Business Objectives First: Rethinking How Enterprises Choose AI Models

Vikrant Modi
Vikrant Modi
August 6, 2026
.
read

Every week, there’s a new model launch with new capabilities. Virtually everyone is captivated by these advancements. Leaders want to join the hype bandwagon and try their hands at whatever is new. What can this model do for me?  

This is not the right way to approach Enterprise AI. Evidence suggests that this “model-first” position is correlated with high abandonment rates after proof of concept (PoC). It doesn’t bode well, neither from a cost nor a data perspective.  

Gartner reports that at least half of generative AI projects were abandoned after PoC due to these very issues. It’s clear that the capabilities of the model aren’t dictating success in enterprises. The failure is organizational and operational.  

In the context of financial institutions, preparatory steps are non-negotiable. Most meaningful deployments are “decision systems” that affect credit, fraud outcomes, customer treatment, market risk posture, regulatory compliance, and (in aggregate) financial stability.  

AI adoption without appropriate controls can amplify financial-sector vulnerabilities. In this article, we argue for a reversal of the typical selection sequence: enterprises should first define business objectives, decision rights, and constraints, and only then select the minimum sufficient model architecture that can meet those requirements.  

Why Financial Institutions Should Avoid Model-First AI 

There are three reasons why:  

  1. AI use by institutions can increase vulnerabilities.  

The expansion of Gen AI has broadened the use case perimeter in FIs. AI can solve for credit risk assessment, customer support, information retrieval, fraud detection, document processing, and software development. However, the realized impact depends on dealing with data-related challenges and model deployment. This makes operating guidelines and governance as decisive as the model itself.  

  1. Regulatory expectations in banking are structurally incompatible with unconstrained model-first experimentation.  

When it comes to compliance, model risk management is not just validation, but also sound development/implementation/use along with governance and board/senior management oversight; it also explicitly calls out the need to understand model limitations and to manage models used incorrectly or outside their design intent.  

  1. Complex ML techniques introduce challenges in decision audibility.  

Advanced models are black-box decision makers, where the models cannot explain the decision that they've made. The implication is that model capability does not always equal deployability. It is a joint function of business objective, control environment, supervisory expectations, and operational constraints.  

The Cost of Model-First Thinking 

The cost of choosing a model before defining your objective are compounded. They hit you on four fronts: strategic, operational, security, and systemic. 

The PoC Graveyard and the Illusion of Progress 

Model-first initiatives tend to optimize for impressive illustrations rather than measurable business outcomes. A team picks the most capable model on a benchmark, builds something that looks great in a boardroom, and then discovers that the data isn't production-ready, the controls don't exist, and the costs don't pencil out.  

This is how you end up in the PoC graveyard. Broader strategic commentary reinforces the point: leading with a model can put the technology ahead of strategy and value creation. The demo creates an illusion of progress; the organizational readiness gap creates the reality of failure. 

Security Externalities Unique to GenAI Deployments 

Model-first GenAI deployments frequently fail to account for a new and expanding threat surface. Prompt injection, data exfiltration via tool-using agents, training data poisoning, insecure output handling, and supply-chain dependencies are all high risks.  

If a leader begins by choosing a model because it is capable and only later asks what controls exist for data leakage and injection attacks, the enterprise can incur security costs and residual risk that exceed whatever business value the model was supposed to deliver. 

Systemic Risk from Concentration and Correlated Behavior 

When a handful of providers dominate AI hardware, cloud infrastructure, and foundation models, financial institutions develop correlated dependencies. This reliance is linked to financial-stability concerns. If many firms converge on the same "best" model benchmark, individually rational choices become systemically fragile when widely replicated.  

India's central bank has raised similar concerns about concentration risk from a small number of AI technology providers. Model-first adoption, where everyone chases the same leaderboard winner, is a textbook collective action problem. 

A Framework for Business-Objective-Led AI Selection   

A "reverse-engineered" approach flips the sequence by putting business objectives first. A practical, board-ready framework has six stages:  

  1. Business objective definition. Define a single measurable outcome tied to a P&L, risk, or service KPI, with a baseline, a time horizon, and clarity on who owns the outcome. AI pilots fail when the value is unclear. Objective clarity is the leading indicator of scaling potential. 
  2. Decision and constraint mapping. Identify the specific decision or workflow the system will influence and define the constraints around it: latency, auditability, privacy, and human oversight. Models are judged in context, not in isolation. Supervisory expectations and consumer outcomes shape what "good performance" actually means. 
  3. Risk tiering and governance alignment. Classify the use case by risk tier. Define validation, documentation, monitoring, and escalation requirements proportionate to that tier. Banking supervisors expect model risk discipline, board oversight, independent validation, and a defined model risk appetite — regardless of the model type. 
  4. Data and knowledge readiness. Establish whether the required data exists, is permissible to use, and is operationally accessible. For retrieval-based GenAI, define how the "source of truth" is controlled. Opaque data and insufficient controls complicate validation and create model risk; GenAI adds new integrity challenges, including prompt injection via retrieved content. 
  5. Minimum sufficient model selection. Choose the simplest model class that satisfies the objective and constraints. The hierarchy runs: rules/heuristics → classical ML → constrained ML → deep learning → LLM with retrieval → fine-tuned LLM → agentic systems. Model complexity increases governance burden and risk exposure. Supervisors explicitly link model risk to complexity and uncertainty. 
  6. In-context evaluation and lifecycle controls. Test not only accuracy but also error costs, fairness, security (including red teaming), drift monitoring, and "effective challenge." Define fallback modes. AI systems can amplify vulnerabilities without appropriate oversight — supervisors and standards bodies emphasize continuous monitoring and control. 

