CDF – AI deployment methodology

| Stage | Name | Goal | Main output |
|---|---|---|---|
| CDF-F0 | Recognition and configuration | assess organizational readiness for AI deployment | deployment profile and initial recommendation |
| CDF-F1 | AI strategy and architecture | turn diagnosis into management and architecture decisions | approved AI strategy and sovereignty model |
| CDF-F1.5 | Compliance-first delivery | prepare compliance before technical deployment | AI Act, DORA, NIS2 and GDPR evidence package |
| CDF-F2 | AI governance and security | define responsibilities, registers and controls | AI governance and security system |
| CDF-F3 | Change management and competence | prepare people for AI-supported work | competence program and adoption plan |
| CDF-F4 | Cognitive sprint | pilot deployment with quality and compliance measurement | sprint report and scale-or-kill decision |
| CDF-F5 | Verification, scaling and acceptance | confirm production readiness and scaling | acceptance and scaling plan |
| CDF-F6 | Cognitive operations | ongoing maintenance of AI quality, knowledge and compliance | cyclical CogOps model |
Organization before transformation
Most organizations that come to allclouds have already gone through initial experiments with AI. A few pilots, purchased tool licenses, maybe an internal ChatGPT usage policy issued by IT. And a sense that something is off – AI is being used, but it is unclear how, by whom, with what effect, and whether it is compliant with the law. We most often encounter one of five symptoms
- Perpetual pilotThe organization has already run three or four AI pilots, each with good results, but none has entered everyday use
- Scaling paralysisOne department implemented AI successfully, but no one knows how to transfer it to the others
- Governance blockadeThe board wants to roll out AI, but the legal and compliance departments block every initiative because there is no policy
- Cultural resistanceEmployees are afraid of AI or use it secretly, bypassing procedures
- Unprepared dataData exist, but they are scattered, inconsistent, and ownerless – AI has nothing to work with
Before we put anything into the schedule and before any funds are committed, we ask one question: is this organization ready? The answer is the Preliminary Assessment (CDF-Eval). One or two days at the client's premises, a hundred-odd interviews conducted in parallel by AI, six readiness areas checked to the core – and a clear recommendation: deploy, deploy conditionally, or do not deploy. We do not diagnose to sell more services. We diagnose so as not to implement the wrong solution for the right problem – nor the right solution for the wrong problem. That is why the Preliminary Assessment sometimes ends with the recommendation "do not deploy". It is honest toward the client and sensible for both parties
Preliminary Assessment – is the organization ready for CDF (CDF-Eval)
Before the first zloty goes into the schedule, we need to know who we are entering the project with. The Preliminary Assessment is not a conversation with the IT director and a quick presentation to the board. It is a systematic examination of the readiness of the entire organization: from operational staff, through managers, to the board. A hundred-odd parallel interviews conducted by AI within one or two days. No data leaves the client's premises
We examine six areas: AI awareness and digital competencies, process maturity and readiness for automation, organizational culture and readiness for change, knowledge management and data availability, governance and regulatory readiness, IT infrastructure and data condition
The result is the AI Readiness Index (0–100), a map of people who will support the change and those who will hinder it, a list of gaps and – above all – a clear recommendation:
- Implement (Go) – the organization is ready for the full CDF program
- Implement conditionally (Conditional Go) – ready after specific conditions are met; the client receives a preparatory plan with a schedule and persons responsible
- Do not implement (No-Go) – the organization needs time to mature. We return in 6–12 months. This is not a failure, but honesty. Better to hear this at the assessment stage than after a year of a failed project
Stage result: AI Readiness Index, a detailed diagnostic report, an executive summary (max. 2 A4 pages), a list of candidates for AI leaders, a preparatory plan (for a conditional recommendation)
CDF-F0 Discovery
CDF-F0.K Company knowledge audit · CDF-F0.L Assessment of legacy systems for AI
Every AI implementation at allclouds begins with a diagnosis. Not with a presentation of our products or the choice of tools – but with the question: where are you and where do you want to get to. It sounds banal, but in practice organizations rarely have a coherent answer to this simultaneously at the board, IT and operational levels
