allclouds.pl
SAIE products / CDF methodology

CDF — an AI deployment methodology

The Cognitive Deployment Framework takes an organisation from readiness assessment through strategy, compliance, governance and people to piloting, scaling and ongoing operations. Every AI decision has an owner, context and evidence

Book an initial assessmentBook a demonstration
8phases from F0 to F6
2–4 weeksto first pilot value
0–100AI readiness score
ISO 42001certified methodology
THE ORGANISATION BEFORE TRANSFORMATION

AI is being used, but nobody knows how, by whom or with what results

Most organisations approaching allclouds have already made initial attempts: a few pilots, purchased licences, perhaps an IT-issued ChatGPT policy. We most often see one of five symptoms

The endless pilotthree or four pilots with good results, but none in everyday use
Scaling paralysisone department successfully deployed AI, but nobody knows how to extend it to the rest
Governance deadlockmanagement wants AI, but legal and compliance teams block every initiative because there is no policy
Cultural resistanceemployees fear AI or use it secretly, bypassing procedures
Unprepared datadata exists, but is scattered, inconsistent and ownerless
THE F0–F6 PATH

Eight phases and an assessment at the start

Every phase has a verifiable outcome
Eval · Initial assessment · F0 · Discovery · F1 · Strategy · F1.5 · Compliance · F2 · Oversight · F3 · People · F4 · Sprint · cognitive · F5 · Scaling · F6 · CogOps · Is the organisation · ready? · CDF-Eval · diagnosis, audit · knowledge, systems · 2–4 weeks · purpose, sovereignty, · architecture · AI Act, DORA, · NIS2, GDPR · required · in regulated · agent register, · gates · change, champions, · academy · pilot and “scale · or stop” · 2–4 weeks · compliance assessment, · waves · ongoing operations · every month
INITIAL ASSESSMENT

Is the organisation ready to deploy AI?

CDF-Eval

Before anything enters the schedule or any price is quoted

A systematic readiness assessment of the entire organisation — from operational staff through managers to the board. Over a hundred parallel AI-led interviews over one or two days at the customer's premises. No data leaves the organisation

We do not diagnose to sell more services. We diagnose to avoid deploying the wrong solution to the right problem — or the right solution to the wrong problem. That is why an initial assessment sometimes recommends not deploying AI

Stage outcomeAn AI readiness score (0–100), a map of supporters and barriers to change, a diagnostic report, an executive summary (up to two A4 pages), a list of AI champion candidates and — for a conditional recommendation — a preparation plan
Six areas, one recommendation
AI awareness · and digital skills · Process maturity · and automation readiness · Organisational culture · and readiness for change · Knowledge management · and data availability · Oversight · and regulatory readiness · IT infrastructure · and data condition · Assessment · assessment · CDF-Eval · AI-led interviews · 1–2 days on site · Readiness score · 0–100 · executive report · up to 2 A4 pages · Deploy · ready for the full CDF programme · Conditional · preparation plan with a schedule · Do not deploy · reassess in 6–12 months · SIX READINESS AREAS · CLEAR RECOMMENDATION
F0 · DISCOVERY

Where you are and where you want to go

CDF-F0.K Company knowledge audit · CDF-F0.L Legacy system assessment

Two to four weeks of conversations — with the CEO and sales team, IT architect and lawyer, HR and compliance. We combine these into a maturity assessment across four areas: data, governance, skills and psychological readiness. This produces an ACE Configuration Profile defining the stages, controls and documents appropriate for the organisation

The knowledge audit (F0.K) is often the most revealing part of the project. Key procedures exist only in the minds of two experts approaching retirement; commercial terms sit on one salesperson's drive. Without organising this knowledge, AI will confidently answer using incomplete data

Where there are many legacy systems, we conduct an F0.L assessment: which are ready for AI now, which require process or data redesign, and which should be left aside for the time being

Stage outcomea deployment profile, a map of processes and decisions with AI potential, a knowledge register and a document defining project exit conditions from the outset (Scale Path Definition)
F1 · F1.5 · STRATEGY AND COMPLIANCE

Three decisions before any deployment

Diagnosis without decisions is analysis for its own sake. CDF-F1 AI strategy and architecture · CDF-F1.5 Compliance first

