Blog
AI Readiness and Operating Models: From Data Foundation to Trusted Impact
Luk Arbuckle, Global AI Practice Leader and Chief Methodologist in Applied AI Science, AI & Technology Solutions
Emily Bratton, Lead in Applied AI Evidence Generation, Design and Delivery Innovation, Research & Development Solutions
Sep 09, 2026

Almost every organization in life sciences is using AI in some form. However, very few organizations can point to a broad lift in decision quality or cycle time, outside of pockets such as drug discovery. e.g., where AI-driven target identification and molecular design are showing real, measurable gains in Phase I, although few AI-designed drugs have reached trials and none have yet been approved.1,2 The wide value gap between isolated success and widespread adoption is the defining feature of the current landscape, and it is rarely explained by model quality. It is explained by data, governance, and ways of working. Why that is the case, and how can a Defensible AI operating model turn AI readiness from an aspiration into a repeatable, native capability?


AI readiness is the compliance floor

The reason this matters now is that the regulatory ground has shifted decisively in about twenty-four months. Regulators have moved from "let's think about this" to "here's how we'll assess it," and the speed and direction of travel is clear even where the detail is still settling.

On the regulatory side, the EMA's reflection paper on AI in the medicinal product lifecycle was finalized in September 2024 and spans the full product lifecycle; the FDA's January 2025 draft guidance sets out a seven-step, risk-based credibility framework with lifecycle maintenance; and the two agencies have since converged on a shared set of AI principles.3,4,5 Alongside the regulators, international standards now provide the foundation, such as ISO/IEC 42001 as an AI management system and ISO/IEC 42005 for AI system impact assessment.6,7 Industry consortia are reporting standards such as TRIPOD+AI, TRIPOD-LLM, ISPE's GAMP guidance, and EFPIA's work on AI across the medicines lifecycle formalize risk-based, tiered validation.8,9,10,11 ISO/IEC 42001 layers over existing quality-management expectations, bridging into frameworks such as ICH Q10 and ISO 13485.

AI Readiness and Operating Models image 1

ISO/IEC 42001, the EU AI Act, and the internal AI policies organizations write to satisfy regulators apply squarely to insights and analytics work, and broader instruments such as the OECD's classification approach and the NIST AI Risk Management Framework shape how regulators think.12,13,14 The practical implication is the one that gives this section its title. These expectations are a compliance floor, not a ceiling, and the cost of building without them in mind is not avoided but deferred, paid back later as retrofit, delay, and rework.


The pattern is consistent across sources

Regardless of which sources you read, a common picture emerges (e.g., BCG, MIT, McKinsey, Deloitte).15,16,17,18 A small minority of organizations capture most of the value, and the spread is widening year over year. A large share of custom generative AI pilots never reach production, and most organizations still lack a comprehensive AI vision. The cause is not the algorithm or the tech. BCG's widely cited framing puts it at roughly 10% algorithms, 20% technology and data, and 70% people, process, and workflow change.19

That 70% of people, process, and workflow change is the part organizations consistently underestimate. It’s also why a brand-performance question that should take a day can take several weeks. The constraint is fragmented data and the bespoke integration needed to make it usable, not the sophistication of the model sitting on top. This is an old lesson in new clothing. The economist Robert Solow observed decades ago that you could see the computer age everywhere except in the productivity statistics.20 The resolution then was not better technology. It was reorganizing work around it. The same holds for AI today.


Winners invest across the same core capabilities

One way to make this concrete is to organize what the strategy consultancies and industry surveys are saying into three buckets.

First is strategy and ambition: the top-down vision and targets that connect revenue uplift and cost reduction to a real mandate. Without it, pilots proliferate and nothing scales. Leadership is needed to create alignment and drive action, by setting targets and ensuring accountability. This is now visibly structural. By 2026 roughly three-quarters of large organizations had appointed a Chief AI Officer, up from about a quarter a year earlier, and those that did reported materially higher returns on their AI investment.21 In large pharma the same pattern holds, with companies such as Sanofi and Eli Lilly building dedicated digital-and-AI operating models and governance councils rather than leaving AI as a departmental side project. 22, 23, 24

The second is AI technology. Read from the bottom up, its elements line up with the way we define IQVIA Healthcare-grade AI®: a quality data foundation, then the engineering and platforms that turn that data into capability, then the trust, governance, and risk layer that sits on top. That ordering is not incidental. It mirrors the building blocks of Healthcare-grade AI® through quality data, fine-tuned and validated technologies, and expert led and in the loop. Because quality in is what produces quality out.

The third is AI adoption, and this is the one most organizations shortchange. Its elements are the operating model, talent and change, and ecosystem and partnerships. In other words, adoption is about the operational model and the ways of working—including change management and the integration of AI into existing workflows and systems—that let people actually use what has been built. This is the strongest alignment with Defensible AI: the operating model that produces evidence and creates trust, building on the foundations of responsible AI and trustworthy AI. Responsible AI states principles and is often policy-focused; trustworthy AI tends to be more technical; Defensible AI is what produces the evidence that a system can withstand scrutiny throughout its lifecycle, not just pass a review once.

