Insights/AI Governance/21 September 2026

AI content compliance checklist: 15 questions every marketing team should ask

Marketing compliance checklist for AI-generated content governance

Key takeaways

AI content compliance is broader than simply checking whether content was created by AI.

Marketing teams need clear policies covering AI tools, human review, factual accuracy, brand standards, risk and approval.

The right level of oversight depends on the content, its intended use and the potential consequences of getting it wrong.

Use the checklist below to identify gaps in your current AI content operation and prioritise what needs to change.

Is your marketing team ready for AI content compliance?

AI has changed how quickly marketing teams can create content. It has also changed the governance challenge. A marketing team can now use generative AI to produce a blog in minutes, create dozens of campaign variations, translate content into multiple languages or use an AI agent to perform an entire sequence of marketing tasks.

That creates enormous potential. It also creates a simple question for marketing leaders: Do we actually know how AI-generated content is being created, reviewed and approved across our organisation?

For many organisations, the answer is no. AI adoption has often happened faster than governance. That does not necessarily mean marketing teams are doing anything wrong. It means the operating model has not yet caught up with the technology.

This checklist provides a practical starting point.

AI content compliance checklist

Use the 15 questions below to assess your current approach.

For each question, mark:

  • Yes = documented and consistently implemented
  • Partly = exists but is inconsistent
  • No = not currently in place

The objective is to identify where your greatest governance gaps are, not to achieve 15 "yes" answers overnight.

1. Do we have a documented AI marketing policy?

Your organisation should have a clear policy explaining how AI may be used by marketing teams. At a minimum, it should cover:

  • Approved AI tools
  • Permitted use cases
  • Prohibited use cases

Human review requirements

  • Data protection considerations
  • Content ownership
  • Fact checking
  • Brand requirements
  • Compliance and legal escalation

AI agent permissions

  • Record keeping
  • Policy review
  • A policy turns informal expectations into an operating standard.
  • Status: ☐ Yes ☐ Partly ☐ No

2. Do we know which AI tools our marketing teams are using?

You cannot govern what you cannot see. Marketing teams may be using:

  • ChatGPT
  • Claude
  • Gemini

AI writing platforms

  • Image generation tools
  • Video generation tools
  • Translation systems
  • SEO tools

AI meeting or research tools

Marketing automation platforms

AI agents

The organisation should maintain an appropriate inventory of approved AI tools and understand what each is being used for.

This is particularly important as AI becomes embedded inside existing marketing software. An employee may not think they are "using AI" when an AI capability is simply built into the platform they already use.

Status: ☐ Yes ☐ Partly ☐ No

3. Can we identify where AI has been used to create content?

Marketing teams should be able to determine whether AI has been used within their content workflows. That does not necessarily mean every asset needs a prominent public "AI-generated" label.

The requirements under the EU AI Act depend on the type of AI system, the content and how it is used. Article 50 contains specific transparency obligations, including requirements around certain AI-generated or manipulated content.

Internally, however, maintaining visibility of AI involvement is valuable regardless of whether a public disclosure is legally required.

Your organisation should know:

  • Which content was AI-generated
  • Which content was AI-assisted
  • Which tools were used
  • What level of human editing occurred
  • Who reviewed the final output
  • Status: ☐ Yes ☐ Partly ☐ No

4. Is human review required where it is appropriate?

The answer should not simply be "everything gets human approval" as that can create an unmanageable bottleneck. Instead, establish clear rules for when human review is required based on factors such as:

  • Content risk
  • Audience
  • Subject matter
  • Regulatory environment
  • Intended use
  • Potential consequences of an error

For example, a routine social post may require a different process from a financial promotion or healthcare article.

The principle is: Human oversight should be proportionate to risk.

Status: ☐ Yes ☐ Partly ☐ No

5. Is human review substantive rather than just proofreading?

This is one of the most important questions on the list. Human oversight should not simply mean someone opens an AI-generated article, checks for spelling mistakes and clicks "approve".

A meaningful review may involve:

  • Assessing factual accuracy
  • Checking sources
  • Challenging unsupported claims
  • Reviewing the logic and argument
  • Assessing brand suitability
  • Checking regulatory requirements
  • Identifying missing context
  • Confirming the content meets the original brief

The human reviewer needs both authority and sufficient expertise to identify problems.

If the reviewer cannot challenge the output, the process is not meaningful oversight.

Status: ☐ Yes ☐ Partly ☐ No

6. Is factual verification mandatory for high-risk content?

AI systems can produce plausible but incorrect information. For higher-risk content, factual verification should therefore be a defined control rather than an optional editorial preference.

Consider mandatory verification for:

  • Statistics
  • Research findings
  • Regulatory claims
  • Medical information
  • Financial information
  • Product claims
  • Customer results
  • Technical specifications
  • Legal statements

The reviewer should know what needs checking and what constitutes an acceptable source.

Status: ☐ Yes ☐ Partly ☐ No

7. Are sources verified?

A source appearing in AI-generated content does not automatically make the claim reliable. Your workflow should distinguish between a source that exists and a source that actually supports the claim being made.

