vikramgrover.com A companion publication
VGInsights · Vikram Grover

Piece 01  ·  Operating Models & Governance

Enterprise AI Is an Operating-Model Decision, Not a Tool Decision

Why sustainable enterprise AI depends less on selecting a model — and more on ownership, architecture, governance and measurable value.

In brief

  • Model selection is downstream of the operating model. Decide ownership, architecture, governance and economics first — the tools will change beneath you.
  • Most AI programs stall not because of the model, but because of unresolved decisions on data, integration, controls, and how value gets measured.
  • A practical 90-day agenda: establish visibility, define the operating model, and prove it on two or three high-value use cases before scaling.

Generative AI discussions often begin with a familiar question: which platform or model should we choose? Microsoft Copilot or a custom solution? OpenAI, Anthropic Claude or Google Gemini? A managed cloud service or an open-weight model deployed in an enterprise-controlled environment?

These are important decisions — but they are not the first decisions an enterprise should make.

The more consequential question is: how will the organization convert AI from a collection of experiments into a governed, scalable and economically sustainable enterprise capability?

That is an operating-model question.

Technology choices will continue to change. Models will improve, costs will shift and new platforms will emerge. An effective operating model gives an enterprise the ability to adopt those changes without repeatedly redesigning its governance, architecture and delivery approach.

The executive question

Enterprise AI is not simply another technology implementation. It introduces new decisions across business ownership, data, risk, architecture, talent and economics.

Executives need clarity on questions such as:

  • Which business outcomes justify AI investment?
  • Who owns the enterprise AI portfolio?
  • What should be centralized and what should remain within business units?
  • How will use cases move from experimentation into production?
  • Which data can models and agents access?
  • How will accuracy, security and regulatory risk be evaluated?
  • How will AI connect with existing ERP, CRM, data and operational platforms?
  • How will the organization measure value and manage consumption cost?
  • Who remains accountable after an AI capability is deployed?

If these questions are unresolved, selecting a model or purchasing licences does not create an enterprise capability. It creates another technology estate that must eventually be rationalized and governed.

Why AI pilots struggle to become enterprise capabilities

Running an AI pilot is increasingly accessible. Scaling one responsibly across the enterprise is considerably harder.

The challenge is rarely limited to the model. It sits in the surrounding enterprise environment:

  • Data is fragmented across business systems.
  • Identity and access models were not designed for AI agents.
  • Ownership is divided among technology, data, security and business teams.
  • Evaluation criteria vary between use cases.
  • Controls are added after development rather than built into delivery.
  • Integration with core business processes is underestimated.
  • Benefits are described in terms of potential rather than measured outcomes.
  • Consumption costs are not connected to business value.

This produces a widening gap between experimentation and operational adoption.

Organizations may have many proofs of concept but no consistent production path. Teams solve similar problems independently, use different platforms and create overlapping controls. Risk functions become bottlenecks because they are engaged too late, while business sponsors struggle to see measurable value.

The answer is not to stop experimentation. It is to create a repeatable system for deciding which experiments deserve to scale — and how they will scale safely.

What the AI operating model must decide

A practical enterprise AI operating model should establish seven things.

1. Business outcomes and portfolio priorities

AI investment should begin with measurable business priorities, not with a search for places to deploy a particular model. Use cases should be evaluated against common criteria:

  • Strategic relevance
  • Financial or operational value
  • User and customer impact
  • Data readiness
  • Technical feasibility
  • Risk and regulatory exposure
  • Time to value
  • Potential for enterprise reuse

This allows leaders to distinguish between an interesting demonstration and a capability worthy of production investment. The objective is not to generate the longest possible list of use cases — it is to create a balanced portfolio of initiatives that can demonstrate value, establish reusable patterns and build organizational confidence.

2. Ownership and decision rights

AI initiatives often cross several organizational boundaries. The business owns the outcome, technology owns much of the platform, data teams govern information, security manages exposure and risk functions interpret regulatory obligations.

Without explicit decision rights, everyone participates but no one is fully accountable. The operating model should define:

  • Who owns the AI strategy and investment portfolio
  • Who sponsors each business outcome
  • Who approves models, platforms and architecture patterns
  • Who accepts residual risk
  • Who owns production performance and ongoing improvement
  • Who can suspend or retire an AI capability
  • How exceptions are approved

This is especially important for AI agents that can retrieve information, initiate workflows or act across enterprise systems.

