AI governance used to sound like a policy problem.
- Who can use AI?
- What can they paste into a prompt?
- What needs human review before it goes live?
Those questions don’t go far enough anymore.
The last brief covered how AI search and AI agents are moving into the workflow layer, and this one goes a step further. The issue now is what AI can access, what it can change, what it can disclose, and who owns the decision when AI output becomes part of the business.
That illustrates how one dimension of AI governance is a permissions problem.
You can see it in:
- ChatGPT Work connecting to apps, files, browsers, plugins, and company workflows.
- The AEO / GEO ownership gap, where brands know AI representation matters but don’t know who should own it inside the business.
- Google’s new AI ad transparency labels, where disclosure starts to become part of commercial trust.
- Google’s Universal Commerce Protocol, where agents will be able to not only read business information, but also to discover capabilities and act on them.
As a B2B leader, that should get your attention quickly.
If you don’t define the permission layer, AI systems will still move forward. They’ll just do it through default settings, disconnected workflows, unclear ownership, and tool-specific assumptions that may or may not match how your business actually needs to operate.
So this edition focuses on a practical question:
What should you allow AI to access, influence, disclose, and act on inside your marketing and revenue systems?
Signal 1: ChatGPT Work turns governance into access architecture
OpenAI launched ChatGPT Work on July 9, describing it as an agent that can take action across apps and files, stay with a project for hours, and turn a goal into finished work. OpenAI says it can gather information across apps and workflows, create materials like sheets, slides, docs, and web apps, and break larger projects into smaller steps it can complete independently.
That is a major shift in what “using AI” means.
This is not the same as asking a chatbot to summarize a blog post or draft an email. OpenAI’s examples include turning customer research into a campaign brief, using that brief to create marketing assets, adapting those assets for different markets, and carrying context across the process. ChatGPT Work also connects to tools like Slack, Microsoft Teams, Google Drive, SharePoint, email, calendars, CRMs, project trackers, and other internal systems through plugins.
The governance section is the most important part. OpenAI says Enterprise and Edu admins can centrally manage who has access, what company context ChatGPT can use, which tools it can connect to, and what actions it can take. It also says admins can manage plugin access, browser use, network access, sensitive actions in connected systems, and local-file or app-based work on desktop. Auto-review adds another control layer, by reviewing important actions involving connected tools and APIs before they happen.
That tells you where enterprise AI is headed.
The question has moved from “Did someone use AI to create this?” to “What did AI have permission to see and do?”
What marketers may misunderstand
A lot of teams will treat ChatGPT Work as a productivity upgrade, and that’s understandable at face value.
The natural first assumption will be based on time savings: faster briefs, research, slide decks, reports, and internal apps. All of that can be useful.
But for marketing and revenue teams, the bigger issue is access.
When AI can connect directly to your CRM data, campaign history, Slack threads, internal documents, customer feedback, browser sessions, and local files, you will need to know what context it’s using, before you can trust the output.
A campaign brief built from clean sources is one thing, but it’s a whole different story if it’s built from outdated messaging, unreviewed Slack comments, old sales decks, or messy CRM notes.
No matter which scenario happens, you’ll end up with quality looking output, and that’s a problem if trusted blindly.
The real implication
AI governance is becoming access architecture.
You’ll need to define which systems AI can reach, what data it can use, which actions it can take, and where you need to insert an approval step before anything changes.
For B2B marketing, that creates risk in several places:
- Campaign strategy based on incomplete or outdated customer information
- Sales enablement built from inconsistent positioning
- Executive reporting influenced by weak source inputs
- AEO or GEO recommendations made from partial visibility data
- Customer-facing assets created from internal notes no one meant to publish
- RevOps workflows adjusted without enough review
All of these scenarios can happen if you allow the AI to run with unclear permissions and weak or nonexistent review steps.
What B2B teams should do now
Start by mapping what AI can access.
Most companies already have a list of approved AI platforms and tools. That’s useful, but it fails to answer the more important questions:
- Which company systems can AI access?
- Which teams can connect which apps?
- What customer, prospect, or employee data is off limits?
- Which AI actions require approval before they happen?
- Who reviews outputs that affect public messaging, sales activity, reporting, or customer experience?
- Where do logs live, and who actually checks them?
Once you answer those questions, you can build practical governance around real workflows, instead of abstract AI usage hypotheses.
