TLDRocket
Sign in

How to build secure and user-friendly AI: ‘If data sits in a silo, it only sees part of the picture’

Sifted

A Box exec says most AI failures aren't about the model at all — they're about messy company data. Fix your files and permissions first, and you can plug in almost any AI later.

Michael Pietsch has heard the same complaint from business leaders for years: pick the wrong AI tool and you're either locked down so tight nobody can use it, or open enough that sensitive files leak out the side door. As VP of DACH at Box, he spends a lot of time telling companies that this is the wrong argument entirely. The real obstacle to AI paying off isn't which large language model you license. It's the state of the data sitting behind it.

His point is blunt: an AI system is only as good as what it can see. Scatter engineering drawings across a file server, contracts in SharePoint, and project notes in Teams, and an AI assistant will happily hand a technician an outdated maintenance manual with total confidence. Not because the model is bad, but because it never had access to the current version in the first place. Pietsch calls this the silo problem, and he argues most companies underestimate how much it quietly undermines every AI rollout they attempt.

The fix he pushes isn't more restrictive IT policy — it's automated governance baked into the platform itself, so security stops being something employees have to think about. He points to sales teams as a familiar failure case: a rep needs to send a client a confidential proposal, the approved process involves VPNs and password-protected zip files, and it's slow enough that people just email an unsecured attachment to hit a deadline. Box's pitch is that AI agents can inherit existing permissions automatically, revoking access instantly and applying policy in the background, so the easy path and the secure path are the same path.

That matters more in regulated markets, where Pietsch says data residency and traceability have moved from an IT concern to a board-level one. GDPR and the EU's NIS2 directive don't just ask whether a company uses AI responsibly — they demand proof of where data physically sits and who touched it. Predictably, some IT departments respond by banning consumer AI tools outright. Pietsch thinks that backfires almost every time, because employees who want AI will simply find an unsanctioned chatbot and paste sensitive text into it, a pattern now common enough to have its own name: Shadow AI.

His advice, stripped down, is almost anti-climactic: stop obsessing over which model wins the next benchmark race, because models will keep changing regardless. Get the underlying content organized and properly governed, and any reasonably capable AI can be plugged in later with far less drama. It's a less exciting message than the usual AI-model hype cycle, but it's also the kind of unglamorous groundwork that tends to actually determine which companies get value out of this stuff and which stay stuck arguing about vendor choice.

My take

This is the boring truth nobody wants to hear at AI conferences: your data hygiene problem was never going to be solved by a shinier model. Companies love debating GPT-whatever versus Claude-whatever while their actual content sits in unsearchable PDF graveyards across four different SharePoint tenants. The Shadow AI point is the sharpest bit here — banning tools without offering a usable alternative just guarantees employees paste your contracts into ChatGPT anyway, which is arguably worse for security than the thing you were trying to prevent.

Read more about this at: Sifted

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads 60+ sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.