Every board I sit in front of eventually asks some version of the same question. Are we moving fast enough on AI. It's the right question, asked slightly wrong. The question that actually determines the outcome isn't speed. It's what the AI is running on underneath.
I've spent enough years in this industry to recognize a pattern when it repeats itself. A genuinely transformative technology arrives. Everyone races to adopt it. And the companies that win aren't the ones that moved first. They're the ones that built the foundation correctly while everyone else was still celebrating the launch.
Key takeaways
- An AI model's output quality is determined by the governance and completeness of the data it can reach, not only by the model itself. A brilliant model on ungoverned data just produces confident versions of your existing governance problem.
- Companies that govern their data first tend to scale AI on stable ground. Companies that prioritize speed of deployment often hit a ceiling caused by a foundation nobody inspected.
- AI data readiness is a business capability as fundamental as compute infrastructure or talent, not a security checkbox bolted on for an audit.
- Boards should ask three sharper questions. What data can our AI systems reach. What could they do with it. Are we governing that continuously, with evidence.
- As AI models commoditize, data governance becomes an increasingly durable competitive advantage that's hard for slower moving competitors to replicate.
The outcome is decided before the model ever runs
Your AI's output quality was determined before a single prompt was ever entered. It was determined by the quality, completeness, and governance of the data that the model can reach. A brilliant model pointed at ungoverned, overexposed, unclassified data doesn't produce brilliant outcomes. It produces confident, fluent, well formatted versions of your existing governance problem, delivered faster and to more people than before. It’s ‘garbage in, garbage out’ at the speed and scale of AI.
This isn't a caveat to bury in a footnote. It's the entire story. Every enterprise racing to deploy copilots, agents, and AI assistants across its operations is making an implicit bet that its data foundation can support what's being built on top of it. Most haven't actually checked.
5 years from now there will be two kinds of companies
I think about the AI landscape five years out in terms of two categories of companies, not one continuum. The first category deployed the best available models, moved quickly, generated a lot of internal excitement, and eventually hit a ceiling they couldn't explain, because their data foundation was never built to support what they were asking of it. The second category moved with what looked, at the time, like more caution. They started with data governance from day 1. They knew what existed, who and what could reach it, and how that access changed over time. When their AI systems scaled, they scaled on solid ground, not on a shaky foundation nobody bothered to take the time to inspect.
I'd rather be boring and right than exciting and wrong on this one. The companies that govern their data first won't just avoid the incidents. They'll compound an advantage the other category structurally cannot catch up to later, for the same reason you can't retrofit a foundation once the building is already standing on top of it.
This is a business capability, not a security feature
I want to correct a framing I hear constantly, including from people inside our own industry who should know better. AI data readiness gets talked about as a security checkbox, something bolted on to satisfy an audit. That framing undersells it badly. This is a business capability, as fundamental to scaling AI as compute infrastructure or talent. You wouldn't scale a machine learning program without GPUs. You shouldn't scale one without knowing what data it can touch and whether that access is governed.
Every company building a trust-layer narrative around AI implicitly agrees with some version of this argument. Where I'd push back is on the framing itself. Trust isn't an abstraction you bolt onto AI adoption after the fact. It's earned, specifically, by governing the data first, not by describing yourself as trustworthy in a funding announcement.
What I'm actually asking boards to do
Stop asking your teams whether you're moving fast enough. Start asking three sharper questions instead:
1. Do we know what data our AI systems can currently reach?
2. Do we know what they could actually do with that access if something went wrong?
3. Are we governing that continuously, or checking once a year and hoping nothing has changed in the meantime?
If your team can't answer those three questions with actual evidence, not confidence, you don't have an AI strategy yet. You have an AI aspiration, and aspirations don't survive contact with a regulator, a board audit, or a bad headline.
The organizations that win with AI over the next five years won't be the ones with the best model. They'll be the ones who governed their data first, and built everything else on top of that. I'd rather this company be remembered for having said that clearly, early, than for having chased a headline about being fast.
See how Sentra builds the data foundation AI strategy depends on. Book a demo
