The speed gap is now measurable
Marketing approval was designed around campaigns. A team proposes a message, audience, budget, and launch date. A reviewer checks the asset, legal checks the claim, and the campaign goes live. That model assumes the important choices happen before publication.
An agent changes the timing. It can select an audience, rebalance a budget, rewrite an offer, suppress a message, choose a channel, or trigger a follow-up after the campaign starts. The approval queue may still exist, but it now approves the initial configuration while the system keeps making consequential moves.
The gap is not theoretical. A July 2026 study reported by MarketScale from Smarsh and FTI found that 55 percent of enterprises were actively deploying AI while only 26 percent said governance kept pace. The percentages are a snapshot, not a universal benchmark, but the shape of the problem is clear: deployment is moving faster than the organization's ability to explain and constrain it.
The response is not to make every approval slower. It is to change what approval means. A CMO should approve the job, the allowed moves, the data boundary, the spend ceiling, the review threshold, and the stop condition. Those are decisions the organization can own. It cannot honestly pre-approve actions it has not yet seen.
A useful boundary
What the system can show
Campaign asset
Initial audience
Initial budget
The old review approves a launch. The distinction matters because visible activity is not automatically evidence of a business outcome.
That distinction also explains shadow AI. When the official process asks for a perfect policy before anyone can test a low-risk workflow, teams move into vendor tools and personal subscriptions. The company gets speed without an inventory, and governance loses the visibility it was trying to create.
The real precedent is about outcomes
The strongest legal precedent is not a story about a chatbot making an offensive suggestion. It is the 2022 DOJ and Meta Fair Housing settlement. The case concerned Meta's ad-delivery algorithm and housing advertising. The algorithm could produce unlawful discriminatory outcomes even when an advertiser did not explicitly choose a protected-class exclusion.
HUD followed with guidance explaining how the Fair Housing Act applies when housing-related advertising and tenant screening rely on algorithms and AI. The 2024 analysis of that guidance is important for marketers because it makes the liability theory portable: an automated system does not escape scrutiny because the human wrote a neutral instruction.
The lesson for a CMO is direct. Intent is evidence, but intent is not the whole review. If an agent reallocates spend toward audiences, locations, or offers that create a prohibited pattern, “the prompt did not say to discriminate” is not an adequate control. The organization needs to know which inputs the system used, what options it considered, what it changed, and who could stop it.
This is why a marketing approval record must become a decision record. Store the version of the agent, policy, data sources, tool permissions, material actions, reviewer interventions, and final outcome. The record should be useful to marketing, compliance, counsel, and finance without translating four different dashboards after an incident.
The same logic applies outside housing. A regulated claim, credit offer, health audience, employment message, or pricing decision can create exposure through the way an automated system distributes or modifies it. The category changes. The need to inspect outcomes does not.

Approval cannot see the decision path
The ordinary campaign review is a snapshot. It shows the proposed creative and a few launch parameters. It often does not show what will happen when the system encounters a new segment, a depleted budget, a missing data field, a conflicting instruction, or a vendor failure.
Agentic work creates four audit questions. What was the agent allowed to change? What did it actually change? What evidence caused that change? What stopped it or allowed it to continue? A green performance dashboard can answer none of these. It can show an outcome while hiding the route that produced it.
01 / Scope
What could it change?
02 / Action
What did it change?
03 / Evidence
Why did it change?
04 / Stop
What could halt it?
The most dangerous gap is the material-change threshold. A model can make hundreds of changes that look individually small but collectively alter price, audience, frequency, claims, or customer treatment. If no threshold exists, the organization either reviews nothing or creates a queue that nobody can clear.
Define materiality in the language of the business. A change to a regulated claim is material even if spend is flat. A shift in geographic delivery is material if it affects a protected market. A new data source is material if it changes the audience definition. A cost increase is material when it crosses a budget limit or removes the margin that made the campaign viable.
Do not confuse a verbose log with an audit trail. A useful record connects request, context, policy version, action, source, reviewer, and outcome. It preserves enough state to replay the decision and enough ownership to answer who could have stopped it. The audit-trail problem is an operating problem before it is a legal one.
Where guardrails are actually built
Guardrails work at the points where an agent can create consequence. Start with identity and scope. Every agent needs a named business owner, technical owner, service account, approved tools, data permissions, and an explicit list of actions it cannot take. “Marketing agent” is not a scope.
