An ad claim, a customer message, an automated step, a decision about a person. At each one an AI output leaves your team, and UK regulators have said who answers for it.

AI Governance in Marketing and Operations Teams

Guides

By James Cotton · Last updated · 7 min read

Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.

By James Cotton, Founder, iO-Sphere

Why the function lead holds the check

On 9 March 2026 the Competition and Markets Authority published Complying with consumer law when using AI agents, and its central line is that a business is responsible for what an AI agent does in the same way it is responsible for what its employees do.

Think of the new starter in each team. In marketing, their first campaign goes to someone who knows the product before it goes to a customer. In operations, they learn the process before anyone lets them change a routing rule. On the CMA's reading, the AI tool is in the new starter's position, and it needs the same reader.

The penalties behind that are real. The CMA's direct consumer-enforcement powers under the Digital Markets, Competition and Consumers Act 2024 came into force on 6 April 2025, announced in its press release of 7 April 2025, with fines of up to 10% of global turnover. The March 2026 guidance adds that breaches can also mean compensation to consumers.

A compliance team can write the policy. It cannot know that this week's product claim overstates what the product does, or that a routing rule mishandles one kind of case. The person running the campaign or the process knows those things, and feels it first when they go wrong. Our guide to who is responsible for AI governance maps the wider split of duties.

An ad claim has to be true whether or not AI made it

The Advertising Standards Authority addressed disclosure in May 2025, in Disclosure of AI in advertising. It found no blanket legal requirement in the UK to say that an ad used AI, and the same advertising rules apply whether or not it did.

Its example is useful for anyone signing off creative. An AI image showing a cosmetic effect that does not match real results is materially misleading, and adding a note that the image was AI-generated does not fix it.

Capability claims bring a second duty. A later ASA article from August 2026, Regulating the illusion of intelligence in ads, says an advertiser must hold evidence for any objective claim about what a product can do.

The check at this point is a product question. Does the image show a result a customer will get, and can we evidence every "it can" in the copy? The marketer who knows the product can answer both in minutes, where a reviewer who has never used it would struggle.

A chatbot or an email speaks for the business

Chatbots, email and direct marketing all put AI words in front of a customer under your name. A Canadian decision from 2024 shows what happens when those words are wrong.

In Moffatt v Air Canada, decided in February 2024 by the Civil Resolution Tribunal of British Columbia, an airline was held responsible for a fare policy that its own website chatbot had stated wrongly. The case is Canadian, and it points the same way as the CMA's view that the business answers for what its tools say.

UK penalties for electronic marketing have also risen. According to the ICO's statement on the commencement of the Data (Use and Access) Act, the Act's next phase began on 5 February 2026, including fines under the Privacy and Electronic Communications Regulations (PECR) of up to £17.5 million or 4% of global turnover.

The practical question is who owns automated replies. Somebody should decide which answers a chatbot may give about price, policy and eligibility, and approve the templates an AI tool fills in for email. That person should be whoever knows the real policy, whatever their place in the org chart.

Automated steps break at the exceptions the team knows

Operations is where most businesses already use AI. The Office for National Statistics reported on 20 July 2026 (fieldwork 5 to 28 June 2026, among businesses using AI) that improving business operations was the most reported use across every size band, at close to 60%; the article has no separate category for marketing or customer service.

Among those businesses, 63% saw no change in headcount. Our reading is that the tool usually joins a process the same people still run, which puts them in the best position to watch it.

A wrong output breaks a process in unglamorous ways. A case goes to the wrong queue, an exception gets treated as routine, or a record holds a field the next step cannot use. Each of those is obvious to someone who has handled the process by hand, and invisible to anyone who has not.

The CMA guidance is direct about this. It warns that AI output can be "nonsensical or inaccurate" and tells businesses to "make sure there is a human in the loop". The operations lead decides where that human stands: usually at the step where an error would be expensive or hard to reverse, and where they know the exceptions by heart.

Decisions about people need a route to contest them

Marketing and operations make more decisions about individuals than they tend to notice. A segmentation model decides who is offered a deal. A pricing tool sets what one customer is quoted against another. A credit or eligibility check decides who can buy on terms, and a queue priority decides whose complaint is answered first.

The function lead's check here is to know which AI outputs in the area amount to a decision about a person, how significant each one is for that person, and whether someone could challenge it and reach a human who can change the answer. When AI helps make those decisions, the ICO's rules on automated decision-making apply, and our guide to data and AI skills for people and HR teams sets them out.

The ICO's updated guidance is still a draft. Its consultation closed on 29 May 2026, and the ICO plans page expects publication in winter 2026. The settled point in the meantime is that a person must be able to contest a significant automated decision about them, so the route to contest is worth testing before the final text arrives.

What a marketing or operations lead needs to judge

On a good day, a sharp marketer catches the overstated claim and an alert operations lead pauses the routing rule. Catching it on an ordinary Thursday takes three abilities: knowing where AI already touches a claim, a message, a process step or a decision in your area; knowing what a plausible wrong output looks like in your kind of work; and knowing which of the rules above applies at each point.

The first two are worth building across the whole team, because the copywriter and the case handler see the output before the lead does, and our data and AI fluency training gives a team that baseline. The third belongs to whoever owns the check, and that person can go deeper on our Data & AI Governance apprenticeship.

The first check needs no training at all. On Monday, pull last week's chatbot answers and AI-drafted emails, read a sample against the real price list and the real policy, and mark any that would have misled a customer. What you find tells you which of the four points to watch first.

Frequently asked questions

Does an AI-written email to a customer need a person to approve it?

Someone should approve it, though not necessarily each message. The CMA's guidance tells businesses to keep a human in the loop and holds them responsible for what the AI does, and the ASA applies the same rules whether or not AI wrote the words. A workable pattern is a person approving the template and every claim it may make, with any message about price or eligibility read before it is sent.

Who is liable when our agency's AI gets it wrong?

Under the CMA's March 2026 guidance, the business is responsible for what an AI agent does even when a third party designed it. An agency contract may settle who pays whom afterwards, but the customer and the regulator will look to you.

Who should check our agency's AI output before it goes out?

The person on your side who briefed the work and knows the product, the customer and the process. Ask the agency to say where AI produced or changed the copy, images, targeting or replies it delivers, and put that work through the same sign-off at the same four points as anything made in house, with the evidence for any capability claim held on your file as well as theirs.

Want to own AI governance in your organisation?

Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.