+31 6 5747 3070

info@thierit.com

Call Now

Why data classification and data ownership finally need to be taken seriously

Organizations are rapidly investing in AI solutions such as Microsoft Copilot. The promise is substantial: productivity, acceleration, better decision-making. But while attention goes to the possibilities, one fundamental reality is often forgotten:

AI isn’t a risk. AI is a mirror. And that mirror reveals exactly how mature your data governance really is.

What is presented today as “AI risk” is actually the result of twenty years of structural underinvestment in data classification, data ownership, adoption, and governance.


Data classification isn’t new—we’ve just ignored it

With Windows Server 2008 R2, Microsoft introduced File Classification Infrastructure (FCI). An early attempt to help organizations label, classify, and protect their data. The technology existed—but adoption didn’t follow.

I still remember wanting to take classification seriously in the File & Print team at a major financial institution. It was seen as “unnecessary complexity.” The instinctive response was:

“We already have NTFS permissions, don’t we? Why make things complicated?”

The answer arrived a few years later.


When Enterprise Search matured, the governance reality became visible

Around 2007–2010, with the rise of SharePoint Search and later FAST technology, something happened that surprised many organizations—and shocked some.

The nuance is that Enterprise Search simply did what it was designed to do: make information discoverable. But the harsh reality was that many organizations suddenly discovered sensitive documents, salaries, executive bonuses, and confidential reports had been stored incorrectly, classified incorrectly, or left unprotected for years.

Not because Search was dangerous. Because governance had been dangerous all along.

Search was the first accelerator. AI is the hyperaccelerator.


AI is Search on Steroids—and that’s precisely the point

Where Search showed what might be discoverable, AI reveals what is actually accessible.

  • An employee who doesn’t know they have access to a folder also doesn’t know AI can search it.
  • A document stored incorrectly ten years ago is now found in milliseconds.
  • AI doesn’t ignore an incorrectly assigned permission—it uses it.

AI doesn’t look at intent. AI looks at permissions.

That’s precisely why this governance issue is so urgent now.


Over the past fifteen years, many organizations have downsized or outsourced their IT departments

“Lean,” “agile,” “more with less”—but that comes at a price:

  • less time for adoption,
  • less time for governance,
  • less time for data classification,
  • less time for systematic quality control.

That’s exactly where the gaps AI now exposes develop.

AI doesn’t increase risks. AI only increases the visibility of risks that were already there.


5. Why this is now strategic, not just technical

With DORA, NIS2, ISO 27001:2022, and similar frameworks, data classification is no longer a “nice to have” but a leadership obligation.

These frameworks explicitly call for:

  • Data ownership
  • Classification and labeling
  • Access management based on value and risk
  • Continuous insight into where data resides and who can access it
  • Governance that demonstrably works

AI doesn’t make these obligations more burdensome—it makes them unavoidable.


Why a technical expert needs a seat at the boardroom table

Many organizations have organized governance as a paper process. That no longer works. AI doesn’t read policy documents. AI reads data.

That’s why it is essential to have someone at the strategic level who:

  • understands how data behaves,
  • knows how systems interpret permissions,
  • can assess the impact of incorrect permissions,
  • can translate the value of data into policy,
  • can explain risks before they materialize.

As Sun Tzu wrote: “Tactics without strategy is the noise before defeat.” Governance without technical realism is exactly that: noise before defeat.

The best strategic decisions emerge when executives are informed by people who understand how technology behaves in practice.


7. Concrete examples already happening today

  • Copilot surfaces an old HR document that should never have existed.
  • An employee asks AI for “all contracts with supplier X” and receives more than they ever knew they could see.
  • A misconfigured SharePoint site suddenly becomes fully searchable.
  • A folder temporarily opened years ago turns out to remain accessible.

These aren’t hypothetical scenarios. They’re everyday realities.


8. The core issue: value and risk begin with classification

If you don’t know:

  • which data you have,
  • what its value is,
  • who owns it,
  • which permissions it should have,
  • how it should be labeled,

…then AI doesn’t know either. But AI will find it.


Call to Action

1. Make data classification a strategic program, not an IT project.

It’s the foundation of every AI strategy.

2. Establish data ownership at the executive level.

For example, through a formally authorized Chief Data Officer. Not as an additional task on the side, but as a full leadership responsibility.

3. Invest in adoption the way organizations did in the 1990s.

Training, guidance, explanation—not just a link to an intranet page.

4. Stop with “more with less.”

Digital risks are growing faster than the capacity to control them.

5. Make sure at least one technical expert is at the boardroom table.

Someone who understands what AI really does, not just what the marketing promises.


Closing

AI doesn’t change how good or bad your governance is. It only changes how visible it becomes.

The question isn’t whether your organization is ready for AI. The question is whether your data is ready to be found and used.


Originally published on LinkedIn. View all blog posts.