AI without governance could come back to bite you

AI governance for enterprise AI

99% of the discussion around generative AI focuses on what the technology might achieve, rather than how to make it work effectively. Organisations are investing heavily in LLMs, PoCs and increasingly expensive tokens, impressed by AI’s ability to generate content, answer complex queries and summarise data.

The bigger question is whether organisations are ready to make an AI into a trusted, business-as-usual infrastructure. The technology can advance rapidly; the challenge is making it trustworthy.

This is unusual for business and IT: LLMs are a new kind of software that doesn’t always behave predictably. Unlike traditional ERP, CRM and other core applications, LLMs can produce unexpected results, making successful deployment more challenging than it first appears.

Trust: hard to come by, but easy to lose

As is well-known, AI failures most often occur because the information feeding into the model is incomplete, inaccurate, outdated, or unverified. While AI can digest enterprise information at great speed, it cannot offset poor information as it doesn’t natively know how to tell the difference.

Left unchecked, AI can take faulty data and amplify any existing weaknesses. As businesses move from one-off pilots to enterprise-wide AI deployment, trustworthy data becomes not just an ethical aim but a technical architecture challenge.

This will only increase in importance as users evolve from actively searching document banks and shared drives to asking questions in natural language and expecting authoritative answers accurate enough to inform material business decisions. This marks a new chapter in how businesses work with information, with huge productivity potential — but those gains must be built on trusted data.

This problem predates AI because enterprise data is rarely as well organised as it should be. For example, organisations might find duplicate documents in multiple repositories, outdated policy records, unsecured sensitive information and many other flaws. Data governance also varies from department to department, with important knowledge often encoded in formats that today’s platforms cannot struggle to interpret.

The question remains, however: how can we move forward and build trust in our data if we want to use it to power breakthrough AI services for us?

Seven possible pillars of AI trust

The following are foundational requirements for trustworthy enterprise AI:

High content quality: Clear control over data quality is essential as information enters the infrastructure, enabling AI to distinguish reliably between accurate information and outdated documentation. Low-quality data equals low-quality results.

Robust, comprehensive governance: Clear rules around data responsibility are essential: who owns data, who can modify it and how sources are maintained. Effective governance provides a structure that prevents AI from generating responses with significant financial or strategic implications based on unreliable sources.

Dependable metadata and context: Business documents derive much of their value from context: when they were created, who approved them, which process they support and how they connect to other information. Accurate metadata helps AI interpret enterprise knowledge reliably and enables users to understand how a given answer was produced.

Bullet-proof security: As AI becomes more deeply embedded in business processes, access control becomes increasingly important. AI must follow each user’s permissions, exposing sensitive financial, legal or customer information only to authorised employees. Trust erodes rapidly when AI uncovers information it should not access.

Strong compliance: AI must operate within rules governing privacy, records management and industry-specific compliance, without overstepping established boundaries. CIOs also need confidence that automated answers remain consistent with the legal and regulatory requirements of each market.

Auditable provenance: Business users need more than an answer; they need to know where it came from. Can the original source or policy be traced? Who approved the data? Has it been updated? Enabling employees to cite authoritative sources ensures AI tools remain accountable and transparent rather than becoming black boxes.

Last but not least, solid data lifecycle management: Data is constantly changing as contracts are renewed, procedures evolve and policies are updated. AI that relies on outdated information cannot be trusted. Effective lifecycle management keeps data current while eliminating obsolete knowledge.

Following these core principles creates the right environment for AI to earn and maintain trust across the organisation. AI does not replace traditional information management procedures; it depends on them. As enterprises increasingly rely on AI for decision-making, mature practices around content management, records, taxonomy, governance and security become ever more important.

AI accelerates the ROI of these systems by making data quality more critical than ever. This brings the final piece of the puzzle into focus: the surprisingly central role of traditional document management systems in achieving AI success.

Enter ECM

Traditionally, enterprise content management (ECM) has been viewed as important operational infrastructure that is, for the most part, invisible. In the context of AI, this changes: ECM moves from being a simple information repository to the foundational knowledge base from which AI tools source evidence, establish context and derive dependable business advice.

AI strategies should be based on a frank assessment of information readiness. Before deploying AI across the business, confidence is needed that data is governed consistently, content can be identified, access controls are robustly enforced and AI responses can be traced back to verifiable sources.

Whether in customer service, legal operations, financial management, healthcare or government, responses must be accountable, making ECM increasingly central to trusted AI. As AI becomes embedded in core processes, explainability and trust matter as much as speed and productivity.

Thankfully, many CIOs already own the necessary infrastructure to support trusted AI. ECM, workflow automation, metadata management and security controls will — and must — all play a role in addressing the information challenges presented by AI. The next step is linking these established tools to modern AI systems rather than treating them as siloed capabilities.

The bottom line is that enterprise AI success depends not only on advances in AI, but on robust information architecture and an effective alliance between new (AI) and old (ECM).

Dr John Bates 2026

Dr. John Bates

Dr. John Bates is CEO of Doxis, a leader in Document Intelligence. A computer science academic at Cambridge University before going on to lead five successful tech companies, Dr Bates developed his doctoral work at Cambridge into a small research team focused on the groundbreaking field of Complex Event Processing (CEP). This work gave rise to an entirely new software category, which he commercialised through his startup, Apama.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE