[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:sr":3,"public-menus:all":38,"post:enterprise-ai-architecture-what-changes-when-ai-enters-a-company:sr":205,"related:post:enterprise-ai-architecture-what-changes-when-ai-enters-a-company:sr:1":3407},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","sr","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":3406},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1563,"featuredImage":1564,"featuredImageAlt":1565,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1566,"publishedAt":1567,"createdAt":1568,"updatedAt":1569,"seoLocalePaths":1570,"categories":1579,"author":1595,"translations":1600},"485","Enterprise AI arhitektura: Šta se menja kada AI uđe u kompaniju","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u003Cp>Arhitektura enterprise AI je arhitektura na nivou cele organizacije koja je potrebna kada AI postane deo stvarnih sistema, podataka, odluka i operacija kompanije. Model je samo jedna komponenta. Kada se AI poveže sa enterprise podacima, identitetima, dozvolama, poslovnim procesima, eksternim provajderima i produkcionim sistemima, arhitektura mora takođe da definiše autoritet nad podacima, granice pristupa, vlasništvo nad rizikom, zavisnosti od provajdera, proverljivost, evaluaciju, kontrolu životnog ciklusa, usklađenost i operativnu odgovornost. Enterprise AI se stoga razlikuje i od pojedinačnog AI rešenja i od zajedničke AI platforme: ona koordinira kako se mnogi AI-omogućeni sistemi uklapaju u širu organizaciju.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Direktan odgovor\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>Šta se menja kada AI uđe u kompaniju?\u003C\u002Fstrong> Postojeće odgovornosti enterprise arhitekture se šire tako da uključuju probabilističko ponašanje modela, nove tokove podataka, pretragu i utemeljenje, zavisnosti od modela\u002Fprovajdera, AI-specifičnu evaluaciju, autoritet agenata\u002Falata, životni ciklus modela i promptova, upravljanje AI rizikom, obaveze transparentnosti i nove operativne načine otkaza. Arhitektura mora da poveže ove aspekte sa postojećim strukturama kompanije za identitet, bezbednost, podatke, nabavku, isporuku i upravljanje, umesto da stvori paralelni „AI univerzum“.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Enterprise AI nije „veći chatbot“\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Chatbot može biti korisnički interfejs. Enterprise AI arhitektura je sistem granica iza njega: kojim podacima AI sme da pristupi, koji izvor je merodavan, ko sme da koristi koju mogućnost, da li eksterni provajderi smeju da prime podatke, koje radnje agent sme da izvrši, kako se izlazi evaluiraju, šta mora da se loguje, ko je vlasnik incidenata i kako se promene odobravaju i vraćaju.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Napomena o aktuelnim izvorima — 8. oktobar 2026.\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Arhitektonski principi u ovom članku imaju za cilj da budu stabilni. Regulativa, standardi i mogućnosti provajdera zavise od verzije. ISO\u002FIEC 42001:2023 i ISO\u002FIEC 23894:2023 su trenutno objavljeni standardi. NIST navodi da se AI RMF 1.0 revidira. Prema trenutnom konsolidovanom tekstu EU AI Act, Uredba se generalno primenjuje od 2. avgusta 2026, dok određene odredbe za visokorizične sisteme imaju kasnije datume primene. Pravna klasifikacija se uvek mora proveriti prema važećem zakonu i konkretnom slučaju upotrebe.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"Sadržaj\">\u003Cstrong class=\"editorjs-toc__title\">Sadržaj\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-6\" class=\"editorjs-toc__link\">Šta enterprise AI arhitektura zaista znači\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-11\" class=\"editorjs-toc__link\">Najjednostavniji primer\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-16\" class=\"editorjs-toc__link\">Gde se jednostavan primer zaustavlja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-19\" class=\"editorjs-toc__link\">Šta se menja u arhitekturi kada AI uđe u preduzeće\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-20\" class=\"editorjs-toc__link\">1. Vlasništvo nad poslom postaje deo tehničke arhitekture\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-23\" class=\"editorjs-toc__link\">2. Pristup podacima nije dovoljan — nadležnost nad podacima mora biti definisana\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-28\" class=\"editorjs-toc__link\">3. Identitet postaje višeslojan\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-32\" class=\"editorjs-toc__link\">4. Dozvole prelaze sa pristupa sadržaju na ovlašćenje za radnju\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-35\" class=\"editorjs-toc__link\">5. AI provajder postaje zavisnost preduzeća\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-39\" class=\"editorjs-toc__link\">6. AI rizik postaje proces životnog ciklusa\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-43\" class=\"editorjs-toc__link\">7. Upravljanje postaje operativni sistem, a ne PDF sa politikama\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-46\" class=\"editorjs-toc__link\">8. Evaluacija postaje proizvodna kontrola\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-50\" class=\"editorjs-toc__link\">9. Vidljivost mora uključivati ponašanje, podatke i kontekst modela\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-53\" class=\"editorjs-toc__link\">10. AI komponente zahtevaju eksplicitno vlasništvo nad životnim ciklusom\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">11. Reagovanje na incidente mora uključivati specifične načine otkaza AI