Information advantage and the new data perimeter: Data trust is becoming government's core security layer
Data is central to how governments operate, from census records to budget reports, agencies have long relied on information to make decisions. As data feeds grow richer and faster, so does the opportunity to make smarter policy decisions. Still, there's a widening gap between agencies that simply collect data and those that build a powerful and permanent culture around it, where data certification, management controls, data products and data context matter just as much as the vast stores of data themselves.
The gap between ordinary data use and culture was one of efficiency but with AI it is evolving into one of security and regulatatory requirements, holding back government’s data capabilities and controls from their beneficial potential.
What other industries are already learning the hard way
Of course, data control and governance isn't a government-specific problem, yet in some ways government has more mandate to improve and iterate quickly to improve.
McKinsey's 2025 State of AI survey, based on nearly 2,000 respondents across roughly 105 countries, found that 51% of organizations using AI have experienced at least one negative consequence in the past year, most commonly tied to inaccurate outputs. The same survey found that organizations manage an average of four categories of AI-related risk today, up from about two in 2022 — real progress, but governance is still catching up to adoption. Separately, only 28% of organizations said their CEO takes direct responsibility for AI governance, and just 17% said their board does, according to the same research.
Verizon's 2025 Data Breach Investigations Report, which analyzed more than 22,000 security incidents across industries, found that nearly 60% of breaches involve a human element — error, negligence, manipulation, or misuse — and flagged a rising pattern of employees accessing generative AI tools with personal accounts on corporate devices, outside of any sanctioned oversight. That's the private-sector version of the exact problem a data culture is designed to prevent: tools and data moving faster than the governance and practices wrapped around them.
The government isn't immune to these trends, and in many ways faces them from a standing start, since the pressure to modernize is colliding with legacy systems, personnel changes and long-entrenched data silos across public agencies. The bottom line: data practices anchored in the past can prevent mission success and greatly impact AI innovation.
The pressure is real
The Government Accountability Office found that across a sample of federal agencies, reported generative AI use cases nearly doubled, from 571 in 2023 to 1,110 in 2024. A separate GAO review of 23 civilian agencies found that although 20 already use or plan to use AI for things like chatbots and fraud detection, most aren't yet adequately addressing the cybersecurity risks, including data corpus poisoning, model theft, and misuse of AI-generated content.
The simple truth is governments can't responsibly manage data it can’t find, classify, and trust. AI systems built on data whose context, lineage and sensitivity aren’t understood could be more error-prone, costly or even harmful than manual data work.
Data as the "ground truth" for Zero Trust
This logic is showing up in cybersecurity policy, not just AI policy. The Department of Defense's (DoD/DoW) 2022 Zero Trust Strategy replaced the old perimeter-based "castle and moat" model with a "never trust, always verify" approach, assuming adversaries may already be inside the network. It set a hard fiscal year 2027 deadline for DoD components to reach target-level Zero Trust across 152 activities spanning seven pillars: User, Device, Application & Workload, Data, Network & Environment, Automation & Orchestration, and Visibility & Analytics. CISA's civilian counterpart, its Zero Trust Maturity Model, organizes the same idea around five pillars plus three cross-cutting capabilities — one of which is Data.
In both frameworks, the Data pillar is foundational, because the target of most cyberattacks isn't the network or device — it's the data itself. A "least privilege" policy is only as good as an agency's ability to know what a piece of data is, where it is and how sensitive it is. Without accurate, continuously maintained classification, access decisions are effectively made in the dark — the same insight a data culture applies to policy analytics, just pointed at security instead.
From data silos to data products
One of the most practical shifts an agency can make is moving from unstructured repositories to well-defined, discoverable data products — data packaged with context about its purpose, quality, lineage, and appropriate use. Collibra's public sector roadmap reflects this: a Data Marketplace with built-in data product functionality, lifecycle trackers showing where data sits in curation, and data contracts that automate quality enforcement. That same discipline — automated discovery, classification, and tagging at scale — is exactly what feeds a Zero Trust Data pillar, giving tools like data loss prevention systems the confidence to move from "monitor-only" to active enforcement without a flood of false positives. The benefits multiply for users as data is more easily found, updated and understood.
Governance as infrastructure, not red tape
The government-wide Federal Data Strategy organizes 40 practices around three themes: building a culture that values data, governing and protecting data, and using data efficiently. That maps closely onto features like Collibra's upcoming Control Tower, which lets agencies configure active controls that continuously scan for assets failing to meet defined criteria and alert the right people automatically — governance as infrastructure, enforced continuously rather than checked once.
AI readiness starts with data integrity
Given the GAO's findings on AI risk, and McKinsey's cross-industry findings on the governance gap, oversight tools matter. Collibra's AI Command Center, coming to government platforms, will inventory AI models, use cases, and agents, each scored for trustworthiness based on documentation completeness, data lineage, and sensitive data handling, giving compliance teams risk ratings at a glance. Paired with FedRAMP-authorized cloud AI capabilities and support for self-hosted, localized LLMs, government agencies won't have to choose between innovation and compliance.
The bottom line
The data backs up what the frameworks assume: AI adoption is outpacing governance across every sector that's been measured, government included, and security models increasingly treat data classification as their foundation. Agencies that invest in data culture now as well as discoverability, quality, governance, and responsible AI will be ready with purpose built protections to defend systems and insights available at the speed of their mission. The question isn't whether to build a data culture. It's whether you have the tools to start today.
Sources
- Gartner, cost of poor data quality research — via Gartner: How to Stop Data Quality Undermining Your Business
- McKinsey & Company, The State of AI: Global Survey 2025
- Verizon, 2025 Data Breach Investigations Report
- U.S. Government Accountability Office, GAO-25-107653: Generative AI Use and Management at Federal Agencies (July 2025)
- U.S. Government Accountability Office, GAO Report: Federal Agencies Struggle to Address AI-Related Cybersecurity Risks (May 2025)
- U.S. Department of Defense, Zero Trust Strategy (Oct. 2022), as summarized via Lawfare and StrongDM
- Federal Data Strategy, OMB / GSA — strategy.data.gov
Keep up with the latest from Collibra
I would like to get updates about the latest Collibra content, events and more.
Thanks for signing up
You'll begin receiving educational materials and invitations to network with our community soon.