Hi ala,
The AI Data friction tax does not show up on any invoice, but it is the biggest real cost of your AI budget.
Your AI pilot works. The business case holds. Then it enters security and compliance review, where months disappear and the use case that comes out the other side is narrower than the one that proved its value. That gap between the AI project you funded and the AI you actually ship has a name: the AI Data friction tax. It is paid three times:
- In time-to-value
- In the capability you quietly cut to get approval
- In the audit overhead that never goes away
Caution is not the problem. The people approving agentic access to regulated and sensitive data are accountable for what happens next, and they're being asked a question they can't answer with confidence: can this agent be trusted with access? An agent can combine individually permitted requests into sensitive knowledge that never existed in any single record. No security or compliance reviewer can sign off on that with a checklist. More permissions won't fix it. More forms won't scale to it.
The fix is not a faster review. It's a different question: protect sensitive values at the data layer, preserve the structure and relationships AI needs, and resolve clear data only when policy authorizes it. At that point, the approval conversation stops being a trust exercise and becomes an evidence review: what stayed protected, where policy applied, when clear values were permitted. That's the difference between a review that takes months and one that takes days, and between agents that ship at a fraction of their design and ones that ship at full capability.
Governance does not disappear in that model. It just gets a repeatable way to say yes.
Where does your own approval process stand today? Take the 10 Qs AI Data Readiness Assessment to find out.