Huang Goodman·POPS4·Prosecco4·Stash Edge·Brand Room·MCP·Fending
TUMIYETIPATAGONIATITLEISTCALLAWAYVINEYARD VINESCUTTER & BUCKCOLUMBIANIKEUNDER ARMOURNORTH FACECARHARTTSTANLEYHYDRO FLASKS'WELLMOLESKINELEATHERMANBOSEJBLAPPLE TUMIYETIPATAGONIATITLEISTCALLAWAYVINEYARD VINESCUTTER & BUCKCOLUMBIANIKEUNDER ARMOURNORTH FACECARHARTTSTANLEYHYDRO FLASKS'WELLMOLESKINELEATHERMANBOSEJBLAPPLE
The Stash Edge · Huang GoodmanVirginia Beach · Atlantic coast · since 1997
On the wire
The Stash Edge · Intelligence Desk ISABELLA'S ISLAY

Brand Safety Used to Be a Phone Call. Now It Is a Search.

A reputation was once protected, and ruined, by a few people who knew each other. AI has changed every part of that: it floods the web with synthetic content, fakes the brand itself, and reads a company, its principals, its vendors and their circle, down to posts, chats and email from years ago, in seconds. Most brands are still using the old controls.

Published September 14, 2026 From the chopped neck
Subject on the desk
Private
DIAMOND · September 14, 2026
SEARCH THE CATALOG 70,000 imprint-ready products · 200+ authorized brands · ASI #217876 Jenny Huang Goodman — open your Brand Room
Jenny Huang Goodman
Principal · ASI #217876 · Since 1997
Planning something Create an event in 30 seconds Date, headcount, tier. Live per-attendee pricing. Start
One vendor pick erased a billion in brand value in a week. The board found out who signed it. More vendor reckonings in the House Edge →
ISABELLA'S ISLAY · September 14, 2026

Brand Safety Used to Be a Phone Call. Now It Is a Search.

A reputation was once protected, and ruined, by a few people who knew each other. AI has changed every part of that: it floods the web with synthetic content, fakes the brand itself, and reads a company, its principals, its vendors and their circle, down to posts, chats and email from years ago, in seconds. Most brands are still using the old controls.

For most of the last century a brand's reputation was protected the same way it was damaged: in private, by a handful of people who knew each other.

AI has ended that arrangement in four ways at once. It has flooded the web with synthetic content faster than the old controls can sort it. It has made the brand itself easy to fake. It reads a company's entire public footprint in seconds: its posts, its executives' posts, its vendors' posts and the posts of the friends who tag them. And it forgets nothing: old posts, archived pages and leaked email come back as if they were written this morning. Most brands are still defending themselves with tools built for the old arrangement.

So ask the obvious question: what are your vendors' socials doing to your brand?

How reputations used to be protected.

Brand protection used to run like a small, well-mannered mafia. A name was made over lunch and unmade the same way: a few phone calls, a word dropped in the right ear, a firm quietly left off a list. The people who decided were few, they were known to each other, and nothing they said was written down.

It worked because it was slow and it was private. A rumour needed a messenger. A correction needed a better-connected friend. Whoever sat closest to the decision controlled the story, and everyone else waited to hear how it came out.

That structure depended on one condition: that what people said about a brand, and what a brand's own circle said about themselves, stayed inside the room where it was said.

What AI changed about brand safety.

For a decade, brand safety meant one thing: keeping a company's advertising away from the wrong content. It ran on shared industry standards, keyword lists and platform moderation. AI has weakened all three.

Start with volume. In January 2025 DoubleVerify identified a network of more than 200 websites filled with AI-generated content and built to look like real publishers, with addresses such as espn24.co.uk and nbcsportz.com. Leading brands were found advertising on them, likely unaware. In Integral Ad Science's December 2025 survey of nearly 300 US media experts, 83 per cent called the rise of AI-generated content on social media a significant concern, and 84 per cent said third-party verification would be needed just to identify it.

Consumers react to it even when they cannot see it. DoubleVerify's July 2026 study of 22,000 consumers across 22 markets found that 56 per cent cannot consistently tell AI-generated content apart, yet 42 per cent say a brand's use of low-quality AI advertising would lower their opinion of that brand.

The old tools have not kept pace. The industry's shared standard, the Global Alliance for Responsible Media, was discontinued by the World Federation of Advertisers on 9 August 2024, and the federation says it will not be restarted. Keyword lists misfire as well: when Fox Corporation scanned its own properties with an AI classifier, it found legacy brand-safety providers marking 30 to 50 per cent of professional publishers' content as high risk, though most of it read as neutral or positive.

And the platforms have stepped back. On 7 January 2025 Meta announced it would end its third-party fact-checking programme in the United States and replace it with Community Notes.

Boards have noticed. According to The Conference Board, 72 per cent of S&P 500 companies disclosed an AI-related risk in 2025, up from 12 per cent in 2023, and 38 per cent flagged reputational risk. The editors of AIVO Journal put the change in a sentence: brand safety now "begins at the point of explanation," the answer an AI assistant gives about a company before anyone visits a site at all.