01North Star objectiveone measurable goal approved by the board, such as reducing application handling time by 40% within 18 months. It becomes the benchmark for the “scale or stop” decision
02Sovereignty modelwhere data and models will physically be processed. The sovereignty matrix assesses each component's risk separately for US, Chinese and European providers
03Compliance built in from the startgaps against the AI Act, DORA, NIS2 and Polish KSC, GDPR, ISO 42001 and the draft Polish AI Systems Act. Outputs: AI Act readiness assessment (0–100%), statement of applicability, impact assessment report and security annex for IT supplier contracts
2–3×

organisations that return to compliance after launch incur higher adaptation costs (industry research, varying by sector). Retrofitting compliance is one of the most expensive AI transformation mistakes

F2 · GOVERNANCE

Structure before tools

CDF-F2 AI governance and security
AI agent registerentry 14 / 37
Identityinvoice-agent-01 · digital certificate
PermissionsKSeF access, draft accounting entry
Autonomy
OwnerFinance Director
Limit
monthly budget, 2,000 calls per day
Emergency shutdown procedure
Example entry — autonomy level on a 0–4 scale

Where autonomous AI agents operate, governance is an architecture of control: who granted an agent permission, how independently it acts, what happens if it makes a mistake, and who finds out — how quickly and through which channel

The AI agent register is the central inventory of all agents in the organisation. Each entry records a digital identity, permissions, autonomy level (0–4), business owner, usage limit and emergency shutdown procedure

Uncontrolled agents appear in every organisation. Shadow Agent Governance is not about punishing initiative, but providing a path to approval and continuous monitoring

Stage outcomethe organisation knows who or what makes decisions on its behalf, with which autonomy, escalation path and immutable event log
Human Competence Gate

People genuinely supervise instead of just clicking “Approve”

Before an employee approves a critical AI-recommended decision — a loan application, supplier selection or contract change — the system asks 5–15 questions to check their understanding of key facts and consequences. Too few correct answers block approval

Question 3 of 8 · Human Competence Gate
What is the payment deadline in the recommended supplier contract?
Correct: 2 / 2Approve the decision
F3 · PEOPLE

The hardest part of transformation

CDF-F3 Change management and capability building
The change curve — anticipated and included in the schedule
3–9 months · 10–30% decline · Recovery point · AI champions and Academy · 70–85% · active within 6–12 months · BASELINE

AI transformations fail because of people who are afraid, do not understand or feel excluded — not because of technology. Productivity drops by 10–30% in the first 3–9 months. A programme that does not plan for this is judged a failure precisely when it is on the right track

AI Champions in every department are ambassadors for change, the first line of support and a feedback channel to the AI board

CDF Academy: 40 hours across three tracks — foundational, role-specific and supervisory — each ending with internal certification. Employees leave with concrete skills: how to formulate instructions, detect a fabricated answer and report an incident

50–70%active users after 12 weeks when champions and the Academy start before the first agents
70–85%within 6–12 months
<40%rarely more when training starts after deployment
F4 · COGNITIVE SPRINT

First real value in 2–4 weeks

CDF-F4 Pilot deployment (Cognitive Sprint)

A Cognitive Sprint is not a research project. It delivers value step by step, with built-in measurement of AI answer quality. If a pilot does not deliver value in 2–4 weeks, something is wrong with its scope, data or process

The Scale-or-Kill Gate: at the end of the pilot there is one question and no extension option. Production deployment costs on average 3–5 times as much as a pilot — a good decision to stop saves more than an unsuccessful deployment

Stage outcomea working pilot with measurable quality indicators, an approved “scale or stop” decision and an initial ISO 42001 evidence pack
accuracypercentage of answers consistent with expert knowledge
<2%fabricated answers in critical applications
<15 minincident response in critical processes — a Cognitive SLA is an agreement with the business, not decoration
F5 · ADOPTION AND SCALING

From project to programme

CDF-F5 Verification, scaling and acceptance

This stage starts with a quality review of F0–F4 documents. For high-risk systems (AI Act Annex III), conformity assessment is required before use, and public bodies register the system in the EU database (Article 49). We guide the customer through this process

Redesign the process first, then add AI. Automating a poor procedure produces poor results faster — redesign holds 80% of the potential value

Stage outcomeformal acceptance, a conformity assessment report, an acceptance record, an AI system catalogue and a schedule of scaling waves
From project to programme — three scaling waves
Wave 1 · pilot department · Wave 2 · departments with similar · processes · Wave 3 · the whole organisation · EVERY WAVE: AI CHAMPIONS · TRAINING · READINESS CRITERION
F6 · COGOPS

