Skip to content

AI

Closing the Trust Gap: The AI Data Problem Nobody Budgeted For

September 3, 2026
Jen NewmanDIrector of Global Alliances

Across AI teams, a familiar pattern is emerging. There's the initial excitement as Copilot or Gemini rolls out, another productivity win added to the roadmap. Then comes the realization: organizations aren't prepared to trust what AI does with their data.

The trust gap is the distance between AI adoption and the governance, protection, and visibility required to use AI safely at scale. Get it wrong, and the costs are specific: storage costs, which were already spiking, continue to spiral as AI produces data at a rate nobody priced for, sensitive content surfaces where it was never meant to be seen, and ransomware finds a larger target because everything's been consolidated to make AI work better.

In AvePoint's 2026 State of AI report with Osterman Research, 89.5% of organizations had at least one GenAI-related security breach in 2026, up from 75.1% just a year earlier, and 86.9% delayed AI deployment by roughly six months over data security concerns.

That’s what it looks like when governance is built after the fact, and now we see what it costs.

The hidden cost of moving fast

At first, the rollout looks straightforward. A pilot team starts using AI tools, and productivity increases immediately. Other consequences surface quickly, too.

Copilot produces a document that should have been deleted years ago. Gemini pulls a stale file out of a Google Drive folder nobody's opened in three years. A retention policy that worked fine for a human reviewer turns out to mean something different when an AI agent is the one reading it. Then the CIO notices the cloud storage bill climbing. It wasn’t a big deal a couple of years ago, and yet we’re suddenly growing at multiple TB per month. Most hyperscale cloud storage providers charge for egress, moving data off the platform, and for every API call made against it. A person querying an archive might do that a few times a week. An AI assistant does it constantly, and the ever-growing bill reflects the difference.

The redundant, obsolete, and trivial content sitting in most organizations was a slow-moving problem as long as nobody was actively engaging with it. AI changes the risk profile because it can access, analyze, summarize, and surface content at a scale no human reviewer ever could, regardless of whether that content should have been cleaned up years ago.

AI isn't the only source of pressure here, either. Regulators and cyber insurers are asking their own version of the same question: can this organization prove its data is governed, and prove that recovery works when it's tested, not just assumed. That kind of proof takes documented and implemented process, not intent. An AI rollout without it becomes a compliance and cyber-insurance risk that is likely to emerge when organizations are least prepared.

And visibility is getting worse, not better. The share of organizations that can't tell whether employees are using unsanctioned AI tools nearly tripled year over year, from 6.3% to 17.6%, according to the State of AI report.

What half-measures miss

Even organizations that recognize the problem often reach for a fix that only addresses part of it.

Some tools clean up and classify data well but don't protect it once it's consolidated. That's real progress right up until a ransomware event or one misconfigured automation rule hits everything at once, because all that carefully organized data is now sitting in a single place with no protection behind it. Others back up data reliably but do nothing to reduce the redundant, ungoverned content driving up cost and risk in the first place, so the backup job gets bigger and more expensive every quarter.

Legacy retention policies add another layer to the problem. They were built around the assumption that a person would eventually review what's being kept and decide whether it should stay. AI doesn't wait for that review. It works with whatever exists in the environment right now, because nothing in the policy tells it otherwise.

Storage pricing has the same blind spot. It was built around egress and per-query fees that made sense when retrieval was occasional. AI made retrieval constant, and fees that might have been negligible now scale with every query.

What closing the trust gap requires

The challenge isn't just reducing risk or lowering costs. To support AI at scale, organizations need governance, protection, and sustainable storage working together as a single foundation.

Organizations that get AI right build toward the same short list of outcomes:

  • Full visibility into what data exists and what can reach it

  • Governance that runs on its own, not another manual cleanup project six months from now

  • Backup that's immutable and ransomware-resilient for whatever gets consolidated along the way

  • Storage and backup economics that are predictable and egress-free, scaling with retrieval instead of punishing an organization for it

Put together, that's a trust layer, a foundation the rest of AI adoption gets to stand on.

A practical path forward

Closing the trust gap takes a sequence of steps, and getting the tools right matters as much as the order.

  1. Assess your current data estate. Inventory what's redundant, obsolete, or trivial, and identify the sensitive content an AI assistant might surface that it shouldn't. This has to cover every platform in play. An organization running both Microsoft 365 and Google Workspace needs the inventory to include both, not whichever one rolled out first.

  2. Choose an AI-ready governance and backup partner. Picking a tool that only cleans up data or only backs it up leaves the other half of the trust gap wide open.

