Skip to content
AI Governance & Compliance

Use AI hard, and stay defensible while you do it

Most marketing teams adopted AI before anyone agreed the rules. Drafts are written in whichever tool is open, claims arrive with no source attached, customer data goes wherever it is pasted, and the brand quietly drifts toward the same phrasing as everyone else. Governance is the fix, and it is smaller than it sounds: a one-page policy, a handful of risk checks, brand safety standards and an approval workflow tiered by exposure — designed so the check costs less than the risk it removes.

The problem

The rules are already being set — informally, by whoever is quickest

In practice, AI arrived in marketing teams from the bottom up. Someone started drafting emails with it, someone else used it for ad copy, and within a quarter it was in the workflow without a single decision being taken about what it may be used for. The result is not recklessness; it is inconsistency. Two people producing external content under two different unwritten standards, and no way to tell which claims have been checked.

The exposure that follows is specific rather than theoretical. AI is fluent, which means it states benefits and statistics with total confidence and no source — and unsubstantiated claims are exactly what UK advertising standards expectations bite on. Meanwhile confidential terms and customer details get pasted into public tools because nobody said where the line was, and the copy slides toward generic phrasing that makes a distinctive business sound like every competitor.

The instinct is to write a long policy, and that is the second failure. A twelve-page document nobody reads changes no behaviour; it just moves the risk from unmanaged to undocumented. What works is small and operational: one page of rules people can remember, a short pre-publish check on the things that actually cause damage, and a named person who signs off. That is what this engagement builds, tested against the content your team really produces.

Outcomes

What changes for your business

  • A one-page AI policy the team can actually remember and follow.
  • A named risk register for marketing AI use, with a control against each risk.
  • Brand safety standards that stop output drifting into generic AI phrasing.
  • A claim-substantiation check so nothing publishes without evidence behind it.
  • Tiered approval workflows: no friction internally, a real gate externally.
Scope

What a governance engagement delivers

AI use and risk assessment

A map of where AI is already being used across marketing, which tools hold what data, and where the real exposure sits — unsubstantiated claims, personal or confidential data, brand drift and third-party content risk — scored so effort goes to the risks that matter.

One-page AI policy

A short, plain-English policy covering approved tools, what AI may and may never be used for, the data boundary, the disclosure position and who approves what. Written to be read in two minutes and handed to a legal adviser or DPO for review where you have one.

Brand safety standards

Documented brand-voice rules, banned constructions and tone tests that AI output must pass before it ships, so scale does not cost distinctiveness. Built from your existing best-performing content rather than from a generic style guide.

Claim substantiation check

A short pre-publish routine for every performance, pricing, comparative or safety claim: what is asserted, what evidences it, and where that evidence is recorded — so a challenged claim has an answer ready rather than a scramble.

Tiered approval workflow

Approval routes defined by exposure: none for internal drafting, a named reviewer for external content, a second review and recorded evidence for regulated, comparative or board-facing claims. Wired into the tools the team already works in.

Team briefing and handover. A working session so the team understands the rules and why each one exists, plus the register, policy, standards and checklists documented and owned internally with a scheduled review as tools and regulation move.

Fit

Who this is right for

  • Marketing teams already using AI daily with no agreed rules in place.
  • Regulated or claim-sensitive sectors where an unevidenced statement is costly.
  • Businesses whose content has started sounding generic since adopting AI.
  • Leadership that wants AI adopted faster but needs the risk answered first.
  • Teams preparing for procurement, investor or client due-diligence questions on AI.
In detail

How this works in practice

The detail behind the headline: how the work is structured, what it depends on and how progress is judged.

Governance is an enabler, not a brake

The standard objection is that governance slows a team down, and badly designed governance certainly does. But watch what actually happens in an ungoverned team: people hesitate before using AI on anything important because nobody has told them whether it is allowed, then use it anyway on the things nobody is checking. Ambiguity produces both hesitation and quiet rule-breaking at the same time.

Clear rules remove both. When a team knows AI is fine for drafting, structuring and summarising, that external claims need a source, and that customer data never leaves the approved tool, they move faster and take more useful risks — because the boundary is visible. The output goes up, and the tail risk goes down.

So the design constraint is proportionality: the check must cost less than the risk it removes. A two-minute claim check before an ad publishes is obviously worth it. A sign-off on an internal draft is not. Governance that fails this test does not get followed, which makes it worse than none at all because it creates a false record of control.

