What AI governance means for marketers

Key takeaways

Most marketing teams are adopting AI faster than they can understand, measure or govern it.

AI is already part of content creation, campaign analysis, customer service, targeting, reporting and everyday operations. The opportunity is real. So is the exposure.

My view is that AI is not necessarily making marketing work easier. It is often making work faster, more complex and more difficult to supervise.

That is why AI governance is so important.

For marketers, AI governance is the practical framework that helps a team use AI in a way it can explain, defend and improve - without unnecessarily slowing down delivery.

The question I keep coming back to

My AI trainer has asked me the same question several times:

“Has AI saved you time?”

I had to think about it because the answer was not obvious.

I do not really optimise for time. I optimise for quality, so my answer may be biased.

Whenever AI gives me a little time back, I usually invest it straight away in improving the result, exploring another idea or testing a new workflow, tool or feature.

AI is a rabbit hole for me, I can lose track of time while exploring a new tool, prompt or process.

So the promise of “saving time” is more complicated than it sounds.

AI may make some tasks faster. But it can also create more things to check, more decisions to make and more risks to consider.

As a result, I would say that the pressure on marketing professionals has increased significantly over the past three years.

83.5% of marketers are expected to produce more content and 35.7% are expected to produce much more, creating a high risk of burnout amid "downward pressure" on resources. (Hubspot, 2026)

AI can accelerate execution but it increases responsibility.

Marketing has moved faster than governance

When GDPR came into force, many clients assumed their marketing agency would know exactly what to do.

As if GDPR had always been our professional passion. 😁

In reality, agencies and marketing teams had to learn, train and adapt. We had to understand what applied to our own operations and how to advise clients responsibly.

The EU AI Act brings a similar challenge, but with a much more complex scope.

Having spent 60 days writing about it on LinkedIn, I can attest to its complexity—especially when navigating it alongside related developments like the AI Omnibus and the European Commission’s transparency guidelines.

To boost adoption, I

wish these regulations were e

asier for non-legal professionals to digest.

The application of the EU AI Act depends on the system, its purpose, the context and the organisation’s role.

Meanwhile, AI adoption has moved quickly. HubSpot’s 2026 State of Marketing reports that 61% of marketers believe AI is causing the biggest disruption marketing has experienced in 20 years.

Deloitte’s 2026 CMO research found that two-thirds of surveyed companies are adopting three or more AI use cases in marketing and growth. Content creation, predictive analytics and conversational AI are among the use cases gaining traction.

The pattern is clear:

  • AI is moving into standard marketing work.

  • Teams are using several tools and features at once.

  • Individual experimentation is becoming part of shared workflows.

  • Governance is often developing later than adoption.

This creates what is known as acceleration risk: the gap between how quickly a team moves and how well it understands and controls what it is doing.

What is AI governance?

AI governance refers to the framework of policies, regulations, and ethical guidelines that oversee the development and deployment of artificial intelligence technologies. This governance aims to address social implications, ensure accountability, and promote responsible innovation within the fields of science and technology. It emphasizes the importance of ethical considerations in shaping AI’s impact on society.
— UNESCO

For marketers, I would put it more simply:

AI governance is how you decide what AI can do, what it cannot do, who is responsible and what happens when something goes wrong.

It includes:

  • visibility over the tools and features being used;

  • rules for data and confidential information;

  • human review;

  • clear ownership;

  • AI literacy and training;

  • risk assessment;

  • documentation;

  • vendor review;

  • incident response;

  • ongoing monitoring.

AI governance turns:

“Everyone uses AI in their own way”

into:

We use AI in a way we can explain and defend.”

Governance has to appear inside the real marketing workflow: the brief, the prompt, the review, the approval and the final delivery.

When AI misuse started to run on my nerves. First exposure.

During my marketing career, I saw clients adopt AI very quickly. I also saw the risks appear just as quickly—if not faster. The problem that frustrated me most was not always an obviously ridiculous AI answer. Those are usually easy to spot. It was the answer that looked polished, had a professional tone and still did not actually make sense.

That is where the AI rewriting trap begins. The result can sound more authoritative while becoming less accurate, less clear or less connected to the original question. This is not only a content-quality issue. It affects brand trust, client confidence, decision-making and accountability.

I whish they had thought of the following questions before they hit “send”:

  • Is it accurate?

  • Is it relevant?

  • Can we support the claims?

  • Does it reflect the intended meaning?

  • Would we be comfortable defending it to a client or customer?

This is one of the reasons AI governance cannot be separated from marketing quality.

