All articles
As The AI Model Becomes A Commodity, Enterprise Data Becomes The Moat
Jayashankar Attupurathu, Technology Strategy Advisor to Boards and CXOs, on why the golden source, the pipeline, and sovereignty rules decide what a model can do.

Enterprises are focusing on who owns the data, where the golden source is, how the pipeline works, and who governs it.

Companies buying AI now choose from the same handful of model providers, and few build their own. The difference between one AI program and another comes from the data underneath. Ownership of that data and control over how it moves through the business decide what any model can produce.
Jayashankar Attupurathu is a Technology Strategy Advisor to Boards and CXOs. He has spent more than two decades in enterprise technology, working as a developer, an Enterprise Architect, and a head of engineering before moving into CTPO roles. The questions buyers bring him now start below the model.
"Enterprises are focusing on who owns the data, where the golden source is, how the pipeline works, and who governs it," Attupurathu says. A golden source is the single copy of a record an organization treats as correct when its systems disagree. Deciding which copy earns that status, and who is allowed to change it, predates AI. The work stalls in most companies.
Pressure on the pipeline
The systems drawing budget now have no user interface. They handle what happens between a company's records and the model. "Two years back, people were investing in chatbots or replacing RPA with AI. Now enterprises are keen on the second layer, the data pipelines, vector stores, orchestration frameworks, and observability tools. Even the board is asking how you govern this and how you find the ROI on AI," Attupurathu notes.
A vector store holds documents in the numerical form a model can search, so its contents set the outer limit of what any answer can draw on. Observability tools capture what the model did and why, which is the record auditors ask for. Both now fall inside the scope of a compliance review.
A company cannot always use the records it already has. Where the data lives can rule that out. "Data sovereignty has been there for ages. In financial services, countries have regulations in place that data cannot go outside their borders, and you cannot use our citizens' data in some other country," Attupurathu explains. Those rules are workable while data stays in one place.
A model improves as it takes in more material, and the data with the most value is often the most restricted. That sends protected records toward wherever the model runs. Where those records travel becomes an architecture question, along with who operates the systems handling them. Both carry data sovereignty risk.
Those decisions have to satisfy laws that are still being written. India's data protection rules took effect in November 2025, with full compliance required by May 2027. The EU continues to revise its framework, and health information in the United States remains under HIPAA. A business operating in all three markets answers to each at once, and the requirements keep diverging.
Context outlives identifiers
Organizations that run models on hardware they control keep every record in-house. Everyone else sends data to an outside service. "Some companies are anonymizing the data before pushing it into the model. That safeguards the PII, but the context is still there," Attupurathu says. A record with the name and account number removed still carries the balance, the transaction history, and the branch. Those details are often enough to identify a person.
"If I push someone's bank balance, the amount in that account is still visible, and you never know how far the AI can go to connect it back," he adds. Any limit on what a model may read depends on an accurate inventory. Platforms that classify sensitive data across storage systems, clouds, and SaaS applications show teams which systems contain regulated records.
Who owns the decision?
Someone has to own the decision about what a model can read, and answer for it. At most organizations, no one does. It passes between the CIO, the data team, and legal, depending on the project.
"If you have 10 departments, is that data aligned and mature enough to run into AI, and which of it is ethical to expose? What if you expose something and it creates insider trading? Those failsafes and gatekeeping methods have to be there," Attupurathu says. Ten departments mean 10 sets of records in different shapes. The consequences of exposing the wrong one reach the company and its officers, not the team that built the pipeline.
"Why not have a committee for AI data? Get independent directors who have exposure to AI and bring them into the fold," he continues. Boards have started formalizing AI oversight, usually by adding it to existing risk or audit agendas and naming which directors are accountable. A dedicated committee would give the question its own members and a standing place on the calendar.
Attupurathu expects the chief data officer title to widen into a chief data and ethics officer, with authority to rule specific datasets out of AI use entirely. The board sets the mandate, and that role enforces it request by request.
All of that structure is internal. A customer deciding whether to hand over its data has no way to check any of it. "We have ESG certification, ISO, and SOC 2, which tell shareholders and the public that a company is ethical," Attupurathu says. Data handling has no equivalent that customers recognize. The closest standard, ISO/IEC 42001, covers how organizations manage AI systems, and certification remains voluntary, which leaves buyers nothing consistent to compare.
Agents raise the stakes
Companies once licensed a separate platform for each business function. Now they ask what an agent could do with the customer accounts and claims files those platforms were built to manage. Attupurathu expects ready-made agents, sold through marketplaces, to take over that work.
One agent can work across all of those systems at once, which gives it reach no single application had. It also acts without a person checking each step. Teams that move agents into production inside processes designed for human review have found the gaps show up quickly. An agent bought off a marketplace comes with its own data requirements, so someone inside the business still has to approve what it can read.
Investors set the clock on all of this. "There is an impatience about returns. They are looking at the dollar value they can get, without the long-term vision," Attupurathu notes. Spending on pipelines and controls pays back on a slower schedule, which is a hard case to make when budgets draw scrutiny. His advice for teams under that pressure is to spend where the differentiation actually is. "Do not create your own models. The models are all out there. Customize them for your needs, and then build something that creates something new in this world," he concludes.




