惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
博客园 - 司徒正美
D
DataBreaches.Net
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
腾讯CDC
博客园_首页
The Cloudflare Blog
S
SegmentFault 最新的问题
C
Check Point Blog
美团技术团队
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
T
The Blog of Author Tim Ferriss
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
A $2 trillion revenue shift hinges on AI data governance ...
Anamarija Pogorelec · 2026-06-16 · via Help Net Security

Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries a cost.

AI data governance

Many enterprises have seen AI initiatives stall over the past year, and the ones stalling most often carry the highest revenue potential: AI-driven marketing, data monetization, personalization, and cross-brand analytics. These are the projects that justify AI spending to the board, so a stall in one of them makes the case for the next investment harder.

Where the time goes

The drag shows up inside engineering teams. A large share of the hours inside AI initiatives goes to data infrastructure repair, consent compliance, and governance workarounds, leaving a smaller slice for building and improving the product itself. Weak consent and preference management also exposes companies to regulatory action, consumer lawsuits, and mass opt-outs.

A structural cause

The root cause sits in architecture. For a decade, enterprises captured consent at the point of collection, stored it in the CRM, and trusted the rest of the stack to respect it. That model worked when data moved slowly and AI sat outside the picture. The model breaks down once data moves at machine speed.

The gap lives between access and usage. Security answers whether a system can reach data. Privacy answers whether a system can use it. A user can download a file or feed a dataset into a model without breaking any access control and still break the promise the business made to the customer who owns the data. With agentic AI pulling and processing records on its own, capture at the point of collection and after-the-fact auditing leave that gap open. Legacy consent and preference tools sit upstream, away from the warehouse, feature store, model pipeline, and agent runtime where data gets consumed.

Encoded governance

Transcend defines a category it calls Encoded AI Governance. The approach embeds permission logic directly in the data path, so a pipeline, model API, or agent runtime allows or denies an operation at the moment a system attempts to use the data. The logic covers what data can be used, for what purpose, under what conditions, and on whose authority, and it runs at the point of use.

“Governance will never work until the permissions and business rules are encoded into the systems that process customer data,” said Ben Brook, Transcend’s CEO and co-founder.

The distinction separates two things that often share the same name. Policies, model cards, and audit logs describe what should happen and record a violation after the fact. Executable controls in the data path determine what does happen and deny an operation before the data leaves the store. Most enterprises hold the first kind and lack the second.

A phased path

Companies moving in this direction tend to start by mapping where consent signals originate and which tools act as systems of record. From there they unify those signals into one decisioning layer, move enforcement from review queues into runtime, and reuse the same permission logic as they add brands, regions, and AI use cases. The path produces value before it is complete, and early wins often come from surfacing hidden trackers and data flows that a prior tool missed.

Several large companies have already deployed the approach across retail media, telecom, and AI services, unifying consent across many business entities and automating privacy requests at scale. The stakes behind the work are large. Industry research projects that $2 trillion in revenue will shift toward personalization leaders over the next five years, and the companies that activate permissioned data first stand to capture it.

Download: The IT and security field guide to AI adoption