top of page
Atlas logo with compass star icon

What Happens When Everyone Has an AI Agent, but They Aren’t Registered?

3 days ago
8 min read

By Rishi Dixit, Head of Strategic Solutions, Innovation & Partnerships, Atlas


The AI you approved and think is running is not the only AI your organization is running.



Life sciences organizations are moving quickly to explore artificial intelligence. Teams are using AI to summarize documents, draft content, support data analysis, prepare meeting materials, accelerate workflows, and surface operational insights. Many of these efforts begin with a reasonable intention: solve a real business problem, reduce administrative burden, or improve decision-making speed.


The challenge is not that teams are experimenting. The challenge is that experimentation can outpace visibility.


In many organizations, the formal portfolio may show a manageable set of approved AI use cases. The steering committee has reviewed intake forms. Governance forums have assigned sponsors. A prioritized roadmap exists. Yet elsewhere, teams may be using agents embedded in Salesforce sandboxes, ServiceNow workflows, personal productivity tools, analytics environments, or locally developed solutions. Some may be configured by vendors. Others may be created by business teams trying to resolve an immediate operational need.

These capabilities may not be malicious or even poorly intended. But if they are not registered, assessed, and governed, they are not part of a managed AI portfolio. They are part of an unmanaged operating reality.


For life sciences organizations, that distinction matters. AI that operates outside the portfolio can introduce uncertainty around data handling, intended use, quality controls, validation expectations, audit readiness, and accountability. More importantly, it can dilute investment in the use cases that have the greatest potential to create measurable value.

The issue is not simply “shadow AI.” It is portfolio discipline.


The Difference Between an AI Inventory and an AI Portfolio


An inventory is a list of tools, pilots, agents, and applications that an organization knows about. A portfolio is a managed set of investments connected to strategy, risk appetite, operating priorities, and measurable outcomes.


Many organizations have begun to establish AI intake processes. A team submits a use case. It identifies the business owner, expected benefit, data sources, technology needs, and potential risks. A committee reviews the proposal and determines whether it should move forward.


This is an important foundation. But an intake process alone does not create portfolio discipline.


A portfolio requires ongoing management. It needs a way to identify what is actually in use, not only what was approved. It needs clear criteria for deciding which use cases should advance, pause, be redesigned, or stop. It needs ownership that extends beyond initial approval. And it needs a practical mechanism to retire initiatives that no longer have a valid business case.


Without these disciplines, organizations can develop what might be called governance theater: visible meetings, documented templates, and established review forums that provide a sense of control without producing a complete view of AI activity.

The result is often a portfolio that looks smaller, more orderly, and more mature than it really is.


Why Unregistered AI Creates a Life Sciences Risk


In a regulated environment, the risks associated with unregistered AI are not limited to cybersecurity or technical architecture. They extend into quality, compliance confidence, operational consistency, and inspection readiness.


Consider a few common scenarios:


  • A commercial team uses an AI-enabled tool to draft field materials or summarize healthcare professional feedback, but the workflow has not been assessed for content review requirements or appropriate data handling.

  • A regulatory operations team implements an agent to organize submission-related content, but its role in the process, output review expectations, and audit trail requirements are unclear.

  • A clinical operations group uses a locally configured model to summarize site communications or identify enrollment trends, but the underlying data sources and human oversight controls are not documented.

  • A quality team adopts an AI feature inside an enterprise platform without a defined intended use, test evidence, or a clear understanding of how the feature affects controlled processes.

 

In each case, the technology may appear useful. It may even produce a short-term productivity gain. But if its use is not visible to the right functions, the organization cannot confidently assess whether the process is fit for purpose.


This is especially important when AI-generated outputs influence regulated decisions, quality records, patient-facing information, product communications, or data used to support clinical, safety, or regulatory activities. The level of control should be proportionate to the use case and its impact. That requires the organization to know the use case exists.


A lack of visibility also complicates audit readiness. When teams cannot readily explain which AI capabilities are in use, what data they access, who owns them, how outputs are reviewed, and what controls apply, the organization may struggle to demonstrate a consistent and defensible governance approach.


The First Step Is Discovery, Not Another Intake Form


When leaders recognize that AI activity may be occurring outside the approved portfolio, the instinct is often to strengthen the intake process. That can help going forward, but it does not solve the immediate problem.


First, organizations need discovery.


Discovery should be designed as an operational exercise rather than a compliance campaign. If employees believe the goal is to identify and punish unapproved experimentation, they may become less forthcoming. The objective should be to understand the current environment, identify meaningful risks and opportunities, and bring valuable work into an appropriate governance model.


A practical discovery effort typically combines several sources of insight:


  • Technology and vendor review: Identify AI capabilities already enabled within enterprise platforms, including features that may have been activated through existing licenses or vendor updates.

  • Business-function interviews: Engage leaders and practitioners across clinical, regulatory, quality, safety, manufacturing, supply chain, medical affairs, commercial, and corporate functions to understand how AI is actually being used.

  • Workflow mapping: Examine high-volume or high-friction processes where teams may have adopted informal tools to reduce manual work.

  • Data and access analysis: Assess where sensitive, personal, proprietary, or regulated data may be entering AI-enabled systems.

  • Pilot and innovation tracking: Reconcile formal pilots, proof-of-concepts, vendor demonstrations, citizen-development efforts, and local automation initiatives.


The output should not be a static spreadsheet. It should be a living AI use-case register that captures the information needed for decisions: business purpose, process owner, user population, data types, system environment, intended use, level of human review, risk classification, controls, value hypothesis, and lifecycle status.