sistema\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-59\" class=\"editorjs-toc__link\">Enterprise AI stvara vlasništvo koje se proteže kroz više funkcija\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-62\" class=\"editorjs-toc__link\">Praktičan model enterprise AI arhitekture\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-66\" class=\"editorjs-toc__link\">Mapirajte enterprise AI kao tokove podataka i ovlašćenja, a ne kao kutije\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-68\" class=\"editorjs-toc__link\">Enterprise mora imati AI inventar pre nego što može da upravlja AI sistemima\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-71\" class=\"editorjs-toc__link\">AI upravljanje i enterprise AI arhitektura su povezani, ali nisu isto\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-73\" class=\"editorjs-toc__link\">Regulativa postaje ulazni parametar arhitekture\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-78\" class=\"editorjs-toc__link\">Nabavka i arhitektura postaju povezane\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-81\" class=\"editorjs-toc__link\">Arhitektura preduzeća odlučuje koliko kontrole nad AI zahtev zaista zahteva\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-84\" class=\"editorjs-toc__link\">AI pretvara upravljanje promenama u problem ponašanja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-87\" class=\"editorjs-toc__link\">AI u preduzeću i dalje zahteva NFR i ADR\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-91\" class=\"editorjs-toc__link\">Arhitektura enterprise AI mora biti povezana sa isporukom\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-94\" class=\"editorjs-toc__link\">Dokazi originalnog projekta: Enterprise Aaasaasa 0.1\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-101\" class=\"editorjs-toc__link\">Podržavajući obrasci implementacije iz šireg rada na platformi\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-104\" class=\"editorjs-toc__link\">Kako se glavni standardi uklapaju\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-107\" class=\"editorjs-toc__link\">Uobičajeni načini neuspeha enterprise AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-109\" class=\"editorjs-toc__link\">Uobičajene zablude\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-111\" class=\"editorjs-toc__link\">Praktičan redosled odlučivanja u arhitekturi enterprise AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-113\" class=\"editorjs-toc__link\">Kontrolna lista za arhitekturu enterprise AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-115\" class=\"editorjs-toc__link\">Granični slučajevi i ograničenja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-120\" class=\"editorjs-toc__link\">Šta bi promenilo ovaj odgovor?\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-123\" class=\"editorjs-toc__link\">Povezano kanonsko znanje\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-130\" class=\"editorjs-toc__link\">Često postavljana pitanja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-132\" class=\"editorjs-toc__link\">Pojmovnik\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-134\" class=\"editorjs-toc__link\">Zaključak\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-138\" class=\"editorjs-toc__link\">Primarni izvori i aktuelne smernice\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-6\">Šta enterprise AI arhitektura zaista znači\u003C\u002Fh2>\n\u003Cp>Enterprise AI arhitektura opisuje kako se AI mogućnosti integrišu u postojeću organizaciju bez kršenja granica koje enterprise sisteme već čine upravljivim: poslovno vlasništvo, identitet, autorizacija, klasifikacija podataka, odgovornost sistema evidencije, upravljanje promenama, nabavka, revizija, kontinuitet i operacije.\u003C\u002Fp>\n\u003Cp>Enterprise arhitekta ne zamenjuje AI Solution Architect ili AI Platform Architect. Enterprise obim postavlja drugačije pitanje: Kako se više AI rešenja i zajedničkih AI mogućnosti uklapaju u ciljnu arhitekturu, politike, pejzaž podataka, model rizika i operativni model kompanije?\u003C\u002Fp>\n\u003Cp>To čini enterprise AI arhitekturu disciplinom koordinacije kroz tehnologiju i organizaciju. Tehnički dobra integracija modela i dalje može biti neuspeh enterprise arhitekture ako stvara tokove podataka u senci, duplira identitet, zaobilazi nabavku, ne može se revidirati, nema vlasnika ili se ne može bezbedno menjati.\u003C\u002Fp>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Arhitektura AI rešenja, platforme i enterprise AI su različiti obimi\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Arhitektura AI rešenja\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Arhitektura AI platforme\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Enterprise AI arhitektura\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Primarni obim\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Primarno pitanje\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Fokus vlasništva\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Uslov uspeha\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-11\">Najjednostavniji primer\u003C\u002Fh2>\n\u003Cp>Kompanija počinje sa jednim internim asistentom za dokumente. Prva verzija pretražuje odobrene dokumente i šalje pronađeni kontekst jezičkom modelu. Na nivou rešenja, to može izgledati jednostavno.\u003C\u002Fp>\n\u003Cp>Zatim drugi tim želi AI za korisničku podršku. Treći želi agenta koji može da ažurira tikete. Finansije žele analizu dokumenata. HR želi internog asistenta. Programeri žele agente za kodiranje. Odjednom kompanija ima nekoliko provajdera, nekoliko klasa podataka, različite korisničke grupe, indekse pretrage koji se preklapaju, različita pravila logovanja, nove dozvole za alate, duplirane tajne i nejasno vlasništvo.