Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Tuesday, 8 September 2026

The Hierarchy of AI Oversight

Organisations frequently treat Responsible AI, AI Governance, and Data Governance as synonymous concepts. In practice, they represent three distinct, interdependent structural tiers. Treating them as interchangeable obscures how AI systems are built, verified, and operationalised within an enterprise.

A useful way to conceptualise this structure is through a three-part stack:

  •  Responsible AI defines organizational intent and boundaries.
  •  AI Governance establishes operational execution and control mechanisms.
  •  Data Governance manages the underlying assets and pipeline inputs.
When any single tier is neglected, the entire oversight framework becomes ineffective.

Responsible AI: Establishing Strategic Intent

Responsible AI sits at the top of the stack as an explicit declaration of intent. It articulates an organisation's risk tolerance, core values, and societal commitments regarding automated systems.
This layer does not detail specific technical configurations or workflow steps. Instead, it defines the overarching ethical perimeter, addressing core themes such as non-discrimination, explainability, safety, and accountability.

Key questions addressed at this layer include:
  •  What operational boundaries define acceptable versus unacceptable AI deployments?
  •  What specific harms must system designs actively prevent?
  •  What baseline commitments are required for external stakeholders and regulatory bodies?
While Responsible AI acts as the strategic compass, policy statements alone do not alter system behavior. Without operational enforcement, policy declarations remain purely symbolic. Operationalising these policies requires the secondary layer: AI Governance.

AI Governance: Implementing Operational Control

AI Governance provides the operational apparatus required to enforce Responsible AI policies. It consists of the decision rights, verification protocols, audit trails, and risk taxonomies that manage an AI model across its complete lifecycle.

This tier shifts abstract commitments into concrete engineering and management workflows. It covers model validation standards, change management, automated drift detection, and post-deployment monitoring. Systems like the GRAICE framework operate within this domain to standardise evaluation criteria.

Key questions addressed at this layer include:
  • Which roles hold approval authority at distinct stages of model development?
  • What quantitative evidence is required prior to production deployment?
  • How are performance degradation, bias drift, and unexpected edge cases detected and remediated?
  • What specific conditions trigger a mandatory model recall or pause?
AI Governance ensures that models operate within defined parameters over time. However, governance controls cannot ensure model integrity if the underlying inputs are flawed. Control frameworks require verifiable data inputs, which depends entirely on the foundational layer.

Data Governance: Securing the System Inputs

Data Governance manages the quality, legal basis, security, and lineage of the data fed into machine learning pipelines. Because statistical models reflect the characteristics of their training data, AI performance is constrained by the quality of its underlying data architecture.

Without robust data management, model output becomes inherently unpredictable. Issues such as unverified data sources, unrecorded pipeline transformations, or demographic skew directly compromise model outputs regardless of how stringent the AI control checks are.

Key questions addressed at this layer include:
  •  What is the precise lineage and chain of custody for training and validation datasets?
  •  Do clear usage rights, legal bases, and consent frameworks exist for the ingested data?
  •  Is the dataset representative, accurate, and properly versioned?
  •  How are data access controls and privacy-preserving techniques maintained through the pipeline?
Strong Data Governance provides the verifiable evidence base that AI Governance relies on. Without it, validation processes lack technical substance
.
Structural Pitfalls of Top-Down Implementation

A common failure mode occurs when organisations implement oversight from the top down. Leadership teams often publish high-level ethical guidelines and establish oversight committees before building the necessary operational controls or securing data infrastructure.

This top-down approach creates several operational vulnerabilities:
  •  Oversight committees evaluate systems without reliable technical lineage or performance data.
  •  Data quality defects and unverified assumptions are identified late in production rather than during ingestion.
  •  Ambiguity surrounds technical accountability when failures occur.
  • Defining ethical principles without establishing underlying governance frameworks leads to superficial compliance—where policy commitments exist on paper but cannot be verified or enforced at the engineering level.
Building a Cohesive Oversight Framework

Establishing an effective oversight framework requires starting from foundational technical controls and building upwards:
  • Establish Data Integrity: Secure data lineage, document legal rights, enforce validation checks, and maintain clear data stewardship across all pipelines.
  • Deploy Control Architectures: Implement repeatable stage-gate approvals, continuous testing protocols, risk logging, and lifecycle monitoring.
  • Align Operational Controls with Policy Boundaries: Connect technical metrics and threshold alerts directly to high-level organizational principles and regulatory requirements.
Aligning these three disciplines transforms AI oversight from a collection of isolated policies into an integrated operational capability.

