RedactSure Perspectives · The Enterprise AI Operating Models

Your AI Strategy Is Probably Wrong

Most enterprises are drifting into one of two failure modes. The fix is not more AI or less of it. It is governing the workflow between the tools you bought and the work you actually do.

01Two sentences that expose the strategy gap

Over the past year of conversations with CIOs, CISOs, and business leaders, two statements come up so often they amount to a market diagnosis. The first: "We have Microsoft Copilot. We are already doing AI." Copilot provides real assistance across email, meetings, and documents. But in many of these companies the highest-value processes remain untouched, and employees who know what modern AI can do are quietly using their own tools to do it.

The second: "We have an enterprise agreement and a BAA. Our confidential data is safe." The commercial protections from OpenAI, Anthropic, and Microsoft are real and worth having. They govern what the vendor may do with your data. They say nothing about what a specific employee, agent, or workflow should be allowed to see and do inside your own operation.

The first statement mistakes a productivity deployment for transformation. The second mistakes vendor commitments for governance. Both errors share a root cause: treating AI strategy as a purchasing decision when the real unit of change is the workflow.

FROM THE FIELD

A health services organization with thousands of employees we spoke with had written acceptable-use policies and no technical controls behind them: nothing prevented protected health information from reaching an unauthorized model, and no one could see where staff were using AI. On paper, a governed deployment. In practice, both failure modes at once.

02The four operating models

The two questions underneath those statements, how broadly sanctioned AI executes work and how exposure is governed, define four operating models. Most companies can locate themselves in about a minute.

The four enterprise AI operating models
Exhibit 1. The four enterprise AI operating models.

The framework is not a vendor ranking. Application AI is a legitimate, valuable building block, and Theater AI describes a deployment choice rather than a product limitation. Nor are the quadrants mutually exclusive. The most common state we encounter is Theater AI and the Time Bomb at the same time: a narrow sanctioned deployment, a policy that assumes compliance, and unmeasured AI use everywhere else.

03Why both failure modes persist

Three adoption and results measures: 78%, 34%, and 13%
Exhibit 2. Adoption has outrun both governance and results.

Theater AI persists because it feels safe. Sanctioned use stays at the assistant layer while employees, who already know what personal LLMs can do, improvise off-channel: personal accounts, retyping, screenshots. Shadow AI is the visible symptom; the operating model is the diagnosis. A ban produces invisibility, not safety.

The Time Bomb persists because it feels covered. An organization connects models and agents to sensitive systems, then assumes the enterprise agreement answers questions it was never designed to answer: what a task should see, which fields are necessary, where an agent may act, which actions require approval. The gap is easy to underestimate because AI looks like a prompt box. An agent is more than that: it reads what the screen shows, every field and record in front of it, and can carry what it read beyond the application and the controls around it. Microsoft's own Purview guidance is the cleanest evidence that these are separate layers: it instructs organizations to prevent sensitive data from being pasted or uploaded even into sanctioned AI applications. OWASP, meanwhile, treats prompt injection, sensitive information disclosure, and excessive agency as distinct risks no contract addresses.

04Application AI: real value, wrong boundary

SAP, Oracle, Salesforce, and Workday are embedding capable agents inside their platforms, and Gartner expects 40% of enterprise applications to ship task-specific agents by the end of 2026, up from under 5% in 2025. These tools bring native context, existing permissions, and vendor-managed controls. Enterprises should use them.

The limitation is structural rather than technical. A procure-to-pay, claims, billing, or onboarding process rarely lives in one application; it crosses inboxes, documents, ERP screens, external portals, and approval systems. Application AI improves the work inside its platform. It becomes Workflow AI only when the organization governs execution across the complete process, and no single vendor owns that boundary.

FROM THE FIELD

A newly appointed CTO at an industrial technology firm made the distinction sharply: his engineering environments were already contained and strictly regulated, so agent risk felt manageable there. The exposure he worried about sat in the business units, where shadow-IT behavior is highest and no engineering discipline governs what AI sees. The quadrant a company occupies can differ by department.

05What Governed Workflow AI looks like

The goal is not to stop AI, and not to open everything. It is to give AI access to the workflow without giving it unrestricted access to everything visible inside the workflow.

  • Start with an end-to-end business outcome, not a model or an application.
  • Redaction before exposure: PII, confidential financials, and credentials are masked at the render layer before any model sees them. User permissions stay exactly as they are; what changes is what the AI can see.
  • Controls at the interaction layer, in addition to IAM, DLP, and native application security, because the browser is where cross-application work actually converges.
  • Human approval on consequential actions, with a named person on the record.
  • A complete audit trail: what the workflow read, changed, transmitted, and approved.
  • Secure compute: real values held in hardware-encrypted enclaves with customer-held keys, unreadable even to the platform provider.

06The first 90 days

Days 1–30. Inventory sanctioned, embedded, and personal AI use. Identify three workflows where employees are already improvising, and map the applications and sensitive data each one touches.

Days 31–60. Design task-specific access, redaction, and approval policies for one high-value, bounded workflow. Define the metrics before the pilot: cycle time, quality, cost, and risk.

Days 61–90. Run the governed pilot. Log what the agent sees and does, compare against the manual process, and use the exceptions to improve the controls. Publish the result internally; a working workflow builds adoption in a way no policy memo can.

07Where RedactSure fits

RedactSure provides the workflow-level control layer this operating model requires: a sanctioned environment where AI co-workers execute cross-application work with every sensitive value masked at the screen layer before any model reads it, human approvals on consequential actions, and an audit trail that holds tokens rather than raw data. It complements enterprise AI contracts, DLP, identity, and native application controls; it does not replace them. The strategy, though, comes first. Whatever tooling you choose, govern the workflow.

Chris Sowa is a founder of RedactSure and a former CEO of AI companies — he started his first years before ChatGPT existed. He was previously an AI Leader at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.

Sources

  1. Microsoft & LinkedIn, "AI at Work Is Here. Now Comes the Hard Part" — 78% of AI users bring their own AI tools to work.
  2. Deloitte, "The State of AI in the Enterprise 2026" — 34% of organizations truly reimagining the business with AI.
  3. Accenture, "Technology Vision 2025" — 13% of executives report significant enterprise-level gen AI impact.
  4. Microsoft Purview, "Block Sensitive Data Going to Sanctioned AI Apps".
  5. OWASP, "Top 10 for Large Language Model Applications 2025".
  6. Gartner, "40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026".
  7. Field observations are drawn from RedactSure customer and prospect conversations and are presented as recurring patterns, not statistical claims.