Discussion about this post

User's avatar
Andrea Politano's avatar

Excellent post, Silvia! One question: what is the status of agentic systems for internal usage? Meaning, a company develops an agent for internal usage, leveraging off-the-shelf LLMs (e.g. GPT without fine-tuning). Does the company falls within the "provider" category is such case?

State of Play's avatar

Thanks for this. Your "the deployer role can change without you noticing" is the sharpest observation in an already sharp piece, and it's more structurally true than the legal framing alone captures. The system-by-system role classification you prescribe runs directly into the fact that most organizations can't enumerate the systems they'd need to classify: surveys across enterprise deployments show more than 50% lack any systematic AI inventory, and roughly 60% of AI systems run outside IT visibility. The silent deployer-to-provider transition isn't an edge case to watch for; it's the modal enterprise situation, and it's structurally invisible precisely because the AI inventory that would surface it is the single most common governance gap. Your decision tree is well-designed; the problem is that step one is failing before step two begins.

3 more comments...

No posts

Ready for more?