Somewhere in most large companies right now, a group of people is trying to answer a tough question: what should our AI be allowed to do, and what should it refuse? If you look around the room, it's a mixed bag of perspectives. Legal is there. Compliance is there. A risk lead, maybe someone from the AI safety side. The people who spend their time thinking about what the company actually stands for, the brand strategists, are almost never in it.
That's odd, because it's their question.
"What should we refuse to do" is not, at its core, a legal question. It's a question about identity. And identity is the thing the brand team has spent years defining, writing down, and defending. The answer everyone is straining to build from first principles is already sitting in a document, and it's called the brand strategy.
But does it sound like us?
There is no shortage of talk about brand and AI. Almost all of it lives at one altitude: does the output sound like us?
A whole category of tools now exists to keep AI-generated content on-brand, Frontify, Jasper, Writer, and others, checking tone, flagging off-brand phrasing, making sure the colours are correct. Brand governance is going strong. Alongside it sits "brand safety", an idea borrowed from advertising, mostly about making sure a machine doesn't place your ad next to something ugly. Both are real problems. Both are the output layer. They ask whether the thing the AI produced looks and sounds like you.
That's the shallow version of the question. The deeper version isn't "does this content sound like us", it's "does this deployment reflect who we are". Should we automate this decision at all? Should our AI do this thing quickly, or is slowness part of what we promise? Those are not tone questions. No amount of brand-voice tooling touches them, because they're decided long before anything gets generated.
Two rooms that should be one
What's happened is that two conversations have grown up separately and never been introduced.
One is AI ethics and governance: fairness, bias, transparency, safety. Serious, well-staffed, and largely framed as a compliance discipline. The other is brand strategy: purpose, positioning, personality, big idea. Also serious, also well-staffed, and treated as a marketing discipline. The two rarely share a table, and when the "what should our AI do" question comes up, it lands on the governance side by default.
But walk through what a brand strategy actually contains and it reads like the missing half of an AI policy. Brand purpose is a statement about what a company believes people are for, which is the exact question underneath every contested AI decision: should this be handed to the machine? Brand positioning is a decision about where you intend to be different and distinctive, which is a map of where AI's pull towards sameness is most dangerous to you specifically. Brand personality is a description of how you want to behave in an interaction, which is a behavioural brief for any agent acting in your name. The brand book isn't adjacent to these decisions. It's the argument for them, and it's already written.
Apple let strangers check its homework
When Apple built the cloud half of Apple Intelligence, it had a problem that was really a brand problem. Apple has always stood for privacy. It has spent years telling people that what happens on your iPhone stays on your iPhone. So a feature that sends your data off to a server to be processed is, for Apple specifically, a threat to the one thing it stands for most loudly. A company with a different promise wouldn't have felt the same pressure.
What Apple did with Private Cloud Compute in 2024 is the tell. Rather than ask people to trust its privacy claims, it published the actual software running the service, built a research environment so security researchers could inspect and verify it, and offered bounties for anyone who could catch it breaking its word. That's an expensive, brave choice. You only make it if "trust us" is precisely the phrase your brand can't afford to use. Apple's brand didn't just shape the marketing. It decided how the thing got built: make it so outsiders can check it, because being taken on faith is the opposite of what Apple sells.
Take Patagonia and Goldman Sachs. They could licence the identical AI tool tomorrow and would be right to deploy it completely differently, not only because regulators treat them differently, but because they stand for different things. A brand whose whole promise is human craft and irreplaceability should be making different automation decisions from one built on speed and scale. That difference is a brand output. It's just not currently being seen as one.
This is the logic we're following at Sideways, at a far smaller scale and still in progress. We're building a tool that scores how trustworthy an organisation is, and the positioning has already made the hard calls for us: a tool that measures trust can't itself be a black box you take on faith, so it has to be open about how it reaches a score. We didn't reason our way there from a risk register. The brand got there first.
Read the brand book
So the challenge is simple: stop building your AI ethics from first principles, and start reading your brand book.
This isn't a claim that brand replaces governance. Bias, privacy and safety are their own disciplines and they're obviously important. It's a claim that the hardest, least technical question, what this company should and shouldn't let a machine do, has a better answer sitting in a document most AI committees have never opened. Gartner expects at least fifteen per cent of everyday work decisions to be made autonomously by AI by 2028. Every one of those is a small statement about identity.
You already have the most sophisticated filter for those decisions that your organisation has ever produced. You're just using it to check the colours.
Sideways is a behavioural design practice for regulated businesses. We treat brand strategy as a working tool for AI decisions, not a coat of paint applied after they're made.