Chapter 26. The Adoption Roadmap
Eighteen months, four phases, and the sequencing that avoids the common failure of building the Control Plane too early.
26.1 The phases
Table 72.
| Timeframe | Transition | Key actions |
|---|---|---|
| Months 0–3 | L1 → L2 | Name an AI Governance Lead, part-time acceptable. Adopt the minimum artifact set. Run S0–S2 on all new initiatives. Do not attempt retroactive classification yet |
| Months 3–9 | L2 → L3 | Expand ARB to five domains. Stand up the AI Governance Body. Adopt independent countersignature. Retroactively classify existing production AI. Adopt the full record set |
| Months 9–18 | L3 → L4 | Implement machine-readable G3 boundaries for agentic systems. Stand up Control Plane telemetry starting with two or three sources. Populate the Regulatory Overlay Reference. Begin audit sampling |
| Months 18+ | L4 → L5 | Extend the Control Plane. Policy-as-code preventive automation. Recalibrate scoring anchors against real incident data. Activate regional governance if multinational |
26.2 Why this order
Three sequencing decisions carry most of the value, and each contradicts a common instinct.
Classification before gates. The instinct is to stand up review gates first, because they feel like governance. Tiering first means the gates arrive with something to scale against; gates first means uniform ceremony that teams learn to route around before proportionality ever appears.
Governance bodies before the Control Plane. The instinct is to buy tooling early. But Compare needs approved-state records, and approved-state records need a body that produces trustworthy decisions. Telemetry connected to thin decision records produces noise (Chapter 18, §18.2).
New initiatives before retroactive classification. The instinct is to inventory and classify everything first. That is a large program that delays any visible benefit and typically stalls. Applying S0–S2 to new work produces immediate value and builds the scoring competence needed to do retroactive classification quickly later.
26.3 Months 0–3 in detail
Objective: establish tiering as a routine step, with one accountable person.
Table 73. Months 0–3 in detail
| Action | Detail |
|---|---|
| Name the AI Governance Lead | Part-time is fine. What matters is a single accountable name |
| Adopt three records | Risk Classification, Data Lineage and Sensitivity, ADR. Not sixteen |
| Run S0–S2 on new initiatives | Every new AI initiative, including procured. No exceptions for pilots |
| Establish countersignature | Even informally. This is the L3 mechanism worth starting early |
| Instrument the process | Record time spent per classification and per gate from week one |
What to resist. Building a tool, running an estate-wide inventory, standing up two bodies, or writing a full policy suite. Each is a legitimate later step and each will consume the first quarter without producing a governed decision.
26.4 Months 3–9 in detail
Objective: working governance bodies, full record set, and a classified estate.
Retroactive classification is the large task here. Run it in tier-descending order of suspected risk, not alphabetically or by system age: systems that make or materially influence decisions about people or money first, agentic systems next, then everything else. Expect the exercise to surface systems nobody knew were AI-enabled, particularly inside purchased software.
[Practice recommendation] Timebox retroactive classification at one quarter and accept incomplete coverage instead of letting it run indefinitely. A classified 70% of the estate with the highest-risk systems covered is more useful than a perfect inventory delivered a year late.
26.5 Months 9–18 in detail
Objective: actual detection capability, starting narrow.
Connect two or three telemetry sources, not ten (Chapter 18, §18.3). Run everything in report-only mode for a full delivery cycle before enforcing anything. Expect the first comparison run to reveal that your approved-state records are less accurate than you thought; that finding is the point of the exercise.
Machine-readable agent boundaries belong in this phase and should not wait. Any agentic system deployed without one carries a boundary nobody can verify.
26.6 What tends to go wrong, by phase
Table 74.
| Phase | Common failure | Early warning sign |
|---|---|---|
| 0–3 | Tiering becomes a form-filling exercise | Scores cluster at Tier 1; justifications are one word |
| 3–9 | Bodies become bottlenecks | Lead time to ARB exceeds three weeks; teams begin pre-briefing to skip queue |
| 3–9 | Retroactive classification stalls | Inventory grows faster than classification |
| 9–18 | Alert volume overwhelms | Findings age without resolution; owners disable notifications |
| 18+ | Automation pressure on corrective controls | Proposals to auto-remediate Tier 3 systems |