What decision should the business make?
Decide whether each named task is approved, restricted, or prohibited. Do not approve a vendor’s AI use as one undifferentiated capability. Research, transcription, outlining, image generation, caption drafting, translation, personalization, comment replies, scheduling, and reporting create different failure costs and require different source material. A provider that may brainstorm from public service facts should not automatically be allowed to upload customer messages or publish synthetic testimonials.
Write the decision beside the operating duty: tool and model, permitted inputs, prohibited inputs, human reviewer, evidence required, disclosure check, final publisher, retention rule, and correction owner. That record gives the owner a reversible permission system and gives the provider a specific boundary it can actually follow.
How does the approve, restrict, or prohibit matrix work?
Approve a task when the input is controlled, the output is easy to inspect, the possible harm is low, and a named person reviews the complete asset before use. Examples include summarizing owner-approved notes, proposing a content outline, or producing several headline options that will be rewritten and checked. Approval still requires the final claim, image, link, accessibility text, and destination to pass the normal content workflow.
Restrict a task when it depends on private data, licensed material, a real person’s identity, a regulated claim, multilingual nuance, or a customer conversation. Add narrower inputs, a qualified reviewer, a non-public sandbox, explicit consent, or a no-training term before proceeding. Prohibit the task when the business cannot validate the output, cannot lawfully supply the input, cannot correct the damage, or would let the tool make a sensitive customer or publishing decision.
What should the manager disclose before using an AI tool?
Ask for an inventory of every tool, model, integration, plug-in, automation, subcontractor, and account that can receive business material or produce public work. For each one, request its purpose, account owner, data categories, retention setting, training or reuse setting, connected permissions, export path, and removal process. A brand name alone is not a data-flow explanation.
Require notice before the provider changes tools or enables a new connected feature. A scheduler that adds an AI assistant or a reporting product that summarizes inbox conversations may change the approved data path even when the deliverable count stays the same. The business should be able to refuse the new route without terminating unrelated work.
Which inputs should stay out of general AI tools?
Default to excluding customer messages, lead records, payment or health information, employee matters, unpublished financial or pricing plans, account credentials, legal advice, private contracts, location-sensitive originals, children’s data, and any file the business lacks authority to reuse. Also exclude licensed stock, customer photographs, testimonials, voice recordings, and creator work until the exact permission covers the proposed tool and output.
Use a minimum-input rule. If a caption can be drafted from an approved public service sheet, do not upload the full customer relationship system. If an image variation can be built from business-owned product photography, do not provide an entire shared drive. Redaction helps only when the remaining details cannot reasonably identify a person, account, property, transaction, or confidential situation.
How should factual claims and synthetic media be reviewed?
AI does not change the advertising standard. Prices, dates, comparisons, performance claims, qualifications, testimonials, before-and-after implications, availability, and urgency still need current support before publication. Make the manager link each material statement to the approved source and mark anything inferred, translated, generated, or unresolved. Owner approval cannot turn an unsupported claim into evidence.
Review synthetic images, audio, and video for the complete impression. Ask whether a reasonable viewer could believe a real customer, employee, property, result, product detail, or event is being shown. Check platform disclosure requirements and the business’s own transparency standard. When realism or alteration could materially affect the customer’s understanding, label clearly or use a different asset.
What copyright and likeness questions belong in the gate?
Ask who selected the source material, wrote or revised the expressive elements, arranged the final work, and preserved evidence of human contribution. The U.S. Copyright Office explains that copyright protection depends on human authorship and evaluates human selection, arrangement, or modification case by case. A vendor promise that the business owns every output is incomplete without the tool terms, source rights, contributor agreement, and final production record.
Keep a provenance packet for important assets: authorized inputs, prompts where useful, generated candidates, human edits, source and final files, model and date, licenses, consents, disclosures, and the signed rights clause. Identity, endorsement, trademark, publicity, and contract questions remain separate from copyright.
What is the 20-point vendor gate?
Award zero, one, or two points in ten areas: task inventory; input boundaries; tool and operator disclosure; source-backed claims; human review; synthetic-media labeling; rights and provenance; access and retention; correction and incident response; and export plus termination. Two points requires a specific answer and usable evidence, one means the control exists but is incomplete, and zero means the provider cannot demonstrate it.
A score of 17 to 20 can support a bounded pilot when no hard stop exists. A score of 13 to 16 calls for a narrower pilot after named gaps are repaired. Twelve or below means the provider should not receive AI-enabled live duties. Shared passwords, hidden operators, confidential-data uploads without authority, invented testimonials, undisclosed impersonation, automatic sensitive replies, unsupported claims, or refusal to pause and export are hard stops regardless of the total.
What does a worked local-business decision look like?
Consider a hypothetical dental office buying eight monthly posts. The manager proposes using AI to turn the office’s approved public service sheet into outlines, create caption variations, remove a distracting background from staff-approved photography, and draft replies from patient messages. The office approves outlines and caption variations after staff review, restricts image editing to named files with written permission and a final visual check, and prohibits patient-message processing because the proposed general tool and workflow are not approved for that information.
The office also prohibits synthetic before-and-after patients and automated treatment replies. It permits routine post scheduling only after a named employee accepts the complete final version. The pilot uses one month, one tool inventory, two content cycles, a deliberate price change, and an access-removal test. The result is not an abstract pro-AI or anti-AI stance; it is a documented set of permissions aligned with actual risk.
What should the contract and approval record say?
