Decision intelligence — Middle East

The AI Operating Model: Who Decides, Who Builds, Who Carries the Risk

Most stalled AI programmes are not blocked on technology. They are blocked because nobody can approve a use case without three functions agreeing, and no one of those functions is accountable for the outcome.

Decision intelligenceWritten by NirjiX AI AdvisoryPublished January 2026Last reviewed February 20269 min read

Direct answer

Direct answer

Use a hybrid: a small central group owns the platform, the risk framework, evaluation standards and the shared data contracts, while business units own their use cases, their benefit cases and their adoption. The central group's authority should be narrow and real — it can block on safety, evaluation and data access, and nothing else. Business units fund and staff delivery, because a use case without a business owner who loses something when it fails will not survive contact with an operational process. Fully centralized models create queues and shelfware; fully federated models create duplicate platforms and inconsistent risk handling. What makes either version work is written decision rights: who approves, who can veto, and how long an approval is allowed to take.

Three structures compared on what actually differs

ModelWorks whenFails as
Centralized (central AI team builds)Few use cases, scarce skills, high regulatory exposureA queue: the central team becomes the bottleneck and business units route around it
Federated (each unit builds)Strong engineering culture in the units, mature platform already in placeDuplication: several platforms, inconsistent evaluation, risk handled differently in each unit
Hybrid (central platform + unit delivery)Most large enterprises past the first pilotsTheatre, if the central group's authority is advisory rather than defined

The decision rights that have to be written down

  • Who approves a use case to enter build, and against what evidence.
  • Who can stop a deployment, on what grounds, and within what time limit.
  • Who owns the data contract when a use case needs data from another function.
  • Who funds delivery — central budget, business unit, or a matched split.
  • Who signs off that a model in production still performs as claimed.
  • What happens when the evidence gate is missed: stop, extend once, or absorb into run.

The capability question underneath the structure

Every operating model assumes a set of roles exists. In practice most enterprises are missing two: a product owner who can specify an AI-supported process end to end, and an evaluation owner who can say whether a system is good enough to release. Engineering talent is usually the easier gap to close.

Deciding structure before those roles exist produces an accurate diagram and no change in throughput. Name the two roles first, even if they are part-time, then choose the model that lets them work.

NirjiX view

The NirjiX view

Reorganizing is the most common substitute for deciding. A hybrid model with vague authority performs worse than a centralized model with clear authority, because at least the centralized version tells people where to queue.

Give the central group three hard vetoes — safety, evaluation, data access — and take away every other approval it holds. Throughput usually improves before headcount changes.

Frequently asked executive questions

Do we need a Chief AI Officer?
Only if the role holds budget and veto authority. A coordinating role without either adds a meeting to every decision. Where accountability already sits with a CIO, CDO or COO who can fund and stop work, a new title rarely changes throughput.
Should the central AI team build the first use cases?
Usually yes, for the first two or three — it is the fastest way to establish patterns, evaluation standards and reusable plumbing. It should stop building by the time the platform is stable, or it becomes the permanent bottleneck.
Where should AI risk and compliance sit?
With existing risk functions, extended rather than duplicated. A parallel AI risk organization dilutes accountability and slows both. The AI-specific addition is evaluation evidence: what was tested, against what, and by whom.
How does this change once agents are in production?
Decision rights matter more, not less. Agentic systems act rather than advise, so the approval path needs a named human owner per agent, a defined scope of action, and a stop mechanism that works in minutes.

Explore

Related guides in this cluster

  • AI Implementation

    Treat production as a set of conditions rather than a deployment event: the output is integrated into the workflow where the decision is made, a named owner is accountable fo…

Transparency

Sources and methodology

This page reflects NirjiX advisory practice rather than a survey or a vendor benchmark. The structure of the assessment — the dimensions, the maturity language and the sequencing logic — is the same framework used inside the NirjiX AI readiness assessment and the AI plan builder.

Where we describe patterns ("most organizations discover…"), we are describing what we observe across client engagements, not a measured statistic. We deliberately avoid quoting market numbers we cannot verify, because an AI investment case built on borrowed statistics collapses the first time a CFO tests it.

Any figure that ends up in your own plan should come from your own data: your cost base, your cycle times, your error rates, your volumes. The assessment and plan builder are designed to force that discipline.

Turn the judgement into a plan you can fund

The AI readiness assessment scores where the organization actually stands; the AI plan turns that into a sequenced, costed set of moves.

Outputs are preliminary and intended for advisor validation before funding decisions.