The first year — and making yourself less necessary

Lesson 6 of 6 in The AI Center of Excellence: Organizing for AI Adoption.

Everything so far is the destination. This lesson is the road: what to actually do in the first twelve months, in what order, and which failure modes are waiting at each turn. The shape mirrors AWS’s CAF-AI adoption cycle — Envision the opportunities, Align the stakeholders and foundations, Launch pilots that prove value, Scale what works — with the CAF-AI’s standing advice attached: iterate, don’t attempt everything in one pass, and pair the big picture with pragmatic steps and measurable KPIs.

The single most important design constraint: deliver value while building the machine. A first year spent only on charters and rubrics produces a center nobody needs; a first year spent only on pilots produces a skunkworks nobody governs. Every 30-day block below therefore contains both an enable deliverable and a govern deliverable — the dual mandate, scheduled.

The first year, block by block

  1. Days 0-30: mandate and quick wins

    Govern: executive sponsor secured, charter drafted and signed, seed team named (a lead plus two or three, mostly borrowed). Enable: two or three quick wins identified — visible, low-risk, 90-day-deliverable use cases that buy credibility. Start the shadow-AI amnesty: an inventory census with no penalties attached.

  2. Days 31-60: the front door opens

    Govern: risk-tiering rubric v1 (borrow the governance program’s scheme; do not invent a rival), registry started from the census. Enable: intake form live, funding model agreed, weekly office hours begin — the moment the CoE becomes findable.

  3. Days 61-90: first cases through the gates

    Govern: first gate reviews run on the quick-win cases — the gates debug themselves on friendly traffic. Enable: role-based training v1 ships, KPI baseline measured (you cannot show improvement without a "before"). The quick wins demo at the first quarterly review.

  4. Months 4-12: scale what worked

    Champions program launches in the two or three most active units — the seedbed for future spokes. Platform guardrails automate the first checklist items. Quarterly portfolio reviews become routine; the pattern library accumulates one entry per delivered case.

  5. Month 12: first maturity assessment

    Honest reading against the maturity model below: what does the estate look like, which migration triggers have fired, what should the center stop doing next year?

  6. Year two: begin pushing outward

    If year one worked, demand now exceeds the center — on schedule. Year two trains spokes, embeds enforcement in the platform, and starts the deliberate migration toward hub-and-spoke.

Your first year does not run on your calendar alone. It runs against a regulatory clock that keeps ticking whether or not the charter is signed — AI-literacy duties already in force, high-risk obligations arriving on fixed dates, standards maturing underneath them. Scan the external timeline before sequencing your internal one: the deadlines closest to your sector decide which governance artifacts cannot wait until month nine.

The clock your first year runs against: EU AI Act milestones

  • 2021-04-21European Commission proposes the AI Act:

    The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.

  • 2023-05-22Commission issues the AI Act standardisation request:

    CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.

  • 2023-12-08AI Act trilogue deal:

    After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.

  • 2024-08-01EU AI Act enters into force:

    Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.

  • 2025-02-02AI Act prohibitions + AI literacy apply:

    The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.

  • 2025-07-10EU GPAI Code of Practice published:

    Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.

  • 2025-08-02AI Act GPAI rules, governance, and penalties apply:

    Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.

  • 2025-11-19Digital Omnibus proposes AI Act simplification:

    The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.

  • 2026-08-02AI Act general application:

    The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.

  • 2026-12-02Synthetic-content marking compliance deadline:

    Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).

  • 2027-12-02High-risk rules apply — Annex III systems:

    The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.

  • 2027-08-02Legacy GPAI models must comply:

    Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.

  • 2028-08-02High-risk rules apply — Annex I products:

    AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.

And then there are the ways first years die. Four anti-patterns account for most AICoE failures — each one is a half of the job mistaken for the whole, and each has a tell you can spot from the metrics.

The ivory tower — strategy without shipping

A year of frameworks, principles decks, and maturity models; zero systems in production. The tell: the CoE’s calendar is full and its registry is empty. This is the CAF-AI warning verbatim — 'a common mistake is to evolve AI units that do not deliver on business value' — and the cure is structural: put quick-win delivery in the first 90 days and make shipped, governed value the KPI the sponsor reads first.

The gatekeeper bottleneck — governing without enabling

Every request queues for the center’s approval; the queue grows; teams route around it. Microsoft names this failure mode explicitly and prescribes the replacement: guardrails that speed teams up, golden paths, and delegated lanes. The tell: cycle time at the gates climbing quarter over quarter while shadow-AI discoveries climb with it — the two curves are the same curve.

The PoC factory — motion without production

Dozens of proofs of concept, demo days every month, nothing crossing gate 3. Scaling beyond proof of concept is one of the four challenges AWS’s AI/ML CoE guidance exists to address — the factory happens when gate 2 has no kill discipline and gate 3 has no owner. The tell: a pipeline funnel that never narrows; healthy funnels kill most ideas at gate 1 and graduate a meaningful fraction of pilots.

The tool-first CoE — platform without problems

The center buys the ML platform, the GPU commitment, and the enterprise licenses before validating a single use case, then goes hunting for problems that justify the spend. In practice this inverts the CAF-AI’s first principle — work backwards from business outcomes — and it shows up as sunk-cost pressure at every gate: the platform must be used, so weak cases survive. The tell: tooling spend committed in quarter one exceeding the value of every use case in the backlog combined.

The annual assessment needs a yardstick, and the right one measures something counterintuitive: how little the organization needs the center anymore. Both vendor lineages converge here. AWS’s CCoE guidance says the center 'might even disband at some point of future maturity'; Microsoft’s AI CoE guidance charts the deliberate evolution 'from centralized control to an advisory team', possible only once governance is embedded in platform operations. Maturity, read along five dimensions:

The AICoE maturity model: success is measured in decreasing dependence
DimensionFounding (year 1)Scaling (years 2-3)Embedded (destination)

Delivery

The center builds most use cases itself

Spokes build on hub patterns; the center takes only the novel and the hard

Units deliver independently on the pattern library; the center consults

Governance

Manual reviews by the center at every gate

Delegated fast lanes; the center reviews high tiers and calibrates spokes

Platform enforces the floor; humans review only judgment calls

Skills

Expertise lives almost entirely in the core team

Champions active in every major unit; training curriculum on its third revision

AI fluency is a hiring baseline; the champions network self-sustains

Platform

Approved-tooling list in a document

Shared pipelines with guardrails as code for common patterns

The paved road is so good nobody builds off it voluntarily

The center itself

Doing: building, reviewing, teaching — hands on everything

Enabling: standards, calibration, the hardest problems

Advising: guardrails, forums, the registry, the enterprise view — Microsoft’s advisory end-state

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.