Chapter 18
18Generative AI in the Studio: A New Asset and a New Vulnerability
“The prompt you type into a public tool may be the most valuable file you sent today.”
In just two years, generative AI has become part of every creative workflow: it writes drafts, suggests designs, generates images and voices, writes code and answers clients through automated agents. This shift changes the whole map of assets and risks; the question is no longer “do we use AI?” but “how do we govern it?”.


Text in this figure
Inputs · Prompts and files · Client data leakage · Training data rights · Model · Tool and vendor · Prompt injection · Untrusted vendor · Outputs · What the model generates · Hallucination, bias · Similar to protected works · Deployment · Reaching the audience · Deepfakes · No disclosure · Matching ISO 42001 controls: data (A.7) · life cycle (A.6) · information (A.8) · suppliers (A.10) · Figure 23
Risks Across the Workflow
- Inputs: Pasting client files, confidential code or personal data into a public tool may mean sharing them with the provider, and sometimes having them used for training.
- Model: Custom models trained on a client’s style or data are assets that can be stolen or poisoned.
- Outputs: Confidently fabricated information (hallucination), content resembling protected works, or bias that harms the brand.
- Agents: An agent with permission to send email or modify files can be tricked by prompt injection into executing an attacker’s instructions hidden in a document or web page.
Prompt Injection: The Top Vulnerability in Model Applications
Prompt injection is when an attacker places instructions inside content the model reads, and the model obeys them as if they came from the user. It might be a hidden sentence in white text in a brief sent by a “client”, or text on a web page the agent summarises. There is still no complete fix, so defence relies on layers: separating instructions from data, minimising the agent’s permissions, requiring human approval for sensitive actions, and monitoring behaviour.
An Acceptable Use Policy for AI
- Approved tools: A list of permitted tools, preferably enterprise editions that do not train on your data.
- Data classification: What may go into each tool: public is allowed; confidential client material is prohibited except in a tool approved for it.
- Human review: No generated content goes to a client or the public without review by a responsible person.
- Disclosure: When and how we tell the client that part of the work is generated.
- Reporting: A channel for reporting a harmful output or strange behaviour from a tool or agent.
From the Field
Most AI leaks in agencies did not come from an attacker, but from a diligent employee who wanted to finish the client brief faster and pasted it in full into a free personal account.
From Security to Governance
Some of these risks are security risks covered by ISO 27001: leakage, access and suppliers. Others go beyond security into questions it was not designed for: is the output fair? Does the affected person understand they are dealing with a machine? Who is responsible when the model is wrong? This is where ISO 42001 comes in, the subject of the rest of this part.
Treat the prompt as a file, the model as an asset, and the agent as a new employee with limited permissions.
Lessons Learned
- 1Generative AI adds new assets: prompts, models and agents.
- 2Prompt injection is defended with layers and minimal permissions.
- 3A clear acceptable use policy prevents most leaks.
- 4Some AI risks go beyond security into governance.
Tip: use ← → to move between sections.

