A compliance officer at a large advertiser was asked a question this year that appears in no policy binder, no vendor questionnaire, and no audit programme written before 2024. The question was whether the company could stand behind what an AI system says about it.
Not what it publishes. Not what it advertises. What a machine, asked a question by a buyer, asserts about the company's prices, its lead times, its certifications and its terms — in the company's name, at scale, with no person in the path.
There is no file for that. There is no vendor for it either.
This paper is written for the officer who has to answer anyway, and for the marketing lead who will be asked to explain it to a board. It covers what the parts of an AI system actually are, where a brand lives once it stops being an object, who is holding that today, and what happens to it when the holder changes hands. It closes with the question worth putting to counsel, and an attempt at answering it.
The machine and its appendages.
Most of the confusion here comes from one word doing four jobs. "AI" is used for the model, for the things attached to the model, for the software that decides what to attach, and for the box a person types into. They fail differently, and only some of them touch a company's data.
The model is a predictor. Given text, it produces the text most likely to follow. It has no lookup, no record, and no way to know whether what it produced is true. When a model states a price with no connection to a live source, it has not consulted anything. It has produced the number that a price for that kind of object usually looks like.
Retrieval is the act of fetching a real document and putting it in front of the model before it answers, so the model paraphrases a record instead of composing from memory. Retrieval is what separates an answer that can be traced from an answer that cannot.
Tools are named operations the model is permitted to call — look up an order, check stock, calculate a total. A tool call is a real request to a real system, and it either succeeds or fails visibly.
An agent is a loop: a model allowed to choose a tool, act, observe the result, and choose again, repeatedly, without a person approving each step. Agents are where small errors compound, because step four inherits step two's mistake and nobody read step two.
The consequence for a compliance function is that these four require different controls, and a questionnaire asking "do you use AI" will not distinguish them. A model that only talks is a reputational surface. An agent holding tool access is an operational one.
The brand you can hold, and the brand you cannot.
There is a version of a brand that exists as an object. A statement in an envelope. A finished piece carrying a mark. A physical good in a box. It has a chain of custody people already know how to reason about, because it is the same reasoning used for any controlled document — who handled it, where it was stored, what happened to the overruns.
There is a second version with no object at all. It is a set of records held in systems the company does not operate: audience segments built from customer behaviour, conversion histories, exclusion and inclusion lists, creative archives, the accumulated learning of every campaign that ever ran, and the account structures those things live inside.
The second version is where most of the value now sits, and it is the version nobody can point to.
That is not a figure of speech, and the measurement is not new. Ocean Tomo has tracked the composition of corporate value across a fifty-year panel of the US market. In 1975, tangible assets — property, plant, equipment, inventory and other physical capital — represented 83 percent of the market value of the S&P 500, with intangible assets accounting for only 17 percent. By the end of 2025 the relationship had completely inverted: intangible assets constitute approximately 92 percent of S&P 500 market capitalisation, and tangible assets a mere 8 percent. The steepest movement came between 1985 and 2005, when the intangible share rose from 32 percent to 79 percent — a 47-point shift inside two decades.

Set that against the custody question and the problem states itself. Ninety-two cents in every dollar of market value now rests on assets with no physical form — the mark, the reputation, the customer relationships, the data. The eight cents that can be walked past in a warehouse are inventoried, insured, depreciated and audited to the item. The ninety-two are, in the part this paper concerns, held in accounts nobody at the company can name.
Who is holding it right now.
In most organisations the second version is held by third parties, under agreements written for a different purpose.
Audience data sits inside a demand-side platform seat. Creative and campaign history sit in accounts an agency provisioned. Exclusion lists sit with a verification vendor. Conversion tracking sits in a platform account whose registered holder may be the agency rather than the advertiser. None of this is unusual and none of it is evidence of bad faith. It is how the business developed.

It becomes material at exactly one moment: when the relationship ends, or when the holder changes.
What moved on the twenty-sixth of November.
On 26 November 2025, Omnicom completed its acquisition of Interpublic. In the company's own announcement, the combination carries "pro forma combined revenue in excess of $25 billion." Legacy Omnicom shareholders hold approximately 60.6 percent of the combined company and legacy Interpublic shareholders approximately 39.4 percent, on a fully diluted basis. The chairman and chief executive called it "a defining moment for our company and our industry."
