Skip to main content

    AI Strategy & Governance

    Design the organisation around the work AI will change.

    An AI operating model defines how capability becomes a reliable business outcome. It connects people, processes, technology, information and controls, with clear responsibility for the decisions between them. The question is not only where the AI team reports. It is how an idea becomes funded work, a supported service and a result somebody owns.

    In short

    Executive Summary

    • An AI operating model connects people, processes, technology, information and controls, with clear responsibility for the decisions between them.
    • Begin with one consequential workflow, followed from its trigger to the accepted result, then ask what AI actually changes about it.
    • Six operating choices settle the design: where accountability sits, what the system may decide or do, and which capabilities are shared. The remaining three are how work is accepted, where information comes from, and how value and failure are managed.
    • A decision-rights map naming who proposes, approves, performs, checks and can stop is the test of whether implemented permissions match the intended design.

    Detail

    Overview

    Follow a process from its trigger to the accepted result. Record decisions, hand-offs, exceptions and dependencies. Then ask what AI changes: does it produce an output, recommend an action, or execute a permitted step? Each design creates different demands on quality, authority, review and recovery. Conventional integration or assisted work may meet the objective without an autonomous agent.

    Six operating choices then settle the design.

    Where accountability sits. Name the business owner of the outcome, and distinguish responsibility for the workflow from responsibility for the model, integration and security controls. Both responsibilities must be explicit.

    What the system may decide or do. Reading a purchase order, drafting a change and approving payment are different permissions. Decide which actions may occur within tested limits, which require meaningful approval, and which remain prohibited. A prompt is not a substitute for an access-control design.

    Which capabilities should be shared. Common platforms, evaluation, procurement and security standards can reduce duplication, while process expertise and benefit ownership often need to remain close to the business. Compare centralised, distributed and federated arrangements against actual decisions and constraints.

    How work is accepted. Define a good outcome and who can judge it, including difficult cases and the consequences of error. If AI removes preparation but increases senior review, review capacity becomes part of the design.

    Where information comes from. Identify authoritative sources, permissions, version control and update owners. More documents can make the context worse if contradictions remain unresolved.

    How value and failure are managed. Measure accepted outcomes, full cost and material exposure, and define triggers for investigation, rollback, reapproval or retirement. A deployed system is an operating responsibility, not a completed experiment.

    Commercial impact

    Why It Matters for Organisations

    A human-agent team is not an organisation chart with software names added. The design has to include supervision, exception handling, customer relationships, professional judgement and learning.

    Workforce decisions should follow evidence of changed work and the organisation's obligations, not a comparison between a licence price and a salary. Retained human capability can also be a resilience requirement: the fallback must be executable by people who understand the process.

    Sequencing matters as much as structure. Start with a scope the organisation can supervise and measure, resolve its dependencies, then expand when the evidence supports it. Avoid enterprise-wide redesign before learning anything, and do not pretend a local pilot has no wider operating consequences. Show the next decision, the evidence it needs and the owner responsible for producing it.

    The strongest operating model is the one the organisation can operate, not the most sophisticated diagram it can approve.

    Podcast

    Listen to how Australian executives are applying AI

    Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.

    The trusted source for Australian executives deciding on AI strategy, governance and adoption. I translate technical complexity into practical business outcomes: growth, margins and time to value.

    In practice

    Examples or Practical Context

    For each important step, identify who proposes, approves, performs, checks and can stop. Compare that map with the permissions actually implemented.

    Take a hypothetical supplier-record workflow. An assistant identifies possible duplicates and shows the evidence. A finance owner decides whether to merge them. A controlled system performs and records the approved change.

    That differs materially from giving an agent broad access and asking it to clean up suppliers. The objective can be similar while authority and risk differ.

    What to do

    Key Takeaways

    • Start from one consequential workflow, traced from trigger to accepted result, rather than from an organisation chart or a platform decision.
    • Separate ownership of the outcome from ownership of the model, integration and security controls, and make both explicit.
    • Enforce action boundaries in technical controls where appropriate, because a prompt is not an access-control design.
    • Treat review capacity, information stewardship and recovery as parts of the operating model, not afterthoughts.
    • Sequence change around constraints: a scope the organisation can supervise and measure, then expansion when the evidence supports it.

    Newsletter

    Get the Executive Brief each week

    Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.

    The trusted source for Australian executives deciding on AI strategy, governance and adoption. I translate technical complexity into practical business outcomes: growth, margins and time to value.

    Assessment

    Run the AI Readiness Assessment

    Benchmark where your organisation stands and see what needs attention first. Use it to move from interest to an operating plan with clear next steps.

    The trusted source for Australian executives deciding on AI strategy, governance and adoption. I translate technical complexity into practical business outcomes: growth, margins and time to value.

    More detail

    Additional Context

    Begin with a consequential workflow

    Follow a process from its trigger to the accepted result. Record decisions, hand-offs, exceptions and dependencies. Then ask what AI changes: does it produce an output, recommend an action or execute a permitted step?

    Each design creates different demands on quality, authority, review and recovery. Conventional integration or assisted work may meet the objective without an autonomous agent.

    Make six operating choices

    Where accountability sits

    Name the business owner of the outcome. Distinguish responsibility for the workflow from responsibility for the model, integration and security controls.

    Technology can maintain a platform without controlling how its output is used. A business owner can own the result without being qualified to approve a security design. Both responsibilities must be explicit.

    What the system may decide or do

    Reading a purchase order, drafting a change and approving payment are different permissions. Decide which actions may occur within tested limits, which require meaningful approval and which remain prohibited.

    Technical controls should enforce the boundary where appropriate. A prompt is not a substitute for an access-control design.

    Which capabilities should be shared

    Common platforms, evaluation, procurement and security standards can reduce duplication. Process expertise and benefit ownership often need to remain close to the business.

    Compare centralised, distributed and federated arrangements against actual decisions and constraints. A centre of excellence needs a clear service and mandate, not only an organisation-chart box.

    How work is accepted

    Define a good outcome and who can judge it. Include difficult cases and consequences of error. If AI removes preparation but increases senior review, review capacity becomes part of the design.

    Where information comes from

    Identify authoritative sources, permissions, version control and update owners. The model should not have to guess which policy, price or customer record is current.

    A knowledge repository needs stewardship. More documents can make the context worse if contradictions remain unresolved.

    How value and failure are managed

    Measure accepted outcomes, full cost and material exposure. Define triggers for investigation, rollback, reapproval or retirement. A deployed system is an operating responsibility, not a completed experiment.

    Design human and agent work together

    A human-agent team is not an organisation chart with software names added. Include supervision, exception handling, customer relationships, professional judgement and learning.

    Workforce decisions should follow evidence of changed work and the organisation's obligations, not a comparison between a licence price and a salary. Retained human capability can also be a resilience requirement: the fallback must be executable by people who understand the process.

    Use a decision-rights map

    For each important step, identify who proposes, approves, performs, checks and can stop. Compare that map with implemented permissions.

    In a hypothetical supplier-record workflow, an assistant identifies possible duplicates and shows the evidence. A finance owner decides whether to merge them. A controlled system performs and records the approved change.

    That differs materially from giving an agent broad access and asking it to “clean up suppliers”. The objective can be similar while authority and risk differ.

    Sequence the change around constraints

    Start with a scope the organisation can supervise and measure. Resolve its dependencies, then expand when the evidence supports it.

    Avoid enterprise-wide redesign before learning anything, but do not pretend a local pilot has no wider operating consequences. Show the next decision, its evidence and the owner responsible for producing it.

    The strongest operating model is the one the organisation can operate, not the most sophisticated diagram it can approve.