Data security posture management for AI: how to prepare your sensitive data
Before AI accesses sensitive data, organizations need to discover it, review access, reduce risk, and protect what remains.

Image a repository nobody has fully mapped. Maybe it’s a shared drive left over from a reorg. Maybe it’s a database inherited from an acquisition. It sat there for years, technically reachable but practically ignored. Then someone connected an AI tool to it. Now it gets read on request, summarized, and cited in an answer. Nothing about the repository changed. What changed is that AI can now access and interpret it.
Getting that data ready for AI access comes down to four things. Find out what your repositories actually hold. Review who can already reach them. Cut what doesn’t need to stay. Protect what does. We’ve written about this in AI data protection: what models can’t unlearn. This piece is where this four-part checklist came from.
1. Find out what the repositories actually hold.
2. Review entitlements on those repositories
The Voltage DSP also shows who’s already entitled to reach each repository it scans. That means the access review starts from evidence, not a blank spreadsheet. You can also scope it to what’s actually connected to an AI tool right now, instead of trying to review the entire estate at once.
3. Reduce unnecessary data
An AI tool can’t retrieve data that no longer exists. Redundant, obsolete, and trivial (known as ROT) data can and should be defensibly deleted before it ever becomes a risk. For structured data (think databases) — usually where volume adds up fastest — OpenText™ Voltage™ Structured Data Manager finds inactive and redundant records and moves them into governed archives, or deletes them under policy. Voltage DSP handles the same job for unstructured repositories, flagging ROT as part of its discovery scan. In practice, that combination can cut production data volume by as much as half.
4. Protect the data that remains
Some data has to stay in circulation no matter what. OpenText™ Voltage™ SecureData Servers applies NIST-standardized format-preserving encryption and tokenization. Keys are derived dynamically instead of stored, so there’s less for an attacker to ever find. The data keeps its usable shape for the business. The values underneath stay protected in transit, at rest, and in use.
Why data security posture management needs a platform, not four separate projects
Each of these products closes one part of the checklist on its own. Run together, under OpenText’s data security portfolio, they close all four continuously. New repositories get discovered and classified as they appear. Redundant data keeps getting reduced. Sensitive values stay protected as the data estate changes underneath them. That’s a very different thing than a report that was accurate for exactly the day it was generated.
That continuous loop is what data security posture management for AI actually means. It isn’t a one-time answer to “is this repository safe.” It’s a standing one — one you can give at any point, to anyone who asks. An AI tool will read whatever your access model already allows. It won’t stop to ask whether it should. These four steps, run by three purpose-built products, are how you make sure that when someone asks what it can reach, you already know the answer.




