Unstructured Data & AI Governance Survey 2026: Information quality is emerging as a strategic AI risk

Organizations have accumulated vast amounts of unstructured information across file shares, SharePoint, Teams, OneDrive, email and cloud services.

For years, much of this information could remain largely in the background. AI changes that equation.

As Copilots, intelligent assistants and analytics solutions gain access to everyday information environments, the quality, relevance, lifecycle, sensitivity and accessibility of that information become increasingly important. AI can only work with the information it can access. If the underlying information is outdated, fragmented, poorly governed or available too broadly, those weaknesses can also become part of AI-enabled processes.

To explore this challenge, GDPR Tech conducted the Unstructured Data & AI Governance Survey 2026 in collaboration with Tutkimusvoima.

The exploratory international expert survey gathered responses from 86 professionals in Europe, North America and Asia-Pacific, including respondents from globally operating organizations. Participants worked in privacy, information governance, compliance, technology, business and executive roles.

Key findings

  • Only 18% of respondents reported good or accurate visibility of their unstructured data volumes.
  • The most frequently selected risk was sensitive or personal data stored in uncontrolled locations, chosen by 73% of respondents.
  • 53% selected outdated information as a risk, and 53% selected incorrect or low-quality information as a risk.
  • Around 65% described their unstructured data governance practices as not established or still at an initial, ad hoc stage.
  • Only 7% reported that retention periods and deletion practices were both implemented and monitored.

Visibility remains limited

One of the clearest findings concerns basic visibility.

Only 18% of respondents reported good or accurate visibility of their unstructured data volumes. Most had only a rough estimate, while some had no visibility at all.

This matters because organizations increasingly need to determine which information should be available to AI systems, which should not, and under what conditions.

Without a reliable picture of the information landscape, even defining the scope of an AI use case becomes more difficult.

Survey respondent
No clear understanding of how much of the data is still relevant.

Sensitive information is the leading risk

The most frequently selected risk was sensitive or personal data stored in uncontrolled locations, chosen by 73% of respondents.

Other frequently selected risks included:

  • outdated information, 53%
  • incorrect or low-quality information, 53%
  • sensitive data leakage via AI, 52%
  • AI access to information without proper controls, 52%
  • excessive access rights, 49%

These findings show that AI governance cannot be separated from existing information governance, privacy and access-control practices.

The risk is not simply that AI systems may produce inaccurate outputs. The information they can reach may already contain problems that organizations have struggled with for years.

Information quality deserves more attention

Information quality emerged as a particularly interesting theme.

More than half of respondents identified outdated information as a significant risk, and just as many identified incorrect or low-quality information. Duplicate or fragmented information was also selected by almost half of respondents.

This does not mean that information quality was ranked as the single biggest risk. Sensitive and personal data in uncontrolled locations clearly ranked higher.

But the findings suggest that information quality deserves a stronger place in strategic AI risk oversight.

Organizations often focus first on AI models, vendors, security controls and policies. Those are necessary, but they do not solve problems in the underlying information.

Governance maturity is still low

The survey also points to a substantial maturity gap.

Around 65% of respondents described their unstructured data governance practices as either not established or still at an initial, ad hoc stage.

Only 7% reported that retention periods and deletion practices were both implemented and monitored.

At the same time, unstructured data is already being used in AI and analytics. Almost half of respondents reported some level of production use.

This creates a familiar governance problem: adoption can move faster than the underlying information management practices.

Survey respondent
The staffing resources, time, and/or technology cost in doing the work to get everything in order. While we prioritize this work to an extent, it is competing with very limited resources against many other high-priority work items.

AI governance starts with information governance

The survey findings point to a fairly practical conclusion.

Before connecting AI to large information environments, organizations should understand at least:

  • what information exists
  • where it is stored
  • who owns it
  • who can access it
  • whether it is still relevant
  • how sensitive it is
  • how long it should be retained
  • whether it is appropriate for the intended AI use case

Technology can support discovery, metadata analysis, permission analysis and content classification at scale. Human judgment is still needed to interpret those results, assess risk and make governance decisions.

The objective is not to clean every file before AI can be used. That would be a rather efficient way to postpone AI until retirement.

The more realistic approach is to start with the information environments needed for a specific business use case, assess them properly and expand governance coverage over time.

Survey respondent
The biggest challenge is turning fragmented, text-heavy information from different projects, reports and communication channels into reliable, searchable and GDPR-compliant knowledge, without creating additional administrative burden for staff.

Download the Executive Insight Report

The Unstructured Data & AI Governance Survey 2026 – Executive Insight Report presents the main findings, selected open-text responses and practical implications for organizations adopting AI and analytics.

Download the Executive Insight Report (PDF)

The survey was conducted by GDPR Tech in collaboration with Tutkimusvoima. Survey findings are reported in anonymized form.

What's new?

In the blog you will find current information, interesting articles and a lot of detailed information related to data protection.

Read these also

Share on social media

Request a quote for services