Data Access, Not Models, Will Determine Enterprise AI's Ceiling
AI is forcing a reckoning with a problem enterprises have been deferring for decades. Organizations are sitting on vast, untapped data assets accumulated across the business. AI offers the first real opportunity to put this data to work, yet it also represents the biggest constraint on AI adoption: specifically, how little of its enterprises’ data can actually be used.
The vast majority of enterprise data sits ungoverned, unaudited, and effectively off-limits to the AI systems that need it. Most executives assume the biggest AI advantage comes down to model choice, but when everyone has access to the same frontier models, it offers no advantage. The real differentiator is the governance gap: the distance between the data a company holds and what it can prove it’s entitled to use. This determines how much of your data is not just accessible but safe to put to work, separating companies that experiment with AI from those that extract long-term value.
The Governance Gap Predates AI; AI Just Made It Impossible To Ignore
Enterprises have been gathering decades’ worth of data assets and making ad hoc decisions about who could access it and for what purpose. On a human scale, the consequences of missing governance layers seemed manageable, if even preferable, to the cost of compliance. Seen as a cost to be minimized rather than an investment, governance technology lagged further behind the pace of data collection.
Armed with petabytes of data, enterprises have been eager to adopt the latest frontier AI models. Menlo Ventures found 2025 enterprise spend on generative AI increased more than 300%, from $11.5 billion to $37 billion in just 12 months. A recent survey from my company, Prosper Insights & Analytics , found that 53.8% of executives and business owners already use generative AI at work, whether for content creation, research, or personal assistance. AI has permeated even the highest layers of enterprise and exposed the increasing gap between data availability and the feasibility of using it responsibly.
Existing Enterprises Risks
While AI adoption accelerates, stagnant data governance leads to unaudited, potentially private data flowing into models and increased AI security incidents. Stanford’s AI Incident Database logged 362 documented AI incidents in 2025, up 55.4% from the year before .
Meanwhile, regulators are increasingly tackling the growing problem with significant financial penalties. The European Union’s GDPR, designed to protect individuals’ data privacy and security in the EU, carries fines of up to 4% of companies’ global annual revenue. The EU AI Act introduces penalties of up to €15 million, or 3% of global annual turnover, for high-risk AI systems that fail to comply. In the US, companies have been fined up to $1.4 billion, the amount Texas recovered from Meta in 2025 for unlawfully collecting personal data.
Financial penalties are based on the premise that enterprises should know what data they hold and justify how they use it whenever a regulator asks. Claiming ignorance is not a sufficient legal defense, and without critical data governance infrastructure, it is the only answer most enterprises can give when a regulator asks why an AI model has accessed a specific dataset.
The Governance Gap Is Growing Exponentially
The window to build necessary infrastructure is closing faster than most executives realize. Gartner projects the average Fortune 500 company will use 150,000 agents by 2028, up from 15 in 2025. Compliance was already behind, buried in manual risk and privacy reviews. Every new agent integration adds more, and the reviews pile up faster than any team can manage as each agent makes its own data-access decisions in real time.
Forrester’s threat research found that 63% of organizations still have no formal AI governance policy, and 97% of organizations that already suffered an AI-related breach had no proper AI access controls in place when it happened. Four in five security teams say they’ve directly observed risky behavior from their own deployed agents. The gap between AI usage and AI preparedness has become impossible to ignore.
Cillian Kieran, Founder and CEO of Ethyca , a governance company that controls what enterprise data AI systems can use and enforces it in real time, has spent years watching that gap widen. His AI governance platform, Astralis, currently runs inside a major US financial institution at 6,000 requests per second. “We passed the point of human review a long time ago,” he says. “As AI agents become increasingly autonomous, trusting AI-integrated workflows means trusting the guardrails built to keep your information safe while still utilizing its potential. You cannot put a person behind every request an agent makes amid hundreds of millions of requests each day. Security must be built in, not bolted on.”
A Data Architecture Problem Hiding Inside An AI Strategy Problem
AI strategy decisions are made in boardrooms; data architecture decisions are made by engineering teams. The result is a structural disconnect: the people responsible for AI outcomes don’t own the data infrastructure those outcomes depend on, and those who do rarely have the mandate or visibility to fix it at the right level. While leadership is drawn towards the most advanced model, the bottleneck lies in governance. By the time the governance gap becomes visible at the executive level – usually resulting from a stalled deployment, or when a regulator starts asking questions – the architectural debt has already accumulated.
Employees and executives sense that uncertainty even without necessarily seeing the mechanics behind it. Prosper’s data found that 39.3% of executives and 36.8% of employees say AI needs more human oversight to be trusted, while 32.5% of executives and 30.9% of employees want more disclosure about the data it uses. Both figures point to the same discomfort: people know AI is already trusted with more than most companies’ infrastructure can account for. That unease often pushes enterprises toward the wrong solution.
Governance As An Accelerant, Not A Brake
AI is increasing risk levels, and most enterprises respond by restricting AI data access until governance catches up. That approach treats governance as a problem to solve, rather than the infrastructure to make AI move faster. “Speed and safety are not mutually exclusive. People hear ‘governance’ or ‘harness’ and think of counterproductive protocols that slow things down,” Kieran says. “It’s the opposite - governance, done well, stops being the bottleneck and becomes the infrastructure that determines how far AI can go, and how fast.”
Once data is confirmed as safe to use, it can flow consistently into AI systems, not just reducing review time and accumulated risk, but driving AI adoption forward. Well-defined, enforceable guardrails don’t limit what AI can do with data; they expand it. It’s the shift from asking permission every time to proving trustworthiness at the data layer and putting your most valuable asset to work at the speed AI demands.
Every company in any given industry can license the same frontier model next quarter; but the same can’t be said for proprietary data. The advantage always lies in unlocking the data. Enterprises that keep treating governance as overhead to trim will have to answer to regulators later; others will do the unglamorous work now, before an army of agents set their own rules. The model labs will keep shipping, but the ceiling is determined in-house by how much of your data you can actually use.
Disclosure: The consumer sentiment study referenced above was conducted by my company, Prosper Insights & Analytics . This is the same dataset used by the National Retail Federation, and available from Amazon Web Services, Databricks, and the London Stock Exchange Group for economic benchmarking.