MMarketing Against The Grain
← All frameworks
Strategy

Three-Front AI Data Audit

Audit data ownership, public exposure, and regulatory risk before AI reshapes your market.

Difficulty
Moderate
Time to result
~weeks to results
Steps
6
Confidence
93%

The Three-Front AI Data Audit evaluates a business through three connected sources of disruption. First, inspect proprietary data: determine who controls each critical dataset, whether access can be withdrawn, and whether suppliers truly own what they sell. Second, examine public data: industries built on accessible legal, tax, financial, or instructional information are easier targets for specialized AI assistants and require faster adaptation. Third, assess regulation and geopolitics: privacy rules, national restrictions, and regional models can determine which tools and datasets remain available. The output is a prioritized data strategy covering vulnerable dependencies, proprietary assets to strengthen, AI opportunities to pursue, and regulatory contingencies to prepare.

Origin

Extracted from Marketing Against The Grain, where Kipp Bodnar and Kieran Flanagan divided the AI data wars into proprietary-data, public-data, and government-regulation fronts.

Core principles

  • 01Treat differentiated data as a strategic asset.
  • 02Assume third-party data access can become costlier or disappear.
  • 03Expect public-data markets to face faster AI disruption.
  • 04Evaluate whether intermediaries own or merely aggregate their data.
  • 05Plan for regional regulation to fragment AI access.

How to run it

  1. 1

    Inventory Data Dependencies

    List the internal and third-party datasets required by products, sales, operations, and customer experiences. Record the supplier, use case, cost, and consequences of losing each source.

    Pro tip Start with workflows that would stop functioning if a vendor revoked API access tomorrow.

    Watch out Do not mistake convenient access for permanent rights to the data.

  2. 2

    Trace Ownership and Control

    Determine whether each supplier creates, licenses, receives, or merely aggregates its data. Assess whether upstream owners could restrict access or demand higher prices.

    Pro tip Ask vendors to document provenance, licensing rights, and upstream dependencies.

    Watch out An aggregator may appear stable while remaining exposed to several upstream policy changes.

  3. 3

    Measure Public-Data Exposure

    Identify how much of the expertise delivered by the business comes from publicly accessible information. Test whether a specialized AI assistant could turn that material into a faster or cheaper customer experience.

    Pro tip Prototype the highest-value customer question against existing AI tools.

    Watch out Do not assume professional complexity will prevent AI disruption when the underlying information is public.

  4. 4

    Assess Disintermediation Risk

    Map intermediaries between the original data source and the end customer. Determine which layers an AI interface could remove by answering questions or completing transactions directly.

    Pro tip Focus on layers that add access or aggregation but little proprietary judgment.

    Watch out Brand strength alone may not protect a middle layer when users can obtain the same outcome directly.

  5. 5

    Map Regional Constraints

    Document privacy, localization, licensing, and AI-access rules in every important jurisdiction. Model how bans, incompatible regulations, or national models could fragment operations.

    Pro tip Maintain separate assumptions for data availability and model availability.

    Watch out This strategic review does not replace qualified legal counsel.

  6. 6

    Build the Response Portfolio

    Prioritize actions such as collecting consented proprietary data, renegotiating supplier rights, adopting vertical AI, or creating fallback sources. Assign owners, deadlines, and measurable risk reductions.

    Pro tip Balance defensive continuity work with offensive AI experiments.

    Watch out Avoid collecting data without a clear lawful purpose, governance process, and customer benefit.

In the wild

Sales Intelligence Vendor Review

A B2B company relies on an external contact database for prospecting. It traces the vendor's data provenance, discovers substantial dependence on aggregated sources, and models a price increase and partial access loss. The company then diversifies suppliers, improves first-party lead capture, and limits critical workflows that depend on a single feed.

The sales operation remains functional if upstream data access changes.

Accounting Firm AI Readiness

An accounting firm recognizes that much of its routine work draws on public tax rules. It tests specialized AI tools on low-risk internal research, adds expert review controls, and shifts its service positioning toward judgment, implementation, and client-specific planning.

The firm adopts AI before public-data automation commoditizes its routine research services.

Common mistakes

Assuming Access Equals Ownership

A business may depend on information that its vendor only aggregates. Upstream restrictions can still raise prices or eliminate access.

Ignoring Public-Data Competition

Organizations often overestimate the defensibility of expertise derived from freely accessible information. Vertical AI can package that information into a competitive experience quickly.

Using One Global AI Assumption

Privacy law, national policy, and model availability can differ substantially by region. A single worldwide operating assumption conceals material risk.

Is it for you?

Best for

It is best for leaders whose companies depend on external datasets, information-rich workflows, or markets vulnerable to vertical AI tools.

Not ideal for

It is not ideal as a technical model-development process or a substitute for specialist legal and privacy advice.

From the transcript

understand that your data strategy is going to change dramatically, over the next one to three years.

Kipp Bodnar · 08:00

Data is like internet gold.

Kieran Flanagan · 05:30

you need to know where that data is coming from.

Kipp Bodnar · 09:30

From the episode

A.I. Data Wars: Why Elon Is So Scared Of OpenAI (#116)