AI Strategy & Transformation: building data and AI capabilities strategically
Many automotive companies have started individual AI projects but lack a foundation to scale them. We guide the build-up of data and AI capabilities strategically and organisationally – from the initial assessment to a prioritised roadmap including governance aligned with the EU AI Act and ISO/IEC 42001.
The situation
After the first pilot projects, the same question arises in many organisations: how do individual initiatives become a scalable capability? The pilots have proven that AI works – but not how data ownership, prioritisation, approval and operations should be organised.
In parallel, the AI inventory grows even without dedicated projects: more and more AI features arrive through standard software. And the EU AI Act demands evidence that an organically grown landscape cannot produce.
Typical data basis
Interviews and workshops with business and IT functions. An inventory of the system landscape and data sources. Existing AI initiatives, pilot projects and their results – including AI features bought in through standard software.
In addition, the regulatory framework, in particular the EU AI Act in its current version, and existing management systems under ISO 27001 and ISO 9001 that AI governance can build on.
Why such initiatives fail
No owner, no transparency. Tens of thousands of data objects are spread across the organisation – often without clear ownership. Before anything can be governed, it has to become visible what sits where and who owns it.
Many ideas, limited budget. Business functions compete for resources and priority. Deciding which use cases get built needs transparent, uniform criteria.
Governance as an innovation brake. Risks have to be controlled without smothering every experiment in an approval process. What matters is the balance between guardrails and speed.
Postponement is not a pause. The regulatory timeline has shifted, the requirements have not. Waiting now only pushes the same effort into a much tighter window.
AI also arrives through the back door. A reliable inventory has to capture the "built-in AI" from standard software too – otherwise the register stays incomplete.
Approach
The mandate follows a four-phase sequence. Phase 1, assessment: an inventory of data sources, organisation, processes and maturity, including a register of all AI applications in use. Phase 2, use case identification: collecting and assessing candidates from the business functions, such as predictive maintenance, forecasting, quality management, supply chain and GenAI applications. Phase 3, business case: assessment by benefit, effort and risk, resulting in a defensible prioritisation. Phase 4: an implementation roadmap with milestones, responsibilities and resource requirements.
In parallel, data governance with a data catalogue, data owner and data steward roles, data quality rules and metadata management – plus AI governance: risk classification per application, a model register, documentation and approval processes, monitoring in operation, and the AI literacy building among users that the EU AI Act has required since February 2025. Where a certifiable framework is desired, we align the processes with ISO/IEC 42001 and attach them to the existing management system instead of building a second structure beside it.
On the regulatory context: the Digital Omnibus to the EU AI Act, Regulation (EU) 2026/1744, postponed the obligations for high-risk systems to December 2027 and August 2028 respectively and narrowed the high-risk definition. Applications that support users, increase efficiency, automate tasks or perform quality control only count as high-risk if their failure can genuinely trigger risks to health or safety. For most engineering applications this means: they fall outside the high-risk class. That is exactly why classification comes first – it bounds the effort rather than creating it. Independently of this, the transparency obligations have applied since August 2026, and the labelling obligations for AI-generated content take effect from December 2026.
What you get
From scattered ideas to a clear roadmap: AI initiatives are assessed together with the business functions, prioritised and translated into an actionable roadmap. Clarity on data and ownership: the most important data objects are catalogued, responsibilities unambiguously assigned.
The AI inventory under control: existing AI applications are registered and classified by risk – including AI features from standard software. Governance that enables delivery: new AI initiatives get a clear, repeatable path from idea to operation, with the EU AI Act's requirements firmly anchored in the process.
The result becomes tangible in the delivered artefacts: the number of assessed and prioritised use cases, the roadmap horizon, the scope of the data catalogue, the number of classified AI applications and the adopted governance documents. We agree this list at the start of the mandate. For a compact entry into the regulatory side, see our AI Compliance Check.
Where our experience comes from
We know both sides: the strategy and governance work, and the delivery behind it – from data foundations for international groups to AI platforms in production use.
Last updated: 13 August 2026