Original Broadcast Date: 8/2/2026
Sponsored by Cohesity and Carahsoft
Why Data Security Is the Foundation of AI Resilience
Artificial intelligence is only as reliable as the data behind it. As agencies continue adopting AI to improve decision-making and automate tasks, protecting the integrity of that data becomes increasingly important. According to Marlin McFade, Public Sector Chief Technology Officer and Chief Information Security Officer at Cohesity, agencies cannot separate AI security from data security because every AI capability depends on trusted information.
McFade explains that AI has no inherent knowledge of its own. Whether agencies are training machine learning models, using retrieval-augmented generation, or deploying autonomous AI agents, every system depends on the data it receives. If that data is manipulated, the AI's understanding changes as well.
"The AI doesn't think that way," McFade says. "You give it data, and that is its truth."
Unlike people, AI systems operate at machine speed. Small changes to data can produce much larger effects as AI rapidly processes information and generates recommendations or decisions. That speed increases the potential impact of data poisoning, where adversaries intentionally alter information to influence AI outputs.
Data Security Supports AI Security
McFade describes a chain of dependencies that begins with sound data management. Organizations first need the proper controls and capabilities to manage their data effectively. Those practices support data resiliency, allowing agencies to recover from disruptions or disasters. Cyber resiliency builds on that foundation by helping organizations recover from cyber incidents through capabilities such as immutable data protection.
Only after those elements are in place can agencies confidently build secure AI environments. "Everything basically relies on data," McFade says. "AI security is relying on data security." Rather than viewing AI security as a separate discipline, he argues that agencies should recognize data security as one of the most important organizational functions because it supports cybersecurity, operational resilience, and AI simultaneously.
Start With the Data, Not the AI
As organizations pursue artificial intelligence, McFade says many make the same mistake by focusing first on acquiring AI technology. Organizations often purchase AI platforms before considering how those systems will be supplied with accurate, well-managed information. Once deployed, they discover that AI cannot produce meaningful results without trusted data.
Instead, McFade encourages agencies to begin with data management. Establishing governance, controls, and quality standards provides the foundation AI systems need to perform reliably. Without that work, agencies risk applying advanced technology to unreliable information.
McFade points to the familiar principle of "garbage in, garbage out." Poor-quality data produces poor-quality results, regardless of how sophisticated an AI model may be. As AI becomes more integrated into agency operations, unreliable outputs can affect more than recommendations. AI systems are increasingly supporting or making decisions that influence other systems and processes, increasing the importance of trusted data.
Understanding the Risk of Data Poisoning
Data poisoning presents a unique challenge because even relatively small changes can influence AI behavior. McFade explains that while people may recognize mistakes, pause, and reconsider, AI systems simply process the information they receive. If inaccurate or manipulated data becomes part of an AI model's knowledge base, that information becomes the basis for future actions.
The risk grows as AI systems become more autonomous. Agentic AI can make decisions continuously and at a much faster pace than human operators. If those decisions rely on compromised data, errors can spread rapidly throughout an organization.
McFade notes that AI agents may also pass information or actions to other connected systems, allowing mistakes to propagate beyond a single application. As agencies expand the use of autonomous AI, maintaining confidence in the underlying data becomes increasingly important to limiting operational risk.
Building a Stronger Foundation for AI
For agencies beginning their AI journey, McFade's recommendation remains consistent: prioritize data before technology. Strong governance, effective data management, resiliency, and cybersecurity practices all contribute to building trustworthy AI environments. These foundational capabilities not only improve security but also increase confidence in the decisions AI systems generate.
As agencies continue exploring new AI use cases, the quality of their data will influence how effectively those tools perform and how safely they can be deployed. McFade's perspective reinforces a simple principle: successful AI adoption begins long before an organization implements an AI platform. It starts with understanding, protecting, and managing the data that powers every AI decision.
