THE SHORT ANSWER

Match controls to the consequence of an error. Keep evidence for claims, minimise unnecessary data exposure, review rights and fairness, define who may publish or act, and prepare a correction process. Human review needs time, expertise and authority to be meaningful.

Begin with what could go wrong for the customer

A generated adjective that feels off-brand needs editing. A fabricated product certification, an incorrect price or a false compatibility claim can change a purchase decision. A workflow should not treat these as equivalent copy defects.

In a hypothetical product launch, keep an approved claim register with evidence and an owner. Require generated drafts to stay within it. Review the actual output, including images, captions and adapted versions; an accurate source brief does not guarantee an accurate final asset.

Use the existing verification process for claim checking. NIST's generative-AI profile supplies a wider risk-management reference, not assurance that a prompt or checklist eliminates failures.

Evidence & context: NIST

Turn each risk into an operating responsibility

An illustrative marketing control register
RiskPractical controlEvidence to retain
Fabricated or exaggerated claimOwner approves against a sourceClaim, source and approved version
Brand or placement mismatchReview creative context and available placement controlsDecision and exception record
Personal data exposureUse approved tools and only necessary informationPurpose, access and retention decisions
Bias or exclusionCheck affected groups and difficult casesTest cases, limitations and corrections
Unintended actionLimit permissions and require approval for consequential changesAuthorisation and action record

For a hypothetical lead-prioritisation system, inspect whether missing information is being treated as low customer value. A group can receive less attention because of how the records were collected, not because its needs are less suitable. Compare errors and access to service, not only the overall conversion rate.

‘A human reviewed it’ is not enough if the reviewer lacks the relevant expertise, cannot see the evidence or has no time to challenge the result. Give review a clear scope and route specialist questions to someone qualified.

Separate privacy, confidentiality and rights questions

A customer record can raise data-protection questions; an unpublished strategy can be commercially confidential without identifying anyone. Both require deliberate handling. Check provider terms, access, retention and permitted uses before uploading material, and avoid assuming that removing a name makes a dataset anonymous.

The UK ICO's AI guidance discusses security and data minimisation. The U.S. Copyright Office's report discusses copyrightability of AI outputs. These sources address different jurisdictions and questions. Neither is a blanket licence to upload, reproduce or publish material.

Seek qualified legal or compliance guidance for the markets, contracts and uses involved. This page offers an operational framework, not legal advice. Keep decisions about source rights, output rights and truthful representation distinct.

Evidence & context: UK Information Commissioner's Office · U.S. Copyright Office

Plan the correction before the launch

  1. Name the person who can pause publication, delivery or automation.
  2. Keep enough version history to identify what went out and where.
  3. Define how affected people can report an error and receive a response.
  4. Correct downstream adaptations as well as the original asset.
  5. Investigate the process failure and change the control before restarting.

A review process should learn from near misses as well as incidents. If the same unsupported claim keeps returning, correcting each draft individually may be less useful than repairing the source material or removing the capability that introduces it.

Sources & further reading

  1. Generative Artificial Intelligence Profile (NIST AI 600-1)

    NIST. Risk-management guidance, including confabulation. It does not establish a universal error rate.

  2. How should we assess security and data minimisation in AI?

    UK Information Commissioner's Office. UK regulatory guidance, checked 11 September 2026. Jurisdiction-specific context, not individual legal advice or permission for a particular use.

  3. Copyright Office releases Part 2 of its Artificial Intelligence Report

    U.S. Copyright Office. January 2025 report announcement on copyrightability and human authorship. U.S.-specific; not a resolution of all training, licensing or infringement questions.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