← AI Agents at Work: A Product Launch, End to End
Module 9 Free 10 min

Legal and Privacy: May We Publish This?

Miriam Adeyemi's review queue used to be forty hours of material a quarter. The agents hand her roughly three times that, produced in a third of the time — and every sentence of it reads as though somebody has already checked it.

What you'll learn

  • Judge whether the evidence behind a marketing claim would satisfy a reasonable person
  • Trace where a claim came from — and see why provenance cannot be reconstructed at the end
  • Build a claims register that turns legal review from a bottleneck into infrastructure

On the Monday of week ten Miriam Adeyemi opens the review folder and scrolls. Ad variants for four channels, a five-email nurture sequence, two landing pages, a webinar deck, a partner one-pager, the launch blog, and image variants for all of it. Her queue in a normal quarter is about forty hours of material; this launch has handed her roughly three times that, in about a third of the time.

The volume is the story, but not all of it. What makes this folder harder than the same weight of human-written copy is that every line is fluent — and badly written copy signals its own weak spots, where well-written copy signals nothing. This is Delia’s rule from module 1 arriving in physical form: an agent may produce anything, and a named human owns every claim that reaches a customer. Miriam is that human, for all of it, at once.

NAOMI & THEOcopy and creative, at volumeMIRIAM ADEYEMImay we publish this?DANA WHITLOCK, OPSapproved wording + conditions

Three times the material, a third of the time — and one desk between all of it and the customer.

What lands on Miriam’s desk

Everything the campaign intends to say, arriving in one lump, four weeks before launch.

Two streams meet here: the words from Naomi in module 7, the images and layouts from Theo in module 8. Both were produced with agents, both are far larger than anything Cadence has reviewed before, and both are internally consistent — a quality that helps a reader and hinders a reviewer. Behind them sit Anika’s research dataset from module 3, 340 claims each carrying a URL, a date and a source tier, and Wes’s product truth document from module 2.

Not hunting for reasons to say no. Deciding what evidence a sentence needs, and whether it exists.

The job is narrower than most people imagine, and it is not about taste. Of every asset Miriam asks four things: is each factual statement supported by evidence Cadence actually holds, does Cadence own the rights to every element, is customer information handled lawfully going in and coming out, and could an ordinary reader take away an impression the company cannot stand behind.

The vocabulary of a claims review

Substantiation
The evidence supporting a claim, held before the claim is made. Being able to defend it later is not the standard.
Net impression
What an ordinary reader takes from the whole piece — headline, image and small print together. The test attaches to that, not to your most careful sentence.
Puffery
Unmeasurable enthusiasm — “the smartest way to watch your supply chain”. Needs no evidence because nobody could test it.
Lawful basis
The specific reason you may hold and use someone’s data, usually their consent. It has a scope, and the scope arrived with it.

The software on Miriam’s desk

Review software cannot read for you. It can make sure nothing reaches a customer unread.
AsanaThe review queueEvery asset, its claims andwho is waiting. Three timesthe volume it was built for.SnowflakeThe evidence trailAnika's 340 claims, eachwith a URL and a date. Theseclear in minutes.Claims registerApproved wordingThe claim, its evidence, itsexact wording, and the dateit expires.DocuSignThe approval gateConditional approval, signedand dated, naming what maynot yet be published.

The register is the product. Everything else is how work reaches it.

The queue is where the volume becomes undeniable, and it is worth being precise about why it is hard: fluent copy does not signal its weak points the way clumsy copy does, so more material takes disproportionately more attention rather than proportionately more.

The evidence trail is the reason this review finishes at all. Every market claim traceable to a source and a date clears quickly; the claims that consume Miriam’s week are the ones that entered during drafting, where nobody attached provenance — which is the argument for building it in at the start rather than reconstructing it at the end. The claims register is her real output: approved wording, its evidence, its expiry. It converts her from a bottleneck into infrastructure, because a pre-approved sentence needs no review at all. And the approval record is dated and conditional, which is what makes it possible to say yes without saying yes to everything.

