Lexguard AI logo
Lexguard AI logo

8 Lessons for Marketing Directors to Govern AI-Assisted Marketing Automation

Bee Cheng Hiang’s AI-assisted email breach offers 8 practical lessons for marketing directors on AI governance, agency controls, RACI accountability, customer-data protection and testing.

Lewis Ho

Email marketing

On 25 April 2026, Singapore food company Bee Cheng Hiang sent an AI-assisted marketing email that disclosed the email addresses of 95,364 customers. An employee had used a generative-AI tool to create a script for a bulk email campaign. The resulting workflow sent emails in batches with recipients’ email addresses visible to one another in the “To” field.

The issue was not described as an AI system malfunction. Rather, the AI prompt did not make clear that recipient addresses had to be concealed, and the campaign was not adequately tested from the recipient’s perspective. The team reportedly reviewed activity logs but did not open and inspect an actual test email before deployment. Bee Cheng Hiang subsequently stopped the campaign, corrected the script, notified affected customers and implemented additional verification procedures.

For marketing leaders, the incident is a useful case study because it exposes failures that can occur in almost any organisation: unclear requirements, unchecked AI-generated code, insufficient customer-experience testing, and blurred accountability between marketing, technology, privacy and external suppliers.


Lesson 1: Classify AI Use Cases Before They Become Embedded in Marketing Operations

Not every AI-enabled marketing activity requires the same level of governance. Using an approved tool to brainstorm campaign themes is fundamentally different from using AI to personalise customer communications, generate code for a bulk-email workflow, analyse CRM data or operate a customer-facing chatbot.

Marketing teams should therefore register AI use cases and apply controls according to the nature of the activity, the data involved, the degree of automation, the potential customer impact and the consequences of error. This allows lower-risk productivity uses to move quickly while ensuring that higher-risk applications receive the appropriate review before they are deployed at scale.

The objective is not to impose a separate approval process on every use of AI. It is to ensure that the level of governance remains proportionate to the use case.

For a detailed explanation of how to build a practical four-tier enterprise AI governance framework, including intake, triage, approval and monitoring, see our earlier article, “Enterprise AI Governance: A Practical Risk-Tiering Framework for Enterprises.”


Lesson 2: Extend Established Marketing Controls to AI-Assisted Work

The Bee Cheng Hiang case was not necessarily evidence that Marketing lacked a process but a failure of the business controls surrounding an AI-assisted workflow. Most established marketing teams already use approval workflows, test sends and launch checklists to protect quality and customer experience. And every marketing professional understands that one recipient must never be able to see another customer’s personal information.

The issue is that those existing controls have not been designed for AI-assisted workflows. When AI generates code, campaign logic or customer communications, the usual process needs additional checks: clear instructions on privacy requirements, validation of AI-generated outputs and confirmation that the final customer experience matches the intended design.

On the other hand, it illustrates a critical limitation of AI: it cannot be expected to infer an organisation’s privacy standards, brand requirements or risk tolerance from an incomplete instruction. Those expectations must be explicitly defined in the prompt and reinforced through governance, testing and human review.

For marketing directors, the implication is clear: ensure that AI becomes a controlled step within the marketing workflow already in place.


Lesson 3: Add AI-Specific Validation to Existing Quality Assurance

Marketing teams already review copy, creative, segmentation, landing pages and campaign performance before launch. AI-generated scripts, automations and workflow logic should be subject to the same discipline.

Where AI is used to generate code or automate an execution step, Marketing should add a targeted validation step to its existing quality-assurance process by testing the output in a safe environment and that the customer-facing result is reviewed before deployment.

For example, a bulk email workflow should continue to include test recipients, proofing and launch approval. The additional AI-specific control is to verify that the generated logic handles recipient data, personalisation fields, suppression rules and sending settings exactly as intended.

Existing Marketing Stage

Established Marketing Control

AI-Specific Addition

Briefing and planning

Define objective, audience, proposition, channel, budget and customer journey.

