'Generative ghosts': what they teach us about digital identity and responsible AI
'Generative ghosts' or deadbots are AI systems capable of producing responses, messages or interactions inspired by a deceased person using available data about them. Although they are an extreme case of digital representation, they help us understand a broader challenge: how to govern AI agents that imitate communication styles, represent users or brands, or act on their behalf.
For businesses, the phenomenon is linked to an increasingly common category: personalised AI agents. These systems can act as digital assistants: prioritising messages, summarising conversations, preparing responses, keeping track of commitments or managing routine interactions. In business processes, they facilitate task automation and support decision-making. They also create risks if there are no clear boundaries around identity, consent and data use.
The paper Generative Ghosts: Anticipating Benefits and Risks of AI Afterlives, by Meredith Ringel Morris and Jed R. Brubaker, uses this term to describe agents capable of producing new content inspired by a person, rather than simply repeating material they created during their lifetime. In a business context, this concept takes to the extreme problems that already affect any generative AI deployment: transparency, data governance, access control, traceability and the risk of impersonation, all of which are issues related to trust in digital identity in the age of AI.
■ Although this is an extreme and even unsettling case, the value of the concept lies in observing what happens when a system speaks, decides or interacts with capabilities associated with a person, role or team. This scenario requires businesses to clearly define identity, permissions, traceability and accountability.
When an agent represents someone, traceability is no longer optional.
Corporate data and the limits of representation
At first glance, a company's internal information is the perfect raw material for building these types of AI solutions: internal documents, meetings, corporate chats, tickets, knowledge bases, emails or customer interactions. But accumulating information is not the same as understanding its context, nor does it legitimise every possible use of those resources.
The challenge arises in three areas: abundant but incomplete data, information created for different purposes and decisions that depend on undocumented variables. In generative AI, it is important to distinguish between the availability, quality and suitability of data, and even whether there is a right to use that data for a specific purpose.
Having data is not the same as having the context or the right to use it.
Why data is not always enough to represent context accurately
A model can analyse thousands of documents and identify language patterns, recurring priorities or common responses. The challenge lies in capturing factors that are not always documented: informal agreements, exceptions, business criteria or nuances in a customer relationship.
In a business environment, this limitation is fundamental. A system may have access to documents, messages or procedures, but that does not mean it understands every nuance of a customer relationship, an expert's judgement or the implications of a sensitive decision.
An agent can identify patterns, but it cannot always grasp the judgement behind a decision.
Digital identity: context, permissions and purpose
In business environments, information sources serve different purposes and do not have the same level of sensitivity. An email, a ticket, a meeting, a knowledge base or a customer interaction each provides different signals and requires specific permissions, purposes and limits on use.
That is why any AI agent operating on corporate information must be built with clear criteria governing what data it can use, for what purpose and for how long. The choice of sources shapes its responses and, in business contexts, can create risks related to privacy, bias or the use of data out of context.
Each data source requires a purpose, permission and limit on its use.
The limits of AI: what is not documented
Many business decisions depend on tacit knowledge: customer context, business priorities, accumulated experience or professional judgement. Some of this knowledge does not appear in documents, tickets or databases, which limits the inferences an AI solution can make using recorded information alone.
That is why an agent can be useful for retrieving information, assisting with tasks or preserving knowledge, but should not be presented as a substitute for professional judgement. For a business, the distinction between assistance and delegation must always be clear.
Assistance should not be confused with replacing professional judgement.
From digital assistants to enterprise agents
The evolution of digital assistants is moving towards agentic systems capable of carrying out tasks, consulting internal information and coordinating steps within business processes. The question is not limited to what they automate: the rules under which they operate and how their activity is supervised also matter.
AI agents capable of automating tasks and operating across business processes can consult internal information, prepare responses, coordinate workflows or support customer service processes. The opportunity is clear, but it requires boundaries, supervision and traceability. Automation only delivers value if the business knows what it is delegating, with what permissions and under what controls.
Automation only delivers value if the business knows what it is delegating and how it is controlled.
