Bottom line: AI integration grants enterprises’ AI systems comprehensive data access while remaining unclear how these systems may use data — a governance gap in established security models.
Enterprises grant AI systems access to their entire data repositories, while doing so weakens decades-old Role-based Access Control (RBAC) and Row-Level Security. This creates a governance gap: it remains unclear which data the AI may process and for which users it derives answers.
The classical principle of data access control in enterprises is based on the question “Who is allowed to see what?” — enforced through RBAC, Row-Level Security, auditing, and monitoring. This architecture emerged over decades, often following painful security incidents. With the integration of AI systems into operational processes, this model is fundamentally challenged: To function comprehensively — answering customer inquiries, creating reports, providing recommendations — AI systems require access to as much data as possible in real time. Enterprises grant them these permissions without clearly defining how the AI may use this data.
The new complexity lies in the changed architecture: whereas previously a missing access authorization for an employee ended the matter, there is now an additional instance between user and database. When an AI receives complete access to data repositories to function across all hierarchical levels, a gray area emerges. It remains unclear which conclusions the AI draws from which data sources, which data combinations it performs, and which answers it generates for whom. The old control question — Who has access? — is replaced by: What is the AI allowed to do with the data treasure, and for whom? Many enterprises have not developed convincing answers to this question.
A second problem lies in speed and infrastructure dimension: AI systems can generate inefficient or resource-intensive database queries when each user prompt triggers complex queries. As AI scales, the underlying IT systems do not automatically scale with it. This can lead to performance bottlenecks that act as stress tests for the entire infrastructure.
The core problem is not that the risks are unknown — data protection and access control are established disciplines. What is problematic is the speed at which AI integration is progressing while regulatory frameworks are still being developed. At the same time, employees often deploy AI tools without their IT department, sometimes without authorization. Enterprises must therefore not fundamentally slow down AI but rather accelerate it more deliberately: with clearly defined policies for data use, explicit governance rules, and continuous monitoring.
Source: www.it-daily.net · Published July 28, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.