3. Organizational model

Most enterprises will need to choose among three broad patterns.

Centralized

A central enterprise AI team owns platforms, standards, governance and most delivery. This provides strong control and consistency, particularly during the early stages of adoption. The risk is that the central team becomes a bottleneck and remains too distant from business processes.

Decentralized

Business units independently select platforms, build solutions and establish their own delivery approaches. This can accelerate local innovation, but it also creates duplication, inconsistent controls, fragmented architecture and reduced purchasing leverage.

Federated

A central capability provides shared platforms, standards, guardrails and specialist expertise, while domain teams own business use cases, adoption and outcomes. For many large enterprises, this is likely to be the most sustainable destination. However, federation requires mature governance and clearly defined boundaries; otherwise, it becomes decentralization under a different name.

AWS describes centralized, decentralized and federated approaches to enterprise generative AI, while Microsoft's AI Centre of Excellence guidance similarly outlines how an initially centralized capability can evolve toward advisory, platform or federated models as adoption matures.

A point of view: centralize what must be common

A strong federated model follows a simple principle:

Centralize what must be consistent across the enterprise. Federate what must remain close to business context and outcomes.

Centralize

  • Identity, access and security standards
  • Approved model and platform patterns
  • AI gateways and model-access controls
  • Data-protection requirements
  • Evaluation and testing frameworks
  • Logging, monitoring and auditability
  • Responsible AI policies
  • Vendor and commercial management
  • Consumption visibility
  • Reusable architecture components
  • Enterprise risk reporting

Federate

  • Business use-case ownership
  • Domain knowledge and context
  • Process redesign
  • Domain-specific data interpretation
  • User adoption
  • Change management
  • Benefit realization
  • Continuous improvement

This structure enables business teams to move with speed without requiring every team to recreate security, architecture and governance foundations.

Architecture is the bridge between policy and execution

An AI policy describes what the organization expects. Architecture determines whether those expectations can be enforced consistently.

The enterprise architecture should provide a controlled path between users, AI applications, models, enterprise data and operational systems. That commonly requires capabilities such as:

  • Model gateways and routing
  • Identity-aware access
  • Prompt and response controls
  • Data classification and retrieval patterns
  • Model and agent evaluation
  • Observability and audit trails
  • Content safety controls
  • Cost and token monitoring
  • Integration with APIs and business workflows
  • Human review for consequential actions
  • Resilience and fallback patterns

This shared foundation should support multiple models rather than binding the enterprise permanently to one provider. It should allow model selection to be based on the use case, including performance, data sensitivity, latency, cost and deployment constraints.

Microsoft's Well-Architected guidance for AI emphasizes security, reliability, operational excellence and cost optimization as architecture concerns — not capabilities to be added after deployment.

Governance must be part of the delivery workflow

AI governance is sometimes treated as a committee that reviews a solution shortly before production. This approach creates delay without necessarily reducing risk.

Effective governance begins during use-case selection and continues throughout the lifecycle. For each initiative, teams should understand:

  • What decision or activity the AI will influence
  • Which data the capability can access
  • The potential impact of an incorrect or inappropriate output
  • The level of human oversight required
  • How the solution will be evaluated before release
  • What will be monitored in production
  • Which events require escalation or suspension
  • When the model, data or use case must be reassessed

The NIST AI Risk Management Framework organizes this work around four connected functions: Govern, Map, Measure and Manage. The value of this structure is that governance is treated as an ongoing management discipline rather than a one-time approval.

The goal is not to eliminate every risk. It is to make risk visible, assign accountability and apply controls proportionate to the business context.

AI economics must be designed, not discovered later

AI cost extends beyond model consumption. The total economic model may include:

  • Platform and model charges
  • Data preparation and retrieval
  • Integration and infrastructure
  • Security and observability
  • Evaluation and testing
  • Human review
  • Change management
  • User enablement
  • Ongoing support and improvement

Enterprises should therefore avoid measuring success through licence activation, prompt volumes or the number of pilots launched. The more useful measures are connected to outcomes:

  • Cost per resolved case
  • Cycle-time reduction
  • Revenue conversion improvement
  • Employee capacity released
  • Customer-service improvement
  • Reduction in operational errors
  • Speed of product or service delivery
  • Risk events prevented
  • Cost per successful AI-assisted transaction

Consumption data remains important, but it must be connected to the business result being created.