This creates a more honest starting point. It also provides the basis for rational portfolio decisions.


Kill Criteria Are a Sign of Maturity, Not Resistance to Innovation


Once an organization has better visibility, it must decide what should remain in the portfolio.


This is where many AI programs lose discipline. New ideas are easy to approve in principle. They are much harder to stop once a sponsor, team, vendor, or budget line is attached. Over time, the organization accumulates pilots that have not scaled, agents with no clear owner, and use cases that continue to consume attention without demonstrating material value.


A disciplined AI portfolio needs clear kill criteria.


Kill criteria do not mean that every use case must produce immediate financial return. Early-stage experimentation has a legitimate role, particularly where the organization is learning about new technologies or testing a high-potential hypothesis. However, experimentation should have defined decision points and evidence expectations.


Useful criteria may include:


  • The use case does not address a documented business, quality, compliance, or operational need.

  • The required data is unavailable, unreliable, or inappropriate for the proposed purpose.

  • The risk profile cannot be managed with reasonable controls.

  • The workflow lacks a committed business owner or accountable process owner.

  • User adoption remains low despite targeted enablement and workflow redesign.

  • The solution does not demonstrate meaningful improvement in cycle time, error reduction, decision quality, capacity, or compliance confidence.

  • The capability duplicates another approved solution or creates unnecessary technology fragmentation.

  • The organization cannot establish sufficient human oversight, traceability, or quality review for the intended use.


The key is to define these criteria before enthusiasm becomes investment inertia.


Every approved AI use case should also have a time-bound lifecycle. If it remains in pilot status indefinitely, it is not a pilot; it is an unmanaged exception. Establishing review dates, success measures, and hard expiration points encourages teams to generate evidence, make decisions, and either scale, redesign, or retire the work.


Adoption Must Be Designed Into the Use Case


Even a well-governed AI solution will not create value if people do not use it in the intended workflow.


This is why AI adoption should not be treated as a final communications step after a technology decision has been made. Adoption begins when the use case is defined. Teams need to understand whose work will change, what decisions will be supported, what remains subject to human judgment, and how the new process will improve the user experience without weakening quality.


In life sciences, the most successful AI implementations tend to focus on specific workflow moments: reducing time spent locating approved information, preparing first drafts for expert review, identifying data anomalies for investigation, organizing evidence for a decision, or streamlining recurring administrative activities.


The AI should be positioned as part of a controlled process, not as an independent decision-maker.


Practical adoption planning includes role-based training, clear standard operating procedures where appropriate, defined escalation paths, user feedback mechanisms, and transparent guidance on when AI outputs can be used, reviewed, modified, or rejected. Leaders should also measure adoption behavior, not merely deployment. A solution that is technically available but consistently bypassed is providing useful feedback: the workflow, controls, user experience, or value proposition needs attention.


Measure Outcomes That Matter to the Business and the Patient


AI portfolios should be evaluated using measures that leaders and users can understand. Technical metrics are important, but they are not sufficient.


For a life sciences organization, outcome measures may include reduced document-processing cycle times, fewer manual handoffs, improved right-first-time quality, decreased rework, faster issue identification, more consistent execution, improved traceability, or greater capacity for scientific and operational teams to focus on higher-value work.


The right measure depends on the use case. A quality-focused AI capability may be evaluated through investigation turnaround time, deviation-trend visibility, review completeness, or audit-readiness indicators. A clinical operations use case may focus on site-support responsiveness, data query resolution, enrollment planning accuracy, or coordinator burden. A regulatory use case may prioritize content retrieval time, authoring efficiency, review-cycle duration, and adherence to approved processes.


Not every benefit will be immediately quantifiable. But every use case should have a clear hypothesis about how it will improve a meaningful outcome. That hypothesis should be tested with baseline measures and reviewed at defined intervals.


This approach helps organizations move beyond a general narrative of innovation. It creates an evidence-based view of which AI investments are genuinely improving performance and which require adjustment.


Build a Portfolio That Can Be Trusted


The goal is not to eliminate experimentation or centralize every decision. It is to create enough visibility, accountability, and discipline that innovation can move with confidence.


A trusted AI portfolio has a clear inventory of active capabilities. It distinguishes between exploration, pilot, scaled deployment, and retirement. It connects use cases to business priorities. It applies proportionate controls based on risk and intended use. It includes clear ownership, measurable outcomes, and defined exit criteria. And it treats adoption as a core part of execution rather than an afterthought.


Organizations do not need to choose between innovation and governance. In fact, disciplined governance is what allows innovation to scale safely.


When every team can create or activate an AI agent, the portfolio is no longer limited to what appears on a steering committee agenda. Leaders must understand what is actually operating across the enterprise, decide what deserves investment, and create the conditions for users to adopt AI in ways that strengthen quality, compliance confidence, and performance.


The question is not whether AI is already running beyond the visible portfolio.


The question is whether the organization is ready to manage it.


About the Author

Rishi Dixit is Head of Strategic Solutions, Innovation & Partnerships at Atlas where he helps build new advisory practices, partnerships, products, and solutions that solve complex business challenges. With more than 30 years of experience across life sciences, technology, consumer goods, and global business, Rishi has led large-scale transformations across people, digital, and organizational change.


He is a portfolio, program, and product management expert, change practitioner, mentor, and AI enthusiast who believes the hardest challenges are rarely just technology problems. They are people problems shaped by technology, process, and change.

 
 
 

Comments


bottom of page