When the Model is a Commodity, Your Data is the Strategy
govciooutlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Gov CIO Outlook Advisory Board.

Dell Technologies

When the Model is a Commodity, Your Data is the Strategy

Arash Ghazanfari

Data Strategy Architect

Almost every organization I speak to is investing in AI to improve insight, reduce repetitive work and improve services for citizens and customers.

The issue is turning a pilot into a dependable service. When that stalls, the model gets blamed. In reality, causes are poor data, unclear ownership, weak governance, and infrastructure never designed for the job.

Data is the Place to Start

AI models are easier to access and harder to distinguish. An organization's data is different. It holds its history, operating knowledge and understanding of the people it serves. Competitors can buy the same technology. They cannot buy that context.

That is why the largest model is not automatically best. For many tasks, a smaller model with secure access to relevant, well-understood data is more useful than a frontier model without context. Model selection matters, but it should come later.

Before choosing a model, ask, what data do we have. Who owns it? Where did it come from? Is it current? Can we trust it? Do we understand how it was created? These determine whether AI works outside a demonstration.

Data Location as a Question of Control

Once organizations examine their data, another question appears—where should it live and be processed?

The instinct has been to collect data centrally and move it to the application. That can make sense, but should not be the default without weighing security, regulation, latency and cost. In some cases, the better approach is to take the model to the data rather than move large quantities of sensitive information to the model. That can reduce unnecessary data movement while keeping control closer to where the information already resides.

Sovereignty conversations need precision. Data residency and sovereignty are related, but not identical. Storing information within national borders may satisfy one requirement, yet say little about who controls the system, holds encryption keys, provides support or can be compelled to grant access.

The useful question is ‘Who has authority over the data?’ This is not an argument against the cloud. Cloud remains essential as an argument for conscious choices. Different workloads carry different risks, and architecture should reflect that.

Governance that Builds Trust

Good data is only valuable if people trust how it is used. That trust comes from security and governance designed in from the start.

Too often, governance arrives at the end as an approval gate. By then, key decisions are made, and controls feel like obstacles. Project teams feel security slows progress, while security teams must accept risks they never shaped.

“Organizations that benefit most from AI will be those that understand their data, establish governance early and make and infrastructure.”

Organizations making progress build governance from the start. They track data provenance and lineage, control access based on authorization, and can trace how models produce outputs and which data influences them. Security is built into the architecture, not added later.

Zero trust is especially relevant. A user, service or model should not receive access simply because it sits inside the network. Access should be explicit, limited and continuously assessed. This matters more as AI moves from answering questions to taking actions. An agent that can initiate a process, update a record or communicate on someone's behalf creates a different risk from a chatbot. They need clear limits, human oversight and a detailed audit trail.

Importance of Infrastructure

Infrastructure enters the AI discussion late, usually after a pilot creates demand for wider use. Then the limitations become expensive.

AI workloads are persistent, computationally intensive and data-hungry. Many estates were not built for that. Performance suffers, cloud costs rise, and energy use is hard to justify. Data movement itself becomes a source of delay and expense.

There is no single infrastructure answer. Some workloads belong in public cloud, and others suit private cloud, on-premises or edge. Most will use a combination based on workload needs. Infrastructure is rarely the most compelling part of an AI story. It is, however, why a demonstration either becomes a dependable service or remains one.

AI Exposes Organizational Weaknesses

The hardest obstacles are often not technical. AI projects cut across processes, ownership, security, legal and operations. Silos become visible quickly. Teams use different languages for the same problem, disagree on data ownership or have never defined the outcome. AI can make a broken process run faster, rather than fixing a fragmented organization.

Start with a business outcome that matters. What delay can we remove? Which decision needs better evidence? What task is keeping skilled people from higher-value work? A clear outcome defines the data needed, the acceptable risk and whether the investment is worthwhile.

Keep architecture open. Models and platforms will keep changing. Tying data too tightly to one technology means today's shortcut becomes tomorrow's constraint.

For any proposal, ask three questions—is the data ready and understood? Can we govern the use responsibly? Can systems support it beyond the pilot?

What this Means for Government Leaders

Leaders are custodians of citizens' information and must modernize within strict legal duties, constrained budgets and skills shortages.

For a CIO or CISO, decisions about location, access and governance are not preferences. Information may be highly personal, the threat environment is contested, and consequences go beyond financial loss. Public confidence is hard to build and easy to damage.

Accountability weighs differently. If an automated system influences a decision about a citizen, someone must explain it, take responsibility and provide a route for the citizen to challenge or correct that decision. Provenance, classification, access control and auditability underpin legitimacy, not just security. The risk I worry about most is that a poorly designed process is automated before it is questioned. The same flawed decision is then made faster and at larger scale.

There is a hopeful side. In one healthcare setting, moving data processing closer to where care was delivered cut diagnosis time from 12 days to less than 24 hours. No single product delivered that. It came from agreeing on the outcome, making data dependable and changing how work was done.

That is what practical AI should look like in public services. Its value is not the prominence of the model, but a shorter waiting list, an earlier diagnosis, a quicker response or staff freed to spend time with people who need them.

Organizations that benefit most from AI may not be those running the largest number of pilots. They will be those that have done much of the difficult work before the right use case appears—understanding their data, establishing governance early and making deliberate decisions about location, control and infrastructure. Enthusiasm can start an AI program. Judgment, preparation and the groundwork behind it are what turn it into something useful.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief