Responsible AI in the Enterprise · Part 1

Where AI belongs in your operating model

Decide which work AI should assist with, automate or act on, who owns it, how it fits your controls and budgets, and where to start.

Executive summary

Most boards have now seen an AI demo that worked. Far fewer have seen AI change a P&L line. The gap is rarely the model. It is the operating model: nobody has decided which work AI should do, who owns the result, or how it fits the controls and budgets the business already runs on.

McKinsey's latest global survey shows the size of that gap. In The state of AI in 2026, 44% of respondents say AI is scaling across their enterprise, yet only 37% attribute any EBIT impact to it. The small group that does see significant returns, about 6% of respondents, stands out for one habit: nearly three quarters of them have fundamentally redesigned workflows around AI. Our view follows from that. Treat AI as a change to how work is organised, owned and funded, and the technology decisions get much easier.

This is Part 1 of our series on responsible AI in the enterprise. It is written for the CEO and COO first, and for the CIO and CTO who will build what they decide.

1. Why pilots stall

Pilots are cheap to start and hard to finish. Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027, and names three causes: rising costs, unclear business value and weak risk controls. None of the three is a model problem. Each one is a decision someone did not make at the start.

We see the same pattern in most organisations we speak to. A team builds something clever. It works in a demo. Then three questions arrive at once. Who signs off when it gets something wrong? Whose budget pays for it next year? Which process does it replace? If nobody can answer, the pilot waits, and then it quietly ends.

HMR insight: AI does not fail in the model. It fails in the gap between the demo and the operating model.

2. Decide the job first: assist, automate or act

Before you choose a tool, decide what kind of work you are asking AI to do. We use four categories. They sound simple, and they settle most arguments early.

Figure 1 Four ways to divide the work
  • Assist

    JobAI drafts, finds or summarises. A person decides and acts.

    CaseA handler gets a summary of a claim file before a call.

  • Automate

    JobAI runs a fixed step inside a process people have already designed.

    CaseInvoices are read and matched to purchase orders, with exceptions sent to a queue.

  • Act

    JobAn agent chooses its next step and uses tools to finish a task.

    CaseAn agent chases missing documents and updates the record, within set limits.

  • Keep with people

    JobJudgement, accountability or trust matter more than speed.

    CaseCredit exceptions, disciplinary decisions, a hard call to a customer.

The category sets almost everything else. Assist needs good data and a trained user. Automate needs a stable process and an exceptions queue. Act needs the full set of agent controls: scoped identities, approval gates, an audit trail and a way to stop a run. We set those out in Part 2 of this series.

Category Who decides Main risk Controls you need
Assist A person, every time Over-trust in a wrong answer Source links, user training
Automate The process design Silent errors at volume Exception queue, sampling
Act The agent, within limits A wrong action in a live system Risk tiers, approvals, stop switch
Keep with people A person, fully accountable Pressure to automate anyway A written reason it stays manual

Most real workflows mix categories. A claims process might use assist for the handler, automate for document checks and act for chasing missing papers. Tag each step, not the whole workflow. Start one level lower than the enthusiasts want. It is easier to move a step from assist to act with evidence than to pull it back after a bad week.

3. Who owns AI

Ownership is where most operating models go vague. Our rule is short. The business owns the outcome. A central team owns the platform and the guardrails. Risk owns the rules for what needs approval.

McKinsey's 2025 survey found the same split in practice. Risk and compliance was fully centralised at 57% of organisations, and data governance at 46%. Tech talent (49%) and the adoption of AI solutions (54%) were most often run as a hybrid. The same survey found that CEO oversight of AI governance was one of the factors most linked to higher reported bottom-line impact, yet only 28% of respondents said their CEO held that role.

Decision Business owner Central AI team Risk
Which workflows, and why Decides Advises on feasibility Flags tier 3 actions
Outcome target Owns and reports Builds the measures Reviews
Platform, models, gateway Uses Owns and runs Sets model rules
Approval tiers Names approvers Enforces in the gateway Owns the policy
Stopping a workflow Can stop Can stop Can stop

Centre of excellence or federated

A central centre of excellence gives you consistency, but it becomes a queue. A fully federated model is fast, but each unit ends up with its own tools, its own data copies and its own idea of acceptable risk. We recommend hub and spoke. The hub runs one platform, one agent gateway and one set of controls. Business teams are the spokes: they build and own their workflows on top of it.

Keep the hub small, and make it shrink its own queue over time. Its job is to make the safe path the easy path, with templates, approved models and shared logging. Frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 are useful here. Both expect clear roles and accountability, and they give your auditors a structure they already recognise.

