- 01
The long-lead item for 2027 is integration and identity, not models — it takes the longest and everything else waits on it.
- 02
Stop funding pilots that have no named production owner; a pilot without a destination is a training exercise billed as investment.
- 03
Data quality work should be scoped to the workflows in the plan, not attempted as an enterprise-wide programme.
The thesis
By 2027 the constraint on enterprise AI is not access to capability, funding appetite or executive sponsorship. It is the state of the estate: whether the systems that hold the data and perform the transactions can be reached programmatically, with identity and entitlements intact, at acceptable latency, under change control. Our view is that the 2027 budget should be read as an integration budget with AI attached, rather than an AI budget with integration as a footnote. This is an unpopular framing because integration work does not demo, but it is the difference between an organisation that can deploy its tenth workflow in six weeks and one that is still negotiating access to a core system for its third. The corollary is that the highest-value line in the plan is usually invisible to the board, which makes it the CIO's job to explain why the unglamorous item is the one that determines the pace of everything they can see.
Fund: the tool layer and identity
The reusable layer that exposes systems of record as governed interfaces is the single most leveraged investment available. It must carry the caller's identity through to the underlying system rather than acting as a shared service account, enforce entitlements at the interface, apply authority limits in code, behave predictably under failure and be versioned like a product. Agents also need identities of their own, with scoped permissions, credential rotation and revocation — a requirement most identity platforms were not designed for and that takes longer than teams expect. Budget this as infrastructure with a multi-year envelope, staffed by a small permanent team rather than by whichever project needs it next. The test of whether it worked is simple and worth committing to publicly: the elapsed time from approving a new workflow to it being live in production should fall by more than half between the first and the fifth, and if it does not, the layer is being rebuilt each time rather than reused.
Fund: evaluation, observability and supervision
The second protected line is the ability to know whether things are working. Golden test sets per workflow, a harness that runs them on every change, tracing that records what each production case did, dashboards that report quality and cost per outcome as trends, and a small standing team that watches production and triages regressions. Enterprises consistently under-fund this because it has no visible output until something goes wrong, and then over-fund it reactively after an incident. Fund it centrally, before scale, and make passing it a condition of deployment. There is a second-order benefit that justifies the line on its own: an organisation with an independent evaluation capability can adopt new models quickly and safely, because it can measure the change rather than argue about it. Without one, every model upgrade is a negotiation based on vendor claims and anecdote, and the enterprise ends up either frozen on an old model or exposed by an unmeasured switch.
Stop: pilots without a destination
Most enterprises are carrying a portfolio of experiments that have proven the technology works and have no path to production, because no business owner accepted the outcome, no supervision was staffed and no integration was funded. These consume engineering attention, create the impression of activity and depress organisational confidence when they quietly end. The 2027 rule worth adopting is simple: no new proof of concept without a named production owner, a defined success threshold agreed in advance, and pre-committed funding for the production path if the threshold is met. Apply it retrospectively to the existing portfolio and expect to close a meaningful share of it. The freed capacity is usually the largest source of engineering time in the plan, and closing the portfolio deliberately — with a stated reason — protects credibility far better than letting projects lapse. Depth in two or three workflows produces a defensible number; breadth across ten produces slideware.
Sequence: data and legacy, scoped to the plan
Two long-standing programmes get pulled into the AI agenda in 2027 and both are dangerous if scoped too broadly. Data quality is real — retrieval over inconsistent, duplicated or unlabelled content produces confident nonsense — but an enterprise-wide data remediation programme will not finish inside the planning horizon. Scope the work to the specific content and records the planned workflows depend on, fix those to a defined standard, and treat the rest as backlog. Legacy modernisation gets a genuinely new justification: a system that cannot expose a governed interface with acceptable latency becomes a hard ceiling on what can be automated around it, and that argument is more concrete than the ones modernisation business cases usually rest on. Sequence modernisation by how many planned workflows a system blocks rather than by age or technical debt score. This produces a shorter, better-argued list, and it is the version a CFO will actually fund.
Implications by role
CIO: defend the infrastructure envelope from being charged to the first workflow, and publish the deployment-lead-time metric as evidence it is working. Chief AI Officer: own the release standard and the evaluation thresholds; that standard is the mechanism by which quality scales beyond the teams you personally see. Enterprise Architecture: sequence modernisation by workflows blocked, and keep tool definitions and evaluation suites vendor-external so migration stays affordable. CISO: treat agent identity as a 2026 delivery item, because it is the dependency most likely to delay 2027 workflows. CFO: fund infrastructure and workflows separately, require cost per completed outcome, and hold a migration reserve. COO: name the production owners now, since the absence of an accountable business owner is the most common reason a technically successful pilot never ships.
The 2027 plan on one page
A defensible allocation looks roughly like this. A protected infrastructure envelope covering the tool layer, identity, retrieval, evaluation and observability, funded centrally and staffed permanently. A workflow portfolio of a small number of end-to-end processes taken to full outcome accountability, each with a named owner, an evaluation suite, a supervision plan and a published cost per outcome. A scoped data and modernisation line, sequenced by workflows blocked rather than by technical debt. A supervision and enablement line covering the standing operations team and the retraining that the role changes require. And a migration reserve. Everything else — model choice, framework choice, vendor selection — is a reversible decision that should not consume executive attention proportionate to how much it is discussed. The organisations that will look well managed in 2027 are the ones whose plan a CFO can read in five minutes and whose numbers survive a year of contact with reality.
- The long-lead item for 2027 is integration and identity, not models — it takes the longest and everything else waits on it.
- Stop funding pilots that have no named production owner; a pilot without a destination is a training exercise billed as investment.
- Data quality work should be scoped to the workflows in the plan, not attempted as an enterprise-wide programme.
- Legacy modernisation gets a new justification in 2027: systems that cannot expose governed interfaces become the ceiling on automation.
- Reserve budget for a forced platform or model migration — it is a near-certainty within the planning horizon.
Questions leaders ask us
- How much of the AI budget should go to infrastructure versus workflows?
- There is no universal ratio, but the diagnostic is the trend: if the fifth workflow does not cost materially less and deploy materially faster than the first, too little went to shared infrastructure.
- Should we pause AI spend until data quality is fixed?
- No. Scope data work to the content and records the planned workflows actually depend on. An enterprise-wide remediation programme will not finish inside the planning horizon.
- What justifies legacy modernisation in an AI plan?
- A system that cannot expose a governed interface at acceptable latency caps what can be automated around it. Sequence modernisation by how many planned workflows each system blocks.
- How do we decide which pilots to stop?
- Close any without a named production owner, an agreed success threshold and pre-committed funding for the production path. That test usually clears a large share of the portfolio.
Sources
- [1] The large majority of enterprise generative AI pilots never produce a measurable production outcome. The GenAI Divide: State of AI in Business — MIT NANDA / Project NANDA, 2025
- [2] Recognised AI risk management practice organises controls around govern, map, measure and manage functions. AI Risk Management Framework (AI RMF 1.0) — NIST, 2023