FDE PulseFDE jobs open 448New in 7 days 29Companies hiring 52Remote-friendly 25%Median US pay $216kTop hirer Databricks 125
VI

The newspaper of the Forward Deployed Engineer

Analysis

AI images for business: the hard part is the approval workflow, not the prompt

A Coca-Cola AI ad earned a top test score, and the public still turned against it. The final approval gate has to be a person with real decision rights, not a number.

AI images for business: the hard part is the approval workflow, not the prompt
Photo: Headway / Unsplash

In brief

  • Publicis Sapient calls AI-driven brand governance a human operating model. The hard part is decision rights and process, not prompts.
  • According to Virtuall, a common mistake is bolting governance on after images are generated, which turns legal review into a bottleneck at the end.
  • High test scores do not stand in for market reaction, and EU disclosure rules make labelling a mandatory step.
ShareLinkedInFacebookX
Linear diagram of five stations in order: legal constraints in the brief, image generation, machine scoring against brand rules, sign-off by a person with authority for each channel (highlighted in orange as the final gate), and export with C2PA.
Legal sets the constraints at the brief. Machines filter out measurable flaws first, while the decision to publish on each channel rests with a person who has been given the authority. Source: Publicis Sapient, Virtuall, EU AI Act (Article 50), C2PA.

In 2024, Coca-Cola’s AI-made Christmas advert scored 5.9, the maximum, on System1’s scale in both the US and the UK. Public sentiment then turned negative. The test said “pass”; the market did not.

That detail shows where many teams building AI images for businesses put their effort in the wrong place. They refine prompts, compare models and tune parameters. Whether an image gets published, where it gets published and who is accountable for it are decided somewhere else: in the approval workflow.

If you want to work as an FDE, this is territory you will hit as soon as your client is a brand, an agency or a retailer. They are not short of image-generation tools. What they lack is a pipeline that marketing, legal and the brand owners can all trust.

If the prompt is the easy part, where is the hard part?

Publicis Sapient answers this fairly directly. Writing about AI-driven brand governance, the firm argues that it is “a human operating model”, not simply a layer of technology.

That model needs structured rules, clear decision rights between teams, connected workflows and teams that actively coordinate with one another.

Read the list closely and none of it is about image quality. Every item is an organisational question. Have the brand rules been written down in a machine-readable form, or are they still a PDF guideline that everyone interprets differently? When the creative team and the brand owners disagree, who has the final say?

These are the questions a pure product engineer tends to skip, and an FDE cannot. You can build an attractive image-generation demo quite quickly. Building a system that legal will sign off on is a different matter, because the hardest part is making clear who approves what.

Virtuall, a creative tooling vendor, describes what it considers a common failure: legal and compliance become a bottleneck at the final stage. According to Virtuall, the cause is that governance is “bolted on” after the images have been generated. The fix is to move constraints to the start of the process.

Picture a Vietnamese cosmetics brand preparing a campaign for Europe. The creative team generates 40 images, shortlists 15, colour-corrects them and lays them out. When they reach legal, half the images feature models who look like real people, and nobody has recorded which images must be disclosed as AI-generated. The whole batch goes back to the starting line.

If the constraint sits in the brief, for example “EU channel: no faces resembling real people, or a label is required”, the first 40 images are generated within those limits. Legal still reviews, but it reviews material that has already been filtered, rather than cleaning up things nobody thought about.

Machines score first, people review second

Publicis Sapient describes a system that scores generated images against brand rules before they move to review. Its argument is that human review becomes “more focused, not more frequent”.

This is the view of an agency selling a solution, so treat it as a hypothesis to test at the client, not a measured result.

Even so, the logic behind it is sound. Errors such as wrong colour codes, logos outside the safe zone or text spilling out of the frame are things machines check better than people. Once the machine has filtered those out, the reviewer is left with the questions only a person can answer: does this image fit the spirit of the brand, and could it offend anyone?

Virtuall adds two more specific requirements. Metadata and audit logs should be the default, not an option. Approval status should also be split by channel: an image may be approved for domestic social media but not yet for a billboard or for the EU market.

Technically, that is the difference between an approved: true column and a relational table linking image, channel, reviewer and approval time. The first is easy to build, but when something goes wrong you cannot answer the question “who allowed this image to be published here?”

