---
title: "Operating AI"
date: 2026-07-12
description: Most AI pilots never reach production; the AI Centre of Excellence is the operating capability that turns scattered experiments into governed, scaled adoption.
author: Mario Thomas
canonical: https://mariothomas.com/briefings/operating-ai/
---

## Start here

Two short reads before the series: what an AI Centre of Excellence actually is, and the order to work through this briefing.

### Why AI Adoption Stalls Without an Operating Capability

Most of the organisations I work with do not have an AI adoption
problem. They have an AI operating problem. Pilots are everywhere;
production is rare. CIO.com reported in 2025 that **88%** of
AI pilots never reach production, and MIT's "State of AI in
Business 2025" report put custom enterprise AI reaching production
at just **5%**. Operating AI is the discipline this briefing
gathers: designing, launching, and evolving the AI Centre of
Excellence, the organisational capability that turns scattered
experiments into scaled, governed adoption.

The mistake I see most often is Boards treating the AI CoE as a
successor to the Cloud Centre of Excellence and filing it under
IT. Cloud was an infrastructure evolution led by technologists. AI
is business-led and arrives everywhere at once: marketing may be
transforming customer engagement while finance is still observing,
and the systems in between are making millions of decisions at a
tempo no quarterly review can oversee. In that multi-speed
reality, one-size-fits-all governance becomes either a
stranglehold or a sieve.

The position these articles take is that the AI CoE belongs
alongside the Board, reporting through the risk committee, with a
mandate to act as both enabler and guardian. Its work is defined
by 18 functions organised around the
[Five Pillars](/remake/library/five-pillars/) diagnostic, applied
with an intensity graduated to each function's stage in the
[AI Stages of Adoption](/remake/library/ai-stages-of-adoption/)
model. The governing principle is the
[Minimum Lovable Governance](/remake/library/minimum-lovable-governance/)
principle: just enough structure to make governed AI faster than
ungoverned AI, so that shadow experiments surface rather than
spread.

Read this briefing and you should come away able to make three
judgements: whether your organisation's governance structure
matches its multi-speed reality, where an AI CoE should sit and
report, and what its first 90 days must deliver. Those are
decisions for the Board rather than for IT, and in my view they
are not decisions to defer.

### Read the Core as a Build Sequence

The core of this briefing is a series I wrote as one continuous
argument, and [the articles](#core-reading) are numbered in the
order I would still read them. The first two establish the
mandate: why AI's decision velocity and multi-speed adoption
demand Board-level governance, and the 18 functions an effective
AI CoE performs. If you read nothing else, read those two before
your next risk committee meeting.

The design work comes next. Mapping your multi-speed reality
shows how to assess where each function actually sits rather than
where the executive summary says it sits, the structure article
sets out the hub-and-spoke model and the roles that staff it, and
the capabilities article turns the Five Pillars into a build plan.

The operating work closes the sequence: a 90-day launch built on
systematic pilot selection, the shift from project to platform
thinking that scaling demands, and the continuous evolution that
keeps the capability relevant as the technology moves.

The further reading goes wider and earlier. The Board-placement
argument starts in The Future of AI Expertise, from January 2025,
and the shadow AI article that followed is the first full
treatment of the CoE itself; the core series builds both out. The
Complete AI Adoption Framework piece, the 2025 precursor to
Remake, shows how the three mechanisms integrate, and the AI
Stages of Adoption primers are the place to begin if the
vocabulary is new to you. The piece on MIT's 2025 findings is the
external validation: the evidence that the operating problem is
the norm rather than the exception. The later pieces carry the
thinking into practice: the case for an AI amnesty as the CoE's
first governance move, the day-one blueprint for operationalising
what the amnesty surfaces, and the Minimum Lovable Governance
principle that keeps the CoE's governance proportionate to the
risk it oversees.

