
Key Takeaways
- Organizations cannot confidently secure or govern AI when they lack a clear understanding of what sensitive data exists, where it resides, who can access it, how it is classified, and what AI-enabled systems can reach.
- Addressing this challenge requires a connected approach that combines data discovery, classification, governance, protection, and remediation within a sustainable operating model. Without this foundation, organizations risk making AI adoption decisions based on incomplete information.
- The cost of inaction is both a user impact, with employees and customers exposed to data mishandling and lost trust, and a business impact, with higher breach risk, compliance exposure, and stalled AI ambitions.
- AHEAD combines strategic advisory services, best-fit data discovery and classification, governance and enforcement capabilities, and ongoing operationalization to help organizations establish the visibility and control needed for responsible AI adoption.
The Critical, Missing Step in AI Adoption
Enterprise AI adoption is accelerating faster than many organizations can establish confidence in the data these systems access. Sensitive information is dispersed across cloud platforms, SaaS applications, collaboration tools, and legacy repositories, while much of that data remains unknown, unclassified, misclassified, or inadequately governed. As a result, critical controls such as data loss prevention, labeling, access governance, and AI oversight often operate on incomplete visibility and inconsistent data foundations.
Generative AI amplifies these challenges by increasing the speed and scale at which users can discover, access, and combine information. Existing issues such as oversharing, weak classification, excessive permissions, and fragmented ownership become more consequential when exposed through AI-enabled experiences.
The most significant enterprise AI security challenge lies not with the model itself, but with the quality, visibility, and governability of the underlying data estate. It proposes a layered approach that integrates data strategy, discovery, classification, governance, and remediation to establish a stronger foundation for AI adoption.
AHEAD’s Better Together approach, which combines strategic advisory services with best-fit data discovery and classification capabilities and Microsoft Purview’s governance and protection, provides a practical framework for improving AI readiness, strengthening governance, and reducing data-related risk at scale.
AI Readiness is a Data Readiness Challenge
Artificial intelligence is transforming how organizations access, analyze, and use information. As AI becomes embedded across productivity, collaboration, analytics, and business applications, the effectiveness of security and governance increasingly depends on the quality and visibility of the underlying data estate. Organizations that lack a clear understanding of their sensitive data, ownership models, access permissions, and classification posture face greater challenges governing AI safely and effectively. In this environment, AI readiness is fundamentally a data readiness challenge.
The Shift in Enterprise Risk
Enterprise security has traditionally focused on infrastructure, endpoints networks, identities, and applications. While these controls remain essential, AI is shifting attention toward the data itself.
Unlike traditional technologies, AI derives value from the information it can access. As a result, AI security is inseparable from data security and governance. Even well-secured environments can introduce significant risk when sensitive data is overshared, poorly classified, stale, or lacks clear ownership. AI amplifies these conditions by increasing the speed and scale at which information can be discovered and used.
This shift carries direct user impact and business impact. For employees, poorly governed data means an AI assistant can surface files, records, or conversations they were never meant to see, eroding trust in the tools they rely on every day. For the business, it means leaders may approve AI initiatives without knowing what those tools can expose, turning a productivity investment into a latent liability.
This is dangerous because the same capability that accelerates work also accelerates exposure.
What’s so wrong with my enterprise data?
Many organizations lack a trusted, comprehensive understanding of their data estate. Sensitive information is distributed across SaaS applications, cloud platforms, Microsoft 365, databases, file repositories, and legacy systems, often without consistent inventory or classification.
This visibility gap weakens downstream controls. Data loss prevention, labeling, access governance, compliance monitoring, and AI oversight all depend on accurate data discovery and classification. When foundational data intelligence is incomplete, governance becomes less precise, investigations become more difficult, and risk decisions rely on assumptions rather than evidence.
Why This Problem Matters Now
The rapid adoption of generative AI has increased the urgency of this challenge. Solutions such as Microsoft Copilot operate within existing permissions and access models, making longstanding issues such as oversharing, excessive permissions, and inconsistent classification more visible and impactful.