Figures circulating in the trade press — a cost-synergy target, the scale of role reductions, a combined billings estimate — do not appear in that announcement. They are reported figures, and they are treated as reported figures here.
The arithmetic of the deal is not the point. The point is that a very large number of advertisers woke that morning with the second version of their brand held inside a corporate entity that had changed shape overnight, under contracts signed with a company that no longer exists in the same form.
Nothing was taken. Nothing needed to be. The custodian became a different organisation, with a different integration roadmap, a different set of preferred platforms, and a different view about which systems to retire.
Was it already vulnerable.
The merger did not create the exposure. It revealed one that had been documented years earlier by the advertisers' own trade body.
In June 2023 the Association of National Advertisers reported that the open web programmatic ecosystem it studied represented $88 billion, and that as much as $20 billion of it — 23 percent — was waste. The finding that should interest an auditor more than the waste figure is a different one: the average campaign among the study's respondents ran on 44,000 websites. The ANA called that "deeply concerning," and set it against its own observation that "advertisers can reach a high percentage of target audiences using a few hundred websites."
In the complete report that followed, the association stated the core number plainly. Only 36 cents of every dollar entering a demand-side platform effectively reaches the consumer, leaving $22 billion in efficiency gains available. Following best practice, it estimated, could raise that from 36 cents to 50 cents or more.
Read those findings the way an auditor reads them rather than the way a media planner does. A control environment in which spending is distributed across 44,000 counterparties, and in which roughly a third of the money arrives where it was intended, is not primarily a performance problem. It is a problem of documentation, concentration and traceability — the three words that appear in every vendor-management finding in every regulated industry.
The association now maintains a market-level measure of how much investment actually clears every quality test at once. Its TrueAdSpend Index — the share of programmatic investment delivering impressions that are fraud-free, measurable, viewable and free of made-for-advertising placement — stood at 43.3 percent in Q1 2026. Fewer than half of the dollars cleared all four conditions simultaneously.
Separately, and from a vendor's own sensor network rather than from the trade body, Fraudlogix reported an invalid traffic rate of 18.12 percent across a sample of 26.3 billion impressions between 1 January and 31 March 2026, against 20.64 percent for full-year 2025. That figure is a vendor's measurement of its own network and is carried here as such, not as an industry constant.
For scale on whose money this is: the association states that its members represent 20,000 brands and $400 billion in annual marketing investment.
The instrument was never calibrated.
The control most organisations believe protects them here is the blocklist: a set of words the brand does not want its advertising to appear beside, applied automatically to every page.
The tool scans the page, finds a listed word, and withholds the advertising. News pages contain those words because that is what news is. So the list does not screen out unsafe pages. It screens out reporting.
Integral Ad Science tested this against Reuters and found that 54 percent of news URLs that had already cleared as brand-suitable would still have triggered keyword blocklists. On the same publisher's lifestyle section the figure was 4.27 percent of URLs, accounting for 13.5 percent of that section's advertising impressions over the test period. Reuters' general manager put the conclusion directly: "Our belief is that it is in everyone's interest, including the marketers, not to use this tool at this point."
The money does not disappear when a page is blocked. It relocates. It lands on pages with deliberately unremarkable vocabulary, which is precisely what made-for-advertising pages are built to be. In 2023 the ANA found such pages accounted for 21 percent of study impressions and 15 percent of spend. By the association's Q1 2026 benchmark that exposure had fallen to 1.1 percent, after running between 0.4 and 0.6 percent through 2025 — with the report naming AI-generated filler as an emerging subtype requiring continued attention.
There is no referee any more.
For five years the industry had a common standard-setter for this. The Global Alliance for Responsible Media, created in 2019, was a voluntary cross-industry initiative addressing digital safety.
On 9 August 2024 the World Federation of Advertisers discontinued it. Its statement is worth reading exactly as written: "GARM is a small, not-for-profit initiative, and recent allegations that unfortunately misconstrue its purpose and activities have caused a distraction and significantly drained its resources and finances."
