Governance Checklist

The 2027 AI-Era Link Building Governance Checklist

TL;DR

Almost every governance checklist written for AI-era search is a review document: a list of things to look at, on a cadence. Reviews find problems after the act.

The acts that create exposure in 2027 finish in seconds, on servers you do not own, and cannot be recalled. A quarterly review cannot govern a four-second act.

The only property of a checklist that matters is what it is empowered to stop. Rank candidate items by who controls the recovery: you, a counterparty, an algorithm, or nobody.

You can afford roughly four gates. Everything else has to become a bright line, because a prohibition costs nothing at the moment of action while a check costs a pause every time.

Six bright lines and eight dated entries follow. If your checklist runs to forty items, about thirty-five of them belong in a different document.

1. The checklist that cannot stop anything

On 30 October 1935, at Wright Field in Ohio, the Boeing Model 299 lifted off, climbed to around three hundred feet, stalled and crashed. Two of the five men aboard died, including Boeing’s chief test pilot Leslie Tower and Major Ployer Hill of the Army Air Corps. The cause was visible in the wreckage: the gust locks — clamps that immobilise the elevator and rudder on the ground so wind cannot damage them — had been left engaged. Critics said the aircraft was too complex to fly.

The engineers reached a different conclusion. The aircraft was not too complex to fly. It was too complicated to be left to a pilot’s memory. Their answer was a card with critical action checks for taxi, take-off and landing.

What gets left out of the retelling is the part that did the work. The card was short. It sat at pause points the aircraft was going to take anyway. And nothing moved until it was finished. The list was not the control. The stop was the control.

The experiment nobody quotes

In 2014 the New England Journal of Medicine published Urbach and colleagues’ study of what happened when Ontario made surgical safety checklists effectively mandatory across 101 acute care hospitals. Self-reported use came in at 98 per cent. The rate of any complication moved from 3.86 per cent to 3.82 per cent. Thirty-day mortality moved from 0.71 per cent to 0.65 per cent. Neither result was statistically significant, and no subgroup benefited.

The 2009 Haynes trial had found large improvements from the same instrument. What changed was everything around it: in Ontario the checklist arrived as a mandated form to be filed rather than a pause to be taken, and adoption was measured by whether the paperwork existed.

In July 2021 a former US Navy F-14 pilot was killed on take-off in Idaho because a gust lock had not been removed — eighty-six years after the Model 299, with a checklist available for the aircraft. A list of items is not a control.

What the 2026 frameworks are, and are not

The mainstream answer to AI governance right now is a framework. NIST’s AI Risk Management Framework organises the work into four functions: govern, map, measure and manage. ISO/IEC 42001 is an AI management system standard, meaning a set of requirements for how an organisation runs its own governance, and it is certifiable through a two-stage audit by an accredited body.

These are good documents, and the point is not that they are wrong but that they are a different class of object. They are management system standards. They govern the system of governing. Not one of them names a moment at which a specific piece of work stops, because not one of them can — they are written to be industry-agnostic. As a mid-2026 comparison of the three main regimes put it without much diplomacy, none of them was designed for agentic systems in the first place.

The gap shows in the adoption numbers. Around 79 per cent of businesses are using or planning to use agentic AI, and roughly 48 per cent report having a framework in place to govern and limit its autonomy. That is usually read as a documentation gap. The less comfortable reading is that between a team with a framework and a team without one, the difference in what actually gets stopped is frequently zero.

What makes something a control rather than a note? A control is a thing that can stop work. A note is a thing that can be read. Almost every line in a published governance checklist is a note.

Key takeaway

The checklist that reduced surgical deaths and the checklist that changed nothing were the same checklist. The variable was whether anything stopped. Measure a governance programme by acts prevented, not items completed.

2. What a 2027 checklist is actually governing

Review cadences fail now because the shape of the risky act changed, not because the law got stricter.

For most of the history of link building, the dangerous acts were slow and reversible. You bought a placement; the page stayed up; if it turned out to be a problem you asked for removal, or you disavowed it, or you waited for a manual action and filed a reconsideration request. Recovery was slow and unpleasant, but it existed, and it sat mostly in your hands or your publisher’s. A quarterly audit suited that world because the world held still between audits.

The 2027 surface has four properties that break the cadence.

They finish faster than any review cycle

An agent issues a request. A proxy network fetches ten thousand pages. A contractor posts a comparison in a forum at eleven at night. The interval between decision and completion is routinely under a minute, and there is no version of a monthly review that sits inside it. Speed is not incidental either — many tactics that work, from newsjacking onwards, are valuable precisely because they are fast, so a design that simply slows everything down gets routed around.

They finish on infrastructure you do not own

Someone else’s server logs the request. Someone else’s platform holds the post and the account behind it. Someone else’s index decides whether your pages come back and in what order.

The consequence outlives the act by months

The screenshot outliving the deleted post is the old version of this. The newer problem is that a retrieval layer that has already ingested the claim will keep repeating it, which is the whole reason fixing what a model says about your brand is a different discipline from correcting a web page. The act took four seconds. The correction takes a quarter, and it is not a correction you can perform yourself.

Some of them have no human actor at all

This is the category governance documents miss completely, because they are written on the assumption that somebody does something. On 15 September 2026 Cloudflare’s defaults change: crawlers classified as Training and Agent are blocked on ad-supported pages for new customers, new sites of existing customers and all free-tier customers — and because the defaults resolve to the most restrictive applicable rule, multi-purpose crawlers including Googlebot are blocked for anyone who has selected to block training. No one on your team performs that act. It is simply true one morning, and whether it applies to you depends on which plan a developer picked in 2023.

A checklist that asks whether you reviewed your crawler settings this quarter will produce a tick in August and a tick in November and will miss September entirely. The item is not wrong. It is aimed at a review cycle that the act does not respect — which is also why choosing what to expose to AI training and retrieval has quietly become a configuration decision rather than a content decision.

3. The Arrest Test

Before ranking anything, you need a way to throw most of it away. Run every candidate item through three questions.

THE ARREST TEST

1. Which act? Name the specific act this item stops. Not the topic — the act. “Disclosure compliance” is a topic. “A placement going live” is an act.

2. Who stops it? Name a person, by role, who is authorised to halt that act and whose halt cannot be overridden by the person doing the work.

3. What waits? State what happens in the meantime. Does the campaign pause, does the invoice hold, does the integration lose its credential?

Three answers means a control. Fewer than three means a note.

Notes are not worthless — they belong in the document you show people, which section 8 is about. They do not belong in the document that runs an operation, because a delivery team reading a mixed list learns within a fortnight that most of it carries no consequence, and then treats all of it that way.

Five items lifted from the shape of published AI-era SEO governance lists, run through the test:

  • “Audit the backlink profile quarterly for toxic links.” No act, no named stopper, nothing waits. A backlink audit is genuinely useful work; it is not a control. Note.
  • “Ensure AI-generated content is disclosed where required.” A topic wearing the grammar of an instruction. Note.
  • “Maintain an AI usage policy.” Names a document, not an act. Note.
  • “Verify that paid placements carry disclosure before publication.” An act (publication) and something that waits (the placement), but no named stopper. A control once you name one.
  • “No campaign brief is approved without a stated data-licence position.” Act: approval. Stopper: whoever approves briefs. What waits: the brief. Control.

One in five. That ratio is stable across the lists I have run this against, and it means the length of a governance document is close to uncorrelated with the amount of governing it does. A twelve-item list with four controls governs better than a forty-item list with four controls, because nobody has to find them.

4. Rank by who controls the recovery

Most risk matrices rank by likelihood and impact. Both are guesses, and in a domain this new they have no base rates behind them. There is a property you can determine with certainty on the day you write the checklist: if this goes wrong, who is in a position to undo it?

ClassWho controls the recoveryTypical recoveryGovernance form that fits
R0 — In-houseYou doMinutes to hours, at your discretionNo gate. Monitoring is sufficient
R1 — Willing counterpartyA publisher, client or partner who wants the relationshipDays to weeks, contingent on goodwillPost-hoc review; keep the relationship warm
R2 — An algorithmA ranking, indexing or retrieval system, on its own scheduleWeeks to months; cannot be bought or acceleratedGate
R3 — Unwilling counterpartyA moderator, a claimant, a former contractor, a competitorOnly by settlement or concessionGate plus a second signature
R4 — NobodyNo party can undo it; the act is completeNot available at any priceNo gate will do. Convert to a prohibition

Where the ordinary work lands

Editing your own page, changing an anchor, pulling a draft before it ships: R0 — most of what a delivery team does in a week, and why so much governance effort is spent in the one place it is least needed. Continuous monitoring of what engines say about the brand belongs here too, because monitoring is the right instrument for a class you can fix yourself and the wrong instrument for everything below.

Asking a publisher to add a label, change a rel attribute or amend a line: R1. R1 degrades to R3 the moment the relationship ends. An agency’s concentrated risk is not in its live accounts but in the ones that churned last quarter, where a favour that used to take an email now takes a lawyer.

