ITTech Pulse Exclusive Interview with John Peluso, Chief Technology Officer, AvePoint
Stay updated with us
Sign up for our newsletter
John Peluso, Chief Technology Officer at AvePoint, discusses how AI governance, data protection, and intelligent resilience are becoming the foundation of trusted enterprise AI adoption.
You started as a software trainer in 1996 and are now CTO of a global AI data protection company. What was the turning point that shifted your path from training to product and technology leadership?
In many ways, I’m the same kind of professional I started out as — someone looking to solve problems. Software was always a means to an end for me, not the end itself. I started as a software trainer helping people work more effectively, and that problem-solving mindset gradually pulled me deeper into how technology enables business. I joined AvePoint in 2010 as a Technology and Training Specialist, and over sixteen years — through the company going public and expanding globally — I grew into the CPO role and then CTO in 2023. The throughline has always been the same: find a better way. If anything, AI is the logical evolution of a thirty-year trend toward giving people more agency over technology. That’s what still drives me today.
You’ve gone from Technology Specialist to CTO within the same company over 16 years – rare in tech. What kept evolving for you at AvePoint that made you stay and grow?
Going from technology specialist to CTO at the same company over sixteen years is rare in tech — I know that. But the thing that kept me here is the same thing that drew me in: AvePoint’s agility. From day one, this was a place that made decisions quickly and changed them just as fast when the evidence called for it. It’s always rewarded people who think differently and don’t get stuck on one path. That environment isn’t for everyone, but it’s exactly right for me. AvePoint started as a two-person operation out of a public library in New Jersey. Today we have over 28,000 customers worldwide. My story may be unusual for the industry, but at AvePoint, it’s really not — people here have always had room to grow in meaningful ways.
Read More: ITTech Pulse Exclusive Interview with Dean Valentine, CEO and Co-founder of ZeroPath
Moving from CTO of AvePoint Public Sector to company-wide CTO is a significant leap. What did leading government and federal customers teach you that now shapes how you build for the broader enterprise?
The biggest thing I took from working with government and federal customers was empathy — genuine empathy for the unique situation of every organization. Commercial companies are relatively easy to read: grow, profit, advance. Public sector is different. It’s about service, not growth. And it comes with layers of complexity, regulation, and bureaucracy that may look irrational from the outside but are very real to the people living inside them.
That experience trained me to pause and truly understand a customer’s situation before acting — to never assume I know their constraints from the outside. I carry that discipline into how I approach building, both internally and for customers, today. Every organization has complexity that isn’t immediately visible, and the best solutions always come from understanding it first.
AI agents are moving from analysis to autonomous action fast. What’s the biggest governance gap you see organizations missing as they deploy agents at scale?
The governance gap comes down to context. When you look at a person in your organization, you know their department, their business unit, their role. That doesn’t predict everything they’ll do, but it gives you a strong baseline — purpose, likely work, the data they should be touching. Comparing that against actual behavior makes risk visible. AI agents, even as we increasingly think of them as a new kind of employee, don’t come with those same designations. They have no org chart entry, no profile — at least not by default.
What we’re working to give organizations is exactly that: business context for their agents — purpose, intended scope, and the ability to apply proper policy against each one based on what it’s actually meant to do. In practice, that becomes an AI trust layer: the governance, security, and data protection controls that sit between agents and the information they act on. That means deeper visibility into what data agents can access, enforcing role-based controls specific to AI use cases, and ensuring sensitive content is properly labeled before agents ever touch it. Our research shows 88.4% of organizations had at least one agent-related security incident in the past year, even as nearly half of employees now rely on agents daily or weekly. Adoption is clearly outpacing governance — and that’s the gap we’re focused on closing.
You’ve said disruption no longer hits a single workload – it cascades. How did that thinking lead to the Minimum Viable Company framework, and why does it matter more now than traditional backup?
The concept of Minimum Viable Company (MVC) is designed to simplify and standardize how organizations address disruptions in security and data operations, like ransomware attacks, outages, tenant compromise, etc. Restoring data in these scenarios is critical, but so is restoring regular business operations, so a company’s people can continue working.
