An AI becomes more useful when it knows your business. But what happens when the combination of mundane information reveals context that no one has explicitly provided?
A business leader uses artificial intelligence daily. One Monday, he asks it to prepare a negotiation with a supplier. A few days later, he analyzes with it the consequences of a pricing policy change. The following month, he submits several budget scenarios, considers an acquisition, prepares a board meeting, and asks how to handle a difficulty with a member of his executive committee.
None of these conversations necessarily contain the company’s complete strategic plan. But what do a hundred, five hundred, or a thousand interactions reveal when put together?
A survey published on August 17, 2026 by Axios and written by Ina Fried analyzes the information we progressively entrust to AI assistants. It led me to shift the question toward the enterprise: what can these systems progressively understand about our organizations?
The article notably emphasizes that the issue is no longer limited to whether prompts are used to train models. It’s also about understanding how they can contribute to shaping the representation the system builds of the user.
What becomes strategic is no longer just the data transmitted to the artificial intelligence. It’s also what several pieces of data, though mundane when considered separately, allow us to understand when combined. One prompt may contain one piece of data, a hundred prompts can tell a story of strategy. A thousand conversations can begin to describe an organization. This evolution introduces, in my view, a new layer in AI governance.
I propose to call it organizational context governance.
Context becomes a condition for value creation
The problem would be relatively simple if companies could simply limit the information AI systems have access to. But that would also reduce their usefulness. An assistant that knows nothing about your company can draft an email, summarize a document, or explain a negotiation method. A system that knows your products, your customers, your processes, your history, your objectives, and your constraints can provide much more relevant assistance.
With AI agents, this difference becomes even more pronounced. A generic agent can explain how to prepare a commercial negotiation.
An agent with access to exchanges with the client, contract history, pricing practiced, deadlines, and commercial objectives can help prepare that specific negotiation. Context therefore creates value, but it simultaneously creates a new governance object.
This is the central paradox: The more context an AI has, the more useful it can become. The more context it has, the more organizations must understand and control what that context allows it to establish. The question is therefore not about choosing between performance and protection. It’s about determining which context is legitimate, necessary, and proportionate to each mission.
From data governance to organizational context governance
Since the arrival of generative AI, much of the debate on confidentiality has focused on a relatively simple question: what data can we transmit to ChatGPT, Claude, Gemini, or other assistants? Companies have progressively established rules. They define confidential data that must not leave the organization, distinguish authorized tools from consumer solutions, and examine the guarantees offered by their suppliers.
These measures remain essential, but they primarily reason data by data. The Axios survey invites us to broaden this reflection. It focuses on the information progressively entrusted to AI assistants and how memory, retention, or personalization functions can modify the relationship between the user and these systems.
Provider policies show that mechanisms differ according to products. OpenAI offers controls dedicated to memory, temporary conversations, and data use. Anthropic explicitly distinguishes its commercial products, whose inputs and outputs are not used by default to train its models, from its consumer products. Google specifies that certain Gemini conversations may be temporarily retained even when certain activity settings are disabled.
For the enterprise, this question opens a broader problem.
It’s no longer enough to ask:
What data are we giving to AI?
We must also ask:
What can a system understand when it can combine multiple pieces of information from the organization?
I call organizational context governance an organization’s ability to control not only the information accessible to an AI, but also the knowledge that their combination can reveal. This approach shifts the unit of analysis. Data corresponds to what the company provides. Access corresponds to what the system can consult. Memory corresponds to what it can retain. Context corresponds to what it can relate to understand a situation and accomplish a mission.
This logic can be summarized as follows:
Data + access + memory + combination capability = organizational context.
This equation is not intended to constitute a mathematical model. It makes visible a dimension that traditional governance policies still inadequately address.
Context sensitivity can exceed that of data
Take a company where each system is properly protected. Its CRM contains its customers. Its calendar contains executives’ appointments. Its financial tool contains forecasts. Its HR platform contains ongoing recruitments. Its document space contains strategic presentations.
Each of these environments has its access rules. But what happens when an agent can cross several of these sources? The information “three meetings are scheduled with a competing company” may be relatively innocuous. The information “an integration director position is being recruited” may also be innocuous. Financial projections show additional financing capacity. An internal document mentions a reflection on external growth. Independently, each element reveals a limited part of the situation. Their combination can begin to make an acquisition operation plausible.
This is where an important change occurs. Context sensitivity can be greater than that of each of the data that compose it.
The phenomenon is not new. Data cross-referencing has always made it possible to produce information that did not explicitly exist in any source taken in isolation. What changes with AI agents is the scale, the diversity of accessible sources, and the ability to mobilize these relationships directly in executing a task. For a long time, organizations have mainly classified their information: public, internal, confidential, secret. But how do you classify a combination of several internal pieces of information that, considered together, become highly strategic?
However, we must remain precise. This does not mean that AI providers necessarily reconstruct a global representation of each company from all their users’ interactions. Possibilities depend on systems, memory and retention settings, architectures used, account type, and data actually accessible. The governance problem is different.
The enterprise must now focus not only on the access it authorizes, but also on what their combination potentially allows the system to establish.
With AI agents, permissions are no longer enough
This question becomes particularly important with AI agents. In a traditional chatbot, context is still largely selected by the user. The user chooses the questions they ask and the documents they transmit. With an agent connected to the company’s systems, access to context can become structural.
To accomplish a task, the agent can consult email, calendar, CRM, financial tool, document database, or several business applications.
Individually, each authorization may be perfectly legitimate. The problem appears in their combination. An agent may have technically compliant rights and yet access a much broader context than necessary for the mission for which it was designed. This is where traditional access control mechanisms reach a limit.
The classic cybersecurity question is:
“Does this system have the right to access this data?”
Context governance adds a second question:
“What does it become capable of understanding when it accesses these different data simultaneously?”
This distinction is essential. An agent that automatically inherits its human user’s permissions may, for example, have a considerable set of accesses. Yet a human collaborator rarely simultaneously consults all documents, all conversations, and all data they are authorized to access. An AI can, depending on its architecture and the tools to which it is connected, much more quickly combine dispersed information.
Agent governance will therefore probably need to go beyond simple permission management. It will need to examine resulting informational capabilities. In other words, not only what the agent can see, but what the combination of its different accesses potentially allows it to understand.
Governing context: scope, duration, combination
The answer is not to systematically reduce access to information. An AI deprived of all context will remain largely generic. The challenge is to provide it with enough context to create value, while controlling what that context can allow to establish.
Three dimensions seem essential to me.
Governing scope
What data, applications, and spaces can the system access? The principle of least privilege, well known in cybersecurity, remains relevant: a user or system should only have the rights necessary for their mission.
But with AI agents, it could be complemented by another logic: least necessary context.
- Does an agent responsible for scheduling appointments need to access the content of all attachments?
- Should a sales agent consult the entire CRM or only accounts within their scope?
- Should an executive assistant have access to all documents their human user is authorized to access?
The question should no longer be only: “Can it access it?”
It should also become: “Does it need it to accomplish this mission?”
Governing duration
Not all context needs to be retained. Some tasks can benefit from persistent memory. Others can be executed from temporary information. Organizations will therefore need to examine retention duration, memory mechanisms, and the possibility of deleting or resetting certain contexts. Memory should not be activated simply because it improves user comfort. It must respond to a clearly identified purpose.
Governing combination
This is probably the newest dimension. Two pieces of information that are not very sensitive when considered separately can become strategic when combined. Governance must therefore go beyond traditional data classification to also examine the knowledge that their combination can reveal. This reflection leads to an avenue that still deserves to be defined and tested: that of a context budget.
A context budget could define, for a given mission, the scope of data, connectors, memory, and combination capabilities that an organization agrees to make accessible to an agent. The principle would be simple: not to give the agent all available context, but only the context necessary to create expected value.
Shadow AI adds an additional difficulty here. When different collaborators use multiple assistants, sometimes personal ones, part of the organizational context can be dispersed among environments whose memory, connectors, or contractual conditions the company does not always control. The issue is therefore no longer just: what tools are being used? It also becomes: in how many environments is our organizational context progressively fragmented?
The context test
This reflection can be applied immediately. Take an assistant or agent currently used in your organization and ask four questions.
- What can it access?
Data, documents, emails, CRM, calendar, business applications.
- What can it retain?
History, memory, preferences, information from previous interactions.
- What can it combine?
What different sources can it combine within the same task?
- What does this combination allow it to understand that your organization considers strategic?
This last question is probably the least familiar. Yet it could become one of the most important. If your organization can answer the first three questions, but not the fourth, it is probably governing its access. Not yet its context.
Governing what AI can understand
Value creation through artificial intelligence will probably increasingly depend on our ability to provide it with rich context. A system without context remains generic. A contextualized system can become much more relevant for integrating the constraints, history, and objectives of an organization into its responses and actions. But this efficiency creates a new responsibility. For several decades, companies have learned to protect their data by asking a fundamental question:
Who can access what?
With AI agents, a second question emerges:
What does a system become capable of understanding from everything we give it access to?
We have learned to govern data. We will now need to learn to govern what it allows us to understand. The next frontier of AI governance could well be that of organizational context.
Sources Ina Fried, “What happens to the secrets you share with AI”, Axios, August 17, 2026. OpenAI, documentation on privacy settings, memory, and temporary conversations in ChatGPT. Anthropic, “Is my data used for model training?”, Privacy Center. Google, “Gemini Apps Privacy Hub”, documentation on Gemini activity and conversation retention.




