Level 3 built a production system for a workflow. Level 4 is about the agency that owns twenty of them, across a portfolio of clients whose categories carry different rules, using vendors whose terms change without notice, holding client data it did not create, and answering to principals who are accountable for all of it.

The material is written for the person who signs. Six things sit on that desk. Governance and accountability: who decides what AI may be used for, who owns each decision, what the risk appetite is, and how an exception is granted and recorded. Client disclosure and contracts: what a client is told about AI use in a pitch, a scope, and a master services agreement, and what the ownership, warranty, indemnity, and audit clauses should say when deliverables are AI-assisted. Vendor assessment: how to evaluate an AI tool before it touches client material, including retention, training, subprocessors, location, security posture, and the exit. Security and client data: the controls an agency owes clients whose customer lists, brand secrets and unreleased campaigns it holds. Regulatory and intellectual-property risk: mapping exposure by client category, understanding what the United States Copyright Office has said about AI-generated material, and knowing which state privacy obligations an agency inherits as a service provider or processor. Independent verification and leadership: how results claims are checked by someone who did not produce them, how an internal audit builds an evidence file, and how a principal leads a change that adds review work to people who are already busy.

Every lesson is written for portfolio-level decisions rather than deliverable-level ones. The scenarios are the ones that arrive without warning: a client demanding a tactic the agency refuses, a vendor changing its retention terms mid-contract, a subprocessor added in a country a client's contract does not permit, a competitor accusing a client of copying a generated image, an acquisition due-diligence questionnaire asking what AI touched which accounts.

The level ends with a governance capstone: build the agency's AI governance package — policy, decision rights, use register, disclosure language, contract clauses, vendor assessment, security controls, risk map, verification and audit plan, and an implementation plan — for a fictional agency, and defend the hardest decisions in a memo to the principal.

This is an independent educational course offered by AI Coalition Network. It does not replace legal, privacy, security, or advertising-compliance advice, and it confers no platform certification or regulatory approval.