7 September 2026·9 min read

AI strategy: what if you started with your data governance?

AI strategy: what if you started with your data governance?

September is here, the moment to set the course for the coming years. Before choosing which AI tool to deploy, a more important question deserves settling: within what framework does artificial intelligence have the right to work for you?

September, the right moment to ask the question

September is when the important decisions come back onto the table. The year's budget, the investment projects, the priorities of the coming months. And for the past two years, one more line has been added for almost every food business: what to do about artificial intelligence.

The question is no longer whether AI will enter the business. It is already there, often through the back door. A sales manager pasting figures into ChatGPT to draft a follow-up. An accountant asking an online assistant to summarise a margin table. These uses are helpful, but they escape the company's control entirely. Nobody knows where the data goes, what becomes of it, or who might read it.

Faced with that, the temptation is to think in terms of tools: which software to choose, which agent to deploy, which feature to switch on. That is a sequencing mistake. Before choosing a tool, you have to choose a policy. And that policy comes down to a simple question: within what framework does artificial intelligence have the right to work for you?

That framework is what we call governance. It is not a constraint bolted on afterwards to get you compliant. It is the foundation everything else rests on.

Why governance comes before the tool

The AI landscape changes every quarter. Models are replaced, architectures evolve, what was state of the art in spring is outdated by autumn. In that context, committing your business to a fixed technology roadmap makes no sense: nobody knows what an AI agent will look like in three years.

One thing, however, does not change: your data remains your data. Your sales, your margins, your purchase prices, your customer files are the company's assets. Whatever technology comes along to exploit them tomorrow, the question of who accesses them, within what limits and under what control will stay exactly the same.

That is why a sound AI strategy is not built on a choice of tool, but on a choice of governance. The tool you may well change. The framework protects you for the long run. A business that has set good rules for how its data moves and is controlled will be able to adopt any future innovation without rebuilding everything. The one that rushed at a tool with no framework will have to backtrack at the first incident.

Setting your governance on a one- to three-year horizon therefore gives you a stable base while the technology keeps moving. Concretely, that governance rests on three principles.

First principle: a one-way data flow

The first fear of a food business leader, when you talk about connecting AI to their information system, is almost always the same: "is this going to touch my ERP?"

It is a legitimate fear. The ERP is the beating heart of the business. It holds the accounts, the stock, the orders, the production. One bad write, one uncontrolled change, and the whole operation wobbles. Handing the keys to that system to an automated piece of software would be irresponsible.

The answer lies in a simple, verifiable architectural principle: the data flow must be strictly one-way. Information travels from the ERP to the analysis tool, never the other way round. The AI reads, it observes, it analyses. It writes nothing, changes nothing, deletes nothing in the source system.

That rule is not a sales promise you are asked to take on trust. It is a technical decision that can be checked. An ERP properly integrated with an analysis tool grants that tool read access only. The AI works on a copy of the data, in its own environment, and the company's management system stays untouched. In case of doubt, of a bug, of unexpected behaviour, the ERP is at no risk: it was never exposed to a single write.

For a business leader, that changes everything. It becomes possible to draw on the richness of your data without ever putting at stake the integrity of the system that runs the company day to day.

Second principle: data boundaries that you choose

Connecting AI to your business should never mean giving it vague access to all of your information. Yet that is too often what happens: a tool asks for broad access, the user accepts without gauging what they are sharing, and nobody knows where the boundary runs any more.

Good governance imposes the opposite: explicit, delimited data perimeters, chosen by the company itself. You decide precisely what the AI has the right to see.

That sharing is structured around clearly identified blocks of data: customer data, orders and sales, products and prices, purchasing. Each block is distinct. A business that wants its raw material purchasing analysed but its customer files kept out of scope can do exactly that. Sharing is not a single switch you turn on or off. It is a set of choices, and they stay yours.

This principle has a virtue that goes beyond mere security: it makes the relationship legible. At any moment, you know exactly which categories of information are being used, and which are not. That clarity is precisely what the General Data Protection Regulation expects of responsible processing: a defined purpose, a controlled perimeter, no collection beyond what is necessary. Compliance then stops being a box ticked after the fact. It follows naturally from the way the tool is built.

Third principle: autonomy that answers to your instructions

This is probably the most misunderstood point about agentic AI, and yet the most important. An intelligent agent can go a very long way. It can monitor dozens of indicators continuously, cross-reference sources of information, produce analysis day after day without being asked again. That capability is real, and it is the whole point of the technology.

But autonomy does not mean freedom. The real governance question is not "how far can the agent go?", but "who decides how far it goes?". And the answer must always be: the human.

That is the principle we have anchored in the design of our agents. They are not configured to take initiatives. They are configured to answer instructions. The distinction is crucial, and it comes down to this:

An agent that takes initiativesAn agent that answers instructions
Decides on its own what deserves its attentionActs within the framework you have set
Extends its scope without consulting youStays strictly within its scope
Asks you to take back controlLeaves you in control by default

A concrete example. You ask Sophie, our financial analysis agent, once, to alert you as soon as a purchase price moves further than a given threshold from the market price. She will do it, every day, for months, without you having to remind her. That is useful autonomy: an instruction set once, carried out faithfully over time. But Sophie will never decide by herself to widen her scope, to renegotiate with a supplier, or to place an order. Those decisions remain yours. The agent sheds light, it alerts, it prepares the ground. It never stands in for the company's decision.

This architecture answers directly to the debate running through the whole AI sector today: as agents become more capable, the question of what they may act on alone, and what must go back through a human, becomes central. It is also what fundamentally separates an AI agent from a simple generative tool — a difference we set out in Generative AI vs AI agents: what is the difference for a food industry SME leader?. In a sector like the food industry, subject to strong traceability and compliance requirements, that boundary is not a luxury. It is a condition of trust.

Governance as an advantage, not a brake

It would be tempting to see all of this as a series of guardrails, limits and precautions that would hold back the power of the tool. The opposite is true.

A business that knows exactly what its AI sees, what it can do and within what framework it operates is a business that can entrust it with more and more important tasks in complete confidence. Trust is not the enemy of ambition: it is its condition. You only truly delegate what you have a grip on.

It is also what the most advanced companies on the subject are finding. Everywhere, AI deployment stumbles less on the capabilities of the models than on organisations' capacity to trust them. Those that have set a clear framework move fast. Those that rushed in without one retreat at the first incident. Governance is not what slows down AI adoption. It is what makes it possible.

Key takeaway

the right question this September is not "which AI tool should we choose?" but "what policy do we want for our data and for the decisions that come out of it?". A controlled, one-way data flow, access perimeters that you choose, autonomy that stays under your command: these three principles depend on no particular technology and will hold whatever progress comes. That is precisely what makes them a foundation rather than a fashion.

Building on foundations that last

As you define your roadmap for the coming years, remember that the foundation matters more than the tool. Technologies will change; the framework you set today will go on protecting you.

At Agrolytics, we built our agents on these three principles because we are convinced that AI is only worth something, in the food industry, if the company keeps its hand on the wheel from start to finish. The one-way data flow, the perimeters you choose, autonomy under instruction: these are not options, they are foundations.

Want to see how an AI agent fits into your existing management, within a framework you control end to end? Book an Agrolytics demo — in 30 minutes, we look together at what your data can produce, and under what rules.

Ready to take control of your data?

Book a 30-minute demo and see what Agrolytics can do for you.

Book a demo