Transparency: knowing when an AI is speaking
Another important lesson concerns transparency. The more natural an interaction becomes, the more important it is to know whether a person, an AI system or an assistant acting on someone's behalf is responding. This clarity helps prevent confusion, manipulation or loss of control.
The EU Artificial Intelligence Act (AI Act) reinforces this by including transparency obligations for certain interactive systems and content generated or manipulated by AI. For businesses, its impact goes beyond regulatory compliance: it requires them to review processes, responsibilities and controls, as we explain in these 10 key points on the impact of the Artificial Intelligence Act on businesses.
Transparency informs the user; governance defines what the system can do and how it is controlled.
AI agent governance: what businesses need to control
Conversational experiences will become increasingly natural as AI models improve. But a seamless interaction does not make a solution secure, reliable or suitable for a business.
Current models can make up details when they cannot find enough information, imitate patterns without understanding the full context and generate responses without knowing the actual priorities of the user, team or function they support.
That is why businesses need to define controls before deploying personalised AI agents: which sources they can consult, which actions they can perform, what limits apply to them, how their responses are supervised and how their access is revoked when it is no longer required. This approach is aligned with the principles of generative AI governance, particularly when models operate on internal information or can influence decisions, communications or business processes. Without this discipline, a useful tool can become an operational blind spot.
When an agent can perform actions, access systems or coordinate processes, the risk is no longer merely conversational but operational. That is why agentic AI in business operations requires controls over permissions, authorised actions, human oversight and responses to errors or misuse. Frameworks such as the NIST AI Risk Management Framework help structure this discussion: governing, mapping, measuring and managing risks throughout the lifecycle of AI systems.
■ Cost and operational sustainability also matter. Building and maintaining advanced systems requires infrastructure, high-quality data, security controls, human oversight, update processes and even cultural and strategic transformation. Without this foundation, the promise of productivity can become a new source of risk.
Without controls, a useful agent can become an operational blind spot.
Expert knowledge, continuity and bias in the business
Preserving expert knowledge can deliver value: capturing lessons learned, documenting decisions or facilitating the transfer of experience when a professional changes roles or leaves the company. But not all knowledge should be turned into an agent, nor is all historical data suitable for training one.
If only certain voices, documents or profiles are preserved, systems can amplify existing biases and provide an incomplete picture of the business. Data governance must take representativeness, quality, currency and context into account.
Preserving business knowledge also requires deciding what should not be automated and what is best kept under human judgement.
Privacy, consent and operational security
The extreme case of the generative ghosts mentioned at the beginning highlights an idea that applies to any business: legal and operational certainty depends on how data is obtained, how its use is explained and the extent to which users can consent to, restrict or revoke that use.
In a corporate environment, the risks include impersonation, loss of control over generated messages, reuse of data outside its original context or the creation of assistants that appear to have authority. The 'AI-generated' label helps, but it is no substitute for clear policies, technical controls and well-defined responsibilities.
Before deploying personalised agents, businesses should answer some basic questions: who authorises their creation, who validates their responses, what data they can consult, what actions they can perform, who audits their activity and when they should stop operating.
■ Privacy, security and consent must form part of the system's design, governance and day-to-day operation. Here, a Zero Trust approach applied to enterprise AI, copilots and agents helps avoid implicit trust, limit privileges and continuously verify access.
Conclusion
Generative ghosts provide a useful warning: they show what can happen when an AI system adopts the traits of a person or brand using data associated with them and generating messages that others may interpret as coming from that person or brand. In a business context, this challenge appears in more everyday forms through agents that respond, make recommendations, automate tasks or take part in business processes.
That is why businesses must define the conditions under which these systems operate: authorised data, appropriate permissions, adequate supervision and the ability to audit or revoke access.
The adoption of personalised AI agents should be assessed on more than their ability to save time or improve digital interactions. It should also be measured in terms of control, traceability, security and alignment with responsible AI principles. In practice, their value will increase when they operate within clear, verifiable and secure boundaries.
The value of AI depends on it operating within clear, verifiable and secure boundaries.
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities