AI governance
Data stewardship stops at the data layer
Data stewards own tables, lineage and quality metrics. The policies, SOPs and memos your AI assistant actually answers from sit outside that remit, with no owner and no review date.
Cognatum Team · Sep 21, 2026 · 5 min read
Most regulated enterprises can name the person accountable for their customer table. Ask who is accountable for the onboarding policy an AI assistant quoted to a client this morning, and the room goes quiet.
Cognatum governs the entry
source · version · approver · permissions
That is not a failure of the stewardship program. It is a boundary that was drawn years before anyone deployed an assistant that reads documents.
What data stewardship actually covers
IBM describes data stewardship as a collection of practices for keeping data high in quality and accessible, run by stewards who define quality metrics, manage metadata and reference data, trace lineage and classify sensitive data. Snowflake splits the role into business, technical, operational and metadata stewards. Dataversity frames the whole discipline as the operational arm of a data governance program.
Every one of those definitions points at the same object: structured data assets sitting in a warehouse, a catalog or a master data system.
The vocabulary gives it away
Quality metrics, valid values, identity resolution, reference codes, lineage. These are the concerns of rows and columns, they are real concerns, and a stewardship program that handles them well is worth what it costs.
None of them describe a supplier agreement, a validation SOP, a superseded pricing memo, or the answer an assistant assembled from all three.
The half with no steward
The material your AI assistant retrieves from is mostly not in the warehouse. It sits in departmental repositories: a Box folder for legal, SharePoint for quality, a Slack channel where the real answer was given last March. That split is normal and it is fine. Departments should keep their own repositories.
The problem is not the split. It is that nothing sits above those repositories with the authority a data steward has over a table.
Where the answers actually come from
Ask an assistant a policy question and it will answer from whatever it can reach. That is usually a mix: an approved policy, a draft nobody deleted, a deck from a conference, an email thread. The assistant does not rank those by authority, because nothing upstream has told it which one carries authority.
What a steward would ask
Four questions, borrowed directly from the warehouse side of the house:
- Who owns this document, by name, today.
- When was it last reviewed, and against what.
- Which version did the assistant read.
- What happens downstream when it is superseded.
In most organizations those four questions have answers for the customer table and no answers at all for the policy library.
Even inside its own boundary, it is hard
Dataversity, citing Gartner's 2024 chief data and analytics officer survey, reports that only 43 percent of respondents had successful stewardship efforts. Snowflake's own account of the discipline names lack of clear ownership and accountability as a leading obstacle. A program still fighting for ownership of the warehouse is unlikely to volunteer for the document library.
The frameworks do not close the gap
It is tempting to assume regulation already covers this. What regulation covers is something adjacent.
What Article 10 governs
Article 10 of the EU AI Act sets data governance obligations for high risk systems developed by training models on data, and it speaks to training, validation and testing data sets. That is a real obligation, aimed squarely at the data a model learned from. It says nothing about which version of a work instruction your assistant retrieved twenty minutes ago and quoted to a customer.
What the management standards assume
ISO/IEC 42001 sets out a management system for artificial intelligence, and the NIST AI Risk Management Framework offers a voluntary structure for identifying and managing AI risk. Both are worth adopting. Neither supplies the authoritative content itself. That part is assumed to already exist, with an owner attached.
Grounding an answer is not stewarding it
The usual reply is retrieval: point the assistant at the real documents and the accuracy problem goes away. A preregistered evaluation of retrieval based legal research tools found that products from LexisNexis and Thomson Reuters hallucinated between 17 and 33 percent of the time, despite vendor language about eliminating hallucinations.
Retrieval decides which document gets fetched. It does not establish that the document was right, current, or approved by anyone.
Unstewarded knowledge does not stay put
APQC's survey of 1,000 professionals, sponsored by eGain, found that 92 percent of organizations do not consistently capture knowledge from soon to be retirees, 85 percent have not operationalized AI for knowledge management, and 58 percent of C-suite respondents are very worried about the loss.
Knowledge with no named owner is knowledge that leaves with the person who held it.
What stewardship of knowledge looks like
Cognatum is a knowledge base that works as a governed layer above the repositories you already have. Nothing migrates. The Cognatum Knowledge Loop runs eight steps across four phases, and one of those steps is a gate rather than a task.
Approve is the step that stays human
The AI does the finding, gathering, cleaning and surfacing. It does not decide what is true. It routes the item to a named person, who can rework the wording and then approve it. What ships afterwards carries an approver, a date and a source, and the record shows where the knowledge stood at the moment the answer was given.
Conflicts are surfaced, not settled
Where two documents disagree, both are presented along with the point of disagreement, rather than one being picked as the winner. A steward of tables would call that a reconciliation queue. It is the same discipline, applied to prose.
Notification when a source moves
External systems are treated as external data, with a flow in both directions. When a table, a query or a stored procedure changes, anything tied to it is flagged so you know what has gone out of date. It does not quietly rewrite an approved answer, and it is not self updating.
Where a data steward would start
Take those four questions and run them against the twenty documents your assistant cites most often. Owner, review date, version, downstream effect. If the answers thin out after the first column, the gap is not in your warehouse.
Your company's knowledge isn't missing. It's unusable. Cognatum changes that.
The Cognatum Knowledge Loop is documented at cognatum.ai/the-loop.
Sources
- What Is Data Stewardship? (ibm.com)
- What Is Data Stewardship? Everything You Need to Know (snowflake.com)
- What Is Data Stewardship? (dataversity.net)
- EU AI Act Article 10: Data and Data Governance (artificialintelligenceact.eu)
- ISO/IEC 42001:2023, AI management systems (iso.org)
- NIST AI Risk Management Framework 1.0 (nvlpubs.nist.gov)
- Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (arxiv.org)
- APQC Study Warns of Looming Great Retirement Crisis (apqc.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is data stewardship?
Data stewardship is the operational side of data governance. Stewards take named responsibility for defined data assets, setting quality metrics, maintaining metadata and reference data, tracing lineage and classifying sensitive data so the organization can trust what sits in its systems.
Is data stewardship the same as data governance?
No. Governance sets the policies, standards and decision rights. Stewardship is the day to day execution of those policies against specific data assets. An organization can have a governance framework on paper and nobody actually stewarding anything.
Does data stewardship cover documents and other unstructured content?
Usually not. The standard definitions and toolsets are built around structured data in warehouses, catalogs and master data systems. Policies, SOPs, contracts and memos normally sit in departmental repositories with no equivalent owner, review cycle or quality metric, which becomes a problem the moment an AI assistant starts answering from them.
Does the EU AI Act require stewardship of the documents an AI assistant retrieves?
Article 10 sets data governance obligations for high risk systems developed by training models on data, and it addresses training, validation and testing data sets. It is not a rule about which version of an internal document a retrieval based assistant pulled this morning. Software can align with those obligations and produce evidence for them, but no product confers compliance.
Who should own the knowledge an AI system answers from?
A named person, the same way a data steward owns a table. In practice that means every answer carries an approver, a date and a source, a human gate before anything is published, and notification when an underlying source changes so the owner can decide what to do about it.