Document the intended AI use, approved tool, data inputs and whether the output will affect customers or production systems.

Creative and campaign development

Review copy, design, offer terms, brand alignment and campaign logic.

Confirm that prompts and AI outputs do not introduce unsupported claims, unapproved content, privacy risks or inappropriate personalisation.

Audience and data preparation

Apply targeting criteria, consent rules, suppression lists and segmentation controls.

Confirm that customer data is necessary, minimised and used only in approved AI environments.

Testing and quality assurance

Conduct proofing, test sends, link checks, rendering checks and audience validation.

Test AI-generated code, automation and personalisation using dummy data or controlled test accounts; inspect the actual customer-facing output.

Approval and launch

Obtain campaign, brand and, where needed, legal approval before deployment.

Escalate higher-risk AI uses for Privacy, Legal or InfoSec approval under defined thresholds.

Post-launch monitoring

Monitor engagement, conversion, complaints and campaign performance.

Monitor for inaccurate outputs, unexpected automation behaviour, customer complaints and potential data or security incidents.


Lesson 4: Marketing Must Not be Expected to Govern AI Alone

A common governance mistake is to give a broad instruction to “use AI responsibly” without providing the enterprise controls required to make that possible. Marketing directors should not be expected to negotiate vendor indemnities, assess cloud architecture, analyse subprocessor terms or determine data-retention schedules. Those duties require specialist ownership.

Function

Core responsibility for AI-enabled marketing

Marketing

Defines use case, campaign objective, prompt logic, audience rules and output-validation.

DPO / Privacy Team

Determines privacy requirements, data minimisation, consent, retention rules, cross-border transfer requirements and breach notification.

Legal Counsel

Negotiates warranties, indemnities, IP provisions, liability caps, audit rights and agency terms.

CISO / Information Security

Approves technical controls, access permissions, infrastructure isolation and logging.

Procurement

Coordinates vendor due diligence, onboarding, contract files, and supplier management.

Following this division of responsibility, a RACI matrix can be created for higher-risk AI marketing activities to clarify who participates in a decision or control, turning vague expectations into operational accountability:

  • R: Responsible — performs the work.

  • A: Accountable — owns the final outcome and decision.

  • C: Consulted — provides advice before the decision.

  • I: Informed — is notified as appropriate.


AI control activity

Marketing

DPO / Privacy

Legal

CISO / InformationSecurity

Procurement

Define campaign AI use case

A/R

C

C

C

I

Define prompt logic and customer journey

A/R

C

C

C

I

Validate customer-facing output

A/R

C

C for regulated claims

C for high-risk automation

I

Approve use of personal or CRM data

C

A/R

C

C

I

Assess vendor security and integration

C

C

C

A/R

R

Set retention, transfer and subprocessor terms

C

A/R

R

C

C

Negotiate indemnity, warranties and liability

C

C

A/R

C

R

Set up access control, logging and system isolation

I

C

I

A/R

C

Manage breach response and notification

C

A/R for privacy notification

R

R

I

The essential principle is that Marketing is accountable for the business use and customer experience; Legal, Privacy and Information Security are accountable for the enterprise controls that make the use safe and defensible.


Lesson 5: Agencies and Freelancers are Part of the AI Risk Exposure

In many enterprises, a significant portion of marketing execution is not performed by in-house employees. An agency could use an unapproved generative-AI tool to analyse campaign results. A freelancer could upload a client CRM extract to a public model to accelerate personalisation. A creative partner could generate customer-facing claims without the approved source material or review process. As a result, an enterprise may have strict internal rules for AI use while still being exposed through its external marketing supply chain.

