Kelvin Cheema is a Global CIO and transformation executive advising boards on technology, AI, transformation and enterprise value creation.
I have spent much of my career leading technology and transformation programs where protecting data was treated as a fundamental part of good governance. We controlled who could access it, where it could move and how it could be used. AI has made me question whether that boundary is still sufficient.
The question I believe boards, CIOs and private equity investors now need to confront is not simply who owns the data but who owns what an AI system learns from it.
That distinction matters because AI can separate learning from its original source. Information may remain inside one company while a model, agent or knowledge system carries forward a pattern learned from it. For private equity, that creates both an opportunity and a governance problem.
When The Data Stays But The Learning Travels
Private equity already transfers knowledge between investments. Operating partners recognize patterns. Executives reuse successful interventions. Technology architectures are compared. Lessons become playbooks. I have seen the value of this kind of institutional learning in transformation. The second time you encounter a problem, you should be better equipped to solve it than the first. AI can industrialize that advantage.
Imagine a system exposed to multiple transformations across a portfolio. Over time, it could learn which interventions tend to fail, which technology investments produce returns, where programs repeatedly lose momentum or which operational signals precede deteriorating performance. Company A’s documents do not necessarily have to be handed to Company B for something valuable to travel between them. The learning can travel instead.
That is where I think conventional information governance starts to become inadequate.
Access Control Does Not Answer The New Question
Most enterprise governance was designed around access. Who can see this information? Who can change it? Where is it stored? Who received it? Those controls remain essential, but AI introduces different questions.
What was the system permitted to learn? What may it retain? Which inferences can be reused? Where may those inferences travel? When must learning remain inside one company? When should models, agents or knowledge stores themselves be separated?
This is not theoretical. The OECD’s 2026 work on information sharing highlights how digital tools, data-sharing arrangements and algorithmic systems can create new competition risks. European Commission guidance also recognizes that commercially sensitive information can be exchanged indirectly, including through shared optimization algorithms.
But I do not think regulation alone will solve this problem. Many of these boundaries will ultimately be determined by technology architecture. That makes them CIO questions as much as legal questions.
In my view, portfolio intelligence needs four clear classifications:
1. Company intelligence belongs within the operating context of an individual business.
2. Sponsor intelligence is expertise legitimately developed through investment, ownership and governance.
3. Reusable intelligence consists of methods, patterns and lessons that can legitimately improve execution elsewhere.
4. Restricted intelligence is knowledge whose confidentiality, competitive sensitivity, contractual position, intellectual property or regulatory treatment limits its reuse.
The difficult territory is the boundary between reusable and restricted intelligence. AI makes that boundary much easier to cross without anyone consciously deciding to cross it.
Adding Decision Lineage To Data Lineage
This is where I believe technology governance needs to evolve. For years, CIOs have invested in data lineage. We want to understand where information originated, how it moved and how it changed. With AI, I would add another requirement: decision lineage.
If an AI-generated recommendation influences a material business decision, I want my team to be able to answer some basic questions: What caused the system to know what it knows? Where did that learning originate? Was the system entitled to reuse it? Who received the resulting recommendation? Who decided to act on it? Whose interests was that person responsible for protecting?
If you cannot answer those questions, you may understand your data architecture without truly understanding your decision architecture.
That distinction becomes particularly important in private equity. A learning generated inside one portfolio company may be extremely valuable to another. But value does not automatically create permission. I would therefore be cautious about building enormous portfolio knowledge repositories and simply putting increasingly powerful AI on top. Sometimes the more intelligent architecture will be the one deliberately designed not to learn everything.
Governed Memory Could Become A Competitive Advantage
None of this weakens the case for portfolio intelligence; I think it strengthens it. A private equity firm capable of remembering why transformations failed, which commercial interventions worked, where technology investments delivered returns and which operational patterns repeatedly preceded problems could shorten the distance between experience and execution. That is potentially a formidable advantage.
AI gives firms the opportunity to turn institutional experience into institutional memory. But I would not judge the sophistication of that capability by how much the system knows. I would judge it by whether you can establish what the system was permitted to learn, what it may retain, where that learning may travel and who remains accountable when it influences a decision.
That requires CIOs, investment teams, operating partners, legal teams and boards to make those choices deliberately. They should not be accidental consequences of architecture.
Private equity has spent years becoming better at transferring operating capability across portfolios. AI gives it the opportunity to transfer learning at an entirely different scale. The firms that get this right may not be those whose systems know the most. They may be the ones that know what their systems have the right to remember.
Because the next governance boundary may not be where the data moves. It may be where the learning does.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