Once you have the shape of the argument,
[Remake](#remake-assets) holds the named mechanisms the series
draws on, and [the questions](#faqs) carry the short answers I
give when Boards ask where to start. The point is not to finish
the briefing in one sitting but to leave it with a structure you
can put in front of your Board.

## Core reading

The core sequence in the order it was written: the case for Board-level authority, then the design, launch, scaling, and continuous evolution of the capability.

1. [AI Centre of Excellence: Moving Beyond Shadow AI Risk to Scaled AI Adoption](https://mariothomas.com/blog/ai-coe-why-boards-need-one/) (11 minute read, 8 June 2025): AI makes millions of decisions at speeds traditional oversight cannot match, and shadow AI adds unmanaged risk: the case for an AI Centre of Excellence.
2. [AI Centre of Excellence: The Essential Functions of the Five Pillars](https://mariothomas.com/blog/ai-coe-functions/) (12 minute read, 15 June 2025): An AI Centre of Excellence earns its mandate through eighteen essential functions across the Five Pillars. Without them, governance is a name on a chart.
3. [AI Centre of Excellence: Mapping Your Multi-Speed AI Reality](https://mariothomas.com/blog/ai-coe-mapping-reality/) (11 minute read, 22 June 2025): Before governing AI, know where the organisation actually is. Mapping the multi-speed reality function by function replaces maturity claims with evidence.
4. [AI Centre of Excellence: Designing Structure for Multi-Speed Governance](https://mariothomas.com/blog/ai-coe-getting-started/) (12 minute read, 29 June 2025): Organisations adopt AI at different speeds, so one governance structure cannot fit them all: designing an AI Centre of Excellence for that multi-speed reality.
5. [AI Centre of Excellence: Building Capabilities That Scale With AI Adoption](https://mariothomas.com/blog/ai-coe-capabilities/) (14 minute read, 13 July 2025): An AI Centre of Excellence earns its keep through capability, not governance paperwork: Five Pillars capabilities built to match a multi-speed organisation.
6. [AI Centre of Excellence: Your First 90 Days With Well-Advised Value Focus](https://mariothomas.com/blog/ai-coe-launch/) (15 minute read, 20 July 2025): The first 90 days of an AI Centre of Excellence should deliver value, not just capability: a sprint portfolio selected with the AI Initiative Rubric.
7. [AI Centre of Excellence: Scaling Beyond Pilots to Enterprise Transformation](https://mariothomas.com/blog/ai-coe-pilot-production/) (12 minute read, 27 July 2025): Successful pilots mask a harder problem: scaling them into enterprise-wide transformation. After the first 90 days, the AI Centre of Excellence's real test begins.
8. [AI Centre of Excellence: Future-proofing Through Continuous Evolution](https://mariothomas.com/blog/ai-coe-future/) (12 minute read, 31 July 2025): The AI landscape moves faster than any governance framework. An AI Centre of Excellence stays relevant only if continuous evolution is designed in.

