Episode 81: Marketing Compliance in the Age of AI
Ashley Cianci walks through PerformLine’s new guide, Marketing Compliance in the Age of AI, breaking down three separate shifts reshaping the compliance landscape: the volume of AI-generated content now outpacing review capacity, AI platforms becoming an unmonitored channel that describes your brand to prospects, and agentic AI pushing compliance from a scheduled check into a continuous requirement. Each shift is walked through with a real example, including a multi-state disclosure case study and a live AI Response Monitor query that surfaced three compliance violations hiding underneath a negative brand mention.
In This Episode:
- AI didn’t add one more channel to monitor. It changed the entire board compliance teams are playing on.
- Shift one: content volume is outpacing review capacity, and a state-by-state disclosure patchwork creates exposure even in content that already passed review.
- Shift two: AI platforms like ChatGPT and Gemini are now describing your brand to prospects, with no named author, no approval workflow, and no edit button.
- A live query on a credit card issuer surfaces three compliance violations sitting underneath a viral-worthy negative sentiment hit.
- Shift three: agentic AI is turning compliance from something run on a schedule into something that has to run continuously.
- The practical fix: move review upstream and make it jurisdiction-aware, pair pre-publication review with continuous discovery, and document everything.
Chapters
- 1:24: Introduction to AI’s Impact on Marketing and Compliance
- 3:53: Multi-State Regulatory Challenges and Disclosures
- 6:17: AI’s Role in Consumer Research and Brand Perception
- 9:04: Compliance Violations Hidden in AI-Generated Content
- 10:53: The Shift to Continuous Compliance Monitoring
- 12:33: Practical Strategies for Extending Compliance Programs
- 13:58: Controlling AI’s Impact Through Ecosystem Management
Show Notes:
- For the full download: https://content.performline.com/guide-to-marketing-compliance-in-the-age-of-ai
- Connect with Ashley Cianci on LinkedIn: https://www.linkedin.com/in/ashley-cianci/
- Subscribe to PerformLine to stay connected to resources and updates: https://lp.performline.com/subscribe-to-performline
Subscribe to COMPLY: The Marketing Compliance Podcast
About COMPLY: The Marketing Compliance Podcast
The state of marketing compliance and regulation is evolving faster than ever. On the COMPLY Podcast, we sit down with the biggest names in marketing, compliance, regulations, and innovation as they share their playbooks to help you take your compliance practice to the next level.
This podcast is for informational and educational purposes only and does not constitute legal advice; consult your own compliance or legal counsel.
Episode Transcript:
Ashley Cianci:
Hey there, COMPLY Podcast listeners, and welcome to this week’s episode. I’m Ashley Cianci, and today I want to do something a little bit different.
I want to start by talking about something that I’ve been thinking about a lot lately, as I’m sure most of us have. But it feels like just yesterday ChatGPT became available to the public. And I remember how amazed I was when I submitted a blog for it to proofread, and it came back with real, accurate, tangible edits.
And then fast forward a couple of weeks, or maybe months later, and it was drafting these blogs for us again with a high consistency and accuracy that truly amazed me. So if you had told me at this point, probably three years ago now, what a marketer was going to be able to do today with these tools, I probably wouldn’t have believed you.
And back then, if you had asked a bank or a fintech what AI and compliance meant, you probably got one question, which is, are we even allowed to use ChatGPT?
That was the whole conversation. You would write a policy, you picked your solution, train people on basically what not to paste into it, and you were done. But that question is already so far behind us. On Wednesday, we published a new guide called Marketing Compliance in the Age of AI. And instead of just pointing you to it, I want to actually walk you through what’s in it, and why we felt like we had to write it.
So grab your coffee, and let’s get into it.
So here’s the argument: AI didn’t add one channel for you to monitor; it changed the entire board that we’re all playing on.
And there are really three separate things happening, which get talked about as one topic all the time, and honestly, they’re not. They have different exposure, different owners, and different fixes.
So the first one is that AI changed the content that you create.
Number two, AI became a channel that describes you to your customers, whether you’re participating in it or not.
And number three, the newest one, is Agentic AI, is turning compliance from something you check on a schedule into something that has to run continuously.
And I wanna be clear about the framing here, because I don’t think this is a story about anybody doing their job poorly. Most of our review processes were designed before any of this existed, so it’s not a failure. It’s just the timeline that we’re living in today.
So let’s take this one step at a time.
All right, so shift number one, and this is the one I think most of you are already feeling heavily in your day-to-day.
But here’s the math: the volume of marketing content being generated this year is on track to exceed every prior year by a very wide margin, and your compliance team’s capacity to review it has stayed likely very flat in terms of manual effort. Same headcount, same hours in the day, same queue.
And that’s really the whole problem in one line. The job itself hasn’t changed, but the amount of work to review has changed that job fundamentally.