Ongoing operations for systems that think

CDF-F6 Cognitive operations — a monthly managed service

AI systems break, models drift, knowledge bases age and regulations change. Without an operating model, an organisation loses most of the value it created within 6–12 months. CogOps is an ITIL equivalent designed for thinking systems — with a dedicated allclouds consultant

The Knowledge Freshness Index checks whether regulations used by agents are from this week or two years ago. The agent lifecycle runs from registration to retirement with memory archiving. Quarterly reviews update the AI policy

Stage outcomethe organisation maintains AI quality over time, responds to regulatory changes before they become problems, and uses data to assess whether its systems are thinking correctly
Seven quality indicators and three response levels
Action · Operations · Human factors · Security · Compliance · Large-scale impact · CogOps · F6 · cognitive operations · 7 quality indicators · AI responses · knowledge freshness index · whether regulations are current · Yellow level · response within 24 hours · Orange level · response within 72 hours · Red level · response within 7 days · Immediate shutdown · when fabricated answers · exceed 5% in critical processes · POST-DEPLOYMENT MONITORING · 6 NIST CATEGORIES · RESPONSE LEVEL
THE ORGANISATION AFTER TRANSFORMATION

After F0–F6, the organisation looks different

Every AI decision has an ownerThe agent register shows at any moment who or what acts on behalf of the organisation. An immutable log documents every human–AI interaction. No auditor hears “we don't know”
Employees neither fear AI nor trust it blindlyThey understand where AI is reliable and where it is not. The division of work between people and AI has become a habit, not a document
Compliance is not a projectThe regulatory calendar tracks deadlines, and quarterly reviews update policy. The AI Act, CRA, NIS2 and the Polish AI Systems Act create ongoing obligations
The organisation has dataThe AI quality dashboard, usage reports and Knowledge Freshness Index enable fact-based rather than intuitive decisions about AI
The allclouds goal: build organisations that own AI, rather than being owned by AI
FAQ

Questions about CDF methodology

12 answers

Does CDF impose the same audit rules on every organisation?

No. The Adaptive Configuration Engine (ACE) selects legal requirements and controls for the organisation's profile — differently for a bank and a public authority

How does CDF differ from a standard IT deployment?

It is a proprietary deployment framework combining legal requirements, such as the AI Act, with technical practice. Compliance is built in before solution development starts, not afterwards

How many stages are there in a CDF deployment?

Eight phases — F0 through F6, including F1.5 dedicated to regulatory compliance. They cover 12 knowledge areas and dozens of requirements and control tables

What is the Knowledge Freshness Index?

An indicator in the AI Quality Dashboard that continuously checks whether the knowledge used by a production model is up to date

How does CDF protect know-how when building procedures?

The platform uses a local AI Advisor model, so the documents it analyses never leave the organisation's infrastructure

Does CDF need to be deployed again for every new law?

No. The methodology is deployed once, and the platform generates evidence and artefacts for different regulations. New rules may require updates to controls or templates, but not a new deployment

Does CDF help implement ISO/IEC 42001?

Yes. It provides ready-to-use registers and operational evidence for AI system management and auditing against the standard

How does CDF help demonstrate compliance with the Cyber Resilience Act?

It supports a model SBOM (Software Bill of Materials) and ready-made reporting of compliance with CRA requirements

How does the platform protect budgets against endless pilots?

There is a firm “scale or stop” decision gate at the end of a pilot. Projects without a production prospect end before they consume the budget

Does CDF simplify security audits?

Yes. The automated AIMS evidence pack continuously prepares artefacts for auditors, including the AI System Register and data protection impact assessments (DPIAs)

How is AI reliability measured in CDF?

With three-tier Cognitive SLA indicators that assess decision quality, hallucination levels and knowledge freshness — not just server availability

Who prepares documentation for AI auditors?

The AIMS evidence pack continuously generates documents such as DPIAs and the central AI System Register from the system's activity history

NEXT

What else to explore

You are here:SAIETWIN:DESKPROXY:AICDF methodologyDeployment and securityDevelopment roadmap
CDF methodologyDeployment and security
Next step
Deployment and security

SaaS, On-Premises, Air-Gap, platform architecture and seven ISO standards

Explore deployment and security
SAIEThree layers, one AI workspace — the problem, the solution and who it is for
TWIN:DESKAn AI workspace: domain assistants, company knowledge, agents and 48 features
PROXY:AIAI control gateway: policies, Zero-Code Switch, WORM records and 54 features
Development roadmap110 roadmap items across five quarters, with the option to submit your own needs

https://www.allclouds.pl/en/metodyka-cdf/