\u003C\u002Fp>\n\u003Cp>U tom trenutku, pitanje više nije „Da li asistent radi?“ Enterprise pitanje postaje: Koje su mogućnosti odobrene, ko je njihov vlasnik, koji podaci mogu da pređu koju granicu, kako se identiteti i dozvole sprovode, koji provajderi su prihvatljivi, šta mora da se revidira i kako organizacija može da menja modele ili dobavljače bez gubitka kontrole?\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Od izolovane AI funkcije do enterprise arhitekture\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Izolovan slučaj upotrebe\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Jedan tim povezuje jedan model sa jednim tokom rada i validira lokalnu vrednost.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Pojavljuju se zajedničke zavisnosti\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Više timova zahteva provajdere, pristup modelima, pretragu, identitet, tajne, observabilnost i evaluaciju.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Prelaze se enterprise granice\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">AI dodiruje regulisane podatke, sisteme evidencije, eksterne dobavljače, privilegovane radnje i poslovne odluke.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. Vlasništvo mora postati eksplicitno\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Poslovanje, arhitektura, podaci, bezbednost, pravna služba\u002Fusklađenost, nabavka i operacije moraju imati definisane odgovornosti.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Životni ciklus postaje organizacioni\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Promene modela, promptova, provajdera i novih mogućnosti agenata postaju upravljane promene, a ne lokalne izmene programera.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Arhitektura postaje ponovljiva\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Organizacija uspostavlja obrasce koji se mogu ponovo koristiti, zapise o odlukama, kontrole, izuzetke i kapije validacije za nove AI radne zadatke.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-16\">Gde se jednostavan primer zaustavlja\u003C\u002Fh2>\n\u003Cp>Enterprise arhitektura ne znači da svaka AI komponenta mora biti centralizovana. Neke mogućnosti treba deliti; druge moraju ostati u vlasništvu domena. Finansije, HR, inženjering i korisnička podrška mogu legitimno zahtevati različite granice podataka, provajdere, kriterijume evaluacije i pravila ljudskog odobravanja.\u003C\u002Fp>\n\u003Cp>Enterprise cilj stoga nije jedan model, jedna vektorska baza podataka ili jedan univerzalni asistent. Cilj je koherentna arhitektura sa eksplicitnim varijacijama: zajedničke politike i mogućnosti koje se mogu ponovo koristiti tamo gde smanjuju rizik i dupliranje, plus kontrolisani izuzeci tamo gde se poslovni ili regulatorni zahtevi razlikuju.\u003C\u002Fp>\n\u003Ch2 id=\"section-19\">Šta se menja u arhitekturi kada AI uđe u preduzeće\u003C\u002Fh2>\n\u003Ch3 id=\"section-20\">1. Vlasništvo nad poslom postaje deo tehničke arhitekture\u003C\u002Fh3>\n\u003Cp>Tradicionalne aplikacije već zahtevaju vlasnike iz poslovnog domena. AI čini taj zahtev vidljivijim jer prihvatljivo ponašanje ne može biti definisano samo kroz dostupnost i funkcionalnu ispravnost. Neko mora biti odgovoran za nameravanu upotrebu, neprihvatljivu upotrebu, kvalitet izlaza, put eskalacije i posledice pogrešnih ili neprikladnih rezultata.\u003C\u002Fp>\n\u003Cp>Model tim ne može sam da odluči da li je odgovor prihvatljiv za HR, finansije, pravni sektor ili upotrebu prema klijentima. Arhitektura AI u preduzeću stoga povezuje tehnički dizajn sa eksplicitnom poslovnom sposobnošću, odgovornim vlasnikom, grupom korisnika i kontekstom odlučivanja.\u003C\u002Fp>\n\u003Ch3 id=\"section-23\">2. Pristup podacima nije dovoljan — nadležnost nad podacima mora biti definisana\u003C\u002Fh3>\n\u003Cp>AI u preduzeću često kombinuje operativne baze podataka, dokumente, indekse pretrage, vektorske baze, skladišta podataka, SaaS sisteme i eksterno znanje. Arhitektura mora da razlikuje gde su informacije uskladištene od toga koji je izvor nadležan za datu tvrdnju ili radnju.\u003C\u002Fp>\n\u003Cp>Vektorski indeks može da poboljša pronalaženje, ali ne bi trebalo tiho da postane zvanični sistem evidencije kompanije. Odgovor modela može da sumira ERP zapis, ali ne bi trebalo da zameni ERP kao nadležni izvor. Keširani kontekst može da poboljša latenciju, ali postaje nesiguran kada se promene dozvole ili osnovno poslovno stanje.\u003C\u002Fp>\n\u003Cp>AI u preduzeću stoga zahteva poreklo, svežinu, klasifikaciju izvora, propagaciju autorizacije i pravila poništavanja pored obične integracije podataka.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Pravilo za podatke u preduzeću\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>AI sistem može da transformiše, pronalazi i zaključuje na osnovu podataka preduzeća, a da pritom ne postane nadležan za te podatke.\u003C\u002Fstrong> Arhitektura treba da očuva put nazad do nadležnog izvora kad god slučaj upotrebe zahteva dokaz, verifikaciju ili radnju sa posledicama.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch3 id=\"section-28\">3. Identitet postaje višeslojan\u003C\u002Fh3>\n\u003Cp>AI u preduzeću ima više identiteta nego ljudski korisnik. Zahtev može da uključi identitet korisnika, identitet aplikacije, identitet servisa, identitet agenta, akreditiv provajdera, akreditiv alata i kontekst zakupca ili organizacije.\u003C\u002Fp>\n\u003Cp>Ovi identiteti ne bi trebalo da se spoje u jedan zajednički API ključ. Autorizacija mora da ostane pripisiva ispravnom principalu, a privilegovani alati bi trebalo da dobiju samo ovlašćenje potrebno za trenutnu operaciju.\u003C\u002Fp>\n\u003Cp>Za agentne sisteme ovo postaje posebno važno: model može da predloži radnju, ali runtime mora da odluči da li identitet koji zahteva sme da je izvrši. Sposobnost modela nije autorizacija.\u003C\u002Fp>\n\u003Ch3 id=\"section-32\">4. Dozvole prelaze sa pristupa sadržaju na ovlašćenje za radnju\u003C\u002Fh3>\n\u003Cp>Asistent samo za čitanje uglavnom zahteva kontrolisan pristup informacijama. Agent u preduzeću može da kreira tikete, menja zapise, šalje poruke, pokreće tokove rada ili upravlja eksternim sistemima. To uvodi drugačiju klasu rizika jer sistem može da menja stanje, a ne samo da ga opisuje.\u003C\u002Fp>\n\u003Cp>Arhitektura treba da razdvoji mogućnosti čitanja, pisanja, odobravanja i administracije; definiše tačke uključivanja čoveka u proces tamo gde posledice to opravdavaju; i očuva revizorski trag koji identifikuje šta je zatraženo, šta je odobreno i šta je zaista promenjeno.\u003C\u002Fp>\n\u003Ch3 id=\"section-35\">5. AI provajder postaje zavisnost preduzeća\u003C\u002Fh3>\n\u003Cp>Pozivanje API-ja modela je takođe odnos sa dobavljačem. Arhitektura može da zavisi od dostupnosti provajdera, uslova pružanja usluge, uslova obrade podataka, podržanih regiona, životnog ciklusa modela, kvota, cena, kompatibilnosti API-ja, bezbednosnih kontrola i obaveštenja o promenama.\u003C\u002Fp>\n\u003Cp>To znači da izbor provajdera nije samo odluka o benchmarku. Nabavka, bezbednost, privatnost, pravna revizija, planiranje kontinuiteta i strategija izlaska mogu postati arhitektonski ulazi.\u003C\u002Fp>\n\u003Cp>Apstrakcija provajdera može smanjiti spreganje, ali samo tamo gde su osnovne mogućnosti zaista prenosive. Korišćenje alata, strukturirani izlaz, ograničenja konteksta, multimodalnost, bezbednosne kontrole, fino podešavanje i funkcije hostovanih agenata mogu se značajno razlikovati između provajdera.\u003C\u002Fp>\n\u003Ch3 id=\"section-39\">6. AI rizik postaje proces životnog ciklusa\u003C\u002Fh3>\n\u003Cp>AI rizik se ne završava jednim odobrenjem pre lansiranja. Model, upit, korpus za preuzimanje, skup alata, provajder, korisnička populacija i okolni poslovni proces mogu se promeniti nakon implementacije. Profil rizika se menja sa njima.\u003C\u002Fp>\n\u003Cp>ISO\u002FIEC 23894:2023 eksplicitno se bavi integracijom upravljanja AI rizikom u organizacione aktivnosti i funkcije. NIST AI RMF na sličan način definiše upravljanje rizikom kroz životni ciklus. Enterprise arhitektura bi stoga trebalo da učini reviziju rizika delom promena i operacija, a ne izolovanim dokumentom o usklađenosti.\u003C\u002Fp>\n\u003Cp>Rizik takođe treba da bude proporcionalan. Asistent za sumiranje i autonomni sistem koji menja proizvodne zapise ne bi trebalo da dobiju identične kontrole samo zato što oba koriste LLM.\u003C\u002Fp>\n\u003Ch3 id=\"section-43\">7. Upravljanje postaje operativni sistem, a ne PDF sa politikama\u003C\u002Fh3>\n\u003Cp>ISO\u002FIEC 42001:2023 definiše zahteve za uspostavljanje, implementaciju, održavanje i kontinuirano poboljšanje AI sistema upravljanja. Arhitektonska posledica je važna: upravljanje mora povezati politiku sa stvarnim inventarima, vlasništvom, procesima, kontrolama, dokazima, revizijama i ciklusima poboljšanja.\u003C\u002Fp>\n\u003Cp>Enterprise AI politika koja nije povezana sa odobravanjem provajdera, identitetom, evidentiranjem, upravljanjem promenama, evaluacijom i odgovorom na incidente ima ograničen arhitektonski efekat. Organizaciji su potrebni mehanizmi koji politiku čine sprovodivom ili barem vidljivom.\u003C\u002Fp>\n\u003Ch3 id=\"section-46\">8. Evaluacija postaje proizvodna kontrola\u003C\u002Fh3>\n\u003Cp>Tradicionalno prijemno testiranje pretpostavlja da isti ulaz obično proizvodi isti deterministički rezultat. Generativna AI može biti nedeterministička, osetljiva na kontekst i zavisna od promenljivog spoljnog znanja. Proizvodno prihvatanje stoga zahteva evaluacije specifične za zadatak, regresione skupove i vidljive pragove, a ne samo unit testove.\u003C\u002Fp>\n\u003Cp>Platforma može obezbediti infrastrukturu za evaluaciju koja se može ponovo koristiti, ali enterprise i dalje mora imati vlasništvo nad domenskom osnovnom istinom i kapijama za izdavanje. Centralni AI tim ne može izmisliti tačan odgovor za svaki poslovni domen.\u003C\u002Fp>\n\u003Cp>Promene modela, upita, preuzimanja i alata treba da budu sledljive do dokaza o evaluaciji tamo gde promena može materijalno uticati na ponašanje izlaza.\u003C\u002Fp>\n\u003Ch3 id=\"section-50\">9. Vidljivost mora uključivati ponašanje, podatke i kontekst modela\u003C\u002Fh3>\n\u003Cp>CPU, memorija i stope HTTP grešaka nisu dovoljni za AI radna opterećenja. Proizvodna vidljivost može zahtevati identifikatore modela\u002Fprovajdera, latenciju, korišćenje tokena, troškove, rezultate preuzimanja, pozive alata, ponašanje odbijanja, ocene evaluacije, bezbednosne događaje i klasifikacije kvarova.\u003C\u002Fp>\n\u003Cp>Istovremeno, AI telemetrija može sadržati osetljive podatke. Evidencije upita i odgovora mogu postati skriveno skladište podataka. Enterprise arhitektura stoga mora definisati šta se može evidentirati, kako se rediguje, ko može pristupiti, koliko dugo se čuva i kada se detaljno praćenje mora onemogućiti.\u003C\u002Fp>\n\u003Ch3 id=\"section-53\">10. AI komponente zahtevaju eksplicitno vlasništvo nad životnim ciklusom\u003C\u002Fh3>\n\u003Cp>Modeli mogu biti preimenovani, zamenjeni, ukinuti ili promenjeni od strane provajdera. Modeli za ugrađivanje mogu poništiti strategiju indeksiranja. Šabloni upita i sistemska uputstva mogu promeniti ponašanje. Runtime okruženja i protokoli agenata mogu evoluirati. Spoljni alati mogu promeniti svoje šeme i dozvole.