How to implement AI

In many companies and public authorities, artificial intelligence is being implemented chaotically. Pilot projects fail to transition into everyday use, compliance with regulations is addressed at the end, employees use AI tools without the IT department's knowledge, and management does not know whether these systems work correctly at all. At the same time, the number of regulations is growing – the EU regulation on AI (AI Act), DORA, NIS2 and the Polish Act on the National Cybersecurity System – with specific deadlines and penalties
Most consulting firms offer an AI strategy as a presentation or a prototype that never reaches everyday use. allclouds delivers a complete, working way to organize AI work: from governance and oversight, through working methods, to structuring corporate knowledge and ongoing maintenance
What we deliver
Our offering consists of two complementary service lines
CDF Line – methodological consulting. CDF is our methodology for deploying AI in large organizations (Cognitive Deployment Framework). We begin every engagement with a Preliminary Assessment (CDF-Eval) – a one- or two-day diagnosis at the client's site, involving more than 100 employees and using our own computing environment. The result is a clear recommendation: deploy, deploy with conditions, or do not deploy – before the client spends any money on the project
If the result is positive, we launch the full methodology: seven main stages (F0–F6), two diagnostic stages (F0.K, F1.5) and an independent audit (CDF-AUD). Each stage has defined start and end conditions, required documents and measurable quality indicators. Among them are Cognitive Thinking Quality Indicators (Cognitive SLA): system availability, answer accuracy, rate of fabricated responses (hallucinations), time to respond to an error, cooperation between AI agents, currency of knowledge. Such measures are not present in any standard Agile or ITIL methodology. Full description of indicators and thresholds – stage CDF-F4
WDR Line – AI operational documents. Six documents that remain in the organization after the project ends and function independently of which AI tools the company uses:
- AI Usage Policy (AI-Operating & Working Agreement),
- AI work methods handbook for every role (AI Work Methods & Effectiveness Guide),
- Operating instructions for the AI workplace environment (AI Workplace Stack & Configuration),
- Document naming standard prepared for AI work (Corporate Document Naming System),
- Implementation plan: automations, management dashboards, schedule (AI Implementation Plan),
- Corporate knowledge architecture: relationship map, glossary of terms, guidelines for knowledge search systems (Corporate Knowledge Architecture)
Three things no one else offers
- Compliance built in from the start, not tacked on at the end We execute the Compliance-First stage (CDF-F1.5, Compliance-First Delivery) before actual deployment, not after. The client receives an AI Act readiness assessment, a Statement of Applicability, an AI System Impact Assessment report (ASIA) and a ready-made security annex for IT vendor contracts. Organizations that build compliance from the outset incur significantly lower costs – industry studies indicate a 2–3x saving depending on the sector
- One decision instead of endless piloting At the end of the pilot there is a single decision point – the Gate „scale or terminate" (Scale-or-Kill Gate): we expand to the entire organization or we stop. There is no option „let's extend a bit more". This is deliberate – a pilot that drags on for 18 months because no one wants to decide costs more than shutting down a failed project. Production deployment costs on average 3–5 times as much as the pilot. A good decision to terminate saves more than a failed deployment
- We practice what we preach The entire described model operates daily at allclouds. Our team applies the same principles, policies and procedures that we implement for clients. We do not advise in theory – we show a working system and help adapt it
Who it's for
For organizations in regulated sectors: finance (banks, insurers, leasing companies), central and local government administration, defense, healthcare, energy and critical infrastructure. Minimum scale: companies with more than 50 employees that already run an AI program or have a clear board decision to start one
Services can be ordered as a full program (Preliminary Assessment + stages F0–F6 + WDR documents), as selected stages individually (e.g., the CDF-AUD audit alone or the WDR-01 to WDR-06 documents only) or as an ongoing monthly CogOps service for organizations that implemented AI independently and now need a way to maintain it
CDF Line – methodological consulting
CDF-F0 Reconnaissance and configuration
Assessment of how ready the organization is to deploy AI: data, processes, people skills, readiness for change and the regulatory situation. On this basis an ACE Configuration Profile is created, which defines the scope of all subsequent stages. We work together with the management board, IT department, compliance department and the owners of selected processes
What the client receives:
- An AI readiness report with a score and a list of items to improve
- An implementation profile of the organization that governs subsequent stages
- A map of processes, data and decisions where AI can deliver value, together with an estimate of implementation costs and a reference point for measuring return
- A list of acceptance criteria for the entire project – an annex to the contract
CDF-F0.K Audit and knowledge map of the company
An inventory and assessment of the organization's knowledge assets – both documented (documents, procedures, systems) and knowledge that exists only in experts' heads, on local drives and in informal notes. We conduct it together with the client's experts: interviews, documentation review, workshops. The results form the basis for building systems that will allow AI to leverage the company's knowledge
What the client receives:
