Something significant is happening at the intersection of artificial intelligence and data security governance. For years, security teams held a monopoly on data protection decisions: they owned the policies, the tools, and the accountability. AI is breaking that monopoly, and Gartner’s latest research suggests that organisations that fail to adapt will pay a heavy price.
In its recently published report “AI Democratisation Drives Collaborative Data Security Governance” (January 2026), Gartner identifies a structural shift in how data security must be approached: the rise of AI across all business functions is making data security governance a cross-functional responsibility, not a centralised IT function. This is a significant departure from how most organisations currently operate and it has profound implications for identity verification, privacy-preserving data use, and enterprise risk management.
The Democratisation Problem
AI tools are no longer the exclusive province of data scientists and IT departments. Business analysts, marketers, product managers, and customer service teams are all using AI-powered applications that ingest, process, and generate sensitive data. As a result, data is being accessed, moved, and acted upon at a scale and speed that traditional centralised security governance simply cannot keep pace with.
Gartner’s broader research paints a stark picture of this reality. According to its 2026 CIO and Technology Executive Survey, 84% of organisations expect to increase GenAI investment this year. Meanwhile, research from Gartner’s cybersecurity practice found that business technologists outside of IT are 1.8 times more likely to behave insecurely, even as they are increasingly empowered to make technology decisions. The gap between AI capability and security maturity is widening and data is caught in the middle.
The Gartner data security report identifies this as the core tension: AI democratisation expands the attack surface of sensitive data, while simultaneously making traditional centralised control models unworkable. You cannot secure what you cannot see, and when data flows through dozens of AI tools across a business, visibility is the first casualty.
The Shift to Collaborative Governance
The report’s central recommendation is that organisations must transition from a model of centralised security oversight to one of collaborative data security governance (DSG). This means building cross-functional ownership of data security policies, with clear accountability structures that extend beyond the security team and into the business units that are actually handling data.
This is not merely a process change. It requires a fundamental rethinking of who defines data security policy, who enforces it, and who is accountable when things go wrong. In practice, it means:
- Security and data analytics teams establishing shared frameworks for risk assessment rather than operating in silos.
- Business units taking active ownership of data handling decisions, supported by clear governance guardrails.
- AI governance policies being embedded into general technology procedures — Gartner predicts this will happen at most organisations by 2027.
- Active metadata management enabling real-time alerts when data is stale, miscategorised, or exposed to AI systems without appropriate authorisation.
Why Identity Is the Critical Missing Layer
One theme in this report stands out to us with particular clarity: as data security governance becomes distributed and collaborative, the question of who is accessing data and whether that access can be trusted becomes more critical, not less.
The Gartner report highlights the emergence of Data Security Posture Management (DSPM) as a key technology response to AI democratisation. DSPM tools discover where sensitive data lives, who has access to it, and what the risk posture looks like across complex multi-cloud environments. But discovery alone is not governance. Knowing that data exists in 47 places across your cloud infrastructure does not tell you whether the people and AI agents querying that data are who they say they are, or whether their access is contextually appropriate or even fully authorised.
Gartner separately predicts that by 2028, more than 50% of enterprises will use AI security platforms to centralise visibility and enforce usage policies across AI tools. The trend toward agentic AI (AI systems that act autonomously on behalf of users) is also introducing new challenges for identity and access management, as Gartner’s Top Cybersecurity Trends for 2026 notes. Machine actors are increasingly requesting access to sensitive data, and the traditional framework of human identity verification does not map cleanly onto this new reality.
This is precisely the challenge that privacy-preserving identity verification was designed to address. When sensitive data is at stake, the question is rarely “who is this person” in the abstract. It is, “does this person meet the criteria required to access this specific data, in this specific context, without exposing their underlying personal information unnecessarily?” Zero knowledge proof technology makes it possible to answer that question definitively without creating new data liabilities in the process.
The Zero-Trust Imperative
The collaborative governance model Gartner describes cannot function without a robust identity layer. Zero-trust data governance — a concept Gartner predicts 50% of organisations will adopt by 2028 in response to the proliferation of AI-generated and AI-accessed data — is built on a simple but demanding premise: no access should be assumed safe, ever. Every query, every data transfer, every agent action must be verified against policy at the point of access.
Implementing zero-trust data governance at scale requires answers to questions that many organisations currently cannot answer with confidence:
- Can you verify the identity of every human and machine actor requesting access to sensitive data?
- Can you do so without storing unnecessary personal data that itself becomes a security liability?
- Can you enforce contextual access policies in real time, across cloud environments, at the speed AI operates?
These are not abstract architectural questions. They are operational requirements for any organisation serious about implementing the collaborative governance model Gartner describes.
What Organisations Should Do Now
Gartner’s recommendations within the AI democratisation report align closely with what we see as best practice for organisations navigating this transition. Drawing on both the report’s findings and our own experience working with regulated industries, we would highlight four priorities:
1. Build cross-functional data security ownership
Security cannot remain a back-office function while AI runs at the front of the business. Form cross-functional teams that bring together cybersecurity, data analytics, legal, and business operations to jointly own data risk assessment and policy definition. Accountability must be shared, and that requires shared understanding of where data goes and what it is used for.
2. Implement DSPM to achieve data visibility
You cannot govern what you cannot see. DSPM tools that continuously discover and classify data across multi-cloud environments are a foundational requirement for collaborative governance. Without visibility into where sensitive data resides and who is accessing it, cross-functional governance teams are working blind.
3. Adopt privacy-preserving identity verification
As data access becomes more distributed across more users, more AI agents, and more environments, the need for trustworthy, privacy-preserving identity verification intensifies. The goal should be to verify access rights without creating new data liabilities. Zero-knowledge proof-based identity verification enables organisations to confirm eligibility for data access without exposing or storing the underlying personal data used to establish that eligibility.
4. Treat AI governance as enterprise-wide, not IT-wide
Gartner predicts that standalone AI governance policies will be absorbed into general technology procedures by 2027. Begin that transition now. Embed data security requirements into the AI tools and workflows your business uses, rather than treating governance as an external audit function. When governance is built in, not bolted on, it scales with AI adoption rather than lagging behind it.
The Bottom Line
The Gartner report on AI democratisation and collaborative data security governance is, at its core, a warning about the cost of inaction. As AI proliferates across every function of the business, the old model of centralised, IT-owned data security becomes not just inefficient but dangerous. The data is moving faster than the policies that protect it.
The solution is not to slow down AI adoption — that is neither practical nor desirable. It is to build a governance model that moves at the same speed, distributes accountability appropriately, and anchors every data access decision in a trustworthy, verifiable identity layer.
That is the work of the next two to three years. Organisations that get ahead of it will have a meaningful competitive and compliance advantage. Those that wait for regulatory pressure to force the issue will find themselves scrambling to retrofit governance into AI systems that were never designed with it in mind.
About Sedicii
Sedicii is a privacy-first identity verification company. Our zero-knowledge proof technology enables organisations to verify identity and eligibility without exposing or storing sensitive personal data — helping enterprises meet the identity requirements of zero-trust and collaborative data security governance frameworks.
To find out how Sedicii can help your organisation implement privacy-preserving identity verification at scale, contact us at contactus@sedicii.com
