I had dinner recently with an attorney whose role includes helping his firm and its clients navigate AI. So naturally, we spent a good part of dinner talking about AI.
We talked about the AI agents we’re building, our AI-hosted podcasts, the ways we’re using AI in marketing and operations, and where all of this is headed. His side of the conversation included privacy, compliance, legal exposure, disclosures and the governance companies need as AI becomes embedded in more of what they do.
At some point, we laughed about the fact that while the two of us were sitting there eating dinner and talking about AI, we both had AI agents somewhere doing work for us.
That’s pretty cool. It’s also worth thinking about.
If your AI is working when you’re not, who’s making sure it knows the rules?
I Was Complaining About This Eight Years Ago
Back in 2018, I wrote a blog called The Compliance Conundrum. My frustration then was that marketing departments and their digital agencies were too often being asked to figure out enterprise compliance from the bottom up.
I thought that was backwards.
The companies doing it right had legal, financial, IT and other appropriate experts establish the requirements from the top down. They told people like us what applied to the digital systems we were building, and we implemented those requirements.
Eight years later, I haven’t changed my mind. AI has just made the consequences considerably bigger.
We’re no longer talking only about a website, form or marketing campaign. AI can communicate with customers, create content, interpret information, access company data, make recommendations and increasingly take actions on behalf of the organization.
Building It Is the Easy Part Now
For marketers, this is an incredibly exciting time. We’re creating things today that would have sounded like science fiction a few years ago.
AI agents can answer customers’ questions around the clock. AI can help produce podcasts, personalize experiences, automate workflows, analyze conversations, assist sales teams and make mountains of company knowledge instantly useful.
And the technology is getting easier to use incredibly fast.
But “Can we build it?” and “Can our company responsibly deploy it?” are two very different questions.
If you’re the person pushing AI forward inside your organization, recognizing that difference doesn’t make you the person putting on the brakes. It makes you the person thinking beyond the cool demo.
And that’s how you become the AI rockstar instead of the person who accidentally creates the next corporate crisis.
Your AI Policy Needs to Become Part of Your AI
The traditional legal review process usually assumes there’s something to review. Marketing creates something. Legal looks at it. Changes are made. Somebody approves it. It gets published.
But what happens when an AI website agent has 10,000 different customer conversations? Or an AI workflow creates something new every day? Or an agent accesses business systems and takes actions without someone approving every individual decision?
You can’t put an attorney behind the AI approving everything it does.
So governance has to move upstream.
That’s where my dinner conversation got especially interesting. What if legal counsel didn’t simply create an AI policy for the humans in your company to follow? What if their expertise also became part of the instructions the AI itself follows?
Some of those requirements may apply everywhere. Others will be unique to your company, industry, customers, data, regulatory environment and particular AI application. A thorough discovery should determine what’s universal, what’s application-specific, what might change, who monitors those changes and who ultimately has authority to approve them.
That’s not something I’d trust to a checklist downloaded from the Internet. And it’s definitely not something I’d ask ChatGPT to decide for me.
Okay, But How Do You Put the Lawyer Inside the AI?
Not literally, of course. But there are several places where legal governance can become part of an AI system rather than something sitting in a policy binder somewhere.
Prompts and instructions. These are the standing directions telling the AI how to behave, what it can do, what it can’t do, what it must disclose and when it needs to involve a human.
Knowledge bases. These provide the approved company, product, service and policy information the AI relies upon to answer questions and perform its job.
Guardrails. These establish boundaries. Don’t make this claim. Don’t provide this kind of advice. Don’t collect this information. Stop and escalate to a human when this happens.
Markdown (.md) files. Most marketers have probably never heard of one. Markdown is simply a lightweight, structured text-file format that’s very easy for AI systems to read. Appropriate counsel-approved governance can be maintained in structured .md files that become part of the AI’s instructions or reference material. Instead of the legal policy existing only in a document humans are supposed to remember, the relevant rules can travel with the AI.
