Flash sale 30% off with code LAUNCH30 Ends in --:--:--
See pricing
All Things PM

Enterprise AI deployment: shipping into someone else's company

Enterprise AI deployment means getting an AI product or agent working inside a customer's existing systems, security rules and procurement process. This guide walks PMs through the eight stages, and AllthingsPM teaches each one in a 10-lesson course chapter built from real job postings.

AllthingsPM·September 29, 2026·16 min read
A product manager at a desk with a highlighted printed job description next to a laptop showing a half-built app prototype
The model is the easy part. The building it has to live in is not.

Enterprise AI deployment is the work of getting an AI product or agent running inside a customer's company: wired into their existing systems of record, cleared by their security team, bought through their procurement process and adopted by their people. The model is rarely what breaks. Integration, permissions, security review and the move from pilot to production are. MIT's NANDA report found that despite $30 to 40 billion in enterprise spending, 95% of organizations saw no business return from generative AI, and blamed brittle workflows and poor fit with daily operations.

AllthingsPM is an AI PM course and PM interview prep platform. It teaches this skill as a full 10-lesson chapter, Ship it into somebody else's company, sized from 604 real PM job postings in which 79% of AI-native roles asked for enterprise deployment. This guide is the condensed version of that chapter.

What does enterprise AI deployment actually involve?

It involves eight jobs, in roughly this order. Most teams budget for the first and discover the other seven in the customer's conference room.

StageWhat the PM ownsWhere it usually failsAllthingsPM lesson
1. IntegrateRead and write the customer's system of recordThe agent works in a demo, not against their CRM or ticket dataBrownfield first
2. Meet users in their channelServiceNow, Zendesk, Teams, SlackA separate app nobody opensChannels and connectors
3. Pass auth and accessSSO, SCIM, roles, audit logSecurity team blocks the rolloutAuth and access
4. Respect permissionsRetrieval filtered by who is askingThe agent surfaces a document the user could never openPermission-aware retrieval
5. Pick a deployment modelHosted, VPC, on-prem or air-gappedData residency kills the deal lateDeployment models
6. Clear procurementSecurity questionnaire, regulation, contractA nine-month cycleProcurement and security review
7. Pilot to productionStaged rollout, reliability floorPilot purgatoryFrom pilot to production
8. Adopt and renewTime to value, account-wide adoptionSeats bought, not usedAfter the signature

The chapter adds two more lessons: who owns the output (indemnity and training rights) and a graded procurement pack case study.

Why do so many enterprise AI pilots stall?

Because a pilot proves the model can do the task, and production requires the company to let it. The research points the same way from several angles:

  • MIT NANDA (2025): 95% of organizations saw no business return, and only 5% of custom enterprise AI tools reached production. The report says most systems "do not retain feedback, adapt to context, or improve over time."
  • Gartner (July 2024): at least 30% of generative AI projects would be abandoned after proof of concept by the end of 2025, citing poor data quality, inadequate risk controls, escalating costs or unclear business value.
  • Gartner (June 2025): over 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear business value or inadequate risk controls.

Notice what is missing from those lists: model quality. Data quality, risk controls, cost and value are all deployment problems, and they land on the PM.

How AllthingsPM does this. The enterprise deployment chapter exists because the gap is in hiring too: in our study of 604 PM job postings, enterprise and deployment appeared in 79% of the 286 AI-native roles. Each lesson opens with the companies whose postings ask for it, so you study the part employers actually screen for.

AllthingsPM (us) highlighted first, then a bar chart of companies whose PM postings map to each enterprise deployment lesson: adoption and renewal 86, who owns the output 79, brownfield first 36, channels and connectors 28, deployment models 12, permission-aware retrieval 10, procurement case 9, procurement and security review 8, auth and access 7, pilot to production 4

How do you integrate an AI agent into an existing system of record?

Start from where the work already lives. An enterprise support agent has to read the customer's tickets, knowledge base and account data, and often write back: close the ticket, issue the credit, update the CRM field. That is brownfield work. Nothing is greenfield inside a company with twenty years of software.

