This interview analysis is sponsored by Securiti and was written, edited, and published in alignment with our Emerj sponsored content guidelines. Learn more about our thought leadership and content creation services on our Emerj Media Services page.
The promise of enterprise AI meets a reality where models and agents can access sensitive data faster than organizations can see, govern, or explain that access — a gap that leaves leaders unable to prove compliance, contain exposure, or defend how AI is using their data.
Stanford HAI reports 88% of organizations now use AI in a business function, while documented AI incidents jumped to 362 in 2025, up from 233 the year before. The GAO found that AI use in financial services introduces data quality, privacy, and cybersecurity risks regulators are actively examining.
The Cloud Security Alliance reports that only 35% of organizations have full visibility into where unstructured data resides. Just 9% have real‑time scanning capabilities, and 23% cannot scan unstructured data for risks at all — structural limits that constrain what any AI system can do well.
Emerj’s Yolandi de Weerdt recently hosted a conversation with Chris Joynt, Director of Product Marketing at Securiti; James Dean, AI Specialist at Google Cloud; Mark Crean, Regional Vice President of Sales at Securiti; Dr. Oscar Rodriguez, Vice President, Data Analytics at Citi; and Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team.
This article outlines four insights that define the core data, governance, and security requirements for safe and scalable AI in financial services:
- Real‑time mapping of sensitive data flows for pre‑ingestion control: Stops ungoverned unstructured data from entering AI systems by revealing where sensitive information lives and moves.
- Unified governance for AI‑ready data across teams: Ensures models and agents only operate on compliant, authorized information so financial AI can scale beyond isolated pilots.
- Pre‑development accountability frameworks for AI decision‑making: Establishing ownership before models are built prevents governance failures that stall deployment as systems move toward production.
- Data‑level security controls for AI ingestion and retrieval: Restrict and sanitize sensitive data at the source so AI systems access only authorized information and breaches can be contained instantly.
Real‑Time Mapping of Sensitive Data Flows for Pre‑Ingestion Control
Episode 1: Why Granular Visibility and Data Control Determines AI Success in Financial Services – with Chris Joynt of Securiti
Guest: Chris Joynt, Director of Product Marketing at Securiti AI
Expertise: AI Security, AI Trust, Product Marketing, Go-to-Market Strategy
Brief Recognition: Chris Joynt is Director of Product Marketing for AI Security at Securiti. Previously, he led product marketing for Cloudera’s Data in Motion portfolio, held multiple AI and IoT leadership roles at PTC, and began his career in advanced analytics at IBM. He holds a bachelor’s degree in Business Administration with concentrations in Marketing and Finance from Temple University.
Chris Joynt describes data estates where unstructured content has grown beyond what traditional governance practices can inspect. He points to customers operating across more than 200,000 data systems, generating billions of files and producing a petabyte of logs per day. At that scale, even determining what sensitive information exists in those files becomes a structural challenge — and that challenge appears before any model is built or evaluated.
Joynt’s central point is that once unstructured data is ingested, transformed, or vectorized, organizations lose meaningful visibility into how it is being used. The original form becomes obscured, derivative copies proliferate, and governance teams cannot reliably trace how sensitive information reached an AI system.
Pre‑ingestion visibility becomes the only place where control can be exerted:
“Unstructured data became gold overnight. Institutions generate enormous volumes of it — logs alone can reach a petabyte a day. You can’t throw that into AI and hope the model figures it out. You need to know what’s in those files, how sensitive they are, and where they’re moving. Once the data is inside the model, you’ve lost control of it. Visibility into the flows is the first layer of safety.”
— Chris Joynt, Director of Product Marketing at Securiti
AI activity may already be occurring outside formal oversight, according to Chris. Shadow AI becomes possible when teams lack discovery into where data is going or which systems are processing it. Mapping flows is the first step toward understanding how content moves, how it is transformed, and where sensitive information may already be exposed.
His practical guidance for C‑suite leaders forms a clear pre‑ingestion framework:
- Map sensitive data flows — Establish factual visibility into where unstructured content resides and how it moves across systems.
- Classify and label unstructured content — Identify PII, transactional records, regulated content, and business‑confidential information before AI systems ingest it.
- Define AI access boundaries — Specify which models, agents, and retrieval pipelines can access particular categories of sensitive data.
- Monitor transformations and derivative paths — Track how content is merged, vectorized, or copied so governance teams can see where exposure originates.
- Detect shadow AI — Surface AI systems already processing sensitive information outside formal governance.
Joynt’s takeaway is structural: pre‑ingestion visibility is the foundation of AI governance. Once sensitive data enters a model, its transformations and derivatives become difficult to track, and control becomes reactive rather than preventative. Mapping flows, classifying content, and defining boundaries upstream gives leaders the factual baseline required to govern AI safely at scale.
