Is your data actually ready for Generative AI? In this video, we dive into why security and compliance are the most critical foundations for any GenAI project. Many organizations rely on “security by obscurity”—the hope that users won’t find data they shouldn’t see.
In this clip from my Pluralsight course on Assessing Data Readiness for Generative AI, we talk about:
✅ Why AI exposes weak access controls
✅ Key security and compliance risks to address before using GenAI
✅ Why security and compliance must be ongoing, not one-time tasks
Take the full course: Assessing Data Readiness for Generative AI
Watch my 100+ courses on Pluralsight
Video Summary
- AI makes hidden data visible – Generative AI can surface documents employees didn’t even know existed. That’s powerful, but risky if someone stumbles across sensitive files they shouldn’t have access to.
- “Security by obscurity” doesn’t work – Many organizations rely on the hope that employees won’t find data. AI blows that up because it amplifies whatever permissions are already in place. If access is sloppy, AI will expose it.
- Lock down permissions before AI projects – The first step in preparing for generative AI isn’t the AI itself—it’s cleaning up data access. Employees should only see what they truly need. This prevents leaks and even improves productivity in everyday tasks like search.
- Compliance is more than a checkbox – Companies must review regulations, privacy rules, and data processing requirements before rolling out AI. For example, if compliance requires data to stay in Europe, but the AI processes it in the US, that’s a problem.
- Ongoing vigilance is key – Security and compliance aren’t one-time tasks. As data, users, and AI evolve, organizations need continuous review and enforcement. It’s a team effort across roles to keep everything aligned and protected.
For more information, read the transcript blog below, or watch the video above!
Transcript
Let’s start by covering the key security and compliance considerations for using generative AI with your data. One of the big benefits of generative AI solutions is that it makes it super easy for users to discover data, even data that they might not have known they had access to. Look at the example here, where the user is simply asking about documents on media communications, and the tool talks about a document called the layoff project plan in 2026.
Now imagine if the user was not supposed to have access to this project or to this document, but now they know about it, even if they didn’t ask about it specifically. Not what we really want. You need to be aware that artificial intelligence tools will amplify your security posture, and too many organizations are currently using security by obscurity when it comes to internal access, which means that they assume or hope that employees will not find or access data because they don’t know about it, even if the users have access to it because of bad permissions.
Now, we’ll be honest, that approach was never good, and adding AI on top of it will make it even worse because AI is an amplifier of your current status. As you work on integrating your data into your Gen AI solution, one of the first things you will need to do is to make sure that each user only has access to the data that they need to have access to in order to do their work and nothing more. And while this course will really focus on the generative AI project, this is something that should be your top priority and something that you should honestly start today. Whether you plan to do your generative AI project in a day or a year from now, securing your data should be a top priority. Securing your data right now will help you prevent data breaches, prevent accidental leaks of data, and it will also improve other employee productivity functions, such as search, for example.
Now, let’s talk about compliance. Each company has different compliance standards that it needs to follow. And as you start implementing a generative AI solution in your organization, there are many things that you need to consider and even more if you want to integrate your data in them. Let’s talk about some of the things that you need to do to prepare from a compliance point of view. First of all, make sure that you know all the different compliance regulations that you need to follow. This way, you can look at the requirements for each one.
Make sure you verify if your chosen generative AI solution shares any data with other customers or trains the public model with your data. We have seen this happen with some AI solutions, so make sure that you know what the privacy implications of integrating your data with that specific AI solution are. You also need to make sure that you understand your data processing requirements and then check if your chosen Gen AI solution will respect those requirements.
For example, would it process any data in the US even if your compliance requirement says that your data must remain in Europe? That might have some big compliance implications. You should also check your chosen Gen AI solution and make sure that there are no features that go against your compliance standards. One example I saw recently was when implementing a copilot at a customer in Europe, they couldn’t use the meeting recap because they were not allowed to record meetings. So that’s one of the examples to look at.
Check all the features and compare them to what is needed for your Gen AI solution. Finally, you need to understand what are the copyright implications of using generative AI solutions with your data and especially with what your employees create. You need to make sure that you maintain that ownership of everything. Also, remember that compliance is a team sport and usually involves multiple people and roles inside the company. So make sure that you involve everyone needed for a full picture of your security and compliance requirements. One important thing to remember is that security and compliance aren’t only a one-time task. As your data, users, and AI capabilities evolve, you need ongoing processes to continuously review, enforce, and improve how your data is protected.