Every organization in financial services and healthcare has been asked the same question by a board or an executive team in the last eighteen months. What are we doing about artificial intelligence.
The answer that usually follows is a pilot. A tool is selected, a small group tries it, and the organization can report that something is underway. That is a reasonable response to the question asked. It is also why so many pilots end up without going anywhere.
The pilot is not the hard part. The hard part sits underneath it, and it has nothing to do with which model or which vendor.
The first real question is what data you have and who can reach it.
Any assistant, copilot, or search tool that is useful inside an organization is useful because it can see internal information. That is the entire value proposition. It is also the entire risk.
Which means the deployment question is not what the tool can do. It is what the tool will be able to see, on whose behalf, and whether the answer to that is actually known.
In most organizations it is not known for confidence. Shared drives have accumulated for fifteen years. Permissions were granted for projects that ended. Folders inherited access from parent folders that were restructured twice. Nobody has audited it, because until recently nothing forced the issue. A person with excessive access has to go looking. A tool with excessive access surfaces things helpfully, at speed, to whoever asked.
Artificial intelligence does not create this problem. It reveals it.
This distinction matters, because it changes what the work is.
An organization that deploys an assistant and discovers that salary data, board materials, or patient information is reachable by people who should not reach it has not been harmed by the assistant. It has learned something true about its environment that was already true yesterday.
That is genuinely useful information. It is considerably less useful when it is learned through an incident report rather than through an inventory.
What regulated organizations must be able to show?
In a less regulated environment, an organization can move quickly and correctly as it goes. In financial services and healthcare, that option is narrower.
A regulator will not ask whether the tool is helpful. The questions are more specific. What data does it process? Where does that data go? Who approved of that? How is access governed? What record exists of the decision? Can you demonstrate the control functioned over a period rather than on the day we asked.
Those questions are answerable only if the underlying work was done first. An organization that classified its data, cleaned up access, and documented the decisions can answer them in an afternoon. One that started with a pilot will spend months reconstructing an answer.
A sequence that works.
None of this argues for waiting. It argues for a different order.
- Inventory. Know what data exists, where it lives, and what category it falls into. Unglamorous and slow, and it is the whole foundation.
- Access. Review who can reach what, and remove what accumulated. This has standalone security value even if no artificial intelligence tool is ever deployed.
- Classification. Decide what may never be processed by an external service, what may be with controls, and what is unrestricted. Write it down and have it approved.
- Then pilot, narrowly. One use case, one defined data set, measured against something specific.
Organizations that run this sequence tend to move faster overall, not slower, because the second and third use cases arrive without renegotiating anything. Organizations that pilot first usually pause at the point of scaling, when someone finally asks the governance question and the answer takes a quarter to assemble.
The unfashionable version of the advice
The most valuable artificial intelligence work most regulated organizations can do this year is data governance work that predates artificial intelligence by a decade. Inventory, classification, access review, and documented decisions.
It does not present well to a board. It is the difference between a pilot that scales and a pilot that quietly ends.
System Custom Consultants work with healthcare, financial services, and public sector organizations on the foundations that make technology adoption defensible, including data governance, access review, and program management that keep the work moving. If you are being asked what you are doing about artificial intelligence, start a conversation at systemcustom.com
