AI Adoption Is an Operating Model Problem: 7 Controls Before Scaling AI
- 6 hours ago
- 7 min read
AI adoption is accelerating faster than most organizations are redesigning the work around it.
The 2026 Stanford AI Index reports that 88% of surveyed organizations used AI in at least one business function during 2025, while 70% reported generative AI use in at least one function. At the same time, AI-agent deployment remained in the single digits across nearly all business functions. That gap matters: access to AI is becoming common; disciplined operational integration is not.
For executives, the practical question is no longer simply, "Should we use AI?" It is, "Which work should AI support, what authority should it have, how will people verify its output, and how will we know whether it is actually improving the business?"
That is an operating model problem.
An AI operating model is the connected set of workflows, decision rights, controls, measures, and management routines that determines how AI is used in real work. It is not the AI tool itself. A company can buy excellent technology and still create more risk, rework, or confusion if it has not designed the surrounding management system.
This article outlines seven controls leaders should establish before scaling AI across functions.
1. Define the workflow before selecting the AI use case
The weakest AI implementations often begin with the tool: employees receive access, teams are encouraged to experiment, and leaders then search for places to use it. A stronger approach begins with the work. Map the workflow first; define the intended outcome, time-consuming steps, judgment points, costly errors, sensitive inputs, opportunities for standardization, and decisions that should remain human-owned.
This distinction is supported by field evidence showing that AI performance is highly task-dependent. Dell'Acqua and colleagues conducted a preregistered field experiment involving 758 knowledge workers completing realistic consulting tasks. On tasks within the tested AI capability frontier, participants using AI completed 12.2% more tasks and were 25.1% faster on average, with higher-quality output. On a complex task deliberately selected outside that frontier, AI users were 19% less likely to reach the correct solution.
The implication is not that AI is unreliable. It is that "AI use" is too broad a unit of analysis. Leaders need to identify the specific task, its failure modes, and the conditions under which AI helps or hurts performance.
2. Specify human-AI decision rights
Every material AI-enabled workflow needs an answer to a simple question: who is authorized to decide? AI may generate, summarize, recommend, classify, predict, draft, or automate; those are different levels of influence.
Executives should define what AI may produce without review; what requires human verification; who has final decision authority; what thresholds require escalation; which actions AI may never initiate independently; and who is accountable when an AI-assisted decision creates an adverse outcome. "The AI said so" is not a governance model.
For lower-risk, reversible work, leaders may permit broad AI assistance with sampling and periodic review. For high-consequence financial, legal, clinical, safety, employment, customer, or reputation-sensitive decisions, stronger human review and explicit escalation are generally warranted. The exact threshold should be risk-based; there is no universal evidence-based rule that every AI output requires the same level of approval.
3. Establish verification standards before scaling output
AI can increase throughput. That creates value only when verification keeps pace.
A large field study published in The Quarterly Journal of Economics examined generative AI assistance among 5,172 customer-support agents. Access to AI assistance increased issues resolved per hour by 15% on average, with much larger gains among less experienced and lower-skilled workers. Effects were heterogeneous; the most experienced workers saw smaller speed gains and, on some quality measures, small declines.
Before scaling, define what counts as an acceptable output; which facts must be independently checked; what quality measures must be monitored; how errors will be sampled and reviewed; what evidence justifies broader deployment; and what failure rate triggers rollback or redesign. Verification should be proportionate to consequence.
4. Build data, privacy, security, and confidentiality controls into the workflow
AI governance cannot sit outside normal information governance. Leaders should know what data employees may enter; which systems are approved; whether prompts or outputs may be retained by a vendor; whether confidential, customer, employee, regulated, or proprietary information is involved; what identity and access controls apply; how records will be retained; and how third-party AI risk will be reviewed.
NIST's voluntary AI Risk Management Framework was developed to help organizations manage AI risks across the design, development, deployment, and use of AI systems. Its companion Generative AI Profile adds risk-management considerations specific to generative AI. NIST structures the framework around four functions: Govern, Map, Measure, and Manage.
For most small and mid-sized organizations, the practical lesson is not to build a separate bureaucracy. It is to incorporate AI into existing security, privacy, vendor, compliance, and risk-management processes.
5. Redesign roles, training, and escalation around the new work
Giving employees access to AI changes more than task speed. It can change what expertise is required; which steps remain manual; where errors are likely to occur; what supervisors need to review; how new employees learn; which knowledge becomes standardized; and where responsibility moves within the workflow.
The customer-support study is particularly relevant because the strongest productivity effects accrued to less experienced workers. One plausible interpretation is that AI can transmit elements of high-performer knowledge to employees who have not yet accumulated the same experience. That can be valuable, but it creates a new management requirement: employees need to understand when to use the system, when not to trust it, how to recognize uncertainty, and when escalation is mandatory.
Training should therefore extend beyond prompt-writing. It should include task selection, verification, privacy and confidentiality, known limitations, escalation, documentation, and domain-specific judgment.