Unified Governance for AI‑Ready Data Across Security, Data, and Business Teams
Episode 2: Why Financial AI Can’t Scale Without Unified Governance with James Dean of Google and Mark Crean of Securiti
Guest: James Dean, AI Specialist at Google Cloud
Expertise: Generative AI, Enterprise AI Strategy, Go-to-Market Strategy, AI Sales
Brief Recognition: James Dean is a Generative AI Specialist at Google Cloud, where he has also led global AI go-to-market strategy and advised enterprise leaders on AI adoption. Previously, he held AI and enterprise sales leadership roles at H2O.ai, SAP, and WealthEngine. He holds an MBA in International Business from Pepperdine Graziadio Business School and a bachelor’s degree in Finance from Northeastern University.
Guest: Mark Crean, Regional Vice President of Sales at Securiti AI
Expertise: AI Security, Data Security, Identity & Access Management, Enterprise Sales
Brief Recognition: Mark Crean is Regional Vice President of Sales at Securiti AI, where he leads strategic enterprise sales across the Americas. Previously, he held sales leadership roles at Ping Identity, ForgeRock, and Oracle, specializing in identity, cloud, and data security solutions. He holds a bachelor’s degree in Marketing and Management from the University of Delaware.
Scaling AI in financial services stalls when security, data, and business teams operate from different definitions of AI‑ready data. Mark Crean and James Dean both point to this fragmentation as the reason pilots remain trapped in innovation labs while high‑value use cases struggle to reach production. Productivity tools and coding assistants move quickly; enterprise‑level AI does not — because governance is not unified.
James Dean underscores the operational gap: post‑POC deployments fail when institutions cannot secure petabytes of sensitive data or reconcile siloed datasets. Half of banks, by his estimate, still have data locked in isolated systems, preventing models and agents from accessing compliant, authorized information. Crean adds that even when AI proliferates internally, organizations lack shared guardrails for access, context, and rollback — leaving teams unsure how to adopt AI safely at scale.
Their combined framing is clear: AI governance becomes scalable only when security, data, and business teams align on a single definition of AI‑ready data and enforce it consistently across the enterprise.
“Aligning stakeholders is always step one. As models and agents proliferate, what guardrails and controls are you putting in place to ensure users can safely adopt these tools? What data security practices ensure the data integrity can be trusted?”
— Mark Crean, Regional Vice President of Sales at Securiti
“It starts by aligning the CISO, data scientists, and business leaders on a shared definition of AI‑ready data. From there, they map governance to every phase and automate data classification before training or cloud migration.”
— James Dean, AI Specialist at Google Cloud
Their guidance forms a unified governance mechanism that C‑suite leaders can operationalize:
- Define AI‑ready data across functions — Establish a shared definition used by security, data, and business teams to determine what information models and agents are permitted to access.
- Automate classification before training — Use NLP‑driven scanning to tag hidden PII, KYC, and regulated content so restricted information never enters training pipelines.
- Embed access controls into model operations — Enforce strict authorization boundaries and auditability directly within model workflows, not as an external afterthought.
- Establish guardrails for agent adoption — Define context requirements, error‑handling expectations, and rollback mechanisms so agents operate safely as they proliferate across the enterprise.
- Integrate governance with compliance readiness — Align governance practices with emerging state‑level and global regulations to ensure models and agents operate within approved boundaries.
The structural result is models and agents only operate on compliant, authorized information, enabling financial institutions to move beyond isolated pilots and into enterprise‑scale AI deployment without compromising security, compliance, or data integrity.
Pre‑Development Accountability Frameworks for AI Decision‑Making
Episode 3: How Financial Services Leaders Operationalize Safe AI – with Dr. Oscar A. Rodriguez of Citi
Guest: Dr. Oscar A. Rodriguez, Vice President, Data Analytics at Citi
Expertise: Data Analytics, Enterprise Data Strategy, Business Intelligence, AI Governance
Brief Recognition: Dr. Oscar A. Rodriguez is Vice President of Data Analytics at Citi, where he leads enterprise data and analytics initiatives for the financial services sector. Previously, he held data leadership roles at Liberty Mutual Insurance, Blockchain Strategy Group, and FCCI Insurance Group. He holds a doctorate in Strategic Business Leadership from Regent University and a master’s degree in Management Information Systems from Florida State University.
AI projects inside financial institutions often collapse at the exact moment they should scale. Dr. Oscar Rodriguez points to a simple cause: teams build before they decide who owns the outcomes. When accountability is undefined, governance becomes a scramble, and the scramble begins only after the model already exists, when it is too late to shape its assumptions, its data, or its risk posture.