Index removal, crawl-rate collapse, loss of citation share, a manual action: R2. This is the class people habitually misfile as R0, because the act that caused it was trivially reversible — one toggle, one line in a file — while the recovery was never in their gift. Getting cited again after you drop out of an answer runs on a schedule set by someone else’s re-crawl and re-embedding.

A moderator’s decision, a cease-and-desist, a complaint from a rival about what an engine says about them and where it got it: R3. The defining feature is that whoever holds the undo button has no reason to press it.

Money paid, a crawl already run, an agent utterance already read by the person it misled, a dataset already downloaded and republished elsewhere: R4. Nothing recovers these, which is why there is nothing left to manage at the point of occurrence.

Key takeaway

Classify by recovery, not by act. The most expensive error in this discipline is treating an R2 as an R0 because the button that caused it was easy to press.

What that misfiling costs: Harbourside Media

Harbourside Media is a nineteen-person digital PR and link agency in Bristol with eleven retained clients. Their own site and four client sites sat on Cloudflare’s free tier, configured once in 2023 by a developer who had since left.

  • 15 September: the defaults change. Nobody performs an act.
  • 3 October: an account manager notices a client’s Search Console crawl statistics have fallen off a cliff and assumes a reporting lag.
  • 9 October: the SEO lead diagnoses it — the training block was catching Googlebot under the most-restrictive rule.
  • 10 October: fixed. One toggle, about eight seconds of work.
  • 18 November: indexed depth back to where it had been.

The act was R0 and the recovery was R2: thirty-nine days, none of them theirs. Harbourside’s checklist had an item covering this: “review crawler and bot settings quarterly”, ticked in August and due again in November. The item that would have caught it is not a review at all but an ownership rule — line six in section 6.

5. You can afford about four gates

Gates are not free. Every gate buys safety with delay, and delay is paid in the currency your delivery team is measured in. So the number of gates you can run is not a matter of appetite. It is arithmetic.

THE GATE BUDGET

g = D ÷ (p × f)

D = the delay you will absorb in a year, in hours, across the whole team

p = the pause a single gate adds to a single act, in hours

f = how often the gated act happens in a year

g is the number of gates of that class you can run. Compute it per act class, not once for the firm.

Harbourside again, with real numbers. They place around 430 links a year across eleven clients, a mix of guest placements, digital PR and editorial partnerships. A pre-publication check on a placement takes an experienced person about twenty-two minutes when it is clean, and considerably longer when it is not. Call it 0.37 hours.

430 × 0.37 = 159 hours. Against a delivery year of roughly 1,800 hours per head, that is one gate consuming about nine per cent of a person. The partners decided they would absorb 300 hours of delay a year across the firm. 300 ÷ 159 = 1.9. They can gate placements. They can gate approximately one other act of similar frequency. That is the whole budget.

The number that ends the argument

Now price the class everyone wants to gate. Harbourside’s prospecting, monitoring and research automations fire something like 4,000 times a year. At three minutes of human review each, that is 200 hours — on its own, two-thirds more than the entire firm’s delay budget, for one class of act, before a single placement has been checked.

This is not a Harbourside problem and it does not improve with scale, because f scales with the team. It is a general result: high-frequency acts eat the budget, so gates land naturally on the low-frequency, high-consequence ones. Signing a contract. Approving a data asset for publication. Pointing a collection tool at a new domain. Issuing a credential. Three to five gates is the answer almost everywhere, and it is the same answer aviation reached ninety years ago with a short card at a stop the aircraft was taking anyway.

Put the gate where the work already stops

This is the cheapest move available and it is almost never made deliberately. A gate inserted into a flow costs the full p. A gate bolted onto a pause that already exists costs close to zero.

Briefs are already approved. Invoices are already authorised. Credentials are already issued by somebody. Contracts are already signed. Four existing stops, and between them they touch nearly every R3 and R4 act in a normal link operation. The expensive part of governance has usually already been paid for by finance and procurement, and what remains is deciding what question gets asked at a desk where work was going to pause regardless. Even the tooling decisions mostly route through a purchase, which is a stop.

6. Convert what you cannot gate into a bright line

The arithmetic in the last section has an implication people resist: most of what you would like to check, you cannot afford to check. The wrong response is to check it badly, which is what a forty-item list is: a promise priced as though checking were free, and quietly abandoned by March.

The right response is to remove the decision. A check costs a pause every time the act occurs. A prohibition costs nothing at the moment of action, because there is nothing to decide.