The brand itself is now being faked.

The larger change is that AI no longer only surrounds a brand. It impersonates it.

Google's 2025 Ads Safety Report, published in April 2026, records more than 8.3 billion ads blocked or removed and 602 million scam ads taken down, and states plainly that "bad actors are using generative AI to create deceptive ads at scale." The FBI's 2025 Internet Crime Report logged 22,364 complaints involving AI, with reported losses of $893 million. The Federal Trade Commission put 2025 losses to impostor scams at $3.5 billion, nearly $1 billion of it to people impersonating businesses.

The impersonation reaches inside companies too. In 2024 an employee of the engineering firm Arup transferred about $25 million after a video conference with what appeared to be the firm's chief financial officer and other colleagues. They were AI-generated. Arup confirmed that false voices and images were used.

In a February 2026 survey of 96 brand leaders by Marqvision, 85 per cent reported AI-accelerated threats such as impersonation accounts and synthetic brand assets. Gartner expects half of all enterprises to be investing in disinformation security by 2027, up from under 5 per cent. As its analyst Andrew Frank put it, "even well-established brands can find themselves at the centre of a synthetic outrage storm overnight."

What are your vendors' socials doing to your brand?

The same technology that fakes a brand also reads one. A procurement team, an investor's diligence desk or a journalist can now point an AI system at a company and have it read everything public in seconds: the company's own accounts, its executives' personal ones, its vendors, the people who tag any of them, and every post that has been screenshotted and reposted since.

Commercial screening already runs at that scale. Moody's adverse-media service, used in customer and anti-money-laundering checks, draws on more than 14,000 media sources and more than 3 billion articles across over 100 countries, using natural-language processing to surface what matters.

The circle is readable too. In a July 2026 review of 72 executive vulnerability assessments, the security firm Nisos found breach data linking every executive's name to at least one current email address. The executives' immediate relatives kept an average of eight public social media accounts, and 97 per cent of those accounts revealed personal details about the executive. Nisos also found that many AI tools are likely trained on data that includes personal information gathered by data brokers.

The reading is not selective, and it is not polite. A model does not know which dinner the photograph came from or who meant a remark as a joke. It records what is there, attributes it to the nearest name, and moves on to the next supplier. It rarely keeps a brand and its vendors apart, either; their posts arrive in the same result.

Consider a plain scenario. A brand's largest groups of employees and customers share a particular background. One of its vendors is ultimately owned, through a holding company or two, from a country on the Commerce Department's list of foreign adversaries, and one of that vendor's principals posts race-baiting and hateful content every day. The brand has never read those posts. The undertow has. Search engines, AI assistants and screening tools pull the vendor's posts into the same results as the brand's name, and the people most likely to see them are the brand's own staff and customers, the very groups the posts target. And a foreign adversary gains a tool it never had to pay for: a vendor it can use, at no cost and without a trace, to drive the stakeholder relationships of major military clients, cheaper than the dirt shrimp feed off. There is not much more harmful to the United States than an adversary's cheap assets in tow.

Nothing the brand published explains what happens next. Trust erodes among the people the posts attack, which is exactly what the research on exposure to hate predicts. Orders slip market by market across the country, recruiting gets harder, and the dashboards show a decline without a cause. The cause is sitting in a vendor's feed, and nobody inside the company thought to look there.

Nothing old stays old.

The machine does not only read what is current. It reads what was kept.

The Internet Archive passed one trillion archived web pages in October 2025, a record reaching back to 1996 that holds pages their authors later edited or deleted. AI search draws on that depth and on the forums around it. In April 2026 Search Engine Land described an AI Overview that gathered years-old Reddit complaints about a company and restated them in strong negative language, though the customer service problems behind them had been resolved nearly a decade earlier. The answer was screenshotted and shared, and the repetition gave it fresh momentum. From scattered fragments, the system had built a narrative, and the narrative read as news.

Old posts carry consequences long after they were written. In November 2025 Paystack, the payments company Stripe acquired in 2020, dismissed a co-founder, citing "significant negative reputational damage" from resurfaced posts more than a decade old. As one legal commentator noted, the posts had been on the open internet when the acquisition was made.

Private conversations do not stay private either. The 2014 hack of Sony Pictures published years of internal email, and in February 2015 the studio's co-chairman stepped down after embarrassing messages became public. In 2017 Yahoo disclosed that all of its user accounts had been affected by a theft in August 2013. Long-established email services hold decades of correspondence, and that archive is what makes them a target.

Where that email is stored matters as well. Mail kept in data centres abroad sits under more than one legal system. The US CLOUD Act, signed on 23 March 2018, requires American providers to disclose data they control "regardless of the location of the data," and the host country's own access laws apply as well. A message held on servers overseas can be reachable under more than one country's rules.

Regulators already treat workplace chat as a permanent record. Since 2021 more than 100 broker-dealers, investment advisers and other firms have paid more than $3 billion in SEC penalties for failing to keep business messages sent by text and through apps such as WhatsApp.

When a post moves a share price.

