Why a flat figure without context is not sound
AI automations differ in process scope, case variation, existing systems, information quality, permitted actions and the consequences of error. An assistant for internal drafts needs a different frame from an agent that changes data or prepares external communication.
A credible assessment therefore begins with the actual workflow and does not invent a market range.
Business prerequisites before estimating effort
The objective, current workflow, participants, case volume, exceptions and desired outcome need to be understandable. A business owner must also be available to provide examples and assess results.
- bounded use case
- documented current process
- representative normal and exceptional cases
- named accountability
- reviewable value and risk criteria
Work packages that determine effort
Delivery involves more than a model or interface. Process analysis, data preparation, permissions, integration, quality tests, security measures, documentation and organisational adoption are separate work packages.
The more systems are connected, sensitive information is handled or consequential actions are enabled, the more careful design and validation need to be.
- analysis and solution design
- data and knowledge preparation
- interfaces and workflow
- permissions and human oversight
- testing, documentation and adoption
Ongoing operation belongs in the overall view
After the pilot, work remains for business maintenance, security and quality review, changes to sources and systems, user support and incident handling. Usage-dependent provider or model costs may also apply.
NIST and BSI view risk across the lifecycle. The assessment therefore covers not only an initial build but also the capacity to operate responsibly.
How to create a sound basis for decision
An initial assessment organises the desired effect, technical dependencies, risks and missing evidence. A bounded pilot can then be planned with clear deliverables and decision gates.
Only results from realistic cases show whether scaling, simplification or stopping makes sense. Expected benefits remain hypotheses until measured against the documented baseline.
Source note
These work packages are a practical structure, not an offer or price commitment. Lifecycle and risk perspectives follow NIST and BSI; primary sources reviewed on 11 August 2026.
Primary sources
Official sources, editorially checked on 11 August 2026.
- AI Risk Management FrameworkNational Institute of Standards and Technology (NIST)
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)National Institute of Standards and Technology (NIST)
- Generative AI Models: Opportunities and Risks for Industry and AuthoritiesBundesamt für Sicherheit in der Informationstechnik (BSI)


