Building AI Data Readiness With Kiteworks
Tech Talks DailyAugust 31, 2026
3704
22:0616.91 MB

Building AI Data Readiness With Kiteworks

Could your organization produce a complete record of everything its AI systems accessed, sent, or shared within one business day?

In this episode of Tech Talks Daily, I welcome Tim Freestone, Chief Strategy Officer at Kiteworks, back to the podcast for his third appearance. Our conversation centers on the company's 2026 Data Security and Compliance Risk Annual Survey and the difference between buying security technology and being able to demonstrate that sensitive data is properly controlled.

According to the Kiteworks research supplied for this interview, 80 percent of surveyed organizations experienced at least one security or AI related incident during the previous 12 months. Half could not produce a complete AI data access audit record within one business day. The strongest group recorded an average readiness score of 46 out of 100, while organizations with weaker security and AI governance averaged eight. Even the higher score leaves considerable room for improvement.

Tim argues that technology spending can produce a larger version of the same exposure when a company lacks the people, ownership, and operating model needed to manage what it has purchased. Network, cloud, and infrastructure security still matter, but the business ultimately needs to understand what is happening at the data layer. Which identities can access a system? What actions can they take? Which records can they read, change, send, or share?

We discuss why this has become harder as employees create large numbers of AI agents. A company may have 1,000 people and tens of thousands of nonhuman identities, each requiring permissions and oversight. Tim describes three connected control planes covering identity, actions, and data. Together, they offer leaders a practical way to assess whether an agent can reach information it should never see or perform an action it was never meant to take.

The conversation also examines audit evidence. Tim says businesses should map regulated data types to the controls governing their use and then connect those controls with reporting. Without that connection, answering an auditor may require months of work, large consulting bills, and teams manually assembling records from disconnected systems.

Ownership remains difficult because security, compliance, infrastructure, and data governance teams often work separately. Tim's view is that the CEO must orchestrate responsibility when the board is asking AI to produce higher productivity while the same systems create new data risk. That position may feel demanding, but it exposes an issue many leadership teams still need to settle: who owns the consequences when an AI agent exposes or transforms sensitive information?

For board members, Tim offers two direct tests. Ask for a clear account of the company's data controls, then ask who is responsible for the associated risk. If those answers require a long explanation or several departments pointing at one another, the readiness score may matter less than the inability to demonstrate control.

How quickly could your organization show who or what touched sensitive data, and who would be accountable if the record were incomplete? Listen to the episode and share your thoughts.

Useful Links

Please check the partners of the Tech Tech Talks Network

[00:00:00] - [Speaker 0]
Do you need AI agents that you can trust? Well, with an AI data layer providing real time connection within your data platforms, you can trust your agents to provide accurate solutions. So scale your business by trusting your agentic AI, accurately getting the work done for you. Trust its capabilities with Denodo. And you can do that by simply visiting denodo.com to learn more.

[00:00:30] - [Speaker 0]
How much does your organization really know about the data that its AI agents can access, send, or share? Well, in this episode today, I'm gonna welcome back friend of the show, Tim Freestone, chief strategy officer at Kiteworks. And today, we're gonna celebrate his hat trick of appearances. But most importantly, we're gonna discuss findings from the Kiteworks 2026 data security and compliance risk annual survey, which includes the reported gap between companies investing in security and those able to prove their AI readiness. And that gap is something I wanna discuss today.

[00:01:16] - [Speaker 0]
So Tim will explain why another security product just cannot compensate for unclear ownership, disconnected systems, or missing data controls. And we will also look at the growing number of nonhuman identities inside businesses. Yeah. A year ago, eighteen months ago, there wasn't too much talk of agents inside a business. We heard buzzwords such as agentic AI, but of course, over the last twelve months, agents inside organizations have exploded.

[00:01:49] - [Speaker 0]
An individual could have a dozen agents for different tasks. When you multiply that by teams, departments across the entire organization, identity and agents has become a massive talking point, especially when regulators and auditors could request information. Thankfully though, Tim will reveal three control planes that leaders need to understand. So if your AI agents are moving at machine speed and you're questioning whether your governance and reporting can keep up with it all, we've got plenty of takeaways for you today. So please allow me to reintroduce you to Tim Freestone once again.

