The AIIM Blog - Overcoming Information Chaos

We Can't Predict AI's Capabilities. We Can Govern Access and Oversight.

Written by Tori Miller Liu, CIP | Sep 17, 2026, 11:00:00 AM

Information professionals don't make judgments about the value of data. We make judgments about the tools used to manage information, what information can be used for, and who should have access. Those judgments rest on laws, standards, and policies, not on gut instinct. That's the job of information professionals. It was our job before generative AI and still the job now that a growing share of the current conversation about AI safety is really a conversation about access and oversight. 

What are the concerns about AI risk? 

 Anthropic's Dario Amodei has warned that a swarm of AI agents could be able to take over large parts of the internet within 6 to 12 months, causing hundreds of billions of dollars in damage. His colleague Evan Hubinger wrote on X that AI could cause human extinction above 10 percent within the next decade. The Guardian recently rounded up six competing expert takes on how seriously to take these warnings, and it's worth reading for the full range of opinion.

As you can see, there are lots of valid opinions on AI risk being written about in traditional media and social media right now, but it's important that we not treat AI as some sort of independent, unitary actor. It's not a boogeyman and there is not one specific risk. When we talk about AI risk, there are multiple risk pathways:

  • Deliberate misuse
  • Accidental failure

  • Systemic degradation

  • Loss of control from highly capable AI

My sense is that the prevalent fear or concern right now is that humans lose control of highly capable AI, which could pose a real risk to humanity.

What is the recipe for disaster?

As a Certified Information Professional, I wanted to understand how we can prevent an AI system from operating outside meaningful human direction with no clear way to regain control.

Loss of control doesn't just happen. There is always a recipe for disaster (just as there is a recipe for success).

Based on my research and AIIM's body of knowledge, loss of control is caused by the deadly combination of advanced capability, autonomy, real-world access, and poor oversight. 

A capable AI model with limited access poses a different risk than an autonomous agent that has the power to access data, execute processes, move funds, or write code. It is the combination of conditions that create the risk of rogue capable AI. Put more simply, unsafe power plus weak control puts humanity at risk. 

Moving past assessing capability

Capability is the one variable information professionals have almost no control over. We don't train the models, and we're not the ones deciding when a frontier lab sends a new release to production. 

Our purview is access and oversight. We also can influence or determine the autonomy AI is granted in a given deployment. Governance and information professionals determine who gets to connect a model to a database, a payment system, a set of employee records. They decide who reviews output and can prove that review happened.

Strip away the argument over whether a given model is capable of something dangerous, and three questions remain:

  1. Has this system been given the access to take action? 

  2. What level of autonomy has been granted to this system?
  3. Is anyone watching when the system acts?

With access control, autonomy determination, and oversight, even a highly capable model poses less risk. The good news is that these are governance decisions and practices that have been in play for decades.

Why investing in governance is the smart move

None of us knows what AI capability will look like five years from now, let alone twenty. That uncertainty is exactly why the smart move is to invest in governance now, rather than wait for clarity that may not come. Access controls, audit trails, and human review requirements don't depend on how capable the underlying model is. They travel with the tool regardless of what it can do.

Governance isn't only about compliance and risk prevention. Employee productivity, customer service, and AI success all depend on it too, because every one of those processes fails when it's running on data that isn't accurate, relevant, or current.

At an enterprise level, here are the three types of governance worth investing in right now, regardless of where you are on your AI journey. ​

  • Information and data management is how information is created, stored, moved, and disposed of. It's the foundational discipline, and it predates AI by decades.​

  • Information and data governance is the rules, policies, and controls that make that work compliant and defensible. It's the framework.​

  • AI governance controls for how AI systems specifically use that information, covering risk, fairness, explainability, and accountability for what the system itself decided or produced. 

This is the work information professionals have been doing for decades. We don't need to invent new practices. They already exist. What's changed is the object we're applying them to.

CIPs Already Rate AI Access Control and Oversight as Critical

Our recent survey of Certified Information Professionals bears that out. We asked what would happen if a CIP performed specific tasks poorly, or not at all, and rated the consequences. Recognizing when human review of AI output is required came back with the highest score of any AI-specific task in the entire survey. Fifty-seven percent of respondents rated it Critical or Catastrophic, ahead of legal holds at 32 percent, retention and disposition scheduling at 39 percent, and distinguishing records from non-records at 25 percent, tasks that have anchored this profession for decades.

Identifying data exposure risks in prompts and AI-generated outputs wasn't far behind, at 54.5 percent. Applying consent management and privacy impact assessments to AI data use came in at 44.4 percent, and detecting and mitigating bias in AI data practices landed at 37.8 percent.

None of these tasks existed in any earlier version of the CIP body of knowledge. CIPs are already treating them with the same weight they give the fundamentals of records management, right now, not as some future skill set they'll need eventually.

What I Can Actually Control

As a CEO, a parent, and a member of society, it's easy to worry about the current debate over AI's threat to humanity. I don't dismiss the importance of that debate, but I'm a pragmatist. I know what's in my control, both as a leader and as a CIP. I can't control AI capability, but at an enterprise level, I can determine what AI has access to, what level of autonomy we're comfortable with, and how we conduct oversight. I can also decide which AI tools we use.

I don't believe access control, autonomy determination, and oversight alone can prevent AI risk. Enterprise governance isn't a substitute for the regulations and frameworks needed to ensure AI safety and ethics at a societal level. We need governments to step up and create unified regulations and frameworks. Regulatory steps taken in California and Singapore appear to be headed in the right direction. 

Get Certified

There are a lot of unknowns ahead. But I do know that information professionals play a key role in responsible AI use. So if you're in a leadership position, make sure you have a qualified CIP on your team. And if you're an information professional, explore earning the CIP so your experience and what you contribute get recognized for what they are.

We are in the process of updating the CIP exam now (I'll write more about that later). You can now apply to take the current version of the CIP exam for just $350, using code CIPFALL2027 at checkout. You will be able to sit for the current exam through April 1, 2027. Learn more.