Thursday, 3 September 2026

Governance Capabilities for High-Risk AI in the EU AI Act

Much of the discussion around the EU AI Act focuses on obligations, classifications, and compliance deadlines. While those are important, they can also obscure a more interesting point. The Act is not simply creating another regulatory checklist. It is describing the governance capabilities organisations need if they want to develop, deploy, and operate AI safely and responsibly at scale.




This becomes particularly clear when looking at Articles 8-15. Rather than a collection of disconnected requirements, these articles describe a connected operating model. They bring together governance, risk management, data quality, transparency, human oversight, documentation, and security into a framework that supports trustworthy AI throughout its lifecycle.

The infographic accompanying this article visualises those capabilities as a connected system rather than a sequence of isolated controls. Before exploring each capability, it is worth understanding where Articles 8-15 sit within the broader structure of the AI Act.

The Risk-Based Foundation of the EU AI Act

The EU AI Act adopts a risk-based approach to regulation. Rather than treating every AI system equally, it classifies systems according to the level of risk they present.

At the top of the pyramid are applications considered to represent an unacceptable risk. These uses are prohibited because they are considered incompatible with European values and fundamental rights. Below this sit High-Risk AI Systems, which are subject to the most extensive governance requirements. Beneath these are Limited Risk and Minimal Risk systems, where obligations are significantly lighter.

This distinction is important because Articles 8-15 are primarily concerned with the governance capabilities required for High-Risk AI Systems. They define what organisations must have in place to demonstrate that these systems are designed, operated, and monitored appropriately.

Governance and Accountability

Effective AI governance starts with accountability.

Although Article 8 focuses on compliance with the requirements applicable to high-risk systems, this is closely linked to the Quality Management System requirements described later in Article 17. Together, they establish the expectation that organisations must have clear governance structures, defined responsibilities, documented processes, and mechanisms for continuous improvement.

This is often where governance discussions become overly procedural. In practice, what matters is whether accountability exists. Who owns decisions? Who approves risk acceptance? Who monitors outcomes? Who intervenes when issues arise?

Organisations that treat governance as a collection of policies frequently struggle to answer these questions. Those that build governance into their operating model tend to have far greater confidence in how AI is being used and controlled.

Risk Management

One of the most significant requirements within the AI Act is the expectation that risk management is continuous.

Article 9 requires organisations to establish, implement, document, and maintain a risk management system throughout the entire lifecycle of a high-risk AI system. This is not a one-off assessment performed during development. Risks must be identified, evaluated, mitigated, monitored, and reassessed over time.

This reflects a broader reality of AI. Models evolve, data changes, user behaviour shifts, and operating environments become more complex. The risks associated with an AI system today may not be identical to those that emerge six months from now.

A mature governance programme therefore treats risk management as an ongoing capability rather than a project activity.

Data Governance

No governance framework can compensate for poor-quality data.

Article 10 recognises this by placing significant emphasis on the quality and governance of training, validation, and testing datasets. Organisations must consider data provenance, representativeness, relevance, completeness, and bias mitigation.

Many AI governance conversations focus heavily on models while paying less attention to the data that underpins them. Yet data remains one of the strongest determinants of whether an AI system will behave as intended.

This requirement is also one of the clearest areas where tools such as Microsoft Purview can support governance objectives. Data lineage, metadata management, business glossaries, and data quality capabilities provide organisations with the visibility needed to understand where data originates, how it moves, and whether it can be trusted for AI use cases.

Data governance is not a separate discipline sitting alongside AI governance. It is one of its foundational components.