Connectors. These determine what outside information and systems the AI can access, including CRMs, email, calendars, databases, documents and customer records. Governance isn’t only about what AI is allowed to say. It’s also about what it’s allowed to see.
Tools and actions. These determine what the AI can actually do. Send an email. Schedule something. Update a record. Trigger a workflow. The rules need to establish what can happen automatically, what requires human approval and what should never happen.
Monitoring. Even carefully governed AI needs oversight. If something goes wrong, the system should help identify it so people can respond and, when necessary, improve the knowledge, prompt, guardrail, governance or workflow that allowed it to happen.
The Rules Aren’t Always Permanent
We see this with Milo, the AI website agent we’ve developed for Milorganite.
Milo has access to information that includes tested PFAS levels. Those numbers aren’t something we should hard-code into a prompt and assume will remain accurate forever. When new testing changes those numbers, there needs to be a mechanism for updating the authoritative information Milo uses.
That’s a straightforward factual example. Now apply the same thinking to a changing privacy requirement, regulation, disclosure obligation, company policy or legal interpretation.
Some rules may remain constant. Others need to be monitored and updated. Governance isn’t a deliverable. It’s a lifecycle.
We’ve encountered the other side of this with AI-generated podcasts. For Lippmann’s CrushCast, for example, the program identifies the hosts as AI and includes an appropriate disclaimer about the nature of the information being discussed. Once requirements like those are established, they can become persistent parts of the production process instead of depending on somebody remembering them every time an episode is produced.
Discover. Define. Implement. Monitor. Update. Verify.
That’s a much more realistic way to think about AI governance.
Good Governance Doesn’t Slow AI Down
I understand why marketers might hear “legal governance” and immediately picture somebody throwing a wet blanket over every good idea.
Done badly, that certainly can happen.
But done correctly, I think governance can have exactly the opposite effect.
Without a framework, every new AI idea starts the same conversation. Can we do this? Is this legal? What data can it use? Who needs to approve it? What happens if it gets something wrong?
A company that has done the work already has a framework for answering those questions. Governance doesn’t have to be the brake. It can be what lets a responsible organization take its foot off the brake.
And for marketers, that’s the opportunity.
The person who walks into the executive meeting with the coolest AI demo might get everyone’s attention. The marketing leader who can explain what AI could do for the business and how legal, IT, leadership and the implementation team need to work together to deploy it responsibly has entered a much more important conversation.
What This Means for You
1. Find out what AI is already doing inside your organization. Look beyond the officially sanctioned projects. Where is AI creating content, communicating with customers, accessing company information, processing data, making recommendations or taking actions? You can’t govern what you don’t know is happening.
2. Make sure somebody qualified is responsible for protecting the enterprise. If you have experienced internal legal counsel covering privacy, data, compliance and AI governance, bring them into the conversation. If you don’t, hire outside counsel with that expertise. And not simply to review your latest AI project. You need legal guidance from people who understand your business, the information it handles, the regulations and privacy obligations it faces, and how those requirements extend into AI.
3. Don’t stop at getting legal advice. Make it operational. A policy sitting in a folder doesn’t govern an AI agent having a customer conversation at 10:30 at night. Determine how counsel’s requirements become prompts, knowledge bases, guardrails, .md governance files, connector permissions, tool restrictions, disclosures, escalation rules and monitoring. And establish who’s responsible for keeping all of it current.
4. Choose an AI implementation partner who understands the difference. Your digital agency shouldn’t be practicing law, and your law firm shouldn’t have to build your marketing technology. You need an agency that knows how to work with your legal experts and translate their requirements into the AI-powered marketing systems it builds and manages for you. That coordination needs to be part of the architecture, not an afterthought before launch.
Do this right and legal governance doesn’t become the thing preventing your marketing team from embracing AI. It becomes part of the infrastructure that lets you embrace more of it, faster and with confidence.
Because your AI is increasingly going to be working when you aren’t.
The goal isn’t to have a lawyer standing over its shoulder. It’s to make sure the lawyer’s rules are still there when the lawyer isn’t.