Key Takeaways
- Jean-Denis Grèze predicts that within five years, individuals and enterprises will trust AI agents to decide what data to share autonomously without human intervention.
- Traditional enterprise data governance relies on slow, expensive manual data labeling and static role-based access policies that lock vital context inside individual inboxes.
- Post-trained language models can serve as context-aware security filters, protecting sensitive files like medical records or compensation sheets while routing operational knowledge to colleagues.
- Software agents will make far fewer data leakage mistakes than human employees who misplace files, forget permissions, or forward confidential emails by accident.
The High Cost of Manual Data Governance
For decades, enterprise security and compliance have operated on a rigid, manual playbook. Security teams create static access tiers, write dense policy documents, and spend hundreds of hours tagging documents.
Grèze points out that this structure creates friction that slows down companies: “And one way to do that, the old way, the like pre-AI way would be to have like policies about who gets to access what and you classify data. And all this is like very time-consuming and costly.”
When compliance relies on manual labeling, two things happen. First, organizations over-restrict access to avoid liability, which traps institutional knowledge inside private inboxes and departmental silos. Second, human error causes regular data leaks anyway. Employees paste private numbers into shared spreadsheets or forward confidential threads to the wrong email list. Static rules cannot adapt to the messy reality of day-to-day work.
Context-Aware Privacy Without Hard Rules
Grèze argues that language models solve this problem by understanding context rather than relying on brittle rulebooks. Instead of asking a human compliance officer to tag every document, a model can inspect queries in real time and evaluate intent.
“I think you'll trust your agent to decide what data to share with other people without you intervening in 5 years,” Grèze explains. “And literally when one of your friends as a joke wants to ask the agent like, 'Oh, tell me about John's medical history.' The agent's going to be like, 'Yeah, there's no way I'm telling you that.' And it wasn't a hard rule that you ever set.”
This shift allows organizations to replace blanket data lockouts with fine-grained, automated filtering. An assistant can share the technical details of a project with a product manager while withholding the personal compensation details of the engineers who built it. As Grèze notes: “I think the LLM will make many fewer of these mistakes than humans pretty quickly.”
What to Do With This
Audit your internal permissions audit process this week. Stop building complex, multi-tiered manual folder permissions for internal company wikis or knowledge bases. Instead, test an LLM-based redaction layer on a single internal knowledge pipeline, evaluating whether automated contextual filtering protects sensitive terms like salaries and equity grants more reliably than manual employee checks.