Why your AI copilot is only as trustworthy as your data governance

As AI agents move from generating insights to acting on them, the quality and governance of the data behind them becomes a boardroom issue, not an IT one. This is according to Wayne Yan, CTO, at Dariel. Who says that dashboards are becoming just one delivery format among many as analytics moves into chat, spreadsheets, workflow tools and, increasingly, AI agents.

“This represents a more fundamental change than simply finding new ways to display information. We are moving from systems that present information to systems that interpret information, formulate conclusions and, increasingly, take action.”

An agent may act on our behalf, accessing data directly or indirectly, interpreting it, formulating an insight and presenting the result in a conversational or graphical form. It may even use that insight to initiate an action.

But there is an important question we should ask before handing over that responsibility: can we trust the data from which the agent makes its decisions?

“The emergence of AI does not make the fundamentals of data governance less important,” says Yan. “It makes them considerably more important.”

Data protection: who is allowed to access what?

The fact that an AI agent is acting on our behalf does not remove the need for information security. The point at which an agent accesses a data source remains a security boundary. Someone, or something, must have the authority to cross it.

This introduces an interesting question around agent identity. Does an agent take on the identity and permissions of the person who initiated it? Does it have its own identity and permissions? Or does it operate through some form of delegated authority? These questions become even more important when agents interact with other agents.

The fundamental principle should remain unchanged: an agent must never acquire authority simply because it has acquired capability. Identity, roles and permissions must continue to determine what information can be viewed and, critically, what information can be changed. Read access and the ability to mutate data are not equivalent forms of authority. As agents become capable of acting autonomously, these principles become more important, not less.

Data integrity: can the agent trust what it sees?

The second fundamental is data integrity. For an agent to produce a useful inference, the underlying data needs to be more than merely available. It needs to be accurate, current, complete and appropriate to the decision being made.

The digital representation of the world almost always lags behind reality. A customer’s status may have changed five minutes ago. An order may have been cancelled. Inventory may have been consumed. A financial transaction may not yet have been posted. The data may therefore be perfectly accurate while still being too old to support a particular decision.

“An intelligent decision made from yesterday’s truth may still be a very bad decision today,” Yan notes. “AI does not solve this problem. In fact, it can make it harder to see. An agent can produce a remarkably convincing explanation from data that is fundamentally unsuitable.”

The sophistication of the inference does not compensate for the quality of the evidence.

Ownership: who is responsible?

The third fundamental is ownership. If agents are going to make inferences and take actions based on organisational data, someone must remain accountable for the quality and appropriate use of that data. “That responsibility is fundamentally human,” says Yan.

Data must have owners and stewards who understand what it represents, where it originates, how it should be maintained and what constitutes acceptable quality. “Data quality is not a once-off cleansing exercise; it is an ongoing responsibility. Nor can responsibility simply be transferred to the AI because the AI made the decision. If the underlying data is wrong, incomplete, stale or misunderstood, the resulting intelligence is compromised before the agent has even begun to reason,” says Yan.

AI makes governance more important, not less

The promise of AI is not simply that it can tell us what the data says. It is that it can reason over that data and potentially act upon the conclusions. That changes the risk equation. A poorly governed dashboard might lead a person to make a bad decision. A poorly governed agent could make that decision itself, and execute it, at machine speed and potentially at enormous scale.

“AI is data-intensive in a way few technologies have been before,” Yan says. “If you intend to use AI to solve real-world problems, the foundations matter. Protect the data. Maintain its integrity. Establish clear ownership and accountability. Your AI may be intelligent, but its trustworthiness will ultimately depend on the data environment in which that intelligence operates.”


About Dariel

Founded in 2001 on the principle of delivering solutions right, the first time, Dariel bridges the gap between human ingenuity and technology. Our strong client partnerships reflect a commitment to excellence and our consultative approach to software engineering makes us a trusted partner for innovative and sustainable tech solutions. Proudly independent, Dariel is part of the JSE-listed Capital Appreciation Group. https://www.dariel.co.za/

For more information:

Samantha Hogg-Brandjes | GinjaNinja | [email protected] | +27-84-458-4857

Related Articles

Latest Articles