The discovery phase (F0) usually lasts two to four weeks. We talk to people: the CEO and a salesperson, the IT architect and the lawyer, HR and the compliance officer. Each conversation reveals a different fragment of the picture. We combine them into an assessment of organizational maturity in four areas: data, governance, competencies and psychological readiness. On that basis we build the organization's implementation profile (ACE Configuration Profile), which defines which stages, controls and documents are appropriate for that particular company
In parallel with or immediately after discovery we conduct the company knowledge audit (F0.K). This is often the most revealing moment of the project. Organizations do not know what they know. Key procedures live only in the heads of two experts nearing retirement. Client engagement terms are on one salesperson's local drive. The regulations underpinning the entire operation have no owner. Without organizing this knowledge no AI system will operate reliably – it will respond in a certain tone but based on incomplete or outdated data
If the organization has many legacy systems – decade-old applications, accounting or sales systems, file-based processes and manual data transfers – we run an additional F0.L stage: an assessment of those systems for AI. The aim is not to persuade replacement of old systems or to bolt AI onto every one of them. The aim is a reliable answer: which systems are ready for AI now, which require first a process or data rebuild, and which should be omitted for the time being. The result is a modernization priority list that feeds the strategy (F1), the pilot (F4) and the implementation plan (WDR-05). Without it, organizations with many legacy systems often fall into scaling paralysis – not because AI does not work, but because old systems have no way to accept it
Stage result: we know what exists, we know what is missing, we know where to start. The organization has an implementation profile, a map of processes and decisions with AI potential, a knowledge register and a document that from the outset defines the project's completion conditions (Scale Path Definition)
Strategic decisions and regulatory compliance
CDF-F1 AI strategy and architecture · CDF-F1.5 Compliance first
Diagnosis without decisions is analysis for the sake of analysis. Stage F1 shifts the emphasis from recognition to action. Three decisions are key and must be made before any proper implementation
North Star – a single measurable business objective for the AI program, approved by the board. Not a generic slogan about innovation, but a concrete, verifiable outcome: shorten application processing time by 40% within 18 months, increase the number of offers by 30% without expanding the team, close monthly books in 2 days instead of 5. This objective becomes the criterion for every subsequent decision and the metric used to evaluate the "scale-or-kill" decision
Sovereignty model – where data and AI models will be physically processed. This is simultaneously an architectural, legal and geopolitical decision. For a bank or public authority, regulations often determine the answer: data must remain in Poland or the EU, and providers from outside Europe are excluded. For the defense sector the question concerns physical isolation from the internet. Our sovereignty matrix allows assessing the geopolitical risk of each solution component – separately for providers from the USA, China and Europe
Built-in compliance from the start – stage F1.5 is mandatory for organizations in regulated sectors. We check gaps against the AI Act, DORA, NIS2 and the Act on the National Cybersecurity System, GDPR, ISO 42001 and the Polish Act on Artificial Intelligence Systems (in draft). The outcome: AI Act readiness assessment (0–100%), a declaration of application, an AI system impact assessment report and a security annex for IT vendor contracts ready for signature. Compliance is not a checklist at the end of the project – it is a precondition for entering proper implementation
Organizations that skip stage F1.5 and return to it after launching the system incur significantly higher adaptation costs than those that built compliance in from the start (industry studies: 2–3 times more, depending on the sector). Patching compliance retroactively is one of the most expensive mistakes in AI transformation
Oversight: structure before tools
CDF-F2 AI Oversight and Security
Most organizations think of AI oversight as a roles table and a policy document. Where autonomous AI agents operate, oversight is fundamentally different: it is a control architecture. Who granted this agent permissions to act? At what level of autonomy does it operate? What will happen if it makes a mistake? Who is informed about it, within what timeframe and by which channel?
