Every company wants to use artificial intelligence. According to the TIC Empresas 2025 survey from Cetic.br, published in August this year, only 17% of Brazilian companies had actually used any artificial intelligence technology — and that share swings hard with size: 15% among small companies, 32% among mid-sized ones, and 50% among large ones.
The gap is not about interest. An artificial intelligence tool only delivers on its promise when it lands on a foundation that is already in place: organized data that is easy to find, access defined by person, equipment and a network that run without falling over, and someone responsible for keeping all of it working. Without that foundation, a company buys the tool, activates the license, and finds out months later that the problem it wanted to solve is still exactly where it was.
A study from IBM on the cost of a data breach, conducted with the Ponemon Institute, shows the size of the risk in skipping that step: among organizations that had an incident tied to artificial intelligence, 97% lacked adequate access control over the tools involved, and 63% had no defined policy for using them at all. It was not the artificial intelligence that failed. It was the foundation that was not ready.
Where the Foundation Usually Falls Short
In a typical small or mid-sized company, the scene looks something like this: a supplier contract is saved in three different folders, each with its own version, and nobody is quite sure which one is current. Access to the financial system is the same for everyone, because setting up a separate login for each person "is too much work." Half of what the company knows about its own processes lives in the heads of two or three people, and the network drops with a regularity that has become an office joke.
None of these problems were created by artificial intelligence — they existed long before, and the company lived with them because the damage seemed manageable. What changes is that an artificial intelligence tool, to work well, needs exactly what is missing: it reads whatever data exists (if it is scattered and outdated, the result will be too), it inherits the access level of whoever is using it (if access is unrestricted, its answers come back unrestricted too, with no filter), and it depends on a stable network to respond on time.
The Cetic.br survey helps measure that gap. Only 53% of Brazilian companies with internet access have a formal digital security policy — the document that defines, among other things, who can access what. Among small companies, that figure drops to 49%; among large ones, it climbs to 88%. In other words, much of the same group of small companies that has not yet put access rules on paper is the group most likely to say it plans to use artificial intelligence next year.
The Center for Internet Security, which maintains one of the most widely used sets of security controls in the world, treats the first two steps as a prerequisite for any other technology project: knowing what the company has — equipment, systems, cloud services — and knowing who can access each one. It is not the sixth or tenth item on a security checklist. It is the first and the second.
Why Buying the Tool Does Not Solve It on Its Own
The common path into artificial intelligence is to buy a license, turn on the assistant inside a system the company already uses, and hope it "tidies up the house" on its own. It does not. An artificial intelligence tool organizes what the company has already organized, or at least labeled — it has no way of knowing that the contract in folder X is outdated and the one in folder Y is the current version, because that information was never written down anywhere before the tool arrived.
There is another side to the same coin, and it is the more serious one: attackers also use artificial intelligence, and they use it specifically to find the gaps a company never closed. The State of Ransomware 2026 report from Sophos, based on more than two thousand security leaders across 17 countries, calls this out directly: artificial intelligence is speeding up how fast software flaws are discovered and exploited, and 62% of ransomware victims in the survey pointed to a known or unknown security gap as part of what made the attack possible.
Put another way: the same gap that slows down a company trying to use artificial intelligence to grow is what speeds up an attacker trying to use artificial intelligence to break in. A disorganized foundation does not sit neutral while the company decides whether to buy the tool — it stays an easier target the whole time.
What Has to Be in Place
Before any artificial intelligence tool enters the company, a handful of mechanisms need to already be standing — the same ones that support any well-run IT operation, with or without AI:
Organized data with an owner. Every important piece of information — a contract, a customer record, a cost spreadsheet — has a clear place and a person responsible for keeping it current. Two versions of the same document in different folders is a sign that nobody owns that job.
Access by person, not blanket access. Each employee sees what their role requires, no more and no less. When someone leaves the company, their access leaves with them — the same day, not "whenever someone remembers."
Equipment and a network that do not go down every week. A tool that freezes or drops connection mid-use saves no time at all; it disappears the hard way and comes back the frustrating way.
An inventory of what the company owns. Knowing how many computers, systems, and cloud services exist — and who uses each one — is what lets a problem get fixed before it turns into a full investigation.
Backups that are actually tested. It is not enough for a backup to exist; someone needs to run a recovery drill from time to time, to know it will work on the day it actually matters.
Someone responsible for running all of it. Network, access, backup, and inventory do not maintain themselves. A person or a team needs to own that upkeep, whether in-house or contracted.
This is how Skills IT works: mapping out the inventory of what a client has, setting access by person instead of blanket access, and testing backup recovery before it ever has to count for real. A similar problem, born at home, is what led to Skyller, the artificial intelligence platform Skills IT built first for its own operation — manual work repeated client after client, and environment knowledge that lived only in the heads of whoever had been on the team the longest — before it became a product.
The Payoff Once the Foundation Exists
The payoff of fixing the foundation first is not abstract. A company with organized data, per-person access, and a stable network spends less staff time hunting for information and less time fixing the same problem twice. When the artificial intelligence tool finally arrives, it works from day one, instead of demanding months of "adjustment" that, in practice, is the company organizing behind the scenes what should have been ready already.
There is also a payoff that only shows up when it is missing: a company with controlled access and an up-to-date inventory reacts faster when something goes wrong, because it knows exactly what that system or that account could reach. That holds true for a technical problem and for a security incident alike — the difference between fixing it in an afternoon and spending a week reconstructing what happened.
And there is a direct financial payoff: money that stops going toward rework, toward a tool license nobody uses properly because the data behind it is poor, or toward an incident that costs more precisely because the company did not know who had access to what.
Five Questions Before Buying the Next AI Tool
Before signing the next artificial intelligence contract, it is worth pausing to ask:
- Where is the data this tool will use, and who owns it? If the answer is "scattered across several folders, nobody is quite sure," the tool will inherit that mess.
- Who has access to the system this tool will connect to? If the answer is "everyone," the tool's reach will be everyone's too.
- Can the network and equipment handle daily use without going down? A tool that freezes mid-shift saves no time.
- Is there an inventory of what the company owns? Without knowing what exists, there is no way to know where the tool will, or will not, reach.
- Who will be responsible for running this after the purchase? A tool with no owner turns into one more forgotten system within a few months.



