Public and non-confidential work
Approved public information, general drafting and low-risk productivity tasks.
- Enterprise identity
- Approved tools
- Usage monitoring
AI platform thesis
A practical operating model for moving from promising technology to governed capabilities, adopted workflows and measurable value.
An independent point of view. It does not describe any employer or internal system.The objective is not to maximise the number of AI experiments. It is to repeatedly turn the right opportunities into safe, adopted and measurable outcomes.
Start with the organisation’s strategy
An AI strategy should begin with the organisation’s priorities, the jobs its people perform and the outcomes its stakeholders experience. The model is a design choice later.
BCG connects stronger AI outcomes with a focused portfolio, redesigned processes, workforce enablement and measurement.[Boston Consulting Group, 15 January 2025]
A good strategy narrows the field. It gives the portfolio a clear reason to say yes, wait or stop.
Treat AI as a platform product
Domain products should feel specific to the user. Underneath, they should reuse enterprise capabilities for identity, retrieval, models, tools, evaluation and operations.
I would build the platform through real use cases, hardening each shared capability as more products reuse it.
This is an illustrative enterprise architecture. It does not describe any specific organisation.
Selected layer
Where work happens: relationship-manager tools, operations workbenches, research experiences and specialist applications.
Provide differentiated access
Access should depend on user role, business domain, personal-data access, data sensitivity, approved tools, deployment environment, permitted actions and required human approval.
The model below is illustrative. An organisation would adapt tiers to its classifications, policies and architecture.
Approved public information, general drafting and low-risk productivity tasks.
Internal knowledge and workflows, with domain-based access and stronger data controls.
Strictly bounded use cases in controlled environments with explicit permissions and oversight.
Run a transparent use-case portfolio
A less impressive use case may create more value when it is easier to adopt, safer to operate or builds capabilities the organisation can reuse.
Scores should expose assumptions. They should never replace accountable judgement.
Change the weights. Use cases move as the portfolio's priorities change. All scores are illustrative.
A score is a decision aid, not a decision. Portfolio review still needs evidence, judgement and accountable owners.
Build governance into delivery
Governance that appears only at final approval is both late and inefficient. Important decisions about data, models and actions have already been made.
NIST’s cross-sector profile turns generative-AI risk into actions for governing, mapping, measuring and managing the lifecycle.[National Institute of Standards and Technology, 26 July 2024; updated 8 April 2026]
Agentic AI makes runtime controls more important. The system needs to know what a user can see, what an agent may do, which tools it may invoke and when a human must approve.
McKinsey’s 2026 global survey connects stronger outcomes with workflow redesign, leadership commitment and operational rigour.[McKinsey & Company, 25 August 2026]Treat adoption as part of the product
Teams need to understand the existing workflow, design the new one, equip users and stay accountable after release.
“Deploying an AI tool is not the same as changing how work gets done.”
Measure and scale
A use case needs a baseline before launch, product and operational measures after launch, and a clear review rhythm.
The decision is explicit: stop, improve or scale. Platform reuse and evaluation performance matter alongside business outcomes.
The evidence does not support further investment.
The problem is valid; the product or control needs work.
Outcome, adoption and operations are ready to expand.
Evidence base
Selected primary and institutional sources. The full bibliography is available on the sources page.
Continue the conversation
If you are building an enterprise AI capability in a regulated environment, I would be glad to compare perspectives.