6. Measure business value, not AI activity
"Number of AI users" is an adoption metric. It is not a business outcome. An executive dashboard for an AI-enabled workflow should connect usage to results such as cycle time, throughput, labor hours, error or rework rate, customer experience, revenue conversion, margin, quality, compliance exceptions, employee workload, and escalation frequency.
Include balancing measures. A process that becomes 30% faster but creates more errors may have negative value. A drafting tool that saves employee time but increases review time may simply shift work downstream.
Before a pilot begins, write down the prediction: "We expect this AI-enabled workflow to reduce [measure] from [baseline] to [target] within [time or volume], without increasing [balancing measure] beyond [limit]." That forces the organization to define value before it becomes invested in the technology.
7. Create a learning loop, including a way to stop
AI systems, models, vendors, workflows, and employee behavior all change. A deployment that performed acceptably three months ago should not be assumed to remain acceptable indefinitely.
Every material AI use case should have an owner; a review date; performance measures; recorded incidents and exceptions; a mechanism for employee feedback; a process for changing prompts, models, or controls; and a rollback or retirement trigger.
This is where AI governance becomes part of the broader management operating system. If an organization already struggles to document decisions, close corrective actions, maintain reliable metrics, or learn from recurring failures, adding AI can amplify those weaknesses rather than solve them.
Ascendare Group's earlier article, When Growth Outruns the Business: 7 Signs You Need a Management Operating System, addresses the underlying operating-system problem. AI makes that architecture more important, not less.
A practical AI operating model for executives
Before scaling a material AI use case, the leadership team should be able to answer seven questions clearly: 1) Workflow: What specific business process and outcome are we changing? 2) Authority: What may AI recommend or execute, and who retains final decision rights? 3) Verification: How will we determine whether the output is correct and useful? 4) Information governance: What data may the system access, and what security, privacy, and confidentiality rules apply? 5) Capability: What do employees and managers need to know to use and supervise the system responsibly? 6) Value: Which business measures should improve, and which balancing measures must not deteriorate? 7) Learning: Who reviews results, incidents, model or workflow changes, and the decision to expand, modify, or stop?
If those questions cannot be answered, the organization may be ready to experiment; it is not yet ready to scale.
What the evidence supports; and what remains practitioner judgment
Empirical and authoritative evidence
Current evidence supports several narrower conclusions. Organizational AI adoption is widespread and still increasing, while agentic deployment remains comparatively early, according to the 2026 Stanford AI Index. Field evidence shows that generative AI can materially improve productivity and quality in some knowledge-work settings. The BCG experiment and customer-support study both demonstrate meaningful gains under specific conditions. Those effects are heterogeneous by task and worker; the BCG study also demonstrates that AI assistance can reduce correctness on work outside the tested capability frontier. NIST provides an authoritative voluntary framework for managing AI risk and emphasizes governance, context mapping, measurement, and active risk management.
These findings do not establish that AI will create a positive return in every organization or workflow.
Ascendare Group practitioner judgment
The seven-control AI operating model in this article is Ascendare Group's synthesis of the research above with organizational psychology, operational excellence, management control, finance, and executive decision-system principles. The seven controls have not been validated as a standalone diagnostic instrument. They should be used as a structured executive management framework, then adapted to the organization's risk, industry, technology, and operating environment.
Where to begin
Do not begin with an enterprise-wide AI transformation. Select one workflow where the business consequence is meaningful; baseline performance can be measured; the work is sufficiently understood; human review is feasible; the use case is reversible; and a responsible executive owner exists.
Map the workflow; define decision rights; establish verification; set information-governance boundaries; train the people involved; measure the business result; and review the outcome before expanding.
For organizations that are still building the management systems needed to scale technology reliably, Ascendare Group's Operational Excellence Consulting work focuses on the underlying processes, controls, management cadence, and decision architecture required for disciplined execution.
The objective is not maximum AI use. It is better organizational performance with appropriate control.
References
Dell'Acqua, F., McFowland, E. III, Mollick, E., Lifshitz, H., Kellogg, K. C., Rajendran, S., Krayer, L., Candelon, F., & Lakhani, K. R. (2026). Navigating the jagged technological frontier: Field experimental evidence of the effects of artificial intelligence on knowledge worker productivity and quality. Organization Science, 37(2), 403-423. https://doi.org/10.1287/orsc.2025.21838
Brynjolfsson, E., Li, D., & Raymond, L. R. (2025). Generative AI at work. The Quarterly Journal of Economics, 140(2), 889-942. https://academic.oup.com/qje/article/140/2/889/7990658
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://doi.org/10.6028/NIST.AI.100-1
Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. https://doi.org/10.6028/NIST.AI.600-1
Stanford Institute for Human-Centered Artificial Intelligence. (2026). The 2026 AI Index Report: Economy. https://hai.stanford.edu/ai-index/2026-ai-index-report/economy

Comments