Mandatory third-party agency disclosure clause

Marketing agreements should include a dedicated generative-AI clause, reviewed and adapted by Legal Counsel. At a minimum, it should require the following:

Generative AI Disclosure and Safeguards. The Agency must disclose, in writing and before use, every generative AI system used to create, modify, analyse, optimise or deploy any client deliverable or campaign activity. The Agency must not input client personal data, CRM data, customer lists, confidential information, credentials or campaign-performance data into public or unapproved generative-AI systems. The Agency warrants that its AI use complies with the client’s approved-tool requirements, data-handling instructions and applicable laws. The Agency must maintain appropriate errors-and-omissions insurance covering losses arising from automated, algorithmic or AI-assisted deliverables, and must promptly report any actual or suspected unauthorised use, disclosure or processing of client data.

For higher-risk agency relationships, enterprises should also require AI tool registers, subprocessor disclosure, audit rights, subcontractor flow-down obligations, deletion certification and incident-response cooperation. For details of manaing vendor AI risk, please refer to another article "AI Vendor Risk: What to Review Before Renewing Enterprise Software."


Lesson 6: “AI-powered” Marketing Claims Require Evidence

AI risk is not limited to data breaches. It also extends to what marketers say about AI products, AI targeting and AI-enabled services.

The U.S. Federal Trade Commission’s action involving Cox Media Group and two other marketing firms illustrates this risk. The FTC alleged that the firms made misleading claims about an “Active Listening” advertising service, including claims about the use of smart-device conversations and consumer opt-in. The companies agreed to pay a combined US$930,000 under final orders.

Terms such as “AI-powered,” “predictive,” “real-time,” “privacy-safe” or “consent-based” can create expectations about how a product or service operates. Marketing should therefore ensure that these descriptions are supported by evidence and aligned with how the technology actually works.


Lesson 7: Govern Chatbots as an Established Customer-Facing Channel

Marketing departments already manage websites, email, social media, call-centre scripts and promotional landing pages as customer-facing channels. An AI chatbot should be governed in the same way.

A chatbot that discusses promotions, prices, product features, refunds, eligibility, loyalty benefits or terms and conditions should be controlled through approved knowledge sources, defined escalation paths, regular testing and human oversight.

A disclaimer may help explain the nature of the tool. It does not excuse misleading customer communications.


AI Governance as a Rational Investment in Protecting Value

Under Singapore’s PDPC, the PDPC may impose a financial penalty of up to S$1 million or 10% of an organisation’s annual turnover in Singapore, whichever is higher, for intentional or negligent contraventions of the data-protection provisions. The 10% cap applies where the organisation’s annual Singapore turnover exceeds S$10 million. Under the GDPR, certain infringements may result in administrative fines of up to €20 million or 4% of global annual turnover for the preceding financial year, whichever is higher.

Regulatory penalties are only part of the potential loss. A breach may also create investigation costs, campaign interruption, agency rework, crisis communications expenses, executive distraction, customer churn and long-term trust damage.

By comparison, the controls that might have prevented the Bee Cheng Hiang incident are modest:

  • a non-production staging environment;

  • a dummy customer-data set;

  • controlled test inboxes;

  • a mandatory “open and inspect” email test;

  • peer review for AI-generated scripts;

  • two-person approval for bulk campaign deployment;

  • a properly configured email platform that prevents visible multi-recipient sends.

The commercial question is not whether governance introduces friction. It is whether the negligible cost of structured testing is lower than the cost of exposing tens of thousands of customer records.

action list

Action List for the Next 30 Days

Week 1: Establish visibility

  1. Create an AI marketing inventory. Document every AI tool, plugin, chatbot, workflow, code-generation tool and agency-managed platform used by Marketing.

  2. Identify customer-data exposure. Flag every use case involving CRM records, customer lists, purchase histories, loyalty data, service transcripts, behavioural data or production credentials.

  3. Map agency and freelancer access. Identify which external partners have access to customer data, campaign tools, analytics platforms or production publishing environments.

  4. Assign temporary owners. Name a Marketing business owner, DPO/Privacy contact, Legal contact and InfoSec contact for each high-risk AI use case.

Week 2: Put immediate guardrails in place

  1. Pause unapproved data use. Prohibit the use of customer or prospect data in public or unapproved AI tools until the appropriate review is complete.

