Can You Vouch for Your AI?
The habits that make AI efficient are the same ones that let you vouch for it.
In an earlier blog, we followed a single document through a day-long AI chat. It was pasted in near the top, then quietly re-sent with every message after it. We talked about what that costs: money, quality, and energy.
This time we want to ask a different question about the same document.
Where did it go? Which tool received it? Under whose account? Is it stored somewhere now, and for how long? Could it end up training someone else's model? And if a customer asked tomorrow, could anyone in your organization answer?
Most teams have crossed the adoption milestone, and many are now working on using AI efficiently. The next question comes from legal, from the security, from the board, and increasingly from customers: Can you vouch for it?
We think this is the question that decides which organizations get to scale AI, and which ones stay stuck in pilot mode.
Every paste is a data transfer
Picture that same day-long chat thread. Somewhere in it is a customer contract. A spreadsheet with names and salaries. A chunk of proprietary code. None of it was pasted with bad intent. It was pasted because it was the fastest way to get the job done.
That's the problem. In a chat window, sharing data doesn't feel like sharing data. It feels like typing. Think of it as an iceberg. Above the waterline is a text box and a helpful answer. Below it, with a hosted AI service, is everything you don't see: data moving outside the environment your organization controls, often without a clear record of what was shared, with which service, and under which controls.
Now add shadow AI. When the approved tool is slow, limited, or missing, the need for AI doesn't go away. People find another way to get the work done, often with tools the organization has never reviewed. It's rarely carelessness; it's people trying to do their jobs well. But sensitive data can still leave the controlled environment, just through a door nobody is watching.
AI risk comes in three layers
Most conversations about AI security stop at the first layer. The other two are where things are heading.
The first layer is what goes out. Personal data, client information, intellectual property: anything you put into a hosted AI service can leave the environment you directly control. This is the familiar one, especially when personal data is involved.
The second layer is what comes in. A model can't reliably tell the difference between content it should read and instructions it should follow. Ask an assistant to summarize an email, and if that email contains instructions planted by an attacker, the AI may treat them as something to follow rather than something to summarize. This is prompt injection. It means context isn't just a cost or quality question anymore. Context is an attack surface.
The third layer is what it can do. AI is moving from answering to acting: sending emails, editing files, calling APIs, running code. An agent's permissions define its blast radius. When a chat gives a wrong answer, a person reads it and moves on. When an agent with write access to your customer records gets it wrong, or gets talked into something, the damage can be done before anyone has a chance to step in.
Compliance isn't the finish line. It's the receipt.
The regulatory picture is getting sharper. The EU's AI Omnibus entered into force in July 2026 and pushed the application date for obligations covering Annex III high-risk systems from 2 August 2026 to 2 December 2027. But August 2026 still brought transparency obligations into force, including transparency requirements for certain AI interactions and AI-generated or manipulated content. Many read "deadline moved" as "we can relax." We read it differently. The deadline moved. The risk didn't.
And regulators aren't the only ones asking. GDPR applies whenever AI use involves processing personal data, whether that happens in a traditional system or in a prompt. Depending on your industry, sector-specific rules on cybersecurity and operational resilience add their own requirements. And AI questions are showing up in customer security questionnaires.
What they all have in common: they don't ask what your policy says. They ask you to show it. Which tools are approved? What data went where? Who approved that agent's access? If you can't show it, then from an auditor's point of view, it didn't happen.
Efficient and secure are the same habit
Here's the part we find most encouraging: the habits that make AI efficient are largely the same habits that make it secure.
Sending the slice instead of the whole PDF cuts tokens and exposure at the same time: that's data minimization, a core GDPR principle. Keeping one task in one chat is a form of containment: it reduces the chance that irrelevant or sensitive context carries into the next task. And focused context leaves fewer places for a malicious instruction to hide.
Efficiency and security are not in tension. Teams that already practice good context engineering have already built some of the habits AI governance depends on.
From context engineering to context governance
When we wrote about efficiency, we suggested three questions before anything goes into context. For security, add three more:
- Should this leave our walls? If it's personal, confidential, or not yours to share, it doesn't go into a tool that isn't approved for it.
- Is the model allowed to act on this, or only read it? Treat external content (emails, web pages, uploaded files) as untrusted data, not as instructions.
- Could we explain this to an auditor or a customer? If the honest answer makes you uncomfortable, that's your answer.
None of this starts with a big program. It starts with habits. Make the approved tool the easiest option: if it's genuinely good, people have no reason to look elsewhere, and bans rarely stop AI use anyway; they just make it invisible. Classify data before it's pasted, not after. Give agents the smallest set of permissions that gets the job done. Require a human to approve anything irreversible: sending, deleting, paying, publishing. And log what matters, so the receipt exists when someone asks for it.
Human in the loop, with a signature
We've argued before that context engineering is a form of human control: people actively deciding what the model sees and how the task is framed. Security adds another requirement: accountability needs a name.
An AI system can't be accountable. A person can. Every AI tool, workflow, and agent in your organization should have an owner: someone who decided what it can see and what it can do, and who checks that this is still true six months later. Oversight without ownership is just hope.
How Knowit helps teams build trust into AI
This is where our AI Advisory and security work meet. We help organizations put practical AI policies in place that people can actually follow. We help choose approved tooling that removes the reason for shadow AI, and we map AI use cases against regulatory requirements before they become audit findings.
For teams moving into agents, we design permissions, approval points, and logging from the start, so autonomy grows only as fast as control does. And through hands-on trainings and workshops, we make secure habits as natural as efficient ones, from what's safe to paste to how prompt injection actually works.
Because AI that no one can vouch for doesn't scale safely.
The questions that separate the phases
Adoption asked: can we use AI? Efficiency asked: are we using it well?
Trust asks harder questions: Do we know where our data goes? Can the model be talked into something? What is it allowed to do without asking? And could we show an auditor tomorrow?
Efficiency gets you to scale. Trustworthiness lets you stay there.
Ready to move from efficiency to trust? Talk to our AI Advisory team.
Ready to move from adoption to efficiency?
Sources
1. OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2026 (LLM01 Prompt Injection, LLM03 Excessive Agency). https://github.com/GenAI-Security-Project/GenAI-LLM-Top10
2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of the EU, 24 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
3. European Commission, AI Act: regulatory framework and application timeline. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
4. European Commission, FAQ: Transparency obligations under Article 50 of the AI Act. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
5. Regulation (EU) 2016/679 (GDPR), Article 5(1)(c), data minimisation. https://eur-lex.europa.eu/eli/reg/2016/679/oj