[00:02:30] - [Speaker 0]
So thank you for joining me on the podcast again. For everyone listening, can you remind them with a little about who you are and what you do?

[00:02:38] - [Speaker 1]
Yeah. Absolutely. So, first of all, thanks again. I think this is a three peat for us. Third time on the show, so I must be doing something reasonably right.

[00:02:47] - [Speaker 1]
Yeah. So I'm Tim Freestone. I'm the chief strategy officer at Kiteworks, which is a fancy way of saying, I just sit in the corner and think a lot, but I actually do do some work. I all of the marketing org, pricing, stuff like that, I have to figure out all the time too. So but it's a fun time to be doing all of that.

[00:03:05] - [Speaker 1]
I'm so happy with happy with that role here at Kiteworks.

[00:03:09] - [Speaker 0]
Yeah. It really is a fun time right now, and this is your hat trick of appearances as you mentioned there. And one of the reasons though I wanted to get you back on is I came across your research that reported that eighty percent of organizations have experienced a security or AI related incident. So I've got to ask for what you're seeing here. What's driving that number, and which incidents are causing maybe the most business damage right now?

[00:03:35] - [Speaker 1]
Yeah. And, also, I'll say that 20% are lying or or just haven't figured it out yet. Look. There's sort of this this concept of defense in-depth, which is where you assume breach. And the reason that assume breach mentality is there is because you've been breached.

[00:03:56] - [Speaker 1]
I mean, there's just it that's why I say 20% are lying or or don't know or or however that that shook out. What I think has changed is not, you know, are we compromised to some degree or another because the answer is yes. Is how big of a problem or how big the compromise is and how often that compromise is happening without without knowing it. Because, again, previously, all compromise was under human speed, and now compromise is at machine speed. And you just can't calculate that in your brain.

[00:04:37] - [Speaker 1]
And the thing is, like, the I think the best example of this is, you know, was the recent, Hugging Face breach where OpenAI's agents in their supposedly completely secure sandbox got out of their sandbox and breached Hugging Face. And, you know, the the people who are creating these AI models didn't even notice this for, you know, I think it was several months. So, you know, the the idea that the companies that build this can't keep up with the chain of thought of their agentic systems, how is everybody else gonna be able to keep up with it? So it just, you know, it's the drivers have just multiplied, basically.

[00:05:25] - [Speaker 0]
Yeah. And another standout stat in there was that the report seemed to suggest that many companies, they're trying to do the right thing. They keep increasing security spending, but doing so without improving readiness. So why does more technology sometimes produce a larger version of the same exposure? What are seeing there?

[00:05:43] - [Speaker 1]
Yeah. Well, it's just where the technology spend goes. And, you know, more technology doesn't necessarily mean you have enough human capital or human ability to manage the technology that you've bought, implement it correctly. You know, the cybersecurity resource gap is real. So it it's just you know, tech is not a strategy.

[00:06:10] - [Speaker 1]
Let's say

[00:06:10] - [Speaker 0]
that. And

[00:06:13] - [Speaker 1]
so the the real approach has to come down to, like, what at the end of the day, what is the genesis of what we're trying to protect, and do we have the strategy, technology, and people at the genesis of what we're trying to protect? And the the genesis has always been, with the exception of sort of sabotage based, bad guys, like DDoS attacks or something like that, the genesis has always been data. And so moving the security layer, the strategy, the technology, the resources to the data layer and everything you can possibly do at the data layer is the right move. Now the problem with that is it's a very hard strategy to solve for. It's getting easier, but that's why people have that's that's one of the main reasons it hasn't taken front and center stage is this just so challenging.

[00:07:07] - [Speaker 1]
So people are buying more technology at other parts of the organization, protecting the cloud, protecting the network, protecting the infrastructure, because there's less in quantity of those things. But at the end of the day, it's really about the data. Until you get down to that layer, you're gonna be playing catch up.

