惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
A $2 trillion revenue shift hinges on AI data governance ...
Anamarija Pogorelec · 2026-06-16 · via Help Net Security

Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries a cost.

AI data governance

Many enterprises have seen AI initiatives stall over the past year, and the ones stalling most often carry the highest revenue potential: AI-driven marketing, data monetization, personalization, and cross-brand analytics. These are the projects that justify AI spending to the board, so a stall in one of them makes the case for the next investment harder.

Where the time goes

The drag shows up inside engineering teams. A large share of the hours inside AI initiatives goes to data infrastructure repair, consent compliance, and governance workarounds, leaving a smaller slice for building and improving the product itself. Weak consent and preference management also exposes companies to regulatory action, consumer lawsuits, and mass opt-outs.

A structural cause

The root cause sits in architecture. For a decade, enterprises captured consent at the point of collection, stored it in the CRM, and trusted the rest of the stack to respect it. That model worked when data moved slowly and AI sat outside the picture. The model breaks down once data moves at machine speed.

The gap lives between access and usage. Security answers whether a system can reach data. Privacy answers whether a system can use it. A user can download a file or feed a dataset into a model without breaking any access control and still break the promise the business made to the customer who owns the data. With agentic AI pulling and processing records on its own, capture at the point of collection and after-the-fact auditing leave that gap open. Legacy consent and preference tools sit upstream, away from the warehouse, feature store, model pipeline, and agent runtime where data gets consumed.

Encoded governance

Transcend defines a category it calls Encoded AI Governance. The approach embeds permission logic directly in the data path, so a pipeline, model API, or agent runtime allows or denies an operation at the moment a system attempts to use the data. The logic covers what data can be used, for what purpose, under what conditions, and on whose authority, and it runs at the point of use.

“Governance will never work until the permissions and business rules are encoded into the systems that process customer data,” said Ben Brook, Transcend’s CEO and co-founder.

The distinction separates two things that often share the same name. Policies, model cards, and audit logs describe what should happen and record a violation after the fact. Executable controls in the data path determine what does happen and deny an operation before the data leaves the store. Most enterprises hold the first kind and lack the second.

A phased path

Companies moving in this direction tend to start by mapping where consent signals originate and which tools act as systems of record. From there they unify those signals into one decisioning layer, move enforcement from review queues into runtime, and reuse the same permission logic as they add brands, regions, and AI use cases. The path produces value before it is complete, and early wins often come from surfacing hidden trackers and data flows that a prior tool missed.

Several large companies have already deployed the approach across retail media, telecom, and AI services, unifying consent across many business entities and automating privacy requests at scale. The stakes behind the work are large. Industry research projects that $2 trillion in revenue will shift toward personalization leaders over the next five years, and the companies that activate permissioned data first stand to capture it.

Download: The IT and security field guide to AI adoption