## Further reading

- [From Shadow AI to Strategic Asset: Building Your AI Centre of Excellence](https://mariothomas.com/blog/building-ai-centre-of-excellence/) (16 minute read, 12 March 2025): Shadow AI is already inside the organisation. A structured AI Centre of Excellence turns it from unmanaged risk into a strategic asset Boards can govern.
- [A Complete AI Adoption Framework: AISA, Five Pillars, and Well-Advised](https://mariothomas.com/blog/complete-ai-framework/) (15 minute read, 1 June 2025): The AI Stages of Adoption, the Five Pillars, and Well-Advised are one framework: how they integrate to govern multi-speed AI adoption across the organisation.
- [Understanding the AI Stages of Adoption: A framework for business leaders](https://mariothomas.com/blog/ai-stages-of-adoption-explainer/) (16 minute read, 21 February 2025): The AI Stages of Adoption locate an organisation, function by function, on a five-stage path from Experimenting to Scaling, and show how to move.
- [Increasing AI Maturity: Navigating the AI Stages of Adoption with the Five Pillars](https://mariothomas.com/blog/ai-stages-of-adoption-five-pillars/) (9 minute read, 2 March 2025): Readiness for the next AI stage is a Five Pillars question, not a calendar one: a function advances only when every pillar reaches the threshold.
- [Crossing the GenAI Divide: Solving The 95% Problem With The Complete AI Framework](https://mariothomas.com/blog/crossing-genai-divide-boardroom/) (12 minute read, 28 August 2025): MIT confirms what I have argued since 2024: 5% of organisations take generative AI from pilot to production. The Complete AI Framework answers that divide.
- [The future of AI expertise: Building and managing AI-capable teams](https://mariothomas.com/blog/future-of-ai-expertise/) (7 minute read, 21 January 2025): AI's promise of productivity and innovation is delivered by teams, not tools. Building AI-capable teams draws on what the Cloud Centre of Excellence taught me.
- [Shadow AI and the Case for an AI Amnesty](https://mariothomas.com/blog/shadow-ai-amnesty-governance/) (15 minute read, 21 September 2025): Shadow AI is surging and most employees would use AI tools without permission. An AI amnesty turns that hidden risk into governed, employee-validated innovation.
- [After the AI Amnesty: Practical Steps to Operationalise Discovered Shadow AI](https://mariothomas.com/blog/shadow-ai-amnesty-next-steps/) (12 minute read, 28 September 2025): After the amnesty, speed matters: employees who disclosed expect enablement, not restriction. A roadmap for turning discovered shadow AI into governed capability.
- [Minimum Lovable Governance: The AI Operating Principle Boards Should Use](https://mariothomas.com/blog/minimum-lovable-governance/) (13 minute read, 30 November 2025): Minimum lovable governance replaces episodic compliance with continuous, embedded oversight people actually want to use: guardrails that earn adoption rather than enforce it. Podcast edition: 17 minute listen.

## Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

- **Model: AI Stages of Adoption**. A framework describing five stages of the AI journey, Experimenting, Adopting, Optimising, Transforming and Scaling, plotted on an investment-value graph, recognising that different functions progress simultaneously at different paces. [Remake Library](https://mariothomas.com/remake/library/ai-stages-of-adoption/)
- **Diagnostic: AI CoE Simulator**. An interactive assessment tool operationalising the AI Stages of Adoption, objectively placing each business function within adoption stages using specific criteria rather than subjective self-assessment, revealing an organisation's multi-speed AI reality. [Remake Library](https://mariothomas.com/remake/library/ai-coe-simulator/)
- **Methodology: CoE 90-Day Sprint**. The time-boxed execution method that launches an AI Centre of Excellence's first pilot portfolio: initiatives scored and selected with the AI Initiative Rubric, run as a ninety-day sprint portfolio that balances quick wins against strategic bets, with governance mechanisms evolving alongside the work rather than ahead of it. [Remake Library](https://mariothomas.com/remake/library/#coe-90-day-sprint)
- **Principle: Minimum Lovable Governance**. Governance embedded in how work happens: proportionate to risk, continuous rather than episodic, and used because it works. [Remake Library](https://mariothomas.com/remake/library/minimum-lovable-governance/)

## Questions

The questions directors put to me most often when an organisation decides to put proper structure around its AI adoption.

### Most of our AI pilots never reach production. Is that a technology problem?

Rarely. The evidence and my own observation point the same way: pilots fail because technical capability races ahead of governance, operations, value tracking, and cultural readiness, and because organisations treat scaling as replication rather than as a shift to platform thinking. The fix is capability, not more technology. I set out the scaling argument in [Scaling Beyond Pilots](/blog/ai-coe-pilot-production/) and the supporting MIT evidence in [Crossing the GenAI Divide](/blog/crossing-genai-divide-boardroom/).

### Why can't AI governance sit within IT or our existing Cloud Centre of Excellence?

Cloud was an infrastructure evolution, so an IT-led CoE made sense. AI transforms decision-making in every function, is usually led by the business rather than by technologists, and operates at a velocity that carries Board-level accountability with it. That is why I argue the AI CoE should report to the Board through the risk committee, a case I make in [Why Boards Need One](/blog/ai-coe-why-boards-need-one/) and [The Future of AI Expertise](/blog/future-of-ai-expertise/).

### Won't a Centre of Excellence just slow innovation down?

Only if it is built as a gate. The model the series describes is governance as a service: templates, frameworks, and expertise that make governed AI faster to launch than ungoverned AI, with oversight graduated to each initiative's stage and risk. The Minimum Lovable Governance principle runs throughout. [Your First 90 Days](/blog/ai-coe-launch/) shows what that looks like in practice.

### What should we do about the AI our people are already using without approval?

Treat shadow AI as market research rather than misconduct. It shows where approved tooling falls short of real need. A time-limited amnesty, a tiered framework of approved alternatives, and monitoring focused on enablement rather than punishment turn hidden risk into a governed pipeline of use cases. I set the approach out in [From Shadow AI to Strategic Asset](/blog/building-ai-centre-of-excellence/).

### When is the AI CoE's job done?

That is the question Boards put to me, and I think it is the wrong one. The better question is how the CoE's role evolves as maturity advances: from educator, to orchestrator, to strategic advisor, with functions formally graduating to business ownership as capability embeds. Some specialised AI governance will remain necessary for longer than it did with cloud. [Future-proofing Through Continuous Evolution](/blog/ai-coe-future/) covers the graduation criteria.

### Who should lead our AI CoE?

Someone who can talk credibly to the data scientists in the morning and the risk committee in the afternoon. The AI CoE Director needs enough technical understanding to engage with engineers, the business acumen to turn AI capability into strategic value, governance expertise to manage risk without stifling innovation, and the gravitas to work with directors. The leaders I have seen succeed have experience spanning technology implementation, business transformation, and risk management. The reporting line matters as much as the person: the Director answers to the Board's risk committee, not to IT. [Designing Structure for Multi-Speed Governance](/blog/ai-coe-getting-started/) and [From Shadow AI to Strategic Asset](/blog/building-ai-centre-of-excellence/) set out the role.

### How do we know when a function is ready for the next stage?

When its capability says so, not the calendar. Readiness is measured with the Five Pillars diagnostic: a function advances a stage in the AI Stages of Adoption model only when every pillar has reached the threshold the next stage demands, and it is often the weakest pillar, governance early on and culture later, that decides whether the transition is smooth or painful. The AI CoE Simulator diagnostic separates mandatory criteria from recommended ones; moving from Experimenting to Adopting requires executive sponsorship, initial governance frameworks, and dedicated budget. [Navigating the Stages with the Five Pillars](/blog/ai-stages-of-adoption-five-pillars/) sets out the transitions, and [Mapping Your Multi-Speed AI Reality](/blog/ai-coe-mapping-reality/) shows the assessment in practice.

### How should the AI CoE work with our existing Cloud CoE?

As partners with a clear division of labour, not as parent and child. The Cloud CoE keeps infrastructure, platforms, and technical standards. The AI CoE owns AI governance, use cases, and value realisation, and answers to the Board's risk committee rather than to IT. Architecture, security, and data governance sit in the shared space, so the mechanisms matter: joint planning sessions, a shared technology roadmap, coordinated vendor management, and integrated training programmes. The split reflects my early work at AWS designing Cloud Centres of Excellence, and it keeps the technical estate with the people who run it. The integration table in [Designing Structure for Multi-Speed Governance](/blog/ai-coe-getting-started/) sets it out.

## References

The external evidence the series draws on, together with the cloud-era frameworks this thinking grew out of.