For business and technology leaders, the question is no longer whether to adopt AI, but whether the organization’s data foundation can support it responsibly. Without confidence in data visibility, classification, and governance, organizations risk either exposing sensitive information or limiting the value AI can deliver. Addressing this challenge requires a stronger foundation of discovery, classification, governance, and remediation to enable secure and scalable AI adoption.
AI Readiness Reality Check
Industry research highlights a growing gap between AI adoption and data governance maturity. IDC found that 90% of organizational data generated in 2022 was unstructured, 50% of organizations reported that much of this data remained siloed, and 22% cited unnecessary data duplication due to limited visibility into existing information assets. At the same time, 84% of organizations were using or evaluating AI technologies, while 49% expressed concerns about exposing proprietary information to large language models.
Operational security findings reveal similar challenges. Concentric AI reported that 16% of business-critical files were accessible to unauthorized users, with organizations averaging approximately 802,000 overshared files and 87,000 incorrectly classified business-critical files. IBM’s 2024 Cost of a Data Breach Report further found that 35% of breaches involved shadow data and 40% involved data distributed across multiple environments, contributing to an average global breach cost of $4.88 million.
Together, these findings reinforce a critical reality: AI does not create underlying data security and governance challenges. It amplifies them. As AI expands the speed and scale of data access, existing weaknesses in visibility, classification, permissions, and ownership become increasingly difficult to manage and more consequential to business outcomes.
Technical Background & Problem Definition
Enterprise AI security challenges are rooted in the growing complexity of modern data estates. Sensitive information is distributed across cloud platforms, SaaS applications, collaboration tools, databases, file repositories, archives, and legacy systems, often without consistent visibility, ownership, or classification. As AI becomes embedded within business processes, these longstanding data management challenges become more consequential because AI operates on the information already available within the environment. Understanding the relationship between data sprawl, classification, governance, and access is therefore critical to managing AI-related risk.
Data Sprawl Across the Enterprise
Modern enterprise data is highly distributed across platforms, repositories, and business functions. Even within a single ecosystem such as Microsoft 365, sensitive information may reside across Teams, SharePoint, OneDrive, Exchange, and connected applications, each with different sharing and access models.
The challenge is not simply knowing where data is stored, but understanding what data exists, how sensitive it is, who owns it, how it is shared, whether it is duplicated, and whether it can be accessed through AI-enabled workflows. As environments grow, organizations often develop a fragmented understanding of their data, limiting the effectiveness of security, privacy, and governance programs.
Dark Data and Classification Challenges
Dark data extends beyond unused information to include unknown, unclassified, misclassified, stale, duplicated, or orphaned content whose risk characteristics are not well understood. Similarly, classification challenges are not limited to missing labels. They also arise from inconsistent labeling practices, outdated taxonomies, disconnected policies, and limited adoption across platforms.
Because classification serves as the foundation for many security and governance controls, weaknesses in this layer create downstream challenges. DLP becomes less precise, governance efforts become less targeted, and organizations struggle to prioritize remediation based on actual risk.
How AI Amplifies Existing Risk
AI does not create most data risks; it accelerates existing ones. Generative AI increases the speed, scale, and accessibility of information by enabling users to locate, summarize, compare, and recombine content through natural-language interactions.
As a result, issues such as oversharing, excessive permissions, stale content, and weak classification become more impactful. AI systems operate using existing permissions and available content, which means poorly governed data can be surfaced more efficiently without introducing a new technical exploit.
Why DLP Alone Is Not Enough
Data Loss Prevention (DLP) remains a critical security control, but its effectiveness depends on accurate discovery, classification, and context. When organizations lack visibility into sensitive data, ownership, and access patterns, DLP policies are forced to make decisions based on incomplete information.
This often results in either excessive alerts that reduce analyst confidence or overly narrow policies that fail to identify meaningful exposure. Effective DLP therefore relies on a strong data intelligence foundation rather than policy tuning alone.
