Data‑First Security Strategies for Enterprise AI
The article examines the gap between AI adoption and data governance, noting that 88% of organizations use AI but only 35% have full visibility into unstructured data. It presents four insights from experts: real-time mapping of sensitive data flows, unified governance, pre-development accountability frameworks, and data-level security controls.
This interview analysis is sponsored by Securiti and was written, edited, and published in alignment with our Emerj sponsored content guidelines. Learn more about our thought leadership and content creation services on our Emerj Media Services page.
The promise of enterprise AI meets a reality where models and agents can access sensitive data faster than organizations can see, govern, or explain that access — a gap that leaves leaders unable to prove compliance, contain exposure, or defend how AI is using their data.
Stanford HAI reports 88% of organizations now use AI in a business function, while documented AI incidents jumped to 362 in 2025, up from 233 the year before. The GAO found that AI use in financial services introduces data quality, privacy, and cybersecurity risks regulators are actively examining.
The Cloud Security Alliance reports that only 35% of organizations have full visibility into where unstructured data resides. Just 9% have real‑time scanning capabilities, and 23% cannot scan unstructured data for risks at all — structural limits that constrain what any AI system can do well.
Emerj’s Yolandi de Weerdt recently hosted a conversation with Chris Joynt, Director of Product Marketing at Securiti; James Dean, AI Specialist at Google Cloud; Mark Crean, Regional Vice President of Sales at Securiti; Dr. Oscar Rodriguez, Vice President, Data Analytics at Citi; and Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team.
This article outlines four insights that define the core data, governance, and security requirements for safe and scalable AI in financial services:
Real‑time mapping of sensitive data flows for pre‑ingestion control: Stops ungoverned unstructured data from entering AI systems by revealing where sensitive information lives and moves.
Unified governance for AI‑ready data across teams: Ensures models and agents only operate on compliant, authorized information so financial AI can scale beyond isolated pilots.
Pre‑development accountability frameworks for AI decision‑making: Establishing ownership before models are built prevents governance failures that stall deployment as systems move toward production.
Data‑level security controls for AI ingestion and retrieval: Restrict and sanitize sensitive data at the source so AI systems access only authorized information and breaches can be contained instantly.
Real‑Time Mapping of Sensitive Data Flows for Pre‑Ingestion Control
Episode 1: Why Granular Visibility and Data Control Determines AI Success in Financial Services – with Chris Joynt of Securiti
Guest: Chris Joynt, Director of Product Marketing at Securiti AI
Expertise: AI Security, AI Trust, Product Marketing, Go-to-Market Strategy
Brief Recognition: Chris Joynt is Director of Product Marketing for AI Security at Securiti. Previously, he led product marketing for Cloudera’s Data in Motion portfolio, held multiple AI and IoT leadership roles at PTC, and began his career in advanced analytics at IBM. He holds a bachelor’s degree in Business Administration with concentrations in Marketing and Finance from Temple University.
Chris Joynt describes data estates where unstructured content has grown beyond what traditional governance practices can inspect. He points to customers operating across more than 200,000 data systems, generating billions of files and producing a petabyte of logs per day. At that scale, even determining what sensitive information exists in those files becomes a structural challenge — and that challenge appears before any model is built or evaluated.
Joynt’s central point is that once unstructured data is ingested, transformed, or vectorized, organizations lose meaningful visibility into how it is being used. The original form becomes obscured, derivative copies proliferate, and governance teams cannot reliably trace how sensitive information reached an AI system.
Pre‑ingestion visibility becomes the only place where control can be exerted:
“Unstructured data became gold overnight. Institutions generate enormous volumes of it — logs alone can reach a petabyte a day. You can’t throw that into AI and hope the model figures it out. You need to know what’s in those files, how sensitive they are, and where they’re moving. Once the data is inside the model, you’ve lost control of it. Visibility into the flows is the first layer of safety.”
— Chris Joynt, Director of Product Marketing at Securiti
AI activity may already be occurring outside formal oversight, according to Chris. Shadow AI becomes possible when teams lack discovery into where data is going or which systems are processing it. Mapping flows is the first step toward understanding how content moves, how it is transformed, and where sensitive information may already be exposed.
His practical guidance for C‑suite leaders forms a clear pre‑ingestion framework:
Map sensitive data flows — Establish factual visibility into where unstructured content resides and how it moves across systems.
Classify and label unstructured content — Identify PII, transactional records, regulated content, and business‑confidential information before AI systems ingest it.
Define AI access boundaries — Specify which models, agents, and retrieval pipelines can access particular categories of sensitive data.
Monitor transformations and derivative paths — Track how content is merged, vectorized, or copied so governance teams can see where exposure originates.
Detect shadow AI — Surface AI systems already processing sensitive information outside formal governance.
Joynt’s takeaway is structural: pre‑ingestion visibility is the foundation of AI governance. Once sensitive data enters a model, its transformations and derivatives become difficult to track, and control becomes reactive rather than preventative. Mapping flows, classifying content, and defining boundaries upstream gives leaders the factual baseline required to govern AI safely at scale.
