Google’s agentic AI transformation framework
Google Cloud's operational framework: vision, an agentic development lifecycle, and the capabilities underneath, with owners named at each stage.
Ranked within each section; the strongest few carry a one-line description of what the document is. Every link opens the publisher's own page or document; those marked PDF open the file directly.
Google Cloud's operational framework: vision, an agentic development lifecycle, and the capabilities underneath, with owners named at each stage.
Records the reasoning directly: if the agent gives the wrong answer and the employee acts on it, it is still the employee's mistake, so people are reluctant to rely on tools they do not fully understand where accuracy, professional judgment and reputation are on the line.
Sets out a specific task-level set - completion rate, work reduction, cost and cycle time per task, safety violations - explicitly in place of technical model scores, which are equally unrelated to whether work got done.
Notes that non-human identities are created by systems rather than business processes and run continuously without direct human oversight: a person reading a screen and pausing between actions creates natural moments to catch a mistake, while an identity executing thousands of operations a second offers no such window.
BCG on what separates firms already operating AI-first from those still planning to, drawn from more than 70 companies.
Why agentic pilots stall short of production, and the architecture Deloitte and Google Cloud propose for getting past it.
Qualifies the cause rather than the effect: the damage is attributed to initiatives led from the technology side without a matching investment in the
Deloitte's six-pillar adoption framework, built around leadership, trust and human-in-the-loop feedback rather than technology.
Presents multi-agent systems as the advanced stage requiring orchestration frameworks, agent-to-agent protocols, robust memory management and deeper e
KPMG's value-assessment method for agentic programmes, pairing value at stake with a staged adoption sequence.
McKinsey on the gen AI paradox — broad adoption, thin P&L impact — and the horizontal-versus-vertical distinction that explains it.
Names fragmentation as the leading obstacle in moving from proof of concept to production: competing tool choices, limited reuse, diverging standards
Identifies the accountability gap that widens with autonomy, notes the proposed AI Liability Directive and the criticised "electronic personhood" idea
Argues that most agentic frameworks are neither declarative nor imperative orchestration frameworks but simply sets of agent abstractions, and that th
Sets out autonomy as a staged progression earned use case by use case - assistant, then recommendation, then automation, with the automation stage act
Draws the architectural distinction - workflows orchestrate models and tools through predefined code paths, agents dynamically direct their own proces
Places the design work in the assembly - tools, memory, control flow - which is the part a model benchmark never covers.
Separates the agent into model, tools and an explicit orchestration layer, making the orchestration a component to be designed rather than inherited f
Defines a workflow as a sequence of steps that must be executed to meet a goal, and an agent as a system that independently accomplishes tasks on the
States that the balance between in-house and external capability determines whether the organization builds a powerful differentiated engine or a weak
Proposes that efficiency, accuracy and user satisfaction be measured and monitored over time with underperforming agents retrained or retired, which r
Argues risks to people increase with the autonomy of a system - the more control a user cedes, the more risks arise - with safety, privacy and securit
Positions independent assurance over AI as an emerging oversight responsibility for audit committees rather than a delivery-team function.
States the case directly: the tolerable error rate is set by what the agent is wired to, not by the agent, and recent capability gains have bought only small improvements in reliability.
IBM on governing agents in regulated settings, comparing emerging Australian and EU regulatory approaches.
Reports 36% higher AI ROI for Chief AI Officers running hub-and-spoke or centralized operating models than for those managing decentralized ones, and roughly twice as many pilots reaching production, from a survey of more than 600 such officers fielded in the first quarter of 2025.
Widens the picture by listing what a regulated firm is already tracking, and the length of that list undercuts the idea of three blocs - though the items are not equivalent regimes. In the United States alone it names a federal executive order, a federal bill, the NIST framework, a securities regulator notice, statutes in Colorado and Texas, and a privacy regulator's automated decision-making rules in California. The United Kingdom appears not as a statute but as a government department and two regulators publishing separately. Asia-Pacific carries national laws in South Korea and Japan, Australian guidance alongside a voluntary safety standard, a Singapore consultation aimed at financial institutions, two Hong Kong publications and an ASEAN guide. The list is offered as non-exhaustive and omits China entirely, so it is a picture of the tracking burden rather than a census.
Deloitte's survey of 695 board members and executives on how far AI has moved onto the board agenda.
Presents vendor lock-in as a strategy risk CEOs may not see coming, framed around ownership of the enterprise's accumulated intelligence rather than o
Reports chief executives saying that many of their directors cannot tell an inflated AI claim from a real one, or judge how quickly value ought to arr
Argues against the premise rather than conditioning it: it reports that 42% of chief executives already use agents weekly precisely to rule out execut
Survey of 625 leaders: 75% of board members rate their AI knowledge on par with or more advanced than peers; nearly 40% of CEOs say boards lack an inf
KPMG's five governance principles for boards, developed with INSEAD's Corporate Governance Centre.
Treats board fluency as maintained rather than acquired - built deliberately, topped up on a rhythm and tied to outcomes, through devices like annual
Argues sustainable transformation needs a top-down vision joined to organizational redesign, rather than deployment alone.
PwC's short brief urging directors to match governance cadence to the pace of deployment.
KPMG on where boards should focus as programmes move from return-hunting toward delegated agency.
Names shortage of AI knowledge among board members as one of the most common hindrances to robust AI governance; oversight becomes cursory and directo
Frames divergence as a geopolitical rather than purely legal problem for boards to navigate.
Qualifies every protocol on this page from the position of someone building the models: the frontier labs do not yet understand how their own systems
Argues satisfying the formal fiduciary arrangement is not the same as adequate oversight, and points to examples of the arrangement proving insufficie
Obligation to ensure compliance is dependent on role (provider vs distributor); the Act addresses the entire value chain with separate requirements fo
EY's study of how boards are restructuring for a faster-moving agenda, with AI one driver among several.
Surveying 300 directors at North American companies above a billion dollars in revenue, finds a slim majority whose boards hear how AI decisions are e
Offers a sequence of questions - impact assessments, documented data sources, testing and removal on discovering bias, regular review - which function
Qualifies who inherits the gap: chief executives must align teams on a shared investment thesis and ensure metrics and timelines are consistent with i
Puts Malaysian directors who consider themselves well briefed on generative AI at 18% - one national market, not a global reading.
BCG's executive perspective on structural cost advantage, and why copilots layered on unchanged processes fail to deliver it.
Deloitte's 28-page analysis of token economics: what drives spend, and where owned infrastructure overtakes metered APIs.
Proposes a concrete measure that separates working systems from demonstrations: count only tasks meeting the quality bar, divide full cost - including employee time, human review, retries and rework - by that number, and track results as ready to use, needs correction, or needs escalation.
Infosys on governing AI cost: observability first, then routing, then enforced guardrails and workflow budgets.
Accenture's argument for tokenomics as a C-suite discipline, jointly owned by the finance and technology functions.
BCG's return-on-AI framing for chief executives, including the margin comparison against AI-native products.
Describes cost per outcome compounding sharply and invisibly through forces traditional software and infrastructure forecasts miss: breadth and depth
Proposes defining the quality bar before testing, running evaluations that reflect real tasks including edge cases, and measuring the full cost of rea
EY on total cost of ownership for agents, written against the projected 2027 cancellation rate.
Frames the allocation question - who gets machine capacity, how many, for what work - as headcount-style management with the same deliberateness and a
Identifies the balance between run and change spend as the core CIO budget challenge, which is exactly where unbudgeted AI operating costs land.
Names the measurement gap outright: indicator usage across 46 measures has flattened rather than shifted toward outcomes, and use of process-effective
Puts the figure on self-reported ground: technology buyers rating their own returns on an unweighted online panel, with a share saying outright that t
Locates lock-in below the contract: once a developer's tooling is expensive enough to leave, the harness ties spend to one model family whatever procu
BCG's account of where AI value actually landed in leading enterprises, and the investment pattern behind it.
Anthropic's engineering account of taking multi-agent research from prototype to production, including evaluation method.
Describes investing in production capabilities including safe model deployment and automatic model retraining, and tooling that measures model quality across all stages, precisely because manual maintenance does not scale.
How L'Oréal stood up a generative AI service for 90,000 employees in three months, with the architecture described.
Capgemini on building a proposal-generation agent for insurance tenders, with the cost profile of running it.
OpenAI's worked example of specialist agents reporting to a coordinating manager, using the agents-as-tools pattern.
Describes classifying data as a precondition for handling it appropriately, which is the mechanism that makes a permitted-use question answerable at s
How Endex built a financial analyst agent on reasoning models, with the accuracy gain over non-reasoning baselines.
Describes building the platform-level controls that make long-running generative workloads operable rather than handling each workload individually.
Names it without caveat: when the wrong passage comes back the model produces errors regardless, and the reported gain - a quarter more acceptable ans
BCG's executive playbook on the marketing function: where generative AI changes content economics and brand control.
BCG's procurement playbook, including the category-level savings ranges and the buyer capacity they assume.
Capgemini's CMO playbook, drawn from roughly 1,500 organisations, on building rather than buying marketing capability.
The World Economic Forum's procurement playbook, focused on supply-chain risk and sustainability rather than cost alone.
BCG on what chief executives should look for when hiring a marketing leader expected to operate AI-first.
Explains the role by tempo: the technology evolves monthly rather than annually and outruns the usual technology adoption cycles, and the answer offer
Provides a standing checklist structure - impact assessment, risk factor evaluation, product assessment - intended as recurring practice rather than a
Genpact and HFS on four interlocking enterprise debts, sized individually and modelled for what resolution is worth.
BCG's annual survey of 640 chief executives on AI investment intent and where it is actually going.
Capgemini on how far AI has reached executive decision-making, and the gap between individual and collective use.
EY-Parthenon's CEO outlook, covering growth expectations and the transformation agenda behind them.
The World Economic Forum with Kearney on rebuilding the operating model around AI, with five building blocks.
BCG's two-sided survey of enterprise buyers and services providers on where autonomy expands the market.
Reports the identical structural change with the opposite valence, as a career accelerator rather than a squeeze - though the day-one-manager claim is
Data from 5,172 customer support agents: 15% average increase in issues resolved per hour, with less experienced and lower-skilled workers improving b
Measures a single defined programming task completed as quickly as possible, which isolates the effect cleanly and by construction says nothing about
Identifies organizations generating substantial AI activity without changing the operating model, and reframes the leadership task from strategy alone
Proposes the surrounding structure in which an individual control sits, so that a disabled control is visible as a gap rather than as a local preference.
Records that both sides found the activity independently and began containing it - while itself treating that detection as insufficient, since the monitoring in place during internal testing is named among the things to strengthen and the systems had already gained network access, escalated privilege and reached a third party's production database before anyone noticed.
Argues the opposite of consolidation: train people inside the delivery and data science teams to run their own reviews and to recognise when to escalate, on the reasoning that a single central function becomes the gate every review waits at, and that each hand-off across an organizational boundary costs something. Offers its own internal programme as the worked example, and is explicit that the posture has to be enablement rather than refusal.
Proposes an identity and session model in which a revocation is notified once and every enforcement point consults shared state, so that a terminated agent is blocked across protocols and integrations rather than per system.
Names the pattern precisely: someone with low privilege induces a high-privilege agent to do what they could not do themselves, and because the action genuinely executes under the agent's trusted identity, the record it leaves reads as legitimate and pushes detection further out. Adds the credential half - keys and tokens that are static, shared between agents, or weakly held let an attacker act as the agent rather than merely through it, which defeats behavioural guardrails and the monitoring tuned to normal behaviour at the same time.
Proposes the artefact whose absence this issue is about, and is specific about what it has to cover: policies for taking an AI system out of service that address user and community concerns and reputational risk, business continuity and financial exposure, dependencies both upstream and downstream, retention and other regulatory duties, and the possibility of a later legal, regulatory, security or forensic investigation. Separately asks that contingency processes for mission-critical systems be verified to include deactivating them - verified, not merely documented. It stops short of naming who holds that authority, which is the part still resting on our own reading.
Reports that most chief executives place cyber threats among the top three business risks while still treating them as a strictly technical matter to
Moves the accountability off the security function and onto the people who own and fund the systems: patch velocity and how current a platform is kept
Sets out documentation as a continuing lifecycle obligation, which is what makes evidence contemporaneous rather than reconstructed.
Proposes a maintained record of each model, and notes candidly that it is a snapshot which decays without sponsorship and enforcement from management.
Places injection in a ranked, maintained taxonomy alongside the other application-layer risks, which is the free reference this points at rather than
Names it from frontline casework rather than as a caveat: identity weakness is implicated in almost 90% of investigations, and over-scoped roles, inhe
Anthropic's deputy CISO on the four questions his team asks before approving any agentic use case.
Microsoft's annual threat intelligence report on how attackers and defenders are both adopting AI.
The World Economic Forum on the CISO's widening remit and the economics behind it.
Accenture's security survey of 2,286 companies on the distance between perceived and demonstrable readiness.
Anthropic's threat intelligence reporting on observed misuse patterns and the techniques behind them.
BCG on why finance functions land well below their AI return targets, and how few executives can quantify the return at all.
Draws on three CISO summits to argue that point-in-time vendor checks cannot assure a dependency that changes weekly, and that vendor-run trust portal
Reports security ownership consolidating while deployment and funding responsibility stay dispersed, and offers the consolidation as a possible struct
Reports that poorly scoped or unsecured prompts can be exploited without any explicit injection, and that instruction text and the list of callable to
Proposes provisioning, rotating and de-provisioning agent credentials on the same footing as human identity, extending diligence to what the vendor's
Describes adversaries targeting different phases of the AI system lifecycle with methods designed to degrade, deny, deceive or manipulate, which is a
Proposes that an agent action carry the person it serves, the reason it was asked for and the grant that permitted it, and that agents be stopped from
Deloitte on embodied AI reaching commercial viability, with four maturity stages and a governance constraint.
EY on the five forces reshaping the CTO mandate in software businesses, including a notable security readiness gap.
PwC's leadership overview covering governance parameters, ethics and trust as operating constraints.
OpenAI's leadership guide, tracking capability, cost and adoption curves and what embedding training into daily work changes.
IBM's fifteenth annual CEO study: 2,000 chief executives across 33 geographies, organised into five plays.
Proposes putting the outcome into how executives are measured, which is the only mechanism that would make an unowned allocation decision somebody's j
Carnegie Mellon SEI with Accenture: five maturity levels across eight dimensions, with evidence artefacts.
EY's projection of how the chief HR officer's remit changes by 2030.
PwC's labour-market analysis built from over a billion job advertisements across six continents.
Accenture's talent research, identifying the minority of organisations taking an integrated human-AI approach.
BCG's HR playbook covering role disruption and the near-term productivity and cost effects.
Frames capability investment as the route through, which addresses competence but not the accountability question underneath it.
EY on moving core functions from cost centre to capability, with three modernisation routes.
Capgemini's method for scoring how amenable a function is to generative AI, and what blocks adoption.
Deloitte's qualification method for agentic suitability, including its differentiability index.
Anthropic's guidance on selecting use cases, with the data and success metrics each requires.
BCG's approach to assessing opportunity by task, covering automatability and the productivity ceiling.
Deloitte's quarterly enterprise survey, here on proliferation and the governance that has not kept pace.
OpenAI's impact-and-effort method for prioritising use cases, drawn from customer success practice.
Proposes a steering committee or centre of excellence with a step-by-step funnel, and prioritisation decided within it.
Proposes a center of excellence to centralize expertise and coordinate cross-functional teams, citing organizations that ran an average of 24 pilots i
Catalogues the emerging roles across three categories - strategic leadership, technical and operational, enablement and adoption - noting many did not
Deloitte's role-by-role playbook setting out what each C-suite officer owns in an agentic programme.
KPMG's quantification of generative AI value at stake, modelled across more than 7,000 companies.
Microsoft's methodology for becoming a frontier firm, built around five elements from strategy to safeguards.
BCG on what chief executives should expect from a transformation officer operating AI-first.
BCG's executive perspective on maximising AI value, covering starting points and capability building.
Microsoft's running collection of customer transformation stories across employee and customer experience.
Capgemini Research Institute's cross-sector use case collection, drawn from around 1,100 organisations.
Google Cloud's agentic use case analysis across finance, healthcare, technology and consumer sectors.
A sector library for technology, media and telecoms, pairing deployment patterns with value estimates.
A catalogue of named-customer deployments sorted by agent type: customer, employee, code, data and security.
Observes that fear of being left behind led many companies to buy off-the-shelf solutions, and expects more building - in-house or with partners - as organizations mature, laying out a decision grid across strategic fit, data sensitivity, customization, governance, integration, cost and skills.
BCG's earlier treatment of the build-or-buy question, focused on where proprietary data justifies building.
IDC's perspective on build versus buy for enterprises assembling AI-ready infrastructure.
Gartner's short framing of build, buy or blend as a deployment decision.
MIT Sloan's framework for choosing between buying, boosting and building generative AI capability.
States that one answer can be assembled from fragments of many documents at once, so the trail is not straightforward, and identifies unstructured data entering and exiting AI systems with little traceability as a major challenge.
Accenture on why cloud programmes declared finished are not, drawn from 216 companies.
BCG on evolving the data and platform stack for AI, drawn from a survey of around 1,000 respondents.
EY's study of how finance leaders are converting AI investment into measurable productivity.
Palantir's fifteen-step blueprint for retaining institutional control across the model, compute and control layers.
Deloitte on the elements that separate organisations scaling generative AI from those stuck experimenting.
BCG's collected executive playbooks, organised by function for senior leaders.