Govern before adopting: the data discipline required to use AI

Govern before adopting: the data discipline required to use AI

Most work environments use artificial intelligence in some form; this is nothing new. According to McKinsey, 88% of employees regularly use AI in at least one business function. But the challenge of the equation is the discipline surrounding that use.

Read more Thus the United States is managing to extract millions of barrels of oil from Hormuz despite the threat from Iran

That discipline is not advancing at the same pace. Ivanti’s 2026 State of Cybersecurity Report reveals that only 55% of cybersecurity professionals use formal guidelines (guardrails) to govern how AI systems and agents are deployed and operated. In other words, half of the sector relies on individual judgment, on default vendor settings to decide what data can be safely entered into a model.

Data reidentification traps us

The historical assumption that information ceases to be “personal data” once names, emails, or identification numbers are removed no longer holds. When device IDs, IP addresses, behavior patterns, metadata, and precise locations are cross-referenced across different databases, advanced analytics can infer a person’s identity without traditional identifiers. Sounds unsettling, right?

And there’s more: cases of reversal in pseudonymized and de-identified datasets have already been recorded. Even anonymized data — considered the highest standard of data cleansing — has been reidentified in documented cases when combined with sufficiently rich context. For Data Protection Officers (DPOs), this means the category of “non-personal data” has drastically shrunk. In other words, for those entering information into AI tools, the comforting idea of “I don’t include names, so it’s not a problem” is increasingly misleading.

What happens with a prompt?

A prompt is information. It contains everything written in it: client names, strategy documents, source code, or the name of an internal project that no one outside your team should know. As soon as it leaves the browser, it is subject to the retention, review, and training policies of the tool provider.

Although employees try to adjust privacy settings in their tools seeking greater discretion, unfortunately, conversations are stored by default in many corporate AI tools. Disabling chat history does not imply immediate deletion; providers usually retain data for a certain period, often on external servers. Also, if the prompts sent contain confidential material, that information may end up integrated into responses generated for other users of the same service.

Read more Nord Stream Gas Pipeline: Preventive detention in Croatia for sabotage suspect

Govern before adopting

Reminding employees to “be careful” does not constitute a privacy control. A cautious employee still makes decisions under time pressure, and the judgment they apply about whether a roadmap is “confidential enough” to exclude it from a model is not a reliable parameter during a regulatory audit.

The effective strategy is to evaluate tools before introducing them into the corporate environment. This involves understanding what data each tool collects, where it goes, how long it is retained, and what rights the provider claims over it. That work belongs to a governance framework.

The concept of Privacy by Design and by Default has existed as a regulatory standard since the General Data Protection Regulation (GDPR) came into effect. Applying it to AI requires conducting that prior analysis. Once the tool is in use and prompts have been sent, the window for a proper evaluation has closed.

What should we assume from today?

For any organization adopting AI at a faster pace than its governance, I suggest maintaining these three working assumptions:

  1. Data cannot be completely withdrawn once shared with an external AI system.
  2. Anonymized data is not always anonymous.
  3. Default privacy settings benefit the model provider, not your business.

These are current realities, not warnings about a distant regulatory future. When oversight intensifies, supervisory authorities will not grant leniency based on employees’ “goodwill.” And from my perspective, the window to establish real discipline over AI use is narrower than it seems. The tools are already here. The data has already moved. Take control of what you can control, today.

Read more Strong winds and earthquakes: is there really a connection? This is what the experts say

*El Comercio opens its pages to the exchange of ideas and reflections. In this plural framework, the newspaper does not necessarily agree with the opinions of the columnists who sign them, although it always respects them.

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *