Framework · AI Strategy
The AI Evolution Stack
AI complexity is inevitable. Instability is optional.
AI systems mature through four structural stages, each adding capability and risk — and governance must expand vertically as fast as capability grows horizontally. AI maturity is not about model intelligence. It is about how context, action and governance expand together.
Four structural stages
Each stage adds capability and risk
- Level 1 · Risk Low
Basic AI
Direct Model
User → LLM → Response
Prompt in, response out. No enterprise memory, no system integration, no action capability.
Governance needUsage policy · Data input restrictions
- Level 2 · Risk Moderate
Contextual AI
Model + Knowledge
User → Retriever → Knowledge Base → LLM → Response
The model retrieves enterprise data before responding.
Governance needData access control · Retrieval architecture standards · Logging
- Level 3 · Risk High
Agentic AI
Model + Knowledge + Action
Goal/User → Agent + Tools (via MCP) → LLM Loop → Action
The agent selects tools. APIs are invoked. Systems are modified.
Governance needTool boundaries · Escalation checkpoints · Autonomy classification · Cost monitoring · Operational logging
- Level 4 · Risk Controlled
Enterprise AI
Governed Platform
Experience · Orchestration · Intelligence · Knowledge · Infrastructure & Governance
AI becomes a layered platform: user interaction, agents and workflows, LLM reasoning, retrieval and enterprise data, with observability, security and guardrails underneath.
Governance needFormal use case intake · Autonomy approval matrix · Cost-per-workflow tracking · Architecture review integration · AI review board oversight · Quarterly structural audits
The central test
Horizontal growth against vertical control
- AI evolves horizontally
- Direct Model → + Context → + Action → + Orchestration
- Governance must evolve vertically
- Policy → Data Control → Tool Boundaries → Platform Governance
If horizontal growth outpaces vertical control, instability follows.
Interactive
Check your AI systems
Place each system at its level and tick the controls it has. The check lists what its level needs — its own controls and every level below — and what it carries beyond that.
Your AI systems by level
No systems yet. Most organisations run several levels at once — classify each one separately. Your inventory stays in this browser only.
In practice
A FinTech running AI systems at three maturity levels at once — a chatbot, a fraud-detection model and a trading agent — all governed identically.
- Before
- Each was governed the same way, which meant none was governed appropriately. The Level 1 chatbot carried too much process; the Level 3 agent carried too little.
- After
- Each system was classified against the stack with controls proportionate to autonomy: the trading agent needed human-in-the-loop confirmation above a threshold, the chatbot needed none, and the governance burden dropped by half.
Implementation · 90 days
Ensure governance matures as fast as intelligence
- Phase 1 · Weeks 1–3
Classification
Map each AI system to its evolution level, identify autonomy exposure and document integrations.
- Phase 2 · Weeks 4–8
Standardization
Standardise retrieval architecture, define tool exposure rules, introduce escalation checkpoints and establish logging.
- Phase 3 · Weeks 9–12
Institutionalization
Introduce an AI review board, implement cost dashboards, integrate AI into architecture governance and conduct a structural audit.
Go deeper
Several levels at once?
Make governance proportionate to autonomy
Bring the inventory you built above to a free 30-minute diagnostic.