Documentation and Evidence

Good governance depends upon evidence.

Articles 11 and 12 establish the requirements for technical documentation and record keeping. Organisations must maintain sufficient documentation to demonstrate conformity with regulatory obligations and provide evidence regarding how the system operates.

Technical documentation includes information such as system design, intended purpose, performance characteristics, testing activities, and risk assessments. Record keeping focuses on logs, traceability, and the ability to reconstruct events when needed.

This may appear administrative at first glance, but it plays a critical role in building accountability. When questions arise about an AI system's behaviour, organisations need more than assumptions or recollections. They need evidence. Documentation transforms governance from intention into demonstration.

Transparency and Explainability

A system cannot be governed effectively if nobody understands how it should be used.

Article 13 requires high-risk AI systems to be sufficiently transparent so that deployers can interpret outputs and use the system appropriately. Users must be provided with information about intended use, limitations, and operational considerations.

Transparency is often reduced to explainability discussions, but it extends beyond technical explanations of model behaviour. It also encompasses user guidance, operational context, and clarity regarding what the system should and should not be used for.

Many governance failures occur not because the AI was technically flawed but because people misunderstood its outputs or relied upon it in inappropriate ways. Transparency helps prevent those misunderstandings.

Human Oversight

One of the most important themes within the AI Act is the continuing role of human judgement.

Article 14 requires organisations to design systems that enable appropriate human oversight. This includes mechanisms for review, escalation, intervention, and, where necessary, stopping or overriding the system.

The phrase "human in the loop" is often used when discussing AI oversight, but the Act's expectations are broader than that. Effective oversight requires authority, competence, and accountability, not merely human presence. People need to be able to challenge outcomes, recognise anomalies, and take action when circumstances demand it. Governance remains a human responsibility, even when decisions are increasingly supported by AI.

Accuracy, Robustness and Security

The final capability area focuses on operational resilience.

Article 15 requires high-risk AI systems to achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their operational life. Organisations must consider not only normal operating conditions but also errors, failures, misuse, and malicious attacks.

This reflects an important shift in thinking. Governance is not solely about policies and controls. It is also about operational performance.

An AI system that cannot remain reliable, secure, and resilient under real-world conditions cannot ultimately be considered trustworthy.

Governance is more than Compliance

When viewed together, Articles 8-15 reveal something that is often missed in discussions about the EU AI Act. The regulation is not describing a set of independent controls. It is describing a connected governance system.

Risk management relies on trustworthy data. Transparency depends on documentation. Oversight requires accountability. Security depends upon effective governance. Each capability supports the others.

This is why organisations should resist the temptation to approach the AI Act as a compliance exercise alone. The most successful governance programmes will be those that use these requirements to establish sustainable operating models that support responsible AI adoption at scale.

Ultimately, the organisations that thrive in the AI era are unlikely to be those with the longest policy documents. They will be those that can demonstrate consistent, repeatable, and accountable governance across their AI estate. That is the broader message embedded within Articles 8-15, and it is arguably far more significant than compliance alone.

Cambridge Report on Database Research and what it means for the future of Data Governance

The Cambridge Report on Database Research, convened on October 19-20, 2023, in Cambridge, MA, discussed the state of the database research field, its recent accomplishments, ongoing challenges, and future directions for research and community engagement. 


Every five years, some of the world's leading database researchers come together to reflect on the state of data management and identify the challenges that will shape the next generation of technology. The latest Cambridge Report on Database Research does exactly that, exploring everything from cloud infrastructure and AI to data systems, machine learning, and governance. While it is not a governance report in the traditional sense, it offers some important clues about how governance will need to evolve over the coming decade.

The most striking observation is that governance is becoming inseparable from the platforms that manage data. The report describes a future where data systems are increasingly autonomous, with automated provisioning, self-managing infrastructure, adaptive optimisation, and intelligent control planes. As these capabilities mature, many of the technical tasks traditionally associated with governance, such as metadata collection, lineage discovery, classification, and monitoring, will become increasingly automated.

