Skip to content

How to put AI governance into practice in marketing

maitiq · Published

AI governance in marketing is the smallest effective combination of inventory, rules, roles, evidence and the authority to stop the system. It answers five questions for every use case: what is the system used for? Which data may it process? Which output or action may it produce? Which person decides? What happens when errors or changes occur? A policy without these operational answers remains paper; a tool without a policy remains an uncontrolled possibility.

For Swiss teams, governance starts with clear responsibilities and concrete data duties. The Federal Data Protection and Information Commissioner (FDPIC) notes that the technology-neutral Swiss Data Protection Act applies to the AI-supported processing of personal data. Depending on the processing, transparency and, for automated individual decisions, their review play a role; where risk is high, a data protection impact assessment is added. Which duty applies in a specific marketing case must be examined by subject specialists and legal advisers.

1. An inventory that enables decisions

Record every AI system in use or in a pilot, including features inside existing platforms. Each entry needs at least: purpose, person responsible, user groups, affected individuals, provider and version, data sources, integrations, output type, permitted action, human approval, retention, risk level, last test and next review.

A product name alone is not enough. The same application can be used to generate ideas from public information, for confidential briefings or for personalised customer communication. These uses involve different data and consequences. Keep one inventory entry per use case, not just per licence.

The inventory is also a gateway. A new purpose, a new data source or a new automated action creates a change that is reviewed again. That is how the team prevents a harmless pilot from gradually turning into an unapproved production process.

2. Permitted, restricted and prohibited use

A policy people can understand describes concrete activities. “Using AI responsibly” is not something you can execute. Three categories with examples work better:

Permitted: for example gathering ideas from public, approved information, provided outputs are treated as drafts and reviewed.

Only with approval: summarising internal documents, classifying customer feedback, creating forecasts, personalising content or integrating systems. Here the purpose, data, contract, testing and human control must be clarified.

Prohibited: entering passwords, secret keys or unapproved confidential, personal or particularly sensitive data into a public, uncontrolled tool; publishing unchecked statements; interpreting a technical access option as approval.

The National Cyber Security Centre (NCSC) recommends not entering personal, sensitive or confidential customer and company data into AI applications, reading the terms and questioning answers critically. This general security rule is a good conservative baseline, but it does not replace company-specific data classification.

3. Data rules along the entire flow

For every case, the data flow from source to deletion must be visible. Clarify:

  • Where does the data come from and for what purpose was it collected?
  • Is personal data, confidential content or protected works being processed?
  • Which fields are really necessary and which can be removed or anonymised?
  • Where are inputs, metadata and outputs transferred?
  • Does a provider use inputs for improvement or training?
  • Who gets access, how long is data stored and how is it deleted?
  • Which subprocessors and countries are involved?
  • How do data subjects receive the necessary information or a review?

The answers do not belong in a one-off presentation but in a versioned data sheet. Contracts, technical configuration and actual behaviour must match. If a question is open, real data access stays blocked or the pilot uses suitable synthetic data.

Data protection is not the only rights layer here. The Swiss Federal Institute of Intellectual Property (IPI) points out that clearly protected material in AI outputs can raise rights questions, and that human creative input can be relevant to whether an output may be protected. A marketing workflow therefore needs a check of sources, licences and originality, especially for text, image, audio and video.

4. Human roles with real authority

“Human in the loop” is only a control once four points are named: who reviews, what that person sees, when they decide and what power they have. Reviewing a result after it has already been published, or a budget change after it has been made, is not prior approval.

A lean allocation of roles can look like this:

  • The business owner owns the purpose, the benefit and the residual risk.
  • The use-case owner covers the process, quality and review.
  • The data owner approves sources, access and retention.
  • Data protection, legal and security have defined review points and the authority to stop the system.
  • Users follow the rules on input, review and reporting.
  • The incident lead coordinates containment, investigation and communication.

One person can hold several roles, but responsibilities must not disappear. Where the impact is higher, the same person should not build the system, assess it alone and accept the residual risk.

5. Internal risk levels as an operational tool

Marketing teams can use a simple internal triage. It is not a legal classification.

Level A – assistance with internal output that is easy to correct: public or approved data, no automated action, qualified review before use.

Level B – influence on published content, analyses or operational recommendations: additional specialist, rights and source review; documented tests and monitoring.

Level C – personal data, individual treatment, budget or customer action, consequences that are hard to reverse: formal data protection, legal, security and management review; narrow scope; strong approvals; incident and fallback plan.

The level follows the use and the impact, not the tool’s marketing name. If the action changes from “proposal” to “execute automatically”, it must be classified again.