The software on this desk

Asana
The review queue. Makes the volume visible and ensures nothing publishes unreviewed.
The evidence warehouse
Anika’s sourced claims. Traceable claims clear in minutes; untraceable ones consume the week.
The claims register
Approved claims, exact wording, evidence and expiry dates. Turns review from a gate into reusable infrastructure.
DocuSign
The dated, conditional approval record — the artefact that proves what was permitted and when.

The four things Miriam decides

One of them concerns a single sentence, and it is the most consequential decision in the campaign.

The thin statistic, and what “supported” means

The centrepiece of the launch copy, in nineteen assets, is this: Supply Signal catches supply disruptions three weeks early. In two ad variants the verb has drifted back to predicts, the exact word Wes refused in module 2. The evidence is the Calder Thermal pilot: in one quarter, at one customer, Supply Signal flagged 7 of 9 disruptions at least three weeks early — encouraging, and the only performance evidence Cadence has.

Substantiation means a claim must be supported by adequate evidence at the moment it is made, not evidence you might assemble if challenged. And the standard is not what the marketer sincerely believes; it is what a reasonable person would need to accept it. Everyone in the room believes the product works, and belief is not the test.

So can n = 9 carry it? Nine events, one customer, one quarter, one industry, one supply base — and Calder is a design partner, who helped build the thing and had Cadence engineers on the phone. The number is fragile too: one more disruption missed and 7 of 9 becomes 6 of 9, eleven percentage points on a single event. A figure that swings that far on one incident is not a performance level. It is an anecdote with decimal places.

Neither rescue works. “Up to three weeks early” sounds cautious and is not, because readers take “up to” as what they can expect — which is why such a figure generally needs a substantial proportion of customers achieving it. “In one pilot”, bolted beneath a headline that says otherwise, fails differently: a disclaimer cannot cure a headline it contradicts. The test attaches to the net impression, and the net impression of a big promise with a small footnote is the big promise.

What Miriam approves instead is not weaker but more specific: In a one-quarter pilot, Calder Thermal saw Supply Signal flag seven of nine supplier disruptions at least three weeks before they hit production. Attributed, sampled, dated, checkable by anyone who asks, conditional on Calder signing off that wording in writing — and better selling, because prospects have been lied to by general claims their entire careers.

A good sentence is hard to kill

Wes refused the strong verb in module 2 and it is back in module 9. Nobody was dishonest. Between the truth document and the finished ad the idea passed through a positioning line, a creative brief, an agent prompt and thirty variants — every step a chance to round up. Refusing a claim once does not remove it from a campaign. Only a written record of the approved wording does.

Where the sentence came from

Reviewing human-written copy has a feature nobody notices until it is gone: you can ask the writer where a number came from, and they say the pilot deck, slide eleven, or — most usefully — I’m not sure, let me check. A draft assembled from a model cannot be interrogated that way. Ask it and the answer arrives just as fluently, but is itself generated: there is no stored memory of a decision, only a plausible account of one, from the machinery that produced the claim. Not a flaw to engineer around. It is what the tool is.

Which is why Anika’s discipline in module 3 pays off here rather than there. Every market claim — what Arbor Risk charges, what buyers complain about, how the category is moving — resolves to a URL and a date in minutes, because provenance was attached at collection and travelled with the claim.

The claims causing trouble entered later, in drafting, when a benefit was sharpened or two true things fused into a third that was nobody’s claim. Nobody attached provenance to those, because when they appeared they did not look like claims. They looked like writing.

The rule this produces

Provenance has to be built in at the start, because it cannot be reconstructed at the end. From week ten every asset arrives with a manifest listing each factual assertion and its source — a dataset ID, a line in the truth document, or a named owner. An assertion with no entry is not reviewed. It is removed.

