Classification, access boundaries, retention, auditability — the plumbing that decides whether an AI rollout compounds or backfires.
Most stalled AI projects aren't AI problems. They're data governance problems wearing a model's costume. The pilot goes well until someone asks who is allowed to see the answer, where the source documents came from, how long the prompt logs are kept, and what happens if a client asks for their data back. When those questions land after the fact, the rollout stalls; when they're answered up front, the rollout compounds.
At Jonsen LLC we do a lot of AI enablement work for professional-services firms. The pattern is remarkably consistent: the leaders who get durable value from AI treat governance as the precondition for the model, not the paperwork that comes after.
What we mean by data governance
Governance is the small set of rules that decide how information moves through your business. For AI purposes, four pieces matter most, and each one has a concrete meaning.
Classification — every meaningful data set is labeled: public, internal, confidential, or regulated. Not on a wiki page; in the systems where the data actually lives.
Access boundaries — who and what (people, apps, and models) can read each class, enforced by identity, not by policy PDFs.
Retention — how long each class is kept, and where it goes when it expires. Prompts and model outputs are data too.
Auditability — the ability to answer, months later, who asked what, which sources were used, and which version of which model produced an answer.
These four are not glamorous. They are the reason a firm can eventually say yes to interesting AI questions without holding its breath.
How governance failures become AI failures
The failure modes are boring, which is why they get missed. A summarization tool ingests a shared drive that contains six years of client records nobody remembered were there. A drafting assistant pulls context from a folder that includes a departing partner's personal notes. A general-purpose chatbot indexes an intranet page that has never been reviewed for accuracy and now answers a compliance question with something no partner would put in writing.
In every case, the model performed exactly as designed. The governance around it did not.
A well-behaved model on ungoverned data is a compliance incident waiting for a scheduler.
Practical first steps for a mid-size business
You don't need a governance program that looks like a bank's. You need enough governance to make one real AI use case safe, and then a repeatable path to add more.
1. Write a one-page data classification
Four tiers is plenty. Give each a plain-English definition, one or two examples, and a short list of what is and isn't allowed. Public, Internal, Confidential, Regulated. Get executive sign-off, then post it where the team already reads other short documents.
2. Map the top ten places your data actually lives
Not every system. The ten repositories that hold the most sensitive material and the ten sources your future AI will want to read. For each, note the classification of what's stored there and who currently has access. This audit alone catches most of the accidents.
3. Consolidate identity before you consolidate models
If you can't see, in one place, which humans and which services have access to a given repository, you cannot govern what a model sees on their behalf. Single sign-on, MFA, and a real leaver process are AI prerequisites even though they don't sound like AI.
4. Decide retention for prompts and outputs before you turn anything on
Whatever you choose is defensible; silence is not. Thirty days, ninety days, one year — pick something appropriate to the class of data being sent, write it down, and configure the tool to enforce it.
5. Design for the audit request that hasn't arrived yet
Assume that in eighteen months a client, an insurer, or a regulator will ask a specific question about a specific answer your AI produced. Which model. Which data. Which person. Which day. If your system can't answer that today, it won't answer it then either.
Where AI accelerates the work
Governance is not a moat that keeps AI out. It is the road AI drives on. Classified data can be routed to a private model. Access-controlled sources can feed a retrieval system that never crosses a boundary the business hasn't approved. Auditable prompts turn into training material for a better prompt tomorrow. Every one of these gets easier when the underlying labels and access rules are already true.
Ship governance alongside the first real use case
The mistake we see most often is treating governance as a phase — a six-month effort that must complete before any AI work begins. That project never ships. The more effective pattern is to pick one meaningful AI use case, define exactly the governance that use case requires, and build both together. The second use case reuses most of the first one's governance. The third one reuses almost all of it. By the fifth, the firm has a program.
That's the version of AI adoption that compounds. Calm, specific, and grounded in data your business already knows how to describe.
Ready for a calmer conversation about technology?
A real reply from Drew within three business days — no drip sequence, no handoff.
Drew leads Jonsen LLC — a Denver technology practice guiding law firms and growing businesses through AI, cybersecurity, and systems that compound over time.