What AI governance means for marketers
Key takeaways
Most marketing teams are adopting AI faster than they can understand, measure or govern it.
AI is already part of content creation, campaign analysis, customer service, targeting, reporting and everyday operations. The opportunity is real. So is the exposure.
My view is that AI is not necessarily making marketing work easier. It is often making work faster, more complex and more difficult to supervise.
That is why AI governance is so important.
For marketers, AI governance is the practical framework that helps a team use AI in a way it can explain, defend and improve - without unnecessarily slowing down delivery.
The question I keep coming back to
My AI trainer has asked me the same question several times:
“Has AI saved you time?”
I had to think about it because the answer was not obvious.
I do not really optimise for time. I optimise for quality, so my answer may be biased.
Whenever AI gives me a little time back, I usually invest it straight away in improving the result, exploring another idea or testing a new workflow, tool or feature.
AI is a rabbit hole for me, I can lose track of time while exploring a new tool, prompt or process.
So the promise of “saving time” is more complicated than it sounds.
AI may make some tasks faster. But it can also create more things to check, more decisions to make and more risks to consider.
As a result, I would say that the pressure on marketing professionals has increased significantly over the past three years.
83.5% of marketers are expected to produce more content and 35.7% are expected to produce much more, creating a high risk of burnout amid "downward pressure" on resources. (Hubspot, 2026)
AI can accelerate execution but it increases responsibility.
Marketing has moved faster than governance
When GDPR came into force, many clients assumed their marketing agency would know exactly what to do.
As if GDPR had always been our professional passion. 😁
In reality, agencies and marketing teams had to learn, train and adapt. We had to understand what applied to our own operations and how to advise clients responsibly.
The EU AI Act brings a similar challenge, but with a much more complex scope.
Having spent 60 days writing about it on LinkedIn, I can attest to its complexity—especially when navigating it alongside related developments like the AI Omnibus and the European Commission’s transparency guidelines.
To boost adoption, I
wish these regulations were e
asier for non-legal professionals to digest.
The application of the EU AI Act depends on the system, its purpose, the context and the organisation’s role.
Meanwhile, AI adoption has moved quickly. HubSpot’s 2026 State of Marketing reports that 61% of marketers believe AI is causing the biggest disruption marketing has experienced in 20 years.
Deloitte’s 2026 CMO research found that two-thirds of surveyed companies are adopting three or more AI use cases in marketing and growth. Content creation, predictive analytics and conversational AI are among the use cases gaining traction.
The pattern is clear:
AI is moving into standard marketing work.
Teams are using several tools and features at once.
Individual experimentation is becoming part of shared workflows.
Governance is often developing later than adoption.
This creates what is known as acceleration risk: the gap between how quickly a team moves and how well it understands and controls what it is doing.
What is AI governance?
“AI governance refers to the framework of policies, regulations, and ethical guidelines that oversee the development and deployment of artificial intelligence technologies. This governance aims to address social implications, ensure accountability, and promote responsible innovation within the fields of science and technology. It emphasizes the importance of ethical considerations in shaping AI’s impact on society.”
For marketers, I would put it more simply:
AI governance is how you decide what AI can do, what it cannot do, who is responsible and what happens when something goes wrong.
It includes:
visibility over the tools and features being used;
rules for data and confidential information;
human review;
clear ownership;
AI literacy and training;
risk assessment;
documentation;
vendor review;
incident response;
ongoing monitoring.
AI governance turns:
“Everyone uses AI in their own way”
into:
“
We use AI in a way we can explain and defend.”
Governance has to appear inside the real marketing workflow: the brief, the prompt, the review, the approval and the final delivery.
When AI misuse started to run on my nerves. First exposure.
During my marketing career, I saw clients adopt AI very quickly. I also saw the risks appear just as quickly—if not faster. The problem that frustrated me most was not always an obviously ridiculous AI answer. Those are usually easy to spot. It was the answer that looked polished, had a professional tone and still did not actually make sense.