Aviation went further than paper. On many aircraft the modern gust lock does not rely on a card at all: it mechanically locks out the throttle until it is removed and stowed. The check became a constraint. Where you can do that — a permission that cannot be granted, a tool that cannot reach a domain, a role that cannot publish — do it in preference to writing a rule about a rule.

THE BRIGHT-LINE CONVERSION

Take any check you cannot afford. Ask what decision it asks someone to make, write the answer down in advance as a prohibition, and state what it costs.

A check asks: is this one all right? A bright line has already answered. The first scales with f. The second does not scale at all.

Test: could a new hire apply it on day one, at speed, without judgment? If not, it is still a check.

Six lines worth drawing for 2027

  1. We do not buy a placement the publisher will not label themselves. Markup is plumbing rather than a statement to a reader, so the label has to be the publisher’s. Making that a condition of purchase moves the question to a stop you already take, and it removes a slice of the sponsored placement and link insertion market from your options.
  2. Nobody posts about a client in a community without a standing, profile-level identification — and where a platform does not support one, we do not run a programme there. This is a prohibition because the alternative is reviewing every post by every contractor at every hour, which no budget survives. It also improves the work: programmes on Hacker News, Product Hunt and expert-quote platforms like HARO and its successors perform better when the identification is permanent, because the authenticity premium is real and disclosure is most of it.
  3. No automated collection runs against a domain that is not on a written allow-list, and only the person who signs contracts amends the list. This converts “is this collection lawful?” — a question that costs a lawyer an hour and returns a maybe — into “is this domain on the list?”, which costs four seconds and returns a yes or a no.
  4. No agent, script or integration holds a credential that can publish, pay or send. Publishing, paying and sending stay human acts. This is the highest-value line on the list, because agent-initiated actions are the fastest-growing R4 class and the gate budget says plainly they cannot be reviewed. It enforces itself, too: issue read-scoped credentials and there is nothing left to remember. As agentic browsing becomes ordinary infrastructure, the question of what is signed and by whom stops being a provenance curiosity and becomes an access-control decision.
  5. No original dataset is published until its licence position is decided in the brief. Deciding it at publication means deciding it after the only moment when the decision was cheap.
  6. Every vendor default surface has a named owner and a diary date; a surface with no owner gets the feature turned off. This is the line that would have saved Harbourside thirty-nine days. It is the only defence against the no-human-actor class, and the inventory it requires — CDN, bot management, CMS, analytics, outreach platform — usually runs to six or seven items, not sixty.

Notice the costs, because someone in the room will. The first line closes off part of the paid market, the second closes off some communities entirely, and the fourth slows automation that was genuinely useful. Those are losses and they belong in the document beside the line.

7. The dates that move your gates

What follows is not a summary of the law. It is a diary: the dates in the next eighteen months on which one of your five items changes state. Each entry is worth a line in a calendar and an owner’s name beside it.

  • 3 September 2026 — Advocate General Szpunar’s opinion in Like Company v Google Ireland (C-250/25), the first case to bring generative AI and copyright before the Court of Justice, heard in Grand Chamber on 10 March 2026. An opinion does not bind the Court and judgment follows months later, so nothing changes on the day. Read it for direction of travel on line five.
  • 15 September 2026 — Cloudflare’s defaults flip for new customers, new sites and all free-tier accounts, with the most restrictive applicable rule deciding multi-purpose crawlers. This is a this-month item, not a this-quarter item, and it is the one date on this list that will change something without anyone deciding to.
  • 2 December 2026 — the AI Act’s Article 50(2) marking obligation reaches generative systems already on the market before 2 August 2026. Article 50 itself has applied since 2 August 2026: the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) deferred the Annex III high-risk deadline to December 2027 and left the transparency layer alone. Penalties sit in the €15 million or 3 per cent of worldwide turnover tier.
  • 3 December 2026 — the main publisher controls under the conduct requirement the CMA imposed on Google on 3 June 2026, following the strategic market status designation of October 2025.
  • 9 December 2026 — the revised Product Liability Directive’s transposition date across member states.
  • 17 December 2026 — the fair ranking and data portability conduct requirements, imposed 17 June 2026, with their notice periods for ranking changes.
  • Q4 2026 — the Digital Fairness Act proposal is expected, aimed at online commercial practices the existing consumer regime handles badly.
  • March 2027 — page-level grounding controls under the publisher conduct requirement, nine months from imposition. This is the first date on which the opt-out question becomes granular enough to be a content decision rather than a domain decision.

