The copy is the risk
Almost every AI program inside a regulated firm opens the same way. Before a model can do anything useful, the data has to be somewhere it can reach. An index, a warehouse, a vector store. Something gets stood up, and records get copied into it.
That step is discussed as plumbing. It is the most consequential architectural decision in the program.
What was created is a second system of record. It has to be secured, access-controlled, retained on a schedule, deleted on request, reconciled against the original, and explained to whoever asks. It inherits every obligation of the source and none of its authority. When the copy and the record disagree, the record wins, which means the copy's entire contribution was convenience.
It is also stale the moment it is written, and it stays stale between refreshes that nobody watches.
What is structurally true
The deeper problem is not duplication. It is that copying inverts provenance.
Once answers come from the index, lineage runs to the index. Ask where a number came from and the honest answer is the store we built last quarter. You have not made the firm legible to AI. You have made a copy of the firm legible to AI, and then started answering questions about the copy, in front of people whose entire job is to ask where things came from.
This keeps happening because make the data available to the model sounds like an infrastructure task and is actually a governance decision. Copying is the default because it is the easiest thing to build, not because it is the right shape.
The other shape is to read at question time, from the system of record, and have the answer cite what it read and when. What persists is not the data. It is the account of the work: who asked, what ran, which source, as of when. Receipts, not records.
That is a smaller surface, not an empty one, and the difference is worth stating plainly. Reading in place still creates things to secure. A credential that spans a CRM, a transcript store and a data room is a valuable object precisely because of its reach, which is why it has to be scoped narrowly and revocable in one action. The receipts are themselves a description of the firm, and whoever holds them inherits an obligation for them. Content transits a model provider on its way to an answer. What goes away is the standing duplicate of the records, and with it the retention schedule, the deletion request and the reconciliation. What remains is a scoped access problem, which is smaller and which the firm already knows how to run.
That last property has a consequence worth naming: turn it off and your systems are exactly as they were. Reversibility is what allows a risk committee to say yes to something new. A migration cannot offer it. Anything that leaves a copy behind has already spent it.
What this means for you
Ask what persists. For any AI proposal, the question is not what the model can do in the demo. It is what exists afterward. Is there a new store? What is in it? Who is obligated to it, and under which policy? If the answer is a new copy of your records, you are not buying a capability. You are buying a system of record.
Make reversibility a requirement, in writing. Can access be revoked in one action, and does revocation leave the environment as it was? If the honest answer involves a deletion project, the arrangement is not reversible.
Separate legibility from mobility. Making a firm readable to AI does not require moving anything. Those two ideas got fused because copying was the easy path, and unfusing them removes much of what makes these programs slow.
On the record
The tell shows up in the pilot. When a firm cannot begin without a data migration, the migration becomes the project, measured in quarters and consuming the budget and the goodwill, and the AI becomes the thing they will get to afterward. Programs can end there, having produced infrastructure and no answers.
Reading in place moves the governance conversation to the scope of an access credential. That is a conversation risk and compliance functions already know how to have. They have been having it about vendors for thirty years.
Trucast builds Foundation, the governed layer for AI in regulated financial firms. Reads are live, every answer cites its source, and every change is a proposal a named person approves. Nothing migrates.