The objective is not to maximise the number of AI experiments. It is to repeatedly turn the right opportunities into safe, adopted and measurable outcomes.

01

Start with the organisation’s strategy

AI is a means. The outcome comes first.

An AI strategy should begin with the organisation’s priorities, the jobs its people perform and the outcomes its stakeholders experience. The model is a design choice later.

BCG connects stronger AI outcomes with a focused portfolio, redesigned processes, workforce enablement and measurement.[Boston Consulting Group, 15 January 2025]

01Customer and stakeholder outcomes
02Employee effectiveness
03Revenue growth
04Operational efficiency
05Risk reduction
06Service quality
07Strategic differentiation

A good strategy narrows the field. It gives the portfolio a clear reason to say yes, wait or stop.

02

Treat AI as a platform product

Build once. Learn repeatedly. Reuse deliberately.

Domain products should feel specific to the user. Underneath, they should reuse enterprise capabilities for identity, retrieval, models, tools, evaluation and operations.

I would build the platform through real use cases, hardening each shared capability as more products reuse it.

Interactive reference model

One platform, five connected layers

This is an illustrative enterprise architecture. It does not describe any specific organisation.

01

Selected layer

User experiences and domain applications

Where work happens: relationship-manager tools, operations workbenches, research experiences and specialist applications.

  • RM workspace
  • Operations console
  • Knowledge assistant
03

Provide differentiated access

The same AI environment should not serve every task.

Access should depend on user role, business domain, personal-data access, data sensitivity, approved tools, deployment environment, permitted actions and required human approval.

The model below is illustrative. An organisation would adapt tiers to its classifications, policies and architecture.

Tier 1

Public and non-confidential work

Approved public information, general drafting and low-risk productivity tasks.

  • Enterprise identity
  • Approved tools
  • Usage monitoring
Tier 2

Internal business information

Internal knowledge and workflows, with domain-based access and stronger data controls.

  • Role and domain access
  • Data-loss controls
  • Human review
Tier 3

Sensitive personal or regulated data

Strictly bounded use cases in controlled environments with explicit permissions and oversight.

  • Need-to-know access
  • Restricted tools
  • Approval & audit trail
04

Run a transparent use-case portfolio

Prioritisation is a set of visible trade-offs.

A less impressive use case may create more value when it is easier to adopt, safer to operate or builds capabilities the organisation can reuse.

Scores should expose assumptions. They should never replace accountable judgement.

Interactive model

Make the trade-offs visible

Change the weights. Use cases move as the portfolio's priorities change. All scores are illustrative.

Criterion weight
Selective bets
Prioritise
Stop or reshape
Quick foundations
Weighted value →Weighted readiness →Case prepPolicyExceptionsResearchIncidents

A score is a decision aid, not a decision. Portfolio review still needs evidence, judgement and accountable owners.

05

Build governance into delivery

Controls should operate with the product.

Governance that appears only at final approval is both late and inefficient. Important decisions about data, models and actions have already been made.

NIST’s cross-sector profile turns generative-AI risk into actions for governing, mapping, measuring and managing the lifecycle.[National Institute of Standards and Technology, 26 July 2024; updated 8 April 2026]

Safe executionby design
01Identity02Access controls03Data handling04Tool permissions05Model selection06Human review07Prompt and workflow versioning08Evaluations09Monitoring10Incident response11Vendor management12Audit trails

Agentic AI makes runtime controls more important. The system needs to know what a user can see, what an agent may do, which tools it may invoke and when a human must approve.

McKinsey’s 2026 global survey connects stronger outcomes with workflow redesign, leadership commitment and operational rigour.[McKinsey & Company, 25 August 2026]
06

Treat adoption as part of the product

Deployment is not behaviour change.

Teams need to understand the existing workflow, design the new one, equip users and stay accountable after release.

“Deploying an AI tool is not the same as changing how work gets done.”

01Workflow discovery
02Role-based training
03Local champions
04Communication
05Onboarding
06Feedback loops
07Usage analytics
08Support
09Workflow redesign
10Change management
07

Measure and scale

Evidence decides what happens next.

A use case needs a baseline before launch, product and operational measures after launch, and a clear review rhythm.

The decision is explicit: stop, improve or scale. Platform reuse and evaluation performance matter alongside business outcomes.

OutcomeUsage is a signal. Value is the result.
BaselinesAdoptionActive usageTask completionTime savedQualityUser satisfactionRevenue influenceRisk reductionCost to serveEvaluation performanceReusable components
01Stop

The evidence does not support further investment.

02Improve

The problem is valid; the product or control needs work.

03Scale

Outcome, adoption and operations are ready to expand.

Evidence base

Research behind the thesis.

Selected primary and institutional sources. The full bibliography is available on the sources page.

McKinsey & Company25 August 2026

The state of AI in 2026: On the road to ROI

Original source
Boston Consulting Group15 January 2025

From Potential to Profit: Closing the AI Impact Gap

Original source
National Institute of Standards and Technology26 July 2024; updated 8 April 2026

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

Original source

Continue the conversation

Let’s discuss the mandate directly.

If you are building an enterprise AI capability in a regulated environment, I would be glad to compare perspectives.