Everyone wants to talk about AI. Nobody wants to talk about the thing that's going to determine whether AI pays off: your data.
Here's the uncomfortable truth I keep running into with clients. The models are fine. The models are, frankly, astonishing. If your AI initiative fails, it almost certainly won't be because the model wasn't smart enough. It will be because the model couldn't get to your data, or because getting it there cost more than the value it created.
The Access Problem
We spent the last five years building security architectures designed to make data hard to reach. SASE, SSE, zero trust — all of it exists to inspect, broker, and restrict every path between a user and a resource. That was the right call. It's still the right call.
But now we're asking AI systems to do exactly what those architectures were built to prevent: reach broadly across the enterprise, touch data in dozens of repositories, and move it somewhere it can be processed. Every AI use case worth doing is, from your security stack's point of view, indistinguishable from an exfiltration event.
So, the pilot that took two weeks to build takes six months to deploy, because every data path has to be renegotiated with the same controls that were designed to say no. The AI isn't slow. The permission to feed it is.
Nobody planned for this collision. The security architecture and the AI strategy were bought by different people, in different years, solving different problems. Now they're in the same building, and they don't get along.
The SaaS Problem
That assumes your data is somewhere you can reach at all. Most of it isn't. It's in SaaS.
Twenty years of best-of-breed buying means the average enterprise's data now lives in a hundred-plus SaaS applications — CRM, HR, ticketing, finance, collaboration — each a silo with its own API, its own schema, its own rate limits, and its own permission model. Your data is in there. Getting it out is another matter.
Because SaaS vendors figured out that your data is their moat. Accessing it is metered and gated at every turn — API call limits, premium tiers to unlock export, per-connector fees, and now the newest move, an "AI add-on" charging you extra to run intelligence against information you already own. You're paying rent to visit your own data.
Their answer to AI makes it worse, not better. Every vendor is bolting a copilot onto its own product — so the roadmap they're selling you is forty disconnected AIs, each one brilliant inside its silo and blind to everything else. That's exactly backwards. AI use cases that actually matter are the cross-silo ones: the answer to "why is this client unhappy" lives across the CRM, the ticketing system, email, and invoices. No vendor copilot will ever see the full picture, because no vendor has an incentive to let intelligence leave its walls.
SaaS didn't just fragment your data. It fragmented it into a hundred businesses whose margins depend on keeping it that way.
The Warehouse Problem
The industry's answer to "AI needs your data in one place" has been the modern data platform. Centralize everything, and intelligence will follow.
I'll say what a lot of CTOs say privately: the state-of-the-art data warehouse is wildly oversold. The demos are beautiful. The reality is a multi-year migration, a consumption-based bill that grows faster than the value, and a platform team you didn't have that now can't be fired. You were promised a single source of truth. You got a very expensive second copy of data you already had, plus a pipeline organization to maintain it.
And here's the kicker: the AI use cases that matter mostly don't need it. They need governed access to data where it lives — in the ERP, in the document stores, in the ticketing system — not a monument to data in a proprietary format with a meter running.
The Money Problem
Add it up. The security stack taxes every data movement. The SaaS vendors tax every API call to your own records. The data platform taxes every query. The AI platform taxes every token. Four separate consumption models, all metering the same underlying activity: moving your own information around your own company.
This is why AI ROI conversations go sideways. The model might genuinely save a knowledge worker five hours a week. But if delivering that capability requires a warehouse migration, a security architecture exception process, and three new line items of consumption billing, the economics collapse before the first user logs in.
The Missing Layer: A Broker
Notice that all three problems are really one problem. AI needs to talk to dozens of systems that were never designed to talk to it, through a security stack that was designed to stop exactly that, without creating expensive copies along the way.
What's missing is a broker — a Rosetta Stone with API access.
Picture a layer that sits between the AI and everything else. On one side, it speaks the native language of every system you own: the ERP, the document stores, the ticketing system, the databases, the SaaS sprawl. On the other side, it presents one clean, governed interface to the AI. The AI never touches a source system directly. It asks the broker. The broker translates, enforces, and delivers.
Look at what that solves — starting, crucially, with security. The broker is the right place to manage rights. Today, entitlements live scattered across every source system, each with its own permission model, its own admin, its own drift. An AI reaching into those systems inherits all that inconsistency at once, and your security team has no single place to reason about what it can actually see.
The broker fixes this. Every request passes through one point that can answer the only question that matters: is this agent, acting on behalf of this user, entitled to this data, right now? Rights get defined once, enforced everywhere, and logged completely. Instead of a hundred exception requests grinding through a stack built for humans and browsers, security gets what it's always wanted — one enforcement point with full visibility.
The other two problems fall out from there. The warehouse becomes optional, because translation replaces centralization: the data stays where it lives, and the broker makes it legible. And the SaaS trap loses its grip — the broker is your side of the API, the one integration you own against the hundred you rent. Cross-silo intelligence stops depending on vendor copilots that will never cooperate, because the intelligence sits above the silos, not inside them.
This is also where the identity conversation lands. An AI agent reaching across the enterprise is a non-human identity with enormous reach, and today most organizations govern it with nothing. The broker is where that governance belongs — the agent authenticates once, to one thing, and that thing holds the credentials, scopes, and entitlements to everything else. One identity to govern, one rights model to maintain, instead of fifty embedded credentials and fifty permission schemes to lose track of.
The industry is starting to circle this idea — you can see early versions of it in emerging agent-to-tool protocols — but the protocols are the easy part. The hard part is the governance layer wrapped around them, and that's where the real architecture work is.
What Actually Works
The organizations getting real value from AI right now share a pattern, and it isn't "biggest model" or "best platform." It's this: they fixed the data path before they scaled the AI.
That means a few unglamorous things. Know where your data actually is and stop pretending the warehouse project will consolidate it — it won't anytime soon. Stand up a broker layer so AI reaches data in place, through one governed interface, instead of through a tangle of direct integrations. Treat AI data access as a first-class security use case, with its own identity and controls, instead of forcing it through exception processes built for a different era. And be ruthless about consumption economics — every layer that meters data movement is a layer that erodes your AI business case.
None of this is exciting. Nobody's giving keynotes about data path remediation. But it's the difference between AI as a line item and AI as an advantage.
The models will keep getting better on their own. Your data problem won't. Fix that first, or the smartest AI in the world will sit there, fully licensed, waiting for permission to be useful.