Shadow AI is already costing agencies real money and real clients - and most leadership teams don’t know it’s happening under their noses. In episode 6, Gareth puts AI governance specialist Callum in the hot seat to unpack why free and personal AI plans are an agency’s biggest hidden liability, the real story of a marketing agency hit with a massive insurance claim after a data leak, and why “all or nothing” AI connectors can expose everything from client contracts to confidential leadership conversations. It’s a practical, occasionally uncomfortable guide to building the governance foundations that let agencies actually use AI without putting the business - or their jobs - on the line.
In this episode
What AI governance actually means. Callum frames it simply: using AI to benefit the agency while mitigating risk — ideally getting it down to no risk at all, so adoption feels safe rather than reckless.
Shadow AI is still the biggest problem. Callum still sees agency staff using free or personal AI plans for company work without leadership’s knowledge. Free plans in particular can use chat data to train models, and without UK GDPR agreements in place, providers can theoretically do what they like with it. The fix is blunt: abolish free and personal plans for business use entirely, move everyone onto paid team/enterprise plans, and reflect the tool and its data obligations in client MSAs.
The horror story. An agency lost a marketing client’s sensitive campaign data after an employee uploaded it into a free AI plan - the data surfaced elsewhere, the client traced the breach back to the agency, and the agency was hit with a massive insurance claim. A personal plan is never a legal “get out” for the business; the client comes to the agency’s door regardless of who used what.
Architecture isn’t enough - you need compliance too. Callum audited a 60-person agency with genuinely excellent AI governance: enterprise Gemini, model training off, updated contracts, a formal tool-approval process. Yet analytics showed two-thirds of the team weren’t using the sanctioned platform at all - still on personal ChatGPT. The lesson: policy without education and enforcement doesn’t change behaviour. Callum’s view is that breaching a “no personal plans” policy should be treated as a fireable offence, given how severe the fallout can be if data leaks.
Give people the “why”, don’t just give them rules. The whippet analogy: you can train a dog to follow a command without it understanding why, but people can understand the reasoning — and will comply far more reliably if they grasp the scale of what’s at stake, rather than experiencing it as leadership being controlling.
Connectors are all-or-nothing - scope them properly. Turning on a connector (Office 365, Google Workspace, etc.) grants the AI everything that the connecting login can see. If that’s the founder’s login, the AI can see financial data, HR records, even confidential leadership meeting transcripts. The fix: work with the agency’s IT provider to create a dedicated, scoped login for the AI tool, starting with access to nothing and adding data in only as it’s needed — bottom-up, not top-down.
Client data needs explicit permission. Don’t connect AI to client data unless the client has confirmed they’re comfortable with third-party AI processing, regardless of what UK GDPR compliance the AI plan itself offers.
Client conflicts of interest are a real, distinct risk. Unlike a human team member, AI won’t discriminate between competing clients’ data if it has access to both — so access needs to be separated by client team, not just by role.
A real cautionary tale. An agency on a free Gemini plan hadn’t locked down its Google Workspace. An employee facing an internal grievance searched their own name and surfaced unfavourable meeting transcripts about themselves - which they then used against the company. A direct consequence of an ungoverned connector plus a free plan retaining data it shouldn’t have.
Exports are the blind spot no connector scope can fix. Even with a perfectly scoped connector, anyone can manually export a file and drag it into an AI chat, bypassing every access control in place. The only real defence is policy and communication - “if it’s not already in your AI environment, don’t drag it in” - backed longer-term by IT-side file classification.
For highly regulated clients, start internal-only. With a health comms client holding regulated patient data, Callum’s approach was to leave client-data connectors off entirely and instead build safe, high-value automations on strictly internal data - timesheet processing was the live example, scoped so the AI could only ever see one folder.
Plugins as governance and future-proofing. Packaging an agency’s context and workflows into a version-controlled “plugin” (Callum hosts his on GitHub) creates a single source of truth, stops workflow version-sprawl, and - critically - keeps the agency’s real asset (its context and data) portable if an AI vendor changes terms or hikes prices. The goal is to stay tool-agnostic: the AI is just the processor, the context is the value.
Governance comes first, always. In every roadmap Callum builds, governance is month one - sometimes week one - before any efficiency or ROI work. The analogy: build the house on solid foundations, not sand. Skip it, and agencies risk discovering months into a build that a client never actually consented to AI use on their data, burning significant time and money.
The unexpected upside. Beyond AI safety, the governance process forces agencies - often unstructured, fast-moving businesses with little formal process - to build real structure and documented ways of working, benefiting the whole business, not just AI adoption.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thestandoutagencypodcast.substack.com