Arrow pointing towards left
All articles
AI

AI Turns Enterprise Memory Into A New Data Layer The CISO Must Defend

The Data Wire - News Team

|

September 15, 2026

AI memory increases what a system can connect, not just what it knows. María Luisa Redondo Velázquez, Global CISO at TK Elevator, says that's where the new risk lives.

Credit: The Data wire
Quote Icon
AI memory doesn't just increase what AI knows. It increases what AI can connect. That's where the new risk appears.

María Luisa Redondo Velázquez

Global CISO
TK Elevator

Much of the value enterprises are seeking from AI increasingly sits below the model. It sits in what a company can retrieve from its own accumulated knowledge, like its documents, decisions, and institutional context, and then feed back into the systems making decisions. That accumulated knowledge increasingly functions as a form of organizational memory. Once an organization treats it that way, a set of questions opens up that the storage conversation never had to answer. What should the system be allowed to remember, on whose behalf, and how does anyone prove that this memory hasn't been tampered with?

Working to tackle these questions is María Luisa Redondo Velázquez, Global CISO at TK Elevator, where she leads cybersecurity strategy across an industrial manufacturer operating in more than 100 countries. Over two decades in the field she's built security functions from the ground up across IT, cloud, and OT environments, and now advises executive committees and boards on how technology risk translates into business decisions. Her approach to AI draws a line most enterprises miss: the risk in giving it memory isn't mainly about what it stores, but about what it can join together.

"AI memory doesn't just increase what AI knows. It increases what AI can connect. That's where the new risk appears," she says. Redondo Velázquez is clear that this isn't an argument against memory. She's quick to share that she uses AI daily herself for tasks like moving from a blank page to a first draft. The value to an enterprise, in her account, is the same accelerant scaled up, but only if the thing the AI reaches into has been built for that purpose.

Memory needs permissions along with capacity

The temptation, as memory becomes the differentiator, is to give AI more of it. Redondo Velázquez pushes back on the premise. "I don't think enterprise AI should have unlimited memory. The challenge is not giving AI more memory. It's giving the right memory, with the right permissions, for the right purpose, at the right time."

That assertion reframes a capacity question as a governance one. Memory, in her model, needs the same foundational controls security teams already apply elsewhere: ownership, permissions, retention limits, provenance, and traceability. An employee should be able to retrieve only what they're authorized to see, even when the underlying system technically holds far more. The point where information from across the business gets connected is exactly the point where access has to be governed most carefully, because things that look harmless on their own can become sensitive once stitched together.

The attacker doesn't need to steal anything

The sharper risk in Redondo Velázquez's view is not exposure, but manipulation, and it changes what security teams have to defend. For years the priorities were confidentiality and availability: keep data from being read, keep it from being locked up. AI retrieval makes a third priority—integrity—far more consequential. "If an attacker can manipulate the data an AI system retrieves, they may not need to encrypt anything," she points out. "They could just influence the decisions or the outputs of the AI." That's a different threat model from ransomware. An adversary who can poison what a model pulls from doesn't have to take the database hostage. They can bend its outputs by altering the knowledge underneath.

Defending against it, she believes, means controls aimed at integrity rather than just access: provenance, versioning, and continuous validation. "We need to know where information came from, who changed it, when it was changed, and whether the AI is relying on trusted information or not." It's also why she now treats a robust data infrastructure as part of the security perimeter rather than a layer beneath it. Rather than repairing a weak data foundation, AI exposes it and acts on it. "The system uses what you already have. If that information is inaccurate, outdated, or compromised, the AI can reproduce—or amplify—the problem."

Distribute the data, centralize the governance

Because AI-connected systems can increasingly reach across silos in a business, Redondo Velázquez doesn't believe prevention alone holds. She frames the alternative as active defense. An environment can't be trusted just because it was secured once. "We continuously challenge the environment looking for anomalous behavior, manipulation, or attempts to compromise the integrity of the information," she shares. Continuous monitoring, deception, provenance validation, and isolating compromised data all sit inside that posture.

Paired with this is an architectural choice. Consolidating all of an organization's knowledge into one repository, she warns, creates both a concentration risk and an attractive target. Her prescription is to spread the information out while keeping a single grip on the rules around it. "Distribute the information, standardize governance, and continuously defend the integrity," she says.

Recovery extends beyond restoring data

The part of this approach that Redondo Velázquez views as the least resolved is recovery. The old playbook assumes that if you can restore the data, you're whole again. AI memory breaks that assumption, because the thing being restored is the context the business now reasons from.

The questions she wants teams asking are where the memory actually lives, how it gets backed up, and how anyone knows a restored version is trustworthy and hasn't been manipulated while stored. "For traditional systems, recovery often means getting the data back. For AI memory, recovery also means restoring trust in the information and infrastructure," she says. This perspective reframes recovery as a resilience, security, and governance problem at once, and it's a growing reason CISOs are moving into conversations that used to belong to storage and infrastructure teams. Ransomware taught enterprises to think about recovering availability. Memory, in Redondo Velázquez's account, makes them think about recovering integrity—and proving that integrity has been restored.

Related Stories