For governance professionals, this represents a significant shift in focus. The challenge will no longer be capturing metadata or maintaining catalogues. Technology will increasingly perform those activities automatically. Instead, organisations will need to determine who is accountable, what policies should govern the use of information, and how trust is maintained across an increasingly complex data and AI landscape. The report also highlights the growing importance of data quality. Future AI models, adaptive systems, and cloud platforms depend on access to trusted, well-managed information. Researchers point to the need for better mechanisms to collect, benchmark, validate, and monitor data at scale. This suggests a future in which data quality becomes a continuously monitored capability rather than a periodic assessment exercise. Many organisations still approach data quality through project-based remediation programmes. However, the direction of travel is towards automated detection, AI-assisted monitoring, and real-time observability. Governance teams will increasingly define quality expectations, ownership responsibilities, and remediation processes, while platforms identify issues and measure compliance against agreed standards.

Perhaps the biggest governance implication comes from the report's focus on AI. Researchers describe a world where traditional databases are no longer the only source of knowledge. Future systems will need to manage documents, images, videos, unstructured content, and AI-generated outputs alongside structured business data. They even envision the ability to query large collections of documents and multimedia content in much the same way that organisations query databases today. This changes the scope of governance dramatically. Governance can no longer focus solely on data warehouses, data lakes, and business intelligence platforms. It must expand to cover enterprise knowledge, collaboration content, AI-generated information, and the growing number of systems that sit between data and decision-making. The report is particularly clear on the need to improve trust in AI-generated outputs. Reducing hallucinations, validating responses, improving retrieval mechanisms, and establishing provenance are all identified as important areas for future innovation. Databases and data management technologies are viewed as a critical part of solving these challenges.

For governance leaders, this is perhaps the most important signal of all. Historically, governance has focused on data ownership, standards, policies, and compliance. In an AI-enabled organisation, the questions become much broader. Where did this answer come from? Which sources were used? Can the result be traced back to trusted information? Who is accountable if the answer is incorrect? These are governance questions as much as they are technical ones. Viewed through this lens, governance starts to look less like an administrative function and more like an assurance discipline. The future governance team may spend less time maintaining catalogues and more time providing confidence in how data, knowledge, and AI are used across the organisation.

What emerges from the Cambridge Report is not a vision of governance disappearing into technology. Quite the opposite. As automation removes manual governance activities, the importance of human accountability, oversight, assurance, and decision-making increases. The technology may become smarter, but organisations will still need clear ownership models, governance operating structures, and mechanisms to establish trust. This aligns with a trend that many organisations are already beginning to recognise. Data governance and AI governance are unlikely to remain separate disciplines for long. Instead, they are converging into a broader information governance operating model that spans data, knowledge, accountability, oversight, assurance, and responsible use.

The technologies will change. Automation will increase. AI will become embedded in everyday business processes. But the fundamental objective of governance remains the same: ensuring that people can trust the information they use to make decisions. The Cambridge Report suggests that this objective may become even more important as intelligent systems become a standard part of the enterprise technology landscape.

My key takeaway is the future of governance is not more policies, more committees, or bigger catalogues. It is creating an operating model that provides confidence in data and AI at scale, while allowing increasingly automated platforms to handle much of the underlying governance workload.


Wednesday, 19 August 2026

Anthropic training programmes

Over the last week I have completed three Anthropic training programmes to expand my use of AI tools from Copilot and Gemini. While the courses focus on Claude, the value goes far beyond learning a particular AI tool. I completed:

  • Claude 101
  • AI Fluency Framework & Foundations
  • Claude Code in Action
Claude 101 provides a solid grounding in how to work effectively with large language models. It covers prompt design, structuring requests, and understanding where AI can genuinely add value versus where human judgement remains essential.

AI Fluency Framework & Foundations takes a broader view. Rather than concentrating on technology alone, it explores how individuals and organisations can develop the skills, mindset and practices needed to adopt AI successfully. It reinforces an important lesson about becoming AI-enabled is as much about people and ways of working as it is about the tools themselves.

