Is your data really ready for AI agents?

Having data is not enough. For AI agents to use it safely, it must be accessible, authorized, contextualized and actionable.

Your company probably already has plenty of data.

Customers in the CRM. Orders and pricing in the ERP. Requests in email. Procedures in documents. Service history in another system. Numbers in spreadsheets.

That does not mean an AI agent can use those data correctly.

When AI only answers a question, bad information may lead to a bad answer. When an agent can then update a record, respond to a customer, create an order or trigger an operation, the issue becomes much more important.

> Data is not ready for an agent simply because it exists. It must be available, accessible, authorized, contextualized and actionable.

Those are five different conditions.

The problem starts before AI

Before asking whether AI can use company data, the organization first needs to know where those data live and what they contain.

In practice, sensitive or useful information may be scattered across structured databases, shared folders, email, digital conversations, file repositories and other systems.

In its 2026 work on data classification practices, NIST emphasizes the need to discover, identify and classify data — including sensitive unstructured data — so organizations understand what they hold and can better control how it is used.

For an AI agent, that becomes step one.

An agent cannot reliably use information the organization itself cannot identify.

An agent rarely works from a single source

Consider a simple request:

“My part is defective. Is it still under warranty, and can you send someone?”

To handle it, an agent may need to consult the CRM, the ERP, service history, warranty documentation and the current email.

The challenge is not simply having data.

It is assembling the right information for this specific request.

NIST made this a specific issue in 2026 in its work on software-agent identity and authorization: agents may need access to multiple datasets, tools and applications, which creates corresponding requirements for identification, authorization and auditability.

This is where “AI-ready data” takes on a broader meaning.

Five states of genuinely usable data

1. Available

The data exists, and the organization knows it exists.

It may be structured in an ERP or buried in a PDF attached to an email three years ago.

Before talking about AI, the company needs to know what information exists, where it resides and which data is sensitive.

2. Accessible

The agent can reach the required source.

A dataset may be clean, accurate and well classified while still being locked inside a system the agent cannot access.

The organization must distinguish:

“We have this information”

from:

“The system performing this task can retrieve it when needed.”

Technical connectivity matters. But connectivity alone is not enough.

3. Authorized

The agent has the right to access this information for this task.

This becomes critical as AI moves from isolated tools to agents connected to enterprise systems.

NIST’s 2026 work on agents focuses directly on this issue: how to identify the agent, determine what it is authorized to do, and preserve enough evidence to reconstruct its actions.

A scheduling agent may need a customer’s name, phone number and availability.

That does not mean it should see the customer’s credit history.

Connecting an agent to a system is not the same as giving it free rein over that system.

4. Contextualized

The data also needs to mean the right thing in the current situation.

A value of $2,500 is not enough information by itself.

Is it an account balance? A credit limit? A quote? A part price? A manager’s approval threshold?

European regulation also reflects the importance of context. For high-risk AI systems subject to Article 10 of the AI Act, data-governance practices must consider factors such as origin, preparation, availability, suitability and the specific context in which the system is intended to operate. Those legal requirements have a defined scope and do not automatically apply to every enterprise agent, but they illustrate a useful principle: data quality depends partly on the purpose for which the data will be used.

An agent must therefore understand more than a value.

It must understand what that value means in this process.

5. Actionable

This is the final boundary.

The information is available. The agent can reach it. It is authorized to view it. It understands the context.

What can it now do with that information?

An agent may be allowed to see a customer’s credit limit without being allowed to change it.

It may determine that a product appears to be under warranty without being allowed to approve a $15,000 replacement.

It may prepare an action and still need an authorized person to approve it.

OpenID Foundation’s AuthZEN work illustrates this distinction. An action may remain unauthorized because a required condition is missing: approval, consent, delegated authority, justification or risk evaluation. Policy still determines whether the action may proceed.

!The five states of data ready for an AI agent: available, accessible, authorized, contextualized and actionable.

Data becomes truly usable by an agent when it can be found, accessed with the right permissions, understood in context and used for an authorized action.

Data access and authority to act are different decisions

This distinction is easy to miss.

To make an agent more useful, it can be tempting to open more systems and more data to it.

But more access does not automatically create a better agent.

It mostly creates an agent that can see more things.

The next question is which things it should see — and what it should be allowed to do with them.

This is why data architecture and agent governance eventually converge.

The organization increasingly needs to reason in context:

Which agent? For what objective? On whose behalf? Which data? Which operation? Under what authority?

When those answers change, access and permitted actions should be able to change with them.

You do not need to make every dataset “AI-ready”

There is an opposite trap: believing the company must clean, centralize and rebuild its entire data architecture before it can start.

Not necessarily.

A specific process can be a better starting point.

Take a service request. Identify the five or six pieces of information needed to handle it. Determine where they live. Decide which ones the agent may access. Define permissions. Clarify which actions the agent may take and which require approval.

Then repeat with the next process.

This avoids turning “prepare our data for AI” into a five-year transformation program that eventually forgets why it started.

The real question is no longer “do we have the data?”

For years, AI readiness was often framed as a question of data volume or quality.

With agents, that definition is incomplete.

An organization may have excellent data and still be poorly prepared if it cannot determine who may use those data, in what context and with what authority.

The better leadership question becomes:

“Can we give an agent exactly the information it needs to complete a specific task — without giving it access or authority beyond that task?”

That is a data question.

It is also an identity, permission, process and governance question.

Once AI begins to act, those subjects can no longer be managed separately.

Main sources