The operating model on one page

DimensionExecutive decisionEvidence of maturity
StrategyWhich outcomes should AI improve?Prioritized portfolio with measurable value hypotheses
OwnershipWho owns decisions, risk and outcomes?Named business sponsors and explicit decision rights
OrganizationWhat is centralized and federated?Clear responsibilities across enterprise and domain teams
PlatformWhich capabilities should be reusable?Governed, multi-model architecture and production patterns
DataWhat information can AI access and why?Identity-aware access, classification and traceability
RiskHow will capabilities be evaluated and monitored?Lifecycle controls, evaluation standards and escalation paths
EconomicsHow will cost and value be managed?Unit economics connected to operational or financial outcomes
AdoptionHow will work and behaviour change?Process redesign, training and accountable benefit owners

A practical 90-day executive agenda

An organization does not need to solve every aspect of enterprise AI before moving forward. It does need enough structure to prevent each initiative from creating a separate architecture and governance model.

Days 1–30: Establish visibility

  • Catalogue current pilots, platforms and vendors
  • Identify business sponsors and intended outcomes
  • Map data sources, integration requirements and risk exposure
  • Review existing security, architecture and governance capabilities
  • Establish a baseline for current spending and expected value
  • Agree on a small set of enterprise AI principles

The objective is to replace fragmented activity with a common view of the portfolio.

Days 31–60: Define the operating model

  • Select the initial centralized, decentralized or federated structure
  • Define ownership and decision rights
  • Establish a use-case intake and prioritization process
  • Define architecture and approved model-access patterns
  • Create minimum governance and evaluation requirements
  • Determine how cost and benefits will be measured
  • Identify the reusable capabilities the central platform must provide

The objective is to establish a consistent path from idea to production.

Days 61–90: Prove the model

  • Select two or three high-value use cases
  • Confirm their business baselines and accountable sponsors
  • Apply the agreed architecture and governance approach
  • Establish production monitoring and evaluation
  • Measure cost, adoption and business outcomes
  • Capture reusable components and lessons
  • Convert the findings into an enterprise platform backlog

The objective is not simply to prove that the AI works. It is to prove that the enterprise can repeatedly identify, govern, deploy and improve AI capabilities.

Questions executive teams should be asking

Before approving the next wave of AI investment, leadership teams should be able to answer:

  1. Which business outcomes are we prioritizing — and why?
  2. Who owns the enterprise AI portfolio?
  3. What must be centralized across the organization?
  4. What authority will remain with business units?
  5. How will a use case move from pilot to production?
  6. Which models and platforms are approved for which contexts?
  7. How will data access be controlled and audited?
  8. How will model and agent performance be evaluated?
  9. What happens when performance, cost or risk moves outside tolerance?
  10. How will we connect AI consumption to measurable business value?
  11. Who owns adoption and process change after deployment?
  12. How will we replace models or vendors without redesigning the enterprise?

If these questions cannot be answered, the organization may have an AI toolset — but it does not yet have an AI operating model.

The leadership imperative

The enterprise AI landscape will continue to change rapidly. No organization can create certainty by selecting a single platform and assuming the decision is complete.

The more durable advantage comes from building organizational capability: the ability to identify valuable opportunities, the discipline to stop weak initiatives, the architecture to support multiple models, the governance to manage risk continuously, the integration capability to embed AI into real work, the economic visibility to scale what creates value, and the leadership model to assign accountability.

Tools will change. Models will change. Commercial terms will change. A strong operating model allows the enterprise to benefit from those changes without losing control of cost, risk or strategic direction.

The AI strategy should therefore not end with a technology selection. It should end with a clear answer to a more important question:

How will this enterprise repeatedly turn AI innovation into governed and measurable business capability?

New pieces, delivered when they are ready.

One email per piece. No summaries of headlines you have already read.