Claude Code in Action was particularly interesting from a practical perspective. It demonstrates how AI can support software development workflows, automate repetitive tasks, assist with code generation and review, and help teams move faster while maintaining quality. Even for those of us who are not full-time developers, it offers valuable insight into how AI is changing the way technical teams work.

The skills I learned on a this tool cover the tool usage but are more about people, skills, governance, and trusted data.



Tuesday, 18 August 2026

What my WorkIQ Persona Sketch taught me about Data Governance


Like most people who have spent years working in data, governance and technology, I am occasionally asked a surprisingly difficult question.

"So, what is it that you actually do?"

It sounds simple enough. After all, I spend my days helping organisations improve the way they govern data and AI. I work with executives, data leaders, governance teams and technology specialists. I write, speak, advise, mentor, and occasionally disappear down a rabbit hole researching some obscure aspect of metadata or organisational complexity. Yet whenever somebody outside the industry asks the question, the answer rarely feels satisfactory.

You can talk about Microsoft Purview, governance operating models, stewardship, responsible AI, data quality, business glossaries and metadata management. You can explain frameworks, programmes and organisational change. Most people are polite enough to listen, but somewhere around the mention of lineage or compliance controls their eyes begin to glaze over.

Recently I decided to create one of the increasingly popular WorkIQ Persona Sketches. I expected it would be an interesting visual exercise and perhaps a useful profile graphic for social media. What I did not expect was that it would force me to reflect on what my work is really about. When the first version appeared, it looked impressive enough. It showed technology platforms, governance activities, speaking engagements, research interests and community involvement. It included the various things I spend time doing and many of the topics I am associated with professionally.

The problem was that it still did not quite feel like me. It described my activities, but not my purpose. As I refined the sketch, removing some elements and emphasising others, a pattern began to emerge. The technology became smaller. The governance themes became larger. The focus shifted away from products and towards outcomes. Instead of listing tools, the sketch started telling a story.

The story was not really about Microsoft Purview, Microsoft Fabric, Power BI or SQL Server, despite all of them appearing on the page. It was about helping organisations build confidence. That may sound like a subtle distinction, but I think it matters.

Many organisations still think of governance as an exercise in control. Policies need writing, roles assigning, rules enforcing and technology deploying. Those things are certainly part of governance, but they are rarely the reason governance exists.

The organisations making the most progress with data and AI are not trying to govern for the sake of governing. They are trying to make better decisions, reduce uncertainty and trying to understand their information well enough to trust it. Increasingly, they are trying to ensure the foundations beneath their AI ambitions are solid enough to support what comes next. Governance is simply the mechanism that helps create that confidence and trust. Looking at the sketch, I realised that almost every part of my career has revolved around that idea.

My doctoral research explored the complexity of database systems and resulted in the development of the CODEX Framework. At the time, I was trying to understand how organisations could make sense of increasingly complex data environments. Years later, those same themes continue to appear in conversations about governance, AI readiness and organisational trust.

My work as a Microsoft Data Platform MVP has never really been about technology advocacy. It has been about helping people understand how technology can support better outcomes.

The conferences, community events, blogs and mentoring activities all stem from the same belief. If we help people understand data better, we help organisations make better decisions. If we improve governance, we improve confidence and the likelihood that data and AI initiatives deliver meaningful value.

The sketch made something else visible too. Many people see specialists through the lens of tools. We become the Purview person, the SQL Server person or the governance person. The reality is usually much broader. The most valuable work often happens between disciplines rather than within them. Good governance sits between business strategy and technology. It sits between risk, innovation, people, processes, culture and platforms. Success rarely comes from solving a technical challenge in isolation. It comes from helping organisations connect those pieces together in a way that makes sense.

That is why the final version of the sketch ended up with a simple statement at its centre:

Helping shape how organisations think strategically about Data & AI Governance and Microsoft Purview.

Microsoft Purview is a powerful accelerator for governance, but it is not the answer to every governance challenge on its own. Organisations still need to make governance decisions with purpose, coherence, and accountability. Governance remains the most important discipline in an organisation because it connects technology, behaviour, and business outcomes.