The Critical Role of Ownership and Data Context
Technology alone cannot solve data governance challenges. Effective governance requires clear ownership, business context, and accountability for sensitive information.
Without identified owners, organizations struggle to classify data consistently, remediate exposures, retire stale content, and make informed AI enablement decisions. Ownership provides the context needed to determine business value, regulatory obligations, retention requirements, and appropriate access controls. As a result, many enterprise AI security challenges are not solely technical issues but governance and accountability challenges as well.
Threat & Business Impact Analysis: What are the Risks of Outdated Data Governance?
The combination of growing data complexity and accelerating AI adoption creates security, compliance, operational, and strategic risks that extend beyond traditional data protection concerns. When organizations lack confidence in the location, sensitivity, ownership, and accessibility of their data, AI can amplify existing weaknesses and increase the consequences of outdated governance practices.
These risks are not abstract. Each one carries a tangible user impact on the employees, customers, and teams who depend on trustworthy data, and a measurable business impact on cost, compliance, and growth. Understanding both is essential, because the organizations that manage this well treat it as a coordinated change management effort rather than a series of isolated technical fixes.
Security Risk
Organizations that cannot effectively discover, classify, and govern sensitive data struggle to assess what AI systems can access and whether existing permissions align with business intent. The resulting risk extends beyond external data loss to include internal oversharing, unintended retrieval, excessive access, and the continued exposure of sensitive information that is no longer needed. AI does not need to bypass security controls to create risk. It can expose existing governance gaps by operating within permissions and data-sharing models that are already misaligned with organizational expectations.
The user impact is immediate. Employees may unintentionally access sensitive HR, financial, or customer information through AI, reducing trust in data protection. For the business, oversharing increases the risk of intellectual property exposure, compliance violations, and costly security incidents, often remaining undetected until after the damage has occurred.
Compliance and Privacy Risk
Weak data inventory and classification practices increase compliance and privacy risk by making it difficult to consistently identify, protect, and manage regulated information. Organizations may struggle to demonstrate where sensitive data resides, how it is governed, and whether appropriate controls have been applied. As AI introduces new methods for retrieving and synthesizing information, gaps in permissions, retention practices, and data governance become more significant, increasing the challenge of maintaining audit readiness and regulatory compliance.
For the business, this translates into failed audits, regulatory fines, and reputational damage that far outweigh the cost of prevention. For users, it means the personal and customer data entrusted to the organization may be mishandled without anyone realizing it. The problem is particularly dangerous because compliance gaps often surface only during an audit or investigation, when it is too late to act.
Operational Risk
Poor data visibility creates operational inefficiencies across security, governance, IT, legal, privacy, and business teams. Security analysts spend more time investigating noisy alerts, data owners struggle to support remediation efforts, and governance teams face challenges enforcing policies consistently across complex environments.
Rather than appearing as isolated incidents, these challenges often manifest as delayed decisions, recurring remediation backlogs, inconsistent governance outcomes, and reduced confidence in security controls.
The user impact is real and ongoing. Security analysts burn out chasing false positives, data owners are pulled into remediation they are not equipped to handle, and business teams lose productivity navigating unclear ownership and inconsistent controls. The business impact compounds over time as decisions slow, backlogs grow, and confidence in security erodes. This quietly drains capacity from the very teams expected to enable AI safely.
Strategic Risk
The most significant long-term risk is the inability to adopt AI with confidence. Organizations that lack visibility into their data environment may delay AI initiatives, deploy them without adequate safeguards, or overestimate the effectiveness of existing controls.
Leading organizations recognize that AI readiness depends on data readiness. Achieving sustainable AI adoption requires confidence in data discovery, classification, permissions, governance, and operational processes. Without this foundation, AI initiatives may increase risk faster than organizations can manage it.
As a result, teams might either avoid AI out of caution or adopt it without guardrails, and neither path delivers value. The business impact is a stalled innovation agenda and lost competitive ground while more prepared peers move forward with confidence.