- A register of knowledge sources with quality assessments and assigned owners
- A map of knowledge loss risks (e.g., departure of key experts) and priorities for safeguarding it
- A preliminary map of relationships between the company's concepts and data (Knowledge Graph)
- Recommendations for the strategy stages (F1) and data oversight (F2)
CDF-F0.L Assessment of legacy systems for AI (Legacy Systems & AI Opportunity Assessment)
A review of existing systems, applications and processes to identify where AI can realistically help. The goal is not to tack AI onto every old system, but to determine: where AI will add value, where a process or system must be rebuilt first, and where implementation would be too risky, expensive or illusory. We work with IT, process owners and system architects
What the client receives:
- A systems assessment report along with their register: criticality, limitations, AI potential
- A map of AI applications assigned to specific systems and processes
- An assessment of systems' readiness for integration and of data quality
- A list of priorities: implement / rebuild / postpone / do not recommend
CDF-F1 AI strategy and architecture
Translating the diagnosis from phase F0 into concrete, approved strategic decisions. A set of documents is produced that serve as the mandate for the entire AI program: the overarching objective, the sovereignty model (how dependent the company is on external providers and from where), costs for 3–5 years, "build or buy" decisions and a contingency plan in case of a supplier change. Everything is approved by the board before proceeding further
What the client receives:
- AI strategy document: objective, metrics, budget – approved by the board
- A decision on the deployment model (cloud / own infrastructure / hybrid model) with technical and legal justification
- An assessment of vendor and AI model risks, including geopolitical risk
- A cost model for 3–5 years (spreadsheet) and an action plan in case of loss of a supplier
CDF-F1.5 Compliance First and Foremost (Compliance-First Delivery)
A separate phase for organizations in regulated sectors. We identify compliance gaps and prepare a complete set of documents before the technical implementation begins. Compliance is designed from the outset, not ticked off a checklist before an audit. Mandatory for companies in the financial sector, public administration and other regulated industries. We work with the compliance department, the data protection officer and the client's legal team
What the client receives:
- A compliance readiness report including an assessment against the AI Act and a remediation plan
- A statement of use and an impact assessment report for each AI system (and a data protection impact assessment, if required)
- A security addendum ready to be incorporated into contracts with IT and AI vendors
- A 24-month regulatory roadmap with assigned responsible parties
CDF-F2 AI Oversight and Security
Design and launch of a complete AI governance system within the organization: who supervises, what the authorities are, a register of active AI agents, and how data protection and security are handled. This phase creates the foundations on which all subsequent work is built. Each mechanism is designed in collaboration with those responsible for security, IT architecture and business processes
What the client receives:
- An AI agents register and a responsibility matrix: who is accountable for what at each level of AI autonomy
- Human oversight policies for AI and a procedure manual for uncontrolled AI tools used by employees
- A data management package (processing register, data quality, data lifecycle)
- A security specification and an immutable event log ready for IT implementation
CDF-F3 Change Management and Competency Building
Preparing people for real work with AI – both in terms of skills and psychologically. The greatest risk in AI transformation is not the technology but people and organizational culture. At this stage we develop internal change leaders who will continue to advance AI after our project ends. We work with HR and department managers
What the client receives:
- An AI leaders program: recruitment, training (16 h), materials
- CDF Academy: three training tracks (40 h in total) with internal certification
- A change management plan: communications, timeline, adoption metrics for AI in the organization
- Measurement tools: team psychological safety and an AI fatigue index with thresholds for when action is required
CDF-F4 Cognitive Sprint – pilot implementation (Cognitive Sprint)
An implementation cycle similar to Agile but focused on delivering measurable AI value while maintaining compliance, full auditability and continuous measurement of response quality. Unlike a regular sprint, we measure not only work velocity but decision quality, the rate of fabricated responses and the effectiveness of human oversight. Each sprint (2–4 weeks) ends with a report and a continuation decision. The entire phase concludes with a Gate „scale or stop" – there is no option to extend the pilot
What the client receives:
- Operational AI Quality Monitoring Dashboard
- Reports after each sprint: results, incidents, recommendations, comparison with the previous sprint
- Preliminary evidence package for ISO 42001 certification (AI management standard)
- A documented "scale or terminate" decision together with verification of the acceptance criteria from stage F0
CDF-F5 Verification, Scaling and Acceptance
Formal verification of the deployment and fulfillment of legal requirements before handing the system over for daily use, followed by scaling across the entire organization. The stage begins with a quality review of all documents from stages F0–F4 and concludes with an acceptance protocol and the launch of a permanent maintenance model (F6)
What the client receives:
- A compliance assessment report ready for external audit, accompanied by the required technical documentation and registration in the EU database (if applicable)
