INSIGHTS

How should an agency review AI work before clients see it?

Use a three-level release gate to match human review to the consequence of getting the work wrong.

CM

By Catarina Mestre

·

29 September 2026

·

7 min read

Listen to this articleAI-generated voice
Two printed layouts for A Brighter Way Forward on a studio desk, one being marked up with an orange pen

An agency should review AI-assisted work according to the consequence of getting it wrong. Low-stakes internal drafts need a quick check. Client advice, public claims and work using personal data need evidence, a qualified reviewer and a clear release decision.

The useful control is a release gate. It states what must be true, who checks it and what stops the work from leaving the agency.

Why does polished AI work still need checking?

Polished language can hide a weak brief, an invented source or a confident mistake. Fluency tells you how the answer sounds. It does not prove that the answer is correct.

Workday's January 2026 research surveyed 3,200 active AI users at organisations with at least US$100 million in annual revenue. Nearly 40% of reported time savings were lost to rework. Daily users also reviewed AI work at least as carefully as human work in 77% of cases.

Those figures describe larger organisations across several regions. They are not a forecast for a 12-person agency. They do show why drafting speed and completed-job speed are different measures.

Forrester and the 4As reported in June 2026 that US agencies had three recurring concerns. Accuracy and bias were cited by 63%, legal concerns by 62%, and privacy or security by 55%.

One final proofread cannot test all three. The reviewer needs the brief, the original evidence and permission to stop the release.

This is also where the five agency workflow assessments end. Each workflow breaks differently, so review must follow the consequence rather than the tool.

How much review does AI-assisted work need?

Review depth should rise with the consequence of a mistake. A private planning note and a client recommendation should not pass through the same gate.

The UK Government's AI Knowledge Hub uses the same principle. Low-stakes work may need a sense-check. Important or public-facing work may need source, number and specialist checks.

That guidance is written for government work. The principle travels: decide the consequence first, then choose the reviewer and evidence.

Guidance and source pages were checked on 29 September 2026.

Match review depth to the consequence

Start with the consequence of an error, not the tool used to make the draft.

LevelTypical agency workReviewerRelease rule
LowInternal notes, early ideas, rough structureThe person doing the workSense-check the brief and remove unsupported claims
MediumClient emails, report summaries, proposals, public copyA second person who knows the workCheck the brief, sources, numbers, data, permissions and brand
HighLegal, financial or people advice; sensitive data; major public claimsA qualified specialist and one accountable ownerDo not release without recorded evidence and named approval
Viravesso editorial decision aid, 29 September 2026.

A low-level check is not permission to be careless. It means the likely harm is limited, the work stays internal and another decision still sits before release.

Move work up a level when it includes personal data, financial figures, contractual promises or claims that could damage the client. Use the higher level when two categories conflict.

What should the release gate check?

A useful release gate checks seven things. Each check needs evidence, not a tick added from memory.

  • Brief: Does the work answer the agreed job for the right audience and format?

  • Evidence: Can every material claim be traced to an opened primary source?

  • Numbers: Has someone recalculated dates, totals, percentages and comparisons from the original data?

  • Data: Was the input allowed in the tool, and does the output expose personal or confidential information?

  • Rights: Can the agency use every image, quote, dataset and other asset in this context?

  • Brand: Does the work sound specific to the client rather than plausible for anyone?

  • Owner: Has one named person accepted responsibility for sending or publishing it?

The Information Commissioner's Office guidance on AI accuracy makes purpose central when personal data is involved. Accuracy requirements change with the use and likely effect of the output.

That does not make the table below a legal checklist. It means personal data needs an explicit check by someone who understands the agency's obligations.

Use Viravesso's responsible AI commitments as a starting point for the team rule. Add the client's contract, approved tools and data policy before using it on live work.

The client-release gate

Copy this into the workflow. Replace the evidence column with the agency's actual source or record.