As I reflected on this, the sketch I was creating shifted. It became less of a personal profile and more of a map of the ideas I care about, the communities I contribute to, and the research, technology, and leadership themes that have shaped my career. Most importantly, it became a reminder that roles are easier to understand when viewed through purpose rather than activity. The common thread running through my work is the ability to connect governance, technology, and business outcomes in a way that creates integrity, clarity, and direction.

The next time somebody asks what I do, I might still mention governance, AI and Microsoft technologies.,  but I suspect I will start with something simpler. I help organisations build confidence in their data and AI so they can make better decisions. Everything else is just how that happens.

Reference 

https://github.com/pnp/copilot-prompts/tree/main/samples/prompts/m365-workiq-persona-sketch

Why Trust Matters more than Discovery: Microsoft Purview Unified Catalog

In the first article in this series, I explored the challenge of visibility and how Microsoft Purview Unified Catalog helps organisations answer a simple but surprisingly difficult question: what data do we actually have?

For many organisations, solving this problem represents a significant milestone. Years of system growth, acquisitions, departmental solutions and technology change often create an environment where information exists but remains difficult to locate. Valuable datasets sit within platforms that few people know about, reports are recreated because earlier versions cannot be found, and knowledge about key information assets becomes concentrated within small groups of specialists.

Improving discovery removes many of those barriers, but it also introduces a new challenge. Once users can locate information more easily, their attention naturally shifts away from finding data and towards understanding it. Very rarely does somebody discover a dataset and immediately begin using it without asking further questions. Instead, they want to know whether the dataset is trusted, who owns it, how it is being maintained and whether it is suitable for the decision, analysis or report they are working on.

In practice, this is the point at which governance becomes far more interesting.

Most organisations do not struggle because they lack information. They struggle because they lack confidence in the information they have. Discovery helps people locate data, but trust determines whether that data is actually used.

Why Data Discovery is only the beginning

Many of the frustrations people experience with data are not caused by technology. They arise because the information lacks sufficient context.

Imagine an analyst searching a catalogue and finding three datasets that appear to contain customer information. All three are current. All three appear relevant. All three contain similar attributes and similar record counts. Discovery has succeeded because the analyst can see that the data exists. Unfortunately, discovery alone does not help determine which dataset should be used.

The questions that follow are usually business questions rather than technical questions.

Which dataset represents the approved source?

Which business area owns it?

What does "customer" actually mean within this context?

How frequently is it updated?

What transformations have been applied since the data was first collected?

Without those answers, users often fall back on familiar behaviour. They email colleagues, consult subject matter experts or continue using whichever data source they trusted previously. The catalogue exists, but confidence has not yet been established.

This is why governance programmes that focus exclusively on discovery often struggle to deliver their full value. Visibility is important, but visibility without context rarely creates trust.

Where Data Curation fits

One of the less discussed aspects of governance is curation. The term itself sounds administrative, which probably explains why it receives less attention than topics such as AI, analytics or compliance. In reality, curation sits at the heart of helping organisations bridge the gap between technical information and business understanding.

Most data assets are created within technology environments. Their names reflect system requirements, integration patterns or development conventions. To the engineers who build and maintain them, those names often make perfect sense. To everyone else, they can be cryptic, ambiguous or completely meaningless.

A curated asset looks different because it includes the information people actually need in order to understand it. Business descriptions explain what the asset represents. Ownership information identifies accountability. Classifications provide context about sensitivity and usage. Associated business terms explain how the asset fits within the language of the organisation.

This process transforms a technical asset into something that can be interpreted and trusted by a much wider audience.

The objective is not simply to document data. It is to create enough context that somebody encountering a dataset for the first time can understand its purpose and relevance without needing to find the person who created it.

The Business Glossary: Creating a Common Language

One of the most valuable governance capabilities within Microsoft Purview is the Business Glossary.

At first glance, a glossary sounds relatively straightforward. Many organisations assume it is simply a dictionary of approved business terms. In practice, its role is significantly more important than that.

