Poor permissions, unmanaged content, weak governance and inconsistent processes can remain hidden for years. AI has a way of uncovering the ugly truth.
AI systems can access and summarize any data a user’s permissions allow, surfacing files, records, and information that were previously hard to stumble across. That makes long-standing gaps in access control, data governance, and process discipline immediately visible.
In most cases, AI is exposing problems that already existed, such as excessive permissions, outdated data, and undocumented workarounds. AI doesn’t create these risks; it makes them far easier to find, by employees and potential bad actors alike.
Before scaling AI adoption, review user permissions, clean up outdated or duplicate data, document who owns key information and processes, and put clear AI governance policies in place covering tool usage and data sharing.
AI governance works best when ownership is assigned to a person, not left to a general policy or a committee. Someone, typically IT leadership working alongside data owners across the business, needs clear accountability for permissions, data quality, and acceptable use.
Track AI spending centrally rather than letting individual departments purchase AI tools independently. Understanding total licensing, consumption-based pricing, and infrastructure costs across the organization helps prevent overlapping capabilities and runaway spend.
Most organizations have some of this. That’s not an indictment of you or your organization. Nor is it of IT in general. It’s just what happens over time.
People come and go. They change roles but keep old permissions. Files and data accumulate. Version control rarely happens. New applications get added. Processes evolve. Workarounds that were supposed to be temporary somehow become permanent.
As long as everything keeps working, we learn to live with it. People have day jobs. They are busy. Introspection and retrospection rarely take precedence over “just get it done”.
AI changes all of that.
Give AI access to your environment and it becomes very good at finding information—sometimes information you didn’t realize was there or didn’t realize someone could access.
Take permissions. An employee may technically have access to thousands of documents they would never stumble across in the normal course of their job. In the past, that wasn’t always obvious because they had to know where to look.
With AI, they can simply ask or worse yet, AI can outright recommend it!
If their permissions say they can see it, AI may find it for them.
AI didn’t create the problem. It exposed a problem that was already there.
The same is true of data and content. Years of documents, emails, spreadsheets, databases and collaboration sites don’t magically become clean and organized because we connect AI to them. Conflicting information can produce conflicting answers. Old information becomes easy to find again. Sensitive information buried somewhere for years may suddenly be very easy to discover.
AI isn’t creating the mess. It’s turning on the lights, and you’ll be forced to look in that mirror.
Governance is more than an AI policy.
We absolutely need rules around which AI tools people can use and what information can be shared with them.
But we also need to ask some basic questions.
Who owns the data? Who should have access to it? What should we keep? What’s the authoritative source when we have three versions of the same thing? Who is responsible when an AI-enabled process gets something wrong?
None of these are particularly new questions. AI is just making it much harder to avoid answering them. And that’s not necessarily a bad thing.
Sometimes your best people are masking your worst processes.
An inherently inefficient process can become surprisingly efficient when it is performed by people who know it exceptionally well.
They know the shortcuts. They know the workarounds. They know which spreadsheet needs to be updated manually and exactly who to call when something doesn’t reconcile.
Eventually, it looks like a pretty good process. But it is holding you back.
AI and automation can expose that too.
The tricky part comes when you change it.
A fundamentally better process can feel worse at first because you’re comparing something new with something people have spent years learning how to make work.
You’ll hear, “The old way was faster.”
And initially, they may be right!
That’s where good change management matters. You need to listen to the people who know the process but hold true to fixing the things that need fixing. Train people properly. But don’t mistake the discomfort of change for evidence that the old process was better.
Give a well-designed process time to bed down and the result should be simpler, more consistent, easier to scale and less dependent on a few people knowing all the tricks.
There will always be an answer. Sometimes you must work through the change long enough to get to it.
There is a cost dimension as well.
AI experimentation can start inexpensively. Enterprise AI adoption is different.
Licensing, consumption-based pricing, cloud infrastructure, data preparation, integration, security and the growing number of vendors charging premiums for AI functionality can add up quickly.
The bigger risk may be allowing AI spending to develop the same way many technology environments developed: one reasonable purchase at a time, distributed across the organization, until nobody has a complete picture of what is being spent or where capabilities overlap.
Eventually, somebody must explain the bill to the CFO. That will likely be YOU.
None of this should scare us away from AI.
I think it’s an opportunity.
If AI exposes permissions that don’t make sense, fix them.
If it exposes bad data, clean it up.
If it identifies a process held together by workarounds and institutional knowledge, build a better one.
If costs are growing without clear ownership or return, get your arms around them.
These are all solvable problems.
The important thing is to look for them before AI finds them for you.
The organizations that do that work aren’t slowing down AI adoption.
They’re building the foundation that will allow them to accelerate it.
AI will expose you. The question is whether you’re ready for what it finds.
What would AI uncover in your organization today and are you ready to face up to it?
If you’re not sure what AI would find in your environment, permissions, data, processes, or costs, that is exactly the picture our Cybersecurity Risk Assessment is built to give you. Let’s find it before AI does.
Ready to talk it through? Contact us and let’s get started.
Thanks for reading,
Dave
Related Insights
AI will expose you. Are you ready?
Poor permissions, unmanaged content, weak governance and inconsistent processes can...
Read MoreAvoiding AI Data Leaks: Governing All of Your AI, Not Just Copilot
Part 1 sorted your Copilot agents into three tiers of...
Read MoreIs Your Microsoft 365 Environment Actually Ready for Copilot? The Governance Checklist to Run First
In the first piece, I made the case that Copilot...
Read More
