Everyone wants to use AI. Boards are asking about it. Leaders are beingpressured to demonstrate progress on it. Vendors are selling it. And somewherein the middle of all of this, practitioners are being handed tools and told tomake them work, often without the foundational questions having been askedfirst.
This piece is for those practitioners.
The conversation around AI adoption has a tendency to skip straight tocapability and land on risk as an afterthought. What can this tool do? Howquickly can we implement it? What does it cost? These are not irrelevantquestions, but they are the wrong starting point.
The right starting point is information security. Specifically, it is the CIAtriad: Confidentiality, Integrity, and Availability. If you are not familiarwith it, read this first. If you are,keep going.
The problem with AI adoption in most organisations
AI tools, at their core, are hungry. They ingest data, process it, and generateoutputs. The quality, safety, and legality of everything they produce isdirectly dependent on the data going in.
Most organisations are adopting AI tools while sitting on years of poorlygoverned data. Unclassified. Poorly documented. Scattered across systems thatdo not talk to each other. Without clear ownership. Without access controlsthat reflect current reality rather than the state of things threereorganisations ago.
Feeding that data into an AI tool does not make those problems disappear. Itamplifies them.
Confidentiality: Should this data be in your tool at all?
The first question is not “what can the AI do with this data?” It is “who willhave access to outputs generated from this data, and is that appropriate?”
AI tools, particularly those accessed via third party platforms, do not alwayskeep your data contained. In March 2023, Samsung engineers used ChatGPT to helpdebug source code and generate meeting notes. Three separate incidents in undera month. In each case, confidential information, including proprietary sourcecode and internal meeting content, was submitted to an external platform. Thatdata was retained by OpenAI. Samsung could not retrieve it. The companyultimately banned generative AI use across the organisation.
This was not a sophisticated attack. It was employees doing their jobs, using atool that had been made available to them, without adequate governance aboutwhat should and should not go into it.
The question of confidentiality in AI adoption is not hypothetical. It isoperational. Before any data touches an AI tool, you need to know itsclassification. You need to know the terms of the platform you are using. Youneed to know whether personal data, commercially sensitive data, or legallyprivileged data is in scope, and if so, whether the tool is even appropriatefor that use case.
This is where information security and AI governance are not separatedisciplines. They are the same conversation.
Integrity: Can you trust what the AI is working with?
Even if your data should be in the tool, the next question is whether it can betrusted.
AI outputs are only as reliable as the data they are built on. If theunderlying data has not been maintained, is out of date, contains duplicates,or has been altered without adequate change controls, you are not gettingintelligent outputs. You are getting confident-sounding outputs built on acompromised foundation.
This matters particularly in regulated environments. If an AI tool is beingused to support decision-making, that tool needs to be working with data thatmeets integrity standards. Can you demonstrate that the data has not beentampered with? Is there an audit trail? Are there controls in place to flaganomalies?
Integrity failures are not always dramatic. They accumulate quietly. A fieldupdated incorrectly here. A record not reconciled there. Over time the datasetdrifts from reality, and the AI tool processes that drift as though it werefact.
If your organisation cannot currently answer the question “is our data what wesay it is,” deploying AI does not fix that. It just makes the consequences ofthe gap more visible, and potentially more damaging.
Availability: Do you even know where your data is?
This is the one that does not get talked about enough, and in my experience itis where a lot of AI adoption projects quietly stall.
Organisations have data. Often enormous amounts of it. Across legacy systems,cloud platforms, shared drives, email archives, spreadsheets that live on oneperson’s laptop. Accumulated over years with varying degrees of governance anddocumentation.
AI tools can only work with data they can ingest. And they can only ingest datathat someone can locate, extract, and present to them in a usable format.Availability in the context of AI adoption is not just about uptime. It isabout data discoverability. It is about whether your data estate is documentedwell enough for anyone to actually find what they need.
If the answer to “where does this data live?” is “it depends who you ask,” thatis an availability problem. It is also a governance problem. And it willsurface the moment you try to implement an AI tool at any meaningful scale.
This is not a technology problem that AI will solve for you. It is a people,process, and governance problem that needs to be addressed before AI enters thepicture.
Information security is the foundation. AI governance sits ontop of it.
The CIA triad is not new. It has been the bedrock of information securitythinking for decades. What is new is the urgency with which it now needs to beapplied, because the consequences of ignoring it have scaled.
When data governance was primarily about filing systems and access logs, theblast radius of a failure was relatively contained. When the same data is beingingested by AI tools that generate outputs consumed across an organisation, theblast radius is considerably larger.
AI governance is a growing and important discipline. But it does not replaceinformation security governance. It requires it. An organisation that cannotanswer the three questions above is not ready to adopt AI responsibly,regardless of how compelling the vendor pitch was.
Walk before you run. Ask the hard questions about your data before you ask whatthe tool can do with it. Your confidentiality, integrity, and availabilityposture will tell you more about your AI readiness than any product demo.