\u003C\u002Fp>\n\u003Cp>Enterprise arhitektura mora da odluči ko detektuje ove promene, ko ih testira, ko ih odobrava, kako se potrošači obaveštavaju, kako funkcioniše vraćanje na prethodno stanje i koji dokazi su potrebni pre nego što nova verzija postane podrazumevana.\u003C\u002Fp>\n\u003Ch3 id=\"section-56\">11. Reagovanje na incidente mora uključivati specifične načine otkaza AI sistema\u003C\u002Fh3>\n\u003Cp>AI incident može biti prekid rada provajdera, curenje podataka, put prompt-injection napada, neuspeh autorizacije, kontaminacija pretrage, neočekivano ponašanje modela, nesigurno izvršavanje alata, skok troškova, zastarelo znanje, regresija evaluacije ili promena u ponašanju eksternog modela.\u003C\u002Fp>\n\u003Cp>Enterprise runbook stoga zahteva više od „restartuj servis“. Može zahtevati onemogućavanje rute modela, opozivanje pristupa alatima, zamrzavanje korpusa, promenu verzije prompta, onemogućavanje sposobnosti agenta, promenu provajdera, eskalaciju do vlasnika domene ili čuvanje tragova za istragu.\u003C\u002Fp>\n\u003Ch2 id=\"section-59\">Enterprise AI stvara vlasništvo koje se proteže kroz više funkcija\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Aspekt\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Tipičan enterprise vlasnik ili saradnik\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Arhitektonsko pitanje\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovna upotreba\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovni vlasnik \u002F vlasnik proizvoda\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koju odluku ili tok posla AI sme da podrži ili automatizuje?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitektura rešenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI \u002F arhitekta rešenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako konkretno radno opterećenje ispunjava svoje funkcionalne i kvalitativne zahteve?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Deljene AI sposobnosti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI platforma \u002F platformski inženjering\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji usluge modela, pretrage, agenata i observabilnosti se pružaju kao ponovo upotrebljive?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Enterprise usklađenost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Enterprise arhitektura\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se AI sistemi uklapaju u ciljnu arhitekturu, standarde, obrasce integracije i organizaciono vlasništvo?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Nadležnost nad podacima\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vlasnik podataka \u002F vlasnik domene\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji podaci su merodavni, aktuelni, dozvoljeni i dovoljno kontrolisani?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Identitet i bezbednost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">IAM \u002F bezbednosna arhitektura\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji identiteti mogu pristupiti kojim podacima i izvršiti koje radnje?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rizik i usklađenost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rizik \u002F pravni \u002F usklađenost \u002F privatnost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koje obaveze, zabranjene upotrebe, kontrole i dokazi se primenjuju na ovaj slučaj upotrebe?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zavisnost od dobavljača\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Nabavka \u002F upravljanje dobavljačima \u002F arhitektura\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji ugovorni, operativni i rizici izlaska proizlaze iz provajdera?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Operacije\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">SRE \u002F operacije \u002F vlasnik platforme\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se sistem prati, podržava, degradira, oporavlja i menja?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Prihvatanje u domeni\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovni\u002Fdomenski specijalisti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta se smatra ispravnim, bezbednim ili korisnim rezultatom u ovoj domeni?\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">RACI tabela sama po sebi nije arhitektura\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Matrice odgovornosti su korisne samo kada su povezane sa stvarnim granicama sistema, odobrenjima, vlasništvom nad podacima, interfejsima, runbook-ovima i procesima promene. Enterprise AI zahteva odgovorno vlasništvo koje se može pratiti do tehničkih kontrola i operativnih radnji.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-62\">Praktičan model enterprise AI arhitekture\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Predloženi slojeviti model\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Sledeći model je praktična sinteza za razmišljanje o enterprise AI arhitekturi. Nije predstavljen kao ISO ili NIST standard. Njegova svrha je da učini granice između organizacija eksplicitnim.