The old gentlemen's clubs have not caught up. Their members still trade one another's names the way they always have: a friend's firm talked up in a caption, a client's product paraded in a photograph, a peer's company tagged in a post meant for a few dozen people. None of it was written for a machine to read. All of it now is.

And the cost of getting it wrong is no longer confined to a small company drawing the wrong kind of attention. It reaches public markets, and it reaches them in minutes.

On 10 November 2022 an impostor account carrying a paid verification badge posted, in Eli Lilly's name, that insulin was now free. The company corrected it. The next day its shares fell 4.37 per cent, erasing more than $15 billion in market value.

On 23 April 2013 a hacked Associated Press account reported explosions at the White House. The Dow Jones Industrial Average lost about 140 points before the report was exposed as false and the losses were recovered. A decade later the fake no longer needed a stolen password: on 22 May 2023 an AI-generated image of an explosion near the Pentagon spread on social media and prompted a brief dip in the stock market.

Real posts carry their own liability. On 20 March 2026 a federal jury in San Francisco found that Elon Musk misled Twitter shareholders with two posts during his 2022 takeover, one of them saying the deal was "temporarily on hold." Damages were put at about $2.1 billion, although the jury rejected the claim that he had schemed to defraud investors.

The damage also travels along the same networks the clubs are built on. A 2008 study in the Academy of Management Journal found that reputational penalties from financial reporting fraud spilled over to companies that merely shared directors with the accused firms. A 2024 study in the International Journal of Operations & Production Management found that corruption at one company lowers the stock returns of its supply-chain partners, and that customers are hit harder than suppliers.

A market that moves on a stranger's post before anyone checks who wrote it will not stop to check a real post from a real director's circle either.

When a few posts become a case.

A handful of bad posts no longer stays a public relations problem. It can become evidence, a shareholder claim, a contracting question or a compliance finding, and it tends to surface at the moment a company can least afford it.

It can become evidence. The Government Accountability Office reported in February 2024 that "federal law enforcement agencies have used online hate posts as evidence" in prosecutions of domestic violent extremism and other hate crimes, and that up to a third of internet users report experiencing hate speech online.

It can surface when a contract is on the line. Before a federal contract is awarded, the contracting officer must find the prospective contractor responsible, and that includes "a satisfactory record of integrity and business ethics." Security clearance investigators, as the next section shows, may read public social media as well. A vendor's worst posts tend to be found exactly when the vendor is being chosen.

In regulated industries the vendor's conduct becomes the client's. The federal banking regulators' 2013 social media guidance warns that working with third parties on social media "can expose financial institutions to substantial reputation risk." It says monitoring what an institution places on those sites remains its own responsibility "even when such functions may be delegated to third parties," and that negative publicity can harm an institution "even if the financial institution has not violated any law." Fair lending rules reach the same channels: under the Equal Credit Opportunity Act, a creditor may not make any statement in advertising or marketing that would discourage applicants on a prohibited basis. The agencies' 2023 guidance on third parties is blunter still: using them "does not diminish or remove" a bank's responsibility to operate safely and within the law.

Hateful content carries a cost of its own. A January 2025 Campbell Collaboration review of 55 studies found that exposure to hate "reduces trust between targeted groups and the general population." Customers, employees and suppliers belong to those groups, and their trust is the asset a brand runs on. Employment lawyers make the same point about staff: "Expressions of racism or other harassment are not political speech."

What the military asks of its own people.

The military has not written rules for brand safety, and it has not written rules for AI. What it has done is set expectations for how its own people post, and the reasoning behind them is the useful part.

In August 2022 the Department of Defense issued DoD Instruction 5400.17, its first department-wide policy on social media. It warns that mishandled social media can compromise the government's standing, including its "reputation for a high ethical and professional standard," and it sets guidance so that personal accounts are not mistaken for official ones.

Since December 2021 the Pentagon's rules on extremist activity have covered online behaviour down to a single click. Asked whether liking extremist content counts, Pentagon Press Secretary John Kirby said: "The physical act of liking is, of course, advocating, right?"

The Army goes further for its own soldiers. Under its command policy regulation, AR 600-20, failing to follow the Army's rules for online behaviour is "a punishable offense under the UCMJ." Its current guidance for personal accounts is just as plain: "Personal accounts must be clearly identifiable as personal." Soldiers are told to avoid titles, insignia or uniforms "in a way that could imply DoD sanction or endorsement," and that they remain "personally responsible for all content they publish."

The Navy put the question of rank in writing in March 2025: "As the position and grade of individual Service Members increase, it becomes increasingly difficult to distinguish between personal opinions and official positions of the DON or DoD. Senior personnel are highly encouraged to include a disclaimer on personal social media communications." Its guidance of October 2025 told sailors and Marines to uphold core values "on duty, off duty, and online," never to disclose nonpublic information, and the department said it was reviewing reported violations.

In June 2026 Army Secretary Dan Driscoll signed Army Directive 2026-17, Optimizing Digital Media, which limits official accounts to a short list of commands, formations and installations and orders every other unit account archived within thirty days. Its stated purpose is to "ensure a clear, unified voice, reduce operational risk, and improve information access."

