This week, I watched an interview with the founder of a technology company facing growing national scrutiny over how information collected by its platform had reportedly been misused.
The interviewer asked a simple question: What can you do to rebuild trust with the public? It is a question every technology provider serving government should think about.

The company recently announced new safeguards intended to identify potential misuse, strengthen auditing, limit access and give organizations greater control over how collected information is used. Those are important steps. But the timing raises a much bigger question. Why weren’t those controls foundational from the beginning?
Across government, we are deploying increasingly powerful technologies capable of collecting, connecting and interpreting enormous volumes of information. Artificial intelligence accelerates that capability even further. The issue is no longer simply what technology can do. The issue is whether government can demonstrate that it is being used responsibly.
This Is a Trust Problem
Public trust is difficult to build and remarkably easy to lose.
When technology collects sensitive information about citizens, government organizations assume a responsibility that extends well beyond cybersecurity. Protecting information from an outside attacker is important. But so is protecting it from inappropriate access by someone who is already authorized to use the system.
That requires a different way of thinking about enterprise security.
- Who accessed the information?
- What did they access?
- When did they access it?
- What did they do with it?
- Were they authorized to perform that action?
- Can unusual activity be identified?
- Can pour organization track all of this daily, weekly, monthly or years later if needed?
These should not be questions agencies begin asking after technology has been deployed. They should be requirements before the first piece of information is collected.
Governance Has to Be Built In
For years, data governance has often been treated as a compliance exercise. Policies are written. Retention schedules are created. Security requirements are documented. But governance cannot simply exist in a policy manual. It has to exist in the technology itself.
Modern information platforms should provide multidimensional access controls that determine not simply whether someone can enter a system, but what information they can see and what actions they can take. They should provide detailed audit trails capable of recording successful and unsuccessful attempts to access or change information. Organizations should be able to audit activity by user, group, information type and action. For particularly sensitive activities, users can be required to document why an action is being performed. Retention and disposition policies should be consistently applied rather than dependent on individual employees remembering what to do.
That is what it means to make governance operational. It is the difference between having a governance policy and having a platform capable of enforcing one.
AI Raises the Stakes
This becomes even more important as government moves deeper into AI and agentic AI.
AI can analyze information at a scale that was previously impossible. Agentic systems can go further by taking action, moving information between systems and advancing work automatically. That creates tremendous opportunity. It also magnifies weak governance.
If access controls are inconsistent, AI does not fix them. If information is poorly governed, AI does not make it trustworthy. If organizations cannot determine who accessed information and why, adding more powerful technology only increases the risk.
Trusted outcomes require trusted information. And trusted information requires governance.
Technology Providers and Government Share the Responsibility
Technology companies have a responsibility to build security, governance and auditability into their platforms from the beginning.
But government agencies cannot outsource public trust to their technology providers. Agencies need clear policies defining what information should be collected, who should have access to it, how long it should be retained, how it can be shared and what constitutes appropriate use. More importantly, those policies need to be continuously tested through auditing and oversight.
The question is not simply, “Is this technology secure?” Government leaders should also ask, “Can we prove that this information is being used appropriately?”
That distinction matters. Because once public trust has been lost, another feature or policy announcement may not immediately restore it. The better approach is to build the controls, policies, governance and accountability mechanisms long before they are needed.
In government, governance is not something that should follow innovation. It is what makes responsible innovation possible. And as technology becomes more powerful, preserving public trust may ultimately depend less on what the technology can do and more about the ability to demonstrate how responsibly it is used.
Andy MacIsaac is a senior marketing leader at Laserfiche, where he drives go-to-market strategy and thought leadership for AI-powered content management, process automation, and data governance in the public sector. With more than two decades of experience partnering with government agencies and education institutions, he helps organizations modernize operations while maintaining security, compliance, and trust. Andy has led industry marketing, demand generation, and sales enablement initiatives across leading software and consulting organizations, translating complex technologies into practical outcomes. As a trusted advisor to CIOs and agency leaders, he is passionate about responsible innovation that improves efficiency, transparency, and service delivery.
Photo Credit: CDC, Pexels



Leave a Reply
You must be logged in to post a comment.