Every time an employee asks AI to summarize a report, analyze a spreadsheet or improve a draft, something else is happening. Organizational information is moving into an AI system. 

That movement can be easy to overlook. But as AI becomes embedded in everyday work, organizations face a practical question they cannot leave to individual judgment: Who has custody of the information and what happens to it next? 

The uncertainty is already influencing adoption. 

Gallup’s February 2026 study of 23,717 U.S. employees found that, among employees in organizations where AI is available, concerns about data privacy, security and compliance were cited by 43% of non-users and 38% of infrequent users as reasons they do not use AI more often. 

Consumers share the concern. Pew Research Center reported in June 2026 that 71% of U.S. adults believe increased AI use will make their personal information less secure. 

For organizations, the issue is broader than privacy alone. It is an operating question about what information is moving into AI, which systems are receiving it and what rules govern what happens next. 

This is the emerging AI data custody problem. 

More AI Use Means More Data Decisions 

Every time someone uses AI at work, there is potentially a data decision involved. 

  • Can I upload this document? 
  • Could I paste client, customer or donor information into our approved AI tool? 
  • Will AI summarize this internal report? 
  • Can I use AI to analyze this spreadsheet if it includes employee, customer or financial information? 
  • What if I remove someone’s name first? 

Most employees aren’t trying to circumvent company policy when they ask these questions. They’re trying to do their jobs. 

And increasingly, the answer cannot simply be: “Don’t put sensitive information into AI.” 

That may be an appropriate boundary for certain types of information, but it is not a sustainable governance strategy for an organization integrating AI into everyday work. 

The more useful question is: What information can our people share with AI, using which tools and under what conditions and what do they need to do before they share it? 

Answering that requires more than an AI policy. It requires translating policy into shared practice. 

The Gap Between AI Policy and AI Practice 

Organizations clearly recognize the need for AI governance. 

The International Association of Privacy Professionals (IAPP) and Credo AI’s 2025 AI Governance Profession Report found that 77% of surveyed organizations were working on AI governance, rising to nearly 90% among organizations already using AI. 

That’s important progress. But a governance document alone does not answer the dozens of practical questions employees encounter as they integrate AI into their work. 

A policy may establish what information should be protected. Employees still have to apply that guidance in context. The information they need may be scattered across documents, data, meeting notes, internal systems or materials provided by clients and partners. They may need to determine whether some portion of that information can appropriately be used with AI, what preparation or review is required first and which AI environment is appropriate for the task. 

That is where broad policy language can fall short. 

At Human Driven AI, we help organizations translate policy into Data Sharing & Classification guidance employees can apply to everyday work. That means establishing clear boundaries for different types of organizational information and practical guidance for how employees should handle that information when using approved AI tools. 

Governance has to move from rules on paper to guidance people can confidently apply in practice. 

But those boundaries should not be generic. 

Every Organization’s Data Boundaries Are Different 

A healthcare organization, marketing agency, nonprofit, retailer and technology company do not hold the same information. Their employees do not perform the same work. Their contractual obligations differ. Their regulatory environments differ. And the AI tools their organizations have approved may offer different protections. 

Even departments within the same organization encounter different information and different AI use cases. 

Recent provider decisions show why the AI environment matters, too. This week, Axios reported that OpenAI is testing a new approach designed to preserve zero data retention protections for eligible enterprise and API customers, while Anthropic is requiring 30-day retention for certain advanced business models, citing security needs. The point is not that one approach is right and the other is wrong. It is that retention and data-handling practices can differ by provider, model and service tier and they can evolve as the technology changes. 

That is why effective AI governance cannot simply be downloaded, published and considered complete. 

Organizations need to intentionally determine what types of information employees routinely encounter, which information can and cannot be used with AI, when additional preparation or review is required, whether different rules apply depending on the AI tool or platform, and where employees should go when the answer is not clear. 

The goal is not to turn every employee into a data governance expert. It is to reduce the fear and ambiguity that can make AI feel risky, give people confidence to use it safely and responsibly and create more room to build their skills and focus on producing great work. 

Gallup’s research points in the same direction. Employees are more likely to use AI frequently when it fits their workflows, when managers support its use and when organizations provide clear policies. Gallup notes that these practices can reduce uncertainty and build confidence in how AI-related risks are managed. 

