Opens in a new tab

NEW ARTICLE: The Zero-Day Clock and AI’s Impact on Security Read Now

Supporting organizations across the entire U.S.

New AI & Data Rules Are Here. The Smart Move Is Turning Them Into an Advantage.

Cybersecurity, IT Leadership

Written by

David McBride

Published on

For most of the last decade, the rules governing how American businesses collect and use customer data lived mostly in California. That arrangement has quietly ended. As of 2026, more than twenty states have enacted comprehensive consumer privacy laws, and together these statutes now cover more than half of the U.S. population. Nebraska joined this group when its Data Privacy Act took effect on January 1, 2025, meaning businesses operating in or selling to Nebraska residents are now subject to a specific set of legal obligations, regardless of where the company is headquartered. A business in Omaha or Lincoln that sells to customers in Texas, Connecticut, and Colorado is no longer operating in a single regulatory environment. It is operating in several at once.

This evolution creates new opportunities for growth, but it also raises important questions. Do you know where sensitive information resides in your organization? Who has access to it? Which AI applications can employees safely use? Can your organization demonstrate that customer and business data is managed responsibly?

These questions sit at the heart of data governance for business. Effective governance defines how information is collected, stored, protected, shared, retained, and ultimately used throughout the organization. Rather than being viewed as a compliance exercise, it provides a framework that helps businesses improve decision-making, strengthen customer trust, simplify regulatory compliance, and adopt emerging technologies with confidence.

The enforcement side of this shift demands executive attention. State attorneys general have moved past warning letters. In 2025, Texas secured a $1.375 billion settlement with Google under its state privacy act, the largest of its kind in U.S. history, signaling that enforcement has moved well beyond warning letters. These are not abstract enterprise risks. Many of the newer laws carry low applicability thresholds, and several have removed the grace period that once let companies fix a violation before penalties applied.

At the same time, two other forces are reshaping the same terrain. Artificial intelligence has spread through the workforce faster than any technology in recent memory, often without management’s knowledge. And cyber insurance has become far harder to obtain and far less forgiving when controls fall short. Each of these developments touches the same underlying question: how well does your organization know, manage, and protect the data it holds?

The organizations that handle this well are the ones that recognize a common thread running through all three, and build a single discipline that addresses them at once. That discipline is data governance, and the businesses that treat it as a strategic capability rather than a paperwork obligation are positioning themselves to win customer trust, lower their costs, and move faster than competitors still scrambling to react.

Why Data Has Become a Business Asset That Demands Management

Every business already collects more information than its leaders typically realize. Customer contact details, payment records, purchase histories, support conversations, employee files, vendor agreements, and increasingly, the prompts and outputs of AI tools all accumulate across email systems, accounting software, cloud drives, and SaaS applications. This information powers daily operations but it also represents concentrated risk. When data is scattered, undocumented, and loosely controlled, an organization cannot answer basic questions: What do we hold? Where does it live? Who can reach it?

Data governance is the set of practices that lets a business answer those questions with confidence. It covers how information is collected, where it is stored, who may access it, how long it is kept, and how it is disposed of. The cost of deferring this work has changed significantly: the average cost of a data breach for small businesses reached $4.44 million in 2025, a figure that includes investigation, notification, downtime, and lost customers.

There is a quieter benefit that rarely makes the headlines. A company that knows its data can use it. Clean, well-organized, properly classified information is the raw material for better forecasting, sharper marketing, faster customer service, and any serious use of AI. Governance and capability are the same investment seen from two angles. The business that organizes its data to satisfy a regulator is, in the same motion, building the foundation it needs to compete on insight.

The U.S. Regulatory Landscape Is a Patchwork & That Is the Hard Part

The defining feature of American privacy law is that there is no single federal standard. Each state writes its own rules, and while most follow a broadly similar template, the differences matter operationally. Nebraska took a different approach. Like Texas, its Data Privacy Act has no consumer-count or revenue threshold. It applies to any business that operates in or sells to Nebraska residents and processes or sells personal data, unless that business qualifies as a small business under the federal Small Business Act. California’s law applies to businesses with $25 million or more in annual revenue or that handle data of 100,000 or more consumers, while Texas and Montana set no revenue threshold at all.

Response timelines differ too. When a consumer requests their data or asks for it to be deleted, a business has between 30 and 45 days to respond depending on the state. A growing number of states now require websites to honor the Global Privacy Control, a browser signal that automatically communicates a consumer’s opt-out preference, meaning compliance is no longer something a business can handle through a privacy banner alone.

For a business selling across state lines, the practical implication is that you cannot maintain a different process for each state by hand. The workable answer is a single, centralized approach that detects which state a customer is in and applies the correct rules automatically. This is an architectural decision as much as a legal one. Sector-specific exemptions add another layer of complexity: businesses already regulated under HIPAA or the Gramm-Leach-Bliley Act may find some of their data carved out, but determining that requires a careful read of each applicable law rather than an assumption. The FTC also maintains independent authority to pursue unfair or deceptive practices related to data security, adding a federal enforcement dimension even without a comprehensive national privacy statute.

Artificial Intelligence Has Created a New Governance Responsibility

The arrival of generative AI in the workplace has been extraordinarily fast, and that adoption has largely outpaced any policy to govern it. For a business, AI is now part of the data governance picture whether leadership planned for it or not, because every time an employee uses one of these tools, company information may be leaving the organization’s control.

