PRESENTERS INFLUENCERS ABOUT US REFERENCES BLOG CONTACT

Data Governance: Before AI or After?

Data governance comes before AI but should not hold it up. A four-layer model, what UK law changed in 2026, and which layer to put in place first for a pilot.

Business Inspiring Motivation Self-Improvement Change Management Artificial Intelligence Leadership
  • Release Date: 07 October 2026
  • Author: Yuce Zerey
Rows of plain grey archive drawers with one crimson drawer slightly open

Most leadership teams I work with split into two camps on this question. One says: sort the data out first, then start on AI. The other says: data is never clean, so build the models and fix things as you go.

Both camps can talk for hours without reaching a decision. The answer that works in practice sits between them. Data governance comes before AI, but it does not hold AI up. The two run in parallel, and AI itself becomes one of the tools that makes data manageable.

Data governance for AI is the discipline that keeps AI systems working on data that is accurate, traceable and used by the right people. In this piece I break it into four layers and show which of them needs to be in place before a pilot starts.

Why is "is our data ready?" the wrong question?

No organisation's data is ever fully ready. Waiting for that moment means waiting indefinitely.

The UK figures show how many businesses are already past the waiting stage. The ONS reports that AI use among businesses with 10 or more employees has risen from around 12% to around 35% since late 2023. It also describes that adoption as relatively shallow: the average adopting business uses between 1 and 2 AI technologies.

Data is one of the reasons adoption stays shallow. In the Department for Science, Innovation and Technology's AI adoption research, published in January 2026, data complexity (a mix of too little data and too much unstructured data) appears among the barriers businesses cite. It weighs more heavily on large businesses than on the average firm.

So the better question is: which data, for which task, at which threshold is good enough? That question produces a decision. "Is our data ready?" produces another meeting.

AI also helps fix the data

One point most boards miss: AI is a tool for making data usable, as well as a consumer of it.

Entity matching, de-duplication, field normalisation and labelling are all tasks where AI does a large share of the work that used to take a data team months. People still review the uncertain cases. The workload drops sharply.

The practical conclusion is that you cannot put data and AI in separate queues. The fastest route to better data often runs through the first AI use case.

The first six weeks in practice

The pattern I see most often looks like this. A group runs several brands, and each brand has its own CRM. The same customer appears three times under three slightly different records. Marketing cannot see it, and neither can sales.

The instinct is to consolidate the CRMs first. That project takes a year. What works in the first six weeks is an identity resolution layer on top of the existing systems. An AI-based matching step compares names, contact details, addresses and purchase patterns, links records that belong to the same customer, and passes the uncertain matches to a person to confirm.

By the end of the third month, the business has a single customer view for its priority segment. The long-term master data project continues in parallel. Neither waits for the other.

Four stacked glass panes on a stone table, the top pane crimson, standing for four governance layers

A four-layer data governance model

The framework below works in the field. The four layers are not a strict sequence, but they depend on each other.

LayerThe question it answersMinimum before an AI pilotWhat happens if you skip it

Quality

Is the data accurate, complete and current?

Critical fields measured and above an agreed threshold

The model learns from data that does not match reality

Catalogue

What data do we hold, where is it, who owns it?

One definition for each critical term

The same question gets three different answers

Lineage

Where did this figure come from and how was it transformed?

Traceable for critical reports

You cannot explain an output to an auditor or regulator

Access

Who can reach which data?

Role-based and logged

An AI agent operates with wider permissions than the person it serves

Quality. Score each critical field on its own: customer name, email address and company number will never be at the same quality level. Averaging them hides the problem. Start working with the fields above the threshold and use AI-assisted cleansing on the rest.

Catalogue. Marketing, sales and finance each define "customer" differently. The catalogue gives every term one definition and one owner.

Lineage. This is the layer regulators and auditors care about most. If a figure feeds a decision, you need to show its route.

Access. AI agents inherit permissions. The basic rule: an agent should never reach more data than the person it works for.

What changed in UK law in 2026?

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its data protection changes came into force in stages through 2026. Three points matter for an AI rollout (as of September 2026):

ChangeIn force sinceWhat it means for AI projects

Automated decision-making: UK GDPR Article 22 replaced by Articles 22A to 22D

5 February 2026

Significant automated decisions can rely on a wider range of lawful bases, with safeguards: information about the decision, the right to make representations, human intervention and a route to challenge. The relaxation does not extend to special category data.

