When Old Customer Data Is No Longer Enough for New AI
Baca dalam 60 detik
- Banyak perusahaan memiliki data pelanggan melimpah, tetapi izin yang melekat tidak mencakup penggunaan untuk kecerdasan buatan.
- Tumpukan teknologi yang dibangun per departemen memperparah masalah, karena setiap sistem menyimpan versi persetujuan yang berbeda.
- Perusahaan yang mampu menata ulang izin justru dapat memanfaatkan data lebih luas dan mempercepat adopsi AI.

Companies racing to adopt artificial intelligence (AI) are often surprised to discover that the customer data they hold cannot simply be used for new models. Consent collected years ago often covered only specific purposes, so when the same data is redirected for AI purposes, that permission is no longer valid. This is what some practitioners call a data readiness crisis, not merely a technology limitation.
Adam Binks, CEO of Syrenis—a consent management software company—describes this situation from his experience assisting various organizations. He has seen an AI project delayed for months not because a violation was found, but because no one could confirm there was no violation. "I've sat in a room where a campaign or AI project stalled for months, not because there was a problem, but because no one could confirm there wasn't one," he told Newsweek.
A real case came from a retailer that had years of customer contact data and built an AI-based outreach model. Before launch, the company reviewed the consent collected for previous campaigns across several markets. The result: that consent did not cover the new use. "No one did anything wrong—the permission simply wasn't sufficient," Binks said. The retailer then went back to customers with a simple explanation of the new purpose and relaunched with a smaller audience. According to Binks, the results were actually better than the original list.
The main problem, according to Binks, lies in how companies build their IT systems. "The biggest issue in large organizations is that they don't design their technology stack for the customer, but for their own departments, products, and business problems," he explained. As a result, customer data is scattered across platforms—marketing, customer service, business units—plus systems from acquisitions and third parties. Even the definition of a preference can differ: "do not contact" can mean different things for marketing, service, and regulated communications.
When a customer changes or withdraws consent, the update must reach the CRM, marketing platforms, analytics tools, external processors, and other systems. "AI workflows must check the current consent status before using data or taking action, rather than relying on a copy of an old record," Binks stressed. Another complication arises for data that has already entered a model or training process before consent was withdrawn. Companies are required to track where data flows and whether the customer's new choice has been applied across all systems.
Binks gives the example of a system that predicts a customer will churn, then an AI agent changes the offer, initiates contact, or adjusts service. At that point, clear boundaries must be set: what actions may be taken, what information may be used, and when a human must review the decision. Responsibility for this control is spread across privacy, technology, and marketing functions. "What often fails is the space between those functions," he said. "Privacy thinks technology has implemented the rules. Technology thinks marketing understands consent. Marketing thinks the data it receives is safe to use."
"Successful organizations actually use more data, not less, because they can prove what is allowed and stop debating internally." — Adam Binks, CEO of Syrenis
For Indonesia, this issue is increasingly relevant with the enactment of the Personal Data Protection Law (UU PDP), which became fully effective in October 2024. Domestic companies that collect customer data for loyalty programs, promotions, or digital services must now ensure the consent obtained covers AI use. Without adjustment, AI initiatives could be stalled or risk sanctions. On the other hand, financial institutions and e-commerce players that already have large databases could move faster if they can reorganize their consent governance.
Awareness of the importance of AI governance is also reflected in SAP's move to update its global AI ethics policy, with mandatory ethics assessments and human oversight. Meanwhile, HeadFirst Global is consolidating 11 businesses under Vertage to help companies define work based on outcomes and determine the mix of talent and AI agents. These steps signal that the data consent issue is not merely compliance, but a foundation for competitiveness.
Going forward, the question is no longer whether companies have enough data, but whether they have the courage and rigor to reorganize the consent they already have. Without that, massive AI investments could stall in the meeting room, not in the market.