Rights in generated material

Here the temperature in most companies is wrong in both directions at once, so Miriam is plain about it. What is genuinely uncertain is ownership of the output: copyright has historically attached to human authorship, and how much human involvement makes a machine-generated image protectable is unsettled and still moving. The practical consequence is undramatic — Cadence may not be able to stop a competitor reusing its generated hero image. An irritation, not a crisis.

The risk that bites sits in the inputs. Feed in a competitor’s product photograph, a stock image lifted from a search, or a third party’s logo as a reference or a style, and the problem travels into the output. “The model made it” is not a chain of title — the record of who owned a work and licensed it onward — it is the absence of one. Nobody can say what rights you hold in a picture when nobody can say what went into it.

So Miriam requires three things: reference inputs logged with their source and licence; generation inside tooling carrying a vendor indemnity where one exists, read rather than assumed, since most are conditional on not feeding in infringing material; and no generated depiction of a real customer’s premises, people or products without written permission.

That last rule kills a specific image: one of Theo’s strongest variants shows an oven plant that reads unmistakably as Calder Thermal, because Calder’s own website photographs were the visual reference. Permission to be named in a pilot story is not permission to synthesise a picture of your factory — and an image that looks like a real place but is not one is itself a factual assertion the campaign cannot support. It goes, replaced by a licensed photograph with a release.

Customer data, going in and coming out

Two exposures, easily confused because both get called privacy.

Going in: what the agents are fed. CRM notes, support tickets and Joel’s interview transcripts from module 4 are full of named individuals, employers and things said in confidence. Pasting that into a general-purpose public tool is not like a disclosure; it is one, of another company’s confidential information, usually in breach of Cadence’s own confidentiality clause with them. So customer material may be processed only inside approved tooling, where the contract says inputs are not used for training and retention is defined — and identifying details are stripped first. An agent finding themes across fifty tickets does not need to know who raised the fourth one.

Coming out: consent and its scope. Every address has a lawful basis attached, and that basis came with limits. Someone who downloaded a white paper on supplier risk gave their details for that purpose; a campaign cannot quietly widen it into a different product line, a partner’s list or an unrelated nurture track because the record sits in the same system. Unsubscribes must be honoured promptly and everywhere, not only in the tool that sent the message — a wiring problem, and therefore Dana’s in module 10. Scope creep is the commonest privacy failure in marketing because it never feels like a decision. It feels like using what you already have.

The claims register — the thing that outlasts the campaign

Her most valuable contribution is not a veto. It is a table.

The register lists every claim Cadence may make about Supply Signal: the exact approved wording, the evidence behind it, its owner, and an expiry date. The Calder sentence is in it word for word, and so is “monitors 1.4m suppliers”, and so is the limitation that there is no native SAP connector at launch.

This converts Miriam from a bottleneck into infrastructure, and the mechanism is simple: a pre-approved sentence needs no review. Naomi’s team can write forty ads without asking her anything, provided every factual assertion comes from the register. Review effort stops scaling with volume of output and starts scaling with genuinely new claims — a far smaller and slower-growing number, and the only structural answer to agent-scale production short of hiring more reviewers.

She insists it be built now rather than after launch. Built now it governs what gets written; built afterwards it is archaeology, a description of what shipped assembled from what shipped, documenting the risk instead of preventing it — and its saving applies only to assets not yet drafted, of which there are none once the campaign is live.

The expiry dates make it a living document, deliberately. “No native SAP connector” stops being true next quarter, and a limitation that outlives its truth costs Cadence deals; the Calder statistic expires the moment twenty customers give it a real number to replace. A claim with no expiry date is a claim nobody rechecks.

Where this goes wrong

Not in the claims that get blocked. In the reviewer who blocks everything and is quietly cut out.

Legal review is not there to make marketing timid, and Miriam says so out loud in the week-ten meeting. A campaign that asserts nothing sells nothing, and a reviewer who treats every bold sentence as a risk is not reducing exposure — they are training the organisation to route around them. It takes about a quarter, and nobody rebels; the borderline items simply stop arriving. Then something genuinely dangerous ships, and it ships unseen.

