Plans
Learn Library

Marketing Teams Are Running Naked With AI: 5 Chairs, 3 Rounds of Interrogation, 11 Questions

A guide to AI governance for marketing teams, outlining a five-seat cross-functional committee and three rounds of eleven questions to vet AI tools before rollout. It covers data handling, copyright checks, human review records, and a two-lane approval process for low-risk versus high-risk AI use.

ai-marketingaigcworkflow
2026-09-21SupaMarketers5 min read

Last week, at 1:30 in the morning, an old friend of mine who works in marketing sent me a message.

He said AI was running full tilt in his department: copy written by AI, images drawn by AI, ad campaigns run by AI agents on their own. The efficiency was so high it was starting to spook him.

I asked him: spooked about what?

A couple of days earlier, an AI-generated image had come out almost identical to a piece an illustrator had made two years ago. The illustrator came knocking, and legal got involved. Even scarier: the team regularly feeds customer data into these tools, and nobody knows what happens to it on the other end.

As he finished, a chill ran down his spine: the department using AI the hardest was the department nobody at the company was watching.

I heard him out and replied with a single line: What you're missing isn't a tool. It's a mechanism for governing the tools.

First, Get This Straight: Why Can't Marketing Make the Call?

What is AI governance?

Plainly put, it comes down to deciding one thing: who has the authority to decide which AI can be used, how it gets used, and where the line is drawn.

So why can't the marketing department make that call itself? Because the risks of using AI take root on someone else's turf.

Only legal can settle the copyright ledger. Only the security team can read the data ledger. And privacy? Every country's laws read it differently. Letting marketing audit itself is like letting students grade their own exams.

So you need a cross-functional committee. And every seat needs to be filled.

5 Chairs, Not One of Them Empty

How do you staff the committee? 5 seats — leave one empty, and a whole category of risk goes unwatched.

The first chair: the head of marketing technology and operations. He knows best which tools the department runs, which workflows are plugged into AI, and who's secretly using it. The real inventory of tools lives with him.

The second chair: legal and compliance. Who owns the copyright on generated content? How is liability split between inputs and outputs? What's buried in the vendor's terms of service? All of it lands on his desk.

The third chair: data security and IT. How data goes in, how it comes out, whether encryption is up to standard, what the vendor's interface policies are. For every word you feed out, he can tell you exactly where it went.

The fourth chair: the head of brand and content. Where the creative bottom line sits, and which published content needs an "AI-assisted" label — he sets the standard.

The fifth chair: a privacy officer. Europe has GDPR, California has CCPA, and new rules keep landing everywhere else. Having one person dedicated to keeping up with the legal reading is far cheaper than digging through statutes after something goes wrong.

You see, these 5 chairs map to 5 different kinds of ledgers. Can marketing fill them all on its own? It can't.

Before the Green Light, 3 Rounds of Interrogation

The committee is in place. Now what?

Set one rule first: every AI tool, every agent, goes through the interrogation before it goes live. 3 rounds, 11 questions in total.

First, ask about data.

Will every prompt you send the tool be used to train public models? Will your customer data become its fodder?

Is opting out of training written into the enterprise agreement, or hidden behind a settings toggle nobody has ever clicked?

Before anything goes out, has the personal information been scrubbed?

Does it conflict with the company's no-retention policy?

Next, ask about copyright.

If what it generates collides with someone else's work, does the vendor pay? Is there a promise in black and white?

Have the outputs been checked for verbatim duplication? Did anything brush against someone's trademark?

For external publishing, is there a record of human review? Without a record, you'll struggle to claim even "this work is our original creation."

For custom models trained on your own data — have they crossed any third-party licensing lines?

Finally, ask about process.

For high-risk decisions and content published externally, is a human required to make the final call?

Are prompt histories, system instructions, and every edit logged and auditable?

Wherever AI faces customers directly, is it spelled out for them, plain as day: what you're talking to is not a person?

Pass all 11, and it's green-lit. Fail one, fix it. Can't fix it, swap the tool.

Don't Turn the Committee Into the Brake

Here's the interesting part: plenty of companies set up governance, only to govern everything into "no to this, no to that."

What a committee should do is build guardrails. Good guardrails are what let you step on the gas.

My suggestion is 2 lanes: low-risk assistive tools — the kind that help you draft a headline or fix a typo — take the fast lane; just file them for the record and move on. High-risk autonomous agents — the ones that run campaigns by themselves, touch customer data by themselves, reply to customers by themselves — get the full inspection, round by round.

And approval isn't the finish line. Logs and records deserve a regular second look. Vendor terms change; AI policies shift. Compliant last month doesn't mean compliant this month.

Back to My Friend

Later, I sent him those 11 questions.

The next day he called back. He went quiet for two seconds, then said: thankfully, nothing major has happened.

I know that feeling well. The efficiency is real, and so is the risk. Pretend not to see it, and it won't go away on its own.

May your team never have to take a call from legal at 1:30 in the morning.

Continue reading