Every organisation has terminology that appears obvious until people are asked to define it. Terms such as customer, employee, supplier, resident, contract or revenue are often assumed to have a consistent meaning. Governance workshops frequently reveal the opposite. Different teams use the same words while referring to slightly different concepts. Those differences may be perfectly reasonable within local contexts, but they become problematic when information is shared across departments, reports or analytical models.

A customer services team may define an active customer differently from the sales function. Finance may calculate revenue differently from operational reporting. Legal, risk and compliance teams may use terminology that reflects regulatory requirements rather than business reporting needs.

These are not necessarily disagreements. More often they are examples of organisational complexity becoming visible.

The Business Glossary provides a mechanism for governing this complexity. Within Microsoft Purview, glossary terms can be organised into domains, assigned owners and stewards, enriched with definitions and related terms, and connected directly to assets within the Unified Catalog. This relationship is particularly important because it links business language to the datasets, reports and information products that rely upon it.

When users search the catalogue, they are not simply looking at technical metadata. They can also see the business terminology associated with assets and understand how those assets relate to agreed organisational definitions. Rather than existing as a separate governance artefact that few people reference, the glossary becomes embedded within the discovery experience itself.

This is often where trust begins. People are far more likely to use information when they understand both what it contains and how the organisation expects it to be interpreted.

Why Lineage builds confidence

Even when terminology is clear and ownership is established, there is usually another question users want answered.

How did this data get here?

Most people consume information at the end of a process. They see a dashboard, a report, a model or, increasingly, an AI-generated response. What they do not see is the journey that information has taken through source systems, integrations, transformation processes and analytical platforms before reaching its final destination.

Understanding that journey is the role of data lineage.

Lineage provides visibility into how information moves through an organisation. Rather than viewing a dataset as an isolated asset, users can see its relationship to upstream systems, transformation processes and downstream consumers. This creates a much richer understanding of where information originated and what happened to it along the way.

The significance of lineage becomes particularly obvious when trust is challenged. If a figure changes unexpectedly, lineage helps explain why. If an upstream source system is modified, lineage can help identify which reports, dashboards and analytical processes may be affected. If two datasets appear similar, lineage may reveal that they originate from different systems and have undergone different transformations.

In other words, lineage provides evidence rather than assumption.

Within Microsoft Purview, lineage is captured automatically through integration with supported technologies and services. Data movement, transformation and processing activities within platforms such as Azure Data Factory, Microsoft Fabric, SQL environments and other supported services can be visualised as connected information flows. Instead of relying on manually maintained diagrams that quickly become outdated, organisations gain a dynamic view of how information actually moves through the estate.

For governance teams this increases visibility. For business users it often increases trust because they can see how a reported value is connected to its source.

Trust is what turns Data into value

Discovery remains a critical part of data governance. Organisations cannot govern information that they cannot find, which is why visibility, cataloguing and discovery capabilities provide such an important foundation.

However, discovery alone does not solve the larger challenge.

People create value from data when they are willing to use it. They use it when they understand it. They trust it when they have confidence in its meaning, ownership and provenance.

Business glossaries help establish shared language. Curation provides business context. Lineage explains how information was created and how it moves across the organisation. Together, these capabilities transform a catalogue from a searchable inventory into a trusted source of organisational knowledge.

Finding data is important. Being confident enough to use it is what ultimately matters.



Friday, 14 August 2026

AI is Forcing Organisations to ask Data Governance questions they have avoided for years

When organisations begin exploring generative AI, the early conversations are usually focused on technology. Attention naturally turns towards copilots, agents, large language models, prompt engineering and how existing processes might be automated. The assumption is often that success will depend on choosing the right tools and identifying the right use cases.



Those discussions are important, but they rarely remain the centre of attention for long.

As AI initiatives move beyond experimentation and into real business scenarios, the conversation often shifts in an unexpected direction. Questions begin to emerge about ownership, trust, definitions and accountability. Teams discover that information which appeared well understood within individual departments becomes considerably more difficult to explain when it is surfaced across the organisation through a single AI-powered experience.