Unified Governance for AI‑Ready Data Across Security, Data, and Business Teams
Episode 2: Why Financial AI Can’t Scale Without Unified Governance with James Dean of Google and Mark Crean of Securiti
Guest: James Dean, AI Specialist at Google Cloud
Expertise: Generative AI, Enterprise AI Strategy, Go-to-Market Strategy, AI Sales
Brief Recognition: James Dean is a Generative AI Specialist at Google Cloud, where he has also led global AI go-to-market strategy and advised enterprise leaders on AI adoption. Previously, he held AI and enterprise sales leadership roles at H2O.ai, SAP, and WealthEngine. He holds an MBA in International Business from Pepperdine Graziadio Business School and a bachelor’s degree in Finance from Northeastern University.
Guest: Mark Crean, Regional Vice President of Sales at Securiti AI
Expertise: AI Security, Data Security, Identity & Access Management, Enterprise Sales
Brief Recognition: Mark Crean is Regional Vice President of Sales at Securiti AI, where he leads strategic enterprise sales across the Americas. Previously, he held sales leadership roles at Ping Identity, ForgeRock, and Oracle, specializing in identity, cloud, and data security solutions. He holds a bachelor’s degree in Marketing and Management from the University of Delaware.
Scaling AI in financial services stalls when security, data, and business teams operate from different definitions of AI‑ready data. Mark Crean and James Dean both point to this fragmentation as the reason pilots remain trapped in innovation labs while high‑value use cases struggle to reach production. Productivity tools and coding assistants move quickly; enterprise‑level AI does not — because governance is not unified.
James Dean underscores the operational gap: post‑POC deployments fail when institutions cannot secure petabytes of sensitive data or reconcile siloed datasets. Half of banks, by his estimate, still have data locked in isolated systems, preventing models and agents from accessing compliant, authorized information. Crean adds that even when AI proliferates internally, organizations lack shared guardrails for access, context, and rollback — leaving teams unsure how to adopt AI safely at scale.
Their combined framing is clear: AI governance becomes scalable only when security, data, and business teams align on a single definition of AI‑ready data and enforce it consistently across the enterprise.
“Aligning stakeholders is always step one. As models and agents proliferate, what guardrails and controls are you putting in place to ensure users can safely adopt these tools? What data security practices ensure the data integrity can be trusted?”
— Mark Crean, Regional Vice President of Sales at Securiti
“It starts by aligning the CISO, data scientists, and business leaders on a shared definition of AI‑ready data. From there, they map governance to every phase and automate data classification before training or cloud migration.”
— James Dean, AI Specialist at Google Cloud
Their guidance forms a unified governance mechanism that C‑suite leaders can operationalize:
Define AI‑ready data across functions — Establish a shared definition used by security, data, and business teams to determine what information models and agents are permitted to access.
Automate classification before training — Use NLP‑driven scanning to tag hidden PII, KYC, and regulated content so restricted information never enters training pipelines.
Embed access controls into model operations — Enforce strict authorization boundaries and auditability directly within model workflows, not as an external afterthought.
Establish guardrails for agent adoption — Define context requirements, error‑handling expectations, and rollback mechanisms so agents operate safely as they proliferate across the enterprise.
Integrate governance with compliance readiness — Align governance practices with emerging state‑level and global regulations to ensure models and agents operate within approved boundaries.
The structural result is models and agents only operate on compliant, authorized information, enabling financial institutions to move beyond isolated pilots and into enterprise‑scale AI deployment without compromising security, compliance, or data integrity.
Pre‑Development Accountability Frameworks for AI Decision‑Making
Episode 3: How Financial Services Leaders Operationalize Safe AI – with Dr. Oscar A. Rodriguez of Citi
Guest: Dr. Oscar A. Rodriguez, Vice President, Data Analytics at Citi
Expertise: Data Analytics, Enterprise Data Strategy, Business Intelligence, AI Governance
Brief Recognition: Dr. Oscar A. Rodriguez is Vice President of Data Analytics at Citi, where he leads enterprise data and analytics initiatives for the financial services sector. Previously, he held data leadership roles at Liberty Mutual Insurance, Blockchain Strategy Group, and FCCI Insurance Group. He holds a doctorate in Strategic Business Leadership from Regent University and a master’s degree in Management Information Systems from Florida State University.
AI projects inside financial institutions often collapse at the exact moment they should scale. Dr. Oscar Rodriguez points to a simple cause: teams build before they decide who owns the outcomes. When accountability is undefined, governance becomes a scramble, and the scramble begins only after the model already exists, when it is too late to shape its assumptions, its data, or its risk posture.
Rodriguez sees this repeatedly. Business units race to experiment. Data teams work from disconnected sources. Security and compliance arrive after the fact. Leadership focuses on future risk while teams focus on proving value. The result is not technical failure but organizational misalignment. Models demonstrate promise in early testing, then stall under scrutiny because no one agreed on standards, ownership, or governance before development began.
A pre‑development accountability framework prevents that s
[truncated for AI cost control]