Enterprise AI Success Depends on Readiness, Not Just Tools
Enterprise AI Adoption Requires Organizational Readiness
Buying AI tools is not the same as preparing a business to use them well. Enterprise AI adoption depends on people, processes and the capacity to change how work gets done. In this Techstrong AI Leadership conversation, EY Distinguished Technologist Rick Ross explores that challenge with host Mike Vizard.
Ross sees many organizations starting with productivity gains, then discovering a larger opportunity to redesign workflows and business models. Adding AI to an existing process may deliver incremental improvements. Capturing broader value can require rethinking the process itself.
That transition also takes preparation. Ross describes the gap between investing in technology and building the organizational capabilities needed to benefit from it. Successful pilots do not remove the work of training people, changing operating models and preparing for scale.
Measure Value and Govern the Agent Lifecycle
The discussion examines why familiar investment calculations may not fully capture AI’s impact. Ross recommends narrowing the initial focus to a specific process or capability. Leaders can then assess outcomes against the business value they want to create.
Investment priorities will differ with available resources and risk appetite. Some organizations can pursue short-, medium- and long-term opportunities together. Others may choose a more cautious approach while vendor offerings and deployment practices mature.
Software agents introduce another layer of responsibility. Ross argues that organizations should manage their lifecycles, including onboarding, role changes and retirement. Service management and governance must account for agents requesting services and interacting with other systems.
He also calls for independent validation and quality oversight. Enterprise and solution architects can help organizations challenge assumptions and maintain governance as development accelerates.
Protect Intellectual Property While Building Capability
Enterprise AI adoption also raises architectural questions about sensitive information and competitive advantage. Ross discusses choosing where models run and which workloads should remain within controlled environments.
He outlines an approach that combines externally hosted models with local processing for selected internal work. The appropriate balance depends on the organization’s requirements, rather than a universal choice between public and private systems.
For business and technology leaders, Ross emphasizes protecting assets while developing the skills to support investment. His message is not to wait for every uncertainty to disappear. It is to move deliberately, with clear ownership, trained people and safeguards that match the business.
Transcript
ai Leadership Insight Series. I'm your host, Mike Bizos. Today, we're with Rick Ross, who's one of the distinguished technologists from EY, and we're having a little chat about, well, AI and enterprises because it seems like a lot of them are struggling, and we're not quite sure why.
And it may differ from one company to another, but there is some definite patterns. Rick, welcome to the show. Thanks, Mike.
Thanks for having me. I'm really excited to talk to you today. All right.
So from your perspective, what separates those organizations that seem to be doing AI well and those that are struggling? Are there patterns or things that you've seen, and how much of this is really about the technology, or is it more about the culture and the processes? Well, that's a pretty big question to start with.
I think what I'm seeing is a pattern is very clear in that a lot of organizations are using AI as a productivity tool first off. It's really quite a big incentive for most organizations to try and get as much out of productivity as possible. And most of them are starting to realize that it's not just the productivity itself.
There's opportunity to look at ways of reimagining the way that they work. So instead of just bolting it on as a tool, it has so much opportunity that can get rid of the efficiencies and recreate better business models, better revenue outcomes, a lot more than just the actual productivity itself. So there's huge opportunity, but we're just starting to see the precipice of many organizations realizing, well, there's more to it than just the tool itself.
It's the process around it. And along with that, most of these organizations, which I find really interesting, is going through, yes, they believe there's value here, and they're going through pilots, but then they're going into scaling out, and then they're realizing that it's not just the technology that needs to be looked at, it's the actual absorption of the actual technology itself. So what I mean by that is, is the people that surround it, it's the business processes that surround it.
It's the readiness of the organization to accept the technologies. That's so much more greater. And there's actually a really interesting theory called the J curve theory, which talks to if you're not ready and you're doing all this investment, it's like a big hockey stick.
It takes time to get that return on investment. It will come at some time, but because you haven't done the readiness from a business perspective, you just don't know when that will come. So, it's a long-winded answer to say there is huge opportunity, and organizations are starting to see the benefit of looking at it other than just a tool.
If I look back in history, we have done the same thing over and over again. A new technology comes down that's pretty innovative, and then we use it to kind of maybe accelerate what we've always been doing slightly. Yeah.
And then we get a little frustrated because it's not living up to the hype. But over time, we wind up reinventing entire workflows and processes, and I can think of the browser and a few other things that kind of fall into that category. So is that where we are on this journey, where a lot of folks are throwing AI at existing workflows and processes without having the time necessarily to engage in what might be called back in the day, some actual digital business process re-engineering?
You know what? That's such a great question as well. Let me take a step back.
Even before the third industrial revolution, we go right back to if you look at history, and we go through the first industrial revolution, which was steam, the second industrial revolution, which was electricity, and then we started to move into semiconductors, into the third and fourth revolution. What was really interesting around that is the pace of change as we went over time. So between the first and second revolution, there was 100 years.