So she separates claims that are wrong from claims that are merely bold. “The smartest way to see supplier trouble coming” is puffery and needs no evidence; “catches disruptions three weeks early” is a performance claim and needs a sample. And her refusals are never “this is risky”, which is unactionable and reads as obstruction. They take the form: this sentence asserts X, the evidence supports Y, here is a sentence that says Y. Rewriting rather than rejecting is what keeps the queue coming.

The bottom line

Substantiation means holding adequate evidence when the claim is made, judged by what a reasonable person would need — and n = 9 at one design partner cannot support a general performance claim, which no amount of “up to” or footnoting will fix. Agent-drafted copy cannot be asked where a number came from, so provenance must be attached at the start. Miriam’s real output is not a veto but a claims register: approved wording, evidence and expiry date, so a pre-approved sentence never needs reviewing twice.

Designing this desk’s agent: the review triage agent

An agent that sorts the queue and is forbidden from approving anything in it.

Miriam’s problem is arithmetic: three times the material, the same reviewer. The agent that helps is not one that reviews — it is one that separates the material that needs her from the material that does not.

What this agent actually is

State it needs
The claims register with exact approved wording and expiry dates, and the review status of every asset.
Inputs
The claims register, asset claim manifests, and Anika’s evidence warehouse.
Core behaviours
Match sentences against approved wording, classify into pre-approved, needs review or blocked, and route with a reason.
Constraints — what it may not do alone
It may not approve, may not interpret regulation, may not resolve ambiguity, and may not mark anything pre-approved on a near match — only on exact approved wording still inside its expiry date.

One concrete design choice. Deliberately asymmetric thresholds. The agent must be extremely reluctant to say pre-approved and generously willing to say needs review, because the two errors cost wildly different amounts: a false review request costs Miriam four minutes, and a false approval costs a regulator’s letter.

{
  "asset_id": "lp-mid-market-01",
  "verdict": "needs_review",
  "matched_claims": ["clm-nine-signals"],
  "unmatched_sentences": ["catches disruptions three weeks early"],
  "reason": "claim_not_in_register",
  "reviewer": "miriam.adeyemi",
  "decided_at": "2026-06-30T11:04:00Z"
}

The metric to track. Precision on the pre-approved verdict, which must be effectively 100%. Recall is allowed to be poor. This is the most important asymmetry in the course: for most agents you balance the two errors, and for this one you deliberately refuse to.

Failure modes and moral hazards

Near-match approval: “up to three weeks” treated as equivalent to the approved wording, which is precisely the substitution that makes an unsupported claim. Expiry blindness: a claim approved in March, supported by a pilot that has since been superseded, still matching cleanly in July. Deadline rubber-stamping: the queue becomes so long before launch that pre-approved stops being read at all — the moral hazard of any triage system under time pressure.

Human responsibility statement

Miriam owns publication. The agent can prove that a sentence matches approved wording; only a person can decide whether a sentence the company has never said before may be said now. If something indefensible reaches a customer, it reached them past her name.

What Miriam hands on

Approval with conditions attached — and a document the whole team now works from.

Dana Whitlock in module 10 receives publication approval that is explicitly conditional. The substituted Calder wording replaces the general claim everywhere it appears, including inside email sequences already loaded, and the factory imagery is withdrawn. Consent scope, unsubscribe propagation across every system rather than just the sending tool, and the approved-tooling rule become things Dana has to build, not policies anyone can agree to. Naomi receives the same conditions against her copy.

The whole team receives the claims register, with one warning. It has expiry dates in it, which means it is not a document that gets filed. Somebody must own it after launch — because the day a claim expires unnoticed is the day the campaign starts asserting something that used to be true.

Would you publish it?

Read each one and decide, then tap a card to check.

Quick check

1. Why can't 7 of 9 disruptions at Calder Thermal support "catches disruptions three weeks early"?

2. What makes agent-drafted copy harder to review than human-drafted copy?

3. Why does a claims register turn Miriam from a bottleneck into infrastructure?