That is where the AI rewriting trap begins. The result can sound more authoritative while becoming less accurate, less clear or less connected to the original question. This is not only a content-quality issue. It affects brand trust, client confidence, decision-making and accountability.
I whish they had thought of the following questions before they hit “send”:
Is it accurate?
Is it relevant?
Can we support the claims?
Does it reflect the intended meaning?
Would we be comfortable defending it to a client or customer?
This is one of the reasons AI governance cannot be separated from marketing quality.
The risks are connected
I am not sure how marketing leaders usually think about AI risks, as over 70% of marketers reporting they have already encountered AI incidents such as hallucinations, bias, or off-brand content. (IAB, 2025).
Perhaps they see them mainly as compliance or legal issues managed by legal colleagues or external advisers.
In practice, AI-related risks fall into several categories, and those categories are interconnected.
Imagine this workflow.
A strategist receives a confidential client brief and uses an AI tool to summarise it. Another team member uses a different tool to rewrite the output. A third person asks an AI assistant to turn it into campaign ideas. The final copy is published after a quick review because the deadline is tight.
What could go wrong?
The original brief may contain confidential or personal information.
The tools may have different data terms and retention settings.
The rewritten content may introduce an inaccurate claim.
The campaign may reproduce a bias or inappropriate assumption.
Nobody may know which tool produced which part of the final output.
The client may ask who approved the process.
The team may not be able to reconstruct what happened.
One workflow can therefore create data, operational, brand, contractual and compliance exposure at the same time.
That is why AI governance should not be treated as a collection of disconnected legal topics.
Five areas marketers need to govern
-
Marketing teams handle personal data, behavioural information, audience segments, campaign logic and confidential client material.
AI can create exposure when teams:
enter personal or confidential information into an unsuitable tool;
use AI-generated audience segments without understanding the underlying logic;
publish inaccurate or misleading claims;
use profiling or targeting systems without appropriate review;
fail to identify whether a particular AI use triggers relevant obligations.
The EU AI Act does not treat every marketing use of AI in the same way. The relevant analysis depends on the system, its purpose, the context and the organisation’s role.
The GDPR and consumer protection rules may also apply, depending on the data and activity involved.
This does not require a major public incident. A client question, procurement review or internal investigation can reveal that nobody knows how a workflow actually operates.
-
AI can produce content quickly.
It can also produce brand-damaging content quickly.
A misleading claim, inappropriate image or tone-deaf message can be reproduced across multiple channels before anyone notices.
The central question is :
“Does the final work meet the standards your audience and clients expect?”
As HubSpot’s 2026 report indicates, AI is creating efficiency opportunities while also increasing complexity. Authenticity and human-created content remain important to audiences. HubSpot
-
AI is often, although not always, presented as a productivity engine. But producing more content is not the same as creating more value.
In my opinion, when AI brings the cost of producing content close to zero, the value shifts even more towards quality. And, in my opinion again, quality has always been the true differentiator.
I may be biased here. As I mentioned earlier, I tend to optimise for quality rather than time saved.
The hidden costs of ungoverned AI may include:
correcting inaccurate outputs;
reviewing inconsistent drafts;
managing additional subscriptions;
repeating work after client feedback;
explaining weak campaign decisions;
coordinating tools that nobody clearly owns;
measuring activity without proving business impact.
Jasper’s 2026 research illustrates this gap: 91% of surveyed marketing teams reported using AI, but only 41% said they could confidently prove AI ROI. Jasper
This is close to my own experience. When AI gives me time back, I tend to reinvest it in quality.
That can be a good choice—but it means that “time saved” is diametrically different as “value created”.
-
Some employees use approved tools. Others use personal accounts, browser extensions or AI features built into existing software. It is easy—and tempting 😈—to try a new tool. It is often one click away, and many tools offer a free trial.
I think the shadow AI problem has grown significantly with the rise of generative AI.
Marketing teams were already using a wide range of software before ChatGPT launched. But since then, they have been exposed to a much larger number of AI tools and AI-enabled features. The rise of vibe coding may accelerate this further by reducing the time, resources and technical skills needed to create a tool or prototype.
