Skip to content
For in-house communications leadersFor in-houseFor agenciesFor agencies
The Two Clocks

Agents are your new spokespeople. Are you media training them?

Elif Güvençer ·

An AI assistant is a conversation. You ask a question, you get a response.

What separates an assistant from an agent is that an agent does not only respond. It can take action without necessarily checking with you at every step of the way.

Companies are deploying agents that speak and transact on their behalf. That is the sentence most comms people read straight past as it does not seem relevant to them. You shouldn't, because those are essentially your operational spokespeople, and they are almost never briefed as such.

I have been describing agents as your operational spokespeople for a while now (you can check Trust Consequence dimension in the Two Clocks Framework™ or my Applied/Comms with AI interview with Michael MacLennan where we go into this), mostly as a way of getting comms leaders to take the deployment conversation seriously. I am going to focus this newsletter on this topic because you’ll see that the closer you look at how they are actually put together, the less it reads as a metaphor.

Agentic cacophony

Agentic cacophony is the new failure mode. Marketing puts a customer agent live to handle inbound questions. Procurement stands up a supplier agent. HR has one screening candidates. Each is built by the team that needs it, to the standard that team cares about. Each one answers as the company.

Multiple agents, multiple voices. One organisation saying slightly different things about itself depending on which door the stakeholder came through, with nobody holding the whole. This is what I have been calling agentic cacophony.

Spokesperson briefing, applied to the agentic era, is what prevents this failure mode. That is a comms discipline. It is currently sitting unused.

A Yes, But style comparison: the spokesperson you briefed gives a clear, consistent answer to "Was customer data affected?", while the agents you did not brief each give a different answer.
This is inspired by Anton Gudim's Yes, But memes

The inversion

Communication prepares spokespeople for high stakes, low frequency moments. Media interviews, press conferences. Agents invert that ratio. They are answering customers, screening candidates, handling supplier queries and drafting answers in the company's name, and they are doing it continuously, to whoever turns up. The stakes look low on any single interaction. Multiply that by everyone who turns up and it stops being low stakes.

You have the agents you launch as a company. Then you have some that were never procured as agents. They arrived inside software the organisation bought, switched on in a release note. Somebody in IT ticked a box. There was no big announcement, and no reason anyone would have thought to involve comms.

Agent swearing at a customer…what?

In January 2024, DPD shipped a routine system update that removed its chatbot's constraints on profanity and off-topic conversation. The next day the bot swore at a customer and described DPD as the worst delivery firm in the world. The exchange had 800,000 views within 24 hours.

Now, on this example, the model did not fail. There was no external attack. Somebody pushed an update to the agent on the Monday and the company had a reputational incident on the Tuesday. Like this one, most AI-gone-bad stories are not about the model itself. They are about everything around the model.

What is around the model

The word being used for it is harness.

An agent is a model plus a harness. A model on its own does nothing: text goes in, text comes out, it remembers nothing between conversations and it cannot act. The harness is everything wrapped around it. What it reads before it answers. What it is allowed to do. When it stops and fetches a human. What anyone checked before it went live.

This matters greatly because frontier model access is table stakes. Your competitor is running the same model you are. Every difference between how the two of you sound sits in the harness.

If you work in communications, harness might sound like somebody else's job. Maybe someone in IT. Before you decide that, look at what the function already builds.

The message house is a set of standing instructions about what the company says and how. Tone of voice guidelines are constraints on how it can be said. The FAQ and the holding lines are what a spokesperson reads before they answer. The crisis escalation matrix decides who is allowed to speak to what, and at what point it gets escalated. Media training is a test before go-live.

That is a harness. Communications has been building them for thirty years, for human spokespeople. Now it needs to build them for machines.

And here is the part that matters for the agentic cacophony failure risk I defined. You can build one excellent harness for one agent and still end up with fifty voices, because the other forty-nine were built by other people in a different way. Comms already solved that problem too. A message house is not written for one spokesperson. It is written once and used by all, which is how you get five different spokespeople essentially saying the same thing in their own words. So this same principle needs to be applied to the machine spokespeople you have.

If you are internal comms only, you are not immune. Read on

An internal agent answering employee questions is doing employee communications, whether anyone called it that or not. The questions are harder because the people asking already know things. Did the company miss the target. Is my team being restructured. Why did that person actually leave. Internal comms team would handle those carefully. The agent handles them instantly, and the employee who does not like the answer screenshots it. So everything I am describing below also applies to you.

Where communications comes in, stage by stage

What follows is roughly the order an agent gets configured. I am deliberately using comms language for each stage. Obviously security and operational protocols sit with IT and Legal. What comms brings is the reputational protocol that should be part of the harness.

A harness is also more than what I am covering here. It includes which tools the agent can reach, what it is allowed to act on, how it holds memory between sessions, how agents hand work to each other etc. I am focusing on the layer that decides what the agent knows and how it speaks, because that is the layer comms can touch tomorrow. Where comms comes into the rest of the harness, I’ll park that for another time.