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Sloj\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Primarna odgovornost\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovanje i politika\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Odobreni slučajevi upotrebe, odgovorni vlasnici, apetit za rizik, zabranjene upotrebe, ljudska odgovornost, poslovno prihvatanje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Identitet i ovlašćenje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Identiteti korisnika\u002Fservisa\u002Fagenata, uloge, opseg zakupca ili organizacije, privilegovane radnje, putevi odobravanja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Enterprise podaci\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sistemi evidencije, izvori dokumenata, podaci kao proizvodi, poreklo, klasifikacija, zadržavanje, svežina i pristup.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI platforma\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pristup provajderu\u002Fmodelu, primitive pretrage, runtime okruženja agenata, brokeri alata, infrastruktura za evaluaciju, observabilnost, kvote i tajne.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI rešenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Domenski tokovi posla, promptovi\u002Finstrukcije, domenska pretraga, poslovna logika, kriterijumi prihvatanja i korisničko iskustvo.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Integracija i alati\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">API-ji, enterprise aplikacije, tokovi posla, razmena poruka, fajl sistemi, eksterne usluge i izvršavanje radnji.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rizik i upravljanje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Inventar, procena, dokazi o usklađenosti, upravljanje izuzecima, odobravanje modela\u002Fprovajdera, pregled i revizija.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Operacije i životni ciklus\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Postavljanje, praćenje, incidenti, izdanja, promene modela\u002Fprovajdera, ukidanje, vraćanje na prethodno stanje i kontinuitet.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Arhitektura je najjača kada svaki sloj može da navede i svoje odgovornosti i svoje ne-odgovornosti. Na primer, AI platforma može da sprovodi politiku provajdera i prikuplja tragove, a da ne postane izvor istine za HR podatke. Rešenje može da definiše domenske promptove, a da ne poseduje enterprise IAM. Poslovni vlasnik može da odobri slučaj upotrebe, a da se od njega ne očekuje da upravlja inference gateway-om.\u003C\u002Fp>\n\u003Ch2 id=\"section-66\">Mapirajte enterprise AI kao tokove podataka i ovlašćenja, a ne kao kutije\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Enterprise AI zahtev sa posledicama\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Poslovni kontekst\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Korisnik zahteva zadatak u okviru odobrenog slučaja upotrebe sa odgovornim poslovnim vlasnikom.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Identitet i autorizacija\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Sistem razrešava korisnika, aplikaciju, servis i opseg zakupca ili organizacije pre privilegovanog pristupa.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Pribavljanje merodavnih podataka\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Rešenje čita ili pretražuje samo izvore dozvoljene za trenutni identitet i zadatak.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. AI obrada\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Odobreni model\u002Fprovajder obrađuje minimalno neophodan kontekst pod definisanim pravilima rutiranja i rukovanja podacima.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Granica alata ili radnje\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Svaka radnja koja menja stanje je nezavisno autorizovana i može zahtevati ljudsko odobrenje u skladu sa posledicama.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Validacija\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Rezultat se proverava prema pravilima prihvatanja, dokazima ili bezbednosti specifičnim za rešenje.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. Revizija i observabilnost\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Dozvoljeni metapodaci, odluke, rute, pozivi alata i ishodi se beleže bez stvaranja nekontrolisanih logova osetljivih podataka.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. Povratna informacija i životni ciklus\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Neuspesi i rezultati evaluacije hrane promene modela, promptova, podataka, politike i procesa kroz kontrolisano upravljanje promenama.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-68\">Enterprise mora imati AI inventar pre nego što može da upravlja AI sistemima\u003C\u002Fh2>\n\u003Cp>Organizacije ne mogu da upravljaju AI sistemima koje ne mogu da identifikuju. Enterprise arhitektura treba da održava inventar na nivou koji je koristan za odluke, a ne samo listu imena modela.\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Polje inventara\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zašto je važno\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Slučaj upotrebe i vlasnik\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Povezuje tehnologiju sa odgovornom poslovnom svrhom.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Korisnici i pogođene strane\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše ko interaguje sa sistemom ili je njime pogođen.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Model\u002Fprovajder\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Identifikuje eksternu zavisnost, sposobnost i rizik životnog ciklusa.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Izvori podataka\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Podržava proveru nadležnosti, privatnosti, klasifikacije i porekla.