The risks are connected

I am not sure how marketing leaders usually think about AI risks, as over 70% of marketers reporting they have already encountered AI incidents such as hallucinations, bias, or off-brand content. (IAB, 2025).

Perhaps they see them mainly as compliance or legal issues managed by legal colleagues or external advisers.

In practice, AI-related risks fall into several categories, and those categories are interconnected.

Imagine this workflow.

A strategist receives a confidential client brief and uses an AI tool to summarise it. Another team member uses a different tool to rewrite the output. A third person asks an AI assistant to turn it into campaign ideas. The final copy is published after a quick review because the deadline is tight.

What could go wrong?

  • The original brief may contain confidential or personal information.

  • The tools may have different data terms and retention settings.

  • The rewritten content may introduce an inaccurate claim.

  • The campaign may reproduce a bias or inappropriate assumption.

  • Nobody may know which tool produced which part of the final output.

  • The client may ask who approved the process.

  • The team may not be able to reconstruct what happened.

One workflow can therefore create data, operational, brand, contractual and compliance exposure at the same time.

That is why AI governance should not be treated as a collection of disconnected legal topics.

Five areas marketers need to govern

What good governance should do

Many marketing leaders associate governance with bureaucracy, slower delivery and additional restrictions.

I understand that reaction.

When you look at legal texts, official guidance and ISO frameworks, the language can feel complex and difficult to digest. It takes real effort to understand what those requirements mean in a specific professional context.

Good governance should achieve the opposite.

It should help teams:

  • know which tools they can use;

  • understand which data is sensitive;

  • recognise when human review is required;

  • make ownership visible;

  • reduce avoidable rework;

  • respond quickly when something goes wrong;

  • answer client questions with confidence.

If I were to push this a little further, I would say that governance can save time.

It prevents teams from wasting time on activities that are not permitted, not defensible or not aligned with the organisation’s risk appetite.

A clear framework helps people understand what they can do—and how to do it safely.

Where to start

Begin with visibility.

1. Map your shadow AI

Ask each team member:

“Which AI tools, browser extensions, personal accounts or embedded AI features have you used in the last five working days?”

Do not ask only about the tools approved by procurement. Ask about the tools people actually use.

The tricky part is that people may have created accounts for tools they no longer use.

So I would also recommend checking company email inboxes for billing receipts, account-confirmation emails and other signs that an account has been created.

This should be done transparently and in line with your organisation’s internal policies and applicable employment and privacy rules.

2. Connect tools to workflows

For each tool, record:

  • who uses it;

  • what marketing activity it supports;

  • what data enters it;

  • where the output goes;

  • whether a client or customer sees the output;

  • who reviews the result.

This turns a list of tools into a view of actual exposure.

3. Prioritise the connected risks

Start with workflows that involve:

  • confidential or personal data;

  • public-facing content;

  • client deliverables;

  • customer interactions;

  • targeting or profiling;

  • important brand or revenue decisions.

Then assign an owner and decide on the first practical control.

That might be:

  • a data rule;

  • an approved-tool list;

  • a mandatory review step;

  • a vendor check;

  • an incident process.

You need a clear view of where your team is exposed and a few rules people can realistically follow.

Conclusion

My view is that AI governance should not be something marketing teams receive from legal as a finished document.

Every team should have ownership of its AI use.

When the internet became widely used over the past 30 years, organisations did not create one “chief of digital” to own every digital activity forever. Digital became part of every department’s work. Each team developed responsibility for its own tools, processes and workflows.

I believe AI will follow a similar path.

I cannot see how one person, team or department could understand the specificities of every AI use case across an entire organisation.

The goal is for your marketing team to understand:

  • where AI is being used;

  • what information enters the tools;

  • what could go wrong;

  • how the risks connect;

  • who is responsible for the final decision.

AI governance should be built around the work marketers actually do.

If you are unsure where to begin, start with shadow AI.

Take the AI Exposure Check to identify common vulnerabilities in your marketing setup and decide what to address first.

It is free, takes about two minutes and is designed to provide practical clarity.

One question to take to your team

Could you list every AI tool currently used across your marketing workflows—including browser extensions, embedded features and personal accounts?

Flora Peter

I’m Flora Peter, an AI governance consultant with 20 years of experience in digital marketing and agency operations. I help marketing teams and agencies turn AI risk into practical governance and responsible growth.

https://www.florapeter.com
Previous
Previous

The AI brand damage you’re not watching for (Part 1. Brand identity)