Hugdrif
EN / IS

Service

AI and agent readiness

An honest assessment of where you can safely apply AI agents, and what has to be in place first.

The problem

The constraint on AI in large organisations is rarely the model or the platform. It is undocumented process, contested data ownership, inconsistent vocabulary, absent audit trails and no agreed answer to who is accountable when the system is wrong. Those are architecture problems, and the AI team cannot solve them alone.

Conventional technical debt is deterministic: you reproduce it, locate it and fix it. AI debt is emergent and probabilistic, and there is often nothing to point at. The remedy is not correcting code but constraining behaviour, and constraining behaviour requires a description of what correct behaviour is. Guardrails belong in a description, not in a prompt.

The piece most organisations have not thought through is that an agent is closer to a role in the organisation than to a feature in a system. A role has a reporting line, a defined responsibility, a set of authorisations and a named human accountable for it. Establishing that while you have three agents is inexpensive. Establishing it once you have three hundred is a reorganisation.

How I work this

Use cases triaged by readiness

Not by enthusiasm and not by what demonstrates best in a meeting. Each case is assessed on vocabulary, process definition, data provenance, oversight and accountability. Some fail, and that is a result.

Agents defined as roles

Reporting line, responsibility, authorisations, escalation and a named human accountable. Set out with RACI so it is actually usable.

Guardrails as constraints, not prose

What an agent may and may not do is derived from process, authorisations and data ownership, rather than written into a prompt nobody can test.

Human oversight as a real step

Oversight that is not in the process does not exist. Human-in-the-loop designs are set out in BPMN, with an owner, a time limit and a defined outcome.

The EU AI Act, practically

Risk classification under the AI Act and what each tier actually requires, in terms a steering committee can act on. Not the legal text copied out.

What you get
  • Use case portfolio, triaged by value against genuine readiness
  • Readiness assessment per case: vocabulary, process definition, data provenance, oversight, accountability
  • Agent role definitions, with RACI
  • Guardrails expressed as constraints derived from processes and rules
  • Human-in-the-loop process designs set out in BPMN
  • EU AI Act risk classification and the obligations of each tier
  • A sequenced plan: what to do now, what to prepare for and what to decline
Get in touch when
  • There is board-level pressure to do something with AI and no framework for deciding what
  • Pilots keep working in demonstration and failing in production
  • You are a public body and need to show that an AI-supported decision is defensible
  • Agents are accumulating without anyone owning the question of who they report to
  • You need a realistic view of EU AI Act obligations before committing to a direction
Scope

Readiness assessment

Two to four weeks. Use cases triaged and a clear answer on what is ready.

Agent governance framework

Four to eight weeks. Roles, authorisations, oversight and accountability established while there are still few of them.

Support through the first case

Advisory alongside the first agent going live, without taking on the implementation.

Related

Readiness rests on the processes in Enterprise architecture and process and the vocabulary in Data and information architecture. Jf neither exists, that is where we start before we go further with agents.

Does this sound familiar?

Tell us briefly where you are. The first conversation costs nothing and usually leaves the question clearer than it was, whether or not this results in a project.

Get in touch