- Quality management system documentation compliant with the AI Act
- A catalogue of the company's AI systems with described applications
- An acceptance protocol and a phased plan for scaling across the organization, with readiness criteria
CDF-F6 Cognitive Operations – continuous maintenance (CogOps)
A maintenance model for AI systems that are already in daily operation. It goes far beyond traditional IT monitoring: it covers response quality, the currency of company knowledge, model aging, the full lifecycle of AI agents and continuous compliance with evolving regulations. Delivered as a monthly, ongoing service with a dedicated allclouds consultant
What the client receives:
- Monthly AI quality report: metrics, trends, incidents, recommendations
- Quarterly compliance review with updates to oversight documentation
- Ongoing update of the AI agents register and the regulatory schedule upon any change in regulations
- Support for external audits – on demand, as part of the service
WDR line – AI operational documents
WDR-01 AI Policy and Governance Principles (AI Policy & Governance Design)
Development or adaptation of an AI Usage Policy (AI-Operating & Working Agreement) – a foundational document that defines rules, roles, constraints and procedures for all employees using AI. Tailored to the client's sector, organizational structure and applicable regulations. Created in workshops with key stakeholders, through several review rounds, with final approval by the board
What the client receives:
- An AI Usage Policy (30–50 pages) tailored to the organization
- A matrix of roles and responsibilities for AI
- Register of systems with built-in AI (Excel template + instructions) and rules on what is allowed, what is restricted, and what is prohibited in interactions with clients and suppliers
- Onboarding pathway for new employees on AI work practices
WDR-02 AI Work Methods (AI Work Methods Design)
Development or adaptation of a practical AI work handbook for each role. It combines three levels: technical (how AI works, how to formulate prompts), methodological (how to process documents, how to guard against fabricated responses) and practical (ready-made templates for project managers, developers, sales, HR, operations and the executive board). Tool-agnostic, with a separate section for client tools. Each template is built on real cases from the client's company
What the client receives:
- AI work methods handbook (150–200 pages) tailored to roles and processes
- A library of at least 30 ready-made prompt templates for individual roles
- A checklist of 10 layers of defense against fabricated responses (printed card + digital version)
- An inventory of the client's AI tools with recommendations
WDR-03 AI Workplace Configuration (AI Workplace Configuration Design)
Development or adaptation of a complete operating manual for the AI work environment. It combines three layers: how AI tools are built within the company, how employees use them day-to-day and what safeguards protect data and processes. We work with the IT architect, the person responsible for security and department heads
What the client receives:
- Operating manual for the AI work environment (40–60 pages) tailored to the company
- Quick-start cards for each role (A4, for print or intranet)
- A completed register of systems with built-in AI and a data flow map for the company
- Security requirements for implementation by IT
WDR-04 Document Naming and Organization (Document Governance & Naming System)
Implementation or adaptation of a document naming standard designed for AI work: machine-readable, compliant with data classification and ready for automation. System-agnostic regarding where the company stores documents (SharePoint, Google Drive, Confluence, Box and others). Developed in workshops with representatives from all departments – each document type must be recognizable to employees, not just IT
What the client receives:
- A complete specification of the document naming standard
- Division into areas and document types tailored to the company's structure
- A phased plan for migrating existing documents to the new standard, together with the logic for automatic name control
- Rules for maintaining the standard: owners and the procedure for implementing changes
WDR-05 AI Implementation Plan (AI Implementation Planning)
Transforming documents WDR-01 to WDR-04 into a concrete, actionable plan: a list of automations, data organization (a single trusted source for each data type), management dashboards and a schedule. The plan specifies WHAT to automate and IN WHAT WAY, not which tool to use. Delivered to the client's IT team or an external contractor as a ready specification
What the client receives:
- Implementation plan (document + Excel sheet): 36 automations with priorities and a schedule
- A flow map of 14 data types with assigned owners
- Specification of 6 management dashboards: indicators, data sources, screen sketches
- A list of quick wins to implement in the first 4 weeks and a handover document for IT or the contractor
WDR-06 Corporate Knowledge Architecture (Corporate Knowledge Architecture)
A detailed elaboration of how the organization's knowledge should be organized so that AI can use it safely and effectively. The starting point is the audit from stage CDF-F0.K or the client's own analysis. It defines the map of relationships between concepts (Knowledge Graph), a glossary of industry terms, governance rules for knowledge and procedures for keeping it up to date. Tool-agnostic – specifies WHAT and FROM WHERE knowledge flows, not HOW to store it technically. Specification ready for implementation by the client's IT team or a contractor
What the client receives:
- Knowledge architecture document with justification for decisions
- A map of relationships between concepts and data with owners, and a glossary of organizational terms
- Knowledge governance rules: who is responsible, how changes are implemented, how its currency is maintained
- Technical specification for the team that will build the system