This is also where HAIF-style thinking has a place in your workflow. Don’t leave review by a human review at the end of every workflow, as a vague final check. Instead, make sure it shows up where the risk changes: when AI moves from drafting to recommending, from recommending to acting, or from acting internally to affecting buyers.
Why this matters for visibility, governance, trust, and revenue
AI will touch more of your revenue system, whether or not your team formalizes the process.
The companies that benefit won’t be the ones that connect every tool as fast as possible. They’ll be the ones that decide which sources AI can use, which actions require review, and which outputs deserve to shape buyer-facing work.
That’s the permission layer.
Without it, AI will be able to move faster than you can verify what happened.
Signal 2: GEO matters, but many companies still don’t know who owns it
Axios reported on July 16 that Muck Rack’s 2026 State of PR report surveyed 1,115 communications professionals and found that organizations are still sorting out who owns GEO. According to Axios, 73% said GEO is at least somewhat important to communications strategy, while 29% said no one at their organization owns it. Only 24% said PR or communications owns GEO, compared with 11% who said marketing leadership does.
That ownership gap is a serious signal.
GEO isn’t just another acronym for SEO. And in this case, I’m pretty sure the study is treating AEO and GEO as one combined discipline, even though they aren’t the same thing. AEO deals with retrieval-based answer systems. GEO deals with how AI systems describe, classify, compare, and remember your brand at the model level. Both depend on strong source signals, but they don’t work the same way.
Axios still makes the source issue clear: whether you call it AEO, GEO, or AI visibility, these systems depend on the sources they can draw from, including earned media coverage, clear official website content, and credible third-party references.
That means AEO and GEO simply can’t belong neatly to one team, because:
- PR influences earned media.
- SEO controls website structure and discoverability.
- Content builds out topical depth.
- Brand affects positioning.
- Product marketing dictates category language and competitive proof.
- RevOps helps connect visibility to pipeline and revenue quality.
- Leadership and customer advocacy strengthen the third-party and human proof AI systems use to understand the company.
No wonder ownership is messy.
What marketers may misunderstand
Marketing teams often try to absorb GEO into SEO. PR teams argues that AI representation depends on earned media and authority signals, so they should own it.
Both claims have some merit, but neither is complete.
SEO influences AEO and GEO with structure, crawlability, extractability, and content depth. PR has a role via third-party credibility, media coverage, and public authority. But AI brand representation pulls from more than search pages and press mentions.
For a B2B company, AI systems build their picture from:
- Website content
- Executive bios
- Case studies
- Customer reviews
- Analyst or media mentions
- Partner listings
- Social profiles
- Product documentation
- Public communities
- Podcasts and webinars
- Comparison pages
- Third-party directories
That mix creates the ownership problem: AEO and GEO live across the organization, and not inside one department.
The real implication
AI Visibility is a shared responsibility, but shared responsibility without ownership becomes nobody’s job.
That’s where many companies will get stuck. They’ll agree that AI representation matters, but no one will own the operating model. Each team may do something useful, but the company still won’t have a governed representation strategy.
That’s the real AHA here.
AEO and GEO need a control model, not a turf battle
What B2B teams should do now
Assign one accountable owner, then build a cross-functional AI Visibility working group around that person.
That owner doesn’t have to do all the work. In fact, they can’t. But someone needs to coordinate the source base and decide what matters most.
A practical AEO/GEO ownership model should answer:
- Who monitors how AI systems describe the company?
- Which prompts or buyer questions matter most?
- Which sources define the company’s categories, services, proof points, and differentiators?
- Who fixes inconsistent or outdated information across public sources?
- What role do PR, SEO, content, product marketing, and RevOps each play?
- How do findings turn into action?
For many B2B companies, the best owner may sit in marketing strategy, product marketing, or brand. PR and SEO still matter a lot, but someone needs to manage the whole representation layer, all the way up to what the executives are saying about the company and its offerings.
Why this matters for visibility, governance, trust, and revenue
Buyers don’t need AI systems to make the final purchasing decision. They only need those systems to shape the shortlist, frame the category, summarize the vendor landscape, or influence the questions buyers bring to sales.
That’s more than enough to affect revenue.
If AI systems describe your company accurately, connect you to the right category, and serve up credible proof, you’ll be in a better position for closing new customers. When they make you sound generic, outdated, or irrelevant, your sales team will be starting the conversation from a weaker place.
