Skip to Content
Back

Governing AI Use: Seven Priorities for Agency Leaders

September 11, 2026

AI is now woven into everyday agency work: research, drafting, creative production, analysis, and more, but the contracts governing your client, vendor, and AI-provider relationships may not have caught up.

Some clients ban AI outright. Others expect AI-enabled speed and efficiency. If your agreements are silent or unclear on AI, your agency may be taking on risks you never intended to accept.

During our recent Governing AI Use webinar, Davis+Gilbert partners Michael Lasky and Andrew Richman outlined seven actions agencies should take now.

1. Review your client agreements

Start with your MSAs. Focus on AI use, confidentiality, ownership, warranties, indemnification, liability, and insurance. Most MSAs require deliverables to be work-for-hire with IP assigned to the client. AI-generated content raises questions about whether that framework holds, and who bears the risk if it doesn’t. Language from older MSAs can create problems: many confidentiality clauses don’t contemplate sharing client information with an AI provider at all.

Action: Address AI explicitly when negotiating or renewing MSAs and confirm with your insurance broker that your insurance covers AI-assisted work.

2. Distinguish between types of AI use

Requiring approval for every AI use isn’t practical once AI is embedded in everyday productivity, research, and analytics tools. Distinguish between internal, everyday AI tools and generative AI used to substantially create client- or public-facing deliverables. Clients can reasonably oversee the latter without controlling every routine use of technology. There’s also a middle ground: preliminary ideation, concepting, storyboards, scripts, and initial creative exploration. This category can often be carved out as permitted use, though it may face some client pushback when outputs are closer to public-facing.

Action: Before the next project begins, define permitted uses and when client disclosure or approval is required and consider agreeing on pre-approved use cases to streamline the process.

3. Protect confidential and client data

Don’t put confidential, proprietary, personal, or client information into an AI system unless it’s been approved for that purpose. Inputs can become part of the algorithm’s training data and subsequently be distributed to others who are not authorized to access the information.

Action: For every approved platform, know how it stores, processes, and retains inputs; whether inputs can train the model; and what data employees may enter. Classify AI tools by risk (or work with legal counsel to do so) so employees know what’s allowed. Reputable AI providers, especially at the enterprise or business tier, are more likely to offer data protections and promises not to use content for training purposes.

4. Allocate responsibility fairly

Be cautious of accepting blanket responsibility for every risk associated with an AI platform. Contracts should establish who is responsible for reviewing, revising, approving, and using AI-assisted work — particularly when a client directs AI use or modifies agency work. Be cautious about accepting liability for the AI platform itself: you don’t control the provider’s underlying systems or practices.

Action: Review AI provisions alongside your client MSA warranties, indemnification, and limitation-of-liability provisions, not in isolation.

5. Extend requirements to vendors

Your agency can be held responsible for work produced by freelancers, creators, influencers, and other third parties, so your AI requirements need to follow the work. The representations, warranties, and indemnities you’re promising to your clients should be flowed down to your vendors.

Action: Update vendor agreements to specify permitted AI uses and tools, data restrictions, and responsibility for AI-assisted output. Know which platforms vendors are using for client- or public-facing work.

6. Vet your AI providers

Not all AI tools or subscription tiers offer the same protections. Free and enterprise versions of the same platform can have very different terms on data, model training, commercial use, IP, and liability.

Action: Before approving a platform, answer:

  • Can outputs be used commercially, and who owns them?
  • Can the provider retain inputs or use them for model training?
  • What IP protections or indemnities are provided?
  • What liability limitations apply?
  • Can third parties access agency or client data?
  • What happens to the data when the relationship ends?

Even when the terms aren’t negotiable, read them before you agree to them. Understanding what you’re agreeing to helps you assess risk and whether it aligns with your client obligations.

7. Make governance operational

Contracts only work if your people and systems follow them.

Action: Maintain an approved-tools list, define permitted uses and escalation steps, train employees, and periodically reassess provider terms and client requirements.

Human review still matters. Before AI-assisted work reaches a client or the public, someone should own checking it for accuracy, confidentiality, bias, IP exposure, and other relevant risks.

The bottom line

Effective AI governance connects what you promise clients with what your employees, vendors, and technology providers actually do. The goal isn’t to eliminate AI risk. It’s to know what you’re agreeing to, establish appropriate safeguards, and make accountability clear.

Do This Now

Ask your legal and operations lead to review:

  • 1 current client MSA
  • 1 vendor agreement
  • Your 3 most-used AI platforms

Use the seven priorities to flag gaps, unclear responsibilities, or terms that need attention. You don’t need to audit everything at once — start with what matters most.

Back