This is particularly important where AI systems generate citations or references.

In AI Refine's research, 48.6% of respondents said they had encountered unverifiable sources in AI-generated content.

A governed workflow should therefore establish:

  • Which sources are acceptable
  • Who verifies them
  • When primary sources are required

How source verification is recorded

Status: ☐ Yes ☐ Partly ☐ No

8. Are brand standards built into the AI content workflow?

Brand governance should not depend entirely on employees remembering to add the right instructions to a prompt.

Your workflow should incorporate:

  • Tone of voice
  • Brand terminology
  • Messaging
  • Positioning
  • Product language
  • Audience guidance
  • Editorial standards
  • Regional requirements

This can be supported through structured prompts, AI configuration, editorial guidelines and human review. The objective is to make brand consistency part of the system rather than an afterthought.

Status: ☐ Yes ☐ Partly ☐ No

Marketing should not send every blog post to the legal team. It should, however, have clear criteria for when specialist review is required.

For example:

  • Content type
  • Potential review
  • Routine blog
  • Editorial
  • Technical article
  • Editorial + SME
  • Product claims
  • Editorial + SME
  • Financial promotion
  • Editorial + compliance + legal

Healthcare content

  • Editorial + SME + compliance where applicable
  • Regulatory commentary
  • Editorial + SME + legal/compliance where appropriate
  • Crisis communications
  • Editorial + legal + executive approval

The exact requirements will vary by organisation and industry. The important thing is to define them before the content needs approval.

Status: ☐ Yes ☐ Partly ☐ No

10. Do we have clear ownership and accountability?

Every content workflow should answer two questions:

  • Who is responsible for doing the work?
  • Who is accountable for the final decision?

Those are not necessarily the same person. A useful RACI model can assign responsibilities across:

  • Marketing
  • Editorial
  • Subject matter experts
  • Compliance
  • Legal
  • Regional teams
  • Product teams

The final published asset should have a clearly identifiable accountable owner. Without that, AI-generated content can create a dangerous accountability gap.

Status: ☐ Yes ☐ Partly ☐ No

11. Are AI agents subject to escalation rules?

AI agents introduce a different governance challenge from individual AI tools. An assistant might generate a paragraph. An agent could potentially research a topic, create content, optimise it, translate it and prepare it for publication. That means an error can propagate through an entire workflow.

Agentic marketing operations should therefore define:

  • What the agent is permitted to do
  • What it cannot do
  • Which decisions require approval
  • When it must escalate
  • Who receives the escalation
  • What actions require human intervention
  • What activity is logged

The principle should be:

The greater the autonomy, the stronger the controls around it.

Status: ☐ Yes ☐ Partly ☐ No

12. Do we retain appropriate records and audit trails?

Good governance should leave evidence. Depending on the content and risk level, records may include:

AI tool used

  • Date created
  • Original AI output

Human reviewers

  • Sources checked
  • Editorial changes
  • Compliance review
  • Legal approval
  • Final approver
  • Version history
  • Publication date

Not every asset requires the same level of documentation. A low-risk blog does not need the same audit trail as a regulated financial communication. The principle is proportionality and you should be able to reconstruct how a material piece of AI-assisted content moved from generation to publication.

Status: ☐ Yes ☐ Partly ☐ No

13. Do we have controls for AI-generated images, video and translations?

AI content governance should not stop at written copy. Marketing teams increasingly use AI to create:

  • Images
  • Video
  • Audio
  • Presentations
  • Translations
  • Localised campaigns

Each introduces different risks. For example, an AI-generated image may require provenance or disclosure considerations. A translation may be grammatically perfect while changing the meaning of a regulated claim.

Multilingual content may therefore require native-language review, particularly where accuracy, brand positioning or compliance is important.

A mature AI content policy should define how different content formats are governed.

Status: ☐ Yes ☐ Partly ☐ No

AI governance should not be a one-off project.

Your risk assessment should evolve as:

AI tools change

  • New use cases emerge
  • Teams adopt AI agents
  • Regulations develop
  • Content volumes increase
  • New markets are entered
  • New risks are identified

A simple risk assessment can evaluate:

Risk → Likelihood → Impact → Control

For example:

  • Risk
  • Example
  • Likelihood
  • Impact
  • Control

Hallucination

Incorrect statistic

High

High

  • Editorial + fact checking
  • Brand inconsistency
  • Wrong tone

High

  • Medium
  • Brand review
  • Compliance
  • Missing disclaimer
  • Medium

High

  • Compliance review
  • Translation
  • Incorrect localisation
  • Medium

High

  • Native-language review
  • Legal
  • Misleading claim
  • Medium
  • Very high
  • Legal approval

This gives marketing leaders a practical way to prioritise governance investment.