Read that once more before moving on. It did not lose the argument. It ran out of the money required to have it.
Whatever view is taken of the dispute, the operational fact is the same for every organisation in this position. The shared definitions are gone, and the obligation to define what is acceptable adjacency has moved back inside each company — to a function that in most cases has never been asked to hold it.
Governance beat price, and it was not close.
The association now publishes a quarterly benchmark, and the Q1 2026 edition contains the single most useful figure in this entire subject.
It separates advertisers into higher- and lower-performing cohorts. Higher performers converted 54.0 percent of programmatic spending into qualified impressions. Lower performers converted 32.1 percent. The 21.9-point spread is the widest the benchmark has recorded.
Then the decomposition, which is the part worth carrying into a meeting:
Transaction costs differed between the two cohorts by 2.4 percentage points.
Media productivity losses differed by 19.4 percentage points.
Higher performers lost 19.0 percent of spending to media quality issues. Lower performers lost 38.4 percent, more than double. The higher cohort held a 13.3-point advantage in measurable inventory and a 6.7-point advantage in viewability, ran materially more concentrated supply footprints, and paid lower average CPMs while doing it.
Average CPMs across the market fell from $5.55 in Q4 2025 to $4.42 in Q1 2026. Prices went down and the quality gap went up.
The previous quarter's edition made the commercial consequence explicit: advertisers optimising toward quality-adjusted measures rather than price alone recorded reductions in cost per conversion approaching 40 percent, even where nominal CPMs rose.
The same edition carries a warning about the middle of the market. The proportion of advertisers clearing the 50 percent conversion threshold fell from 50.0 percent in Q3 2025 to 43.8 percent in Q4 — gains concentrating among those actively managing quality while everyone else slipped. Participation in the benchmark itself grew from 54 marketers to 86 over the following quarter, which suggests the finding is being taken seriously by the people who can see it.
The layer with no vendor.
Every control described so far concerns where advertising appeared. An entire industry exists to verify it, and the numbers above come from that industry's instrumentation.
Not one part of it does the other job. None of it verifies what a machine says about a company.
When a model answers a buyer's question about a price, a lead time, a certification or a term of supply, no vendor checks that answer against the company's records. There is no viewability equivalent. There is no measurement standard. There is no log, unless the company built one.
This is the gap that matters, because the failure is worse in kind. An advertisement beside an unfortunate article is an embarrassment. A stated price the company never set, given to a buyer who relies on it, is a representation — made in the company's name, without the company's knowledge, at a volume no review process was designed for.
The industry spent a decade learning that in the media layer, governance beat price. That lesson has not been applied one layer up.

What the duty of care actually is.
The question worth putting to counsel is short. Who owes a duty of care to the brand's data — the CMO, the agency, the platform, or nobody? And if the honest answer is nobody, is that a contract problem or a governance problem?
The CMO owes it. The agency and the platform owe something narrower, and only if it was written down before the work began. When the honest answer feels like nobody, it is almost always because three documents were signed without reading them, and none of them contained the word backup or portability or access-after-termination.
Contract problem or governance problem is the wrong split. It is a contract problem that only shows up when governance was ceremonial. The CMO who never asked where is this held, in whose name, and what happens to it if you close our account tomorrow created the exposure. The contract that answered none of those questions made it permanent.
The agency's general terms usually say they will use reasonable care. Reasonable does not include maintaining a second copy after the engagement ends, or handing over credentials to accounts they provisioned in their own name. The platform's terms say the account holder is responsible for their own data, and the account holder is often the agency, not the brand.
When the agency folds, or the relationship sours, or the platform bans the account for a reason it will not explain, the brand discovers it owns nothing it can prove and has no one it can compel. That is not bad luck. It is what signing a scope of work that did not mention data custody looks like twelve months later.
What should have been written:
Data is held in an account titled to the brand, or in an account the agency provisions with documented transfer rights that survive termination.
The brand receives a full export monthly, in a named format, held in a location only the brand controls.
The agency returns all credentials, archives and access within five days of termination, and confirms deletion of any copies it held.
The platform contract is reviewed for the suspension and deletion clauses before the account is funded, and someone at the brand has read what happens when the platform decides you violated something.