Executive AI Readiness Assessment
Executive teams should be able to answer the following questions with confidence:
- Where is our most sensitive data located?
- How much of it is classified accurately?
- Who owns it?
- Who can access it today?
- What can Microsoft Copilot access?
- What can third-party AI tools access?
- Which repositories present the greatest AI exposure risk?
If these questions cannot be answered with evidence, AI governance decisions are being made on assumptions rather than facts.
Why Traditional Approaches Fall Short
Many organizations have invested in security, governance, and compliance technologies, yet continue to struggle with data-related risk. The challenge is rarely the absence of tools. More often, it stems from fragmented processes, incomplete data intelligence, and operating models that were not designed for AI-enabled environments. As AI increases the accessibility and value of enterprise data, organizations must move beyond isolated controls toward a more integrated approach to discovery, governance, and risk management.
Tool Ownership Does Not Equal Risk Reduction
Owning security and governance tools does not guarantee effective outcomes. Many organizations have deployed DLP, data governance, cataloging, and Microsoft security capabilities while still facing challenges with unclassified data, excessive sharing, unclear ownership, and inconsistent controls.
Without accurate context about data sensitivity, ownership, and access, even mature technology investments can deliver limited risk reduction.
Point Controls Create Fragmented Outcomes
Traditional security programs often evolve as collections of independent controls managed by different teams. Discovery, governance, DLP, access reviews, and AI enablement may each improve individually, while the broader data risk picture remains fragmented.
This approach becomes increasingly difficult to sustain in AI-driven environments, where data and workflows span multiple platforms, repositories, and business functions.
Governance Requires Reliable Data Context
Effective governance depends on a clear understanding of data inventory, sensitivity, ownership, and access. When that context is incomplete or outdated, policies become difficult to apply consistently, and governance decisions lose precision.
The challenge is often not governance intent, but the lack of sufficient visibility to enforce governance effectively at scale.
DLP Without Discovery Is Reactive
DLP remains a critical control, but it performs best when supported by strong discovery and classification practices. Organizations that rely primarily on policy tuning often find themselves responding to alert noise, false positives, and coverage gaps rather than addressing root causes.
A sustainable DLP strategy requires a reliable foundation of data intelligence, ownership, and risk context.
AI Changes Traditional Security Assumptions
Many legacy security models rely, in part, on the practical difficulty of locating and assembling information across dispersed repositories. AI fundamentally changes this dynamic by enabling users to retrieve, summarize, and connect information through natural-language interactions.
As access to information becomes easier, the protective value of obscurity declines. Organizations must place greater emphasis on data discovery, permissions management, classification, and governance to ensure that AI-enabled access aligns with business and security requirements.
Building a Sustainable Data Security Foundation for AI
Building a sustainable data security foundation for AI requires a coordinated approach that connects data visibility, classification, governance, and risk management. Organizations must understand where sensitive data resides, ensure it is properly classified and protected, identify how AI can access it, and continuously monitor and improve controls as data environments evolve. The following six steps provide a practical framework for reducing AI-related risk and enabling responsible AI adoption:
- Establish Unified Data Visibility: Organizations need visibility across SaaS, cloud, on-premises, and Microsoft 365 environments. Beyond inventory, this requires understanding what data exists, where it resides, how it is shared, who owns it, and which AI-enabled systems can access it.
- Strengthen Classification at Scale: Effective classification must span structured and unstructured data while supporting both business and regulatory requirements. Labels alone are insufficient. Organizations must ensure classifications accurately reflect content sensitivity and drive meaningful governance and protection outcomes.
- Align Security and Governance Controls: Discovery, classification, labeling, DLP, access reviews, and governance should operate as interconnected processes rather than independent functions. When aligned, discovery improves classification, classification enhances policy accuracy, and policy outcomes inform remediation and ongoing governance efforts.
