allclouds.pl

CDF – AI deployment methodology

CDF – AI deployment methodology
StageNameGoalMain output
CDF-F0Recognition and configurationassess organizational readiness for AI deploymentdeployment profile and initial recommendation
CDF-F1AI strategy and architectureturn diagnosis into management and architecture decisionsapproved AI strategy and sovereignty model
CDF-F1.5Compliance-first deliveryprepare compliance before technical deploymentAI Act, DORA, NIS2 and GDPR evidence package
CDF-F2AI governance and securitydefine responsibilities, registers and controlsAI governance and security system
CDF-F3Change management and competenceprepare people for AI-supported workcompetence program and adoption plan
CDF-F4Cognitive sprintpilot deployment with quality and compliance measurementsprint report and scale-or-kill decision
CDF-F5Verification, scaling and acceptanceconfirm production readiness and scalingacceptance and scaling plan
CDF-F6Cognitive operationsongoing maintenance of AI quality, knowledge and compliancecyclical CogOps model

Organization before transformation

Most organizations that come to allclouds have already gone through initial experiments with AI. A few pilots, purchased tool licenses, maybe an internal ChatGPT usage policy issued by IT. And a sense that something is off – AI is being used, but it is unclear how, by whom, with what effect, and whether it is compliant with the law. We most often encounter one of five symptoms

Before we put anything into the schedule and before any funds are committed, we ask one question: is this organization ready? The answer is the Preliminary Assessment (CDF-Eval). One or two days at the client's premises, a hundred-odd interviews conducted in parallel by AI, six readiness areas checked to the core – and a clear recommendation: deploy, deploy conditionally, or do not deploy. We do not diagnose to sell more services. We diagnose so as not to implement the wrong solution for the right problem – nor the right solution for the wrong problem. That is why the Preliminary Assessment sometimes ends with the recommendation "do not deploy". It is honest toward the client and sensible for both parties

Preliminary Assessment – is the organization ready for CDF (CDF-Eval)

Before the first zloty goes into the schedule, we need to know who we are entering the project with. The Preliminary Assessment is not a conversation with the IT director and a quick presentation to the board. It is a systematic examination of the readiness of the entire organization: from operational staff, through managers, to the board. A hundred-odd parallel interviews conducted by AI within one or two days. No data leaves the client's premises

We examine six areas: AI awareness and digital competencies, process maturity and readiness for automation, organizational culture and readiness for change, knowledge management and data availability, governance and regulatory readiness, IT infrastructure and data condition

The result is the AI Readiness Index (0–100), a map of people who will support the change and those who will hinder it, a list of gaps and – above all – a clear recommendation:

Stage result: AI Readiness Index, a detailed diagnostic report, an executive summary (max. 2 A4 pages), a list of candidates for AI leaders, a preparatory plan (for a conditional recommendation)

CDF-F0 Discovery

CDF-F0.K Company knowledge audit · CDF-F0.L Assessment of legacy systems for AI

Every AI implementation at allclouds begins with a diagnosis. Not with a presentation of our products or the choice of tools – but with the question: where are you and where do you want to get to. It sounds banal, but in practice organizations rarely have a coherent answer to this simultaneously at the board, IT and operational levels

The discovery phase (F0) usually lasts two to four weeks. We talk to people: the CEO and a salesperson, the IT architect and the lawyer, HR and the compliance officer. Each conversation reveals a different fragment of the picture. We combine them into an assessment of organizational maturity in four areas: data, governance, competencies and psychological readiness. On that basis we build the organization's implementation profile (ACE Configuration Profile), which defines which stages, controls and documents are appropriate for that particular company

In parallel with or immediately after discovery we conduct the company knowledge audit (F0.K). This is often the most revealing moment of the project. Organizations do not know what they know. Key procedures live only in the heads of two experts nearing retirement. Client engagement terms are on one salesperson's local drive. The regulations underpinning the entire operation have no owner. Without organizing this knowledge no AI system will operate reliably – it will respond in a certain tone but based on incomplete or outdated data

If the organization has many legacy systems – decade-old applications, accounting or sales systems, file-based processes and manual data transfers – we run an additional F0.L stage: an assessment of those systems for AI. The aim is not to persuade replacement of old systems or to bolt AI onto every one of them. The aim is a reliable answer: which systems are ready for AI now, which require first a process or data rebuild, and which should be omitted for the time being. The result is a modernization priority list that feeds the strategy (F1), the pilot (F4) and the implementation plan (WDR-05). Without it, organizations with many legacy systems often fall into scaling paralysis – not because AI does not work, but because old systems have no way to accept it

Stage result: we know what exists, we know what is missing, we know where to start. The organization has an implementation profile, a map of processes and decisions with AI potential, a knowledge register and a document that from the outset defines the project's completion conditions (Scale Path Definition)

Strategic decisions and regulatory compliance

CDF-F1 AI strategy and architecture · CDF-F1.5 Compliance first

Diagnosis without decisions is analysis for the sake of analysis. Stage F1 shifts the emphasis from recognition to action. Three decisions are key and must be made before any proper implementation

North Star – a single measurable business objective for the AI program, approved by the board. Not a generic slogan about innovation, but a concrete, verifiable outcome: shorten application processing time by 40% within 18 months, increase the number of offers by 30% without expanding the team, close monthly books in 2 days instead of 5. This objective becomes the criterion for every subsequent decision and the metric used to evaluate the "scale-or-kill" decision

Sovereignty model – where data and AI models will be physically processed. This is simultaneously an architectural, legal and geopolitical decision. For a bank or public authority, regulations often determine the answer: data must remain in Poland or the EU, and providers from outside Europe are excluded. For the defense sector the question concerns physical isolation from the internet. Our sovereignty matrix allows assessing the geopolitical risk of each solution component – separately for providers from the USA, China and Europe

Built-in compliance from the start – stage F1.5 is mandatory for organizations in regulated sectors. We check gaps against the AI Act, DORA, NIS2 and the Act on the National Cybersecurity System, GDPR, ISO 42001 and the Polish Act on Artificial Intelligence Systems (in draft). The outcome: AI Act readiness assessment (0–100%), a declaration of application, an AI system impact assessment report and a security annex for IT vendor contracts ready for signature. Compliance is not a checklist at the end of the project – it is a precondition for entering proper implementation

Organizations that skip stage F1.5 and return to it after launching the system incur significantly higher adaptation costs than those that built compliance in from the start (industry studies: 2–3 times more, depending on the sector). Patching compliance retroactively is one of the most expensive mistakes in AI transformation

Oversight: structure before tools

CDF-F2 AI Oversight and Security

Most organizations think of AI oversight as a roles table and a policy document. Where autonomous AI agents operate, oversight is fundamentally different: it is a control architecture. Who granted this agent permissions to act? At what level of autonomy does it operate? What will happen if it makes a mistake? Who is informed about it, within what timeframe and by which channel?

In stage F2 we build the AI Agents Register – a central inventory of all agents in the organization. It is not a list of tools. Each entry contains the agent's digital identity, scope of permissions, level of autonomy on a scale from 0 to 4, business owner, consumption limit and an emergency shutdown procedure. Without this register the organization does not know what acts on its behalf

The Human Competence Gate is a mechanism that provokes resistance in every organization – until they see the first incident it would have prevented. Before an employee approves a critical AI-recommended decision – acceptance of a loan application, selection of a contractor, modification of a contract – the system asks 5–15 verification questions to check whether they understand the key facts and consequences. Too few correct answers block the approval. This is not an impediment. It is a guarantee that a human truly supervises rather than just clicks "Approve"

Uncontrolled AI agents (Shadow Agent Governance) is an issue that appears in every organization without exception. Employees install their own agents, build automations and connect external AI models to the company's sales system in ways that move customer data outside the EU. A discovery scan always reveals findings that surprise even the CIO. The goal is not to punish initiative – it is to create a path to legalization and continuous monitoring so that grassroots innovation does not become a risk for the entire company

Outcome of the stage: the organization knows who or what makes decisions on its behalf, at what level of autonomy, with what escalation path and with which immutable event log. This is the foundation without which no audit – internal or external – can be reliable

People: the hardest part of transformation

CDF-F3 Change Management and Capability Building

AI transformations do not fail because of bad technology. They fail because of people who are afraid, do not understand, do not trust or feel sidelined. After more than a dozen deployments in regulated sectors we know that change management is harder than configuring agents. There is no algorithm for this. There are, however, a few things that always work

The initial drop is inevitable. In the first 3–9 months after deployment organizational productivity falls by 10–30%. People are learning new tools, processes and habits. A board that is unprepared will draw premature conclusions. An AI program that does not plan for this drop is usually judged a failure precisely when it is on the right track. Therefore managing this curve is part of every project: we announce the drop in advance, include it in the schedule and define the rebound point

AI Champions are an investment, not a cost. In each department we appoint and train an internal AI leader – a person who knows their department and can translate AI capabilities into real use cases. Champions are not tool administrators. They are change ambassadors, the first line of support for colleagues and a feedback channel to the AI council. Without them the AI program loses its foothold in daily work

The CDF Academy provides a certificate, not just information. 40 hours across three tracks: a basic track for everyone, a specialist role-based track and an oversight track for the AI council and IT leaders. Each track ends with an internal certification. This is not slideware training. The aim is for the employee to leave the room with concrete skills: how to formulate a prompt to analyze a contract, how to spot a fabricated AI response and how to report an incident