And look, for most of its history, compliance review has been a downstream gate. So creative gets made, compliance reviews it, things get sent back, and campaigns get delayed. Everybody complains about that bottleneck, and everybody lives with it because the volume was tolerable enough.
But generative AI breaks that entire arrangement, not because the review got works, but because the gap between how fast content gets produced and how fast it can get reviewed turns into a real, measurable exposure.
And here’s the part that I think is getting underestimated, and it’s the part that worries me the most. This is not just your marketing team’s AI-generated content.
It’s a loan officer using an AI tool to draft social posts on a Sunday night. It’s a partner bank generating product descriptions with an LLM. It’s a comparison site auto-generating rate summaries off a data feed. And none of that goes anywhere near your review queue. It shows up on your channels your team isn’t watching, often before anybody inside your building even know it exists.
Now, the second half of that shift one has nothing to do with AI at all, and I actually think it’s the underrated one. It’s the multi-state problem.
Even content that passes review can create exposure because the standard it’s getting reviewed against is no longer uniform under a federal regulatory umbrella.
We use an example in the guide, and I want to walk through it, because it’s exactly the kind of thing that looks completely clean on the way out the door: a digital campaign for a new savings account.
High-yield savings, your money working harder, the 4.5% APY in the headline is all real. The disclosures are present, legal reviewed it, compliance signed off on it, and everybody did their job. Check, check, check.
But what the headline doesn’t surface is that the 4.5% only applies to balances under $10,000. Above that, the rate drops to 0.5%, and that’s disclosed in the linked terms. So under a federal baseline review, that ad looks probably fine.
Now run it in California, New York, and New Jersey, and you’re operating under different enforcement frameworks all at the same time. California’s SB 825 expanded the DFPI’s ability to pursue unfair or deceptive marketing without waiting on federal referral. New York’s Fair Business Practices Act gave the AG new authority on unfair and abusive practices. And New Jersey’s AG and Division of Consumer Affairs issued an enforcement statement that specifically names inadequate disclosure and drip pricing.
Same ad, different regulators, different questions, and one review process that wasn’t built for any of them but the first.
And here’s my take, which is the same thing we keep landing on in our Roundup podcast, but don’t try to thread the needle 50 times. Map your disclosures against the strictest applicable state standard and then apply that everywhere.
Now layer AI-generated content on top of that patchwork, and the whole thing compounds.
Okay, shift number two. And if you only read one section of this guide, I want it to be this one. And I want to start somewhere personal, because this is how it clicked for me. My own “let’s just Google” it has quietly turned into let’s ask ChatGPT”. I didn’t decide to do that, and I didn’t notice it happening; it just happened. And I’m guessing a lot of you can relate to that exact sentiment happening in our everyday lives. But now think about what that means if you’re the brand on the other side of the question.
You already know how to monitor marketing channels. Affiliate networks get audited, email campaigns get reviewed, digital ads get checked against disclosures. That’s table stakes at this point.
AI platforms are so vastly different, and the difference is structural. There’s no named author, no approval workflow, no edit button. There’s no CMS to pull a bad page from, and no partner you can email about it. There’s just an answer generated in real time from a model trained on public web content that happened to include your brand.
And the scale is not theoretical. OpenAI reported ChatGPT passing 900 million weekly active users back in February. And a TD survey this spring found 78% of Americans are using AI tools in daily life, and more than half saying they use AI to help manage their finances. That number was 10% the year before. 10 to 55 in 12 months. But here’s the stat from that survey I keep coming back to: only 18% of those people say they trust AI to make financial recommendations on its own.
So sit with that for a second. People are consulting AI about their money in enormous numbers while openly not trusting it. They’re using it for research, so for the first pass, for framing the question before they go anywhere else.
Which means AI’s answer about your product is shaping the decision without ever being the decision. Your prospects are asking an AI about your rates, your fees, your licensing, your terms before they ever land on your website.
And some of what it’s telling them is likely wrong.
Now there’s a whole category of tools that’s gotten really good at answering the question every marketer is asking right now, which is, are we showing up in AI responses and how often?
And that matters.
GEO, or generative engine optimization, is becoming the new SEO, or search engine optimization. And teams that get ahead of that are going to have a structural advantage.
But visibility tells you that you’re in the conversation. It doesn’t tell you what happens to your brand once you’re in it. A brand can show up consistently and be misrepresented, outdated, or non-compliant in every single response.
Visibility measures exposure; it does not measure risk.
So let me give you a real one because this is the one that stopped me in my tracks.
So we ran a query through our own personal AI Response monitor platform, mirroring what consumers actually type: “The best credit cards for improving a low score.” And we wanted to see what one specific issuer landed. Gemini’s response about the issuer was, and I’m quoting this: “Honestly, I’d rank them dead last, and I would avoid them like the plague.”
Now, a visibility tool catches that. It logs the mention, tags a sentiment, negative, and then somebody on the brand team has a rough morning.
