Your AI Strategy Starts with Your Data

Artificial intelligence is rapidly becoming part of the everyday workplace. Staff are using AI to draft emails, summarise meetings, analyse information, create content and answer questions, often through tools already built into the software businesses use every day.
For business leaders, the question is no longer simply whether to adopt AI. The more important question is, do you know what data your people are already giving AI access to?
Before businesses build an AI strategy, there is a more fundamental piece of work to do: understand the data sitting underneath it.
AI adoption is already happening. Governance needs to catch up.
AI adoption rarely starts with a board-approved strategy. It often starts with an employee trying to solve a problem.
Someone uploads a spreadsheet to a chatbot, uses an AI assistant to summarise a document, or connects an AI tool to their calendar, email or cloud storage. These actions are usually driven by productivity, not malicious intent. The problem is that organisations may have little visibility over what information is being shared, where it is going, or what controls are in place.
“AI is already becoming part of the way people work, whether or not an organisation has a formal AI strategy in place” says Lachlan Gardiner, Chief Commercial Officer at Integrated ICT. “The challenge is making sure data governance can keep pace with that adoption.”
The Office of the Australian Information Commissioner advises a risk-based approach to AI involving personal information, including considering what information is necessary to provide and who will have access to it.
The challenge is that information does not always look sensitive. Meeting notes pasted into an AI tool for a summary may contain a customer's name, a staff member's personal circumstances or details of an upcoming business decision. The task itself feels harmless. The data being shared may not be.
The answer is not necessarily to ban AI but to understand what you have, what your staff are using and where the risks sit.
Your AI strategy starts with your data
Imagine an employee with access to an ownerless SharePoint site of five-year-old documents containing everyday sensitive information. They may have had access for years, but finding it required knowing the site existed and where to look. AI changes that equation.
When an AI assistant is connected to business information, it can make that information significantly easier to discover. Microsoft itself notes that Copilot operates within existing permissions rather than bypassing them. The issue is that poorly governed or overshared information becomes much easier to surface through natural-language queries. That makes one question increasingly important. Who can access this data, and should they?
Businesses should look for data that has accumulated quietly over time. Folders shared with everyone, sites without an owner, old project material, duplicate files, unlabelled sensitive documents and information not accessed for years.
“AI doesn't necessarily create the permission problem. It exposes the permission problem,” says Gardiner. “If someone already has access to information they shouldn't, AI can make that information much easier to find. That is why data governance is becoming an AI security issue.”
Classification matters too. A confidential customer document should not be treated like a public marketing brochure, and labels provide the context to apply different controls.
As AI evolves from simply answering questions to acting on behalf of users, access controls become essential.
Make your data AI-ready before making AI bigger
For businesses wondering where to start, the answer does not have to be complicated.
Start with visibility. Identify what AI tools your staff are already using, including the capabilities built into software you already own. Create a register of approved tools and understand what information each can access.
Assess your data. Look across your Microsoft 365 environment, cloud storage, file servers and other repositories for broad permissions, orphaned sites, unclassified sensitive information and data with no clear business purpose.
Fix the highest-risk areas first. Prioritise personal, financial, commercial or otherwise sensitive information where access is broader than necessary.
Apply appropriate classification and permissions. Make sure sensitive information is clearly identified and access is limited to people who genuinely need it.
Review what should still exist. Old information creates risk as well as clutter. Retention and disposal policies should be part of the conversation, particularly where legal, regulatory or contractual obligations apply.
Finally, give employees clear rules for AI use. People need to know which tools are approved, what information can be entered and when human review is required.
AI presents enormous opportunities for productivity, customer service and operational intelligence. The organisations best positioned to benefit from AI will not necessarily be those that adopt the most tools first. They will be those that understand their data well enough to know what AI should be allowed to see, what it should not, and why.