In Five Barriers CEOs Must Overcome for AI Impact, published in March, BCG puts a number on something most people running AI programmes can feel but struggle to name: “where no explicit value logic has been defined, 10 to 20% of anticipated value erodes before it reaches the P&L”. Their diagnosis is not that AI lacks potential. It is that the pathway from local efficiency to enterprise impact was never designed.
KPMG’s Transforming the Enterprise 2026 arrives at the same place from a different direction — most organisations are scaling AI faster than they are redesigning the enterprise that has to carry it, leaving programmes stuck at the level of localised productivity gains.
Both describe an organisational design problem wearing a technology costume. And for any group structure it resolves into one question: who decides what, and on what basis?
Centralising AI strategy is the right instinct.
It is worth saying, because what follows is not an argument against it.
A group that sets AI direction centrally is doing something rational. It avoids multiple entities separately procuring the same tool on different contracts. It applies consistent controls to a technology whose regulatory position is still moving. It concentrates scarce expertise rather than spreading it too thin to be useful anywhere. For a financial group operating across jurisdictions, that coherence is not bureaucracy. It is what makes the risk manageable.
Nobody who has watched an ungoverned AI estate develop would argue for the alternative.
There are two ways to get the calibration wrong, and they are symmetrical.
Centralise too little and the outcome is well known: parallel initiatives with no shared operating model, duplicated effort, uneven quality, a spend line nobody budgeted, governance permanently behind the deployment curve. This failure is visible and embarrassing, which is why most organisations have corrected for it.
Centralise too much and the failure is quieter, which is why it persists.
The use cases that matter most are rarely visible from the centre. They sit inside processes only the people running them can describe — the AML alert review where most hits follow three recognisable shapes, the reconciliation exception that recurs every month end, the onboarding step that takes four days because one system cannot talk to another. These are not strategic initiatives. They are the texture of how work actually happens, and no amount of central reporting surfaces them, because the people who know them were never asked and would not know how to describe them in the format the centre uses.
When everything needs central approval, those use cases do not get escalated. They get worked around informally by whoever is closest to the problem, often with a tool nobody sanctioned and in the best case spreadsheets. Which is the chaos outcome arriving through the door marked control.
The line is not between types of decision. It is between what the centre can see.
Some things the centre sees better by definition: platform and infrastructure, security access standards, supplier contracts and concentration, model selection and the governance frame around it. Consolidating these is not a constraint on local operations — it is what lets local operations proceed without each one solving the same problems badly.
Other things the centre will never see, regardless of reporting quality. Which process is worth automating and which is about to be redesigned anyway. Where exceptions originate and why. What a correct output looks like in a context the centre does not operate in. Whether a wrong answer in a particular workflow is an inconvenience or a regulatory event.
Pulling the second category upward does not produce control. It produces decisions made without the information required to make them, and a local organisation that stops raising things because raising them achieves nothing.
Why nobody holds the end-to-end view — and why that was once the right answer.
Here is what makes calibration genuinely hard, rather than a matter of drawing the line in the right place.
Devolving latitude only works if there is something local to devolve it to. And in most financial institutions, the layer that would have to exercise it does not hold an end-to-end view of its own processes. Not through any failure of capability. Through design.
For twenty years the organising principle was specialisation, and it was correct. Compliance expertise deepened. Risk expertise deepened. Security, AML, data protection, operational resilience — each became a discipline with its own body of knowledge, its own qualifications, its own regulatory interlocutor. That specialisation is why these institutions can meet obligations that would be unmanageable by generalists. It was the right answer to the question being asked, which was how to build defensible depth in each domain.
The question has changed. The structure has not caught up.
How specialisation specifically defeats AI value.
This is the mechanism behind BCG’s eroding 10 to 20%, and it is worth being precise about it.
A specialist optimises their segment. Deploy AI inside a specialist function and it optimises that segment further — faster reviews, quicker drafting, better first-pass quality. Real gains, measurable locally.
But three things tend to be true of a process running across specialised functions, and none of them are visible from inside a single function.