But that’s not actually the part that worries me. What a visibility tool does not catch, are three compliance violations sitting in one layer underneath it.
Number one, required disclosures were missing: product benefits described without the terms and apply qualifiers that issuers’ own affiliate guidelines require.
Number two, card names used incorrectly: a shortened, non-registered version instead of the exact brand name.
And number three, improved wording violation: product details paraphrased instead of presented word for word and the way the program mandates.
And the “avoid them like the plague” line is the headline. The compliance violations are the liability underneath it.
And that’s a piece legal and compliance end up absorbing long after the brand damage has already shown up and been forgotten about.
So why does this matter? And are regulators actually gonna care about something that your company didn’t write?
I’d push back on the premise there a little bit. The CFPB has already stated that existing consumer protection laws do apply to AI with no exceptions, and specifically flagged that chatbots and LLM-based systems can give consumers inaccurate information, that raises the risk of unfair, deceptive, and abusive practices.
So that law hasn’t changed. Who enforces it has. And those state frameworks we just walked through don’t stop at content you just produced.
Under UDAAP and Fair Lending Standards, if a consumer makes a financial decision based on inaccurate information about your product, regardless of who generated it, you have potential exposure. The regulatory question isn’t about authorship; it’s about consumer harm and what you did to prevent it.
So the teams getting this right aren’t picking between visibility and response monitoring. They’re running both.
All right, shift number three, and this one is just arriving.
So for most of its history, compliance ran on a clock: reviews quarterly, audits annually, risk assessments on a fixed schedule. And honestly, that model made complete sense when risk moved slowly.
Agentic AI breaks that assumption. As AI systems start assembling context and acting across channels, the pace and the volume of what has to be monitored stops fitting into a scheduled review.
And here’s the counter-intuitive thing I really want you to sit with, because it runs up against the pitch everybody is hearing right now.
More AI means more compliance, not less.
The common assumption is that AI shrinks this compliance burden, but it’s doing the opposite. Every AI capability you adopt to move faster is, in the same motion, a brand-new surface you have to govern.
This is the tension we’ve been hearing all year from the teams that we work with. Financial institutions want to grow, and they want to use AI to do it, but the question nobody has a clean answer to yet is how do you do that without the growth costing you on compliance?
And the gap is already showing up in the data. IBM’s Institute for Business Value surveyed 2,000 CIOs and CTOs this year across 33 countries and 19 industries. 77% said AI adoption has already outrun their current governance capabilities, and only 11% felt fully ready for the volume of AI agents they expect to deploy in the next 12 months.
Those same organizations averaged 54 AI agent incidents in the prior year, and 17% of those incidents triggered compliance issues that needed human intervention.
So this isn’t a forward-looking risk anymore. It’s already generating work.
So let me close on a practical part because none of this requires rebuilding your compliance program. It requires extending it three different shifts.
Number one, move review upstream and make it jurisdiction-aware. Pre-publication review is where to start, because it’s your clearest shot at stopping a problem before it reaches a consumer.
But content reviewed only against a federal baseline is going to miss exposure in the states with broader standards. Your process has to account for where content is going to run, not just what it says.
Number two, pair pre-publication control with continuous discovery. Review and approved is the floor. It’s not the same thing as monitored. Content evolves after publication, its services on third-party channels, and now it gets generated by AI completely outside your workflow.
The strongest programs do both.
And number three, document everything so it survives an inquiry. State AG investigations don’t follow predictable calendars. When one shows up, the first question is whether you can demonstrate a functioning program across the period under review: review records, monitoring cadence, remediation history. Evaluate, score, document.
All right, so quick recap. AI changed what you create, and your review capacity didn’t move with it. AI became a channel describing your products to prospects, with no author and no edit button. And Agentic AI is pushing compliance from periodic to perpetual.
And one last thought before I let you go, because I think it’s the most hopeful part of all of this. You can’t control what AI says about your brand, but you can absolutely improve the accuracy of what it’s learning from. These models train on publicly available web content: your site, your affiliate network, your partner marketing, your old ad copy that’s still cached somewhere out there.
And when an AI generates an inaccurate claim about your product, it usually traces right back to something in your own digital ecosystem that nobody was actively managing.
The window on this is narrowing, though. As AI becomes a primary way people learn about financial products, regulators are going to expect evidence that you’re monitoring what’s being said across every channel, including the AI ones. The question isn’t whether AI monitoring becomes a compliance expectation. It’s whether you close the gap before a regulator asks how you’re handling it or after.
The full guide, “Marketing Compliance in the Age of AI,” is on performline.com. I’ll absolutely link it in the show notes. I would really encourage you to subscribe so you don’t miss what’s next. And you can follow PerformLine on LinkedIn for content in between episodes. And if you’ve got feedback on this one, or a story you think we should be covering, reach out or connect with me on LinkedIn. I really do want to hear it.
Thank you so much for listening, and I’ll see you on the next one.