Brand safety used to be a media-buying checkbox. In 2026 it’s an operating system problem — and most teams still don’t have one.
A new enterprise guide from Hootsuite lays out why: the risk surface has widened from ad adjacency into AI-generated fakes, bot-driven pile-ons and creator partnerships nobody vetted properly. The fix isn’t a tool purchase. It’s roles, workflows and escalation paths written down before anything goes wrong.
Why the floor moved
For years, teams anchored to the Brand Safety Floor produced by the Global Alliance for Responsible Media (GARM), the cross-industry initiative launched in 2019. The World Federation of Advertisers discontinued GARM on August 9, 2024 — but its Brand Safety Floor and Adjacency Standards Framework are still used as legacy reference points, with the IAB and accredited verification vendors measuring whether placements actually held the line.
Translation for growth teams: the standard you’re quoting in your media plan no longer has an owner. Your internal policy is now the real standard.
Safety vs. suitability — know which decision you’re making
The guide draws a distinction worth stealing for your next brand deck. Brand safety is the universal floor: content no advertiser wants to sit beside. Brand suitability is your call, based on your category, values and risk appetite.
A news story about a natural disaster clears the safety floor. It’s still a terrible neighbour for a travel brand running a beach campaign. Different people, different criteria, both decisions logged.
The five risks that actually cause incidents
- Ad adjacency. Programmatic accounts for over 90% of US digital display ad spend, so placement decisions happen faster than any human review. Inclusion lists beat exclusion lists; most enterprise teams run both plus keyword and category blocks, and audit placement reports monthly instead of at campaign wrap.
- Bots, trolls and coordinated behaviour. The real danger isn’t the noise — it’s overreacting to manufactured outrage or missing a genuine complaint buried under it.
- Unvetted creators. Vetting has to go past follower counts into past posts, audience authenticity, brand conflicts and how the creator handles criticism. Contracts need approval rights, disclosure terms and clean exit clauses.
- Deepfakes and misinformation. Gartner found 62% of organisations experienced a deepfake incident in the prior 12 months. Fake endorsements and cloned brand accounts spread faster than corrections.
- Trend hijacking. Trends can flip meaning within hours. Run the screenshot test before publishing.
What an internal policy has to contain
The guide breaks the policy into six components, and none of them are exotic:
Roles. Creators, editors, compliance reviewers, approvers, channel owners, escalation leads. Brand safety collapses when everyone assumes someone else checked.
Workflows and permissions. A clear Draft → Review → Approve → Publish path, tighter checks on claims, UGC and influencer content, and publish rights limited to a handful of trusted users. Review access quarterly. Kill it the day someone changes roles.
Content standards. Tone rules, examples of unsafe content, and a named list of topics and keywords that trigger extra review.
Crisis detection. Define what counts as an incident, who reviews first, who gets notified in legal and PR, what happens in the first hour, and when you pause publishing across every channel.
Access security. Role-based access, 2FA everywhere, password rotation, login alerts.
Training. Quarterly refreshers, short certifications or on-demand video — whatever survives contact with a busy team.
Then test it. Run drills on a complaint surge, an unvetted influencer post, misinformation in the comments, a publishing mistake. Review the policy every 6-12 months and after every close call.
Don’t write it like a threat
The most practical advice in the piece comes from Nick Martin, Social Media Lead at Tilpati, on how to set guardrails without scaring employees off social entirely. Fear-based rules, he argues, just make people freeze.
Instead of termination warnings, use plain expectations — Martin’s example is simply being aware not to share customer or private data in a post. He also recommends recording a new-hire session, running follow-ups through the year, and screenshotting good employee posts to give public shoutouts.
Positive reinforcement scales. Legal threats don’t.
The takeaway
If you can’t name your escalation lead, or you couldn’t produce your approval workflow in the next ten minutes, you don’t have a brand safety policy — you have a vibe. Map how content actually gets made today, including the unofficial shortcuts, and build from there.