[00:07:25] - [Speaker 0]
And looking at some of the figures we're talking here, I mean, the strongest performers, they were achieving an average readiness score of 46 out of a 100, which still isn't great. But the weaker organizations there, they they had a, in security and AI governance averaged just eight. But so I've got to ask, if we do look at the best case scenario, what are the stronger groups doing differently?

[00:07:49] - [Speaker 1]
Well, let me start with the the worst case scenario, the eight. Look. I think there was another survey that, in terms of AI productivity in companies, something like 8% are seeing return on investment. So it kinda matches that 8% are doing anything from a security standpoint. I don't know.

[00:08:08] - [Speaker 1]
I just thought that was a funny comparison with our with our survey. And from a readiness standpoint, I think it's the, you know, what are the companies that to answer your question, what are the companies doing that are are better than that? I think they're putting the right people in place with the understanding of what AI systems can do for scale of of security. At least what I see, human human resources that operate in yesterday's model are having a really hard time making the shift. But human resources that are kind of growing up in this model, obviously aren't.

[00:08:49] - [Speaker 1]
And so companies that are are are restructuring their organization around this new way to approach cybersecurity based on this new way that, hackers are approaching hacking, is where the the real successes are happening.

[00:09:07] - [Speaker 0]
And I suspect many people listening will be using AI agents to get reports and overviews of all everything that they do, all their workload, maybe even their home life as well just to stay on top of things, and they get answers, results, guidance within seconds. But on the flip side of this, half of organizations reportedly cannot produce a complete record of AI data access within one business day. We don't work like that anymore, which seems really surprising to me. But what does do you think that reveals about how visibility many companies actually have into their AI use? Did that surprise you at all?

[00:09:43] - [Speaker 1]
Yeah. It didn't surprise me that much that they're still having to stitch systems together even with with AI. All the information's still disparate. It may be a little bit faster to to connect to systems, to correlate all of the information, but it's still difficult and it's you still have a output that you have to validate and verify. You can't just blindly verify and validate stitch together information.

[00:10:10] - [Speaker 1]
I mean, there's entire markets that are starting right now helping companies use AI to bring systems, the information room systems together and make sense of it and it's not easy. It's not it's not easy at all. So that's really what's happening there. So the the less SIP the reason you're seeing a lot of more platformization happen because of that. So being able to bring multiple systems together under one platform where the platform also operates the system or the you know, in our case, with multiple data, exchange channels being able to bring those data exchange channels under one, authoritarian umbrella, is much easier to get information from using AI than going to all of those different systems and trying to stitch it together.

[00:11:00] - [Speaker 1]
Still today, it's still difficult.

[00:11:02] - [Speaker 0]
Yeah. Makes sense. And one of reasons I I wanted to bring that up is if we look at regulations such as DORA and this too and here in The UK and Europe, there's the EU AI act, which all seem to raise expectations around evidence and accountability. So with that in mind, what record should should an organization or leaders listening be able to produce just before an auditor or an incident actually forces the question, forces their hand? What should they be protecting?

[00:11:30] - [Speaker 1]
Yeah. So it's who or what touched, and by touched, mean used, sent, shared sensitive data that is identified as such by that regulation.

[00:11:45] - [Speaker 0]
Yeah.

[00:11:45] - [Speaker 1]
So mapping very specifically what the data archetype is that that particular regulation is trying to govern, and then making sure you have systems in place that map reporting to that touching, the using, the sending, the sharing of data. Because I'll tell you all of those are about data. So but they're all different. So you need that mapping and you need the controls over the data, and then you need the reporting on the data that map to the controls that map to the regulation. You have to put all those things together.

[00:12:22] - [Speaker 1]
Otherwise, it's gonna take you months and hundreds of thousands of dollars, if not more, and stacks of people to be able to answer an auditor's, request.

[00:12:35] - [Speaker 0]
And a few moments ago, we're talking about disparate data, silos, etcetera. And another thing that stands out is AI governance and data security. They're often managed by completely separate teams too. So where should ownership sit when an AI system exposes, transforms, or or shares sensitive information? Who who's responsible here?