CheckQuestionEvidence required
BriefDoes this complete the agreed job?Approved brief and acceptance criteria
EvidenceCan each material claim be traced?Opened primary source beside the claim
NumbersWere figures recalculated outside the prose?Original export, formula or calculation
DataWas every input allowed in this tool?Approved tool and data-handling record
RightsCan every asset be used this way?Licence, permission or usage record
BrandIs the judgement specific to this client?Named human review against the brief
OwnerWho signs and answers for the work?One recorded approver
Viravesso practical release gate, 29 September 2026.

Stop the release when a material source is missing, the original figures are unavailable or the tool was not approved for the data. Stop when the required reviewer is not qualified to judge the claim.

Unclear ownership is also a stop. A team cannot hand responsibility to a tool because the tool produced the first draft.

Who should own the final decision?

One person should own the release decision. Their name belongs on the job, not inside a vague note that says the team reviewed it.

For medium-consequence work, choose someone who understands the brief and did not rely on the same assumptions as the drafter. This can be an account lead, strategist, editor or analyst.

High-consequence work needs the relevant specialist. A senior copywriter cannot validate legal advice through seniority alone. The same applies to financial, employment and safety claims.

The owner may use AI to find gaps or test clarity. The owner still checks the evidence independently and makes the decision.

How would an agency review an AI-assisted client report?

Start with the release unit. In this hypothetical example, it is one monthly report with campaign results, an interpretation and three recommendations.

The analyst exports the source data and records the reporting period. AI helps draft the summary from approved inputs. The analyst recalculates every figure from the export rather than from the generated prose.

Next, the account lead checks the report against the agreed questions and client context. They remove claims that the data cannot support and check that recommendations follow from the evidence.

A senior owner reviews any commercially sensitive recommendation. They confirm the correct file, links and permissions, then record the release decision.

The report does not pass because five people opened it. It passes because each important question has evidence and one person owns the answer.

How do you stop review becoming repeated rework?

Record the failure, not just the correction. Use a small error log with the deliverable, failed check, cause, fix and workflow change.

After three similar failures, change the prompt, source pack, template or approval order. Do not add another reviewer without knowing what that person must catch.

This is how review improves the workflow rather than sitting after it. The small-team adoption sequence starts with one workflow for the same reason.

Measure completed work, including review and corrections. Workday's large-company result is a warning about hidden rework, not a percentage to copy into the agency's forecast.

What to do next

Choose one client deliverable due this week. Put it at the correct level, copy the release gate and name the owner before AI touches the work.

Run the gate once, then record what failed. If the same problem returns, change the workflow rather than hoping for a better first draft.

ViraOps's Monthly Workflow Playbooks lay out agency jobs in stages, with a tool, prompt and expected output. Add the release gate to the stage where the work becomes fit for a client.

Use ViraOps's Monthly Workflow Playbooks to give each stage a named owner, prompt, expected output and release check.

PUT IT INTO PRACTICE

ViraOps turns this into weekly steps for your whole team.

Questions

Every AI-assisted client deliverable needs a named human owner, but review depth should match the consequence of an error. A routine email may need a brief check against the source and brief. A report with personal data, financial figures or public claims needs stronger evidence and a suitably qualified reviewer.

A specialist should review AI-assisted work when a claim needs expertise the drafter or account lead does not have. This includes legal, financial, employment and safety advice. The specialist checks the relevant claim and evidence. One accountable owner still decides whether the complete deliverable is ready to release.

An AI detector does not prove that work is accurate, permitted or fit for the client's brief. It estimates whether a pattern resembles generated text. The release gate checks the things that matter: evidence, numbers, data, rights, brand and ownership. Use detection only when a contract or policy requires it.

Record the deliverable, its review level, the evidence checked, the named approver and any failure that changed the work. Keep a small error log with the cause and workflow fix. That record helps the team improve prompts, source packs and approval order instead of correcting the same problem every month.

SOURCES