And since 2016, Security Executive Agent Directive 5 has allowed investigators to collect and use publicly available social media information when deciding who may hold a security clearance.

Why the same logic now reaches brands.

None of those rules bind a company. A vendor's founder is not subject to the Uniform Code of Military Justice, and a brand's marketing account does not need a commanding officer's approval. What binds a company is its contracts and, if it is public, its securities obligations.

Regulators reached a similar view about executives' own feeds. In April 2013 the Securities and Exchange Commission confirmed that companies may announce material news on social media, but only if investors have been told where to look, after Netflix's chief executive reported a viewing milestone on his personal Facebook page. In September 2018 Elon Musk and Tesla each paid $20 million to settle charges over his posts about taking Tesla private, after the SEC found Tesla "had no disclosure controls or procedures in place to determine whether Musk's tweets contained information required to be disclosed."

The reasoning transfers. A post is attributable, permanent and readable by people with interests of their own. The Navy's point about rank translates most directly of all: the more senior the person, the harder it is for anyone reading to tell a private opinion from a company position. That is the standing of every founder, director and board member whose name sits on a supplier's letterhead, and of every peer whose caption treats that name as common property.

A vendor's principal is part of that vendor's security posture. So are the peers who tag them, the clients they photograph and the accounts that look like theirs but are not. A buyer's system that reads the vendor will read all of it, and it will not separate the company from the people around it any more than a clearance investigator separates a candidate from what the candidate has published. As the compliance lawyer Michael Volkov wrote in June 2026 about vendors' AI failures: "Reputational risk does not follow legal doctrine. It follows public perception."

The clause most supplier codes leave out.

Hako Shikin's Vendor Standards were written with this in view. Expectation 08 asks for "public conduct consistent with these values, and respect for the people a business works with and serves," and says plainly that "conduct reaches past the company to its principals and owners, including what they say in public. No hate speech. No advocacy of violence."

It is an unusual clause. Of the supplier codes reviewed when those standards were drafted, from Walmart, Costco, Target, Wegmans and the Responsible Business Alliance, none extends to what a supplier's principals say in public. They cover labour, safety, bribery, data and audit rights in detail. They stop at the company's edge.

That edge is exactly where the reading now starts.

What to check this quarter.

Run the read on yourself before a buyer does. Point an AI system at the company name, then at each principal's name, and read what comes back as a stranger would. Ask the major AI assistants what they say about the company, and correct what is wrong at the source.

Search the archive, not only the feed. Old posts, forum threads and cached pages are often what an AI system finds first, and a complaint resolved years ago can still read as current.

Treat every message as a record. Chats and email outlive the conversation that produced them. Know where the company's email is stored, and which countries' laws can reach it.

Separate the personal from the official, as defense policy does for its own people. Anyone whose company title appears on a personal account should make clear that its opinions are their own, and the more senior the person, the more that line matters.

Consolidate. If the Army can order unit accounts closed to reduce operational risk, a company can close the dormant pages still carrying its logo.

Know who may speak in the company's name, and write it down. If the company is public, route anything material through its disclosure controls, whoever's account it appears on.

Plan for impersonation. Watch for accounts and ads that only look like yours, and never approve a payment on the strength of a video call or a message alone. A verification badge proved nothing in November 2022, and a familiar face on a screen proved nothing at Arup.

Move advertising controls from keyword lists to context, so safe content is not blocked and unsafe content is not missed.

Label and verify the company's own content, using verification standards such as Content Credentials, so a genuine announcement can be told apart from a fake one.

Ask what your vendors' socials are doing to your brand. Screen vendors the way a bank must: before the contract and between reviews, including what their principals publish and who ultimately owns them.

Put public conduct in the supplier code, and extend it to principals and owners.

And tell the circle. The friends, peers and clients who tag a company are not trying to harm it. They simply have not been told that a machine is now in the room.

The room got bigger.

A reputation used to be decided in a small room by people who knew each other. The room still exists. It has simply been joined by every system that can read, and by every system that can fake what it reads. None of them were invited, none of them forget, and none of them are leaving.

About us.

Hako Shikin LLC has been making things for other people's brands since 1997, out of Virginia Beach, Virginia. It is the brand partner for brands that cannot afford a bad headline: one house that stays accountable from the first conversation to the pallet on the dock, rather than a chain of vendors each holding a piece and none of them holding the date. Four arms do the work. Huang Goodman for public relations, strategy and program management. Hako Shikin for production, routed across more than 1,400 vetted American manufacturers. POPS4 for the catalogue, 70,000+ products across 200+ brands. Prosecco4 for events. The people who call are usually holding something that matters and a date that will not move, and what they are looking for is rarely a proposal. It is somebody who picks up, gives them the real number, and is still standing there when the truck arrives.

If you are building from what is left, you are not finished.