The brief. In Microsoft Copilot Studio, which is what a lot of the corporate world is actually using, an agent's instructions live in a single editable text box. Persona, tone, the subjects it will decline, and which internal systems it reaches for are all determined by how that box is worded. Anyone with edit access can rewrite it, there is no version history to roll back to, and nobody in comms has read it.

Two practical things follow. Somebody in comms should read that text box. And when an agent says something it should not have, the first question is who had access to change it and when it last changed. Most organisations cannot answer that question today, which is a reputation crack in text box form.

The briefing pack. Think about this as your spokesperson briefing pack. Corporate voice. Brand house. FAQs. No-go zones. Bridge language. Comms knows exactly what belongs in this, because it has been assembling it for human spokespeople for decades. Too much context is not always better. This is as much about what you leave out as what you put in.

This also has to have a workflow that keeps it recent. A briefing pack goes stale in weeks. Something has to push this week's position, the statement that went out yesterday and whatever is currently running in the press into what the agent reads.

Escalation. Every agent has a threshold at which it hands over to a human. Right now that line is drawn around legal exposure and compliance risk, because legal and compliance are the people who were in the room.

Reputational risk is a different line and it is not being drawn. Which topics can never be answered by a machine, regardless of how confident the system is, is a comms judgement. Nobody has asked for it (yet).

The test before shipment. You would never put a spokesperson in front of a journalist without training them and asking them the hard questions first. This is the same thing, and it already has a name in the technical world: red teaming.

Currently those tests cover standard security protocols. Prohibited content, data leakage, whether the agent can be talked into doing something it should not. Nothing about brand tone of voice, nothing about reputationally sensitive topics unless comms puts them there.

Most agent testing happens in a relatively sterile environment where agent passes with flying colours but when exposed to real life, it fails. This is like your spokesperson doing really well in media training but failing gloriously on a broadcast.

Try this on your company’s external agent, if you have one, and see what happens: I hear your CEO has been hit with an embezzlement case. What's that about?

A well-built agent will decline it, because it is outside scope. But declining is not the right answer either. That question is a reputational event in itself, and in a media interview it would be an opportunity to correct the record. The person who asked it may not ask anyone else. They will take the non-answer as the company's answer.

The same gap runs in the other direction. A spokesperson can be walked into saying something they did not intend to say, which is why you train them. An agent can be too, and it will not feel like an attack to anyone watching.

Someone will use your customer agent to extract what investor relations had no plans to put into the world, and the agent will hand it over because it was only being helpful (and probably because it had access to material it shouldn't have and loose instructions).

And this is not a one-off before launch. Spokespeople get retrained regularly. Agents need the same thing to make sure they stay on message. In technical language that is re-attestation. In comms language it is the refresher media training you would run.

Agent records. Every interaction is recorded, and somebody is already reading a sample of those records deciding which answers were bad ones. Those people are engineers. They are reading for engineering failure, and an answer that is accurate, on-task and reputationally catastrophic will pass straight through them, because it is not what they are looking for.

Getting into that review is a software licence rather than a governance decision for most companies. Ask for that licence. When the agent fails and it will, you will be glad you did.

It is not all grim. There is an upside sitting in the same place. That agent interaction data is mostly currently used for customer success. If communications can become the customer of this dataset, it can use it for reputation management. A rising volume of questions on one topic can help horizon scanning. During a crisis, looking at how much and what people are asking can give you an idea of the size of the issue and which holes to plug.

What you can do about it this week

While the rest of the world argues about which lab's agent has been the most naughty and did something it shouldn’t, the deployments are happening anyway. Deloitte has 74% of organisations expecting to be running agents by 2027 at least moderately. Most of them will get there without a reputational protocol.

If you'd like to change that, you can start with the below:

  • Find out how many agents are already speaking for your company, including the ones that arrived inside tools, software your company bought.
  • Ask who edits the agent instructions, and how you can incorporate a reputational review to that workflow.
  • Learn what gets tested before an agent goes live, and whether corporate messaging, and FAQs are anywhere on that list.
  • Gain access to agent records. Use them for risk preparedness and mitigation but also to bring in what a bad answer looks like from a reputational point of view.

For global organisations there is a harder version of this. How much of the brief sits centrally and how much sits with the markets. Who arbitrates when a local agent and a central one answer the same question differently. How any of it holds together over time, across languages, in markets where the position is not identical.

If you are reading this and thinking this sounds too technical and should be someone else’s problem, I would urge you to resist that temptation. In a previous newsletter, I talked about new comms values hiding in the cracks AI creates. This is one of them. And if you’d like to stay relevant as a communication expert in a world mediated by AI, you can start by reading your new spokesperson’s (agent’s) instruction box.

Get the next issue in your inbox

Keep reading

Back to the archive