AI Fluency Without AI Literacy Is a Governance Problem Waiting to Happen
Mario Martins argues that enterprise AI adoption is moving faster than the access controls, data practices, and governance models needed to manage it safely.

Make AI Data Press one of your go-to sources on Google
People use AI and create things with AI, but they don’t always stop to think about how AI actually works.

Companies don’t need much convincing that AI can make employees faster. The harder question is what happens once those tools become part of everyday work, without the rules around access, oversight, and data use keeping pace.
Mario Martins, Founder of Lumera, has more than 20 years of experience in technology, including nearly 15 years at BTG Pactual, where he rose through leadership roles to Associate Partner. He brings that experience across financial services, asset management, and highly regulated enterprise environments to the AI workshops he runs. The sessions combine practical AI use with a closer look at what changes around governance, access, and oversight as the technology takes on a larger role in everyday work.
“We’re at a unique moment because we have enormous processing power, companies have access to large amounts of data, and we have new ways to process that data,” he explains.
The AI learning curve starts with understanding the technology
Martins starts every workshop by establishing the importance of AI. Before showing participants a tool or asking them to build anything, he frames the moment around a convergence of computing power, data, and new ways to process it. He asks: “Why AI? Why is everyone talking about AI? Why is this a special moment for the technology and for enterprise efficiency?”
AI brings a different set of priorities than the cloud migration wave, when enterprise technology discussions focused largely on scalability, resilience, and infrastructure. The risks are different too. Martins describes AI as a genuinely disruptive technology and argues that adoption is moving faster than many organizations’ understanding of what happens beneath the interface. “The launch of GPT was significant, but people often don’t pay enough attention to security, LGPD, or other aspects of these interactions,” he notes.
To expose that gap, Martins leads with a question. “If someone asks GPT who the first president of the United States was, how does the model actually produce the name on the screen?” Most participants don’t know. Some assume it searches Google, while others imagine someone at OpenAI is somehow supplying the response. “People use AI and create things with AI, but they don’t always stop to think about how AI actually works,” he argues.
“I say, ‘Give me your worst task. Give me the boring task.’” Someone in finance or operations might point to a spreadsheet they have to check. “So we put the spreadsheet into GPT or Copilot, explain the task, and automate something that might otherwise take much longer in five minutes,” Martins explains. That’s often when the value of AI stops feeling abstract. “People say, ‘Okay, now I understand the efficiency.’”
Sensitive data as a governance and control issue
When talking about governance to the workshop participants, Martins likes to use basic examples that show how easily people can expose sensitive information. One comes from his family. “My mother uses GPT. She took her medical exam results and put them into GPT,” he says. “Why? Because she wanted it to tell her about her health. But you still need a doctor to analyze those results properly.”
People are comfortable giving AI systems information they would normally treat as sensitive, often without knowing what happens to that data after they submit it. The same behavior becomes more consequential inside a company. “Imagine a company blocks AI and says nobody can use it. An analyst can still take out their phone, take a picture of their screen, and send it to ChatGPT,” Martins explains. “That’s a problem because company data can end up in public AI systems and public LLMs.” A ban, in other words, doesn’t eliminate the behavior. It can push it outside the systems an organization can monitor.
AI turns nominal access into operational reach
The framework leads into a broader concern Martins sees inside enterprises. The biggest governance risk, in his view, isn’t always a new vulnerability created by AI. Often, AI exposes weaknesses in access control that were already there. “There have been cases in AI research where models operating in a contained environment found ways to reach outside that environment to obtain information,” he says. “For me, that illustrates a broader problem, and I think it applies to companies as well.”
"Imagine that an employee technically has access to the company's salary list," he explains. "That's a problem if he isn't supposed to have that information." For a human, reaching that information still requires deliberately navigating into a specific SharePoint location and searching for the right file, and most people who could look never bother. An AI agent with the same access and no security or governance constraints could retrieve that information from systems across the company without the same friction. "A human might try once, twice, or three times and then stop. AI can potentially try many more paths and combinations until it finds the information", Martins argues.
The three models of human-AI collaboration
Once participants understand the risks of using AI without clear boundaries, Martins turns the question back on them. How much of their work are they actually handing over to AI, and how closely are they working with it? “Sometimes I talk about the Boston Consulting Group study where they discuss cyborgs, centaurs, and delegated AI tasks,” he explains.
Delegation sits at one end of the spectrum. “With delegated AI, a person gives the entire task to AI. I can’t necessarily control it, audit it, or ensure compliance,” Martins says. “I send the task to AI, and AI does it.”
The centaur model keeps the division of labor clearer. A person might remain responsible for answering emails, for example, while AI handles research, review, or another defined part of the process. “You delegate part of the work to AI, but the responsibilities remain clearly separated.”
With the cyborg model, that boundary becomes much harder to see. “The use of AI is very intrinsic to the person’s work,” Martins says. “The person and AI are working together so closely that it can sometimes become difficult to distinguish which parts were done by the person and which were done by AI.”
Martins finds the cyborg model the most promising because it combines existing expertise with AI instead of simply transferring responsibility to the technology. He points to a colleague who is highly skilled with Excel formulas but has never learned VBA or Python. “If that person is already a strong professional and they combine their expertise with AI while doing the same work, the result can be fantastic,” he notes.
The agent era will redefine enterprise access
Teaching employees how to use AI is only part of the job. Organizations also need to understand where their existing permissions, data practices, and governance models assume a human will be the one guiding the system. As AI becomes more deeply embedded in everyday work, those assumptions become harder to rely on.
The same tools that can help an experienced employee work faster can also make it easier to reach information that was technically accessible but practically difficult to find. That makes access control a more immediate part of AI adoption, especially as companies move from assistants toward agents that can operate across multiple systems. “Access security is already a problem inside companies, and AI has the potential to make that problem much bigger,” Martins concludes.