This is shadow AI: AI entering professional workflows without complete organisational visibility.
When something goes wrong, leaders may not know:
which tool was used;
what information was entered;
which model or feature produced the output;
who reviewed it;
who can pause the workflow;
who is accountable for the final decision.
It is an operational blind spot.
-
For agencies, AI governance is also a commercial issue.
Clients may want to know:
whether their data is entered into AI tools;
which tools support the delivery of the work;
how confidential information is protected;
who owns AI-assisted outputs;
how accuracy and human review are managed;
what happens if an AI-supported deliverable causes harm.
If an agency cannot answer these questions clearly, the consequences may appear during a pitch, procurement review or contract negotiation.
Governance can therefore become a differentiator.
I think it will become a differentiator, although I may be biased here too. 😁
Consider website creation.
Having a website in the late 1990s was impressive. Today, it is normal. A website now needs to meet a long list of expectations in order to stand out: conversion, accessibility, performance, security, user experience and, increasingly, environmental impact.
I think AI governance will follow a similar path. Clients already know that agencies use AI—in many different ways. What they will increasingly want is a clear explanation of how that use is controlled.
What good governance should do
Many marketing leaders associate governance with bureaucracy, slower delivery and additional restrictions.
I understand that reaction.
When you look at legal texts, official guidance and ISO frameworks, the language can feel complex and difficult to digest. It takes real effort to understand what those requirements mean in a specific professional context.
Good governance should achieve the opposite.
It should help teams:
know which tools they can use;
understand which data is sensitive;
recognise when human review is required;
make ownership visible;
reduce avoidable rework;
respond quickly when something goes wrong;
answer client questions with confidence.
If I were to push this a little further, I would say that governance can save time.
It prevents teams from wasting time on activities that are not permitted, not defensible or not aligned with the organisation’s risk appetite.
A clear framework helps people understand what they can do—and how to do it safely.
Where to start
Begin with visibility.
1. Map your shadow AI
Ask each team member:
“Which AI tools, browser extensions, personal accounts or embedded AI features have you used in the last five working days?”
Do not ask only about the tools approved by procurement. Ask about the tools people actually use.
The tricky part is that people may have created accounts for tools they no longer use.
So I would also recommend checking company email inboxes for billing receipts, account-confirmation emails and other signs that an account has been created.
This should be done transparently and in line with your organisation’s internal policies and applicable employment and privacy rules.
2. Connect tools to workflows
For each tool, record:
who uses it;
what marketing activity it supports;
what data enters it;
where the output goes;
whether a client or customer sees the output;
who reviews the result.
This turns a list of tools into a view of actual exposure.
3. Prioritise the connected risks
Start with workflows that involve:
confidential or personal data;
public-facing content;
client deliverables;
customer interactions;
targeting or profiling;
important brand or revenue decisions.
Then assign an owner and decide on the first practical control.
That might be:
a data rule;
an approved-tool list;
a mandatory review step;
a vendor check;
an incident process.
You need a clear view of where your team is exposed and a few rules people can realistically follow.
Conclusion
My view is that AI governance should not be something marketing teams receive from legal as a finished document.
Every team should have ownership of its AI use.
When the internet became widely used over the past 30 years, organisations did not create one “chief of digital” to own every digital activity forever. Digital became part of every department’s work. Each team developed responsibility for its own tools, processes and workflows.
I believe AI will follow a similar path.
I cannot see how one person, team or department could understand the specificities of every AI use case across an entire organisation.
The goal is for your marketing team to understand:
where AI is being used;
what information enters the tools;
what could go wrong;
how the risks connect;
who is responsible for the final decision.
AI governance should be built around the work marketers actually do.
If you are unsure where to begin, start with shadow AI.
Take the AI Exposure Check to identify common vulnerabilities in your marketing setup and decide what to address first.
It is free, takes about two minutes and is designed to provide practical clarity.
One question to take to your team
Could you list every AI tool currently used across your marketing workflows—including browser extensions, embedded features and personal accounts?