6. Test before granting authority

A governance-compliant test has approved data, predefined cases and a reference. It assesses not only average quality but critical errors, omissions, biases, checks on permissions and protected material as applicable, rework and behaviour outside the intended context.

Document the model or product version, configuration, test data, assessors, result and deviations. The OECD principle on accountability stresses the traceability of datasets, processes and decisions. In marketing this becomes a practical rule: an approval is documented with evidence, so that the responsible person can later explain the decision.

Authority is granted in stages. A system may first deliver drafts, then perhaps recommendations in a narrower area. A live action requires a separate technical permission and business approval. Authorising the installation and use of a system does not by itself authorise every change it can make. A separately recorded business mandate may cover defined actions within its limits; actions already covered do not need duplicate approval.

7. Transparency and AI-generated content

Transparency has several audiences. Employees must know when they are using AI and which limits apply. Reviewers need sources, configuration and uncertainty. Depending on the processing, data subjects may need information about the purpose, how the system works or automated decisions. In certain situations, the public and customers need a recognisable indication that content is AI-generated or manipulated.

No blanket statement is permissible for EU references. The European Commission notes that the AI Act has in principle been applicable since 2 August 2026, with exceptions and amended transition periods. Whether a Swiss company, a system or a specific marketing output falls within its scope must be reviewed legally.

A voluntary disclosure can also support trust, but it must not replace a legal review. Likewise, a small label is not enough if the processing itself would be unlawful or misleading.

8. Controlling suppliers and integrated platforms

Procurement does not only check the provider on the contract date. It defines which changes must be reported: model changes, new data use, subprocessors, storage location, pricing logic, security functions or material limits on performance.

For your specific case, ask for the data flow, roles, deletion, the reporting channel for incidents, testing options, release notes, data export and how the service can be discontinued. A general security sheet is useful, but it does not automatically answer how a marketing integration works with your permissions.

The same logic applies to features in advertising, CRM or content platforms. An AI feature that is enabled by default must go into the inventory if it processes relevant data or influences decisions. Platform convenience is not a governance exception.

9. Monitoring, incidents and the authority to stop the system

Monitor metrics that match the consequences of failure: critical factual errors, unsupported statements, rights violations, impermissible data access, wrong audience targeting, wrong actions, rework, cost or drift after an update. A usage counter alone shows no control.

The incident process must be known before it is needed. Staff know how to report an incident and how to contain it. Incident responsibility can lock access, stop integrations or switch to the manual process. Evidence and logs are secured appropriately. Data protection, security, legal and communication roles are involved according to defined criteria.

After an incident come root cause, correction, a further test and an explicit decision to restart. Not every error is a reportable incident, but every critical pattern deserves a documented response.

10. Change and decommissioning

AI systems change. Define which changes trigger regression tests or a new approval: model version, prompt, data source, target group, channel, permission, threshold or supplier. Compare new results against a stable test set and the guardrail metrics.

Governance also covers the end. The exit plan names data export, account lock, confirmation of deletion, archiving of necessary records, a replacement process and communication. Do not keep paying for an unmanaged system without a person responsible, a benefit or a controllable supplier; decommission it in an orderly way.

The minimum governance package

A small marketing pilot does not need a hundred pages, but six documents should exist: use case entry, data sheet, roles and approval matrix, test and evidence record, operations/incident card and change/exit plan. Each document has a person responsible, a version and a review date.

This package makes responsibility visible without blocking every idea in advance. The greater the data volume, the degree of automation and the consequences of failure, the deeper the specialist review. Good governance is therefore not the opposite of experimentation. It enables smaller, more honest experiments and prevents a test from quietly becoming a permanent decision-making process.

How maitiq helps: rules the team can work with

Sort activities by their impact: an internal text draft, a publication and a budget change need different reviews. For each activity, record the permitted data, the person responsible and the route to take when in doubt. A short, understandable example per activity helps more than an abstract policy with no connection to the work.

In an agreed project, maitiq translates such rules into templates, training and process controls. Specialist or legal approvals remain with the people responsible for them. Measure whether employees know what they are allowed to do and where a problematic case belongs.

How a first pilot with maitiq begins

In an agreed project, a scoped initial assessment shows which governance is already concrete enough and how maitiq turns open rules into a workable operating process. You receive a clearly bounded use case, the open data and control questions, a pilot plan and the criteria for later operation.

Sources and how to read them

Authority sources set out the context: the FDPIC covers data protection, the NCSC covers security and the IPI covers copyright. The European Commission documents how the AI Act applies and which transition periods remain. The OECD accountability principle supports the traceability of datasets, processes and decisions. Information about how maitiq works is available at maitiq.com.

Have maitiq review your specific case.