  2. Implement a high-impact approval gate. Require independent approval for AI-enabled bulk sends, AI-generated production code, automated publishing, CRM updates, customer-specific offers and chatbot policy changes.

  3. Create a mandatory testing protocol. Require dummy data, test recipients and direct inspection of the customer-facing output before deployment.

  4. Restrict production access. Work with InfoSec to ensure that AI tools, agencies and freelancers have only the minimum permissions necessary to perform approved work.

Week 3: Formalise enterprise and agency controls

  1. Build the RACI matrix. Document responsibility and accountability for use-case approval, data handling, vendor assessment, testing, contracting and incident response.

  2. Review priority vendors. Ask Legal, Privacy and InfoSec to review high-risk AI vendors for data retention, model-training practices, security controls, subprocessors, indemnification and audit rights.

  3. Update agency agreements. Insert mandatory AI disclosure, public-model restrictions, incident notification, insurance and subcontractor obligations.

  4. Publish an approved-tool list. Give marketing teams and agencies a clear list of tools that may be used, tools that require approval and tools that are prohibited.

Week 4: Measure readiness and test response

  1. Create an executive dashboard. Track AI use-case inventory coverage, approved-tool adoption, agency disclosure compliance, high-risk campaign review rates, AI defects detected and time to disable unsafe workflows.

  2. Run an incident simulation. Test the response to a misaddressed bulk email, unauthorised agency data upload or inaccurate chatbot promotion.

  3. Train teams and partners. Ensure employees, agencies and freelancers understand what data cannot be entered into AI tools, which activities require review and who must be contacted before deployment.

  4. Report progress to leadership. Present the AI inventory, top risks, outstanding control gaps, business value opportunities and required decisions to the CEO or relevant executive committee.

marketing performance tracking

Conclusion: AI Governance is now a Marketing Leadership Responsibility

When marketing workflows can query databases, generate code and distribute messages to 100,000 customers within minutes, an unreviewed prompt is no longer a minor staff oversight. Instead of removing the need for operational controls, AI automation magnifies the consequences of weak ones, posing material privacy, regulatory and reputational risk.

With the assistance of Legal, Information Security or the Data Protection Officer, the key responsibilty of Marketing leaders is to prevent the governance gap in which “shadow automation” can emerge. This requires three practical disciplines:

  • Own the customer reality, not merely the system log. A delivery log may confirm that an email was sent or an automation was executed. It does not show whether the correct recipients received it, whether personal data was handled appropriately, or whether the customer experience was accurate, compliant and aligned with the brand.

  • Close the agency blind spot. Governance cannot end at the company firewall. Agencies and freelancers may use AI tools to draft content, process customer information, generate code or deploy campaigns. Where they do, their use of AI should be visible, contractually governed and subject to the same standards for data handling, testing and approval that apply internally.

  • Institutionalise the “stop” button. High-impact, customer-facing automations should not proceed directly from prompt to production. They should require named business ownership, a validated staging or test run, and documented human approval before launch. Teams must also be able to pause or withdraw an automation quickly when an error, complaint or unexpected outcome emerges.

The race to adopt AI is often framed as a race for efficiency. But efficiency without control is simply risk operating at greater speed and scale. The leadership task is therefore not to slow down responsible experimentation. It is to ensure that automation serves the business while human judgement, accountability and customer protection remain firmly in place.

FAQ
  1. Is AI-generated marketing code inherently unsafe?

No. The risk arises when generated code is deployed without requirements review, secure development controls, testing, access restrictions and human approval. AI-generated code should be treated as third-party code: useful, but untrusted until reviewed and tested.

  1. Can an agency use public generative AI tools for client work?

Only if the enterprise has explicitly approved the tool and the intended data use. As a default, agencies should never place client CRM data, personal data, confidential information, credentials or unpublished strategy into public models.

  1. Who is accountable when an AI chatbot gives the wrong answer?

The company operating the customer channel remains accountable. A chatbot is part of the customer experience, not a separate legal or commercial actor.