Chief Data Officer / CDAO
Owns what AI is allowed to know — and often the whole AI strategy.
You are accountable for
- Classification, lineage, and permissions that survive contact with retrieval
- Training and grounding data with documented rights
- Gartner finds ~70% of CDAOs hold AI strategy — this framework is their map
What keeps you up at night
- An assistant surfacing the over-shared folder nobody audited
- PII discovered in prompts, logs, or a vendor's retention store
- A tuning corpus with rights nobody can prove
Decisions you own
- Set the data-class-to-AI-system access matrix and enforce it at index time
- Mandate de-identification pipelines for sensitive domains
- Make lineage capture automatic from source to model to output
Your layers of the stack
Questions you should be asking
- Which corpora are indexed for AI, and when were their permissions last reviewed?
- Can we trace any AI output back to sources, model version, and training data?
- Where does our data physically go — inference, caching, logging — per vendor?