-Jenny Huang Goodman MPA MSc MHSA jenny@huanggoodman.com

---

## Contents labels (toc_notes)

1. How reputations used to be protected | A few phone calls, a word dropped, a name left off a list
2. What AI changed about brand safety | Synthetic content, failing blocklists, and 72% of the S&P 500 now listing AI risk
3. The brand itself is now being faked | 602 million scam ads, $893 million in AI-linked losses, a $25 million deepfake call
4. What are your vendors' socials doing to your brand? | Everything public, in seconds, and the vendor whose feed sinks your orders
5. Nothing old stays old | A trillion archived pages, decade-old posts, leaked and overseas email
6. When a post moves a share price | $15 billion from one fake account, $2.1 billion from two real ones
7. When a few posts become a case | Evidence, contracts, bank vendor rules and the cost of hate
8. What the military asks of its own people | Personal accounts, rank, and a single click
9. Why the same logic reaches brands | Rank, disclosure controls and the executive's personal feed
10. The clause supplier codes leave out | Public conduct, extended to principals and owners
11. What to check this quarter | Twelve checks before a buyer runs them
12. The room got bigger | Every system that can read, or fake, is now in the room
13. About us | Who we are and what we make

## Tags
brand safety · AI governance · deepfakes · impersonation · social media · vendor standards · procurement · public markets · third-party risk