The key discipline this forces: model selection becomes a derived decision, not a starting point. AI procurement becomes an exercise in "mission fit," where the mission is defined by measurable business outcomes and bounded risk tolerance. 

How Does this Framework Look in Practice?  

To see how this works in practice, consider three patterns: 

Credit Underwriting

In credit underwriting, if the objective is to reduce time-to-decision or improve risk differentiation, the model must still support specific explanations for adverse actions. There is no special exemption because a complex algorithm is used.  

In this context, "best" often means interpretable or constrained models with strong governance. The Apple Card controversy illustrated how quickly perceived opacity can become a reputational and supervisory event, even when investigations don't ultimately find unlawful discrimination. The ability to explain is part of business viability. 

AML Monitoring  

In AML monitoring, it's important to move beyond purely rules-based transaction monitoring toward more effective outcomes and responsible innovation. An objective-first framing would specify something like: "reduce investigator workload while maintaining or improving true positive yield and regulatory confidence."  

That commonly leads to hybrid approaches — rules plus ML risk scoring plus human-in-the-loop workflows — rather than "deploy an LLM and see what happens. 

Customer Support and Information Retrieval  

In customer support and internal knowledge workflows, the objective might be to reduce average handling time or improve first-contact resolution, but the acceptable error cost is still bounded by conduct risk and mis-selling risk. Here, retrieval-grounded systems and strict human oversight can matter more than parameter count. Deployment controls — not model capability alone — determine business appropriateness. 

Recommendations for Leaders 

Treat model selection as a board-level governance question because its impact extends far beyond what you’d expect from an IT decision.  

Institutionalize a "Minimum Sufficient Model" Principle 

Model risks will rise with complexity and uncertainty, and so will the costs and escalation. Leaders should require explicit justification whenever a more complex model class is proposed. Ostensibly, it seems contrary to innovation. But it is just disciplined capital allocation.  

Integrate AI Security into the Business Case 

GenAI risk profiles include prompt injection, data poisoning, and information integrity threats. Leaders should mandate security threat modeling and adversarial testing as part of the approval criteria for any production deployment, particularly where systems connect to internal tools or customer-facing channels.  

Make Auditability an Explicit Design Requirement  

Where AI outputs affect customer inclusion or exclusion (credit, limits, pricing, fraud blocks) decision auditability is not optional. It is a legitimacy requirement and often a regulatory one. Transparency is a business outcome in its own right. 

Align Model Governance with Emerging Supervisory Norms Across Jurisdictions 

Global standard-setting is converging around fairness, accountability, transparency, and robust governance. Singapore's MAS introduced FEAT principles. India's RBI has published a national framework emphasizing governance, protection, and assurance. Leaders should require that AI programs demonstrate compliance-by-design and supervisory defensibility, with evidence trails and independent challenge. 

Actively Manage Concentration and Resilience Risk in the AI Supply Chain  

Leaders should treat AI vendor strategy as a resilience issue, including exit plans, portability, and multi-vendor options. Model risk guidance calls for disciplined selection and monitoring of vendor models, and contingency planning if a vendor becomes unavailable. 

Adopt a Common Risk Language for Both Predictive AI and GenAI  

Govern, map, measure, manage: provide a structure that lets boards compare a credit underwriting model, an AML risk scoring model, and a GenAI assistant using shared governance logic, while still allowing proportional controls by risk tier. 

Conclusion 

Enterprise AI in financial institutions cannot be deployed credibly through model-first enthusiasm. Model-first approaches systematically underestimate the costs and constraints that determine real-world impact.  

A business-objectives-first approach is the disciplined alternative. It begins by defining the business decision to improve, the measurable outcomes to achieve, and the constraints that cannot be violated.   

Then selects the minimum sufficient model and the lifecycle controls required for safe scale.  

The question for leaders isn't "what can this model do?" It's "what must this decision system achieve, under what constraints, and what is the simplest way to get there responsibly?" 

If you’d like to find an innovative and responsible way to Enterprise AI, connect with our experts at Arya.ai.  

Table of contents

Low-Code AI Automation Starts Here – Try Arya Apex

Access 100+ plug & play AI APIs to streamline manual tasks and improve productivity. A low code solution for enabling seamless automation of processes at scale.
Start Free Trial
arrow up