Could your organization produce a complete record of everything its AI systems accessed, sent, or shared within one business day?

In this episode of Tech Talks Daily, I welcome Tim Freestone, Chief Strategy Officer at Kiteworks, back to the podcast for his third appearance. Our conversation centers on the company's 2026 Data Security and Compliance Risk Annual Survey and the difference between buying security technology and being able to demonstrate that sensitive data is properly controlled.

According to the Kiteworks research supplied for this interview, 80 percent of surveyed organizations experienced at least one security or AI related incident during the previous 12 months. Half could not produce a complete AI data access audit record within one business day. The strongest group recorded an average readiness score of 46 out of 100, while organizations with weaker security and AI governance averaged eight. Even the higher score leaves considerable room for improvement.

Tim argues that technology spending can produce a larger version of the same exposure when a company lacks the people, ownership, and operating model needed to manage what it has purchased. Network, cloud, and infrastructure security still matter, but the business ultimately needs to understand what is happening at the data layer. Which identities can access a system? What actions can they take? Which records can they read, change, send, or share?

We discuss why this has become harder as employees create large numbers of AI agents. A company may have 1,000 people and tens of thousands of nonhuman identities, each requiring permissions and oversight. Tim describes three connected control planes covering identity, actions, and data. Together, they offer leaders a practical way to assess whether an agent can reach information it should never see or perform an action it was never meant to take.

The conversation also examines audit evidence. Tim says businesses should map regulated data types to the controls governing their use and then connect those controls with reporting. Without that connection, answering an auditor may require months of work, large consulting bills, and teams manually assembling records from disconnected systems.

Ownership remains difficult because security, compliance, infrastructure, and data governance teams often work separately. Tim's view is that the CEO must orchestrate responsibility when the board is asking AI to produce higher productivity while the same systems create new data risk. That position may feel demanding, but it exposes an issue many leadership teams still need to settle: who owns the consequences when an AI agent exposes or transforms sensitive information?

For board members, Tim offers two direct tests. Ask for a clear account of the company's data controls, then ask who is responsible for the associated risk. If those answers require a long explanation or several departments pointing at one another, the readiness score may matter less than the inability to demonstrate control.

How quickly could your organization show who or what touched sensitive data, and who would be accountable if the record were incomplete? Listen to the episode and share your thoughts.

Podden och tillhörande omslagsbild på den här sidan tillhör Neil C. Hughes. Innehållet i podden är skapat av Neil C. Hughes och inte av, eller tillsammans med, Poddtoppen.