4. Fit it into what you already run

An AI workflow is still a workflow. It has to fit your process maps, your control framework, your budget cycle and your people. Skipping any one of these is how a working pilot becomes an orphan.

Figure 2 Four places every AI workflow has to fit
  • Process. Redraw the workflow with the AI step in it. Mark where work enters, where it waits and where a person takes over.
  • Controls. Map each AI action to your existing delegation of authority and maker-checker rules. An agent should not get a limit no person has.
  • Budget. Fund each workflow with its run cost, its review time and one outcome it must move. Stop funding what does not move it.
  • People. Name who reviews the work, who can stop it and whose job changes. Tell them before go-live, not after.

Controls deserve the most care. Your delegation of authority matrix already says who can approve a refund, a discount or a payment. An agent should inherit those limits, never exceed them. If a clerk needs a manager's sign-off above a set amount, so does the agent. This is how the risk tiers in Part 2 map onto rules your auditors already test.

Budgets need a change of habit too. A licence fee is predictable. AI run costs grow with use, and human review time is a real cost that often goes unrecorded. Fund each workflow as a line with an owner, a run cost, a review cost and one measure it has to move. Review it each quarter like any other investment.

5. Choosing the first workflows

The first workflows matter more than their size suggests. They set the pattern, test the platform and decide whether the board trusts the next request. Pick them on purpose.

Figure 3 Choosing the first workflows
  1. ListCollect ten to twenty candidate workflows from the business, not from the tech team.
  2. ScoreRate each for value, data readiness, risk and a named owner who wants it.
  3. TierMark every action with a risk tier, so you know the approvals before you build.
  4. CommitPick two or three. Give each an owner, a budget, a measure and a date to decide.

We score candidates on five questions. Each gets a simple high, medium or low.

Question What a good first candidate looks like
Is the value clear? Volume is high and the work is measurable today
Is the data ready? The inputs are digital, current and accessible
Is the risk contained? Most actions are tier 0 or 1, and errors are reversible
Is there an owner? A named leader wants it and will report on it
Can people see it? The result shows up in a number the board already reads

Avoid two traps. The first is choosing the most impressive use case, which is often the riskiest. The second is choosing something so small that success proves nothing. Good first candidates are dull, frequent and painful, and someone senior wants them fixed.

6. Illustrative scenario: a freight forwarder's back office

This scenario is illustrative. The company is fictional.

Tapti Freight Lines moves containers for exporters across western India. Its leadership has approved several AI pilots over two years. Each worked in isolation, and none reached daily use. The COO asks a simple question: which of these should we actually run?

The team lists fourteen candidate workflows and scores them. Two rise to the top. Matching carrier invoices to bookings is high volume, mostly tier 1 and owned by the finance controller. Chasing shippers for missing export documents is repetitive and reversible, and the operations head wants it. A third idea, an agent that negotiates carrier rates, scores high on value but carries tier 3 actions. It goes on the list for later, once the controls have a track record.

The central team stands up one platform and gateway for both workflows. Finance keeps its maker-checker rule, so any invoice variance above its threshold still goes to a person. Each workflow gets a budget line, a weekly review of sampled runs, and a date after which the owner decides to widen, adjust or stop. What changes first is not headcount. It is that every AI step now has an owner, a limit and a place in the P&L.

7. What the rest of this series covers

This article sets out where AI belongs. The other five go deeper on how to run it safely.

Moving forward

Pick three workflows this quarter, name an owner for each and write down which category each step falls into. If you want help scoring the candidates and checking your foundations, our three-week Readiness Audit ends in a ranked plan. You can see how we govern our own use of AI in our AI governance policy, or book a readiness audit to start.

Sources

  1. McKinsey, The state of AI in 2026: On the road to ROI, August 2026
  2. McKinsey, The state of AI: How organizations are rewiring to capture value, March 2025
  3. Gartner, Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027, June 2025
  4. NIST, AI Risk Management Framework
  5. ISO, ISO/IEC 42001:2023 AI management systems
  • Responsible AI in the Enterprise · Part 3

    Data boundaries for AI systems

    What an AI system may read, send, keep and where it may run: permission-aware retrieval, masking, provider terms and DPDP duties.

    10 min read

  • Responsible AI in the Enterprise · Part 2

    A governance model for enterprise AI agents

    Six controls that let AI agents run real workflows while named people stay in charge of every step that carries risk, and how to put them in place.

    7 min read