
Over the last few years, conversational AI has gone from experiment to infrastructure. It now sits at the centre of how many companies support customers, run internal operations, and expose core systems. That shift brings real value-but it also changes the risk profile. As a CTPO, one pattern I see again and again is this: agents are given more data access than they actually need. Not because teams are careless, but because limiting access is hard to do well. And when it’s hard, the fastest way to success is “just give it access”. The answer isn’t to slow innovation or restrict agents to the point they become useless. The answer is data minimisation, done properly, with tooling that makes targeted…