## Sources (48 — cap is 24; recommend raising to 50 before publishing)
1. DoubleVerify "Synthetic Echo" AI slop sites (B&T, 17 Jan 2025): https://www.bandt.com.au/doubleverify-uncovers-over-200-ai-slop-sites-misleading-advertisers-wasting-spend/
2. Integral Ad Science — 2026 Industry Pulse Report (8 Dec 2025): https://integralads.com/news/2026-ias-industry-pulse-report/
3. DoubleVerify — Global Insights: Media Quality in the Age of AI (29 Jul 2026): https://www.stocktitan.net/news/DV/global-study-poor-quality-ai-content-puts-brand-trust-at-91m79lhsgkv3.html
4. World Federation of Advertisers — GARM litigation settled; GARM discontinued 9 Aug 2024: https://wfanet.org/knowledge/item/2026/07/29/wfa-and-x-settle-over-garm-litigation
5. AdExchanger — AI Is Helping Brand Safety Break Free From Blocklists (13 Oct 2025): https://www.adexchanger.com/marketers/ai-is-helping-brand-safety-break-free-from-blocklists/
6. Meta — More Speech and Fewer Mistakes (7 Jan 2025): https://about.fb.com/news/2025/01/meta-more-speech-fewer-mistakes/
7. The Conference Board via Harvard Law School Forum on Corporate Governance — AI Risk Disclosures in the S&P 500 (15 Oct 2025): https://corpgov.law.harvard.edu/2025/10/15/ai-risk-disclosures-in-the-sp-500-reputation-cybersecurity-and-regulation/
8. AIVO Journal — Brand Safety Has Moved Upstream of Media (18 Jan 2026): https://www.aivojournal.org/brand-safety-has-moved-upstream-of-media/
9. Google — 2025 Ads Safety Report (16 Apr 2026): https://blog.google/products/ads-commerce/2025-ads-safety-report/
10. FBI IC3 — 2025 Internet Crime Report: https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
11. FTC — People reported losing $3.5 billion to imposter scams in 2025 (15 Jun 2026): https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
12. CFO Dive — Arup deepfake CFO scam (17 May 2024): https://www.cfodive.com/news/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai/716501/
13. Marqvision — 2026 Brand Integrity Report (16 Feb 2026): https://www.marqvision.com/blog/2026-brand-integrity-report
14. Gartner — 50% of enterprises will invest in disinformation security and TrustOps by 2027 (20 Nov 2025): https://www.gartner.com/en/newsroom/press-releases/2025-11-20-gartner-predicts-50-percent-of-enterprises-will-invest-in-disinformation-security-and-trustops-by-2027
15. Moody's — Adverse media screening: https://www.moodys.com/web/en/us/kyc/solutions/screen-monitor/adverse-media-screening.html
16. Nisos — Executive Digital Exposure Trends 2026 (13 Jul 2026): https://nisos.com/blog/executive-digital-exposure-trends-2026/
17. 15 CFR § 791.4 — Determination of foreign adversaries (Department of Commerce), via Cornell LII: https://www.law.cornell.edu/cfr/text/15/791.4
18. Internet Archive — One trillion web pages archived (31 Oct 2025): https://blog.archive.org/2025/10/31/one-trillion-web-pages-archived-internet-archive-celebrates-a-civilization-scale-milestone/
19. Search Engine Land — Why AI search is your new reputation risk (3 Apr 2026): https://searchengineland.com/ai-search-reputation-risk-473361
20. WeeTracker — Paystack dismissal over resurfaced posts (25 Nov 2025): https://weetracker.com/2025/11/25/paystack-fired-ezra-olubi-old-tweets-legal-concerns/
21. CBS News — Amy Pascal steps down as Sony Pictures co-chairman (5 Feb 2015): https://www.cbsnews.com/amp/news/amy-pascal-steps-down-as-sony-pictures-co-chairman
22. Oath/Yahoo — 8-K Exhibit 99.1, all user accounts affected by August 2013 theft (3 Oct 2017): https://www.sec.gov/Archives/edgar/data/732712/000073271217000003/a2017_10x3xoathxexhibitx991.htm
23. Stanford Law Review — Microsoft Ireland, the CLOUD Act, and International Lawmaking 2.0: https://www.stanfordlawreview.org/online/microsoft-ireland-cloud-act-international-lawmaking-2-0/
24. Holland & Knight — SEC off-channel communications enforcement (20 Dec 2024): https://www.hklaw.com/en/insights/publications/2024/12/a-long-winters-nap-sec-off-channel-communications
25. Advisory Board — How a fake tweet cost Eli Lilly billions (14 Nov 2022): https://www.advisory.com/daily-briefing/2022/11/14/eli-lilly-twitter
26. NBC News — AP Twitter account hacked (23 Apr 2013): https://www.nbcnews.com/tech/tech-news/ap-twitter-account-hacked-posts-false-white-house-scare-flna6C9560165
27. Al Jazeera — Fake Pentagon explosion photo goes viral (23 May 2023): https://www.aljazeera.com/news/2023/5/23/fake-pentagon-explosion-photo-goes-viral-how-to-spot-an-ai-image
28. PBS NewsHour — Jury finds Musk misled investors during Twitter takeover (20 Mar 2026): https://www.pbs.org/newshour/nation/jury-finds-musk-misled-investors-during-twitter-takeover-absolves-him-of-some-fraud-claims
29. Kang, E. — Director Interlocks and Spillover Effects of Reputational Penalties From Financial Reporting Fraud, Academy of Management Journal (2008): https://doi.org/10.5465/AMJ.2008.32626007
30. International Journal of Operations & Production Management — Spillover effects of supply chain corruption on stock returns (2024): https://www.emerald.com/insight/content/doi/10.1108/IJOPM-11-2022-0760/full/html
31. U.S. GAO — Online Extremism is a Growing Problem, But What's Being Done About It? (13 Feb 2024): https://www.gao.gov/blog/online-extremism-growing-problem-whats-being-done-about-it
32. Federal Acquisition Regulation 9.104-1 — General standards (responsible prospective contractors): https://www.acquisition.gov/far/9.104-1
33. FFIEC — Social Media: Consumer Compliance Risk Management Guidance (2013): https://files.consumerfinance.gov/f/201309_cfpb_social_media_guidance.pdf
34. Federal Reserve SR 23-4 — Interagency Guidance on Third-Party Relationships: Risk Management (7 Jun 2023): https://www.federalreserve.gov/supervisionreg/srletters/SR2304.htm
35. Campbell Collaboration — Exposure to hate in online and traditional media: systematic review and meta-analysis (16 Jan 2025): https://www.campbellcollaboration.org/review/exposure-to-hate-in-online-and-traditional-media-a-systematic-review-and-meta-analysis-of-the-impact-of-this-exposure-on-individuals-and-communities/
36. Ogletree — Social Media Posts During Turbulent Times: FAQs (22 Jun 2020): https://ogletree.com/insights-resources/blog-posts/social-media-posts-during-turbulent-times-faqs-on-employee-rights-and-employer-responsibilities/
37. U.S. Army — DoD releases first department-wide social media policy (DoDI 5400.17): https://www.army.mil/article/259433/dod_releases_first_department_wide_social_media_policy
38. Defense One — Click 'Like', get punished under Pentagon's new anti-extremism policy (Dec 2021): https://www.defenseone.com/threats/2021/12/click-get-punished-under-pentagons-new-anti-extremism-policy/359999/
39. U.S. Army — Social Media Policies (AR 600-20): https://www.army.mil/socialmedia/policies/
40. U.S. Army — Personal Use Guidelines: https://www.army.mil/socialmedia/personal/
41. ClearanceJobs — Navy updates social media guidance for FY25 (27 Mar 2025): https://news.clearancejobs.com/2025/03/27/uniforms-opinions-and-instagram-navy-updates-social-media-guidance-for-fy25/
42. Navy Times — US Navy releases new social media guidelines (28 Oct 2025): https://www.navytimes.com/news/your-navy/2025/10/28/us-navy-releases-new-social-media-guidelines-for-service-members/
43. DefenseScoop — Army Directive 2026-17, Optimizing Digital Media (9 Jul 2026): https://defensescoop.com/2026/07/09/army-social-media-policy-dan-driscoll-directive/
44. ODNI — Security Executive Agent Directive 5: https://archive.dni.gov/index.php/ncsc-how-we-work/ncsc-security-executive-agent/ncsc-policy
45. SEC — Elon Musk settles SEC fraud charges; Tesla charged (29 Sep 2018): https://www.sec.gov/newsroom/press-releases/2018-226
46. Goodwin — SEC clarifies social media use and Reg FD compliance (Apr 2013): https://www.goodwinlaw.com/en/insights/publications/2013/04/sec-clarifies-social-media-use-and-reg-fd-compliance
47. Volkov Law — Reputational Risk When Your Vendor's AI Misbehaves (15 Jun 2026): https://blog.volkovlaw.com/2026/06/detangling-third-party-ai-risks-reputational-risk-when-your-vendors-ai-misbehaves-part-ii-of-ii/
48. Hako Shikin — Vendor Standards: https://hakoshikin.com/vendor-standards