AI Readiness and Operating Models image 2

Defensible AI is delivered across a governed, human-led lifecycle: data governance and quality, model development and validation, risk-based testing and oversight, and deployment and lifecycle management. These are aligned with FDA and EMA AI principles,5 ISO/IEC 42001 and 42005,6,7 and GxP best practice. The point of the framework is proportionality: the same operating model, applied with a calibrated bar so that a commercial use case gets promotional-compliance and drift monitoring rather than a clinical validation package.

Our earlier writing sets out the underlying logic here, from the standards themselves in A Blueprint for Defensible AI to the risk-tiering that makes proportionality workable in Building Credible AI—Risk Tiering and Trust, and the platform-level practices in Managing AI in Practice: A Structured Approach to Reliable and Defensible Systems. Extending those defenses to the security threats that AI systems uniquely introduce is the subject of An Integrated Approach to Securing AI.


Why the industry background matters for AI readiness

We should recognize that the barrier to value is organizational before it is technical, which reframes what AI readiness has to mean. Readiness is not the same as digital maturity. Digital transformation makes an organization AI-capable through integrated data, cloud, digital workflows, and workforce fluency. AI readiness is the capability layer built above digital maturity, adding governance for automated decision-making, AI-specific workforce skills, strategic alignment on AI outcomes, and model management and monitoring.

Two extremes follow directly, and are found in the surveys mentioned above. Digitally mature organizations may assume they are AI-ready and systematically underinvest in governance and workforce. Others may treat AI readiness as a fresh start and duplicate investments they have already made. Both misjudge where the work actually is. The readiness question extends the thinking in Navigating AI by Evaluating Readiness, which framed readiness as a foundation built from data wrangling, infrastructure, talent, governance, and culture.

It’s useful to anchor this on an AI maturity model to see the path forward. One that is quite useful is the MIT CISR enterprise AI maturity model, which provides clear direction with concrete attributes.25 It describes four stages: experiment and prepare, where you educate the workforce, set AI policy, and become evidence-based; build pilots and capabilities, where you define metrics and develop enterprise capability; develop ways of working, where you simplify and automate processes and build a test-and-learn culture; and become AI future-ready, with AI embedded in decision-making and proprietary AI used internally.

The reason we highlight this model is precisely because it reinforces the importance of developing ways of working. Most insights and analytics functions probably sit in the second stage today, i.e., strong pilots, weak metrics. The largest jump in value comes at the third stage, and it’s a ways-of-working change, not a technology one. That’s the same conclusion the industry evidence points to, arrived at from a different direction.


From foundation to trusted impact

Though it may not always seem clear, the through-line is straightforward. The constraint on AI value is not models; it’s data foundations, governance, and workflow change. A Defensible AI operating model addresses all three at once, applied proportionately so that the bar fits the use case rather than defaulting to the most conservative setting for everyone. The winning move is speed with defensibility built in rather than bolted on afterward, because retrofitting governance later means delay and rework, while building it in keeps the work regulator-ready without slowing the cycle.

The organizations that pull ahead are not the ones with the best algorithms. They are the ones that treat adoption, operating model, and ways of working as first-class investments, and that build the evidence to trust the systems they deploy.


References

1 Jayatunga MKP, Ayers M, Bruens L, Jayanth D, Meier C. How successful are AI-discovered drugs in clinical trials? A first analysis and emerging lessons. Drug Discov Today. 2024;29(6):104009. Available from: https://doi.org/10.1016/j.drudis.2024.104009

2  Wilczok D, Zhavoronkov A. Progress, pitfalls, and impact of AI-driven clinical trials. Clin Pharmacol Ther. 2025;117(4):887–890. Available from: https://doi.org/10.1002/cpt.3542

3 European Medicines Agency. Reflection paper on the use of artificial intelligence in the medicinal product lifecycle [Internet]. EMA; 2024 Sep. Available from: https://www.ema.europa.eu/en/use-artificial-intelligence-ai-medicinal-product-lifecycle-scientific-guideline

4 US Food and Drug Administration. FDA proposes framework to advance credibility of AI models used in drug and biological product submissions [Internet]. FDA; 2025 Jan. Available from: https://www.fda.gov/news-events/press-announcements/fda-proposes-framework-advance-credibility-ai-models-used-drug-and-biological-product-submissions

5 US Food and Drug Administration, European Medicines Agency. Guiding principles: good machine learning / AI practice for drug development [Internet]. FDA; 2026 Jan. Available from: https://www.fda.gov/about-fda/artificial-intelligence-drug-development/guiding-principles-good-ai-practice-drug-development

