Sponsored by

Box

Sponsored by

August 4, 2026

How to build secure and user-friendly AI: ‘If data sits in a silo, it only sees part of the picture’

The secret to successful AI isn't choosing the perfect model, but safe and organised company data

Lara Bryant

5 min read

Many organisations are now using AI to automate workflows and enhance how their teams work. But some still find themselves stuck at the first hurdle.

Caught between security and usability, business leaders often spend more time than necessary deliberating over which AI model to use.

But the reality is much simpler, according to Michael Pietsch, VP of DACH at intelligent content management platform Box. The biggest barrier to AI success isn't the technology itself, but the data it uses.

He advises companies to manage their data before looking to AI. “AI can only work with the information you give it. Take what you already have in your company and make it AI-ready.”

Pietsch sat down with Sifted to unpack how companies can reap the benefits of AI without compromising on data security.

The trade-off between security and usability 

Small and medium-sized businesses (SMBs) often operate under the assumption that AI software can either be secure or user-friendly — never both.

IT teams also tend to lean towards platforms that satisfy compliance and governance mandates, says Pietsch. But these systems can be inaccessible to users.

“Employees want tools that feel as easy as the platforms they use at home,” he says. This forces business leaders to choose between security and simplicity.

But companies no longer need to make this trade-off. By using an intelligent content management platform like Box, they can place consumer user experience on top of a foundational layer of governance.

By automating security controls in the background, AI can still be accessible to the user.

The AI knows exactly who accesses the file, can revoke access instantly and even apply security policies automatically.

Pietsch uses sales as an example of how this can work in practice. Traditionally, sharing a confidential proposal with a client might require VPNs, password-protected zip files or authorisation from IT.

But if the process is too difficult, a salesperson might send unsecured email attachments just to get the proposal out the door.

When usability and security are used together, employees don't have to navigate security protocols as the platform handles them automatically.

By using Box, for example, AI agents automatically inherit existing user permissions and compliance controls, without the need for a separate governance layer.

“The AI knows exactly who accesses the file, can revoke access instantly and even apply security policies automatically. Everyone gets what they need,” Pietsch says.

Advertisement

Why unstructured data is the bottleneck to AI adoption 

A major barrier to AI adoption is the state of underlying data. When data, such as PDF contracts, email threads and slide decks, is scattered across systems, even sophisticated AI will struggle to deliver results.

Bring everything together, and suddenly AI has the context it needs to deliver really valuable results.

When an AI tool is introduced into scattered data, it only gets a partial view of the company's knowledge. “Before companies can really benefit from AI, they need to get their content under control and make sure it’s properly governed,” says Pietsch.

“If data sits in a silo, AI only sees part of the picture,” he adds. “Bring everything together, and suddenly AI has the context it needs to deliver really valuable results.”

Pietsch uses the example of an engineer. “Engineering drawings sit on a file server, contracts in SharePoint and project documents are scattered across Teams,” he says.

“If a service technician needs the latest maintenance manual and AI only sees an old version because the new one is stored somewhere else, it will confidently give the wrong answer.”

Once data is consolidated, a new challenge arises. If an organisation pools all of its documents into a single system for AI to analyse, it runs the risk of sensitive information or confidential records being surfaced to the wrong person.

To prevent this, AI must adhere to the company's existing user permissions and controls.

Governance and avoiding Shadow AI

Companies operating in regulated markets, such as healthcare, finance and the public sector, often face a dilemma when wanting to use AI.

For these organisations, the question isn't just how an AI model processes information, but where that information sits.

In regions such as Germany, Austria and Switzerland, compliance and data sovereignty are also not just IT concerns but board-level mandates.

Regulations such as the GDPR and the EU's NIS2 directive make it a legal requirement to demonstrate exactly where data is processed, who accessed it and how it’s being used — expectations that only increase when AI enters the picture.

Pietsch emphasises the importance of local data residency — the country or region where an organisation’s data is stored and processed, often the physical location of data centres.

If your content is in good shape, you can plug almost any AI into it in the future.

When faced with these compliance requirements, many IT departments will block access to consumer AI tools altogether.

But strict clampdowns don’t often work. Instead, it can breed ‘Shadow AI,’ where employees bypass company networks to feed sensitive data into public AI chatbots.

“People won't stop using AI just because you tell them not to—they'll just find another tool,” says Pietsch. “That’s why companies need to offer a secure alternative.

“With platforms like Box, for example, employees get the AI capabilities they want while the content stays inside the company in a governed environment. It’s much better to provide a secure alternative than to constantly try to fight Shadow AI."

Pietsch advises business leaders not to spend too much time thinking about which AI model to use, but to focus on content and data instead.

“Models will keep changing. Focus on your content instead,” he says. “If your content is in good shape, you can plug almost any AI into it in the future.”

AI is no longer just assisting—it's doing the work. How should your company navigate this new era of ‘digital colleagues’? Get the key insights and trends you need in the latest Sifted report in partnership with Box.

Lara Bryant

Lara is a content writer at Sifted, based in London. You can find her on LinkedIn

Sifted Daily newsletter

Sifted Daily newsletter

Weekdays

Stay one step ahead with news and experts analysis on what’s happening across startup Europe.