All briefings
AI GovernanceRegulation

Scaling AI safely: what leadership should expect

By Marcin Pajdzik ·

AI can enter an organisation through several routes at once. Teams run their own pilots, suppliers add AI features to software the organisation already licenses, and staff use public AI services in their daily work. Where each route develops separately, leadership may be unable to say what AI is doing in the business, who approved it, what it costs and who is accountable when it produces a wrong or harmful result.

We use "AI factory" to describe a shared capability for assessing, delivering and operating AI use cases under common governance. It gives the organisation's use of AI a governed route, so that use can grow and remain under control.

How an AI factory works

The capability has four parts, each with a named owner.

Secure foundation. The foundation controls who and what can reach the organisation's data and models, and records activity. The foundation enforces which AI services people and systems can use, for which approved tasks and data.

Delivery. A delivery process takes each use case through defined decision points, from an assessment of its value and risk through to build, testing and launch.

Operations. Operations monitor live use cases for quality, cost and security, and retire them when they no longer serve their purpose.

Governance. Governance sets who may approve a use case, how its risk is classified, and where a person must review or authorise what the AI does.

The same governance covers AI bought as a service or enabled in software the organisation already uses. For purchased AI, supplier assurance covers the provider's development and operating practices. The organisation still tests the configured service against its intended use, data permissions and acceptance criteria.

Why it matters to the business

Investment follows evidence of value. Before funding delivery, each use case needs a business owner, a measurable benefit, an estimate of its full operating cost and criteria for continuing or stopping. Full cost includes integration, evaluation, human review and support, alongside the charges for the AI service itself. The delivery process then gives each pilot a route to production and a point at which it stops if the case for it does not hold. Components built for earlier use cases, such as approved models, data connections and controls, can shorten delivery for later ones.

Risk is assessed before launch. AI systems can expose confidential data, produce confident but incorrect output, or act beyond what their owners intended. Controls on data access, testing before launch and monitoring afterwards address those risks at the points where they arise.

Costs are visible and owned. Where AI services are charged by usage, costs can rise quickly as adoption spreads. Attributing those costs to the use cases and business units that incur them lets leadership weigh each one against the value it delivers.

Dependence on one provider can be reduced. AI models and providers continue to change. A foundation designed for portability can reduce dependence on one provider. Alternative models are evaluated against the use case's quality, security and cost requirements before adoption.

What it makes possible

The same foundation supports different applications. The risk of each depends on its context, the consequences of an error, the permissions it holds, the scale at which it operates and the oversight around it.

Approved AI services for everyday work. Staff draft, summarise and analyse with AI services approved for those tasks and the data involved, through access the organisation controls and with protections for the data they enter. A sanctioned option also gives people an alternative to public services the organisation has not approved.

Assistants that draw on internal knowledge. An assistant answers questions from the organisation's own policies, contracts or technical documents. Access controls must preserve each user's permissions when information is retrieved and used to generate answers.

Support for document-heavy processes. AI can extract, classify and draft across contracts, correspondence and case files, with a person reviewing the output before it affects a customer, an employee or a decision.

Software development assistance. Engineers use approved coding assistants, and generated code is reviewed and tested under the organisation's existing controls.

Agents that act in other systems. Agents introduce risks through the permissions and autonomy they receive. An agent that can update records, send messages or start transactions is given only the permissions its task needs, its actions are recorded, and a person approves anything above a defined threshold.

Governance that lets AI scale

Governance starts with an inventory of AI use across the organisation, including tools adopted without formal approval, so the organisation knows what it is governing. Each use case is then classified by risk, and the classification sets the approvals, testing and human oversight it needs. Human oversight depends on reviewers with the competence, information and authority to challenge, override or stop the system, and that capability is established and tested before launch. Evaluation continues after launch, because a model's behaviour can change with new data, new versions or new ways of using it.

Applicable duties depend on the use case, jurisdiction and the organisation's role. Governance should translate them into approval requirements, oversight arrangements and evidence, alongside the organisation's own assessment of business risk.

What the board should see

The board should receive a consolidated view of AI adoption, benefits, costs and risk, with detail on material use cases, significant incidents and decisions requiring its attention. Benefits are reported against those expected when the investment was approved. Management maintains the complete inventory, with a named owner and risk assessment for each use case, and exceptions to the agreed rules have named owners and review dates.

Questions for the board

  • Do we know where AI is used across the organisation, including tools adopted without approval?
  • Who owns each AI use case, and who approves new ones?
  • What does each use case cost in full, and what benefit has it delivered against what was expected?
  • Which AI services are approved for which tasks and data, and how are those restrictions enforced?
  • How do we know that live AI systems continue to perform as intended?
  • Where must a person review or approve what the AI does, and are those reviewers able to challenge or stop it?
  • Who can suspend an AI service when it behaves unexpectedly, and how will the business continue without it?
  • Which regulatory duties apply to our AI use, and who is accountable for meeting them?

Epitechnic's Enterprise AI Factory service builds the foundation, delivery process, operations and governance together, with a named owner for each, and advises independently of model and cloud providers. An AI Readiness and Governance Review establishes where AI is already in use across your organisation, what governance it lacks and what to build first.

References

  • National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023.
  • National Institute of Standards and Technology, AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024.
  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system.
  • OWASP, Top 10 for Large Language Model Applications, 2025, including Excessive Agency and Vector and Embedding Weaknesses.
Start the conversation

Facing this in your organisation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.