AI-generated image of a motion-blurred crowd in blue, green and red light, with one person in sharp focus at the centre
Insights

When an ad goes ‘rogue’

This year’s headlines are about AI agents breaking out of their sandboxes. Malcolm Ché, Head of Innovation at Identity, argues the bigger risk for brands is closer to home: ad platforms that change approved creative to suit the algorithm, without asking first.

In July, OpenAI said its AI models had broken out of a sandboxed test, reached the internet and got into Hugging Face’s systems. It made headlines everywhere. It is the story people expect: the machine breaks free.

That story misses the bigger risk for most marketers. Few will ever run a frontier model in a sandbox. Nearly all of them run ads on platforms with tools built to change those ads. Nothing has to ‘break free’ for a brand to lose control of its message. The tool only has to do its job, by rules the brand didn’t write.

Approval used to be the end of the process

For most of advertising’s history, sign-off was final. A client approved the copy and the image, and that is what ran.

That has changed. For rapid-iteration campaigns, automated changes are a good way to test and amplify. Recently, we saw the downside. A campaign for a public-sector client had been signed off by both teams. One ad in the set went live with an image nobody had approved for it. The sign-up link pointed to an upcoming date. The image promoted an earlier one.

A small edit by the platform later switched it back on. Like with many new feature roll-outs, the benefits to the platform get switched back on by design, which their corporate jargon refers to as “sticky defaults”. We traced the error to its source and fixed it within hours.

Our intervention meant sign-ups stayed in line with expectations. How it happened is the more useful lesson.

Relevant to an audience, or an algorithm?

The problem is in the word “relevant”. To the platform, a relevant image is one its model predicts will earn engagement on its own platforms. Whether the image matches the brief doesn’t come into it. Nor does anything the platform can’t see, such as a regulated message, a sensitive audience or a date that has passed.

Other advertisers report the same problem. One clothing brand that targets men aged 30 to 45 found its best-performing ad replaced by an AI-generated image of a smiling grandmother in an armchair. In a July investigation by Business Insider, eight advertisers and agency leaders said fixing the platform’s AI mistakes was now part of their normal week. One agency sets aside several mornings a week to check that settings it turned off are still off.

If you have to check every week that a setting is still off, you haven’t really opted out. The platform decides what is opt-in and what is opt-out, and any update can change it.

Calling this “rogue AI” is wrong. Rogue means the system broke its rules. Here it followed the platform’s rules, which weren’t the brand’s.

Why trust doesn’t hold

Automation is tempting for good reasons. It promises faster testing at lower cost. Automated A/B testing is useful when a person designs the test and owns the result. The risk starts when the platform runs the test and marks its own homework.

Handing over that control is an act of trust. Trust works between people because both sides understand the wider context and share the consequences. A platform’s agent has neither. It knows the metric it was given and the data it can see. It has no view of the client’s reputation or the rules a regulated message has to follow.

So it does what optimisers do and keeps going. If another image might earn more engagement, it swaps it in. If a setting is in the way, an update can switch it back on. At no point does it decide the work is finished, and it has no taste beyond the number it is chasing.

Knowing when to stop

Dieter Rams’ work as head of design at Braun, from 1961 to 1995, set the standard for modern product design, Apple’s included. The last of his ten principles is that good design is as little design as possible. His shorthand was “less, but better”: focus on what matters and remove the rest. The hard part is judgement. Someone has to decide what to remove, and when the work is done.

That judgement is what professionals are trained for. A good creative team knows when one more change would weaken the work. An agent cannot know any context wider than the one it is optimising for, so it has no way to tell when the brief has been met.

This is the Agency’s job: we decide how, when and how much to use any tool, automation included. We have agency. Before asking how to win with a brief, we ask whether it is the right brief. Efficiency is a fair reason to automate parts of the work. Judgement about the message has to stay with people who understand what is at stake.

Real intelligence includes knowing when to stop. Today’s ad platforms are not built to do that, so the people using them have to.

Sources

RECENT INSIGHTS
man engaging with tech

Experience
Changes
Thinking

Looking for a new perspective?
We want to hear what matters most to you.