Disaster recovery has historically focused on recovering data first and restoring services to customers and stakeholders second. MVC homes in on the smallest set of people, systems, and data that must be restored for the organization to function. It’s not about restoring everything at once, but restoring your most critical data first, in the right order, so the business can continue to function.
Traditional access controls were built for humans. How does governing an AI agent’s permissions differ fundamentally – and why can’t organizations just apply existing policies?
AI agents can now perform many common business tasks with human-like competency, but that doesn’t mean that they process information or reason the same way that a human does, which is why they need a unique kind of control. Without strict access guardrails and “human-in-the-loop” design, agents can quickly cause widespread chaos because, while they’re remarkably competent, they can’t reason their way out of making certain mistakes—like sharing confidential information, for example.
Traditional RBAC don’t always work to govern agents, as they can easily identify alternative paths within the data environment to accomplish their goals. AI agents should be treated as low privilege across the organization and only be provided access to a certain subset of data to work with to ensure that their outputs are accurate and useful.
Read More: ITTech Pulse Exclusive Interview with Nicholas Janouskovec Global Cybersecurity Business Development Manager at Emerson
With 51% of partners citing governance as their primary hurdle, how real is the shadow AI threat today and are businesses underestimating it?
Especially with the introduction of agents, shadow AI is a fast-growing problem, and like its name, it’s proliferating in the shadows: outside of the security team’s view. Left ungoverned, AI agents can produce outputs based on sensitive files, outdated documents, and duplicate data, producing hallucinations and inappropriate outputs, and also inadvertently sharing information that should have strict access controls.
This is a real and growing blind spot. Our newest research shows 21.1% of organizations don’t even know whether employees are using unsanctioned tools to build AI agents in the first place. That’s a visibility gap that’s nearly tripled year-over-year for generative AI tools overall, from 6.3% to 17.6%. You can’t govern what you can’t see.
On the other hand, Shadow AI exists within human workflows as well. Employees may be leveraging unauthorized AI tools to get their work done (and in many cases providing these LLMs with sensitive information), that leadership isn’t even aware of. AI policies need to evolve past static, one-time documents – and be constantly updated, iterated on and circulated to reflect how AI is actually being used across the organization.
Multicloud complexity keeps growing. Where does AI-driven governance automation go in the next two years and what manual processes will it fully replace?
AvePoint’s recent research report, conducted in partnership with Omdia, found that multi-tenant complexity is currently limiting automation and AI initiatives for 40% of MSPs. As multi-cloud environments continue to increase in complexity (as AI is layered into the tech stack), organizations need tools that can not only provide deeper visibility into data protection and management across different cloud environments, but platforms that can leverage AI to advance active enforcement and accelerate adoption and automate unique compliance considerations.
It’s also worth noting that AI-generated data itself is becoming a governance problem. Our latest report found 35.5% of enterprise data is now AI-generated, and that’s expected to hit 42.1% within a year. Governance automation over the next two years has to account for that, not just where data lives, but where it came from.
Thank you, John Peluso, for taking the time to share your insights with us.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.
John Peluso is AvePoint’s Chief Technology Officer. In this role, he aligns the Company’s technology and product roadmaps to grow AvePoint’s market share, and accelerate the ideation, development, and launch of innovative software products tailored to anticipate customer needs. Prior to this role, John held multiple leadership roles over his 16-year tenure at AvePoint, including Chief Product Officer, SVP of Product Strategy, Director of Education, and Chief Technology Officer, Public Sector.
AvePoint is the global leader in data protection, unifying data security, governance, and resilience to provide a trusted foundation for AI. More than 28,000 customers rely on the AvePoint Confidence Platform to secure, govern, and rapidly recover data across Microsoft, Google, Salesforce, and other cloud environments. With a single platform for lifecycle control, multicloud governance, and rapid recovery paired with clear ownership across the business, we prevent overexposure and sprawl, modernize legacy and fragmented data, and minimize data loss and interruption. Our global partner ecosystem includes approximately 6,000 MSPs, VARs, and SIs, and our solutions are available in over 100 cloud marketplaces. To learn more, visit www.avepoint.com.