The question is no longer what AI can do, but what we are willing to let it do.
A few days ago, we were talking about Which sectors are leading the adoption of agent-based AI, and where are we headed by 2027?. Now it's time to take it a step further. AI is already part of the daily operations of many companies, and with the advent of agents capable of accessing systems, chaining together actions, and performing tasks, the need to set limits is also growing.
This is where the AI governance: the set of criteria, standards, and controls that determine how artificial intelligence may be used within an organization, what decisions it may make, and which decisions must be made under human supervision.
Because The more autonomy we give AI, the more important it is to know what it's doing, what information we want to share and how far we want to take it.
What AI Is Already Doing in Businesses
Marketing is one of the areas where this transformation is happening the fastest. Salesforce notes that 75 % of the professionals surveyed already use AI. The potential is clear: AI can generate twenty newsletter topics, ten versions of a landing page, fifty ads, or one hundred social media posts at virtually no marginal cost.
However, 84 % of those same professionals admit to continuing to develop generic campaigns. The problems of Data quality, fragmentation, and availability remain the main barrier to achieve the personalization that the technology promises.
AI has drastically reduced the cost of producing content. It hasn't reduced the cost of having something interesting to say.
And the more accessible the generation is, The assets that are not available to everyone will be the ones that hold the most value: personal experience, proprietary data, real-world cases, client knowledge, judgment, methodology, reputation, and the ability to connect the dots.
From Prompt to Method: How AI Is Starting to Be Used in Your Company
During these early years, we've focused a lot of our attention on learning how to ask the AI for things: how to write better prompts, how to provide context, and how to get more accurate answers. The prompt was the first way we interacted with ita: a direct, specific instruction intended to elicit a specific response. Useful, but limited. Every time you started a conversation, you had to start from scratch.
The next step came in October 2025 with Skills: Reusable sets of instructions that you define once for a specific type of task, and the AI applies them continuously without having to repeat them. It’s not a prompt; it’s the criteria that remain constant. A skill can define how a campaign should be analyzed, what steps to follow, which sources to consider valid, what exceptions exist, or which decisions require human approval. You set it up once, and it always works the same way, with your company’s logic built right in.
The challenge now is to go further: ensure that AI operates in a way that aligns with the entire organization's workflow.
Let’s consider a Google Ads analysis. It’s not enough to simply say, «Analyze this campaign.» A company may want any analysis to first verify the quality of the tracking, validate the periods being compared, review investment, conversions, CPA, or ROAS, search terms, historical changes, promotions, and seasonality—always distinguishing facts from hypotheses. That’s not a prompt or even a standalone skill. It’s the work method from that company, transferred to the machine.
We don't know exactly what form this will take in the coming years. What does seem clear, however, is the direction: Every company needs to make AI an integral part of its operations, with its knowledge, its rules, its processes, and its limitations. A generic AI that doesn't understand how your company works can generate a lot of noise. One that's integrated into your way of working can provide real value. And that difference isn't created by technology alone; it's built by each organization.
It is likely that within a few years this will even give rise to a new professional specialty: people whose role is not merely to know how to use AI, but design how AI should function within a company.
One's Own Context as a Competitive Advantage
Salesforce has found a significant difference between teams that simply use AI and those capable of feeding it connected business data. Marketing teams with unified data are 2.4 times more likely to rank among the top-performing professionals and are 60 % more likely to use agents to scale their operations.
It's not just a technological issue. An AI that doesn't know who the customer is, What customers have purchased, what problems they've encountered, which products are available, which ones generate profit margins, or what the sales strategy is—you can automate a lot of this and still contribute very little.
If we all have access to similar AI models, a growing portion of The competitive advantage will lie in the context that each company is able to provide them. CRM, documentation, historical records, customer data, and accumulated experience can become the true raw material for enterprise artificial intelligence.
It is also worth keeping in mind What happens to the information we provide to these systems?s. Some language models can use conversations to improve future versions, unless corporate settings prevent this. A company that systematically enters strategic information into free tools without reviewing their terms of use is unwittingly making a decision about the ownership of its own knowledge.
Do we use it to think, or to avoid thinking?
AI Eliminates Friction. Research that used to take several hours can now be completed in minutes. You can summarize hundreds of pages, compare competitors, analyze thousands of customer reviews, or explore ten different scenarios almost instantly.
The advantage is obvious, but it also creates a temptation: stop researching because asking is much faster. In the past, competitive analysis involved searching for information, reading it, verifying it, comparing it, interpreting it, and discussing it before making a decision. Now we can type, «Analyze these five competitors and tell me what my company should do,» and have a proposal ready thirty seconds later.
The point is not to give up that ability, but to understand what we are receiving. There is a huge difference between asking AI to find patterns we haven't detected and asking it directly to define our strategy. The first approach amplifies our capabilities. The second risks replacing them.