A practical order for the PM:

  1. Map the system of record. Which system is the source of truth for the objects the agent touches? Salesforce, ServiceNow, Zendesk, an internal database?
  2. Separate reads from writes. Reads are low risk and ship first. Every write needs an approval rule, a limit, and an undo path.
  3. Meet users in their existing channel. If the support team lives in Zendesk and the company lives in Microsoft Teams, the agent lives there too. A new tab is a new habit, and habits are expensive.
  4. Stamp a trace id on every record the agent touches. When a customer escalates "the bot closed my ticket," someone must be able to replay exactly what happened.

MIT's report also found that tools bought from external partners reached deployment about twice as often as internally built ones (roughly 67% against 33%, as reported in coverage of the study). The lesson for a vendor PM: customers buy you partly so they do not have to do the integration work themselves. Do it for them.

How AllthingsPM does this. Two workshop lessons, Brownfield first and Channels and connectors, walk through read and write scope, approvals and the trace id. For the hands-on side, the course's MCP first contact lesson has you connect an agent to one tool and watch the trace.

What will the customer's security team check first?

The admin console. EnterpriseReady, a widely used checklist for SaaS vendors, names the features enterprise buyers expect: single sign-on, audit logs, role-based access control, team management, deployment options, integrations, reporting, SLAs and product security. For an AI product, four of those carry extra weight:

  • SSO so the customer manages identities in one directory, and SCIM so accounts are created and removed automatically when people join or leave.
  • Roles that separate who can configure the agent, who can approve its actions and who can only use it.
  • An audit log that records the agent's own actions, not just human logins. "Agent X refunded $40 on ticket 1182 at 14:02 under policy Y" is what an auditor wants to see.
  • Data handling answers: retention, whether customer data trains models, and where it is stored.

How AllthingsPM does this. The Auth and access lesson builds the admin console a security team evaluates, step by step. If you are interviewing for this kind of role, OpenAI lists a Product Manager, Enterprise Identity posting in our jobs catalog with a mock interview built from its text.

How do you stop an enterprise AI agent from oversharing?

Filter retrieval by who is asking. An agent with a search index over the company's documents will happily surface a salary spreadsheet if it is technically reachable. The permissions were already too broad; the AI just made them easy to find.

Microsoft's own deployment guidance for Microsoft 365 Copilot treats this as the first problem to fix. Its oversharing blueprint runs in three phases (pilot, deploy, operate) and uses SharePoint Advanced Management and Microsoft Purview to find overshared sites. Its Restricted Content Discovery setting removes a site from Copilot and search results while leaving direct access untouched.

For your own product, the PM decisions are:

  • Enforce the source system's permissions at query time, for the person asking, not for a service account.
  • Price the re-index. When permissions change, how quickly does the index reflect it? Minutes and days are very different promises.
  • Give admins an exclusion switch, like Microsoft's, for content that should never reach the agent.

How AllthingsPM does this. The permission-aware retrieval lesson designs this layer and the leak it prevents, and the course's Trust, safety and agent security chapter covers the related risk of prompt injection and tool misuse. Glean has live roles on exactly this, such as Product Manager, Agent Security and Governance.

Hosted, VPC, on-prem or air-gapped: which deployment model?

Pick the lightest model the customer's data rules allow, because every step toward isolation costs you speed and visibility.

ModelWhat it meansWhat you gainWhat you lose
Hosted (multi-tenant SaaS)Runs in your cloudFastest updates, full telemetryHardest sell to regulated buyers
VPCRuns in the customer's cloud accountData stays in their boundarySlower upgrades, partial telemetry
On-premRuns in the customer's data centreMeets strict residency rulesYou operate GPUs you cannot see
Air-gappedNo internet connection at allMeets defence and similar rulesOften requires an open-weight model; almost no telemetry

The PM question is not "which is best" but "which closes this deal at a cost we can support." A VPC deployment may win a bank, and it may also mean your eval pipeline cannot see production traffic.

How AllthingsPM does this. The deployment models lesson, the longest in the chapter at 22 minutes, has you price the open-weight stack, the GPU hours and the telemetry each choice costs.