In stage F2 we build the AI Agents Register – a central inventory of all agents in the organization. It is not a list of tools. Each entry contains the agent's digital identity, scope of permissions, level of autonomy on a scale from 0 to 4, business owner, consumption limit and an emergency shutdown procedure. Without this register the organization does not know what acts on its behalf
The Human Competence Gate is a mechanism that provokes resistance in every organization – until they see the first incident it would have prevented. Before an employee approves a critical AI-recommended decision – acceptance of a loan application, selection of a contractor, modification of a contract – the system asks 5–15 verification questions to check whether they understand the key facts and consequences. Too few correct answers block the approval. This is not an impediment. It is a guarantee that a human truly supervises rather than just clicks "Approve"
Uncontrolled AI agents (Shadow Agent Governance) is an issue that appears in every organization without exception. Employees install their own agents, build automations and connect external AI models to the company's sales system in ways that move customer data outside the EU. A discovery scan always reveals findings that surprise even the CIO. The goal is not to punish initiative – it is to create a path to legalization and continuous monitoring so that grassroots innovation does not become a risk for the entire company
Outcome of the stage: the organization knows who or what makes decisions on its behalf, at what level of autonomy, with what escalation path and with which immutable event log. This is the foundation without which no audit – internal or external – can be reliable
People: the hardest part of transformation
CDF-F3 Change Management and Capability Building
AI transformations do not fail because of bad technology. They fail because of people who are afraid, do not understand, do not trust or feel sidelined. After more than a dozen deployments in regulated sectors we know that change management is harder than configuring agents. There is no algorithm for this. There are, however, a few things that always work
The initial drop is inevitable. In the first 3–9 months after deployment organizational productivity falls by 10–30%. People are learning new tools, processes and habits. A board that is unprepared will draw premature conclusions. An AI program that does not plan for this drop is usually judged a failure precisely when it is on the right track. Therefore managing this curve is part of every project: we announce the drop in advance, include it in the schedule and define the rebound point
AI Champions are an investment, not a cost. In each department we appoint and train an internal AI leader – a person who knows their department and can translate AI capabilities into real use cases. Champions are not tool administrators. They are change ambassadors, the first line of support for colleagues and a feedback channel to the AI council. Without them the AI program loses its foothold in daily work
The CDF Academy provides a certificate, not just information. 40 hours across three tracks: a basic track for everyone, a specialist role-based track and an oversight track for the AI council and IT leaders. Each track ends with an internal certification. This is not slideware training. The aim is for the employee to leave the room with concrete skills: how to formulate a prompt to analyze a contract, how to spot a fabricated AI response and how to report an incident
Organizations that invest in AI Champions and the CDF Academy before launching their first agents achieve 50–70% active users after 12 weeks and 70–85% within 6–12 months. Organizations that start training after deployment rarely exceed 40% in the same timeframe
Cognitive sprint: the first real value
CDF-F4 Pilot deployment (Cognitive Sprint)
An AI pilot should deliver value within 2–4 weeks of start. If it does not, there is something wrong with the scope, the data or the process we are trying to support. A cognitive sprint is not a research project. It is delivering value step by step, with built-in measurement of the quality of AI responses
Cognitive quality metrics (Cognitive SLA) are something no standard Agile methodology includes. We measure not only whether the system works, but whether it thinks correctly. Accuracy of responses – the percentage consistent with expert knowledge. Rate of fabricated responses – for critical use cases the target: below 2%. Incident response time – in critical processes: under 15 minutes. These measures are not ornamentation – they are a commitment to the business
The "scale-or-kill" gate (Scale-or-Kill Gate) is the element that provokes the most discussion in every project. At the end of the pilot there is only one question: do we scale or do we stop? There is no option to extend. This is deliberate. A perpetual pilot – the organization has been running it for 18 months because no one wants to decide – costs more than closing a failed project. Ending is not a failure: it is avoiding a large investment in the wrong direction. Production deployment typically costs 3–5 times the pilot. A good decision to stop saves more than a failed implementation
Stage outcome: an operational pilot with measurable quality metrics, an approved "scale-or-kill" decision, and a preliminary evidentiary package for ISO 42001. For the first time the organization knows based on data – not intuition – whether its AI thinks correctly