When an employee pastes a customer list, a contract, or a financial report into a public AI tool, that information enters the tool provider’s systems. Even where the provider’s terms prevent the data from being used to train its models, the act of sending it externally can create a compliance problem under state privacy laws and industry-specific regulations. AI also introduces a subtler risk: when employees act on AI-generated analysis without verifying it, errors can quietly become the basis for business decisions, with no audit trail to catch them.

The honest framing for executives is that this is a manageable problem, not a reason to fear the technology. AI delivers real productivity gains, and the goal is to capture them safely. That framing leads directly to the most underappreciated piece of the puzzle.

Shadow AI: The Risk Hiding in Plain Sight

The most pressing AI governance challenge in most organizations is not the AI strategy leadership chose. It is the use of AI that leadership never authorized. A Gartner survey found that 69% of organizations suspect or have confirmed that employees are using prohibited public generative AI tools. Microsoft research found that 78% bring their own AI tools. IBM’s analysis found that shadow AI incidents accounted for 20% of all data breaches and carried roughly $670,000 higher costs per case compared to other breach types. Smaller businesses are not insulated from this. The instinctive response (an outright ban) tends to backfire; studies consistently show that nearly half of employees would keep using personal AI accounts even after a prohibition, which simply drives the activity further out of sight. What works is the opposite. When employees are given approved, governed AI tools, unauthorized use drops sharply. The lesson is clear: employees turn to shadow tools because the sanctioned environment is slower or absent. Give them a fast, safe, approved path, set clear policies for what data may and may not be used, and the shadow problem shrinks on its own.

Cyber Insurance Has Become a Security Audit

Many businesses have treated cyber insurance as a financial safety net, something to buy and forget. That understanding is now out of date. After years of large ransomware payouts, carriers rebuilt their underwriting from the ground up, and applications that were once short questionnaires now read like enterprise security audits.

The controls carriers treat as table stakes are specific: multi-factor authentication enforced across all systems, endpoint detection and response software that has replaced basic antivirus, tested and immutable backups, formal patch management, and a written incident response plan. Two points deserve emphasis because they catch businesses off guard.

First, partial implementation is worse than it looks. A company that enabled MFA on email but not on its cloud admin accounts may answer “yes” in good faith and later find a claim denied when an incident occurs. Second, the math strongly favors fixing the gaps: the IT investment required to meet these controls is almost always less than the premium savings they unlock. Insurers now also ask about state privacy law exposure during underwriting, a detail that ties this thread directly back to the first section.

A Practical Framework: People, Processes & Technology

The good news is that the same foundation answers every one of these pressures. A company that knows what data it holds, controls who can access it, and documents how it protects that data is simultaneously meeting state privacy obligations, containing its AI risk, and satisfying its insurer. The work organizes naturally into three areas.

People come first because most data risk originates with everyday human behavior rather than sophisticated attacks. CISA notes that multi-factor authentication alone blocks 99.9% of automated cyberattacks, a control that depends entirely on people actually using it. Clear policies and regular, practical training turn a workforce from the weakest link into the first line of defense. For Nebraska businesses in particular, employees also need to understand basic consumer rights under the state’s Data Privacy Act, including how to handle data access and deletion requests.

Processes come second. This means written procedures for the things that previously happened informally: how a consumer data request is received, verified, and fulfilled within the required window; which AI tools are approved and what may be entered into them; how often backups are tested by actually restoring from them; and what the organization does in the first hours of a security incident. The NIST AI Risk Management Framework offers a voluntary, widely respected model built around four functions, Govern, Map, Measure, and Manage, designed to be usable by businesses of any size, including those without deep in-house expertise.

Technology comes third, in support of the first two rather than ahead of them. The tools that matter most enforce the policies people and processes define: identity systems that make MFA unavoidable, endpoint detection that watches every device, centralized privacy infrastructure that applies the correct state rules automatically, and approved AI platforms that let employees work quickly without sending data into the wild. Technology bought without the surrounding discipline tends to sit unused. Technology chosen to serve a clear governance plan pays for itself.

Building Competitive Advantage Through Better Governance

Data governance supports much more than regulatory compliance.

It gives leadership greater visibility into business operations, improves confidence in decision-making, strengthens customer trust, supports cyber insurance readiness, and creates a stronger foundation for responsible AI adoption.

Organizations that establish governance early are better prepared to integrate new technologies, respond efficiently to changing regulatory expectations, and demonstrate accountability to customers, partners, insurers, and regulators.

With the right technology partner, governance becomes an ongoing business capability rather than a periodic compliance project. The result is an environment where technology, security, AI, and business strategy work together to support sustainable growth.

IT Consulting & Strategy: Strategic technology roadmaps that align governance, compliance, cybersecurity, and long-term business objectives.

Managed IT Services: Continuous monitoring, proactive support, and operational management that improve visibility and system performance.

Cloud Solutions: Secure, scalable cloud environments designed to protect critical business data while supporting collaboration and flexibility.

Cybersecurity: Identity-based security, continuous monitoring, and layered protection that reduce business risk and strengthen security maturity.

AI Integration & Governance: Practical strategies that help businesses adopt AI securely, establish responsible governance practices, and unlock measurable business value.

👉 If your organization is ready to strengthen data governance, adopt AI responsibly, and build a secure foundation for future growth, our team is ready to help you take the next step.