Four copies of a brand

The industry has found an answer to producing with AI: every tool gets its own copy of the brand. Only, you cannot ask a copy.

Microsoft’s Copilot can now learn a brand. A brand manager uploads the guidelines, Copilot extracts colours, voice and rules. From one PDF. Exactly one: to upload a new one you have to delete the old one first, and the new values override the previous ones, brand voice included.

Canva keeps its own brand kit, with logos, colours, fonts and templates. The agency works from its deck. And somewhere sits the brand book all three were once copied from. That is four versions of the same brand, and each ages at its own pace.

All four answer the same kind of question: which blue, which logo, which typeface. Questions you look up. The questions that only come up during the work, none of them answers.

A campaign takes shape in Canva. Visuals, ads for twelve formats, all with the tool’s AI. The brand kit knows the colours. Whether the visual fits the brand’s personality and whether the claim has been approved, it does not know. The team decides that from memory, variant by variant. At the fourteenth something is off, and nobody can say what.

Whether the fourteenth variant is still the brand is written in none of the four copies. Nobody did anything wrong. The tool did what tools with copies do: it guessed.

Consistent is not coherent

In each of the fourteen variants the colours are right. That is consistency. Whether the fourteen together still add up to one brand is coherence.

Consistency can be looked up. Colour values, logo variants, type weights, the whole corporate design, plus binding product names and writing rules. These are questions with one right answer, and once a machine has the answer it sticks to it. Coherence arises one level up, in the brand’s layer of meaning. Whether this visual fits it, or whether we may claim that, cannot be looked up anywhere. Each time it is a judgement about a single case.

For a machine to take part in that, every rule needs a test question, one that shows whether a draft holds to it. A rule you cannot think of one for is not a rule. It is a mood. Authentic, approachable, empathetic: that is how many brand books read, and for people the image is enough. For a machine it is not a language. How many such moods sit in a brand book only becomes apparent when a machine asks for them.

The reflex at that point is to regulate everything, so the machine cannot get anything wrong. Many brands have been regulated down to the smallest detail over the years anyway, because every new application got a new rule. It does not help here, though. Consistency tolerates many rules, because they are cheap to check. Coherence needs few, and those have to really hold. A brand is recognised by a few things, a colour, a mark, a visual language. The rest assembles itself in the mind. Fix those few hard and you can release the rest. Choosing them is brand management.

A brand you can ask

For consistency there is already a solution, and it is built. The first brand answers agents’ questions itself, publicly and without a login.

Pulumi, a vendor of cloud infrastructure software, runs a server for its own brand at brand.pulumi.com. In mid-September 2026 it held 13 sources to read, among them brand voice, writing rules and binding product names. Alongside them, 11 tools, small functions an agent calls by itself in the middle of the work. Ask whether the brand’s violet is legible enough on white, and a calculated contrast value comes back.

The technology behind it is called the Model Context Protocol, MCP for short, and it has become the standard route by which AI applications reach outside data and functions. A server like this is built for everyone working in the brand’s name: in-house teams, agencies, partners. A second connection is now going to customers’ agents: businesses can submit connectors for Meta’s agent Muse, through which it books and buys.

Pulumi is not alone. Frontify, Canva and Monotype offer something similar or are testing it, and a Belgian agency already advertises that the brand book is dead, long live the brand MCP server. It is not widespread yet.

It is worth a lot all the same. Build twelve formats today and you are working from four ageing copies. With a server you are working from one source that is current, and a change arrives everywhere the same day instead of next quarter. For consistency this is a big step, and it is worth taking even without anything that follows.

Everyone delivers. Nobody decides.

The question an agent really has in the middle of the work is not one you look up. It is: may I say this in the brand’s name? None of these servers answers it.

Pulumi’s list holds no tool that checks a statement. The brand only judges for itself on colours. For copy, images and designs there are three prompts a human has to trigger. Ask it to check a headline and you get back around 33,000 characters of guidelines, and the deciding is left to the model that reads them. Pulumi’s own rules are honest about it: nothing goes out without a human having checked it.

The picture is the same elsewhere. Frontify’s server for brand portals carries a good fifty tools. They read, write and manage what sits in the portal, and Frontify itself advises checking every result before publishing. Through Canva’s server agents create designs and reach brand kits. Monotype has been testing a connector since July 2026 that detects unlicensed fonts. It flags them, nothing more.

This is not a reproach to the vendors. They built the part that can be built for everyone. Handing out rules works the same way for every brand. Deciding statements is something every brand has to do for itself.

Hand out rules only, and you still get a judgement. An anonymous one. A model reads the rules and interprets them, freshly every time, and next quarter it is a different model. Nobody sees how it was decided, and nobody stands behind it. The judgement has no address.