  3. Redesign your architecture. Don't just clean up once. A one-time purge feels like progress, but the data estate refills quickly. Combine automated and ongoing lifecycle policies with immutable backup and recovery testing, so the cleanup doesn't need to happen again next year. Mainly because it’s happening according to your defined schedules.

  4. Configure your storage layer for AI-scale retrieval. Look for a storage provider that connects via S3-compatible APIs, so it can slot into governance and backup tools without a custom integration, and that doesn't charge for egress or per-API-call retrieval.

  5. Validate before you scale AI further. Test restores. Confirm governance policies are actually being enforced, not just configured. Re-assess as new AI tools get added. Validation isn't a final step so much as a habit that repeats every time the environment changes.

AvePoint and Wasabi cover that sequence end-to-end: AvePoint Opus for governance, AvePoint Cloud Backup for protection, and Wasabi as the storage layer underneath both.

The economics that make it sustainable

There's one more piece of the trust gap that's easy to overlook until the invoice arrives. Storage pricing built for cold, untouched archives doesn't hold up once AI is the one doing the retrieving.

Wasabi removes the fees driving those costs. There's no egress fee and no per-API-call retrieval charge, so storage cost stays flat no matter how often an archive is queried. Retrieval, the thing AI does constantly, stops being billable.

The savings compound through the same sequence used to close the trust gap. Governance reduces what's being stored and retrieved in the first place, since AvePoint Opus removes redundant and obsolete content instead of archiving it indefinitely. Wasabi keeps what's left affordable to query, at any frequency. The same flat-rate model applied to AvePoint Cloud Backup makes recovery testing affordable to run regularly, instead of something a budget can only justify once a year.

AvePoint and Wasabi's joint customers have seen storage costs drop by more than half after removing redundant content and archiving what remains to Wasabi, with the same savings recurring on the backup side.

The clock is running

Your AI rollout is more than a productivity project. It's the point where your data strategy either closes the trust gap or gets left behind by it.

The work doesn't get easier by waiting. Every month of delay is a month more content accumulates, more access goes ungoverned, and more of what's stored is AI-generated rather than reviewed. That share is already more than a third of enterprise data, according to the 2026 State of AI report, headed to 42% within the year.

The organizations closing the trust gap now are treating governance, storage, and protection as one decision, made together, before the next AI tool gets added.

Explore how AvePoint and Wasabi together can help you build the trust layer your AI strategy depends on:

https://wasabi.com/partner/integrations/avepoint

Or connect with a Wasabi expert to map out your AI-readiness strategy:

https://wasabi.com/contact-us/

The trust gap is the distance between how fast organizations deploy AI tools like Copilot and Gemini and how well they've governed the data those tools can access. It shows up as spiking storage costs, sensitive content getting surfaced, and larger ransomware exposure once data is consolidated for AI use.

AI tools can surface content that users already have permission to access, including outdated, duplicated, or forgotten information. Without governance controls, that content can appear in AI-generated responses even when it no longer provides business value.

Most cloud storage pricing charges for egress and per-API-call retrieval, fees that stayed negligible when data sat untouched for years. AI queries data constantly rather than occasionally, so the same pricing model that once rounded to nothing starts scaling with every query an AI system makes.

Yes. Both AvePoint Opus and AvePoint Cloud Backup support Wasabi as an S3-compatible storage target now, with no proprietary connector or separate contract required. Archiving policies and backup jobs can point at a Wasabi bucket the same week governance rules go live.

Some tools clean up and classify data but don't protect it once consolidated, leaving a single, well-organized target exposed. Others back up data reliably but don't reduce the redundant content driving up cost and risk, so the backup job grows more expensive every quarter without addressing the underlying problem.

AvePoint and Wasabi's joint customers have seen storage costs drop by more than half after removing redundant content and archiving what remains to Wasabi, with equivalent savings recurring on the backup side due to Wasabi's egress-free pricing model.

Related article

global digital network
INDUSTRYThe four dimensions of data sovereignty: A practical framework

Most Recent

The four dimensions of data sovereignty: A practical framework

Some teams check one box on data sovereignty and call it done. Wasabi’s Kevin Dunn breaks down IDC’s four dimensions of data sovereignty, the two that get missed, and three questions to test your own posture.

The independence advantage: Why truly resilient backup shouldn’t depend on one vendor

Four myths justify single-vendor backup storage. None hold up in a real incident. See what independent storage like Wasabi actually delivers.

Why data sovereignty became a boardroom priority

Data sovereignty has moved from the legal team to the board. Wasabi’s Kevin Dunn on what changed, what research shows, and the one variable organizations can control.

SUBSCRIBE

Storage Insights from the Storage Experts

Storage insights sent direct to your inbox.

Subscribe