Attach the task matrix to the scope. Name permitted tools and duties, forbidden data, notification before tool changes, human-review obligations, source and disclosure records, security and retention settings, subcontractors, ownership and license terms, incident timing, correction duties, export formats, deletion, access removal, audit evidence, and which business decisions can never be automated. Avoid a blanket clause that simply says the provider may use AI to perform services.
For every public asset, preserve the approved source facts, important input rights, draft and final versions, human reviewer, disclosure decision, destination, publication time, and correction history. The provider should be able to find every derivative when a fact or permission changes. This makes AI-assisted work fit the same approval and offboarding system as other managed content.
How should a paid pilot test the controls?
Use one current customer decision, approved public facts, representative media, one or two channels, a named reviewer, and the narrowest platform access needed. In cycle one, observe ordinary intake, generation, revision, approval, publishing, and reporting. In cycle two, withdraw one image permission or change one price after drafts exist. The provider should identify affected derivatives, pause them, revise from the current source, obtain fresh approval, and verify the live destination.
Measure more than output speed. Record owner review time, factual corrections, discarded generations, disclosure decisions, customer-action quality, failed links, tool changes, incident handling, source and final file delivery, and removal of access. Continue only if the observed savings remain useful after the business counts supervision and if the controls work when something changes.
When should the business say no?
Say no when the provider cannot explain where information goes, who operates the tool, how the output is checked, what the platform requires, what the business receives, or how the work is removed. Also say no when the proposed efficiency depends on plausible claims without sources, fabricated people or experiences, material without a defensible right, or responses to sensitive customers without a qualified owner.
The business can approve a safer manual path while rejecting the AI path. It can also allow one AI-assisted duty and prohibit another with the same provider. The goal is a truthful, reversible content operation in which a responsible person can explain, approve, correct, and recover every public decision.
What does current guidance change about this plan?
We reviewed current U.S. government guidance on generative-AI risk, advertising truth, and copyrightability together with first-party Meta and TikTok disclosure material. We then translated those sources into a task-level purchasing and vendor-control decision rather than treating AI use as one blanket permission.
Generative-AI risk should be governed across the actual workflow
NIST's Generative AI Profile is a voluntary companion to the AI Risk Management Framework that identifies risks and actions across governance, mapping, measurement, and management rather than reducing responsible use to a final-output check.
How to apply itClassify each manager duty separately, document inputs and operators, require a named human reviewer, test a material change, and make the permission reversible.
Review NIST: Generative AI ProfileAI-assisted advertising still needs truthful claims and evidence
FTC small-business guidance requires advertising to be truthful, non-deceptive, and supported for objective claims regardless of whether a person or a generative tool drafted the language or imagery.
How to apply itLink each price, date, comparison, result, testimonial, availability statement, and implied visual claim to a current approved source before publication.
Review FTC: Advertising FAQs for small businessCopyrightability turns on human contribution
The U.S. Copyright Office reports that wholly AI-generated material is not protected by copyright and that protectable human authorship in selection, arrangement, or modification is evaluated case by case.
How to apply itPreserve authorized inputs, human selections and edits, source and final files, tool terms, licenses, and contributor agreements instead of relying on a blanket output-ownership promise.
Review U.S. Copyright Office: Copyrightability of generative AI outputsDisclosure depends on the synthetic element and platform context
Meta describes AI labels using detectable industry signals and user disclosure, while TikTok requires labeling of realistic AI-generated or significantly AI-edited content under its stated rules.
How to apply itReview whether synthetic media could be mistaken for a real person, event, place, product detail, or result, then apply the platform rule and the business's own transparency standard before publishing.
Review TikTok: AI-generated contentTool access and publishing authority are separate decisions
Meta separates Page capabilities for content, messages, advertising, insights, settings, and access administration, allowing delegated work without automatically granting full control.
How to apply itGrant the manager only the platform role required for the accepted task and keep the final approval, primary ownership, recovery, and removal path under business control.
Review Meta: About Facebook Page accessWhich useful examples can you adapt?
These are not fake captions to copy word for word. Use them as structure, then replace the proof, timing, and CTA with real business details.
For a DIY-versus-service decision, compare the next campaign, available source files, editing time, required formats, deadline, and ownership after delivery.
Replace every detail with the current business facts, then keep only the evidence needed to choose the smallest path that gets the campaign published.
The manager uses a named tool only to organize an owner-approved service sheet.
Approve with final human claim and destination review, while keeping publication authority outside the tool.
The manager wants to paste inbound customer conversations into a general assistant.
Prohibit until information authority, tool terms, retention, operator access, response boundaries, and qualified review are explicitly accepted.
Which authoritative sources should the practice review?
Use these sources as a starting point, then follow the laws, professional rules, and qualified advice that apply to the practice and its location.
- NIST: Generative AI Profile NIST's voluntary companion to the AI Risk Management Framework for identifying and managing generative-AI risks across a system's lifecycle.
- U.S. Copyright Office: Copyrightability of generative AI outputs The Copyright Office's report on human authorship, prompts, modifications, arrangements, and copyrightability in works involving generative AI.
- Meta: Labeling AI-generated content Meta's explanation of AI labels based on detectable industry signals and user disclosure.
- TikTok: AI-generated content TikTok's first-party requirements and controls for labeling realistic AI-generated or significantly AI-edited content.
- FTC: Advertising FAQs for small business FTC guidance on truthful advertising, objective claims, disclosures, and the evidence businesses should keep.
- Meta: About Facebook Page access Meta's current explanation of full-control, partial-control, task, content, message, advertising, and insight permissions for Pages.