IM BLOG: AI with Hands Needs IM at the Table: Why records professionals must become proactive architects
For the first wave of generative AI, the dominant image was a chatbot: ask a question, receive an answer. The emerging generation of AI agents are different. These tools can work across applications, organise files, draft responses, update systems and complete multi-step workflows. They are, in effect, AI with hands.
That is a significant shift for records and information management. The question is no longer only whether an AI-generated answer is accurate. It is whether an AI-enabled action is authorised, traceable, explainable and reversible and whether the information it acted on was trustworthy in the first place.
The profession already holds part of the answer
A recent SWOT exercise with RIMPA Global’s AI and IM Community of Practice was not intended as formal research but the pattern was clear. Participants saw the profession’s strongest contributions in records and metadata expertise, governance and risk, authenticity and evidence, accountability and the ability to provide context and provenance.
These are not peripheral capabilities in an AI-enabled organisation. They are the foundations that allow an organisation to know what information an agent accessed, which version it used, what action followed and whether the result can be relied upon. Data volume is not the same as information quality and access does not equal authority.
If AI is expected to act on organisational information, then information professionals have knowledge that belongs at the design table from the beginning.
Our greatest weakness is arriving too late
The same exercise identified a familiar weakness: RM and IM professionals are often brought into technology initiatives after the important decisions have been made. By then, the platform has been selected, access settings established, workflows designed and value proposition promised. Information governance becomes a retrofit or is treated as the obstacle delaying delivery.
AI makes that approach more dangerous. A system that can take action can also create, alter, relocate or disclose information at speed. If no one has defined the records of those actions, the logs that must be retained, the evidence required for review or the boundaries of acceptable use, the organisation may only discover the gap when a decision is challenged or something goes wrong. Being involved early is therefore not about saying no sooner. It is about helping teams ask better questions before risk is designed into the workflow.
AI cannot repair an unmanaged information environment
There is a temptation to imagine AI as the solution to years of information sprawl. Point it at the shared drives, SharePoint sites and business systems and let it sort everything out. AI does not fix poor information architecture, it highlights it and does it quickly. Consider the roll out of Microsoft Copilot for example, if your SharePoint permissions are not adequately protecting sensitive information then Copilot will rapidly expose this.
Before AI can add real value some basic conditions need to be true. Information architecture must be coherent enough for systems and people to interpret. Site and library creation must be governed. Metadata standards must be used not just documented and information assurance must be robust. Executive sponsorship must reinforce the behaviours technology cannot create. Someone must also own the ongoing training, monitoring and governance of automated classification and action.
This is not a demand for perfect information before any AI project can begin. It is a call to understand the current environment honestly, identify the minimum foundations the use case depends on and avoid automating disorder.
Treat AI as an accelerant, not an autonomous solution
A useful principle is to treat AI in records management as a workflow accelerant. It can assist with repetitive work, surface patterns and help people act faster. It should not become the unaccountable owner of decisions the organisation must be able to defend. Recent cases strongly support this point – take the recent Wellington City Council report completed by Deloitte which cost the council $435,000. The ‘Future Fit Poneke’ report claimed 330 excess staff, but the Mayor Andrew Little revealed large chunks of the report were written by AI, and it turned out Deloitte had double-counted current employees with vacant roles and relied on three-year old employment data, overstating staffing costs by $21.5 million.
This is where familiar IM practices can be extended:
- Define the intended use and the situations in which the tool should not be used.
- Record the data sources and conditions on which it depends.
- Document known limitations, risks and performance expectations.
- Decide what evidence of operation must be retained.
- Understand important constructs and how they can inform AI outputs, for example the use of model cards. (1)
We should be able to explain what the system was meant to do, what it actually did and how that was checked.
From reactive custodians to proactive architects
AI gives the IM profession a choice. We can remain reactive custodians, managing records after systems and processes have already been built. Or we can become proactive architects who help shape how information is created, used, governed and evidenced from the start.
That shift requires us to understand AI well enough to engage confidently, frame IM benefits in business terms and propose workable alternatives rather than appearing only at the compliance checkpoint. It also requires technology, risk, privacy, security and business teams to recognise that information expertise is part of successful AI design and governance is jointly owned across these disciplines.
Effective information management is a strategic enabler. Ignore it and AI becomes both a strategic risk and a significant missed opportunity. When AI develops hands, IM needs a seat at the table.
(1) A model card is a standardised document that discloses an AI model’s capabilities, limitations, training data, and intended / unintended uses, so people can evaluate whether its safe and appropriate for their purpose.
Meet your blog author: