Select Page

DATACON 2026: Governing Data in the Age of Copilot

Your copilot doesn’t need more data. It needs better context.

Many organizations are asking whether they’re ready for Copilot, but a better question would be: is your data ready for Copilot?

As AI moves beyond answering questions and begins interacting with business systems, workflows, and decision-making processes, governance becomes much more than an access-control problem. Organizations now need to understand what AI can access, what it should trust, and what actions it should be allowed to take.

That’s where many AI initiatives run into trouble.

The issue often isn’t whether AI can find information. The issue is whether it can find the right information, understand which sources are authoritative, and operate within clearly defined guardrails.

At DATACON 2026, Jay Natarajan, Vice President of AI, Datavail, and Brook Shuford, CISO, Datavail, presented on a practical framework for governing data, business context, and AI-driven actions so organizations can move from experimentation to trusted enterprise AI.

What You’ll Learn

  • Why governance must evolve from managing data access to governing context, actions, and evidence.
  • The three core AI governance risks organizations need to address before scaling Copilot and AI agents.
  • How excessive permissions become AI exposure when Copilot can surface information users may have forgotten they can access.

Move from AI Experimentation to Trusted Enterprise AI

The organizations seeing the greatest value from Copilot and AI agents aren’t simply enabling new technology. They’re establishing trusted context.

Access controls, business definitions, governance processes, approvals, and accountability all play a role in helping AI deliver business value safely and reliably.

Explore the presentation “Governing Data in the Age of Copilot” to learn how to identify governance gaps, establish trusted business context, govern AI-powered actions, and create a roadmap for responsible AI adoption across your organization.

Frequently Asked Questions

What is the difference between access risk and context risk?

Access risk occurs when AI surfaces information that users can technically access but may no longer need. Context risk occurs when AI encounters multiple sources with conflicting answers and lacks guidance on which source should be considered authoritative.

Why do organizations need authoritative business definitions?

Trusted AI depends on more than access permissions. Organizations need shared definitions, certified metrics, data lineage, ownership, and governance processes so AI can consistently provide answers grounded in trusted enterprise data.

What should organizations consider before deploying AI agents?

Organizations should establish controls around identity, approved data sources, tools, approvals, monitoring, auditability, and ownership. Once agents can take action, governance requirements become operational requirements.