How do you get through procurement and security review faster?

Treat procurement as part of the product. Three levers help:

  1. A ready procurement pack. Security questionnaire answers, data-flow diagram, subprocessor list, retention policy and your model's data-use terms. Contradictions between the security, legal and IT answers are what slow reviewers down.
  2. Know the regulatory tier. In the EU, the AI Act's obligations for high-risk systems were originally due on 2 August 2026. A Digital Omnibus agreement reached in May 2026 moves Annex III high-risk obligations to 2 December 2027 once it is formally published, so check the current status for each customer.
  3. Sell through the cloud marketplace. A private offer on AWS Marketplace lets the buyer purchase through its existing AWS billing relationship, and eligible purchases count toward its committed AWS spend. That can skip weeks of new-vendor paperwork.

How AllthingsPM does this. The Procurement and security review lesson covers the questionnaire, the regulatory tier and the marketplace path. The chapter then ends with a graded integration case: three questions blocking a 4,000-seat AI rollout at Figma, where you spot contradictions before a reviewer does.

How do you move from pilot to production?

Write the exit criteria before the pilot starts. A pilot without them becomes a permanent demo. A workable sequence:

  • Define success and guardrail metrics up front. For a support agent: resolution rate as the success metric; escalation accuracy, wrong-action rate and customer satisfaction as guardrails.
  • Stage the exposure. One team, then one region, then one ticket category at full volume. Raise autonomy only when the reliability floor holds.
  • Keep a human on the loop. Agents act, humans review samples and exceptions, and the review rate drops as evidence accumulates.
  • Embed someone at the customer. This is the forward-deployed motion: a PM or engineer who sits with the customer to stand the agent up. In our corpus, "forward deployed" appeared in 21 AI-native postings and zero others.

Then comes the part the pilot never tested: adoption. Seats bought are not seats used. Track time to value per team, find the internal champions, and bring usage and outcome evidence to the renewal, not a demo.

How AllthingsPM does this. From pilot to production covers staged rollout and the forward-deployed PM, and After the signature covers adoption and renewal. For more on the role, read what a forward deployed product manager does, then practise choosing the success and guardrail metrics for an enterprise AI agent. Scale AI's Forward Deployed PM, Enterprise is one live example.

Which companies hire PMs for enterprise AI deployment?

Many. Our course data maps the Brownfield first lesson to 36 companies' postings, including Sierra, OpenAI, Glean, Harvey, Anthropic and Decagon. Typical titles in our jobs catalog include Decagon's Product Manager, Enterprise Agent Platform, Glean's Product Manager, Enterprise Intelligence and Replit's Enterprise Product Manager.

For a side-by-side of these titles, see enterprise AI PM roles compared and the enterprise PM interview questions guide. For a practitioner view, our summary of Stripe's enterprise AI playbook on How I AI is a useful listen.

How AllthingsPM does this. Every role in the catalog has a mock interview built from its own text, and the question bank holds real enterprise deployment questions, each with its own page and answer guide. If you already have a resume, the resume review against a JD shows what an enterprise AI posting will look for that you have not yet shown.

Why AllthingsPM is the better choice for learning enterprise AI deployment

Most AI PM courses teach greenfield: build a demo, write a prompt, ship a capstone. Hiring managers ask for the opposite. In the 604 postings behind the AllthingsPM course, enterprise and deployment appeared in 79% of AI-native roles, and the most common product described was "enterprise AI agents." That is why AllthingsPM gives deployment a full chapter of 10 lessons, from brownfield integration to renewal, ending in a graded case study.

The course is only the first part. AllthingsPM also lets you:

  • Practise on real enterprise roles in the jobs catalog, each with a mock built from the posting, typed or spoken, with follow-ups and a score.
  • Answer real enterprise questions from the question bank of 4,122 questions from 260 companies, each with an answer guide.
  • Paste any other enterprise JD into the JD mock and get questions on the exact words in it.