The four risks that actually matter

First, unsubstantiated claims. Language models produce confident specifics — percentages, superlatives, comparative benefits — with no source, and those are precisely the statements that draw regulatory and competitor attention. The control is a substantiation check: every external claim carries a recorded evidence source before it ships.

Second, data. Confidential commercial terms and personal data get pasted into public tools because nobody defined the boundary. The control is an approved-tool list plus one memorable rule about what never gets pasted. Third, brand drift: AI regresses toward the mean of everything it has read, so unmanaged scale makes a distinctive business sound generic. The control is documented voice standards with tests output must pass.

Fourth, third-party content risk — output that resembles someone else's material closely enough to matter. The control is a human review that checks originality and evidence, not just fluency. Four risks, four cheap controls, one review gate. That is the substance of marketing AI governance; everything else is documentation.

Approval workflows sized to exposure

Uniform approval is the most common design mistake. Route everything through one reviewer and you build a queue that the team routes around within a month. The alternative is tiering by exposure, defined against your own content types so nobody has to interpret the rule in the moment.

Tier one is internal and low-risk: notes, briefs, ideation, first drafts — no approval, use AI freely. Tier two is external but claim-light: social posts, blog articles, newsletters — one named reviewer checking voice, accuracy and evidence. Tier three carries commercial or regulatory weight: performance and pricing claims, comparative advertising, anything to the board, press or a regulator — second review plus a recorded evidence source.

Written down this way, the workflow answers the question the team actually has, which is not "what is our AI policy?" but "can I press publish?". The gate holds where it matters and disappears where it does not, and the record of what was reviewed exists if it is ever needed.

Two-minute assessment

Find your AI exposure tier first

Eight questions on how your team actually uses AI returns an exposure tier, the areas where your risk is concentrated, and the approval workflow that matches it. It scores in your browser and nothing is stored.

Free starter pack

The AI Governance Starter Pack

Three working templates you can complete in one 90-minute session: a one-page AI use policy, a risk register with starter rows already written, and a tiered approval workflow with the pre-publication checks that keep AI-assisted marketing defensible.

  • A one-page AI use policy your team will actually read
  • A risk register with six starter rows most marketing teams need
  • A three-tier approval workflow sized to real exposure
  • A six-question pre-publication checklist for your content brief
  • A session plan for completing the pack with the people who publish

PDF · 10 pages · templates, not legal advice. Your details are used to send the pack and nothing else.

Watch

Marketing thinking in short form

Strategy, SEO and paid search explained in a couple of minutes on Instagram and TikTok.

