Your backlog has a deadline: What AI adoption does to unremediated data risk 

Your remediation backlog was survivable when nothing was reading it. Here's how to prioritize AI data security before sensitive data reaches AI systems.

Everyone has a backlog. Now there’s a deadline. 

Let’s get one thing out of the way early: your remediation backlog is not a personal failing. Every organization has one. Every organization has always had one. Somewhere in your environment there is a storage bucket whose owner left the company in 2021, a finding that’s been reassigned three times and quietly reclassified as low priority, and a folder called temp_final_v2 that has outlived two reorgs and one acquisition. 

This is not incompetence!  

Discovery scans generate findings faster than humans can close them, new data arrives faster than old data gets cleaned up, and remediation almost always requires cooperation from someone whose bonus depends on something else entirely. The backlog is the natural resting state of data security.  

For years, that was fine. Uncomfortable, occasionally embarrassing in a board meeting, but fine. The data sat there mostly untouched… until AI came along. 

Your backlog is not to blame 

The queue was never the problem. The backlog was survivable because it was static. Sensitive data in a forgotten repository was exposed in theory, to a specific and fairly small population: whoever had permissions, whoever could find it, and whoever was motivated enough to look. 

Then organizations started pointing AI systems at their own data, and the theoretical population became everyone who can type a question. The numbers show this reality. 

In a global study of 2,000 IT and IT security practitioners and executives conducted by Ponemon Institute and sponsored by OpenText, 58 percent of organizations had deployed AI technologies. Only 21 percent described their AI programs as mature. 

The governance side is where it gets uncomfortable. Sixty-one percent named minimizing data risks as a top governance challenge. Fifty-nine percent named compliance with privacy and security regulations. And more than half said they expect AI agents to significantly increase data theft, a notable thing for a population to believe while continuing to deploy them. 

AI did not create your backlog. Rather, it found a use for it. 

Data security risk increases when AI reaches old data 

The repositories generating the most findings tend to be the oldest and least governed. Legacy file shares. Cloud storage nobody has reviewed since the migration. Collaboration sites where permissions were inherited from a group that no longer exists. 

Those are also, unfortunately, the repositories AI teams like best. The content is abundant, unstructured, and nobody has ever told them not to use it. 

Three things change the moment that data gets connected. 

Copies stop being countable. Sensitive values land in vector stores, embeddings, caches, prompt logs, and generated responses. Each one exists outside the scope of the finding that was supposed to cover it. 

Access controls stay behind. Permissions govern who opens a file. They do not govern what an assistant says when someone asks a question the file happens to answer. 

Agents remove the pause. A person who stumbles onto a folder of unredacted records usually hesitates. An agent completes the task and moves on to the next one. 

An open finding used to mean the data was simply reachable. Now it can mean the data is conversational. Organizations need a broader approach to data security that helps them discover, understand, and protect sensitive data wherever it resides. 

The part that shows up in the audit 

Three costs, in ascending order of how much they will ruin your quarter. 

Findings age badly. A finding open at one assessment is a work item. The same finding open at the next assessment is evidence of a control gap, and auditors have started asking specifically how AI systems handle regulated data. “We know exactly where it is” is not the answer to that question. It’s the setup for a worse one. 

Retrofitting is brutal. Once sensitive data flows into pipelines, indexes, and derived datasets, pulling it back out means unwinding every downstream artifact it touched, and then proving you got all of them. Protecting the data before ingestion costs a fraction of that, and you pay it once. 

The volume is not on your side. Global data is projected to reach 394 zettabytes by 2028. Statista But with the relentless growth of AI we could expect this to grow even faster! Every quarter the backlog stays open, more of it becomes AI-accessible by default rather than by anyone’s decision. 

How to prioritize data security before AI adoption 

Nobody is closing this backlog. That’s still not the goal. The goal is changing which parts of it you close first. 

  1. Triage by connection, not by count. Which repositories are already wired to a copilot, retrieval system, or agent — or on the roadmap to be? That subset is the actual queue. The rest can wait. 
  1. Rank by what the data is worth to someone else. Financial exposure gets budget approved. Severity labels get meetings scheduled. 
  1. Protect the data before it moves. Masking, tokenization, and encryption applied at the source travel into every downstream copy. Permissions don’t. 
  1. Delete things. Redundant and outdated data is the only remediation that’s free and permanent. It is also the only one nobody ever gets promoted for. 
  1. Report the trend, not the total. Time-to-remediation, tracked the way your operations team tracks vulnerability closure. The total will never look good. The trend can. 

The visibility problem is broadly solved. The backlog was a tolerable liability right up until the moment something started reading it — and that moment has already happened in most environments, whether or not it made it onto anyone’s risk register. 

Nik Earnest

Nik Earnest is a Product Marketing Manager at OpenText focused promoting AI, ML, and behavior analytics in cybersecurity. He currently manages product marketing for OpenText ArcSight Intelligence and Cybersecurity Aviator. With exciting advances in AI, Nik is committed to equipping customers with the tools they need to defend against advanced attacks and insider threats, ensuring the security and integrity of their organizations.
Check Also
Close