Enterprise AI

Applying Data Trust in Enterprise AI

By Susan Laine, Chief Technologist, Quest Software

Recently, our product management team was validating an idea with customers, and one concern surfaced repeatedly: people were struggling to trust the data behind their AI work. I had heard the same concern before, as data trust has been part of the enterprise conversation for years. What has changed is the need to put it into practice as AI systems move from controlled tests into everyday use. Thus, the emphasis on “applied” data trust. 

What does it really mean to establish data trust? In my opinion, data trust cannot be established through intent alone. It comes from tangible application embedded in AI systems, along with human oversight. The outcome is trusted data that is transparent and monitored for value. 

Poorly understood data can lead to confidently wrong answers, expose sensitive information and produce results that teams cannot use. Data validation may go smoothly during development, while production introduces more users, data sources and ways for weak assumptions to surface. 

Most organizations do not have a year to establish a traditional data governance program before they begin using AI. The practical question I’m asked now is how to build trust into the data as the work moves forward. From what I have seen, organizations make the most progress when they incorporate context and controls into their LLMs and include data and context management in their AI strategy.

Use the controls available today 

In a recent LinkedIn post, Sol Rashidi summarized eight techniques enterprises use to reduce hallucinations: retrieval-augmented generation, prompt grounding, chunking and re-ranking, structured output, tool calling, advanced RAG with fact verification, fine-tuning on trusted data, and confidence gates with human review. The list covers several points in the process, from the information a model retrieves to the way an answer is checked before anyone acts on it. 

Several of these controls can be added close to the point of use. RAG connects a model to an organization’s own sources. Grounded prompts define the rules and boundaries for an answer. Re-ranking helps the model focus on the most relevant evidence. Structured outputs and tool calls give downstream systems consistent information to work with. Fact verification adds another check before a response reaches a user. 

The two areas I spend the most time on are fine-tuning with trusted data and confidence gates with human review. They require decisions about how data is classified, managed and monitored across the organization. That work is more foundational and can support more than one AI use case. 

Map the data before you build with it 

When a company fine-tunes a model on its own data, the quality of the result depends on how well that data reflects the business. Definitions, exceptions and domain context need to be clear before they are handed to the model. Clients are using an underlying ontology as part of their AI strategy to define and manage this organizational context.  

IBM’s overview of AI hallucinations explains how grounding and fine-tuning can help a model work with domain-specific information. In an enterprise setting, that work starts with data that is organized well enough for people and systems to understand. 

Working with domain-specific data usually starts with some form of domain classification. A logical data model or ontology organizes the data around shared business definitions and standards. Domain experts explain how the data should be used, where it came from and which exceptions matter. Teams that move ahead without that work often discover the gaps after an issue reaches production and no one can explain where a number came from. 

This work can move much faster than it did in the past. A consistent process for organizing the data gives teams an ongoing GPS for finding the right information. Existing analytics environments can provide a starting point for a logical model, and AI can help teams create or extend that model. Breaking the work into data product specifications or smaller logical data products also makes it easier to update definitions without waiting for one large modeling project to finish. 

The technology can take on more of the mechanical work. Domain experts still provide the context. They know which definitions are disputed, which exceptions matter and when a source that looks authoritative is no longer current. 

This approach is consistent with a longstanding idea from data mesh: treat data as a product and give ownership to the people who understand its business context. 

Make trust visible 

A useful trust score brings together data quality, curation, user feedback, proximity to the original source, and scarcity or value. Those signals can be translated into a gold, silver or bronze classification so people can quickly judge whether the data is appropriate for their work. 

Some teams use those trust labels alongside a medallion architecture, updating the score as data is profiled, curated and used. For those labels to be useful, people need to see the evidence and workflow behind them. A business user should be able to understand how the data was evaluated and whether it is ready for the task at hand. 

Confidence gates create another place to apply trust. A model can route low-confidence answers to a person for review. That person needs enough context to examine the data and understand why the system was uncertain. Human review requires a working process with clear responsibility for looking at how data is created and changed. 

That oversight becomes especially important as organizations explore agentic AI. Deloitte’s 2026 enterprise AI survey found that only about one in five companies has a mature governance model for autonomous agents. Many organizations are adopting agents before they have established the oversight those systems and subsequent data require. 

That oversight usually comes from a governance program. Some customers call their approach “governing as you go” or “just enough governance.” They involve the right people as decisions come up and avoid turning governance into a long approval process. The EU AI Act places human oversight among the requirements for high-risk systems. Those obligations are scheduled to begin applying on December 2, 2027. In day-to-day terms, organizations need a way to observe the data, understand how it changes and step in when something needs attention. 

What this looks like when it works 

Let me give you one example. A client had a general ledger process that required someone to work through 300 spreadsheets whenever an issue appeared in any line of business. They built a single data product that brought the calculations, reports and underlying data together in one validated asset. The new process saved them roughly 750 days of effort. 

The improvement came from making the right data easier to find and reliable enough to use without second-guessing it. For me, this is what applying trust looks like in practice. 

I have spent more than 25 years working with enterprise data programs, and I have seen how quickly confidence disappears when data lets someone down. People rarely return to the same source without a clear reason to believe it has improved. Once the well feels tainted, they look elsewhere. 

Applying trust means making a few important details visible: where the data came from, how it was evaluated and who is responsible for it. People can then decide whether the data is right for the work in front of them. 

Susan Laine is Chief Technologist at Quest Software, an enterprise software company headquartered in Austin, Texas. Quest provides specialized tools and SaaS platforms focused on data management and governance, cybersecurity, identity access management, and platform modernization to help organizations manage infrastructure and support AI initiatives 

Related Articles

Back to top button