Level 3 taught you to run AI-assisted agency work as a system many people operate. Level 4 asks you to govern it across the whole agency, and to defend what you decided to a client, the FTC, a state attorney general, the NAD, a competitor's counsel, an insurer or a journalist. It is written for agency principals, managing directors and partners, heads of strategy, creative, media and PR, operations and legal-liaison leads, and the CMOs and communications directors who own AI policy for an in-house team. Much of the authority in this area is unsettled, so the level teaches a method of reasoning rather than confident answers the sources do not support.

The first four modules place accountability and map what binds the agency. Module one shows why responsibility for AI work spreads across client, account team, studio, freelancers and tools, what each FTC source says about agencies, why the agency must be honest with its own clients about its AI services, and what no tool, vendor or client indemnity can take off the agency. Module two writes a governance programme in eight parts, built on the voluntary NIST AI Risk Management Framework, with ISO/IEC 42001, PRSA guidance and the IAB disclosure framework as optional inputs and the EU AI Act where the work falls in its scope. Module three keeps the decision record: why, by whom, on what evidence and when to review, the records the law already requires, and what a future principal, client, acquirer or regulator needs after staff and clients have changed. Module four builds the regulatory map: section 5, the reviews rule and the TCPA as the federal floor, state privacy law by threshold worked through for California and Connecticut, state AI law in Colorado and Texas taught as movement, the EU AI Act as a scope question, and the client categories that redraw the map.

Modules five to seven cover what the agency buys and what it signs. Module five assesses a marketing AI supplier before it touches client work, tests its capability claims against the FTC's enforcement record, examines data handling and changing terms, and sets out the agency's own exposure when it resells or white-labels a supplier's service. Module six reads each evidence claim about AI in marketing by what was measured, on whom and whether it was corrected: personalisation after the Salvi correction, the null microtargeting result, audience experiments on AI authorship, synthetic faces and labels, and the agency's own test with a baseline and a holdout. It leaves no basis for claiming that AI makes marketing more persuasive. Module seven covers the terms needed before client material reaches an AI supplier or ad tech: data use and training, subprocessors, privacy terms, model change notice, deletion, exit and acquisition, digital replica terms for talent, and client clauses that divide work honestly.

Modules eight and nine handle security and fraud from the defender's side. Module eight places AI tools and agents inside a security programme organised by the six NIST CSF 2.0 functions, with phishing-resistant sign-in, narrow access for agents, logging, supplier oversight and incident response taught as good practice rather than law. Module nine covers impersonated brands, celebrities and executives, what the FTC impersonation rule reaches, why people and detectors miss synthetic media, why provenance cannot settle authenticity, call-back verification for payments and approvals, and the state patchwork of likeness protection.

Modules ten and eleven cover what audiences are told. Module ten separates the AI disclosures the law requires, including New York's synthetic performer duty and deception law as the backstop, from those an agency chooses to make, treats the IAB's materiality approach as a policy input rather than a safe harbour, reads the label research, and sets persuasion limits and a written disclosure position agreed with each client. Module eleven reads four state election texts one at a time, California, Michigan, Minnesota and Washington, names what was not verified, and gives no multi-state summary rule; it then covers election-ad platform terms, cheap persuasive text, synthetic front groups, and how an agency decides whether to take political or issue work.

Modules twelve to fourteen make the agency answerable and move it forward. Module twelve designs independent verification before AI-assisted work runs, explains how a challenge arrives through the NAD, NARB appeal, referral to the FTC or a Lanham Act suit, and builds the substantiation pack for AI capability claims. Module thirteen leads adoption in a creative culture whose people have good reasons to doubt it, explains why training alone does not stop automation bias, and measures adoption honestly. Module fourteen sequences the programme from the lowest-risk uses outward, labels every cost, benefit and risk figure, carries the dated milestones a roadmap cannot miss, and prepares the capstone: an AI Governance Programme, Scenario Defence and Ownership Report for a fictional agency.

Statements of authority say whom they bind and when they were checked; federal AI policy is taught as movement, proposals as proposals, and platform policies as contract terms, voluntary frameworks are never taught as law, and no framework is claimed to reduce harm. The level ships with a printable workbook and ten templates, and the examination draws forty scenario questions from a reviewed bank.

Everything here is professional education. It is not legal, privacy, advertising-compliance, election-law, security or intellectual property advice, and it does not replace counsel, a platform's own policies, or the law that applies to a campaign. Completing the level earns an independent educational certificate issued by AI Coalition Network with a public verification page. It is not a licence, a platform certification, a professional designation or a regulatory approval, and it carries no professional education hours.