Status: ☐ Yes ☐ Partly ☐ No

15. Do we monitor the quality of AI content over time?

Governance does not end when content is published. Organisations should monitor whether AI-assisted content is actually performing to the required standard. Useful measures include:

  • Quality
  • Factual correction rates
  • Editorial revision rates
  • Source verification
  • Brand consistency
  • Operational
  • Time from brief to publication
  • Review time
  • Approval time
  • Workflow bottlenecks
  • Commercial
  • Organic traffic

AI search visibility

  • Engagement
  • Leads
  • Conversion
  • Pipeline contribution
  • Governance
  • Review completion
  • Compliance exceptions
  • Escalations
  • Policy breaches
  • Audit findings

The purpose is to identify whether the operating model is improving.

  • Status: ☐ Yes ☐ Partly ☐ No
  • Your AI content compliance scorecard

Once you have completed the checklist, count your answers.

12 to 15 "Yes" answers

You have many of the foundations required for a governed AI content operation. The next step is likely to focus on consistency, measurement and scaling.

7 to 11 "Yes" answers

You have some controls in place, but there are likely gaps between policy and day-to-day execution. Focus first on ownership, review workflows and risk-based escalation.

0 to 6 "Yes" answers

Your organisation may be adopting AI faster than it is governing it. Start with the fundamentals: an AI marketing policy, approved tools, human review requirements, accountability and a defined workflow.

This score is an internal maturity indicator, not a legal compliance assessment. Whether your organisation meets its obligations under the EU AI Act depends on the specific AI systems, roles, uses and circumstances involved.

What should an AI content compliance process look like?

The 15 questions above can be turned into a simple operating model:

Brief

AI generation

Editorial review

Fact checking

Compliance review where required

Brand review

Approval

Publication

Performance feedback

The important point is that not every asset necessarily needs every stage and the workflow should route content according to risk. A low-risk asset might move through four stages, but a high-risk asset might require seven or eight. That is how marketing teams can increase AI adoption without turning governance into a bottleneck.

The bigger question for marketing leaders

The question is no longer whether your marketing team is using AI because most teams already are. The more important questions now are:

  • Can you see where it is being used?
  • Do you know what it is producing?
  • Can you identify which outputs require additional scrutiny?
  • Do people know when they are accountable for reviewing AI-generated content?
  • Can you demonstrate how high-risk content was approved?
  • Do your AI agents operate within defined boundaries?

If the answer to those questions is unclear, you have an AI adoption problem that looks like a governance problem.

The good news is that governance does not need to mean slowing everything down. In fact, the right operating model does the opposite. It gives marketing teams the confidence to use AI at a greater scale because the rules, responsibilities and controls are clear.

Want the complete framework?

This checklist is designed to give marketing leaders a practical starting point, but a checklist only identifies the gaps.

The harder question is how to build the operating model that closes them. Our ebook The Marketing Leader's Guide to the EU AI Act takes that next step.

The guide covers:

What the EU AI Act actually means for marketing

Human oversight

AI content governance

  • Risk assessment
  • Governed AI workflows

AI agents and autonomous marketing

  • Enterprise governance checklists
  • An adaptable AI marketing policy
  • A practical AI governance workflow
  • Roles and responsibilities
  • Approval processes

Download the free guide and use the frameworks to build an AI content operation your organisation can trust.

Download The Marketing Leader's Guide to the EU AI Act

Frequently asked questions

What is an AI content compliance checklist?
An AI content compliance checklist is a practical set of questions used to assess whether an organisation has appropriate policies, review processes, risk controls and accountability for AI-assisted content.
Does the EU AI Act require all AI-generated marketing content to be reviewed by a human?
No. The EU AI Act does not impose a blanket requirement for human review of every piece of AI-generated marketing content. Article 50 contains specific transparency obligations, including one concerning AI-generated or manipulated text published to inform the public on matters of public interest where it has not undergone human review or editorial control. The precise obligations depend on the AI system, its use and the circumstances.
What should an AI marketing policy include?
An AI marketing policy should typically cover approved AI tools, permitted uses, human review, factual verification, brand standards, data protection, content ownership, compliance escalation, AI agents, record keeping and policy review.
How should marketing teams review AI-generated content?
Review should be proportionate to risk. Depending on the content, this can include editorial review, fact checking, source verification, subject matter expert review, brand review, compliance review and legal approval.
How can marketing teams govern AI agents?
Marketing teams should define what agents can do, what they cannot do, which decisions require human approval and when they must escalate. Higher-risk autonomous activities should have stronger human checkpoints and appropriate audit trails.
When do AI-generated marketing materials need to be labelled?
The answer depends on the type of AI system, the content and how it is used. Under Article 50, certain AI-generated or manipulated content is subject to transparency obligations, including deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. The Article 50 transparency obligations apply from 2 August 2026.
Is AI content compliance the same as AI governance?
No. Compliance is one part of governance. AI governance also covers quality, brand consistency, accountability, workflows, risk management, human oversight, monitoring and operational controls.
How often should an AI content policy be reviewed?
There is no universal review interval that suits every organisation. A sensible approach is to review the policy on a defined schedule and whenever there are material changes to AI tools, regulations, use cases, organisational risk or the marketing operating model.

Want the complete framework?

Download The Marketing Leader's Guide to the EU AI Act for enterprise checklists, policy templates and a practical AI governance workflow.

Download the free guide →