AI search can make company knowledge much easier to find. Instead of opening folders, searching through documents, and reading long reports, an employee can simply ask a question and get an answer.
That is powerful - but it also creates a serious responsibility.
The basic rule should be simple: AI should never make information easier to access than the systems it searches.
If an employee cannot normally open a salary document, legal memo, patient record, acquisition plan, or confidential engineering file, an AI assistant should not be able to retrieve it, summarize it, quote it, or reveal information from it.
AI search can expose more than normal search
Traditional search usually returns links, document titles, or short previews. Generative AI goes much further.
An AI system may retrieve several documents, combine information from them, summarize the findings, and produce a confident answer.
That means a permission mistake can become much more serious.
Imagine an employee asks:
"Is the company planning any major restructuring this year?"
The employee may not have access to confidential leadership documents. But if the AI search system ignores permissions, it could use those documents behind the scenes and reveal information indirectly.
The user does not need to see the original document for sensitive information to leak.
This is why permissions must be enforced before protected information reaches the AI model, rather than simply telling the model through a prompt not to reveal confidential information.
AI should inherit the permissions companies already use
Most organisations already have rules controlling access to information.
For example:
- HR employees may access certain employee records.
- Finance teams may access financial reports.
- Engineers may access particular repositories.
- Executives may access strategy documents.
- Project teams may access documents belonging to their projects.
AI search should respect these same boundaries.
When someone makes a search, the system should first identify the user and understand their roles, groups, and permissions. It should then search only the information that person is allowed to access.
Only authorised information should be sent to the AI model.
This principle becomes especially important when documents are divided into smaller pieces for AI search. If one confidential document becomes twenty searchable pieces, all twenty pieces must keep the original document's permission information.
Permissions also need to change when people change roles
Access inside organisations changes constantly.
Employees join projects, move departments, get promoted, leave teams, or leave the company entirely.
An AI search system therefore cannot treat permissions as something configured once and forgotten.
If someone's access is removed from a source system, the AI search system should also stop giving that person access.
Companies should regularly test situations such as:
- an employee being removed from a project;
- a confidential document becoming restricted;
- someone leaving the organisation;
- group permissions changing;
- identity systems temporarily becoming unavailable.
When the system cannot confirm whether someone has access, the safer approach is to deny access rather than expose potentially sensitive information.
Good AI search should also show where answers come from
Security is only one part of trust.
People also need to understand why the AI gave them an answer.
A good enterprise AI search system should preserve information about its sources, including the document, version, owner, date, location, and relevant security classification.
The interface can then provide citations or links to the original material.
This creates two important questions:
Permission: Am I allowed to see this information?
Provenance: Where did this information come from?
Showing sources helps employees verify important answers instead of simply trusting fluent AI-generated text.
Security should not depend on the AI behaving perfectly
AI models can make mistakes. They can misunderstand information, encounter conflicting documents, or be influenced by malicious content.
The surrounding system therefore needs strong controls.
Permission-aware AI search should include identity checks, access controls, logging, monitoring, testing, and clear rules for what happens when something goes wrong.
Organisations should also test attempts to bypass permissions, access information from another team, exploit outdated memberships, or manipulate the AI through malicious instructions.
What good permission-aware AI search looks like
A strong system connects to company identity, understands groups and roles, preserves document permissions during indexing, filters information before it reaches the AI, records where answers came from, logs important access decisions, and continuously tests whether permission changes are working correctly.
These protections can add some engineering complexity and may slightly increase search time. But removing access controls simply to make AI search faster is the wrong trade-off.
The goal should be the fastest useful search that remains correctly authorised.
Ultimately, enterprise AI search should not try to let everyone find everything.
It should help each person find the best information they are actually allowed to use, explain where that information came from, and leave enough evidence to show that the organisation's rules were followed.