AI Governance and the New Responsibilities of Marketing Teams

Most people assume that using an AI tool works a bit like using a search engine. You type something into ChatGPT, Claude, Gemini or similar tools, get something back, and assume whatever you shared stays between you and the screen. The reality is considerably more complicated.

Depending on the platform you're using, whether you're logged into a personal or enterprise account, and how your organisation has configured its AI environment, that information may be processed, retained or protected in very different ways. The gap between what most people think happens to their data and what actually happens is the governance challenge we are dealing with today.

Already AI has become embedded in the way organisations operate. Marketing teams use it to develop campaigns and monitor results, communications professionals use it to draft media statements and executive messaging, HR teams use it to write job descriptions, finance teams use it to analyse reports, and business leaders rely on it to summarise meetings and explore strategic decisions. While AI adoption has happened quickly, governance has not kept pace.

For marketing and communications professionals, this presents a particularly interesting challenge. Few functions handle as much commercially sensitive information while simultaneously embracing AI as enthusiastically. Campaign strategies, customer insights, unpublished product launches, executive speeches, agency briefs, brand positioning and strategy all flow through AI tools every day. Yet many organisations still treat AI governance as though it belongs exclusively to Legal or IT.

But there's an added irony here. Normally, when something goes wrong in the business, it’s the comms and marketing teams who are brought in to manage a crisis. But what happens when it's your own AI use (or that of an external agency or freelance partner) that exposes a client contract, an unreleased campaign or embargoed financial information? Then, you are no longer managing someone else's crisis. You're the crisis.

The Misconception That's Undermining AI Governance

One of the reasons governance has struggled to keep pace with adoption is because AI feels deceptively informal.

Someone asks ChatGPT to rewrite an email.

A communications manager pastes in a media statement to make it more concise or uploads a new product spec sheet and tech document to get an overview of the benefits.

A marketer uploads a campaign brief to brainstorm creative ideas.

An external agency partner pastes a client's confidential campaign brief into their own AI subscription to move faster on a pitch.

None of these actions feel like a big deal. Yet every one of those prompts contains data. Sometimes that data is public. Sometimes it contains confidential client information, commercially sensitive research, intellectual property or personal information protected by privacy legislation. Whether that information remains protected depends on whether the AI is being used on free personal account, an enterprise account, etc.

For example, enterprise services such as ChatGPT Enterprise and Microsoft 365 Copilot provide contractual guarantees that customer prompts are not used to train foundation models and include stronger security and administrative controls. Personal accounts often operate under different terms. The problem is that many employees move seamlessly between the two, using whichever tool is quickest without necessarily considering where the information is going.

Microsoft's 2025 Work Trend Index found that 78 percent of AI users are bringing their own AI tools into the workplace, creating what researchers describe as "Bring Your Own AI." The report highlights a growing disconnect between organisational AI strategies and the tools employees are actually using.

This phenomenon, increasingly referred to as shadow AI, has become one of the biggest governance challenges organisations face today (source: UpGuard's State of Shadow AI report).

What Happens When AI Governance Falls Behind: The Samsung Wake-Up Call

In March 2023, Samsung Semiconductor experienced three separate data leakage incidents within weeks of allowing employees to use ChatGPT.

One engineer pasted proprietary source code from Samsung's semiconductor equipment measurement database into the tool, simply asking it to find and fix a bug. A second engineer submitted code used to identify defective fabrication equipment, looking for optimisation suggestions. A third converted the recording of a confidential internal meeting, covering unreleased process technology, into a transcript and asked ChatGPT to turn it into meeting minutes. None of the three had malicious intent, but once that data was typed into the prompt box, Samsung had no way to retrieve it or control where it went next.

For Samsung's legal and communications teams, this turned into a crisis comms problem almost as fast as it became a security one. Once South Korean media reported the leaks, Samsung had to respond publicly and internally at the same time. It capped ChatGPT submissions at 1,024 bytes per prompt, issued a company-wide notice warning staff that any repeat incident could lead to termination, and within weeks banned generative AI tools from company devices altogether.

As you can imagine, the story travelled quickly into the international tech press, turning the situation into a very public case study of how easily "helpful" AI use can undermine a company's ability to protect its own trade secrets, along with its credibility with regulators, investors and customers who assumed that information was locked down.

Samsung wasn't the only company caught out. A couple of months earlier, in January 2023, Amazon's legal team had warned staff internally after noticing that ChatGPT's output in some cases closely resembled Amazon's own internal material. This raised the concern that confidential information, including source code, may already have been fed into the tool through employee prompts.

Amazon told staff not to share confidential information with ChatGPT and not to use its output where it echoed Amazon's own content, partly because it could complicate the company's ability to later claim that material as its own IP.

In both these situations, it took an incident, and some fast crisis communication to manage it, before the companies established clear AI governance. Neither leak involved a rogue employee; it was well-meaning staff trying to work faster. Factor in agencies, freelancers and other outside partners who also touch your campaigns, briefs and unreleased data, and the number of ways this can go wrong multiplies fast.

AI Governance Is Becoming a Legal Requirement

For communications professionals, AI governance is ultimately about trust. We have always been responsible for protecting reputation, communicating transparently and ensuring organisations speak with credibility. AI introduces another dimension to that responsibility – especially with national AI requirements coming into play. When that trust breaks, whether through a data leak, an unlabelled AI-generated statement or a hallucinated executive quote, it's comms teams who are left managing the fallout. That makes AI governance our responsibility too, not just Legal's or IT's.

Already we have GDPR (a comprehensive privacy law that gives individuals control over their personal data), and now we also have the EU AI Act, the world's first comprehensive legal framework for AI systems. It came into force in August 2024 and is rolling out in stages, with transparency obligations under Article 50, becoming enforceable in August 2026.

Article 50 covers the disclosure of AI interactions, labelling of synthetic content, and deepfake identification. For marketing and communications teams regardless of where they're based, this is a big operational shift. It means that any AI-generated content circulated in the EU will need to be identifiable as such.

If you are a content creator you can read more about the details of Article 50 here.

Turning AI Governance Into Everyday Practice

The most important thing to understand is that your prompts are data. Avoid putting into an AI tool anything you wouldn't put in an email to a third party such as client details, unreleased financial information, confidential personnel matters, or anything covered by a non-disclosure agreement.

For marketing and communications professionals, client data, brand information, creative IP, and audience data all flow through the AI tools your team uses daily. The bigger question is whether you know what your team is using, on which accounts, and what your policy says about what goes in. If you don’t have a policy yet, educate your team on best practices and keep them updated on new national regulations.

Your governance can't stop at your own building, either. Agencies, freelancers and other external partners often work across multiple client accounts, sometimes with their own AI subscriptions and little to no policy of their own. If a brief, an unreleased campaign concept or an embargoed announcement ends up in the wrong AI tool because of an agency's carelessness, it's still your organisation's data, and still your organisation managing the resulting crisis. A good practice is to extend your AI policy into vendor and agency agreements.

AI isn't going away, and neither is the risk that comes with treating it casually. The organisations that get ahead of this won't be the ones with the most restrictive policies (people will always find a way around firewalls and blocks). They'll be the ones that helped everyone understand that a prompt is a piece of data that is sent somewhere and that it could have consequences.

For marketing and communications teams especially, that understanding isn't optional. We are the custodians of brand trust. The last thing we want is to cause a crisis situation by accidentally leaking data.

Previous
Previous

The Art of Storytelling: How Comms Can Shape Industries

Next
Next

The Expert Eye: Why Experience Still Matters in the Age of AI