Recognised legitimate interests

5 February 2026

A defined list of purposes (for example crime prevention and safeguarding) no longer needs a balancing test. It is a narrow list and does not cover commercial AI use cases in general.

Complaints handling

19 June 2026

Organisations must acknowledge a data protection complaint within 30 days and offer an electronic complaint form.

The ICO's guidance on AI and data protection is currently under review following the Act. Its accountability section still makes two points that shape governance work: in the vast majority of cases, using AI will require a data protection impact assessment, and senior management cannot delegate these issues to data scientists or engineering teams. The ICO has also said its draft guidance on automated decision-making will feed into an AI and ADM code of practice. No publication date has been given for the code.

A practical check follows from this: does your DPIA template, and the privacy information you give people, already reflect the new safeguards for significant automated decisions? If not, update them before the pilot goes live.

The maximum fine under UK GDPR remains the higher of £17.5 million or 4% of worldwide annual turnover. That is one more reason the access and lineage layers belong on the board agenda.

Is MDM the same as data governance?

No, and the confusion costs time in budget meetings. Master data management creates a single trusted record for core entities: customer, product, supplier. Data governance is the framework for how all data is managed. MDM is one part of it.

In the AI era, the gap is visible. Agent access rules, lineage tracking and monitoring of model outputs all sit in the governance layer. If you already run an MDM programme, you have one part of governance in place. The rest still needs an owner.

Parallel steel pipes joining at a crimson valve in a clean facility, standing for data lineage

Which layer comes first?

Two of the four layers are urgent. The other two are larger investments.

Access and quality come first, because both allow an AI project to start. Without quality, the model produces unreliable output. Without access controls, legal and security will stop the project, and under the ICO's accountability expectations they would be right to.

Catalogue and lineage become essential at scale. A pilot can start without them; a production system cannot. Delaying a pilot until they are finished is the most common mistake I warn against.

Smaller businesses sometimes assume this is only for large organisations. The need is the same; the scale is smaller. A handful of data sources, a simple quality check, a basic catalogue and clear access rules cover most of it. The UK picture on AI adoption in smaller firms is covered in our AI roadmap for SMEs.

This short talk of mine looks at e-commerce growth:

E-Commerce Growth | Yuce Zerey (YouTube)

Bring this to tomorrow's meeting

List your three most critical data tables. For each, write down the owner, the date it was last updated and its current quality score. Count the empty fields.

Take that single page to the next meeting. The discussion moves from "is our data ready?" to "which table, at which threshold, under whose responsibility?" That shift is the real gain.

If the board needs its own briefing on where AI stands, our guide to an 8-slide board AI report shows how to structure it.

Plan an AI governance session for your leadership team

Tell us where your data and AI programme stands, and we will suggest a speaker and format for your board or leadership team. We reply within 24 hours.
AI Speakers Response within 24 hours

Frequently Asked Questions

Can we start an AI project before data governance is complete?

Yes, and in most cases you should. No organisation's data is ever complete. What matters is reaching an agreed quality threshold in the critical fields for the use case. A pilot can run on a measured, threshold-passing data set; the threshold rises as the project scales.

Which of the four layers is most urgent?

Access and quality. Both allow a project to start. Without quality the model produces unreliable output; without access controls legal and security will stop the project. Catalogue and lineage become essential at scale.

What did the Data (Use and Access) Act 2025 change for AI?

From 5 February 2026, UK GDPR Article 22 was replaced by Articles 22A to 22D. Significant automated decisions can now rely on a wider range of lawful bases, with safeguards such as human intervention and the right to challenge. The relaxation does not apply to special category data.

Do we need a DPIA for an AI project?

In most cases, yes. The ICO's guidance on AI and data protection says that in the vast majority of cases the use of AI will involve processing likely to result in a high risk, which triggers the legal requirement for a data protection impact assessment. The guidance is under review following the 2025 Act.

Can AI really clean data?

For specific tasks, yes: entity matching, de-duplication, field normalisation and labelling. Uncertain cases still go to a person. The realistic goal is to reduce manual work sharply, with people reviewing what the system cannot resolve.

Should an AI project wait for an MDM programme to finish?

No. The two run in parallel. MDM is the lasting structural fix; an identity resolution layer is the fast, practical one. Waiting for MDM to finish delays most AI projects by more than a year.