Questions

Frequently asked questions

What is AI governance for a marketing team?
A small, practical set of rules and checks that decide what AI may be used for, what it may never be used for, what evidence a claim needs before it publishes, and who signs off. In a marketing context that means brand-voice standards, a claim-substantiation check, a personal-data boundary, a disclosure position and a named approval gate — written on a page or two that a busy team will actually follow, not a policy document that lives in a folder nobody opens.
Is this a legal or compliance service?
No, and it is important to be clear about that. This is marketing governance: the operational controls that keep AI-assisted output on-brand, evidenced and defensible, aligned with UK advertising standards expectations and your own data commitments. It is designed to be handed to a legal adviser or DPO for review where you have one, and it flags the points where you should take formal advice rather than pretending to give it.
Won't governance slow the team down?
Badly designed governance does. The whole design principle here is that the check must be cheaper than the risk: a two-minute pre-publish check on the things that actually cause damage, and no check at all on low-risk internal drafting. Most teams find output speeds up, because the ambiguity about what is allowed — which is what really causes hesitation, rework and quiet rule-breaking — disappears.
What are the real risks with AI in marketing?
Four come up repeatedly: unsubstantiated claims (the model asserts a benefit or statistic nobody can evidence), confidential or personal data pasted into a public tool, brand drift into generic AI phrasing that erodes distinctiveness, and third-party content risk where output resembles someone else's material. Each has a specific, cheap control. The risk that never appears on anyone's list — quietly losing the ability to sound like yourself — is usually the most expensive one.
What does the approval workflow look like in practice?
It is tiered by exposure rather than uniform. Internal drafts and ideation need no approval. External content gets a named reviewer checking brand voice, factual accuracy and claim evidence. Anything making a performance, pricing, safety or comparative claim, or anything going to the board or the press, gets a second review and a recorded evidence source. The tiers are defined against your own content types so the team knows which applies without asking.
Do we need this if we are only using AI lightly?
If anyone in the team is drafting external content with AI — which, realistically, they are — then the exposure already exists and the rules are already being made informally by whoever is fastest. A light-touch version takes a single workshop and produces a one-page policy plus a pre-publish check. It is far easier to set the standard before a bad claim ships than to retrofit one afterwards.
Do you use AI in your marketing consultancy work?
Yes — deliberately, and I help clients do the same. AI is used for research and synthesis, keyword and intent clustering, first drafts that a specialist then corrects, campaign variants and reporting commentary, all under human review with a written data and brand policy behind it. It is never used for the parts that carry commercial risk: positioning, pricing narrative, segment priorities or any claim that has to be defensible. I also work on the other half of the AI shift — making sure your business is the source ChatGPT, Google AI Overviews, Gemini and Perplexity cite when a buyer asks who the credible options are, because a growing share of shortlists are now formed inside an assistant rather than on a search results page.
Why should I use you as my marketing consultant rather than an agency?
An agency sells you delivery. I sell you judgement. Before anyone writes an ad or a blog post, someone has to decide which segments you are targeting, what your proposition is, which channels deserve budget and what a qualified enquiry is actually worth. That is the work that decides whether the delivery pays for itself. I do that work first, in writing, then either brief your existing agency properly or build the plan in-house — and because I have no media to sell you, there is no incentive for me to recommend spend you do not need.
What makes you different from other Fractional CMOs and marketing consultants?
Three things. First, a client-side operating background rather than a pure agency one: I have run marketing inside an industrial B2B manufacturer, dealing with technical buyers, distributor networks, long sales cycles and a board that wants commercial numbers rather than impressions. Second, formal grounding — Member of the Chartered Institute of Marketing (MCIM) and an MSc in Digital Marketing Management, so recommendations are based on tested frameworks rather than whatever is trending on LinkedIn. Third, I work across B2B, retail and SaaS, which means the retail pricing and merchandising discipline informs the B2B work and the SaaS retention thinking informs both.
How much does a marketing consultant cost compared with hiring a Marketing Director?
A full-time Marketing Director in the UK typically costs £70,000-£110,000 plus employer's NI, pension, recruitment fees, holiday and the risk of a bad hire — realistically £100,000+ a year all-in before they have spent a penny on marketing. Consultancy and Fractional CMO retainers give you the same seniority for one or two days a week, at a fraction of that cost, with no notice period and no recruitment risk. For most SMEs turning over £1m-£20m that is the difference between having senior marketing judgement and having none.
Do you work with B2B, retail and SaaS businesses?
Yes — all three, and the differences matter. B2B work centres on pipeline: proposition clarity, technical content, sales and marketing alignment, cost per qualified enquiry. Retail and ecommerce work centres on unit economics: contribution margin after ad spend, repeat purchase rate, lifetime value and the seasonality of demand. SaaS work centres on efficient acquisition and retention: activation, trial-to-paid conversion, churn and payback period. The strategic method is the same; the metrics I hold the plan to are different.
How quickly will I see results from working with a marketing consultancy?
You get clarity in the first two to three weeks: a written diagnosis of where marketing is losing money, what to stop and a prioritised plan. Quick operational wins — tracking that actually works, tightened paid search, fixed conversion paths, a CRM that reports honestly — typically land inside 30 to 60 days. Compounding channels such as SEO and content usually show meaningful movement in three to six months, and that is exactly why the plan sequences fast wins first: they fund the patience the slower channels require.
Will you replace my team or agency?
No. The aim is to make what you already have work harder. In most engagements your team and your agencies keep delivering; what changes is that they receive clear priorities, a proper brief and a measurement framework, and someone senior holds the whole thing to commercial outcomes. Where a supplier genuinely is not performing, I will tell you plainly and help you replace them — but replacement is a conclusion, not a starting assumption.
How do you measure success, and how am I kept accountable to it?
Every engagement is tied to commercial metrics agreed up front: qualified enquiries, cost per qualified enquiry by channel, pipeline value, conversion rate and, where the data allows, revenue and contribution. You get a monthly review pack you can put in front of a board, showing what was done, what it produced and where the next pound of budget should go. If a channel is not paying for itself, you will hear it from me before you have to ask.
What does the first conversation involve, and is there any commitment?
It is a one-hour call, free, with no pitch deck. We cover your growth target, how you sell today, what marketing is currently producing and where the obvious gaps are. You leave with an honest view on whether consultancy, a Fractional CMO retainer, a defined project or nothing at all is the right next step. There is no obligation, and I will say so directly if I do not think I am the right partner for your situation.
Next step

Get AI governance in place before it is needed

A 30-minute discovery call to understand your targets, your current marketing and whether I'm the right partner for the next stage.