This is the old weakness in a new build. Paul Jun, who leads brand at the US financial software company Ramp, put it in one sentence in an essay in September: “The old system distributed rules without distributing judgment.” The brand book took the rules everywhere and the judgement nowhere. A server that only delivers repeats that. Just faster. It is a brand book with an interface.

Machines have long been able to check. Adobe’s campaign tool shows a percentage for every draft, namely how many of the stored guidelines it passes, and recalculates after every edit. Markup AI, born out of the text checker Acrolinx, flags what does not match the style guide, explains why and offers wording, over MCP as well. Furthest along is pharma. There the pre-check by an agent can be bought off the shelf, as a step before the mandatory approval. And even there it only checks against stored specifications and decides nothing. All three measure the draft against a copy of the guidelines, and none of them says who decided a rule or since when it applies.

The layer you cannot buy

Another tool will not solve this. Coherence needs a layer no vendor can ship, because it looks different in every brand.

The connection is spreading. Logos, colours, fonts and components the machines already fetch themselves. Of 21 open-source design systems, among them those of IBM, Shopify and GitHub, 18 shipped an MCP server of their own by the summer of 2026. Design systems are kits for interfaces, not brand guidelines, but the direction is clear. In two years everyone will have it; by then it is standard equipment and no longer a difference.

What gets delivered through it still has to have been decided by somebody. Which statement is approved, how much a breach weighs, what the brand does not say, where a human takes over and what an agent may do in its name. No model produces that. Every model can build an ad. The question is which commitment it builds from.

An agency writes a LinkedIn post in the brand’s name, and its agent wants to claim the product is cheaper than the competition. It asks the brand first whether it may say that. The answer is no. Price comparisons only with legal approval, a hard limit, decided by this person, in force since this date. The agent cuts the sentence or puts it in front of a human. The agency did not receive a PDF and did not misinterpret anything. It asked, and the brand answered.

An answer like that is short. Yes, no, or “a human takes over”. The third is the most important, because a system that only knows yes and no also decides where it has no business deciding. And every answer carries what a brand book never had: the rule, how binding it is, a date and a name. That makes it an accountable decision.

Most brands are distributed, across agencies, markets and licensees. For them the brand only becomes binding once somebody sets out what applies and what is deliberately left unautomated. Which few things hold hard is known only to whoever leads the brand. That is why the server is the smallest part of the work. The larger part belongs to brand management and cannot be delegated to IT.

That applies all the more to what an agent may do. Which tools a brand gives to which agent is not a technical question. A tool that grants discounts is a power of attorney. That is Agent Authority in its technical form. For access and money there is already software for it: the open-source Olivares keeps every agent’s permissions as a map, reports what an agent does without being allowed to, and writes every call into a signed ledger. For statements made in the brand’s name there is nothing of the kind.

The technology will keep changing anyway. MCP has been through five revisions since November 2024 and may change again. The interface is replaceable. The decisions are not.

Where to start

Not with the server. With a number.

Checking does not have to wait for the next draft. You can run the test questions for the existing rules across what is already there: the campaigns of the last twelve months, the presentations in the shared drive, the answers of the service bot. Out comes a number. How much of what the brand produced last year would it have approved this way? Plus a map of where the deviations sit, in which channel, in which tool, against which rule. That is the inventory that belongs before any commitment, as a run across the existing material rather than a workshop. Three months later the same run shows whether anything has changed, and after every model switch as well.

Then comes the separation: what every agent may read, what it gets on request, and what the brand decides itself. The last list is the shortest and the most important.

For that to hold, the brand has to get out of the shared drive where files sit and age. It needs a versioned form that can show it has an effect. That the five hundredth variant still looks like the brand proves little. What is evidence is that the result changes when you change a rule. The place for that is what I described in Open Brand Repo: somewhere every change carries a date, a reason and a sender.

Honesty requires naming what is still missing. There is no published customer case with numbers for brand servers so far. And a server that is merely there gets barely used. Marc Berg, CEO of Statista, describes how usage of their own server stayed low at many customers and only rose once an agent provided the data in the middle of an editorial workflow. The check belongs where the draft is made. And it has to help people finish faster. Nobody wants the server. Everybody wants the ad that gets through.

In HORIZONT I wrote that somebody has to set out what machines may deliver, that this is not a technical role and that in most organisations it is unfilled. The server makes that role visible, because somebody has to be accountable for the answers it gives. It belongs in brand management.

The address does not have to be the person who does everything themselves. It is the one everybody knows to go to: I noticed something, I report it there, and it gets written down.

Delivering and checking can be automated. Running it can be outsourced. The address cannot.

Read next: Open Brand Repo: Brand Rules Belong in a Repository. →

Terms used in this text: See the glossary →