Category: Insights

  • AI readiness is a data problem wearing a technology costume

    Ask an executive team why their Copilot rollout stalled and you will hear about licensing, change management, prompt training. Ask their security office and you will hear the truer answer: the pilot worked too well. It found things.

    An enterprise AI assistant is, functionally, the most diligent employee you have ever hired. It reads everything it is permitted to read, remembers all of it, and repeats it to anyone who asks nicely. If your permissions are wrong — and after fifteen years of migrations and reorganisations, they are — the assistant does not create the exposure. It reveals it, at conversational speed, to whoever happens to be typing.

    The order of operations

    The organisations that deploy AI without incident all follow the same unglamorous sequence. First, an inventory: what exists, where, and how sensitive. Second, containment: withdraw the sharing nobody intended and the access nobody remembers granting. Third, curation: remove the expired, the duplicated and the trivial, because a model grounded on debris produces debris with confidence. Only then, fourth, the AI itself — admitted onto an estate that has been made ready to receive it.

    Every stalled programme we are asked to rescue attempted the fourth step first.

    What “ready” looks like in practice

    Readiness is not a maturity score. It is a short list of provable statements: we know where our regulated data is; no sensitive item is reachable by an audience its owner cannot name; retention is enforced rather than aspirational; and every AI system that touches the estate leaves an audit trail. An organisation that can evidence those four sentences can deploy almost anything. An organisation that cannot should deploy nothing — and most know it, which is why the pilot quietly never leaves pilot.

    Grey Glade prepares estates for AI as a matter of course. If your pilot found things, we should talk.

  • Defensible deletion: the discipline nobody wants and everybody needs

    No one has ever been promoted for deleting data. This single fact explains the state of most corporate estates better than any technology assessment.

    Keeping everything feels safe. It is the opposite. Every record held past its lawful purpose is simultaneously storage cost, discovery burden, breach surface and — newly — AI training material. The email archive from 2011 cannot help you win business, but it can absolutely appear in a regulator’s production request or a copilot’s helpful summary.

    Why “defensible” is the operative word

    Deletion without process is destruction of evidence; deletion with process is compliance. The difference is entirely procedural: a retention schedule grounded in actual obligation, holds that are checked before anything moves, an approval step with a named human, and a disposition log that records what was removed, when, why and on whose authority. Done this way, deletion becomes the easiest control in the estate to defend — you are, after all, executing your own published policy.

    Starting without drama

    The estates that succeed do not begin with the contested material. They begin with the unambiguous: duplicates, expired drafts, departed employees’ scratch space, system logs past their window. Months of quiet, uncontroversial disposition build the muscle — and the audit trail — that makes the harder conversations short. By the time the schedule reaches material anyone cares about, deletion is simply something the organisation does, on schedule, with paperwork.

    Grey Glade’s Compliance & Posture practice runs disposition as a standing programme. The first tranche is always easier than you fear.

  • The permission nobody remembers granting

    Every large organisation’s access model is an archaeological site. Each layer made sense to someone, once. The project site shared with a supplier in 2019; the “temporary” all-staff link created the week before an audit; the guest account belonging to a consultant whose firm no longer exists. Nothing was malicious. Everything accumulated.

    Why reviews fail

    The standard remedy — the quarterly access review — fails for a predictable reason: it asks the wrong person a question they cannot answer. A site owner presented with four hundred names will approve all of them, because approving is one click and investigating is an afternoon. The review completes, the certificate files itself, and the exposure survives, now with a compliance stamp on it.

    Inverting the question

    Remediation at scale works when the question is inverted. Not “who should have access to this site?” but “this item is regulated — who can currently reach it, and can anyone explain why?” Sensitivity-first triage shrinks the problem from millions of permissions to hundreds of consequential ones, each of which can be withdrawn, confirmed or escalated with evidence attached. The long tail is then handled by policy — expiring links, sunset dates on guest access, containers that inherit sensible defaults — so the archaeology never re-accumulates.

    Exposure, treated this way, stops being a periodic scandal and becomes a metric: a number that falls, is reported, and is noticed when it rises. Which is all a risk committee ever wanted.

    The Exposure & Access Control practice produces your first exposure index in two weeks.