Top Selling Multipurpose WP Theme
Home CEO/Interviews Can Indian Enterprises Build AI Without Losing Control of Their Data?

Can Indian Enterprises Build AI Without Losing Control of Their Data?

By Manish Gupta, Director, Liferay India

The challenge is increasingly moving from whether organisations should adopt AI to how they can do so without weakening the controls already established around enterprise data. Indian enterprises operate with large volumes of customer, employee, financial and operational information, often spread across multiple applications and repositories. Giving AI access to this information without clearly defining what it can access, under which circumstances and on whose behalf creates significant risk.

Another challenge is that governance is often considered after a use case has already been developed. This can make deployment slower because organisations then have to retrofit security, access controls, audit mechanisms and data policies. A more sustainable approach is to establish these boundaries at the architectural level, so that security and governance form part of the deployment model rather than becoming an additional layer added later.

The focus should therefore be on controlled access rather than simply restricting access. Organisations need to ensure that AI systems can use the right information for a particular task while respecting the same permissions and data boundaries that apply to human users.

Many enterprises still operate across fragmented and legacy systems. How does this impact their ability to build secure, reliable AI applications, and what role can a unified digital platform play in addressing these challenges?

Fragmentation creates two related problems: access to data and understanding its context. Enterprise information may reside across CRM, ERP, content management, service management and legacy systems, each with its own data structures and permission models. Simply connecting these systems does not automatically create a reliable foundation; organisations also need to understand where information comes from, who owns it and who is authorised to use it.

A unified digital platform can provide a common layer through which information, identity, permissions and business processes can be managed more consistently. The objective should not be to replace every existing system, but to connect the systems that already run the business while providing a controlled environment through which users and applications can interact with them.

This is particularly important for organisations that want to move from isolated pilots to enterprise-wide deployments. The underlying architecture needs to support integration without creating another disconnected technology layer.

As generative AI and AI agents become part of everyday business workflows, how important is data governance in ensuring that AI systems access only the information they are authorised to use?

Data governance is fundamental because the quality of an AI application is not determined only by the model being used. It also depends on the information that the system can retrieve, the conditions under which it can use that information and the controls applied to the resulting output.

For enterprise applications, access should be contextual. An employee working with one set of records should not automatically gain access to information simply because an AI system can retrieve it. The system needs to operate within defined roles, permissions and data boundaries.

This is why governance should extend beyond policies and documentation. It needs to be reflected in the technical architecture, with mechanisms for enforcing permissions, monitoring interactions and maintaining an audit trail. Liferay’s approach, for example, builds on the existing security and access-control framework of its DXP environment rather than requiring organisations to establish an entirely separate governance model.

How can enterprises ensure that AI agents respect existing user roles, permissions and data boundaries—for example, ensuring that an employee, customer or partner only receives information they are authorised to access?

The starting point is to treat an AI agent as another participant in an existing business process, rather than as an independent application with unrestricted access to enterprise information. Its permissions should be inherited from, or explicitly tied to, the identity and role of the person or process it is acting for.

This means access controls need to be enforced at the point where data is retrieved, not simply at the user interface. An employee may have access to certain HR information, for example, while a customer or partner should have access only to information relevant to their relationship with the organisation.

Organisations should also be able to trace interactions: who initiated a request, what information was accessed and what response was generated. Such auditability is important not only for security teams but also for organisations operating under regulatory and internal compliance requirements. Liferay AI Hub, for instance, uses existing roles and permissions and provides auditability around agent interactions.

With enterprises increasingly using multiple AI models and LLMs, should organisations avoid being locked into a single model? How important is the ability to connect different AI models while maintaining security, governance and control over enterprise data?

Model flexibility is becoming increasingly important because the technology landscape is evolving quickly. Different models may perform better for different workloads, and organisations may also have requirements around cost, performance, data residency or deployment architecture.

The question is therefore less about choosing one model permanently and more about creating an architecture that allows organisations to make those choices over time. A model-agnostic approach can reduce dependency on a single provider and allow enterprises to introduce or replace models without redesigning their entire application environment.

However, model flexibility should not come at the expense of governance. The security and data controls should sit around the enterprise application and remain consistent irrespective of which model is being used. Liferay AI Hub follows this model-agnostic approach, allowing organisations to connect different AI services while maintaining the governance framework around their enterprise environment.

Looking ahead, what will distinguish Indian enterprises that successfully scale AI from those that struggle with data security, governance and control—and what should CIOs prioritise today to build a more responsible AI foundation?

The organisations that scale successfully will be those that treat AI as an enterprise architecture issue rather than only a technology experiment. Starting with individual use cases is useful, but organisations also need to consider how those use cases will connect with existing data, identity, security and business systems as adoption grows.

For CIOs, three priorities stand out. First, establish clear ownership and governance for enterprise data. Secondly, ensure that identity, permissions and auditability are built into the architecture from the beginning. Thirdly, avoid creating isolated technology stacks for every new use case; wherever possible, build on existing enterprise platforms and integration capabilities.

There is also a need to establish practical boundaries around where AI can and cannot be used. Not every process requires the same level of autonomy or access to information. A risk-based approach, with appropriate human oversight for sensitive decisions, can help organisations scale adoption while retaining accountability.

Ultimately, responsible AI adoption is less about limiting what technology can do and more about ensuring that organisations remain in control of how it is used. For Indian enterprises, that distinction will become increasingly important as deployments move from experimentation into core business operations.

@2023 – Cellit. All Rights Reserved.

Contact us: contact@cellit.in