This is creating an interesting situation. Many organisations believe they are encountering AI challenges when, in reality, they are encountering long-standing governance challenges that have remained largely hidden until now.

For years it has been possible for businesses to operate successfully despite inconsistencies in the way data is managed. Different departments develop their own reporting processes, terminology and working practices. Over time these approaches become embedded into everyday operations. Finance may calculate a measure one way, while another business unit calculates it differently. Multiple systems may contain records relating to the same customer, product or asset. Ownership may be understood informally without being clearly defined.

None of these situations are unusual. In fact, they are common in organisations of every size and sector.

What has changed is that generative AI is exposing these inconsistencies in ways that traditional reporting platforms rarely did. Information that once remained within the boundaries of a specific application, report or team is increasingly being brought together and presented through a single interface. As soon as that happens, differences in meaning, ownership and interpretation become much more visible.

One of the more striking developments over the past year has been how quickly discussions about AI become discussions about data governance. An organisation may start by exploring how employees can use Copilot more effectively, only to find itself debating which definition of a business term should be treated as authoritative. A workshop intended to focus on automation can quickly become a conversation about data ownership. Questions about whether users can trust AI-generated responses often lead directly to questions about where underlying information originated and how it is managed.

These are not new concerns. Governance professionals have been dealing with them for decades. The difference is that they are no longer confined to governance programmes.

AI is bringing them into boardrooms, project teams and business conversations that might previously never have engaged with governance at all.

The issue is not that AI is creating poor governance. Rather, it is making gaps in governance more difficult to ignore.

A useful parallel can be found in the idea of technical debt. Most organisations understand that technology decisions made years ago can create future complexity. Shortcuts that seem reasonable at the time often require greater effort to address later. Data governance follows a similar pattern. Business definitions are left undocumented because everyone believes they share the same understanding. Ownership remains informal because responsibilities appear obvious. Metadata is treated as a technical concern rather than a business asset. Lineage documentation is postponed because delivery deadlines take priority.

Individually, these decisions rarely feel significant. Collectively, they create an environment where information becomes harder to understand, trust and govern over time.

Historically, organisations could continue operating with this ambiguity because people compensated for it. Experienced employees knew which reports to trust and who to contact when figures did not align. Unwritten knowledge often filled the gaps that formal governance processes had not addressed.

Generative AI changes that dynamic because it lacks this organisational context. It relies on information being discoverable, understandable and consistent. When definitions vary between teams, when ownership is unclear or when information carries little context, those weaknesses become more apparent. The technology is simply revealing what has always been there.

This is one reason metadata has suddenly become a much more strategic conversation. Business glossaries, catalogues, classifications, stewardship models and lineage are often viewed as traditional governance disciplines. Increasingly, they are becoming recognised as fundamental enablers for AI adoption. Organisations are realising that it is difficult to scale AI responsibly when basic questions about information cannot be answered consistently.

The organisations making the strongest progress with AI are not always the ones investing the most heavily in AI technology itself. More often, they are organisations that have a reasonable understanding of their information landscape. They know which data matters to the business, who is accountable for it, how it is defined and where it comes from. They have established enough structure and context to create confidence in the information being consumed.

That confidence matters because successful AI adoption is ultimately a trust exercise. Users need confidence that information is accurate, that responses can be explained and that decisions can be justified. Without trust, adoption slows regardless of how capable the underlying technology may be.

Perhaps the most interesting outcome of the current AI wave is that it is forcing organisations to revisit some of the fundamentals of information management. After years of being viewed as a compliance activity or a specialist discipline, data governance is finding itself at the centre of conversations about innovation, productivity and business transformation.

The irony is that many organisations began their AI journey expecting to focus primarily on technology. Instead, they are being asked to confront questions about data that have existed for years. They have questions about ownership, meaning, accountability,  and trust. Those are governance questions, and they are becoming increasingly difficult to avoid.

AI may not have been designed to improve data governance, but it is proving remarkably effective at showing organisations where governance needs attention. In many cases, the most valuable insight generated by AI is not contained within a response or recommendation. It is the realisation that understanding data remains one of the most important prerequisites for using it effectively.