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Lokacija postavljanja\u002Fruntime-a\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Razjašnjava lokaciju obrade, povezivost i operativnu kontrolu.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Alati\u002Fradnje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pokazuje da li AI može da promeni eksterno stanje i sa kojim posledicama.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ljudski nadzor\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Beleži gde je potreban pregled, odobrenje ili eskalacija.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rizik\u002Fklasifikacija\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Povezuje sistem sa organizacionim i regulatornim kontrolama.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Dokazi o evaluaciji\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pokazuje šta je testirano i pod kojim uslovima validnosti.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Trenutna verzija\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Omogućava da se incidenti i regresije prate do stvarnog stanja u produkciji.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Stanje životnog ciklusa\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Predloženo, eksperimentalno, odobreno, produkcija, ograničeno, ukinuto ili povučeno.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-71\">AI upravljanje i enterprise AI arhitektura su povezani, ali nisu isto\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Upravljanje naspram arhitekture\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">AI upravljanje\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Enterprise AI arhitektura\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Svrha\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Primer\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Neuspeh ako je izolovano\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-73\">Regulativa postaje ulazni parametar arhitekture\u003C\u002Fh2>\n\u003Cp>Za organizacije koje posluju u Evropskoj uniji, AI Act može stvoriti zahteve koji utiču na dizajn sistema, dokumentaciju, transparentnost, upravljanje i operativne procese. Arhitektonski uticaj zavisi od uloge organizacije u AI lancu vrednosti i konkretne klasifikacije sistema; nema svaki AI sistem iste obaveze.\u003C\u002Fp>\n\u003Cp>Od 8. oktobra 2026, trenutni konsolidovani tekst navodi da se Regulativa generalno primenjuje od 2. avgusta 2026. Pravila upravljanja i obaveze za modele opšte namene počeli su da se primenjuju ranije, dok određene odredbe za sisteme visokog rizika imaju kasnije datume. Komisija je takođe počela da sprovodi nove zahteve transparentnosti od 2. avgusta 2026. za relevantne interaktivne sisteme i sisteme sintetičkog sadržaja.\u003C\u002Fp>\n\u003Cp>Lekcija za arhitekturu preduzeća nije „staviti usklađenost u model“. Već učiniti klasifikaciju, ulogu pružaoca\u002Fkorisnika, dokumentaciju, transparentnost, nadzor, evidentiranje i dokaze o promenama sledljivim do sistema koji zaista implementira slučaj upotrebe.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Pravni obim zavisi od slučaja upotrebe\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Ovaj članak opisuje arhitektonske implikacije, a ne pravni savet. Arhitektura AI u preduzeću treba da sačuva informacije potrebne pravnim i compliance stručnjacima da klasifikuju stvarni sistem i mapiraju obaveze na konkretne kontrole. Arhitektura ne treba da ugrađuje jedno regulatorno tumačenje kao da svaki AI radni zadatak ima isti status.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-78\">Nabavka i arhitektura postaju povezane\u003C\u002Fh2>\n\u003Cp>Spoljni model ili upravljana AI platforma može postati duboka zavisnost čak i kada integracija zahteva samo nekoliko API poziva. Arhitektura preduzeća zato treba da učini pitanja nabavke tehnički konkretnim.\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Pitanje nabavke\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Arhitektonska posledica\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Gde se podaci obrađuju?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Region, mrežna putanja, rezidentnost podataka i kontrole prenosa.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Da li se podaci korisnika čuvaju ili koriste za poboljšanje kod pružaoca?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Minimizacija podataka, ugovorne kontrole i podobnost pružaoca.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se modeli verzioniraju ili povlače?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Regresiono testiranje, kompatibilnost, rezervni plan i planiranje životnog ciklusa.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji su kvote i ograničenja usluge?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitektura kapaciteta, kontrola prijema i rukovanje otkazima.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koliko je integracija prenosiva?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Apstrakcija pružaoca, trošak izlaska i napor migracije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koje informacije o incidentima su dostupne?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Opservabilnost, forenzičke mogućnosti i eskalacija podrške.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji podprocesori ili spoljne usluge su uključeni?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Mapiranje zavisnosti i procena rizika.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta se menja bez izričitog odobrenja korisnika?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Detekcija promena, kapije izdanja i strategija prihvatanja.