Insights · 2026-06-27

From pilot to production: what controlled AI actually requires

Most AI programmes never leave the pilot. The demo impresses, the budget gets approved, and then the system meets procurement, security review, and the question every regulator eventually asks: who is accountable when it is wrong? That is where undisciplined AI work quietly dies.

The gap between a promising pilot and a production system is rarely the model. It is everything around the model: data boundaries, review ownership, logging, adoption, and the proof trail a corporate can defend.

Data boundaries are not decoration

A location promise is not enough. Serious buyers need to know who can reach the data, which providers process it, which keys protect it, and what happens when the work leaves the prototype.

Said plainly: the question is not just where the data sits. The question is whether the people accountable for the work can inspect and control the path from source material to output.

Make human-in-the-loop a mechanic, not a slogan

“Human oversight” means nothing to an auditor. A mechanic does: the AI stages an action, a named human approves it, and every step is written to an audit record. That sentence is testable. It tells a regulator exactly where accountability lives and exactly what evidence exists.

Designing for that from day one is what lets a pilot graduate. It is also what lets control become a useful product quality, not a compliance afterthought.

What we look for before we build

Which data can the system touch? Which decisions must keep a human approver? What gets logged, and who can read the log? Which standards, such as ISO 27001 and ISO 42001, does this need to map to, and is the claim true today or in progress? Answer those honestly and the path from pilot to production stops being a leap of faith.

That is the whole job: clear intelligence that a corporate can stand behind.