The takeaway
Brand safety no longer means where a logo appears. It means what a company, its principals and their circle have already published, and that includes its vendors, because AI systems often collapse a brand's public expression and its vendors' into the same result. A market will price that before anyone checks who wrote it.
Steal this — share it
Want the 60-second program for your specific event?
Enter your event and email — we build it and send the branded proposal before lunch. No obligation.
Already planning? → dashboard.pops4.com · Query via AI agent → mcp.pops4.com/mcp · Book a call → 15 minutes with Jenny
Sources
  1. DoubleVerify "Synthetic Echo" AI slop sites (B&T, 17 Jan 2025)
  2. Integral Ad Science — 2026 Industry Pulse Report (8 Dec 2025)
  3. DoubleVerify — Global Insights: Media Quality in the Age of AI (29 Jul 2026)
  4. World Federation of Advertisers — GARM litigation settled; GARM discontinued 9 Aug 2024
  5. AdExchanger — AI Is Helping Brand Safety Break Free From Blocklists (13 Oct 2025)
  6. Meta — More Speech and Fewer Mistakes (7 Jan 2025)
  7. The Conference Board via Harvard Law School Forum on Corporate Governance — AI Risk Disclosures in the S&P 500 (15 Oct 2025)
  8. AIVO Journal — Brand Safety Has Moved Upstream of Media (18 Jan 2026)
  9. Google — 2025 Ads Safety Report (16 Apr 2026)
  10. FBI IC3 — 2025 Internet Crime Report
  11. FTC — People reported losing $3.5 billion to imposter scams in 2025 (15 Jun 2026)
  12. CFO Dive — Arup deepfake CFO scam (17 May 2024)
  13. Marqvision — 2026 Brand Integrity Report (16 Feb 2026)
  14. Gartner — 50% of enterprises will invest in disinformation security and TrustOps by 2027 (20 Nov 2025)
  15. Moody's — Adverse media screening
  16. Nisos — Executive Digital Exposure Trends 2026 (13 Jul 2026)
  17. 15 CFR § 791.4 — Determination of foreign adversaries (Department of Commerce), via Cornell LII
  18. Internet Archive — One trillion web pages archived (31 Oct 2025)
  19. Search Engine Land — Why AI search is your new reputation risk (3 Apr 2026)
  20. WeeTracker — Paystack dismissal over resurfaced posts (25 Nov 2025)
  21. CBS News — Amy Pascal steps down as Sony Pictures co-chairman (5 Feb 2015)
  22. Oath/Yahoo — 8-K Exhibit 99.1, all user accounts affected by August 2013 theft (3 Oct 2017)
  23. Stanford Law Review — Microsoft Ireland, the CLOUD Act, and International Lawmaking 2.0
  24. Holland & Knight — SEC off-channel communications enforcement (20 Dec 2024)
  25. Advisory Board — How a fake tweet cost Eli Lilly billions (14 Nov 2022)
  26. NBC News — AP Twitter account hacked (23 Apr 2013)
  27. Al Jazeera — Fake Pentagon explosion photo goes viral (23 May 2023)
  28. PBS NewsHour — Jury finds Musk misled investors during Twitter takeover (20 Mar 2026)
  29. Kang, E. — Director Interlocks and Spillover Effects of Reputational Penalties From Financial Reporting Fraud, Academy of Management Journal (2008)
  30. International Journal of Operations & Production Management — Spillover effects of supply chain corruption on stock returns (2024)
  31. U.S. GAO — Online Extremism is a Growing Problem, But What's Being Done About It? (13 Feb 2024)
  32. Federal Acquisition Regulation 9.104-1 — General standards (responsible prospective contractors)
  33. FFIEC — Social Media: Consumer Compliance Risk Management Guidance (2013)
  34. Federal Reserve SR 23-4 — Interagency Guidance on Third-Party Relationships: Risk Management (7 Jun 2023)
  35. Campbell Collaboration — Exposure to hate in online and traditional media: systematic review and meta-analysis (16 Jan 2025)
  36. Ogletree — Social Media Posts During Turbulent Times: FAQs (22 Jun 2020)
  37. U.S. Army — DoD releases first department-wide social media policy (DoDI 5400.17)
  38. Defense One — Click 'Like', get punished under Pentagon's new anti-extremism policy (Dec 2021)
  39. U.S. Army — Social Media Policies (AR 600-20)
  40. U.S. Army — Personal Use Guidelines
  41. ClearanceJobs — Navy updates social media guidance for FY25 (27 Mar 2025)
  42. Navy Times — US Navy releases new social media guidelines (28 Oct 2025)
  43. DefenseScoop — Army Directive 2026-17, Optimizing Digital Media (9 Jul 2026)
  44. ODNI — Security Executive Agent Directive 5
  45. SEC — Elon Musk settles SEC fraud charges; Tesla charged (29 Sep 2018)
  46. Goodwin — SEC clarifies social media use and Reg FD compliance (Apr 2013)
  47. Volkov Law — Reputational Risk When Your Vendor's AI Misbehaves (15 Jun 2026)
  48. Hako Shikin — Vendor Standards
brand safetyAI governancedeepfakesimpersonationsocial mediavendor standards
Brand your brand — for real
70,000 products · virtual proof in 60 seconds · no platform fee · imprinted since 1997
Huang Goodman · cradle-to-grave branded identity infrastructure
One house behind your brand.
The branded-identity layer Chiefs of Staff and heritage CMOs route through — your name imprinted on real authorized stock, your pick of 200+ brands and 70,000 products, shipped from one accountable house. Nine editorial desks publish the intelligence those operators read before they sign.
200+authorized brands
70,000products · virtual proof on each
9 deskspublishing daily
1997one house, since
70,000 SKUs · virtual proof in 60 seconds · no platform fee · blind-shipped · ASI #217876
Your next customer won't visit your website. Their AI will.
AI assistants have quietly taken over the first step of buying — they answer from catalogs they can read and shortlist whoever can actually ship. Two questions now decide whether you exist to that buyer: can a machine read your catalog, and can you fulfill the order. Most brands fail one or both and never find out why the orders went elsewhere. The winners of this shift aren't the loudest. They're the most readable. Build for the machine that's about to do the shopping.
24AI workers live
70,000MCP-queryable SKUs
700+branded videos shipped
24/7concierge coverage
Built by the craft floor — apparel, media, packaging, and secure print.
This trade runs on hands, not desks. Imprint manufacturing & Komori heritage press through approved vendors · Canon high-speed secure-media operations is a craft floor — genuine Six Sigma discipline applied to ink, thread, foil, and registration, where a hundredth of an inch is the difference between a brand that reads serious and one that reads cheap. POPS4 is built by exactly those operators: independent, boots-on-the-ground engineers who carry their own book, read a client in microseconds, and put their name on every run. Beyond our own Virginia Beach floor, we work with a vetted network of craft manufacturers across the US — each meeting the highest excellence in QC standards in the industry, each a specialist in its own discipline — so apparel, hard-goods imprinting, media manufacturing, packaging, and secure printing all go to the bench built for them, coordinated from one accountable hub. Short-run from twenty-five units, volume to five hundred thousand. Two hundred authorized national brands, seventy thousand SKUs with virtual proofing on every one. Art archived for instant reorders. Net-thirty corporate terms, NDA-standard white-label — your name on the work, or none at all.
70,000products · virtual proof
200+authorized brands
25 → 500Kunit range
ASI #217876DUNS 18-204-6339
Full-service, AI-native. Nine desks in-house.
Strategy, positioning, identity, creative, and messaging — wired into an AI system that publishes and distributes on its own. Nine editorial desks generate the authority, the production house ships the physical proof, and the attribution layer tells you which post sold which SKU. What you get is an operating layer — content, catalog, and order path under one roof — that keeps working whether or not you are in the room. Built for principals who would rather own the machine than rent the agency.
9editorial desks in-house
26K+LinkedIn network
700+branded videos produced
Multi-channelLinkedIn · X · Bluesky · Substack
Named-account programs — one desk, quiet delivery, NDA-standard.
One point of contact who already knows the file, so nothing restarts from zero between engagements. The work ships blind, under NDA, with your name on it or none at all. Built for single-family offices, heritage-house CMOs, sports-ownership groups, and the agencies that white-label our production. The relationship is the product; the merch is the proof of it.
SFO · Chief of Staff desk. Principal household, properties, aircraft, yacht, calendar, philanthropy — one file.
Heritage houses. LVMH / Kering / Richemont tier. Brand-standards cleared. Onboarding, ambassador, press-moment production.
Sports ownership. Suite activation, principal-box, championship, sponsor co-branded. ALSD-circuit visibility.
Foundations + capital campaigns. Annual reports, gala programs, donor recognition, named-chair objects.
Peers + vendors. Commercial printers routing Komori capacity · brand manufacturers seeking distribution · creative agencies white-labeling production.
Shop seventy thousand products. Virtual proof on every one. 24/7.
Drop your logo on any product and see the virtual proof before asking. Quote routes direct to the desk. MCP catalog for AI agents. Celeste for the fast conversation. Full self-service checkout in development.
70,000products
200+authorized brands
Every SKUvirtual proof
24/7open catalog + concierge
TUMIYETIPATAGONIATITLEISTCALLAWAYVINEYARD VINESCUTTER & BUCKCOLUMBIANIKEUNDER ARMOURNORTH FACECARHARTTSTANLEYHYDRO FLASKS'WELLMOLESKINELEATHERMANBOSEJBLAPPLE TUMIYETIPATAGONIATITLEISTCALLAWAYVINEYARD VINESCUTTER & BUCKCOLUMBIANIKEUNDER ARMOURNORTH FACECARHARTTSTANLEYHYDRO FLASKS'WELLMOLESKINELEATHERMANBOSEJBLAPPLE
Your program
Generate a program in 30 seconds
Date, headcount, tier. Live per-attendee pricing.
Start →