A date is not a control either, and a diary of eight entries with no owners is eight notes. Each of these needs the same three answers as everything else: which act does it change, who is watching, and what waits.

Key takeaway

Of the eight dates above, exactly one changes your configuration whether or not you act: 15 September. That asymmetry is the argument for line six in one sentence.

8. The objection: a five-item checklist looks thin

The strongest objection to everything above is not that it is wrong. It is that it is unhelpfully honest in a market that buys documents.

ISO/IEC 42001 certification has moved from differentiator towards procurement table stakes; enterprise due-diligence questionnaires now ask for it by name. When a client’s procurement team, an insurer or a regulator asks what your governance looks like, a card with five items on it is not an answer anyone can file. And enforcement discretion is real: an organisation that can evidence a mature programme is treated differently from one that cannot. On that view, a short checklist is a luxury for firms nobody is auditing.

The objection is right about the market and wrong about the conclusion.

The assessors are not asking about length

The US Department of Justice’s Evaluation of Corporate Compliance Programs, the ancestor of most procurement questionnaires, is organised around three questions: is the programme well designed, is it adequately resourced and empowered to function effectively, and does it work in practice. The May 2025 revision to the monitor-selection policy cut the factors prosecutors weigh from ten to four, and one of the survivors is the maturity of a company’s controls and its ability to independently test and update them.

Those are questions about arrest and testing. None of them is answered better by a longer list. The Ontario study is what an unarrested programme looks like when somebody measures it. A firm that can show three years of a stop log will out-answer a competitor with a forty-page policy.

The answer is two documents, not one

The operating checklist is short, lives where the work happens, and is judged on acts prevented. The programme description is long, lives in a folder, maps to whichever framework your buyers name, and is judged on whether an outsider can understand what you do. They are written for different readers and should not be the same file.

The failure mode this whole article is aimed at is the fused document: forty items assembled to satisfy an external reader, then handed to a delivery team as though it were an operating procedure. It stops nothing and it reads badly, because a document optimised for two readers serves neither. A programme description that can say “these five acts are gated, here are the names, here is the log of the eleven times work was stopped last year, here are our four bright lines and what each one costs us” is more persuasive than one listing forty intentions.

What would show this ranking is wrong

If an enforcement outcome in 2027 turns on the breadth of a policy document rather than on the existence of a control that stopped something — a fine reduced because a firm had a comprehensive framework it never operated — the ranking here is wrong and should be discarded. That is not the current shape of the DOJ, CMA or ICO material, but it is the kind of thing that changes without announcement.

A concession on scale, too. Below roughly ten people the gate budget is not binding: f is small, the founder sees everything, and the correct governance is attention rather than architecture. Writing five gates and six bright lines for a three-person team is cargo cult. This framework starts to earn its keep when the number of people who can cause an R3 or R4 act exceeds the number who can see all of them at once — usually somewhere between ten and twenty-five.

9. The Monday version

Eight steps, in order. The first three cost an afternoon between them.

  1. Run every item on your current checklist through the Arrest Test. Mark each one control or note. Expect a ratio near one in five.
  2. Move the notes into a second document and title it something like “governance programme”. Do not delete them — that is your procurement answer and you will need it.
  3. Classify the acts that survive by who controls the recovery, R0 to R4. Do this out loud with the delivery team, because they will correct at least two of your classifications and the corrections are the valuable part.
  4. Compute the gate budget, D ÷ (p × f), for each act class you were planning to gate. If the answer is under three, that is not a failure of the method; that is the number.
  5. Place the gates you can afford at pauses the work already takes: brief approval, invoice authorisation, credential issue, contract signature. Name the person at each, in writing, by role.
  6. Convert everything else into bright lines. Argue about each until someone can state what it costs, and write the cost next to the line.
  7. Inventory your vendor default surfaces, name an owner for each, and put 15 September in the diary this week.
  8. Start a stop log with four columns: date, act, who stopped it, what happened next. It is the only evidence any of this works, and after a year it will be the most persuasive page in your programme description.

The Model 299 card did not make the aircraft simpler. It made a small number of moments non-negotiable, and it accepted that everything else would be handled by competent people using judgment. That is the trade a governance checklist is actually offering, — a good one, as long as you are honest about which moments you picked and what it costs when the aircraft waits. The rest of what you know about earning links, from the strategies that still work to the numbers behind them, is judgment. Governance is only the short list of places where judgment is not allowed to be exercised alone.

Leave a Reply

Your email address will not be published. Required fields are marked *

Data-Scraping Litigation Previous post Data-Scraping Litigation and Your Linkable Assets: A Risk Review