Many organizations are embracing artificial intelligence (AI) to streamline operations and boost team productivity. However, a significant hurdle remains for some: balancing the critical needs of data security with the demand for user-friendly AI tools. Michael Pietsch, VP of DACH at intelligent content management platform Box, suggests that the primary obstacle isn’t the AI technology itself, but rather the quality and accessibility of the data it relies upon. He emphasizes that companies should prioritize organizing and preparing their data before diving into AI implementation.
The AI Dilemma: Security vs. Usability
A common misconception, particularly among small and medium-sized businesses (SMBs), is that AI solutions must sacrifice either robust security or intuitive usability. IT departments often lean towards platforms that meet stringent compliance and governance requirements, which can inadvertently make these tools difficult for employees to access and use effectively. As Pietsch notes, “Employees want tools that feel as easy as the platforms they use at home.” This creates a difficult choice for business leaders, forcing them to pick between a secure but cumbersome system or a user-friendly but potentially less secure option.
However, this trade-off is becoming obsolete. Modern intelligent content management platforms are designed to integrate a consumer-grade user experience with a strong foundation of governance. These systems automate security controls in the background, ensuring that AI remains accessible without compromising safety. For instance, an AI system can precisely track who accesses files, revoke permissions instantly, and automatically enforce security policies.
Streamlining Secure Data Sharing
Consider the traditional process of sharing a sensitive sales proposal with a client. It might involve complex steps like using VPNs, password-protected files, or obtaining explicit IT authorization. The friction in such a process can tempt employees to bypass security protocols, perhaps by sending unsecured email attachments just to expedite the task. When security and usability are harmonized, employees are freed from navigating intricate security measures, as the platform handles these automatically. Platforms like Box, for example, enable AI agents to inherit existing user permissions and compliance controls seamlessly, eliminating the need for a separate, cumbersome governance layer. Pietsch explains, “The AI knows exactly who accesses the file, can revoke access instantly and even apply security policies automatically. Everyone gets what they need.”
Unstructured Data: The Bottleneck for AI Adoption
A significant impediment to widespread AI adoption lies in the condition of the underlying data. When critical information, such as contracts, email correspondence, and presentations, is fragmented across disparate systems, even advanced AI tools struggle to deliver meaningful insights. Consolidating this data provides AI with the necessary context to generate truly valuable results.
Introducing an AI tool into an environment with scattered data results in a limited perspective. “Before companies can really benefit from AI, they need to get their content under control and make sure it’s properly governed,” advises Pietsch. “If data sits in a silo, AI only sees part of the picture.” He elaborates, “Bring everything together, and suddenly AI has the context it needs to deliver really valuable results.”
The Risk of Incomplete Information
Imagine an engineer needing the latest maintenance manual. If engineering drawings are on one server, contracts in another system like SharePoint, and project documents scattered across collaboration tools, the AI might only access an outdated version stored elsewhere. This incomplete data set could lead the AI to confidently provide incorrect information, as illustrated by Pietsch: “If a service technician needs the latest maintenance manual and AI only sees an old version because the new one is stored somewhere else, it will confidently give the wrong answer.”
Consolidating Data and Avoiding ‘Shadow AI’
Once data is consolidated, a new challenge emerges: ensuring sensitive information isn’t inadvertently exposed to unauthorized individuals. To mitigate this, AI systems must strictly adhere to the organization’s established user permissions and access controls. This is particularly crucial for companies operating in highly regulated sectors like healthcare, finance, and the public sector.
Navigating Regulatory Landscapes
For organizations in these sectors, the location and processing of data are as important as how the AI model analyzes it. In regions like Germany, Austria, and Switzerland, data sovereignty and compliance are not merely IT concerns but are mandated at the board level. Regulations such as the GDPR and the EU’s NIS2 directive legally require organizations to demonstrate precisely where data is processed, who has accessed it, and how it is utilized—expectations that intensify with the integration of AI.
Pietsch highlights the significance of local data residency, which refers to the geographical region where an organization’s data is stored and processed, often dictated by the physical location of data centers. If an organization’s content is well-organized and governed, it can readily integrate various AI solutions in the future.
The Peril of Bypassing Controls
When faced with strict compliance requirements, many IT departments opt to block access to consumer-grade AI tools entirely. However, such restrictive measures often prove counterproductive, leading to the rise of ‘Shadow AI.’ This phenomenon occurs when employees circumvent official company networks to use public AI chatbots with sensitive corporate data. “People won’t stop using AI just because you tell them not to—they’ll just find another tool,” warns Pietsch. “That’s why companies need to offer a secure alternative.”
Providing a secure, governed environment is a more effective strategy. “With platforms like Box, for example, employees get the AI capabilities they want while the content stays inside the company in a governed environment. It’s much better to provide a secure alternative than to constantly try to fight Shadow AI.”
Focus on Content, Not Just Models
Pietsch advises business leaders to shift their focus from selecting the perfect AI model to ensuring their content and data are in optimal condition. “Models will keep changing. Focus on your content instead,” he urges. “If your content is in good shape, you can plug almost any AI into it in the future.” By prioritizing data management and governance, organizations can build a robust foundation for secure, user-friendly, and effective AI implementation.


