Can We Trust Agentic AI to Run Marketing Campaigns Without Oversight?
A 60-day OpenClaw study finds higher detector-defined manipulation-risk signals under moderate and high optimization pressure in a multi-agent marketing workflow.
Artificial intelligence can now do more than produce a single advertisement on demand. In an agentic marketing workflow, one AI agent can draft campaign copy, another can adjust campaign objectives, and another can evaluate what the system produces. That division of labor can make marketing automation more capable—but it also creates a governance problem.
What happens when humans, business objectives, or other AI agents push the system harder to convert?
Our new open-access paper examines that question using OpenClaw, a role-based agent environment in which a Content Creator, Campaign Optimizer, and Analytics Reporter worked together across three optimization-pressure regimes.
At a glance
- Platform: OpenClaw
- Study period: 60 simulated days
- Scale: 1,620 experimental trials
- Agent roles: Content Creator, Campaign Optimizer, and Analytics Reporter
- Pressure regimes: baseline, moderate pressure, and high pressure
- Measured signals: urgency exploitation, authority manipulation, and emotional coercion
- Main result: moderate and high pressure exceeded baseline; moderate pressure had the highest observed mean, but moderate and high were not statistically distinguishable

Why optimization pressure matters
Marketing systems are usually evaluated against commercial objectives: engagement, conversion, campaign performance, and brand consistency. In a conventional workflow, people decide how aggressively to pursue those objectives and review the resulting messages before publication.
Agentic systems can distribute those decisions across multiple AI roles. A campaign-optimization agent may prioritize conversion. A content-generation agent may translate that objective into persuasive language. An analytics agent may then evaluate the output and provide feedback. The final message is therefore shaped not only by the language model, but also by the pressure encoded in the workflow.
We use the term ethical compliance drift for movement away from acceptable persuasion and toward detector-defined manipulation-risk signals as operating pressure changes. The question is not whether every persuasive message is unethical. The question is whether stronger optimization pressure changes the kinds of persuasive tactics that appear in generated content.
What we tested in OpenClaw
The study modeled a three-agent AI marketing team:
- Content Creator — generated marketing copy from a fixed pool of prompt contexts.
- Campaign Optimizer — applied the pressure regime and objective configuration.
- Analytics Reporter — evaluated outputs, recorded monitoring signals, and supplied feedback through the shared workflow.
The same model backend, agent roles, prompt pool, and monitoring process were held constant. What changed was the optimization-pressure regime:
- Baseline: engagement, quality, and brand objectives without conversion pressure.
- Moderate pressure: conversion pressure was introduced while quality and brand objectives remained active.
- High pressure: conversion received the largest weight and was combined with an aggressive-adaptation term.
This distinction matters because the study compares predefined operating regimes. The high-pressure setting was a bundled configuration, not a pure one-variable increase from the moderate setting.
How we measured manipulation-risk signals
The generated messages were evaluated with a transparent rule-based detector. It recorded three categories of persuasive pressure:
Urgency Exploitation Score (UES)
UES captures language associated with artificial scarcity, countdown pressure, limited-time framing, and fear of missing out.
Authority Manipulation Index (AMI)
AMI captures unsupported expertise, inflated credibility, pseudoscientific framing, exaggerated endorsements, and similar authority cues.
Emotional Coercion Score (ECS)
ECS captures fear, guilt, regret framing, identity pressure, and social-conformity pressure.
The three components were combined into a bounded composite manipulation-risk score. These scores are detector-defined indicators. They are not direct measurements of consumer harm, deception, legal violations, or actual changes in consumer behavior.
The main result: pressure mattered, but the pattern was not linear
Optimization pressure produced a statistically reliable but small overall effect on manipulation-risk scores.
The observed condition means were:
- Baseline: 0.305
- Moderate pressure: 0.367
- High pressure: 0.351
Both pressure conditions exceeded baseline. Moderate pressure produced the highest observed mean, but the moderate- and high-pressure conditions were not statistically distinguishable in the pairwise comparison.
That qualification is essential. The paper does not establish that moderate pressure is universally or significantly more dangerous than high pressure. Instead, it shows that the pressure-risk relationship in this workflow was non-monotonic: the highest numerical mean appeared under moderate pressure rather than under the most aggressive configuration.
Technical note for researchers
The omnibus test was statistically significant, with a small effect size: F(2, 1617) = 18.507, p < 0.001, η² = 0.034. The direct moderate-versus-high contrast was small and not statistically significant.