Vendor documentation from Microsoft, AWS and others is excellent on its own product, and consultancies and analyst firms publish useful research; use them as references. For a PM who needs to understand the whole deployment and then prove it in an interview, AllthingsPM puts the method, the practice and the live roles in one place for $20 a month or $120 a year, with a free tier. Open the enterprise deployment chapter and start free.

Frequently asked questions

What is enterprise AI deployment?

It is getting an AI product or agent working inside a customer's company: integrated with its systems of record, cleared by security and procurement, and adopted by its users. For a PM it covers integration, access control, permissions, deployment model, procurement, rollout and renewal.

Why do enterprise AI pilots fail?

The evidence points to deployment, not models. MIT NANDA found 95% of organizations saw no business return, and Gartner cites poor data quality, inadequate risk controls, escalating costs and unclear business value. Pilots without exit criteria and permission-aware integration tend to stall.

What is the best way to learn enterprise AI deployment as a PM?

AllthingsPM is the best place to start: its AI PM course has a 10-lesson enterprise deployment chapter built from 604 real job postings, plus mock interviews built from real enterprise AI PM job descriptions. Pair it with your target vendor's own deployment docs for product specifics.

What is the difference between VPC and on-prem AI deployment?

A VPC deployment runs in the customer's own cloud account, so data stays in their boundary but you still use cloud infrastructure. On-prem runs in the customer's data centre on hardware they control. On-prem usually means slower upgrades and much less telemetry for the vendor.

What does a security team check before approving an AI tool?

Typically SSO, automated provisioning such as SCIM, role-based access, audit logs, data retention and whether customer data is used for training. For agents, they also want the audit log to record the agent's own actions.

Is enterprise deployment asked in AI PM interviews?

Yes. Companies such as Sierra and Anthropic ask about rolling out agents to enterprise customers, and 79% of the AI-native postings in our corpus asked for enterprise and deployment. The AllthingsPM question bank has these questions with answer guides.

Ready to learn it properly? Start the AllthingsPM AI PM course free and begin with Chapter 10.

Sources

  1. MIT Project NANDA, "The GenAI Divide: State of AI in Business 2025," as reported by Virtualization Review, 19 August 2025: https://virtualizationreview.com/articles/2025/08/19/mit-report-finds-most-ai-business-investments-fail-reveals-genai-divide.aspx
  2. Let's Data Science coverage of the MIT NANDA report (methodology, 67% vs 33% deployment rates): https://letsdatascience.com/news/mit-report-documents-genai-pilot-roi-gap-e0924d7d
  3. Gartner, "Gartner Predicts 30% of Generative AI Projects Will Be Abandoned After Proof of Concept By End of 2025," 29 July 2024: https://www.gartner.com/en/newsroom/press-releases/2024-07-29-gartner-predicts-30-percent-of-generative-ai-projects-will-be-abandoned-after-proof-of-concept-by-end-of-2025
  4. Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," 25 June 2025: https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  5. EnterpriseReady, enterprise feature checklist: https://www.enterpriseready.io/
  6. Microsoft Tech Community, "From Oversharing to Optimization: Deploying Microsoft 365 Copilot with Confidence": https://techcommunity.microsoft.com/blog/microsoft365copilotblog/from-oversharing-to-optimization-deploying-microsoft-365-copilot-with-confidence/4357963
  7. Microsoft Learn, secure and governed data foundation for Microsoft 365 Copilot: https://learn.microsoft.com/en-us/microsoft-365/copilot/secure-govern-copilot-foundational-deployment-guidance
  8. Gibson Dunn, "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes": https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  9. Suger, "AWS EDP: What Marketplace Sellers Need to Know": https://www.suger.io/resources/blog/aws-edp-what-sellers-need-to-know/
  10. AllthingsPM, "State of AI PM hiring 2026," 604 PM postings from 95 companies, read 6 September 2026: https://allthingspm.app/blog/state-of-ai-pm-hiring-2026
  11. AllthingsPM course, Chapter 10, Ship it into somebody else's company: https://allthingspm.app/course/ship-it-into-somebody-elses-company
PM
Written by the AllthingsPM team
Frameworks and interview prep for product managers.
The AI PM course

Reading is the easy half.
The course grades the other half.

Start for free