- Understand AI Reachability: Knowing where sensitive data exists is only part of the equation. Organizations must also understand which users, copilots, agents, applications, and AI services can access that information. AI risk is determined not only by data sensitivity, but by the combination of content, permissions, and access pathways.
- Operationalize Continuous Improvement: Data environments evolve continuously as repositories grow, permissions change, projects end, and new AI capabilities emerge. Sustainable risk reduction requires clear ownership, ongoing monitoring, remediation processes, and governance reviews to ensure improvements remain effective over time.
- Lead with Governance and Change Management: Sustainable data security is not only a technical outcome. It depends on people and process. Clear ownership, adoption of new practices, stakeholder alignment, and accountability determine whether improvements in visibility, classification, and governance take hold and endure, minimizing disruption for users while protecting business value.
What is AHEAD’s Recommended Data Security and Governance Framework?
Addressing AI-related data risk requires more than deploying additional controls. Organizations need a structured approach that combines strategy, visibility, governance, and operational execution to create a sustainable foundation for AI adoption. AHEAD’s Better Together approach aligns data discovery, classification, protection, and governance to improve both AI readiness and long-term risk management.
Strategy First
AHEAD begins by helping organizations define the underlying business and data challenges before implementing technology. This approach aligns stakeholders, identifies priority repositories and workflows, assesses governance maturity, and establishes a roadmap tailored to the organizations objectives.
By focusing on data visibility, classification quality, ownership, access, and risk, organizations can move beyond tool-centric discussions and toward a more sustainable operating model.
Because lasting risk reduction depends on adoption, AHEAD embeds governance and change management from the outset, aligning stakeholders, defining data ownership, and preparing teams for new ways of working. This directly reduces user impact by minimizing disruption and giving employees clarity on their responsibilities, and it strengthens business impact by ensuring investments translate into durable, measurable outcomes rather than shelfware.
Establish the Discovery and Classification Foundation
Effective governance begins with understanding the data estate. AHEAD helps organizations improve visibility across cloud, SaaS, on-premises, and Microsoft 365 environments while identifying sensitive data, ownership gaps, and areas of concentrated risk.
A dedicated data discovery and classification capability plays a key role in this phase by accelerating discovery and classification, enabling organizations to better understand where sensitive information resides, how it is exposed, and which areas should be prioritized for remediation. AHEAD remains tool-agnostic, selecting and integrating the discovery and classification solution that best fits each client’s environment and objectives.
Strengthen Protection and Governance
With stronger data intelligence in place, organizations can improve labeling, refine DLP policies, prioritize remediation efforts, and make governance decisions with greater confidence.
In Microsoft-centric environments, Microsoft Purview serves as a powerful governance and enforcement layer. Combined with improved discovery and classification, Purview can deliver more effective labeling, data protection, compliance, and policy management outcomes.
Analyze Exposure and AI Reachability
Understanding where sensitive data exists is only part of the challenge. Organizations must also understand who and what can access it.
AHEAD helps clients assess exposure by analyzing permissions, sharing practices, repositories, user groups, and AI-enabled workflows to identify combinations of sensitive content and broad access. This reachability analysis provides a more accurate view of potential AI-related risk and remediation priorities.
Operationalize for Long-Term Success
Sustainable risk reduction requires more than one-time assessments or technology deployments. Organizations need clear ownership, governance processes, remediation workflows, reporting, and ongoing review mechanisms to maintain progress as data environments evolve.
By operationalizing governance and accountability, organizations can ensure that improvements in visibility, classification, and protection remain effective as repositories change, ownership shifts, and new AI capabilities emerge.
Operationalizing these gains is fundamentally a change management effort. AHEAD helps clients establish the ownership, training, communication, and review cadences that keep new controls effective as the organization evolves. For users, this means data protection becomes a natural part of how they work; for the business, it means risk reduction and AI readiness are sustained rather than eroding after the initial project ends.