That’s why AEO and GEO ownership belong in governance, and AI representation is now part of brand management.
Signal 3: Google’s AI ad labels move paid media into a disclosure layer
Google announced new AI transparency features for ads on July 9. The company is adding a “How this ad was made” section to the My Ad Center panel, accessible globally through the three-dot menu or info icon on ads across Search, YouTube, and Discover. Google says this panel will indicate whether an ad was created or edited with AI.
Google also says ads created with its generative AI advertising tools will receive automatic disclosure in the My Ad Center panel. When advertisers use other AI tools, Google is introducing a control, so they can indicate that generative AI was used. Depending on local requirements, a label might appear directly on the ad.
AI-generated commercial content is moving into a more visible trust environment.
Marketers have spent the last couple of years asking whether AI can help create ads faster. Now platforms and regulators are pushing a different question: Will people know when AI was involved?
What marketers may misunderstand
Some teams will treat this as a compliance checkbox.
- Did we label the AI ad?
- Did the platform apply the disclosure?
- Are we covered?
That’s too narrow.
The real issue is whether or not the ad even hits the mark, based on how it was created. You need to know how an ad was made, what AI changed, who approved those changes, and whether the final ad still represents the product, offer, audience, and brand correctly.
Business Insider’s reporting on Meta’s AI ad tools shows why this is a big deal. Advertisers and agency executives described AI-generated ad problems that altered products, added unwanted elements, created strange visuals, or required extra manual checks. Meta told Business Insider that advertisers remain responsible for reviewing AI outputs.
That’s the part marketers need to pay attention to: automation doesn’t resolve your company of accountability for what the AI is automatically creating.
The real implication
Paid media needs better AI controls.
If AI creates or edits an ad, your team should know what changed and who approved it. That applies to copy, images, video crops, product visuals, audience variations, landing page suggestions, and any automated creative enhancement that could affect the buyer’s perception.
This matters even more in B2B, where ads often support longer sales cycles, high-consideration purchases, regulated claims, complex products, and brand trust over time.
A sloppy AI-generated consumer ad may become a social media joke. But a misleading B2B ad can create sales friction, legal review problems, channel conflict, or brand credibility loss with a narrow audience that is crucial to your success.
What B2B teams should do now
Apply a model like HAIF to your paid ad review process, to ensure nothing slips through.
You don’t need to make this complicated; just add a clear checkpoint whenever AI is involved.
For every campaign, ask:
- Did AI create, edit, crop, summarize, rewrite, or generate any ad asset?
- Which tool made the change?
- Was the AI feature enabled intentionally?
- Did a member of the team compare the output against the original product, offer, and brand standards?
- Does the ad require a label or disclosure in the platform or region where it runs?
- Who approved the final version?
This should become part of campaign QA, not an emergency response after a weird or inaccurate creative asset goes live.
Why this matters for visibility, governance, trust, and revenue
AI can help teams produce and test more creative, but some of those variations very well may NOT be okay to use publicly.
Paid media already sits close to revenue. It drives demand, sets first impressions, retargets buyers, and carries claims into the market. When AI starts generating or modifying those messages, governance needs to move into the ad workflow itself.
A disclosure label tells users that AI was involved, but it won’t illustrate whether or not the ad was accurate, useful, or on-brand.
That review still belongs to you.
Signal 4: Google’s Universal Commerce Protocol points to agent-facing business access
Google’s Universal Commerce Protocol is still commerce-specific, but the broader signal is what grabbed my attention here.
Google describes UCP as an open-source standard for agentic commerce that gives consumer surfaces, businesses, and payment providers a common language. It can work with existing retail infrastructure and supports integrations through APIs, Agent2Agent, and the Model Context Protocol. Google says UCP lets businesses showcase product and service offerings at shopping touchpoints across consumer interfaces such as AI Mode in Google Search and the Gemini app, while businesses own their business logic and remain the Merchant of Record.
The technical details point to the bigger direction. UCP creates a standard way for consumer facing tools like AI Mode and Gemini to connect to business backends for things like product discovery and checkout. It also allows agents to discover business capabilities and payment options dynamically.
That might sound far away from B2B services, but it isn’t.
The specific protocol applies most directly to retail today, but the pattern is important for everyone: AI agents will need structured access to what businesses can do, and not just what businesses say.
