Answer
A useful first step is data classification: sorting sources into what is already safe for broad internal use, such as published documentation and approved reports, versus what carries sensitivity, such as customer financial records, employee data, or anything covered by a compliance requirement. Well-governed sources tend to have a clear owner, a defined update process, and an existing access control model the AI workflow can inherit rather than reinvent. Curated ticket histories and knowledge base content are good early candidates precisely because someone already reviews and maintains them.
When production data genuinely needs to enter the workflow, it is safer to work from a read-only extract or replica of Db2 for i data rather than connecting an AI tool directly to live transactional files, since that limits blast radius and keeps the AI workflow from competing with production jobs for system resources. Buyers should also read the vendor's data retention and training terms closely, specifically whether prompts or outputs are stored, for how long, and whether the vendor uses customer data to train their own models, since those answers vary widely and matter more than the tool's feature list.