m Flora Peter, an AI governance consultant with 20 years of experience in digital marketing and agency operations. I help marketing teams and agencies turn AI risk into practical governance and responsible growth.

How exposed is your marketing team to AI risk?

Free 2-minute AI Exposure Check: spot gaps across AI tools, client data, human review, transparency, IP, training and incident response, then identify where to act first.

https://www.florapeter.com/ai-exposure
Next
Next

The real price of AI in marketing: why cost uncertainty is a governance risk