Next comes the action boundary. Read-only research can move quickly. Drafting can move with a review gate. Customer-facing sends, pricing changes, regulated claims, payments, and irreversible deletions need stronger control. The exact tiers will differ, but the principle is stable: controls should follow blast radius.
Spending infrastructure is becoming part of the same conversation. Agent-scoped payment tools, prepaid limits, and approval thresholds can stop a system from turning a campaign test into an open-ended financial commitment. A CMO does not need to approve every API call. The system should enforce the ceiling the CMO actually approved.
The company also needs a sandbox that is easier to use than a shadow vendor. Give teams synthetic or read-only data, a representative evaluation set, safe credentials, and a published route to graduate. Exit criteria should include quality, latency, cost, logging, ownership, rollback, and incident response. A sandbox without an exit becomes a waiting room. An exit without a sandbox becomes a bypass.
Measure guardrails by behavior. Are unregistered agents declining? Are low-risk reviews faster? Are material changes actually stopping? Can finance reconcile spend to an owner? Can legal retrieve the record without asking engineering to reconstruct it? If the answer is no, the organization has a policy document, not an operating control.

The regulated-market reality
Regulated markets expose the weakness in generic approval language. A campaign can comply with a checklist and still produce a different outcome once the agent optimizes delivery against a proxy. The system may never receive a prohibited attribute, yet its choices can recreate the pattern a rule is meant to prevent.
The review must therefore include the environment around the model. Which features are available? Which audiences are excluded? Which proxies can be inferred? Which jurisdictions receive which message? Which claims require substantiation? What happens when a model expresses uncertainty or loses access to a source?
This is also where speed arguments become most misleading. A fast agent that cannot explain its audience or claim selection may create more delay after launch than a slower system that preserves evidence. The relevant performance metric includes reversals, complaints, review time, and remediation, not just conversion.
A CMO does not need to become the system's auditor. The CMO does need to insist that the auditability contract exists before an agent receives production authority. That contract should be understandable in business terms and testable in the actual system.
Context
Market, use case, audience, and claim
Constraint
Restricted inputs, proxy risks, and the material-change gate
Proof
Owner, test cases, release evidence, and review date
In practice, that contract starts with a jurisdiction and use-case matrix. The same optimization can be acceptable for a general brand campaign and unacceptable for housing, employment, credit, healthcare, or political communication. The matrix should name the relevant rule set, the restricted inputs and proxies, the reviewer who owns the decision, and the evidence required to release the work. It should also record where the system is allowed to operate. A rule that applies in one market cannot be treated as a footnote in a global agent configuration.
Reviewers should test outcomes before they approve autonomy. Give the agent matched scenarios, edge cases, and a holdout set that includes the audiences and claims most likely to create exposure. Compare what it recommends, what it actually does, and what it records. A passing prompt test is not enough if the production connector can use a different field, audience, or destination. The control has to follow the action into the system where the consequence occurs.
The same discipline applies when a vendor updates its model. A model version, retrieval source, policy file, tool scope, and evaluation set are all part of the operating context. If one changes, the organization should know whether the old approval still applies. This does not require a full legal review for every patch. It does require a defined change threshold and a record of who decided that the threshold was or was not crossed.
What a workable approval model looks like
Start by replacing one approval question with five boundary questions: what job is the agent doing, what may it change, what data may it use, what counts as a material change, and what stops it? Record the answers in the inventory and attach them to the deployed version, not only to the original project brief.
01
Job
What is it for?
02
Authority
What may it change?
03
Data
What may it use?
04
Threshold
What needs review?
05
Stop
What halts it?
Fast lane
Drafts and read-only work
Automatic checks inside a sandbox.
Middle lane
Customer-facing work
Evaluation and a human review gate.
Controlled lane
Money and irreversible action
A named owner, strict evidence, and a real stop path.
Name a bridge owner who runs the inventory, coordinates the review, and can stop the system. Separate approval from observation: one authorizes a boundary, the other checks that the agent stayed inside it. Alerts, sampled decisions, spend checks, and policy-drift checks make that visible.
Test one live workflow, record the route and recovery path, then review it on a schedule tied to risk. Your job is to approve the limits and require proof that the agent stayed inside them.

