Most organisations have adopted AI tools broadly. Far fewer have worked out what that means for the data sitting underneath them, and I’d put myself in the group still thinking it through.
The Adoption Ran Ahead Of The Understanding
Copilot is in wide use. At the same time, staff have ChatGPT and Claude open in a browser, putting work material into systems nobody here has assessed. Those tools also crawl what’s in OneDrive or Google Drive unless somebody has physically turned that off. The exposure builds from hundreds of small decisions, made by people getting on with their jobs, not from one taken at a leadership level.
Something else is happening alongside it. You no longer need to be a developer to write software, or to pick up something somebody else wrote. Anyone can build a tool and put it out into the world now, and there’s a lot of it about.
The Money Is Going Somewhere Else
Organisations are spending on cyber, on infrastructure, on adopting AI itself. The data underneath all of it gets comparatively little. Data security outside of cyber gets less again.
That’s the part I find hardest to explain to people. The tools being bought are real and the risks they address are real. It’s the thing they all sit on top of that keeps missing out.
I’m Not Arguing Against Any Of It
These systems are efficient. I use them. I can get a job done in thirty minutes that used to take most of a day, and I’m not giving that back.
What I can’t tell you yet is what it means to have software acting on our behalf, at speed, with whatever access somebody handed it at setup and nobody has reviewed since. I don’t think anyone has properly grasped that one, and I’d be suspicious of anyone who says they have.
So the question I’d start with is narrow and boring rather than strategic. What can these tools already reach today, before anybody widens what they’re allowed to do?
