IMPAKT
Back to Decision Library
Updated Enterprise AI Strategy, AI Governance, Solution Architecture

Ten Rules for a Model-Swappable Enterprise AI Strategy

Build an enterprise AI strategy around accepted workflows instead of one model family. These ten rules separate replaceable supplier facts from compounding workload, authority, evidence, and recovery assets, then turn reversibility, ownership, and change triggers into a practical funding screen for CTOs and boards.

A field note by for IMPAKT.

A durable enterprise artificial intelligence (AI) strategy is a model-swappable operating system built around accepted work. Keep the workload definition, authority, evidence, and recovery contract stable enough to learn; treat models, prices, limits, and supplier features as dated inputs that must requalify. The ten rules below screen the assets a portfolio should own. The separate placement decision chooses an execution configuration for each workload. Narrow proposals that fail either decision before funding them.

The strategic asset sits below the model layer

A model can improve quickly while the surrounding workflow still fails to complete accountable work. The gap includes context construction, tool integration, permissions, validation, exception handling, human judgment, and recovery. An ineligible data path or unauthorized action remains binding regardless of checkpoint speed.

This is why IMPAKT recommends separating two layers. The replaceable layer contains model IDs, context limits, modalities, prices, feature flags, licenses, regions, retention terms, and current benchmark positions. These facts belong in a dated qualification inventory.

The compounding layer contains workload definitions, acceptance cases, identity, data rights, tool contracts, failure cases, traces, release records, incident learning, and recovery exercises. Those assets can remain useful when a supplier, checkpoint, runtime, or execution venue changes.

The enterprise may rent components while retaining accountable ownership of the control contract and exportable evidence. The NIST AI Risk Management Framework similarly treats governance, mapping, measurement, and management as connected functions, while remaining a voluntary framework rather than an approval.

Rules one through three: decide from the workload

1. Workload before model. Define the task, user, full data path, accepted end state, quality threshold, latency, demand, consequence, exceptions, and recovery before comparing infrastructure. “Use the strongest model” describes a preference rather than a workload.

2. Eligibility before scoring. Remove any complete configuration that fails a binding capability, data, authority, service, recovery, or ownership gate. A weighted benefit elsewhere cannot average away a prohibited route or an unowned failure.

3. Outcome before token. Compare cost, latency, capacity, and energy at the same accepted completed-workflow unit. Count results only after they pass task, severe-failure, service, authority, and recovery thresholds.

These rules prevent early procurement momentum from becoming architecture. The live IMPAKT guide to API, self-hosted, and hybrid placement provides the detailed hard-gate matrix. The strategic point is simpler: every candidate must be a whole, named configuration evaluated against the same work.

Rules four through six: design the whole system

4. System before checkpoint. Qualify the model together with its prompt, context, retrieval, state, tools, permissions, evaluator, operator, and recovery path. Changing one of those elements changes the released system.

5. Evidence before autonomy. Increase authority only after repeated end-to-end behavior, containment, detection, recourse, and recovery support the exact next boundary. Drafting evidence supports drafting; each new action and tool requires its own evidence.

6. Enforcement outside the model. Generated text may propose an action. Trusted application components must authenticate the actor, authorize the resource and operation, validate arguments, execute the call, record the result, and reject prohibited behavior.

Vendor-authored guidance on building effective agents distinguishes predefined workflows from agents and recommends using the simplest approach that meets the need. That source supports a useful design direction; enterprise release still requires local evidence.

The unit to approve is therefore the harnessed workflow. A goal contract names deliverables and non-goals. Structured state makes work restartable. Tool schemas limit action. Evaluations inspect behavior. Budgets and stop rules prevent an indefinite loop. Recovery defines what happens after partial execution, duplicate requests, timeouts, or an unavailable dependency.

Rules seven through ten: operate for change

7. Reversibility before commitment. Keep adapters explicit, versions pinned, cases replayable, and evidence exportable. Qualify a second route only when its resilience or negotiating value exceeds the ongoing cost of maintaining it. A tested manual path can be more credible than a neglected backup integration.

8. Ownership follows control. Self-operation increases control only when named teams can own serving, capacity, patching, evaluation, security, incidents, and lifecycle work. Renting inference can still preserve enterprise control when the contract, evidence, data path, and exit conditions pass.

9. Change invalidates evidence. Reopen the decision after a material change to the workload, model, prompt, retrieval, data distribution, tool, permission, evaluator, runtime, quantization, supplier, owner, or recovery path. A successful test supports its versioned configuration and workload boundary.

10. Scenarios before forecasts. Use several plausible causal worlds, observable signposts, no-regret moves, and reversible options. Keep a historical benchmark curve as one evidence input; set capital dates through signposts and decision gates.

Together, these rules make change a qualification event rather than a strategy reset. The organization continues to own the question, the accepted outcome, and the proof burden even when the answer changes.

Use the ten-rule strategy card

For one proposed investment, write a one-page record with these fields:

  • workload ID, accountable owner, current baseline, and decision deadline;
  • start state, accepted end state, severe failures, and recovery objective;
  • complete candidate configuration and every binding eligibility gate;
  • accepted-workflow unit, demand range, service threshold, and cost boundary;
  • permitted authority, external enforcement point, and human checkpoint;
  • evidence package, version, date, expiry, and change triggers;
  • operating owner, incident owner, replacement path, and exit cost;
  • scenario signposts that could renew, reroute, resize, or retire the investment.

An incomplete item becomes an owned unknown with a test and date. Decide whether its uncertainty blocks the next stage. Any unknown that can reverse eligibility or create a severe consequence blocks release.

Synthetic worked workload — invoice-exception brief. Workload FIN-INV-EXC-01 drafts an evidence-linked brief from approved invoices, purchase orders, and receipts; an authenticated finance owner retains every system change. The model can change while the workload contract, source rights, acceptance cases, trace, and manual fallback remain enterprise assets. Measure accepted briefs per hour, review minutes, severe citation failures, recovery time, and cost per accepted brief on each complete route. Keep values marked to measure until matched tests exist. The strategy rule is to fund the reusable evidence and authority plane first. The boundary is equally concrete: an acceptable drafting route earns drafting scope, while payment and supplier records remain outside its authority.

When a differentiated feature should remain sticky

Model swappability preserves the accepted outcome rather than enforcing lowest-common-denominator architecture. A supplier-specific tool, state mechanism, modality, or control can create measurable value. Keep it when that value exceeds the added qualification, control, and exit burden for the named workload.

The countercondition matters. If a thin adapter destroys material capability, increases severe failures, or makes recovery less credible, preserve the differentiated path and record the concentration. Portability should protect the accepted outcome and evidence, not imitate every interface.

Decision rule

Own the workload, authority, evidence, and recovery plane. Rent or operate inference according to current workload value, and narrow any investment that cannot be explained through all ten rules.

What this does not prove

These ten rules are an IMPAKT synthesis and operating recommendation. They do not prove that one architecture is universally superior, that model substitution is costless, or that a completed checklist establishes security, compliance, production readiness, savings, resilience, or business value. Each workload still requires current evidence and accountable specialist review.

Editorial process

This article was extracted from the IMPAKT LLM Operating Playbook with AI-assisted structure, drafting, editing, and metadata preparation. It underwent an independent critique and substantive revision loop against IMPAKT's publication rubric; primary sources are linked beside supported claims, and synthesis, recommendations, and evidence boundaries remain explicit.

Sources