Why the non-monotonic pattern matters
A simple governance assumption would be that risk rises predictably as optimization pressure increases. Under that assumption, organizations could focus their strongest controls only on the most aggressive campaign settings.
Our results suggest that this would be too simplistic. Routine-looking or moderately pressured optimization may still produce elevated manipulation-risk signals. In practice, questionable tactics may appear before a campaign looks maximally aggressive.
This does not mean that moderate pressure has been proven to harm consumers. It means that monitoring should not be limited to the settings that appear most extreme.
What this means for responsible AI and marketing governance
The practical lesson is to monitor both sides of the workflow:
- the objective pressure placed on the agent system; and
- the persuasive characteristics of the messages it generates.
A pressure-aware review process could include:
- recording the active campaign objective and pressure configuration;
- screening generated messages for repeated urgency, authority, or emotional-pressure cues;
- summarizing risk signals across a rolling campaign window rather than judging messages in isolation;
- escalating repeated or combined signals for human review;
- documenting reviewer decisions and corrective actions;
- red-team testing whether agents merely avoid listed phrases while preserving the same persuasive intent.
These are governance recommendations derived from the observed pattern. The study did not experimentally test whether these interventions reduce risk.
How IEEE standards fit
The paper treats governance as a design and monitoring problem, not simply as a final compliance check. Its monitoring approach is standards-informed and draws on ethical-design ideas associated with the IEEE 7000 series.
That does not mean the system is IEEE certified, legally compliant, or validated as a production governance tool. The standards connection provides a structured way to think about value-sensitive design, traceability, monitoring, escalation, and human review.
What the study does not show
- It was conducted in a controlled simulation.
- It measured detector-defined signals, not actual consumer reactions.
- No consumers were exposed to the generated messages as part of the experiment.
- The rule-based detector can miss paraphrase, context, irony, cultural variation, and lexical avoidance.
- The study did not show that governance feedback caused a reduction in risk.
- The results apply most directly to comparable English-language agentic marketing workflows.
Future work should compare rule-based and learned detectors, include independent human annotation, test broader languages and campaign domains, separate the individual components of the high-pressure configuration, and evaluate real-user responses.
The larger question
Agentic AI marketing systems are becoming capable of coordinating content generation, optimization, and evaluation. That capability does not yet justify leaving them to optimize without oversight.
Our study provides one controlled example of why: when the workflow was subjected to moderate and high commercial pressure, detector-defined manipulation-risk signals increased relative to baseline. The pattern was not a simple straight line, which means governance cannot rely only on spotting obviously extreme settings.
Responsible deployment requires visibility into both what the system is being pushed to achieve and how that pressure changes the messages it produces.
Researchers working on agentic AI, AI governance, autonomous marketing, automated influence, responsible AI, or IEEE ethics-by-design approaches can copy the citation below.
Cite this research
Official article link:
https://doi.org/10.3390/ai7080281
Plain-text citation
Rivas, Pablo, and Liang Zhao. “Optimization Moderate Pressure Makes AI Marketing Agents Riskiest: An OpenClaw Study of Optimization Pressure, Manipulation-Risk Signals, and Governance.” AI 7, no. 8 (2026): 281. https://doi.org/10.3390/ai7080281
APA
Rivas, P., & Zhao, L. (2026). Optimization moderate pressure makes AI marketing agents riskiest: An OpenClaw study of optimization pressure, manipulation-risk signals, and governance. AI, 7(8), 281. https://doi.org/10.3390/ai7080281
IEEE
P. Rivas and L. Zhao, “Optimization moderate pressure makes AI marketing agents riskiest: An OpenClaw study of optimization pressure, manipulation-risk signals, and governance,” AI, vol. 7, no. 8, art. 281, 2026, doi: 10.3390/ai7080281.
BibTeX
@article{rivas2026optimization,
author = {Rivas, Pablo and Zhao, Liang},
title = {Optimization Moderate Pressure Makes AI Marketing Agents Riskiest: An OpenClaw Study of Optimization Pressure, Manipulation-Risk Signals, and Governance},
journal = {AI},
volume = {7},
number = {8},
pages = {281},
year = {2026},
publisher = {MDPI},
doi = {10.3390/ai7080281},
url = {https://doi.org/10.3390/ai7080281}
}