A high test score is not market approval

Back to Coca-Cola. The company has kept pursuing AI despite the public reaction, and in defending that direction it has pointed to pre-release testing, calling one of its adverts among the best-tested in its history.

For the 2024 advert, two things are true at once. It really did achieve the maximum test score. But the public reaction after release was still negative, which means the pre-release number did not predict how the market would receive it.

The lesson for system builders is not to let automated scores or test scores become the final approval gate.

There needs to be a step where a person, specifically a decision-maker named in advance, weighs reputational risk.

That step cannot be automated, but it can be recorded in the log like every other step.

AI disclosure: from “should do” to mandatory step

For businesses selling into the EU, Article 50 of the EU AI Act removes the choice. Deployers who use AI to create deepfakes must disclose that the content has been generated or manipulated by AI. The disclosure must be clear, distinguishable and meet accessibility requirements.

For the pipeline, this means “does this need disclosure?” must be a metadata field, decided at the approval step for the EU channel, not something left to the designer’s memory. The wording and placement of the label also need approving as part of the image, because the law requires the label to be clear and accessible.

Many teams look to C2PA, or Content Credentials, as the technical answer to content provenance. It is worth integrating, but C2PA’s own explainer acknowledges that it is not a silver bullet and is intended only to mitigate risk. Attaching a credential to a file does not replace a disclosure label the viewer can actually see.

What each control layer catches and what it misses

Set the control layers side by side and it is clear that no single layer is enough. The value lies in putting the right layer in the right place in the pipeline.

Control layer Where it belongs Catches Misses
Legal and compliance constraints In the brief, before generation Images wrong from the outset, late revision rounds New risks that arise when the channel changes
Scoring against brand rules After generation, before the reviewer Measurable colour, logo and layout errors Brand spirit, emotion
Reviewer with clear decision rights After machine scoring, per channel Reputational risk, cultural context Subjective errors; no way to trace who approved without a log
Pre-release ad testing Before the campaign runs The ad’s own score Real public reaction after release
Article 50 disclosure label Approval step for the EU channel Disclosure obligation to viewers Cannot prove a file’s provenance
Content Credentials (C2PA) At file export Provenance trail attached to the content Not a silver bullet

The fourth row is the one worth taking to your first working session with a client. If their marketing team treats testing as the final gate, the Coca-Cola example is a natural way to open a discussion about decision rights.

Where developers can start

The good news is that most of the skills here are familiar backend skills: schema design, a state machine for approval status, audit logging, role-based permissions. What is new is the context. You need to understand why an image can be “approved” on one channel and “not approved” on another, and why the “AI disclosure required” field must be mandatory.

When reading FDE job descriptions at creative-tooling companies or agencies, look for phrases such as brand governance, approval workflow, content provenance or compliance. They signal a role weighted towards process rather than models.

On your CV, do not write “integrated an image-generation API”. Write “designed a multi-channel approval flow with audit logging, reducing revision rounds at the legal stage”, with numbers if you have measured them.

If you do not yet have a real project, build a small one yourself so you have something for your CV. A repo containing a state machine with draft, scored and approved-per-channel states, an audit log table recording who approved what and when, and a mandatory “AI disclosure required” field for the EU channel is enough to tell a complete story.

The README should explain why you put constraints in the brief rather than at the end, because that is the part that shows FDE thinking.

For interviews, prepare a story in three beats: which rules you turned into something a machine can score, which decisions you deliberately left to people, and how the log helps answer the question “who allowed this?”

If you are working for a client with a marketing team, the first thing to do is not to propose a new model. Spend a session with the legal team and ask why they usually reject images. That list of reasons is the first draft of the rule set the machine will score against.

Image-generation models will keep changing. What clients need over the long term is someone who knows how to put the rules in the right place, before a whole batch of images has to be redone from scratch.

Was this article useful?

Use with your AI assistantAsk Claude ↗Ask ChatGPT ↗
6 sources
Read next on the roadmap · Stage 3: Applied AIClaude Agent SDK, OpenAI Agents SDK or Google ADK: four questions to ask the client before you chooseAt first glance the three agent frameworks look much alike. A single clause on data retention, or a requirement to run on the client's own infrastructure, can still force a project team to rethink its choice.