In organizations that are achieving real results, AI has not replaced human judgment, but rather has forced him to be more explicit. Professionals who work best with these systems know exactly what value they add and what tasks they can delegate. Those who simply use them to avoid having to think are, without realizing it, building a dependency that ultimately reduces their ability to do their jobs well without them. It’s not a technological problem. It’s a habit.
Perhaps the most dangerous risk isn't that AI will make a mistake
Artificial intelligence systems can misinterpret a source, omit relevant information, invent a fact, or construct a logical explanation for something that did not actually happen that way. The most delicate problem arises when we stop expecting them to make mistakes.
An incorrect answer may be superbly structured, use professional terminology, and present a perfectly coherent argument. It may sound even more convincing that the analysis prepared by one person could still be incorrect.
In marketing, this happens particularly often. We might enter some data and ask why the cost of acquisition has increased. AI can come up with a reasonable explanation based on CPC or the competition. However, perhaps a promotion ended, inventory changed, there was a tracking issue, or we’re comparing periods that aren’t equivalent.
There is a fundamental distinction here: AI can be extraordinary at generating hypotheses; professionals must turn those hypotheses into evidence. Data, interpretation, hypothesis, recommendation, and decision are not the same thing. One of the risks of using AI continuously is moving too quickly through that chain until we end up making a decision based on something we never actually verified.
The problem escalates when AI stops responding and starts taking action. Until recently, a mistake with AI might have meant getting poor-quality text or an incorrect answer. Now, systems are beginning to have access to data, applications, and business processes: they can query a CRM, analyze campaigns, modify information, trigger automations, or execute actions.
Imagine a customer service representative connected to the order management system. If the system misinterprets a return policy, it no longer generates an incorrect message that someone will review before sending. Instead, it directly triggers an incorrect action: an unwarranted refund, an unauthorized discount, or a promise of an impossible turnaround time.
An AI that gives incorrect answers generates incorrect information. An AI connected to systems can turn that incorrect information into an incorrect action.
Risks are also spreading beyond the company
The problem isn't limited to internal data and processes. We're starting to see consequences for reputation, intellectual property, fraud, and trust.
In September 2026, new cases were reported of influencers whose images were used in deepfakes to promote products with which they had never had any connection.
The Guardian (in an investigation published on September 12, 2026) cites estimates that put global losses related to deepfake scams at approximately $3.7 billion in 2026. Companies are no longer merely potential victims of this type of fraud; they can also unwittingly become its vector when a vendor or third party uses images, voices, or corporate identities for unauthorized purposes.
Microsoft notes that 32 % of the reported data security incidents were related to generative AI tools. And 71 % of the British employees surveyed had used unauthorized consumer AI tools to do their work, with 51 % continuing to do so on a weekly basis. It’s easy to imagine what this means in a real-world business setting: budgets pasted into a chatbot, contracts entered to generate a summary, business reports analyzed by free tools, or confidential information used to prepare a presentation.
You don't have to have officially implemented AI to already have an AI governance problem.
The regulatory environment has also changed. The European AI Act, which has been in effect since 2024, has been gradually implementing its obligations, while Spain is also making progress in developing its own Artificial Intelligence Act.
The conversation about artificial intelligence is no longer just about how much time we can save. It’s starting to include security, privacy, rights, reputation, transparency, and accountability.
What a gap that most companies aren't closing
The paradox of this moment is that the magnitude of the challenge can be measured. Deloitte (in its "State of AI in the Enterprise 2026" Report) notes that about 60 % of workers already have access to AI tools approved by their companies, compared to less than 40 % a year earlier. However, Only 21 % of the companies say they have a mature model for governing autonomous agents, and three out of four expect to use this type of agent in the next two years.
Gartner adds that up to 40 % of organizations could reduce autonomy or withdraw AI agents by 2027 due to governance issues discovered after they were deployed in production, and that only 13 % currently considers itself to have adequate governance.
Adoption is moving faster than governance. And that gap has direct consequences.

It's no longer enough to experiment: we must govern
The word “governance” may conjure images of large corporations, regulations, and committees, but the concept is much simpler and applies to any medium-sized company as well.
Governance of AI means being able to answer very specific questions: who can use it, what it can be used for, what information it can provide, what sources we consider valid, what decisions it can recommend, which ones it can carry out, when it needs authorization, how we can verify what it has done, and who remains responsible when something goes wrong.
It's not about monitoring every prompt a worker writes. The goal is to establish some ground rules before AI is integrated into so many processes that it becomes difficult to tell where its involvement begins and ends.
And here, governance ceases to be a bureaucratic layer that we add after implementing the technology. It should be part of the design from the very beginning.

Governance does not mean holding back AI
A company may view governance as a set of prohibitions: don't use this tool, don't enter that data, don't automate that. That would be a mistake.
Good governance should, in fact, make it possible to use AI more in areas where it adds value, because we know what its limitations are. It's similar to any other business process. Having permits, designated personnel, controls, and procedures doesn't get in the way of work; it allows you to do it with less uncertainty.
