Close

New Research from CDW on Workplace Friction

Learn how IT leaders are working to build a frictionless enterprise.

Jul 24 2026
Artificial Intelligence

From Governance to Results: Building Enterprise AI in 90 Days

Federal agencies can move from fragmented experiments to durable, compliant artificial intelligence without stalling on speed.

The challenges of integrating artificial intelligence into federal agencies often occur not during a pilot program, but afterwards. As second and third pilots arrive, each tends to bring different owners, tools and vendors, until the IT and program teams responsible for modernizing agency systems find themselves managing sprawl instead of delivering on mission.

That was the central theme of Asim Iqbal and Aaron Chapman’s CDW Government panel at the AWS Summit Washington, D.C. Iqbal and Chapman argued that governance is what turns AI experiments into durable, compliant results, as well as what keeps agencies aligned with Office of Management and Budget (OMB) direction as they scale.

Left unmanaged, AI adoption across an agency tends to produce well-intentioned chaos. Program offices select different models, build separate approval paths, and by the third pilot, the agency is fighting fragmentation and duplicative spending rather than compounding gains.

CDW’s proposed fix: Build one front door for every AI use case, with a single intake and renewal process that a CIO or governance board can oversee.

Click the banner below to view CDW’s enterprise AI readiness strategy.

 

CDW’s 90-Day Roadmap to an AI Enterprise

Iqbal and Chapman discussed a framework that sequences the work into three phases meant to balance speed with the control agencies are accountable for:

  • Days 1-30: Strategy and alignment. Identify high-value, mission-aligned use cases, map expected public benefit, secure agency leadership and CIO sponsorship, and assess data readiness and authorization boundaries.
  • Days 31-60: Technical build and policy. Establish a responsible AI framework consistent with the National Institute of Standards and Technology (NIST) AI Risk Management Framework, assign ownership, and set governance policy covering access controls, content filtering and data protection within an authorized environment.
  • Days 61-90: Execution and cadence. Roll out specific capabilities — such as pre-vetted bots or Microsoft Copilot integrations — under continuous monitoring aligned with existing FedRAMP and authorization to operate obligations.

Intake, Risk Tiers and Guardrails

Much of CDW’s session focused on mechanics. Every use case begins with intake: Who owns it? What is its risk tier? Low and moderate risk cases receive lightweight controls and evidence requirements; high-impact AI requires a formal impact assessment, a review and approval process, and an appeals path.

On AWS GovCloud, speakers noted, this maps to Amazon Bedrock guardrails for runtime policy, content filtering and denied topics, along with identity tracing so every call is logged for audit. The described runtime flow is sequential: Verify identity, apply policy, check inputs and outputs against guardrails, restrict retrieval to approved and authorized sources, use only human-approved models, and collect evidence — including cost — on every call.

Designing for Failure

A recurring point was that AI does not replace traditional security or existing federal compliance obligations, but it does add new failure modes. Speakers referenced standards including OMB’s definition of high-impact AI, the NIST AI framework and the OWASP list of AI threats.

CDW recommended that agencies never over-grant authority to a model, and that they keep models on a need-to-know basis consistent with least-privilege principles, maintain full traceability for audit and oversight, and require human review of consequential actions.

The Takeaway

Iqbal and Chapman highlighted cost discipline as especially relevant under tight appropriations. They suggested agencies measure mission outcomes rather than token counts and build in observability from the start.

Overall, Iqbal and Chapman argued that governance functions should be used less as a brake on AI than as the structure that lets agencies avoid fragmentation, satisfy OMB and NIST guidance and deploy with confidence.

Igor Suka/Getty Images