Daily use and scaling
CDF-F5 Verification, scaling and acceptance
Transitioning from pilot to daily use is not a button click. It is a change of operating mode: operational, legal and organizational. Stage F5 begins with a quality review – a formal inspection of all documents from stages F0–F4 for completeness and compliance. Only after that do we proceed with verification
For high‑risk AI systems (Annex III AI Act) a conformity assessment – internal or by a designated external body, depending on the system category – is required before being put into use; public bodies must also register the system in the EU database (art. 49 AI Act). We guide the client through this process as an experienced partner – not a bystander
Redesign the process first, then add AI. This principle meets resistance because it lengthens the project. But AI applied to an inefficient process multiplies that inefficiency. Automating a bad procedure produces bad results faster. Redesign takes time and the involvement of process owners, but this is where 80% of the potential value lies
We scale in waves: first the pilot team, then departments with similar processes, and finally the whole organization. Each wave has AI leaders, scheduled training and a readiness criterion. The company's AI systems catalog – a collection of proven use cases with before-and-after results – becomes an internal asset that accelerates every subsequent wave
Outcome of the stage: formal acceptance of the implementation, conformity assessment report, acceptance protocol, AI systems catalog and scaling wave schedule. The organization moves from a project to a program
Cognitive organization: ongoing maintenance (CogOps)
CDF-F6 Cognitive operations – steady‑state service model
Launching an AI system is not the end of the project – it is the end of the startup phase. AI systems break. Models drift. Knowledge bases age. Regulations change. New employees do not know how to work with AI. An organization that has deployed AI and has no maintenance model will lose most of the value it created within 6–12 months
CogOps is the maintenance model for AI systems that are already in daily use – the equivalent of what ITIL is for IT infrastructure, but designed for thinking systems. Delivered as a monthly retainer service with a dedicated allclouds consultant
Key elements. Monitoring seven quality indicators of AI responses with a three‑stage reaction procedure: yellow (24 h), orange (72 h), red (7 days or immediate shutdown when fabricated responses in critical processes exceed 5%). Freshness indicator: whether the regulations used by AI agents are from this week or two years ago. Agent lifecycle management – from registration to formal decommissioning with memory archiving. Post‑deployment monitoring across six categories according to the NIST standard: performance, operations, human factors (overreliance on automation, skill degradation), security, compliance and large‑scale impact
The quarterly review is the moment when we check whether the AI policy still matches reality. Over a quarter new tools appear, regulations change, and employees discover new ways of using AI – both good and bad. CogOps provides a continuous learning loop that prevents the organization from returning to square one after each environmental change
Outcome of the CogOps model: an organization that maintains AI quality over time, responds to regulatory changes before they become a problem, and knows – based on data – whether its AI systems are thinking correctly each day
Organization after transformation
An organization that has completed the full path – from F0 to F6 – looks different than before the project. It is not about AI tools on employees' screens. It is about decision structures, work culture and the capacity for continuous learning
- Every AI decision has an owner and a chain of responsibility. The agents register shows at any time who or what is acting on behalf of the organization and with what level of autonomy. An immutable event log documents every human–AI interaction. No auditor will hear: we don't know
- Employees neither fear AI nor trust it blindly. They understand where AI is reliable – speed, scale, processing – and where it fails – fabricated answers, lack of emotional context, lack of accountability. The division of labor between humans and AI has become a habit, not a document
- Compliance is not a project. The regulatory schedule tracks upcoming deadlines. The quarterly review updates AI policy with every environmental change. The organization understands that the AI Act, CRA, NIS2 and the Polish Act on AI Systems are not one‑off checklists but ongoing commitments
- And finally: the organization has data. From the AI quality dashboard, usage reports and the freshness indicator it knows whether its AI is working correctly, whether it is being used, and whether the knowledge it relies on is up to date. This enables decisions about AI based on facts, not intuition
AI transformation does not end on the day of deployment. It ends when the organization can independently manage its AI – update policy, deploy new agents, respond to incidents and prepare for regulatory changes – without continuous dependence on an external partner. This is allclouds' goal: to build organizations that own AI, not organizations that are owned by AI