---
title: "Sequence enterprise AI adoption by risk, not by hype | Dhruv Doshi"
description: "Most enterprise AI programs fail in one of two ways: they start with the highest risk use case and stall in governance review, or they scatter dozens of disconnected pilots that never…"
canonical: https://doshidhruv.com/notes/sequence-enterprise-ai-adoption-by-risk-not-by-hype/
author: Dhruv Doshi
---

[Skip to content](#main-content)

[Dhruv Doshi](/)

[Work](/projects)[Experience](/resume)[Notes](/notes)[Guides](/guides)[Research](/research)[Investing](/investing)[About](/about)[Contact](/contact)[Search /](/search)dark mode

[All notes](/notes)

[Enterprise AI](/topics/enterprise-ai)

# Sequence enterprise AI adoption by risk, not by hype

2026-10-01 · 5 minute read

Most enterprise AI programs fail in one of two ways: they start with the highest-risk use case and stall in governance review, or they scatter dozens of disconnected pilots that never reach production. Both failure modes come from sequencing by enthusiasm instead of sequencing by risk, reversibility, and organizational learning.

A better approach treats adoption as a portfolio ordered deliberately. Early bets should be low-risk, high-learning, and cheap to reverse. Each wave funds the credibility, controls, and platform capability the next wave requires.

## Start where failure is cheap

The first wave should target internal productivity for knowledge workers: drafting assistance, meeting summarization, code assistance, and document search over internal knowledge bases. These share three useful properties. The user remains the decision-maker, so a wrong answer costs minutes rather than customers. The data stays inside existing access boundaries. And the organization learns how models actually behave on its own content before any customer-facing commitment.

Measure this wave honestly. Track time saved on defined tasks, output quality against a baseline, and where the assistant misleads confident users. The goal is not a return-on-investment slide; it is calibrated judgment about what the technology does well and where it fails inside your environment.

## Build the control plane before the showcase

The second wave is infrastructure, not demos. Stand up the capabilities every later use case will need: an inventory of AI-enabled systems with owners and risk tiers, approved model endpoints with logging, evaluation suites tied to release gates, permission-aware retrieval over governed corpora, and an incident process that covers model behavior.

This is the work described in platform and governance practice as the AI control plane. Organizations that skip it discover that each new pilot re-litigates the same security, privacy, legal, and risk questions. Organizations that build it find the third, fourth, and tenth use cases move faster because the answers already exist.

Resist the urge to buy a platform that promises to solve this before you understand your own requirements. A quarter of disciplined manual process teaches you what to automate; premature platforming encodes guesses.

## Move to customer-adjacent work with humans in the loop

The third wave touches customers but keeps a person accountable for the outcome: agent-assisted support where the agent drafts and the human sends, underwriting or triage work where the model recommends and a specialist decides, and content generation with editorial review before publication.

For each use case, define the decision contract explicitly. What may the system do autonomously? What requires human approval? What must it never do, and how is that enforced technically rather than by policy text? Log the human decision alongside the model recommendation so you can measure agreement rates and catch automation bias early.

This wave is also where evaluation must become continuous. A model version change, a retrieval index update, or a prompt edit can shift behavior without a code deploy. Regression suites tied to release gates are the mechanism that keeps the third wave safe as it scales.

## Reserve autonomous and high-stakes systems for last

Fully autonomous actions and high-stakes decisions — automated eligibility, financial advice, safety-critical triage — belong at the end of the sequence, not the beginning. They demand everything the earlier waves built: a working control plane, calibrated evaluation, operational experience with model failure, and an organization that has seen the technology misbehave in low-stakes settings first.

They also demand the strongest form of governance: independent validation, explicit human accountability for outcomes, and the ability to demonstrate to a regulator or auditor exactly how a decision was reached. In regulated industries such as banking, this maps to existing model risk management expectations, extended to cover generative behavior.

## Sequence the organization, not just the technology

Each wave needs a different coalition. The first wave needs enthusiastic early adopters and a tolerant IT security review. The second needs platform engineering, security architecture, and risk. The third needs product owners, customer operations, and legal. The fourth needs executives willing to own outcomes publicly.

A common mistake is staffing the program with only technologists. Adoption is an organizational change problem wearing a technology costume. The scarcest resource is not model access; it is the set of people who can translate between business risk and engineering controls.

Review the sequence quarterly. Retire pilots that did not teach anything. Promote the patterns that worked into platform defaults. The objective is not a large number of AI projects. It is a growing set of production systems the organization understands, can defend, and can improve.

## Fund each wave with the previous wave's credibility

AI programs die between waves, not within them. The first wave produces learning but rarely the return-on-investment numbers that finance wants. The second wave produces infrastructure that looks like cost. The bridge is a funding story tied to risk reduction rather than revenue.

Frame the control plane as the thing that makes the third wave insurable: without it, every customer-facing use case carries unquantified risk. Frame the third wave's human-in-the-loop design as the evidence that the organization can be trusted with the fourth. Each wave's deliverable is the permission structure for the next.

This also means staffing the program as a program, not a project. A rolling team with platform, security, and product representation — funded for eighteen months, reviewed quarterly — outperforms a series of disconnected pilots that each have to re-justify their existence. Adoption is a multi-year organizational change; fund it like one.

## Continue reading

- ["Agent orchestration patterns: planner-executor, routing, and supervision"](/notes/agent-orchestration-patterns-planner-executor-routing-and-supervision) · Note
- ["Choosing a vector database: what actually differentiates them"](/notes/choosing-a-vector-database-what-actually-differentiates-them) · Note
- ["Fine-tuning vs RAG vs prompting: how to actually decide"](/notes/fine-tuning-vs-rag-vs-prompting-how-to-actually-decide) · Note
- ["FinOps for AI workloads: controlling GPU and inference spend"](/notes/finops-for-ai-workloads-controlling-gpu-and-inference-spend) · Note

**Dhruv Doshi** · Toronto, Canada · [work@doshidhruv.com](mailto:work@doshidhruv.com)

[Resume](/resume)[Notes](/notes)[Guides](/guides)[Topics](/topics)[Search](/search)[Research](/research)[Investing](/investing)[LinkedIn](https://www.linkedin.com/in/dhruvdoshi25071999)[GitHub](https://github.com/DhruvDoshi)

[Sitemap](/sitemap.xml)[RSS](/feed.xml)[LLMs](/llms.txt)

© 2026 Dhruv Doshi
