Shadow IT becomes a group-wide platform.
An international testing and certification group wanted to make AI usable across the whole organisation - without shadow IT, without data leaving the company, without being tied to a single vendor. We built a central AI platform that serves every business unit and brings compliance, cost and governance together in one place.
The starting point
After the first waves of ChatGPT, several isolated solutions had taken hold across the organisation: individual departments were buying their own AI access, often directly from third-party providers. Where the data ended up, who was spending how much, and which regulatory requirements were being met had become close to untraceable for IT and compliance. At the same time the pressure from the business units was rising to make AI broadly available at last - not as a pilot, but as a tool in everyday work.
What we deliberately did not do
The obvious proposal, "one central chat frontend for everyone", had to be rejected. The use cases across business units differ fundamentally - an auditor needs something different from a sales representative, and a compliance function something different again. A single interface would have served everyone only halfway and would have cost acceptance exactly where it mattered.
Just as deliberately, we decided against a single AI provider. For a business-critical platform, being tied to one contractual partner is a strategic risk - both commercially and in regulatory terms.
What we actually built
A platform with clearly separated building blocks that share a common foundation - permissions, cost control, auditing, data sources. That way each business unit gets the interface and the functions it needs, without every team having to reinvent compliance, security and governance.
- A group-wide, governed AI workspace for employees.
- An internal marketplace for domain-specific AI applications - from a sales assistant to audit support.
- A shared knowledge base that makes group documents accessible securely and in line with permissions.
- A single sign-on, tenant and quota layer serving all the building blocks.
What did not work
The first version of the knowledge access delivered answers that were too often topically plausible but factually wrong - typical of purely semantic search. For an organisation whose business rests on reliability, that was not acceptable. We rebuilt the approach so that it combines semantic and classical search and handles queries differently depending on their type. The "half right" answers largely disappeared.
The strategic lever
The most important architectural decision was organisational, not technical: build the shared foundations once, centrally - and give them to every new domain application for free. Any department can stand up its own solution on the platform quickly, without rebuilding compliance, permissions and cost reporting. That turned a platform project into a platform lever: every new use case is cheaper and faster than the one before it.
What we would do differently today
We would have built the central sign-on and permissions layer earlier. We initially used separate solutions per building block and merged them afterwards - which cost quarters. For a platform that touches the whole company, clarifying auth, permissions and cost reporting centrally pays off at the start, not at the end.
A similar platform requirement at your company?
45 minutes. We walk the architecture, the governance and the pitfalls through your case.