What marketers may misunderstand
A lot of B2B teams will dismiss this as ecommerce plumbing.
For now, that’s understandable. If you sell consulting, software, industrial services, healthcare technology, or complex B2B solutions, you’re probably not thinking about AI agents checking out with a shopping cart.
But don’t ignore the direction: Agentic systems will push companies to expose capabilities.
AI systems will eventually need structured ways to understand:
- What services you offer
- Who they’re for
- What integrations you support
- Which workflows your product can perform
- What documentation defines your capabilities
- What pricing or packaging constraints exist
- How a qualified buyer can request, configure, or initiate the next step
That is business structure, not just content.
The real implication
Discoverability is moving from pages to capabilities.
AEO already made this shift partly visible. Answer engines don’t only rank pages. They retrieve pieces of information, synthesize answers, and cite sources.
Agentic systems take the next step, moving beyond just understanding information. They need to know what actions are available, which systems can be invoked, what permissions apply, and what proof exists that a business can deliver.
For B2B companies, this won’t happen all at once, but the direction is clear enough for us to all start preparing.
Your website, schema, product documentation, API documentation, partner listings, integration pages, service descriptions, and sales workflows will all become more important, as AI systems try to understand not just your message, but your actual capabilities.
What B2B teams should do now
Start making your capabilities easier for machines and humans to understand.
That doesn’t mean turning your website into a developer portal overnight. It’s more about reducing ambiguity in the places where you define what the business does.
Focus on the basics first:
- Clear service and product categories
- Strong entity consistency across the website and third-party sources
- Specific use cases and industries served
- Structured data where appropriate
- Integration and platform pages, if relevant
- Documentation that reflects current capabilities
- Case studies that prove the work
- Calls to action that match the buyer’s stage
If your public information is vague, AI systems will struggle to understand what your company can actually do. And guess what…buyers will, too.
Why this matters for visibility, governance, trust, and revenue
AI discoverability is expanding beyond rankings and citations.
As agents become more capable, they’ll need to understand which businesses can perform specific actions under which constraints. That creates a new kind of visibility problem.
Your company will need to be findable as a source, understandable as an entity, credible as a vendor, and usable as a capability layer.
That’s a lot more than SEO.
Once AI systems can act on business capabilities, we’ll all need to decide what those systems can access, what they can initiate, and what requires human approval.
The bigger pattern
These four signals connect around the same issue: permissions.
That gives B2B organizations a more useful way to think about AI governance.
You don’t need to start with a giant policy. Start by defining permission boundaries around the work that matters most.
The permission questions look different by area:
- Internal AI workflows: What can AI see, use, remember, and change?
- AEO / GEO: Who owns the sources that influence how AI systems describe the brand?
- Paid media: Who approves AI-created or AI-edited commercial content before it reaches buyers?
- Agent-facing discovery: What business capabilities should AI systems be able to understand or initiate?
Those are important questions around how you approach and optimize visibility, trust, source/input integrity, buyer experience, and revenue quality.
What to do now
Start with the highest-risk permission gaps.
For internal AI workflows, review which tools can connect to company data. Decide where AI can assist, where it can recommend, and where it can act. Those levels need different controls.
For AEO and GEO, assign an accountable owner. Then bring PR, SEO, content, brand, product marketing, and RevOps into a working model that treats AI representation as a shared source integrity problem.
For paid media, add AI reviews to campaign QA. Your team must know when AI changed an ad, who approved the change, and whether the final version still represents the offer accurately.
For future agent-facing discovery, make your business capabilities easier to understand. Clear pages, structured data, documentation, integrations, and proof points will be even more important, as AI systems move from answering questions to helping users take action.
The main takeaway is simple: AI governance is no longer just about whether your team used AI.
Now you need to think about what AI had permission to access, infer, disclose, recommend, and do.
That is where B2B companies need to focus next.
Tommy Landry
Latest posts by Tommy Landry (see all)
- The AI Marketing Signal Brief: AI Marketing Governance Is Becoming a Permissions Problem - July 20, 2026
- The AI Marketing Signal Brief: AI Search and AI Agents Are Forcing Governance Into the Workflow Layer - July 6, 2026
- The AI Marketing Signal Brief: AI Search Reporting Is Entering the Revenue System - June 19, 2026