Then came 70 years between the next revolution, then 40 years between the next revolution. What's really interesting is if you look at, there's two characteristics that I like to look at from economics perspective. The first is that as these revolutions started to advance, the infrastructure started to become more and more apparent.
So take point in that, because where we are now is a lot of the digital infrastructure is there. And sure, we can see a lot of constraints around it. So if we look at data centers, for example, we know that there's constraints around electricity, we know that there's constraints around water.
But hey, the foundations are there, right? What's also interesting is the characteristics of the technologies, steam, electricity, semiconductors, Internet of Things, they all have what's called in a theory around it called general purpose technology, where they have mass opportunity, much wider than just a simple technology itself, but mass opportunity in terms of affecting much larger industries across industries. So where I'm getting with this is that the opportunity here is very much along the lines of this technology does have a much wider implication in terms of the business processes that we talked about that need to be rethought, and that will come over time.
But I see this as a significant revolution that has the characteristics similar of these other type of technologies, which means a reinvention process. And that's essentially what we're going through. One of the things that people seem to be struggling with is that phrase, return on investment, AKA ROI.
And part of the issue is it's hard to determine with AI, like what is actually going to be something that is a return on investment that is sustainable to the business in terms of some sort of competitive capability versus what just might actually just be new table stakes. And in order to remain competitive, I have to have some AI capability because somebody's going to invent something who's a competitor of mine, and I'm going to have to reverse engineer it pretty darn quick and vice versa. But neither one of us maybe gains a sustainable advantage because, well, the total addressable market didn't really change.
Yeah. So what do you think the question is there around that aspect? Well, the question then becomes, should we be obsessing about ROI to the degree that we are, or should we just recognize that AI is, well, for all intents and purposes, another tool in the quiver and everybody's going to use it, and if I want to remain relevant, I got to get my arms around it.
Yeah, got it. So I think what, Keith, if I bring this back a little bit, a lot of organizations are struggling with when will the return on investment come? What's really interesting that I'm finding in terms of a lot of outcomes that we're seeing from our organization, but also from academic studies, is that the actual methods and processes that can be used for this type of technology doesn't really work.
They're not holding. So when I talk to that, you can't use a NPV calculation that's similar to what you would use with established technologies, established platforms. They're very different.
It's very different in terms of the nature of the impact, and that's what a lot of organizations are struggling with in terms of I can't really use the existing valuation process to value what my return on investment is. So there's the gotcha there. As we go through this process, we'll start to build out what the valuation models are looking like.
But organizations really do need to stay, as much as they can, focused on trying to work out a narrow part of where the value might come out. And that might be, for example, looking at a very narrow view of a business process or a change to a capability in a specific area, and then looking at, well, what does that mean in terms of the amount of cost that will be reduced on the productivity, depending on what your value driver tree might be or how you value your organization. It also seems like as we move into the agentic AI era, we're starting to expose weaknesses that exist in our IT environments that span everything from governance to security.
And the reason for that, I think, is they were basically designed to be used by humans, and the assumption was that if there was a nefarious actor, that they too were human, and they might not discover a particular weakness. But in the age of AI, the agents seem to be crawling all over things and discovering things immediately. So how much are we just going to have to reinvent the way we structure our IT environments for this AI age, rather than for something that was originally designed solely for humans?
A significant amount. So the point being that we can't not do anything about the absorption of agents. And when I talk about non-human agents, I'll specifically talk about software agents because there's a lot more technology solutions around it.
And if we take an example, so an example would be, let's talk about the ways that service management used to be, and currently is traditionally 10 decades of service management, and it's all been about the customer being the human. Now we have to deal with the customer might not be human and might be an agent, might be a software agent. That software agent might be lodging an incident, it might be requesting a request.
It might be talking to another agent because it needs to go through an onboarding process as well. So if you think about the operating model, the operating model needs to change because these are things that we're testing now, and that means the level of governance around that, the oversight, needs to be really looked at. And that means things like looking at, as we do onboarding with employees now, we go through their change in role changes, their career progression.
We off-board them because they're resigning or they're retiring. The same thing applies for agents as well. It means that we need to manage the lifecycle of agents, and that's really something that resonates, I think, with many people in terms of it's the same thing that we went through with humans in terms of the digital age that started three decades ago.
We need to do it with agents as well. So that governance and oversight is very important. How long will it take us to work this through?
Because I think a lot of folks had this notion of AI as kind of the magic wand, but it seems like this is going to be work, and it's going to take a while to kind of sort through all these issues and get to that value prop. So, is there a way I should be thinking about my AI investments going forward and maybe, I don't know, should I narrow them into short-term, near term, and long term, and kind of have a plan wrapped around that? I think that, again, is a very good question as well, because we can't predict what's going to happen.
And for many organizations, the investment profile and how they handle it will be very different to other organizations. Those that have deep pockets will be able to manage their portfolio with more oversight, and they'll be able to do that, like you just talked about, which is the three different buckets of these are the quick wins, these are the medium-term wins, these are the long-term wins. The others we might find are very cautious, and they might wait for change to come out and wait for vendors to deliver solutions.