6 International Organization for Standardization. ISO/IEC 42001:2023 — AI management system [Internet]. ISO; 2023 Dec. Available from: https://www.iso.org/standard/42001

7 International Organization for Standardization. ISO/IEC 42005:2025 — AI system impact assessment [Internet]. ISO; 2025 May. Available from: https://www.iso.org/standard/42005

8 Collins GS, Moons KGM, Dhiman P, Riley RD, Beam AL, Van Calster B, et al. TRIPOD+AI statement: updated guidance for reporting clinical prediction models that use regression or machine learning methods. BMJ. 2024;385:e078378. Available from: https://www.bmj.com/content/385/bmj-2023-078378

9 Gallifant J, Afshar M, Ameen S, Aphinyanaphongs Y, Chen S, Cacciamani G, et al. The TRIPOD-LLM reporting guideline for studies using large language models. Nat Med. 2025;31(1):60–69. Available from: https://www.nature.com/articles/s41591-024-03425-5

10 International Society for Pharmaceutical Engineering. GAMP guide: artificial intelligence [Internet]. ISPE; 2025 Jul. Available from: https://guidance-docs.ispe.org/doi/book/10.1002/9781946964854

11 European Federation of Pharmaceutical Industries and Associations. AI across the medicines lifecycle: insights from preliminary case studies and considerations for policy [Internet]. EFPIA; 2025 Nov. Available from: https://efpia.eu/news-events/the-efpia-view/efpia-news/ai-across-the-medicines-lifecycle-insights-from-preliminary-case-studies-and-considerations-for-policy/

12 European Parliament. EU AI Act: first regulation on artificial intelligence [Internet]. 2024 Jun. Available from: https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence

13 Organisation for Economic Co-operation and Development. OECD framework for the classification of AI systems. OECD Digital Economy Papers, No. 323. Paris: OECD Publishing; 2022 Feb. Available from: https://www.oecd.org/en/publications/oecd-framework-for-the-classification-of-ai-systems_cb6d9eca-en.html [oecd.org], [digitalgov...enthub.org]

14 Tabassi E. Artificial intelligence risk management framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg (MD): National Institute of Standards and Technology; 2023 Jan. Available from: https://doi.org/10.6028/NIST.AI.100-1

15 Apotheker J, Beauchene V, de Bellefonds N, Forth P, Franke MR, Grebe M, Kataeva N, Kirvelä S, Kleine D, de Laubier R, Lukic V, Luther A, Martin M, Walters J, Schweizer C. The widening AI value gap: build for the future 2025 [Internet]. Boston Consulting Group; 2025 Sep 30. Available from: https://www.bcg.com/publications/2025/are-you-generating-value-from-ai-the-widening-gap

16 Challapally A, Pease C, Raskar R, Chari P. The GenAI divide: state of AI in business 2025 [Internet]. MIT Project NANDA; 2025 Jul. Available from: https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf

17 Singla A, Sukharevsky A, Hall B, Yee L, Chui M, Balakrishnan T. The state of AI in 2025: agents, innovation, and transformation [Internet]. McKinsey & Company, QuantumBlack; 2025 Nov 5. Available from: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

18 Asaftei GM, Roberts R, Sticha A, Prinsen C. State of AI trust in 2026: Shifting to the agentic era [Internet]. McKinsey & Company; 2026 Mar 25. Available from: https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era

19 Boston Consulting Group. The leader's guide to transforming with AI [Internet]. BCG; 2024 Dec 12. Available from: https://www.bcg.com/featured-insights/the-leaders-guide-to-transforming-with-ai

20 Solow RM. We'd better watch out. New York Times Book Review. 1987 Jul 12:36. Available from: http://digamo.free.fr/solow87.pdf

21 IBM Institute for Business Value. 2026 CEO study: rewiring the C-suite — the fast track to 2030 [Internet]. Armonk (NY): IBM; 2026 May. Available from: https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2026-ceo

22 Sanofi. Sanofi "all in" on artificial intelligence and data science to speed breakthroughs for patients [Internet]. Paris: Sanofi; 2023 Jun 13. Available from: https://www.sanofi.com/en/media-room/press-releases/2023/2023-06-13-12-00-00-2687072

23 Sanofi. Sanofi launches its first Digital Accelerator, fueled by new talent and focused on growth [Internet]. Paris: Sanofi; 2025 Apr 29.

24 Eli Lilly and Company. Lilly appoints Thomas J. Fuchs as the company's first chief AI officer [Internet]. Indianapolis (IN): Eli Lilly and Company; 2024 Oct 8. Available from: https://investor.lilly.com/news-releases/news-release-details/lilly-appoints-thomas-j-fuchs-companys-first-chief-ai-officer

25 Weill P, Woerner SL, Sebastian IM. Building enterprise AI maturity. MIT Center for Information Systems Research; Research Briefing No. XXIV-12; 2024 Dec 19. Available from: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian

Related solutions