The competent answer is a walkthrough. They show you the accounts, they show you who holds root access, they confirm the brand owns the credentials or has a documented right to receive them, and they produce the export format and the interval at which it happens. If you hear we back everything up without seeing where or in what form, or it's all in the platform without anyone explaining what the platform's terms actually say about your continued access, you are working with someone who has not read the failure modes. The fuller answer would include a copy of the platform's data retention and account suspension terms, marked up to show which clauses matter, and a written schedule of who performs the export and where the brand's copy is held. If they cannot produce that inside a week, they have not been doing it.
A protocol, defined for a brand.
The Model Context Protocol is a published interface that lets an AI system ask a business a question and receive the answer from that business's own records, live, instead of composing one from memory.
Four things follow from that, and they are the four a marketing officer needs.
It is not a chatbot and not a website feature. It is a connection standard. A card terminal does not move money; it connects to the system that does. This is that, for questions about the company.
It changes the verb. Without it, a model generates a claim about the brand — it predicts what the price sounds like. With it, the model retrieves one. Identical question, entirely different liability.

The company chooses what is exposed. Current price, stock position, lead time, which certifications are in force. What is not exposed stays unexposed, and that is a decision made deliberately rather than by omission.
It produces a log. Every question asked about the brand, every answer returned, timestamped. Brand safety has never had an audit trail at the answer layer. This is one.
Why the budget looks different now.
Three line items exist in a 2026 marketing budget that did not exist in a 2022 one, and none of them are media.
The first is custody. Somebody has to hold the export, in a named format, in a location the company controls, on a schedule. That is a small recurring cost that eliminates a category of total loss.
The second is retrieval. Making the company's own facts machine-readable and answerable is engineering work. It is built once and answered from at near-zero marginal cost afterwards, which is why it behaves like an asset rather than a campaign.
The third is audit. Keeping the log, reviewing it, and being able to produce it. This is the line that converts an assertion problem into a documented process, and it is the one a regulator or an insurer will ask about first.
Against those, the benchmark suggests where the money comes from. Concentrating the supply footprint, measuring quality rather than price, and governing the buy moved 19.4 percentage points of productivity in the association's own data. The budget is not larger. It is differently shaped, and the shape follows the exposure rather than the calendar.
What to ask before the next cycle.
These six separate the organisations that are governing this from the organisations that are hoping. They are in the order they are usually needed.
Whose name is on each account that holds our data, and where is that written down?
What is our export format, how often does it run, and who at this company holds the copy?
On termination, what returns to us, within how many days, and what evidence of deletion do we receive?
How many domains did our spending touch last quarter, and can we produce the list?
When a model is asked what we charge, where does that number come from?
Who reviews the log of what was said about us, and how often?

An organisation that can answer all six is governing this. An organisation that can answer none is not exposed because of anything a machine did. It is exposed because the questions were never on the agenda.
Knowing the questions is not the same as having done anything. Five actions, in order, none of which require a budget cycle to begin:
One. List every account that holds company data and record who the registered owner is on each. Not who uses it. Who owns it. Capture the evidence rather than the recollection.
Two. Ask the agency for the three most recent exports. If three do not exist, that is the finding, and it is available today rather than at renewal.
Three. Put thirty minutes with counsel on the calendar to read the suspension and deletion clauses of the two platforms carrying the most spend.
Four. Pull last quarter's domain count and ask for the list. The number arrives quickly. The list is the test.
Five. Ask what a model currently answers when a buyer asks what the company charges, and where that number came from. If nobody can say, that is the gap this paper describes, measured in the company's own words.
None of that is a project. It is a week, and it converts an unbounded exposure into a documented one — which is the only move available before anything else can be fixed.
About us.
Huang Goodman is the brand partner for brands that cannot afford a bad headline. Four arms under one house: strategy and public relations, creative and content, program management, and physical production through Hako Shikin, with 1,400-plus vetted American manufacturers and a catalogue of 70,000-plus products across 200-plus authorized brands. One accountable operator, documented handoffs, and a live dashboard that tracks the work from quote to delivery. Virginia Beach, since 1997.
-Jenny Huang Goodman MPA MSc MHSA jenny@huanggoodman.com