Over the past several weeks, I've tracked four companies — a credit union, a law firm, a national general contractor, and a regional bank — each naming a first-ever Chief AI Officer, VP of AI, or Director of AI Enablement. Different industries, different org charts, same underlying event: a company deciding, for the first time, that AI needs a named owner instead of being everyone's part-time responsibility.

If you're the person walking into one of these roles — or the CEO who just created one — this article is the operating model I'd want in place before month one ends. Not a roadmap. An operating model. The distinction matters more than it sounds like it should, and it's the single biggest reason these roles succeed or stall.

The trap: mistaking a roadmap for a plan

Almost every new AI leader I've talked with reaches for the same first move: a roadmap. Pick a vendor, write a strategy deck, name a flagship pilot, present it to the board. It photographs well. It also skips the one step that actually determines whether anything on that roadmap works: finding out what's already happening.

By the time a company creates a Chief AI Officer role, employees have usually been using AI for a year or more — personal ChatGPT accounts, an unofficial Copilot login here, a Claude subscription expensed as "software" there. None of it shows up in an IT asset inventory. All of it represents real behavior, real risk, and real value that a roadmap written in a vacuum will either duplicate or ignore.

A roadmap answers "where are we going." An operating model answers "how do we actually run this" — inventory, pilot selection, governance, and measurement, in that order, on a repeatable cycle. Skip straight to the roadmap and you've built a strategy for a company that doesn't exist yet. Build the operating model first and the roadmap writes itself from evidence instead of guesswork.

Step 1: Inventory before policy

Before a single policy gets written, find out what's actually in use. This is not a survey — surveys tell you what people are willing to admit to, not what they're doing. It's a combination of:

  • SSO and expense-report review for AI tool subscriptions (personal and corporate)
  • Browser extension and SaaS-discovery tooling where available
  • Direct, non-punitive conversations with team leads: "what are people on your team actually using to get work done faster?"

The goal isn't enforcement. It's a map. You cannot govern, secure, or scale what you haven't found. Every AI enablement engagement I've run starts here, and every one of them has surfaced tool sprawl the client didn't know existed — overlapping subscriptions, unsanctioned data flowing to consumer-grade AI accounts, pockets of genuinely good practice nobody had documented or shared.

This inventory step is also where you find your first pilot. Don't invent a use case from a whiteboard session — pick the workflow that's already half-automated by an employee's own initiative, and formalize it.

Step 2: One measurable pilot, not a five-year strategy

The second trap is scope. New AI leaders are under pressure to show vision, and vision tends to expand into a five-year, cross-departmental transformation plan before anything has actually shipped. That plan will not survive contact with the first budget review.

Instead: one workflow, one team, one measurable before/after. Repetitive three-to-four-hour tasks — research, reporting, proposal drafting, intake, meeting prep and follow-up, reconciliation — are the highest-yield targets, because the baseline is easy to measure and the improvement is easy to demonstrate. Human-in-the-loop is not a placeholder until the "real" automation arrives — for most of these workflows, a human reviewing AI-assisted output in minutes instead of doing the work in hours is the correct enterprise design, permanently.

A single well-measured pilot does two things a strategy deck cannot: it proves the operating model works on real work, and it gives you a number to defend the next budget ask with. Executives fund what they can measure. They rarely fund what they can only be told to imagine.

Step 3: Identity, permissions, and audit trails — from day one, not as a retrofit

This is the step most new AI leaders defer, and it's the one that causes the most expensive problems later. AI agents and assistants need identity, permissions, and audit logging the same way employees do — who can access what, what they did with it, and a record that survives a security review or a compliance audit. Retrofitting governance onto a year of ungoverned usage is dramatically more expensive than building it in from the start, and it's the difference between a security team that trusts the AI program and one that tries to shut it down.

Concretely, this means from day one:

  • An approved-model gateway rather than ad hoc consumer accounts
  • SSO/RBAC on every AI surface employees touch, not just the flagship pilot
  • Logging sufficient to reconstruct what an AI system did and why, after the fact
  • A clear, written position: this is AI-assisted work with human oversight and approval gates — never a "fully autonomous" system making unreviewed decisions

That last point is worth stating plainly because it's both the safer engineering choice and the more honest one. Enterprises that position AI as autonomous decision-making create liability they can't fully explain later. Enterprises that build human approval into the design from the start move faster in practice, because nobody has to fight the security team for permission to keep the pilot running.

If your company is in a regulated industry — banking, healthcare, insurance, financial services — this step also happens to be the fastest path to satisfying the compliance questions that are coming regardless: SOC 2, HIPAA, PCI DSS, customer security questionnaires, and increasingly, board-level questions about AI risk. Build the audit trail once, for the right reasons, and it answers all of those asks instead of requiring a separate scramble for each one.

Step 4: A number at day 90, not a vision statement

By day 90, you should be able to walk into a board or leadership meeting with one of three things: usage data, cost data, or time-saved data. Not a vision statement, not a maturity-model slide, not a comparison to what a competitor announced in a press release. A number, tied to the one pilot from Step 2, that a CFO would accept without an argument.

This is the step that determines whether you get a second pilot funded. It's also the step most new AI leaders skip, because after 90 days of inventory work and governance building, there's a temptation to present the process as the accomplishment. The process is necessary. It is not what buys you the next budget cycle. The number is.

Where this goes next: department-specific agents, without starting over

Once the operating model is running — inventory current, one pilot proven, governance instrumented, a number reported — the natural next move is department-specific expansion: sales research, proposal drafting, compliance evidence gathering, IT support triage, finance reporting, HR policy Q&A. Each department's AI agent should sit inside the same governance layer built in Step 3, not a new one built from scratch. This is also where a governed enterprise knowledge layer becomes relevant — teams stop rebuilding answers that already exist somewhere in SharePoint, Confluence, Slack, or a colleague's inbox, without flattening the access permissions that existed before AI touched any of it.

The mistake to avoid at this stage is the same one from Step 2, at a larger scale: trying to roll out AI agents to every department simultaneously instead of expanding one proven pattern at a time. The operating model scales. A five-year strategy deck does not.

The checklist

For the Chief AI Officer, VP of AI, or Director of AI Enablement reading this in their first 90 days:

  1. Inventory what's actually in use before writing a single policy.
  2. Pick one workflow, one team, one measurable pilot — not a five-year plan.
  3. Build identity, permissions, and audit trails from day one; position every deployment as AI-assisted with human oversight, never autonomous.
  4. Report a hard number — usage, cost, or time saved — by day 90.
  5. Expand department by department inside the same governance layer, never starting a new one.

The role is being invented in real time, across every industry, right now. The companies getting it right aren't the ones with the most ambitious roadmap. They're the ones who built the operating model first and let the roadmap follow the evidence.


If you're building this in your own organization and want the one-page 90-day framework version of this article, book 15 minutes: https://calendly.com/gms-cloud/complitruai

— Deep Patel, GMS