The bottleneck is usually at the handoff, not within the segment. Automating a step that feeds a queue does not shorten the process. It lengthens the queue.
Exceptions usually originate upstream of where they surface. The team spending forty per cent of its time on exceptions is rarely the team that caused them. Fix the symptom at the point of pain and the cost simply moves.
And most consequentially: a specialist can tell you whether their work is done well. They cannot tell you whether it needs to exist. An AML analyst can assess whether an alert review is thorough. Only an end-to-end view reveals whether the alert was generated because of genuine risk, or because a threshold three steps upstream was set conservatively years ago and never revisited.
Automate that review and you have made an unnecessary control efficient. The local metric improves. Nothing reaches the P&L. That is the exact shape of the erosion BCG measured.
What the end-to-end view actually restores.
Three things, and only the first is usually discussed.
It shows where value is genuinely created versus where effort is merely consumed — the prerequisite for deciding what AI should touch at all.
It restores meaning for the people doing the work. A specialist who sees only their segment cannot tell whether their contribution matters. That is a real cost in engagement, and it compounds once AI starts absorbing the visible parts of their role.
And it repositions the work against what the client actually experiences. A four-day onboarding step is a technical constraint internally. To the client it is the relationship, and nobody inside a single function owns that view.
Training does not produce any of this on its own. Deloitte’s 2026 enterprise AI research found that education, rather than role or workflow redesign, was the primary way organisations adjusted their talent strategy for AI — and concluded that focusing on tool training without addressing how work is designed leaves skill development failing to translate into performance.
That is not an argument against training. Prompting skills are genuinely useful and organisations running that training are doing something sensible. It is an argument that it is one of two required things, and the second — giving people sight of the processes they are being asked to improve — is slower, harder to demonstrate, and therefore usually deferred.
Where to start, and why it is also a diagnostic.
The pattern Deloitte identifies among organisations making real progress is unglamorous: redesign one workflow end to end, with clear ownership, then scale. End-to-end ownership creates accountability, surfaces governance gaps early, and builds the confidence to go further.
What makes it useful beyond its own merits is that it tests the calibration at the same time.
Pick one process that matters locally. Give it a named owner with genuine end-to-end visibility and a real decision right. Give the centre a defined role — platform, security review, standards — and no veto over process design. Then watch where it sticks.
If nobody locally can hold the end-to-end view, the answer is not more devolution. Capability has to be built before latitude means anything.
If work stalls waiting for central sign-off on questions the centre cannot answer, the calibration is wrong in the other direction — and there is now a concrete case to point at rather than a complaint.
One warning worth stating. Map the process before deciding AI is the answer, because frequently it is not. A meaningful share of what looks like an automation opportunity turns out to be a step that exists for a reason that expired, a control duplicated across two functions, or a handoff that could be removed entirely. Those fixes are cheaper, faster, and they make any subsequent automation worth more. An organisation that automates before it maps will industrialise whatever it happens to be doing today.
What this does to the shape of the organisation.
One consequence worth anticipating. The capability this requires is not deep functional expertise — the thing most senior roles in financial services were built around. It is the ability to see across a process, hold several systems in mind at once, and work out where a problem originates rather than where it appears.
That shift, from depth in a function to breadth across a chain, is a recruitment and development question, and it resolves more slowly than any AI deployment. Organisations starting now will have it. Those treating it as a downstream consequence will find it is the constraint.
The useful question is not whether to centralise AI strategy. For most groups that decision is made, and it was probably right.
It is narrower: which decisions about AI has your organisation centralised because it concluded they had to be — and which ended up there because nobody asked?
The second category is usually larger than expected, and it is where most of the missing value sits.
Alexandre Castaing is Managing Director of Axon Advisory & Consulting, working with supervised financial entities in Luxembourg on digital transformation, AI governance and operational resilience. Articles are AI-assisted, human-directed, and source-verified.
#AIStrategy #OperatingModel #Leadership #DigitalTransformation #FinancialServices #Luxembourg