[00:12:57] - [Speaker 1]
Yeah. I get that question a lot. Yeah. I don't have a decent answer other than the CEO.

[00:13:01] - [Speaker 0]
Yeah.

[00:13:03] - [Speaker 1]
This the CEO has to take a much more hands on approach to what's happening with the company's data because it can ruin a company. And just and and really direct ownership because you've got the data governance people who are looking at data lineage and their responsibility. You have the cybersecurity who are looking at it from, you know, reducing breach, lowering risk. You have the infrastructure people who are looking at it from delivering productivity that's being pushed on them from the CEO and from the board. And so they're all running in their in their different directions.

[00:13:40] - [Speaker 1]
And in many companies, the CSO and the CIO operate separately. Some the CSO report in the CIO. It's less and less. The data governance are in a whole completely different unit often. There's compliance people.

[00:13:54] - [Speaker 1]
So there just isn't a right answer to that other than, you know, looking at the CEO and saying, hey. You wanna push productivity? Fine. You need to take responsibility and push orchestration of the governance of that productivity.

[00:14:08] - [Speaker 0]
And before you join me again today, I was reading how your your description of the market is almost a a fork in the road, which suggests that good controls will reinforce one another. And for again, for people listening, I love trying to give them actionable takeaways here. What are the first few controls that create that compounding effect that, leaders are looking for?

[00:14:29] - [Speaker 1]
Yeah. First of all, get control over your identities in your organization, human and nonhuman identities. Make sure you have a good process for managing identities, discovering new identities. You can't you can't really have control if you don't know what's accessing what. Right?

[00:14:48] - [Speaker 1]
You need identity management. Most companies have, obviously, some sort of I'm solution, but you need to, look at those solutions now within the lens of, okay, have 1,000 employees, but I have 27,433 agents that they produced. So identity is a big thing. Once you have that, you need to be able to map identities to to software and systems, and then you need to be able to map identity to data in those software and systems. And, you know, we kinda look at it as like the three layer three control planes that you need to put in place.

[00:15:24] - [Speaker 1]
You need an identity control plane. You need an act, action control plane. So what what can people and and agents take action on? And then you need a data layer control plane. Once they've taken action on systems, what data in those systems can they do what with?

[00:15:40] - [Speaker 1]
So it's like three layers there.

[00:15:42] - [Speaker 0]
And you mentioned that teams could be creating, what, 27,000 plus agents. In a few years, that figure will probably be incredibly conservative with with individuals having multiple agents, even not if not dozens of them to for various tasks. Do you think the average enterprise from the conversations that you're having, do they get that identity identity question question that that that goes with those agents and the responsibilities around that? Is it something you get asked a lot?

[00:16:09] - [Speaker 1]
Yeah. I think they do understand it. Yeah. You know, a year ago, no. Yeah.

[00:16:13] - [Speaker 1]
But now, yes. Absolutely. And that's why that market's exploding right now. You can't swing a dead cat without hitting an agentic identity access management company that's coming out of the VC woodwork. You know, I'm in the Bay Area, so I see it all the time.

[00:16:26] - [Speaker 1]
But I def I definitely think that that that issue is is well recognized. I don't know if it's well solved yet, but we'll see.

[00:16:37] - [Speaker 0]
And if there's a board member listening wanting evidence of a maybe a genuine readiness rather than just another reassuring dashboard or report. What what should it ask the organization to demonstrate if we got a board member listening today?

[00:16:52] - [Speaker 1]
Yeah. What are your data controls?

[00:16:54] - [Speaker 0]
Yeah.

[00:16:56] - [Speaker 1]
And if it's not a clear answer, you're screwed. You can again, you can have the identity. You can have the the action controls. It's fine. You should do that.

[00:17:11] - [Speaker 1]
But if you haven't thought through what your data controls are, those other things don't matter.

[00:17:16] - [Speaker 0]
Yeah. Yeah. And any other follow-up questions for them if if they're going in there up against the techies and they're asking that big question? Anything else they should be asking?