So that might mean them waiting for a considerable time until their confidence is there or until their risk appetite is there. So I think that's a hard question to answer because it depends on the organization, as you would expect, right? Mm-hmm.
" I think for those that are running a pace, I see this already. I'm a seasoned enterprise architect, and what I will tell you is the pace of change going on with the organization, where organizations are investing, where they're doing engineering themselves, where they're making decisions around vendors as well, it's great. It's all good.
But where's the oversight coming from? And I worry about that. I really worry about the independence within the organization and where that quality control is, where that validation is coming from.
Because if it's not coming from inside the organization, then where else is it coming from? Do you have a partner to help you with that, and who are you listening to? So that really worries me, because I've seen that pattern over the last six months.
Many organizations are feeling that there's just two things that they can do themselves, which is okay to understand that. But then also at the same time, they're believing that they're creating a frontier as well. So you've got almost this paradigm of, we don't believe that the market has the capability, and we're going to do it ourselves.
So I worry about where's the independence coming from? Where's the oversight coming from a governance perspective? And that's where enterprise architects, solution architects, can really support, at least within the organization, some of the governance activities that should be there.
Humans in the loop oversight. Initially, at least, there was this massive sense of fear of missing out, and everybody was trying to drive AI adoption in their organization, and that may have proven to be a little bit of a hit-and-miss. But where are we now?
Are we maybe at some point where people are taking a more studied approach to how to implement AI across their organization, and they're kind of starting to get to a point where rather than just randomly banging a drum, they're kind of saying, "We need an actual plan"? Yeah, I think that will vary as well. And some of these answers are a little bit topical in terms of the way that I answer these, and it's only because it depends on the risk appetite and the economies as such.
So many of the advanced economies, I won't name any of those, but those are the ones that all don't want to miss out. They're really investing, and they're investing heavily. And I can see that in terms of the academic studies that are coming out.
They're more coming out from the advanced economies, essentially. They're the ones that have done the trials, they're the ones that are publishing peer-reviewed articles and studies, et cetera. The ones that are not so advanced, they're the ones that are actually cautious and waiting for things to play out, and they're the ones that are sort of working out, well, this is the outcome of some of these advanced economies.
Let's take the best of that and let's work with the right things that are appropriate. An example might be responsible AI. Now, that's something that we all have to do.
But the advancement of responsible AI in terms of the guardrails might be very different in advanced economies. Might be less different in advanced economies as well, compared to others. Everybody's also tossing around the word moat these days, and I think that means different things to different folks.
Yeah. But one of the issues that seems to come up is that people are starting to realize that, well, the more I expose my data and my workflow and my code to those AI services, they may not be training on my data, but they certainly see my metadata and they see my code, and they might use that at some point to go create or launch an application that suddenly is in my space. So a lot of folks are trying to figure out, well, how do I draw a line around my IP so it doesn't wind up just being some sort of collective resource for everybody else, and the next thing you know, my supplier is a competitor.
Yeah. And here's the thing that most organizations need to think about along with the IP. It's what do I do?
Like the moat situation is what gives me that competitive advantage, and how do I protect that for not only external but also internal as well as in terms of the employees? And this is an architectural decision that you need to think about. This is what I clearly believe that you need to think through in terms of, right, these are things that you don't want exposed on a public-hosted LLM in the cloud.
Maybe there's things that you do in terms of sovereignty, which is to bring it into an environment which is localized, inference is localized, and you've got some sort of moat around that. And maybe there is some architectural design pattern which says, we'll go out and use these type of models hosted externally because it makes sense for us to do that. And we'll have a gateway that allows us to do that, as well as when we think we have our internal IP, we'll do that localized, trained inferenced locally.
To me, that makes sense, and I think this should resonate with a lot of people. You need to make those architectural decisions around what's supported for the organization. So if you were the business leader for any of these outfits, or the tech leader for that matter, what's that one thing that you would be focused on right now?
What would you be telling people to kind of zone in on? Firstly, I'd love to be the business leader or tech leader. I'll just say that.
I think honestly, the pace of change is so incredibly fast, so not doing anything is not an option anymore. You need to actually focus on protecting your assets, first off. I strongly believe that.
You mentioned before around agents coming online and starting to be mass adopted. It's probably a likely scenario. So you've got to do something around some sort of protection.
You've got to do something around if you believe that there is a competitive advantage and you do have investment capital, you should start to look at that, but also train your people within your organization so that they're capable to support the investment as well. So, those are only a sample of a couple of things, but I'd love to talk more to you about that at some point. All right, my friends.
Well, this is an ongoing conversation for sure. But to Rick's point, I think we've come to that moment where the worst thing you could possibly do is nothing. Hey, Rick, thanks for being on the show.
Thanks, Mike. Really appreciate it. All right.
AI Leadership Insight Series. You can find this episode and others on our website. We invite you to check all those out.
Until then, we'll see you next time.