Organizations that invest in AI Champions and the CDF Academy before launching their first agents achieve 50–70% active users after 12 weeks and 70–85% within 6–12 months. Organizations that start training after deployment rarely exceed 40% in the same timeframe

Cognitive sprint: the first real value

CDF-F4 Pilot deployment (Cognitive Sprint)

An AI pilot should deliver value within 2–4 weeks of start. If it does not, there is something wrong with the scope, the data or the process we are trying to support. A cognitive sprint is not a research project. It is delivering value step by step, with built-in measurement of the quality of AI responses

Cognitive quality metrics (Cognitive SLA) are something no standard Agile methodology includes. We measure not only whether the system works, but whether it thinks correctly. Accuracy of responses – the percentage consistent with expert knowledge. Rate of fabricated responses – for critical use cases the target: below 2%. Incident response time – in critical processes: under 15 minutes. These measures are not ornamentation – they are a commitment to the business

The "scale-or-kill" gate (Scale-or-Kill Gate) is the element that provokes the most discussion in every project. At the end of the pilot there is only one question: do we scale or do we stop? There is no option to extend. This is deliberate. A perpetual pilot – the organization has been running it for 18 months because no one wants to decide – costs more than closing a failed project. Ending is not a failure: it is avoiding a large investment in the wrong direction. Production deployment typically costs 3–5 times the pilot. A good decision to stop saves more than a failed implementation

Stage outcome: an operational pilot with measurable quality metrics, an approved "scale-or-kill" decision, and a preliminary evidentiary package for ISO 42001. For the first time the organization knows based on data – not intuition – whether its AI thinks correctly

Daily use and scaling

CDF-F5 Verification, scaling and acceptance

Transitioning from pilot to daily use is not a button click. It is a change of operating mode: operational, legal and organizational. Stage F5 begins with a quality review – a formal inspection of all documents from stages F0–F4 for completeness and compliance. Only after that do we proceed with verification

For high‑risk AI systems (Annex III AI Act) a conformity assessment – internal or by a designated external body, depending on the system category – is required before being put into use; public bodies must also register the system in the EU database (art. 49 AI Act). We guide the client through this process as an experienced partner – not a bystander

Redesign the process first, then add AI. This principle meets resistance because it lengthens the project. But AI applied to an inefficient process multiplies that inefficiency. Automating a bad procedure produces bad results faster. Redesign takes time and the involvement of process owners, but this is where 80% of the potential value lies

We scale in waves: first the pilot team, then departments with similar processes, and finally the whole organization. Each wave has AI leaders, scheduled training and a readiness criterion. The company's AI systems catalog – a collection of proven use cases with before-and-after results – becomes an internal asset that accelerates every subsequent wave

Outcome of the stage: formal acceptance of the implementation, conformity assessment report, acceptance protocol, AI systems catalog and scaling wave schedule. The organization moves from a project to a program

Cognitive organization: ongoing maintenance (CogOps)

CDF-F6 Cognitive operations – steady‑state service model

Launching an AI system is not the end of the project – it is the end of the startup phase. AI systems break. Models drift. Knowledge bases age. Regulations change. New employees do not know how to work with AI. An organization that has deployed AI and has no maintenance model will lose most of the value it created within 6–12 months

CogOps is the maintenance model for AI systems that are already in daily use – the equivalent of what ITIL is for IT infrastructure, but designed for thinking systems. Delivered as a monthly retainer service with a dedicated allclouds consultant

Key elements. Monitoring seven quality indicators of AI responses with a three‑stage reaction procedure: yellow (24 h), orange (72 h), red (7 days or immediate shutdown when fabricated responses in critical processes exceed 5%). Freshness indicator: whether the regulations used by AI agents are from this week or two years ago. Agent lifecycle management – from registration to formal decommissioning with memory archiving. Post‑deployment monitoring across six categories according to the NIST standard: performance, operations, human factors (overreliance on automation, skill degradation), security, compliance and large‑scale impact

The quarterly review is the moment when we check whether the AI policy still matches reality. Over a quarter new tools appear, regulations change, and employees discover new ways of using AI – both good and bad. CogOps provides a continuous learning loop that prevents the organization from returning to square one after each environmental change

Outcome of the CogOps model: an organization that maintains AI quality over time, responds to regulatory changes before they become a problem, and knows – based on data – whether its AI systems are thinking correctly each day

Organization after transformation

An organization that has completed the full path – from F0 to F6 – looks different than before the project. It is not about AI tools on employees' screens. It is about decision structures, work culture and the capacity for continuous learning

AI transformation does not end on the day of deployment. It ends when the organization can independently manage its AI – update policy, deploy new agents, respond to incidents and prepare for regulatory changes – without continuous dependence on an external partner. This is allclouds' goal: to build organizations that own AI, not organizations that are owned by AI