Rodriguez sees this repeatedly. Business units race to experiment. Data teams work from disconnected sources. Security and compliance arrive after the fact. Leadership focuses on future risk while teams focus on proving value. The result is not technical failure but organizational misalignment. Models demonstrate promise in early testing, then stall under scrutiny because no one agreed on standards, ownership, or governance before development began.
A pre‑development accountability framework prevents that stall. It forces clarity before code, ownership before modeling, and governance before enthusiasm.
Rodriguez’s guidance is practical:
- Define who owns model decisions — Identify the accountable party for outcomes, failures, and escalations before any model is built.
- Align teams on shared standards — Prevent duplicate efforts by agreeing on data quality, risk tolerance, compliance requirements, and success metrics upfront.
- Embed governance into design — Treat governance as part of the build process, not a late‑stage add‑on.
- Document accountability pathways — Make responsibility explicit: who approves, who monitors, who intervenes, and who carries consequences.
- Plan for regulatory change — Build structures that can adjust as regulations evolve rather than retrofitting compliance after deployment.
Rodriguez’s emphasis is that accountability is not a compliance requirement — it is the foundation that determines whether a model can survive the journey from proof of concept to production. When ownership is defined early, governance becomes structural rather than reactive, and AI systems can move toward production without collapsing under regulatory or operational pressure.
“Teams experiment independently. They want to get there first. Leadership is focused on different things. You end up with duplicate efforts, inconsistent standards, and competing priorities. Governance gets introduced after the model is already built, and that’s a formula for disaster.”
— Dr. Oscar Rodriguez, Vice President, Data Analytics at Citi
Data‑Level Security Controls for AI Ingestion and Retrieval
Episode 4: Preparing Enterprise Data for Safe AI Deployment – with Todd Vancil of Securiti AI
Guest: Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team
Expertise: AI Security, Data Security & Privacy, Sales Engineering, Go-to-Market Strategy
Brief Recognition: Todd Vancil is VP of Veeam’s Securiti AI Sales Engineering Team, where he leads global presales and enablement efforts focused on helping enterprises securely adopt AI and data-driven technologies. Previously, he held senior leadership roles at Fortinet, Amplitude, and Conga, leading sales engineering, presales, and go-to-market organizations. He earned a bachelor’s degree in Management from the University of Tampa.
“Walk into the library, scan and classify every book, understand who has access, how it got there, where it moved. Label the book so ingestion policies respect it. That’s how you keep sensitive data out of the wrong LLM, and how you contain exposure when something goes wrong.”
— Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team.
Todd Vancil’s metaphor is simple, but the operational reality behind it is not. As enterprises move workloads into cloud platforms, SaaS environments, data lakes, and shared systems, sensitive information sprawls across locations that perimeter controls can no longer meaningfully protect. AI systems ingest and retrieve content at machine speed, and the traditional model of securing networks, endpoints, or access pathways cannot keep pace. The only control point that scales with AI is the data itself.
Vancil argues that security must shift from guarding the doors to governing the contents. If sensitive data is not classified, labeled, and restricted at the source, AI ingestion pipelines will absorb information they should never see, retrieval workflows will surface content they should never access, and breaches will propagate faster than any human response. Data‑level controls become the mechanism that determines what AI can read, what it can retrieve, and what it must never touch.
Leaders who adopt this posture start upstream, long before prompts, agents, or retrieval workflows come into play:
- Scan and classify sensitive data at scale — Treat the enterprise as a distributed library and read every file, dataset, and document to determine sensitivity, lineage, and access.
- Label unstructured content before ingestion — Apply sensitivity labels to PDFs, text files, presentations, and other unstructured sources so LLMs and agents cannot train on or read restricted information.
- Enforce ingestion policies at the data layer — Ensure training pipelines respect labels and redactions rather than relying on model‑level controls.
- Secure retrieval‑augmented generation — Restrict what agents can retrieve, how context is filtered, and which systems can be queried.
- Use data‑level visibility for instant containment — When exposure occurs, classification and lineage make it possible to determine what moved, who accessed it, and where containment must be applied immediately.
- Eliminate redundant, obsolete, and trivial data — Remove stale content that creates legal exposure, storage cost, and unnecessary risk — and keep it out of AI systems entirely.
The shift Vancil describes is not cosmetic. It is a redefinition of the security control plane. AI systems cannot be expected to interpret enterprise policies or navigate legacy access structures at the velocity they operate. Security must be embedded in the data itself — classified, labeled, and governed at the source — so ingestion and retrieval workflows operate only on authorized information, and breaches can be contained the moment they occur.


















