This Influencer Draws No Salary. She Doesn't Sleep, Either. Then Legal Said: Wait.
A learn article recounting an undisclosed, unapproved AI influencer launched by a marketing team, tallying five legal bills (trust, content, images, data, ad law), then covering compliant disclosure, agentic AI risks, and EU AI Act preparation.
A few days ago, I heard about a case that got more interesting the more I thought about it.
A company's marketing team bounced up to legal, all excited: do us a favor, draft a privacy policy for our new social media account.
A perfectly ordinary request. Legal opened the account and took a look.
And froze.
The account belonged to a young woman named Lucy. Posting outfits, posting her everyday life, chatting away in the comments. Whatever fans asked, she answered. At two in the morning, she was still answering.
But she isn't human.
It was a fully automated AI influencer system. The photos were scraped from the web. Even the name Lucy was copied — lifted from the real name of a human influencer in the same niche. Posting, replying to comments: all automated.
The marketing team was quite proud of itself. Just think about the math: no salary, no vacation days, no mood swings, online 24 hours a day, and you can dial the posting frequency as high as you like.
Legal asked just one question: did this project go through approval?
The marketing team looked blank. Approval? What approval?
The Problem Isn't the Technology. It's That Nobody Knew the Rules
First, let's get the concept straight.
What is an AI influencer? It's an AI-generated virtual persona that plays a real person on social media, builds a following, and speaks for brands.
In itself, this isn't illegal — it's even an industry that's still growing up. Brands around the world are already using virtual humans for endorsements and product seeding.
So where did this company go wrong?
Three words: they didn't know.
The marketing team didn't know that launching something like this at their company required approval. No one had ever been trained. No policy told them where the lines were.
The technology took one day to stand up. The governance hasn't had a single one.
What goes wrong is never the tool. It's that nobody knew the rules.
Let's Run the Numbers, Bill by Bill
You might say, it's just an account. Is it really that serious?
It is. Let's run the numbers.
First bill: trust. Nothing on the account says she's AI, so users think they're chatting with a real person. The day the truth comes out, the fans' first reaction will very likely be: I've been played.
Second bill: content. She answers comments automatically, and whatever she says is decided by the model. If she's right, fine. But if she's wrong? She talks nonsense at your consumers — who takes responsibility for that?
Third bill: images. The photos were scraped from the web. Every single one is an intellectual-property landmine.
Fourth bill: data. Scraping images, moving content around, processing the personal data inside user comments — every step can land you in a data-protection trap.
And then there's the fifth bill: advertising law. Putting a "fake person" out front to endorse products without any disclosure — how does that score under advertising and marketing law?
Once you've tallied all the bills, do you still think this is just an account?

But AI Influencers Have No Original Sin
That said, I'm not for writing AI influencers off entirely.
Done right, this business can absolutely be run the compliant way.
Disclose: tell users plainly that she's AI. Change the name — don't ride on a real person. After launch, keep watching what she says. And one more thing, upstream: this kind of project must never again bypass approval.
Notice what these moves have in common: they all let the users "know."
Transparency is the only foundation an AI influencer can stand on.
And disclosure isn't slapping an "AI-generated" label on and calling it done. What data was used, what guardrails are in place — spell it out. People are already wary of AI as it is; the more fully you explain, the more willing they are to trust you.
Think about it. You follow a creator, and half the time you can't tell which lines were said by a human and which were generated by a machine — would you still trust his recommendations?
Flip it around: fans know perfectly well that she's a virtual persona, love the persona and the content, and follow her anyway. The trust at that point is the real thing.
Users can accept an honest robot. They will not forgive a "human" who lies.
The Bigger Headache: Agentic AI
If the AI influencer is only "playing a person," the next thing plays a person and then goes off to do the work on its own.
Agentic AI. Give it a goal, and it breaks down the tasks, executes them, and chains them together on its own.
Humans have moved one more step away from "seeing what happens."
Here's an analogy. Back in school, why did the teacher insist you show your work?
Because an all-correct answer might still be a guess. Nine out of ten right makes a lovely report card. But what the teacher really worried about was the one you got wrong: without the process, they couldn't tell whether you truly understood — or just got lucky.
Agentic AI is homework with no work shown. Three or five agents strung together, running on their own. Three in the morning, the office empty, they're still running.
The results look fine. The process, nobody can see.
So for companies building tools, the responsibility just got one layer heavier. Customers take your tool and run their business with it, and they have to rely on the guardrails you built in to satisfy their own compliance requirements. Transparency and switchable protections can't wait for customers to come asking — they have to grow into the product.
Don't Push All the Governance onto Legal
There's a detail in this case that deserves its own mention.
A company decides to get serious about AI governance. What's the first reflex? Call legal.
Legal matters, of course. Rely on legal alone, and things will go wrong.
This isn't a new problem, either. Veterans of data governance all understand: if a project has only lawyers in the room from start to finish, who looks after data quality? Who calculates how retrievable the data is, what storage will cost?
Governance has to grow where the work happens. Inside the engineering team writing the code, inside the daily workflow of that marketing colleague who wants to build an AI influencer. So that without waiting for legal to speak up, he already knows on his own: this needs to be flagged first.
Rules pinned to a wall are useless. They have to live in people's hands.
TripAdvisor has shared an internal lesson that points the same way: every department ran its own experiments, piled up a heap of overlapping tools, ran identical processes — and what got burned wasn't just money, but time. So enterprise AI has two ends: governance on one, focus on the other. Trying everything amounts to trying nothing.
And the EU AI Act, Still Rolling Out?
A European company once asked: the regulation is still in its adjustment period — what do we do? Wait for the final text before making a move?
The advice they got was very practical: prepare against the current version, and keep some flexibility.
Because most of the planned revisions only tweak the timelines and the wording; the direction hasn't changed. Standing still is the biggest risk of all.
Finally
Back to Lucy.
What happened to her afterward, I don't know. But if that company patches the rules and does disclosure properly, there's no reason she couldn't come back and stay in business. The virtual-influencer business has no original sin. The original sin is doing it quietly.
Technology turned "building a person" into a few days' work. Getting a person trusted, though, has always been slow, patient work.
AI can generate an influencer overnight. Trust has to be earned comment by comment.

May the colleague sitting next to you be one who knows the rules.