Kitecast

Robert Smallwood: AI Governance Needs Data Governance

Kendall Barnes Season 4 Episode 54

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 49:18

Most companies rolling out AI have the sequence backward. That is the case Robert Smallwood makes on this episode of Kitecast. Smallwood has spent over a decade defining what information governance means in practice, authoring more than nine books on the subject, including his newest, AI Governance Playbook, from Bloomsbury. He is also the founder of the Institute for Information Governance and chair of the Certified Information Governance Officers Association (CIGOA). His argument is simple, and once you hear it, hard to unhear. Organizations are pouring ungoverned, uncleaned, undocumented data into AI models and then wondering why the outputs cannot be trusted.

Smallwood ties the pattern to widely cited research, including MIT's 2025 GenAI Divide study, which found that 95% of enterprise generative AI pilots fail to deliver measurable financial return. He traces that failure back to a step most teams skip entirely. Before data ever reaches a model, it needs to be inventoried, cleaned, deduplicated, and checked for bias. That is information governance work, not AI work, but without it, generative AI systems inherit every flaw already sitting in an organization's unstructured files, spreadsheets, and email. He also flags a gap he sees across most AI governance training programs. Almost none of them account for e-discovery, the process organizations must follow once litigation hits. Skip that step now, he argues, and you are building a liability nobody notices until a lawsuit forces the issue.

Agentic AI raises the stakes further. Smallwood walks through why autonomous agents need the same scrutiny as new employees: sandboxed environments before go-live, spending and action limits, kill switches, and a clear audit trail showing what data was touched, by which agent, and when. As he puts it, agents will accomplish exactly the goal they are given, which means the guardrails must be defined before deployment, not patched in afterward. That distinction between generative AI, which most companies have already normalized through tools like Copilot, and agentic AI, which is still in early, cautious pilot stages at even the largest enterprises, shapes the rest of the conversation.

Smallwood also previews his CIGO/AI and CIGO/AI-A certification tracks and the AI Gov World conference, running October 12-14 at the Flamingo in Las Vegas, where Kiteworks will be presenting and sponsoring a booth. Listen to the full episode for his take on why corporate boards still flinch at the words "information governance," why that needs to change, and what a genuinely defensible AI program looks like from the inside.

LinkedIn Profile: https://www.linkedin.com/in/robertfsmallwood/

Check out video versions of Kitecast episodes at https://www.kiteworks.com/kitecast or on YouTube at https://www.youtube.com/c/KiteworksCGCP.