The Role of Discovery, Classification, and Governance in the Technical Story
Secure AI adoption requires both strong data intelligence and effective governance. Organizations that focus exclusively on discovery may gain visibility without improving control, while those that focus only on enforcement often struggle with inaccurate or incomplete data context. AHEAD’s Better Together approach addresses both challenges by combining strong data discovery and classification capabilities with Microsoft’s governance and protection framework to create a more complete and sustainable data security model.
Microsoft Purview as the Governance and Enforcement Layer
Microsoft Purview serves as the governance and enforcement foundation for many enterprises, providing capabilities for sensitivity labeling, DLP, compliance management, access governance, and Microsoft 365 protection.
Purview’s strength lies in translating data intelligence into action. However, governance controls are most effective when supported by accurate data discovery and classification. When organizations have confidence in their data context, Purview can deliver more precise policies, stronger protection outcomes, and greater confidence in AI governance decisions.
The Discovery and Classification Foundation
A capable data discovery and classification platform provides the visibility needed to understand the modern data estate. By discovering and classifying sensitive information across cloud, SaaS, on-premises, and Microsoft 365 environments, these tools help organizations identify exposure risks, ownership gaps, stale content, and areas requiring remediation.
Its value extends beyond inventory. The right discovery and classification capability helps organizations understand what data matters most, where it resides, how it is exposed, and what should be prioritized to reduce risk and improve AI readiness. Because no single tool fits every environment, AHEAD stays vendor-neutral and selects the platform best suited to each client’s data estate, then integrates it into the broader Better Together model.
The Better-Together Model
The greatest value is not delivered by discovery or governance in isolation, but by combining the strengths of both within a unified security and governance strategy.
The discovery and classification layer provides the classification and exposure intelligence needed to understand the data estate. Purview uses that intelligence to drive governance, labeling, DLP, compliance, and protection outcomes. Together, they create a continuous cycle in which improved visibility strengthens governance, stronger governance informs remediation, and remediation further improves data quality and risk posture.
This is the foundation of AHEAD’s Better Together approach. Rather than treating discovery and governance as separate initiatives, AHEAD integrates them into a cohesive framework that connects data intelligence, protection, remediation, and operational governance. The result is more accurate policy decisions, improved prioritization of risk, greater confidence in AI enablement, and stronger long-term security outcomes.
From an architectural perspective, discovery without governance provides visibility but limited control. Governance without discovery provides controls but limited confidence. When combined through AHEAD’s strategic guidance, implementation expertise, and operating model design, organizations gain both the visibility required to understand risk and the governance capabilities required to manage it. This combination creates a stronger foundation for AI readiness, making the Better Together model not simply a technology integration, but a critical enabler of sustainable enterprise AI adoption.
Remediation Paths and Expected Outcomes
Effective remediation should focus on outcomes rather than individual technologies. Organizations must improve data visibility, classification quality, access governance, and policy effectiveness to reduce AI-related risk. This includes identifying and prioritizing high-risk repositories, strengthening classification consistency, refining DLP policies, reducing unnecessary access, and improving understanding of what AI-enabled users and systems can reach.
Equally important is establishing a sustainable operating model with clear ownership, governance processes, remediation workflows, metrics, and ongoing review. Together, these efforts enable organizations to build a more accurate understanding of their sensitive data, improve the effectiveness of security controls, strengthen governance decisions, and increase confidence in AI adoption. The result is a more defensible and trusted data security posture aligned to business and compliance objectives.
Conclusion: Data Security for AI Adoption Confidence
The most significant enterprise AI security challenge is not the model itself, but the quality, visibility, and governability of the data it can access. Organizations cannot confidently secure or govern AI when they lack a clear understanding of what sensitive data exists, where it resides, who can access it, how it is classified, and what AI-enabled systems can reach.
Addressing this challenge requires more than deploying additional tools. It requires a connected approach that combines data discovery, classification, governance, protection, and remediation within a sustainable operating model. Without this foundation, organizations risk making AI adoption decisions based on incomplete information, reducing the effectiveness of both security controls and governance programs.