Implementing AI also requires figuring out how the company really works
When we try to explain to a machine how to correctly perform a task, another reality quickly emerges: Many processes are not actually documented. They're in the minds of certain people.
An experienced professional knows that before making changes to a campaign, it’s a good idea to check certain metrics; that a specific source isn’t reliable; that there’s an exception for a certain type of customer; or that a seemingly simple decision requires checking with someone else first. That a series of small decisions It constitutes a very important part of business knowledge.
That is why the implementation of AI may have an unexpectedly positive consequence: it may force us to convert tacit knowledge into organized knowledge. To achieve this, we must answer questions that we may never have explicitly asked ourselves before: how do we actually carry out a task, what do we always check, what distinguishes good work from mediocre work, which decisions require authorization, and which mistakes are acceptable and which are not.
AI may require us to document our criteria before attempting to automate them.
A medium-sized company doesn't need to start with the tool
One of the most common mistakes is to start the conversation with «What AI tool should we use?» Before selecting a technology, you should Identify where there is a real opportunity and what the risk is if you're wrong.
One simple way to do this is to evaluate each process using three variables: how much work a task requires, how much value AI can add, and what the consequences of an error would be.

Where would a medium-sized company start tomorrow?
There's no need to immediately set up an AI committee or write a 100-page manual. But you do need to bring some order to the process. Here are eight specific steps:
- Find out what's happening right now. A simple inventory of tools, departments, uses, and types of information employed. Before designing a strategy, it is important to understand actual usage, including any that has emerged informally.
- Set a few red lines. Information that cannot be entered into unauthorized tools, actions that AI cannot perform on its own, and decisions that always require a person.
- Choose between three and five low-risk, time-consuming processes. It's better to learn about specific processes than to try to «implement AI across the entire company.».
- Document how to do the job right. Before automating a process, define which sources it uses, what steps it should follow, what a professional checks, and what exceptions exist.
- Assign a person in charge. Every relevant use case should have a process owner—not necessarily a technical person, but someone capable of determining whether the result makes sense.
- Grant permissions gradually. First, read and analyze. Next, make recommendations. Then, develop a plan of action. Only when there is sufficient trust should you allow autonomous execution within clear boundaries.
- Measure productivity as well as errors. Time saved, quality, and results—but also necessary corrections, incidents, and situations in which human oversight prevented a problem.
- Check the model periodically. Capabilities are changing too quickly to consider any definitive policy. What we reject today may very well be safe a year from now.
This makes implementation a gradual process: observe > test > measure > document > increase autonomy. Not in a race to integrate AI into the entire company.
Three Questions to Ask Before Granting Autonomy to AI
Before allowing an agent to act independently in a process, it is important to be able to clearly answer three questions:
- What happens if you make a mistake? Determine the actual level of risk. An error in an internal report and an error in a transfer or a message to a customer do not have the same impact.
- How will we know that he made a mistake? Determine the level of oversight. If there is no clear way to detect the error, the AI should not act autonomously in that process.
- Who will be responsible when it happens? Determine accountability. If no one is in charge of the process, there is no guarantee of effective oversight: AI does not assume responsibility, but people do.
If a company cannot clearly answer all three questions, it probably should not yet grant autonomy to AI in that process.
And what would I reject right off the bat?
It may also be helpful to establish certain decisions that should immediately trigger a warning sign:
- Automate a process that we don't yet fully understand.
- Connecting sensitive information to tools whose data processing practices we are unaware of.
- Allow irreversible actions without approval.
- Using results that no one within the company knows how to verify.
- Delegate important decisions simply because the system is usually right.
- Implementing AI simply because a new feature exists, without having identified the problem it solves.
There is a a particularly useful rule: «If we can’t explain how a task should be done correctly without AI, we’re probably not ready to automate it with AI yet.»
The future may not lie in using more AI, but in better designing how it works with us
As of September 2026, we are still in a early and rapidly changing stage. We're now talking about prompts, agents, co-pilots, and different models because they are some of the tools and architectures available. It's quite likely that in a few years, some of this terminology will have become outdated.
We may end up with systems connected to virtually the entire organization that are capable of continuously understanding the business context. Professionals may emerge who specialize in designing the methods, boundaries, and criteria by which these systems operate. Most likely, both of these developments will evolve simultaneously.
What The need to decide what information we provide is unlikely to disappear, what level of autonomy we grant, what results we verify, and who is responsible.
That's why perhaps the competitive advantage doesn't lie in becoming the company that automates the most. It will lie in to become the company that knows best what to automate, what knowledge to transfer to the machine and which decisions it wants to keep in human hands.
Artificial intelligence can help us work faster, analyze more information, and carry out processes that until recently seemed impossible to automate. But as its capabilities grow, so too must our ability to manage it.
Because we can delegate work, streamline processes, and integrate AI with virtually every aspect of our business. What What we cannot delegate is the responsibility to understand what he is doing and why.
