The question comes up every week in different shapes, from executive teams, IT leaders and business owners alike. Sometimes as ambition, sometimes as frustration, often as doubt about the next step. What starts as enthusiasm for a chatbot or a Copilot license gets stuck after a few months on questions nobody had asked beforehand. This article lays out those questions and offers a framework for answering them. For those just getting started with AI, and for those already underway and wondering why the results aren't coming.
:focal())
You might recognize yourself in one of these questions:
"Everyone's talking about AI, but where do I start?"
"We launched a chatbot, but the business isn't seeing any added value."
"How do I keep our data safe when people are using ChatGPT?"
"My employees are already using AI tools… but which ones, and with what data?"
"We have three AI projects running, but nobody knows how they fit together."
"The CISO says no. The business wants speed. IT has no capacity. And the CEO wants results."
"How do I protect my organization against the risks that come with AI?"
"We're looking at Copilot, but is that a tool, a platform, or a strategy?"
Does one or more of these questions sound familiar? Then keep reading.
The AI stack in six layers
AI works in layers. And each layer builds on the one below it. Many organizations invest in a single AI application and forget that underneath it lie four or five more foundations that determine whether it actually works. The result: building on sand.
Layer 1: The models
The large language models themselves: GPT-4o, Claude, Gemini, LLaMA. Closed or open source, powerful, and also a source of bias, hallucinations and intellectual property questions. Pick the wrong model for the wrong use case and things go wrong before you even start.
Layer 2: The API layer
The silent gateway between your organization and the model. Every prompt sent through an external tool sends data out: providers log it, models learn from it, and leaked API keys hand over full access. The layer most organizations overlook.
Layer 3: Developer tooling
The tools developers use to build with AI: GitHub Copilot, Claude Code, Azure AI Foundry, Copilot Studio. Connected in the background to external servers, secrets and business logic included. Without a clear policy, this stays a blind spot.
Layer 4: Agent frameworks and orchestration
The layer where AI acts instead of just answering: MCP, LangChain, AutoGen, multi-agent systems that send emails, create files, kick off processes. At this layer, prompt injection becomes a real attack surface.
Layer 5: The business applications
The layer the business sees: chatbots, email agents, document processing, process automation. With a solid foundation, this delivers value. With shaky layers underneath, it becomes a new silo or a ticking time bomb.
Layer 6: Governance, security and compliance
The framework that keeps everything above it manageable: EU AI Act, GDPR, ISO 42001, acceptable use policies, audit trails, human oversight. Without this layer, everything above stays unmanaged.
"One weak layer carries through to everything above it."
You can have the most beautiful Copilot implementation there is. Without data governance, a shadow AI policy or monitoring, you're building a lovely house on a shaky foundation.

What makes Xylos's approach different?
AI changes something fundamental about how IT projects run. What used to work as separate domains — modern workplace, cloud, security, data, managed services — gets woven by AI into a single whole. An AI agent in the cloud touches security. A Copilot implementation touches data governance and the modern workplace. A process automation project touches both the application layer and the infrastructure. The boundaries between those disciplines are blurring, and many parties get stuck right there.
At Xylos, we've spent years building expertise across all of these domains. Each with its own people, its own maturity, its own architectural choices. Today, AI is bringing our people closer together: the security expert talks to the data architect, the workplace specialist works alongside the developer building agents. That's how we work.
At the same time, we see too many organizations looking only at the top layer. The business applications, the chatbot, the Copilot or Claude license. Anyone who only tackles that top layer forgets the questions that should come first: is your data in order, are your processes mature enough for automation, who manages the risks?
Where do you start as an organization?
Start with a plan. Then choose the tool.
That's why we bring in an AI Program Manager: someone who stands alongside your organization in the short term, maps out the initiatives, names the blind spots, and proposes a program that holds up at every layer. Technically sound, organizationally supported, from leadership down to employees. What remains is a clear starting point, a realistic path, and a partner who understands the full stack.
All the expertise sits under one roof: modern workplace, cloud, security, data, managed services. Locally rooted, with people who understand your context, and a vision that reaches further than the chatbot or the optimized email.
"AI deserves a program-level approach."
Is your organization ready to address the full AI stack? I'd love to talk about it.
About the author
[Peter Verrykt ](https://be.linkedin.com/in/peter-verrykt)is Business Unit Lead Data & AI at Xylos and helps organizations turn data into concrete business value. He helps companies look beyond technical implementations and uses data and AI as a foundation for better decisions, greater agility and sustainable growth.