Documents Create Their Own Governance Questions 

Data classification is only part of the equation. 

Once AI begins helping employees create, revise or transform documents, organizations need shared expectations for what happens to that work. 

  • Should AI-assisted work be labeled? 
  • When is disclosure appropriate or required? 
  • What level of human review is expected before work is handed off or published? 
  • How should approved versions be retained and superseded drafts handled? 
  • Which strong outputs should become reusable team assets rather than remain scattered across individual chats and files? 

These are not abstract AI ethics questions. They are everyday operating questions. 

That is why our 4Ds of Shared AI Practice™ at Human Driven AI includes both Data and Documents as foundational areas of AI-enabled work. 

Data Sharing & Classification guidance helps employees determine what information can move into an AI-assisted workflow and under what conditions. AI-Assisted Document Standards establish shared expectations for naming and labeling, disclosure and review, versioning and retention and the reuse of strong AI-assisted work as shared organizational assets. 

Together with organization-wide and, where appropriate, department-specific AI policies, these practices create something more useful than a list of restrictions. They create shared ways of working. 

The AI Data Custody Problem Doesn’t Stop at Your Door 

There is another layer organizations are beginning to confront: What happens to company information after you give it to someone else? 

Organizations routinely share information with agencies, consultants, contractors, technology providers and other partners to get work done. Increasingly, those vendors may also be using AI to deliver their services. 

That raises questions many existing AI policies do not answer. 

  • Can a vendor use your documents or data with AI? 
  • Can your information be uploaded, retained or used to improve or train an AI system? 
  • What protections apply to confidential or proprietary information? 
  • Are subcontractors, subprocessors or other AI providers involved? 

This is the external side of the AI data custody problem. 

An organization may establish clear rules for how its own employees use company information with AI. But those rules do not automatically follow the information when it moves outside the organization. 

Organizations can establish AI-specific confidentiality and data-use requirements for paid vendors, consultants, agencies and service providers, with appropriate legal or procurement review. They can also make AI practices part of vendor due diligence by asking new and existing providers for their AI policies and specifically how those policies apply when working with company information. 

Not every vendor relationship carries the same level of risk, and not every organization needs the same restrictions. Appropriate requirements should reflect the information being shared, the work being performed, the tools involved, existing contractual obligations and the organization’s own risk and confidentiality requirements. 

The important shift is this: AI data governance should not end where your organization’s employees, systems or policies end. 

Governance Has to Follow the Work 

The organizations that succeed with AI will not necessarily be the ones with the longest AI policies. They will be the ones that make responsible AI use easier to understand and apply in the flow of work. 

When people understand the boundaries, they can spend less energy wondering whether they are doing something wrong and more energy building their skills, exercising judgment and producing strong work. 

That is governance embedded into adoption; not a policy sitting beside the work, but shared guidance that travels with it from employee to AI tool, document and external partner. 

As AI becomes part of more workflows, the data custody question will become more important. Organizations do not need to keep useful information out of AI indefinitely. They need clear, intentional practices that help people use information responsibly as the work moves across tools and organizational boundaries. 

AI governance must follow the work. 

And that raises one more question organizations providing services to others should be prepared to answer: 

If you’re asking your vendors how they’re using AI with your information, what will you say when your clients start asking the same thing about theirs? 


Remember, AI won’t take your job. Someone who knows how to use AI will. Upskilling your team today, ensures success tomorrow. Custom in-person and virtual trainings are available. If you’re looking for something more top-level to jump start your team’s interest in AI, we offer one-hour Lunch-and-LearnsIf you’re planning your next company offsite, our half-day workshops are as fun as they are informational. And, of course, we offer AI consulting and GEO strategies. Whatever your needs, we are your partner in AI success.

Read more: The Emerging AI Data Custody Problem: Why an AI Policy Isn’t Enough 

Top 10 Things Your AI Policy Should Include

An effective AI policy should help employees make sound decisions when AI shows up in real work. Here are 10 areas organizations should address—from tools and data to AI agents, transparency, records and human accountability.

AI Governance Cannot Stand Still When AI Doesn’t 

AI is changing faster than most organizational policies. As new models, AI agents, disclosure requirements and regulations emerge, organizations need to move beyond static AI policies toward a living governance practice that evolves with the technology and the work.

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading