Key points
- When organizational AI gives wrong answers, the cause is usually the information it was given, not the model.
- The information layer has six parts: sources and authority, entities and relationships, permissions, provenance, freshness and feedback.
- Improving it is practical work: pick a domain, name owners, retire stale content, add metadata and test with real questions.
- Executives do not need technical depth to lead this. They need to ask the right questions.
When an AI assistant tells an employee the wrong parental leave policy, quotes a price from last year, or cannot say which contracts belong to a client, the instinct is to blame the model. Usually, the model did what it was asked with what it was given. The problem was the information.
Most AI failures inside organizations are information failures. Knowledge is scattered across drives, inboxes and systems. Documents contradict each other. Nobody knows which version is current. Important context lives only in people’s heads. AI does not fix these problems. It exposes them, quickly and at scale.
The encouraging part is that this is fixable, and fixing it improves far more than AI. This guide explains the information layer AI depends on, in plain terms.
Why the model is only one layer
Modern AI models are broadly capable, but they know nothing about your organization unless you tell them. In most organizational systems, the model answers questions using information retrieved from your documents and systems at the moment of asking. (Our guide on what it means to train AI on your organization explains how this works.) If the retrieved information is wrong, outdated or incomplete, a better model will simply give a more fluent wrong answer.
That is why reliable intelligence starts with structured information, explicit relationships, provenance, permissions and clear source authority.
The six parts of the information layer
| Part | The question it answers |
|---|---|
| Sources and source authority | Which information is official, and which wins when two sources disagree? |
| Entities and relationships | What are the important things in our organization, and how are they connected? |
| Permissions | Who is allowed to see what, and does the AI respect that? |
| Provenance | Where did this answer come from, and can someone check it? |
| Freshness | Is this still current, and who keeps it that way? |
| Feedback | When something is wrong, how does it get fixed? |
Sources and source authority
Not all documents are equal. A board-approved policy outranks a slide deck that summarizes it. A system of record outranks a spreadsheet someone exported last quarter. Source authority means deciding, topic by topic, which sources are official, and making sure AI systems prefer them. Without it, AI treats a draft and a final version as equally valid.
Entities and relationships
Entities are the things your organization cares about: clients, products, projects, locations, contracts, people, policies. Relationships are how they connect: this client holds these contracts, this product is governed by this policy, this team owns this process. When these are defined explicitly, rather than implied across hundreds of documents, AI can answer questions that span them. It also helps with consistency: one agreed name for each client or product, rather than five variations.
Permissions
An AI assistant should never become a way around access controls. If an employee cannot open the executive compensation file directly, the assistant should not summarize it for them. Permissions must follow the information into the AI system. This is both a security issue and, where personal information is involved, a privacy one.
Provenance
Provenance means knowing where information came from. For AI, it means answers that cite their sources so a person can check them, and records of which sources informed which outputs. Provenance is what makes AI auditable and what lets people trust it appropriately rather than blindly.
Freshness
Information goes stale. Policies are revised, prices change, people move roles. Every important source needs an owner and a review cycle, and superseded versions need to be retired or clearly marked, not left sitting in a folder for AI to find.
Feedback
No information layer is perfect at launch. Users need an easy way to flag wrong or unhelpful answers, and someone must be responsible for tracing each one back to its cause: a wrong source, a missing document, a permissions gap or an unclear instruction.
Practical steps to structure it
This does not require a multi-year data program before anything useful happens. Start small and build outward:
- Pick one domain. Choose an area where AI would clearly help, such as HR policy questions, product information or a specific client service process.
- Inventory the sources. List where the relevant information lives today, including the unofficial places people actually look.
- Name owners and decide authority. For each topic, identify the authoritative source and the person responsible for keeping it accurate.
- Clean up. Retire duplicates and superseded versions, and resolve contradictions.
- Add metadata. Tag sources with owner, effective date, audience, sensitivity and permissions.
- Define key entities. Agree on the core entities and relationships for the domain, and use consistent names.
- Test with real questions. Collect questions people actually ask, check the answers, and trace every failure to its cause.
- Set up feedback and review. Make flagging easy and schedule regular reviews of sources and failures.
Once one domain works well, the patterns, tools and habits carry over to the next. So does the benefit to people: a clean, well-owned policy library helps a new employee as much as it helps an AI assistant.
Bilingual organizations should plan for language early. If English and French versions of a policy exist, decide how they are linked, which is authoritative if they diverge, and how both stay current. In Quebec, French-language requirements make this especially important.
What executives should ask
Leaders do not need to understand retrieval pipelines or knowledge graphs to lead this well. They need to ask good questions of their teams and vendors:
- When our AI gives an answer, can we see where it came from?
- Who decides which source is authoritative when documents disagree?
- Does the AI respect the same access permissions our people have?
- How do we know the information it uses is current, and who owns keeping it that way?
- What happens when someone reports a wrong answer? Who fixes it, and how fast?
- What personal information does the system use, and have we confirmed our obligations with counsel?
- How are we testing quality before and after changes?
If the answers are vague, the information layer is probably the constraint, not the model. The questions about oversight and accountability connect directly to our responsible AI approach.
How Trained helps
Trained helps Canadian organizations structure the information layer that AI depends on: sources, authority, entities, relationships, permissions, provenance and feedback. We start with a domain where AI can help, build the information foundation for it, and connect it to the systems and workflows that use it. This is a core part of our model and knowledge training work. If your AI is only as good as your information, let’s talk about the information.