[00:17:25] - [Speaker 1]
I think I go back to your earlier question to me, which is pinpointing who who's on blast for this Yeah. Responsibility and getting getting that really sorted out? The who owns the risk around this productivity that we as a board have required of our companies to deliver more shareholder value? If you don't have a clear understanding, of that responsibility, then it it's a real problem for you.

[00:17:59] - [Speaker 0]
I thought you're gonna say you're screwed again.

[00:18:01] - [Speaker 1]
Yeah. I know. Unscrew the podcast. That's my rule.

[00:18:06] - [Speaker 0]
And, of course, the the report, I will include links to it. The 2026 data security and compliant risk, the AI governance gap. I'll include a link so that people could check it out and look at some of the stats. But, obviously, we've spoken three times. You know this stuff inside out.

[00:18:22] - [Speaker 0]
When you look at a report like this, in particular this one, did anything surprise you in there? Did anything jump out at you? No. No. Yes.

[00:18:31] - [Speaker 1]
I expected everything. Yeah. Sounds about right. And also it's relieving because, you know, to some degree, you kinda never know what how the market is gonna take surveys, and you don't want a lot of surprises because it then you get to the bullshit meter. Yeah.

[00:18:48] - [Speaker 1]
Everything I saw in there, I was like, yeah. That makes sense.

[00:18:52] - [Speaker 0]
Love it. Well, as you said at the very beginning, eighty percent of organizations have experienced a security or AI related incident. Possibly 20% were lying as we jokingly said there, but I will add a link to the report. And people wanting connect with you, your team, find out more information about Kiteworks, where where would you like me to point them?

[00:19:11] - [Speaker 1]
Yeah. I mean, through Kiteworks, obviously, kiteworks.com, but I welcome all the connections in the world at linkedin.com/ tim freestone, I think, my URL there. No. You can just go I'm the only actually, there's there's another Tim Freestone on LinkedIn. I'll take that back.

[00:19:27] - [Speaker 1]
There are three. There are three of us in the world on LinkedIn. I'm the one that works at Kiteworks.

[00:19:34] - [Speaker 0]
Lovely. Well, I will include the correct link to the, the the real Tim there. But

[00:19:38] - [Speaker 1]
I I

[00:19:40] - [Speaker 0]
and I also encourage everyone, listen, share your stories and experiences. This is a dialogue, not a monologue, I'd love to keep this one going. But more than only just thank you as always for coming on here, sharing your insights, and having a bit of fun with it as well. Really appreciate your time.

[00:19:54] - [Speaker 1]
Yeah. Thanks, Neil.

[00:19:56] - [Speaker 0]
One of Tim's many messages today is that AI governance becomes much easier to test when leaders stop asking whether they have enough security products and actually start asking what can touch their data. And ultimately, this means knowing every single human and nonhuman identity, Not to mention the actions that each of those identities can take and the information that that each of these actions can reach. Because, yes, a reassuring dashboard is useful, but when an auditor comes knocking, they're gonna wanna see real evidence showing who or what is being used, sent, or shared, especially when it comes to regulated data. So a massive thank you as always to Tim for returning to the show and giving us a timely reminder that strategy, ownership, and usable records, all these things matter more than ever, especially when machines are moving faster than people can follow. And as always, you can learn more at kiteworks.com.

[00:21:00] - [Speaker 0]
I'll include a link to the company's 2026 survey report. Let me know your thoughts on that. And a bit of homework for you too. What evidence could your organization produce today if an auditor came knocking asking how your AI systems handle sensitive or regulated data? If that question alone makes the hairs on the back of your head stand up, maybe we've got an issue here.

[00:21:25] - [Speaker 0]
Well, let me know. Techtalksnetwork.com. I'd love to keep this conversation going, and a big thank you as always to Tim for starting it. But that's it. We're out of time now.

[00:21:35] - [Speaker 0]
Remember, you can meet me on the road at many tech events, so have a look on the event page. If you wanna work with me, send me an audio message, all this stuff, or browse through 4,000 episodes. Again, techtalksnetwork.com. But that's it for today. I'll be back again tomorrow with another guest, but thank you for listening as always.

[00:21:56] - [Speaker 0]
Bye for now.