WorkThe story, in brief

Should AI have the same data access restrictions as employees?

Your AI system just gave an employee salary data they shouldn't see. Here's why conventional access controls don't work anymore.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

As enterprises deploy agentic AI with broad data access, a critical governance gap has emerged: AI systems can bypass original access controls by retrieving from vector databases and data lakes. CIOs need to enforce permission mapping across the entire RAG pipeline—or risk creating an unintended backdoor to sensitive information.

The key facts

9 to know
  1. Air Canada chatbot case: tribunal held company liable for incorrect bereavement-fare advice, setting precedent for AI tool accountability

  2. Access control gap: employees without permission to view salary spreadsheets can obtain contents via AI if data copied to vector databases without permission rules

  3. RAG pipeline vulnerability: data ingestion, indexing, and retrieval stages must each enforce original permissions—no automatic carry-forward

  4. Solution framework: inventory source systems, select data by relevance/date, maintain audit logs of data movement into AI pipelines, enforce permission mapping at query time

  5. CIO governance checklist needed: what data enters system, where from, relevance justification, currency, exclusion of outdated/unnecessary information

  6. Air Canada tribunal case: chatbot liable for giving incorrect bereavement-fare advice; company remains responsible for AI tool accuracy

  7. Key governance gap: employees denied access to salary spreadsheets may retrieve that data via AI if it's indexed in vector databases without permission mapping

  8. RAG pipelines create permission bypass risk: original access controls on source data don't automatically carry forward through data lakes and vector databases

  9. CIO checklist includes: data inventory, relevance vetting, exclusion of outdated/irrelevant data, audit logging of data movement, permission-mapping at ingestion/indexing/response stages

Go to the source

CIOcio.com

Publisher excerpt: To get the most out of generative and agentic AI systems, enterprises are giving them broad access to business data. This process, however, is not simply a matter of opening the data floodgates and letting AI do its thing; it raises some very important governance questions that CIOs need to…
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work01

US and China Discuss Alerting Each Other to AI National Security Threats

A bilateral notification mechanism for AI national security threats signals that governments are moving from rhetoric to operational coordination on AI risk — affecting how enterprises think about cross-border AI deployment, vendor risk, and regulatory compliance.

Wired AI
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

UN says AI safeguards can’t wait for certainty

As AI agents move from labs to deployment, the UN is positioning AI safety regulation on the global diplomatic agenda — signaling that policy will move faster than technical certainty, with real implications for how enterprises and governments manage AI risk.

The Verge AI
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

7 projects top of mind for IT leaders today

AI adoption has moved from pilot to operational priority across enterprises, forcing IT leaders to rebuild processes, governance, and team structures around agentic work. This is no longer about bolting AI onto legacy systems — it's about transforming how IT operates and how workers interact with autonomous systems.

CIO