Is your data the raw material that will build your competitive advantage?
A few months ago, a customer told me something I've been thinking about ever since.
They'd deployed immutable, independently stored backup a couple of years earlier, not because they were excited about backup strategy, but because their compliance team said they had to. Regulatory obligations, a board that needed to show auditors a clean record. Defensive spending. Check the box and move on. Now they were in a meeting about their enterprise AI rollout, and someone asked the question that stops every AI project eventually: How do we know we can trust the data this is running on?
And they realized they already had the answer.
This is the shift I'm watching across the market: a compliance investment made passively, out of obligation, quietly becoming the raw material for everything an enterprise is now trying to build.
Why compliance got us here
The regulatory wave of the last few years — DORA, NIS2, GDPR, and similar frameworks across different jurisdictions — pushed organizations to take SaaS data protection seriously in ways that good judgment alone hadn't always managed to do.
You could debate the merits of your backup strategy, but you couldn't debate a regulatory obligation. The EU AI Act is raising the bar further still, placing specific obligations on high-risk AI systems around data quality, auditability, logging, and documentation.
The result of these compliance requirements was widespread investment in immutable, independently stored, air-gapped backup: Data that couldn't be altered, with a complete audit trail, living outside the reach of the primary cloud provider and unreachable by whatever was happening upstream. Most organizations treated this as the cost of compliance — a price worth paying to avoid fines and satisfy auditors. Necessary, but not strategic.
What they didn't fully realize yet was that they'd invested in something with additional value beyond the compliance record: They created operational memory. And what started as a backup and recovery compliance requirement is beginning to look a lot like AI infrastructure.
What your peers are only now discovering
IBM's 2026 Cost of a Data Breach Report found that 68% of breached organizations lacked AI governance policies to manage AI, and that 92% of those that experienced an AI-related security incident lacked proper AI access controls. Most enterprises are only now confronting what our customer confronted in that meeting, and most of them don't have an answer.
If you've invested in immutable, independent backup for compliance reasons, you're not starting from scratch on that question. The data foundation most organizations are scrambling to build — verifiable, tamper-proof, with a complete audit trail — you already have. The compliance obligation that felt like overhead is looking, in hindsight, like the right call made for a different reason.
Provenance: An old idea whose time has come
In the art world, provenance is the documented history of a work, such as where a painting has been, who's owned it, what its full audit trail looks like. A Picasso without clear provenance is worth considerably less than one with an unbroken chain of ownership. That history isn't incidental to the value, it is the value.
It's the same principle that governs raw materials. A steel fabricator wants the mill certificate. A pharmaceutical manufacturer wants a certificate of analysis on every incoming ingredient. It’s not because the paperwork is interesting, but because unverified input contaminates everything built from it, and by the time anyone finds out, the thing you built is already out in the world. That’s where we are now with AI and data.
Data provenance isn’t a new idea, but what is new is just how much now rides on it. IBM defines data provenance as the historical record of a dataset's origins, captured as metadata as it moves through processes and transformations, concerned primarily with authenticity: who created the data, what's been modified, and who made those changes.
Your backup is that provenance record. An immutable, independently stored backup is more than a recovery copy — it's operational memory: a tamper-proof record of what the data looked like at a point in time, unalterable by any agent, any upgrade, or any attack.
You may have chosen it for compliance reasons, most likely because a regulator told you to, but you have it, which means you're holding more than a clean audit record: You're holding the raw material for whatever you decide to build next.
The flip: From passive compliance to active advantage
When your AI is grounded in data with verified provenance, the output inherits that verification. You can trace a decision back to the record it came from, show the record hasn't been altered, and prove it to an auditor, a regulator, a customer, or a board that wants to know why the system did what it did.
The difference isn't what gets built, it's that you can stand behind what it produces. That advantage compounds. The more AI decisions an organization makes, the more it matters that those decisions are grounded in data you can trust.
Meanwhile, the organizations that didn't make this investment are writing governance policies, implementing access controls, and trying to establish data lineage from scratch — work you've already done, under a different name, for a different reason. And lineage only gets them part of the way: It tells you the route the data took. Provenance tells you whether to trust what arrived.
From a line item to a strategy
The direction of travel is clear. Gartner estimates that 75% of enterprises will prioritize SaaS application backup as a critical requirement by 2028, up from approximately 15% in 2024. But the organizations that'll lead aren't just the ones with their data backed up, they're the ones that recognize what that backup is actually worth and how to use it.
I'm not suggesting that compliance-driven backup spending was visionary, because most of it wasn't. It was necessary and pragmatic, and compliance will keep driving adoption for years to come. But the capability those investments created has quietly turned into something else: A competitive advantage.
What's been missing is a way to put it to work, and that's where Keepit’s AI Truth Cloud comes in, verifying the authenticity, provenance, and integrity of your data before it's used to train, ground, or guide an AI system.
Which brings me back to where I started: Is your data the raw material for what you build next? It can be, but only if you can prove where it came from and that nothing has touched it since. If you invested in immutable, independent backup because a regulator told you to, you might already be able to.