AHEAD’s Better Together approach is designed to address this challenge directly. By combining strategic advisory services, best-fit data discovery and classification, Microsoft Purview governance and enforcement capabilities, and ongoing operationalization, AHEAD helps organizations establish the visibility and control needed for responsible AI adoption. Together, discovery and governance provide the foundation for understanding, governing, and protecting sensitive data, while AHEAD delivers the strategy, integration, and operational guidance required to turn those capabilities into measurable business outcomes.
Framed simply, the cost of inaction is both a user impact, with employees and customers exposed to data mishandling and lost trust, and a business impact, with higher breach risk, compliance exposure, and stalled AI ambitions. AHEAD closes this gap not only with technology, but with the strategy and change management required to make new controls stick. By aligning people, process, and data intelligence, AHEAD turns AI readiness into a repeatable operating model that reduces exposure while enabling innovation with confidence.
About the Authors
Sara Dokter, Associate Technical Consultant
Sara Dokter is an Associate Technical Consultant in AHEAD’s Security practice, where they support security engineering and consulting efforts focused on helping organizations strengthen data security and reduce risk. Their work centers on cybersecurity, data protection, and addressing modern security challenges across enterprise environments, with an emphasis on safeguarding sensitive information and improving overall security posture. Backed by a foundation in digital forensics and a strong commitment to continuous learning, Sara brings a thoughtful, technically grounded perspective to helping clients navigate evolving data security needs.
Harrison Conley, Principal Technical Consultant
Harrison Conley is a Principal Technical Consultant and Data Security Strategy Lead at AHEAD, where he helps enterprises secure sensitive data, reduce risk, and prepare for responsible AI adoption. With more than a decade of cybersecurity experience, he advises security leaders across regulated and Fortune 1000 organizations, translating complex challenges across data security, AI readiness, and Zero Trust into practical roadmaps and measurable outcomes. Harrison has led high-impact client programs, shaped AHEAD’s data security strategy and services, built the firm’s Cyera and Zscaler services portfolios, and received an AHEAD IMPACT Award in the Consulting & Services category.
Sources
- Concentric AI. (2024, October 28). Data Risk Report: 60% increase in sensitive data oversharing. https://concentric.ai/press-release/latest-industry-data-risk-report-from-concentric-ai-shows-60-percent-increase-in-oversharing-of-sensitive-data-over-the-past-year/.
- IBM. (2024, July 30). IBM report: Escalating data breach disruption pushes costs to new highs. IBM Newsroom. https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs.
- Microsoft. (2024). Data governance and security baselines with Microsoft Purview. https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/data/governance-security-baselines-purview-data-estate-unify-data-platform.
- Microsoft. (2024). Microsoft 365 Copilot blueprint for oversharing. https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-blueprint-oversharing.
- Microsoft. (2025). Use Microsoft Purview to manage data security and compliance for Microsoft 365 Copilot Chat/Cowork. https://learn.microsoft.com/en-us/purview/ai-copilot-cowork.
- Microsoft Tech Community. (2025, August 27). Mitigate oversharing to govern Microsoft 365 Copilot and agents. https://techcommunity.microsoft.com/blog/microsoft365copilotblog/mitigate-oversharing-to-govern-microsoft-365-copilot-and-agents/4448744.
- Muscolino, H., Machado, A., Vesset, D., & Rydning, J. (2023, August). Untapped value: What every executive needs to know about unstructured data (IDC White Paper No. US51128223). IDC. https://resource.itbusinesstoday.com/whitepapers/46231-Box-CPL-Q2-Q3-ABM-DTG-CAN-3.pdf.
- National Institute of Standards and Technology. (2019). Data loss prevention. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=904672.
- National Institute of Standards and Technology. (2024). NIST AI RMF Playbook. https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook.
- National Institute of Standards and Technology. (2026). NIST SP 1800-39 (Initial public draft): Data classification practices. https://csrc.nist.gov/News/2026/sp-1800-39-ipd-data-classification-practices.

;
;
;