Securing AI’s Future Without Closing the Door to Innovation

AI is changing how companies decide. Security has to keep pace without leaving advanced AI only to a handful of firms. Name three risks — tampering, leakage, exfiltration — then ask where the training data came from and who verifies a “sanitized” file.


Quality systems were built to answer a simple question: can we trust the record?

Artificial intelligence is now part of that record. It drafts investigations, summarizes audits, ranks suppliers, and puts numbers in front of people who will act on them. That is not an IT sidebar. It is a quality problem.

The Industrial Revolution changed how we make things. The internet changed how we share information. AI is changing how organizations analyze information, coordinate work, and make decisions. As those systems get more capable and more connected, the people who depend on them inherit the risk.

We need safeguards for privacy, cybersecurity, fraud, discrimination, and the other harms that show up when a model is wrong or a dataset is sloppy. We also need rules that do not leave advanced AI only to a handful of billion-dollar companies. Security that only the largest vendors can afford is not a standard. It is a moat.

Watch the Quality Minute Insights episode, then use this brief with your quality, legal, and data owners.

Three failure modes quality already knows how to name

Tampering is interference with a model, its data, or the systems around it so the output changes. A compromised component can look fine in ordinary use — the same way a drifted gauge still prints a number. You need trusted sources, testing, and a way to detect behavior that does not match the approved method.

Leakage is information crossing a boundary it was supposed to stay inside. Sensitive data in a response. An assistant hooked to a tool it should not call. Clear permissions, monitoring, and human oversight matter more as these systems take on more tasks. If nobody can say what the model was allowed to see, you do not have document control. You have hope.

Exfiltration is unauthorized removal of something valuable: model weights, proprietary process data, employee files, customer records. A stolen model can be reused. Exposed data can harm the people and organizations that trusted you with it. Quality already treats uncontrolled copies of controlled documents as a finding. Weights and training corpora are controlled documents with a new name.

A warning label and a firewall do not close any of those loops. Developers, customers, researchers, and governments have to test systems, limit access where the risk requires it, share what they learn, and respond when a weakness appears. The United States should work with partners on practices that can move as fast as the tools. That is alignment work, not a press release.

The fourth risk: the market for other people’s files

Licensing data for AI development can be legitimate. News organizations can license archives. Companies can sell or share what they have the right to sell.

A company’s records are rarely that clean. They hold employee information, confidential communications, trade secrets, and material that belongs to customers, suppliers, and partners. A promise to “sanitize” a dataset is a claim. Claims get verified.

The proposed sale of Spirit Airlines’ business data is a public illustration, not a courtroom verdict. Google won an initial auction with a $10 million bid. AI data company micro1 later filed a competing offer of $12.5 million. The proposed sale prompted objections about how employee information would be protected. An offer does not establish wrongdoing by any bidder. It does establish that corporate records now have a market price — and that the contract must say exactly what the buyer receives and may do with it.

If you cannot answer those questions, you are not transferring a dataset. You are transferring an untraced process.

What quality management actually requires

Start with provenance, the same way you start a material cert.

  • Where did the information come from?
  • Who had authority to sell or license it?
  • What consent, contracts, and restrictions apply?
  • What must be removed before transfer?
  • Who verifies the result — and against what procedure?

Then install controls you can test:

  • Document the approved use.
  • Limit access.
  • Validate de-identification. Do not assume that stripping names removes every privacy or confidentiality risk.
  • Restrict onward sharing.
  • Set retention and deletion rules.
  • Keep an audit trail.

If a review finds a gap, assign corrective action and verify that the fix worked. That is not bureaucracy. That is how you keep an invented “clean file” out of the next training run.

This is also where practical standards earn their keep. Buyers and sellers should be able to demonstrate how a dataset was obtained, prepared, protected, and used. The standard should measure real risk and still let responsible companies of every size participate. If only the largest firms can prove the chain of custody, you have protected the incumbents and called it safety.

What this means if you run a plant, a QMS, or a P&L

Do not put process data, CAPA narratives, or employee training files into a tool you cannot name, bound, or audit.
Do not accept an AI number that cannot cite its source. “Not in source” is a valid quality answer.
Do not treat prompt catalogs as optional. An unapproved prompt is an unapproved work instruction.
Do not sign a data deal until provenance, use limits, and verification are written down.

Harrington HQMS exists to hold the records those rules attach to: documents, CAPA, audits, training, suppliers, risk. AI can sit on that thread. It should not replace the thread.

The decisions made in the next few years will decide who gets to build with AI and whose information becomes someone else’s training set. Protect people, corporate information, and critical systems. Leave room for responsible innovation. That is how you build technology — and a quality system — worthy of trust.

See HQMS: https://hgint.com/quality-management-systems/

Request a demo

800-ISO-9000

www.hgint.com

Harrington Group International. Better processes. Better decisions. Better results.

FAQ

What are tampering, leakage, and exfiltration in a QMS context?
Tampering changes how the model or its inputs behave. Leakage is data or access leaving its approved boundary. Exfiltration is taking weights, records, or know-how without authorization.

Is selling company data for AI training always improper?
No. Authority, contract scope, and verification decide. Quality asks who approved the transfer and what was actually in the file.

Why isn’t de-identification enough?
Names are one identifier. Contracts, process detail, and third-party content can still identify people or disclose secrets. Verify against a written method.

Where should a manufacturer start?
Inventory what AI can see. Write the approved-use rule. Put CAPA on gaps. Keep a human on every controlled output.