AI Can Find Information. It Can’t Establish Authority.

The AI Readiness Question Most Organizations Aren’t Asking

My friend and longtime colleague Steve Weissman recently published an insightful LinkedIn article, Governance and AI ROI: Trust is What You Need. He argues that organizations cannot fully realize the value of artificial intelligence without improving the governance of the information these systems use.

I agree. His article also raised another important question within records and information governance that deserves more attention as organizations move from AI experimentation to enterprise deployment:

Can AI recognize an authoritative record?

This may seem like a subtle distinction, but it is not.

Organizations often struggle with a deceptively simple question: Which version is the official one? Multiple copies of the same policy may exist across various platforms, each appearing legitimate and containing useful information. However, only one reflects the organization’s current, approved position.

Before AI, that created confusion for employees. Today, it creates confusion at machine speed.

Artificial intelligence excels at finding information. It can summarize large volumes of content, compare documents, identify patterns, and generate convincing answers quickly. However, it cannot determine whether a retrieved document is the organization’s authoritative record.

This is not a failure of AI; it was not designed for this purpose. Determining whether information is authentic, reliable, current, and authoritative remains the responsibility of records and information governance.

Information Is Not the Same as Evidence

A recurring issue in AI discussions is the interchangeable use of the terms data, information, content, and records. In our profession, we recognize these are distinct concepts.

An AI system may retrieve accurate information and produce an excellent summary. However, accuracy alone does not make information authoritative. A document can be technically correct yet still be the wrong one.

A later revision may have superseded it. It could be an unapproved draft, a document past its retention period, or one that conflicts with another due to incomplete lifecycle management. It may also be a convenient copy rather than the official record, or lack the context needed to determine its status.

These are not just information quality issues; they are records management problems.

Organizations do not make important decisions based solely on information. They rely on information that serves as evidence of policy, commitment, action, ownership, or authority. This distinction is critical as AI-generated responses increasingly influence operations, compliance, customer interactions, legal positions, and organizational knowledge.

For decades, records and information governance professionals have established controls to ensure information can be trusted. We determine which documents are official records, assign ownership, classify, maintain, retain, supersede, and dispose of them appropriately. ISO 15489 reflects these principles by emphasizing authenticity, reliability, integrity, and usability throughout the records lifecycle.1

Artificial intelligence does not independently establish these characteristics; it assumes the organization has already done so.

This is a significant assumption.

AI Reveals the Governance Environment It Inherits

Few of the governance problems exposed by AI are new. Organizations have long struggled with duplicate repositories, inconsistent metadata, outdated policies, excessive permissions, abandoned collaboration sites, uncontrolled copies, and decades of accumulated digital clutter.

Employees often worked around these issues by relying on informal organizational knowledge. They knew which shared drives were trusted, which policies were outdated, where signed versions were stored, and whom to contact when procedures conflicted.

AI lacks this institutional memory. It cannot distinguish between trusted and convenient repositories, recognize obsolete documents unless clearly identified, or know if a draft was unapproved, a policy superseded, or a record overdue for disposal.

It only knows what it can retrieve and what the systems permit it to access.

This is why AI does not create most governance problems; it reveals them. It exposes the consequences of weak lifecycle controls, inconsistent ownership, poor classification, unmanaged access, and unclear authority. Issues previously managed through experience or institutional knowledge become harder to contain when AI can retrieve and reuse information across the enterprise at scale.

Microsoft acknowledges this in its guidance for Microsoft 365 Copilot, especially regarding oversharing, permissions, information protection, and governance.2

The technology assumes organizations understand the information environment they expose to AI.

Many organizations are discovering they do not.

Authority Is Established, Not Discovered

This is the heart of the issue.

Authority is not an inherent property of a document. A PDF is not authoritative simply because it is well written, widely shared, or stored in a familiar location. A policy is not official because it appears at the top of a search result, nor is a contract the record copy because AI retrieved it first.

Authority is conferred through governance.

A policy is authoritative because the organization approved it, assigned ownership, controlled revisions, identified the official version, governed access, and managed its lifecycle. A contract is the official record because the organization established processes for execution, custody, retention, and disposition. A retention schedule carries authority because it has been formally adopted, maintained, and applied through defined responsibilities and controls.

These decisions result from organizational policy, accountability, and governance, not from algorithms.

AI can detect clues by comparing dates, identifying version numbers, examining metadata, and recognizing language that suggests approval. While useful, these capabilities do not establish authority. A newer file is not always the approved file, a document marked “final” may not be final, a signed copy may not be the record copy, and metadata may be incomplete or incorrect.

AI can assist in applying governance, but it cannot create governance where none exists.

This distinction is important as organizations increasingly expect AI to participate in processes that require reliable information. The quality of an answer may seem impressive, but fluency does not equal authority. An AI-generated response can be clear and logical, yet based on the wrong version of a policy.

The resulting answer may sound more certain than the underlying information deserves.

A More Fundamental Test of AI Readiness

Current discussions about AI readiness often focus on infrastructure, cybersecurity, acceptable use, model selection, privacy, and technical deployment. While essential, these do not address a more fundamental question: Has the organization established authority over the information AI will use?

This question leads to several others: Can the organization identify its authoritative records? Can it demonstrate ownership and accountability? Can it distinguish current policy from obsolete guidance, identify superseded versions and uncontrolled copies, explain why one document should be relied upon over another, apply retention and disposition consistently, and govern access without letting convenience override responsibility?

These are not new questions for our profession, but artificial intelligence has made the consequences of failing to answer them more visible.

Steve Weissman is correct that organizations will struggle to achieve expected returns from AI if they neglect governance. Governance must do more than improve information quality or accessibility; it must establish which information carries authority and why.

Artificial intelligence can retrieve, summarize, compare, classify, and analyze information. However, it cannot independently determine whether the information it finds is the organization’s authoritative record.

That responsibility still belongs to us.

For decades, records and information governance professionals have built structures that enable organizations to trust their information. AI has not made this work obsolete; it has made its importance more apparent.

Before assessing AI readiness, organizations should first consider a more fundamental question:

Has the organization established the authority of the information its AI depends upon?

  1. International Organization for Standardization. ISO 15489-1:2016, Information and Documentation: Records Management, Part 1: Concepts and Principles. []
  2. Guidance on using Microsoft Purview to manage data security, compliance, permissions, and governance for Microsoft 365 Copilot. []

Leave a Comment

Your email address will not be published. Required fields are marked *

Verified by ExactMetrics