- **IDC** (25 March 2025): [88% of AI pilots fail to reach production — but that’s not all on IT](https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html). The pilot failure rate the series returns to, and the case that its causes sit well beyond IT.
- **The Economist** (21 May 2025): [Welcome to the AI trough of disillusionment](https://www.economist.com/business/2025/05/21/welcome-to-the-ai-trough-of-disillusionment). Reports 42% of companies abandoning their generative AI projects, the cost of misreading organisational readiness.
- **McKinsey & Company** (5 November 2025): [The State of AI](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai). The recurring global survey behind the finding that most organisations see no enterprise-level EBIT impact from generative AI.
- **HiddenLayer** (15 May 2024): [AI Threat Landscape Report](https://hiddenlayer.com/innovation-hub/hiddenlayer-ai-threat-landscape-report-reveals-ai-breaches-on-the-rise/). Found 74% of organisations reported an AI breach in 2024, the risk baseline behind the governance mandate.
- **Amazon Web Services** (2017): [Evaluating migration readiness](https://docs.aws.amazon.com/prescriptive-guidance/latest/evaluating-migration-readiness/introduction.html). The cloud-era readiness assessment I co-authored, which AISA shares DNA with and deliberately departs from.
- **Amazon Web Services** (February 2015): [AWS Cloud Adoption Framework](https://aws.amazon.com/cloud-adoption-framework/). The capability-domain approach from my early AWS work that informed the shape of the Five Pillars.
- **MIT NANDA** (July 2025): [The GenAI Divide: State of AI in Business 2025](https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf). The State of AI in Business 2025 report: around 5% of enterprise AI pilots reach production, the figure the operating-model articles set out to change.

## The ideas beneath this briefing

Ideas I've named and matured writing about Operating AI: what each one means, and where it started.

- **Multi-Speed Reality**: Different parts of a business sitting at different AISA stages simultaneously, marketing transforming with AI content while operations experiments with predictive maintenance, demanding coordination rather than a single organisation-wide posture. [Read more](https://mariothomas.com/blog/ai-coe-mapping-reality/)
- **Multi-Speed Governance**: Governance recognising that different business functions adopt AI at different speeds and maturities simultaneously, applying varying oversight intensity rather than uniform, one-size-fits-all control that either stifles or fails to contain risk. [Read more](https://mariothomas.com/blog/ai-coe-getting-started/)
- **Federated Coherence**: An infrastructure principle centralising shared platforms, common tools and security standards for efficiency while federating unique needs and edge deployments, using standard composable components teams assemble into solutions. [Read more](https://mariothomas.com/blog/ai-coe-capabilities/)
- **Innovation Ratchets**: Structural mechanisms, such as escalating success metrics and mandatory talent rotation, that make backward movement difficult and keep an AI CoE focused on innovation rather than drifting into administration. [Read more](https://mariothomas.com/blog/ai-coe-future/)
- **Investment-Value Realisation Graph**: The visualisation plotting AISA stages with investment (financial, people, data, process and time) on the x-axis and tangible and non-tangible value on the y-axis, reflecting varied returns. [Read more](https://mariothomas.com/blog/ai-stages-of-adoption-explainer/)

All concepts: https://mariothomas.com/glossary/concepts/

## More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

- [AI Strategy](https://mariothomas.com/briefings/ai-strategy/): Approving good AI projects is not a strategy, and the Board's move is from accumulating pilots to a strategy it owns.
- [AI Governance](https://mariothomas.com/briefings/ai-governance/): Governance people route around fails to govern; the task is governing AI the Board cannot fully see without strangling adoption.
- [AI Transformation](https://mariothomas.com/briefings/ai-transformation/): Most organisations are stuck at the pilot stage; crossing the divide is a Board judgement about delegation, architecture, and governance, not a technology purchase.
- [AI Business Cases](https://mariothomas.com/briefings/ai-business-cases/): Business cases built for predictable payback misread AI, whose value arrives in parallel, late, and elsewhere; Boards need different instruments.