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-81\">Arhitektura preduzeća odlučuje koliko kontrole nad AI zahtev zaista zahteva\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zahtev\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Mogući arhitektonski odgovor\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Brz pristup upravljanim modelima\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Upravljani pružalac sa identitetom preduzeća, kontrolama mrežnog prolaza i ugovornim pregledom.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Privatni podaci sa upravljanom orkestracijom\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Upravljana kontrolna ravan plus izvršavanje pod kontrolom korisnika ili privatna ravan podataka gde je podržano.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Stroga lokalnost ili suverenost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Region-restriktivna, suverena, privatna ili samo-hostovana arhitektura u skladu sa stvarnim zahtevom.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vazdušno izolovano okruženje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Lokalno hostovani modeli, lokalno pretraživanje, lokalni alati, vanmrežno ažuriranje\u002Fdistribucija i izolovana opservabilnost.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Prenosivost između pružalaca\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Stanje domena u vlasništvu aplikacije plus adapteri i ugovori koji izoluju ponašanje specifično za pružaoca gde je praktično.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Najviša kontrola nad semantikom agenata\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Samo-upravljano ili duboko kontrolisano izvršno okruženje sa izričitim vlasništvom nad alatima, kontekstom, stanjem i životnim ciklusom.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Najkontrolisanija arhitektura nije automatski najbolja arhitektura preduzeća. Veće vlasništvo povećava odgovornost za zakrpe, kapacitet, bezbednost, testiranje, operacije modela i odgovor na incidente. Arhitektura preduzeća treba da poveća kontrolu samo tamo gde zahtev opravdava dodatni operativni teret.\u003C\u002Fp>\n\u003Ch2 id=\"section-84\">AI pretvara upravljanje promenama u problem ponašanja\u003C\u002Fh2>\n\u003Cp>Uobičajeno ažuriranje zavisnosti može promeniti performanse ili kompatibilnost. AI promena može takođe promeniti ponašanje. Zamena modela, promena sistemskog upita, promena pretraživanja, dodavanje alata ili promena politike konteksta može izmeniti način na koji sistem tumači i odgovara čak i ako se okolni aplikativni kod jedva menja.\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Put promene AI u produkciji\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Promena identifikovana\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Predlaže se ili detektuje promena modela, pružaoca, upita, izvora pretraživanja, alata, politike ili izvršnog okruženja.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Uticaj mapiran\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Identifikuju se pogođena rešenja, klase podataka, korisnici, kontrole rizika, troškovi, ugovori i operativne zavisnosti.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Arhitektonska odluka ažurirana\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Materijalni izbori i kompromisi se beleže; zamenjene odluke ostaju istorijski sledljive.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. Evaluacija sprovedena\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Pokreću se relevantni regresioni, bezbednosni, testovi pretraživanja, latencije, troškova i domena.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Odobrenje primenjeno\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Nivo odobrenja prati posledice, rizik i organizacionu politiku.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Kontrolisano uvođenje\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Verzionirano izdanje, kanarinac ili fazno uvođenje se koristi gde je prikladno.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. Prikupljeni dokazi iz produkcije\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Telemetrija, incidenti, povratne informacije i ishodi domena se prate.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. Povratak ili prihvatanje\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Promena se prihvata, ograničava, povlači ili zamenjuje na osnovu dokaza.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-87\">AI u preduzeću i dalje zahteva NFR i ADR\u003C\u002Fh2>\n\u003Cp>AI ne zamenjuje običnu arhitektonsku disciplinu. Nefunkcionalni zahtevi ostaju ciljni uslovi: dostupnost, latencija, privatnost, izolacija, revizibilnost, oporavak, granice troškova, objašnjivost ili drugi zahtevi kvaliteta. Zapisnici o arhitektonskim odlukama čuvaju izabrani odgovor i njegove kompromise.\u003C\u002Fp>\n\u003Cp>AI-specifična razlika je da se neki atributi kvaliteta moraju evaluirati probabilistički ili empirijski. „Odgovori moraju biti korisni“ je previše neodređeno. Produkcijski zahtev treba da identifikuje zadatak, podatke, korisničku populaciju, prihvatljive uslove neuspeha, metodu merenja i prag gde je praktično.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Lanac sledljivosti u preduzeću\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>Poslovna potreba → zahtev \u002F NFR → arhitektonska odluka → implementacija → evaluacija \u002F validacija → posmatranje u produkciji → odluka o promeni.\u003C\u002Fstrong> AI dodaje nove varijable u ovaj lanac; ne čini lanac nepotrebnim.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-91\">Arhitektura enterprise AI mora biti povezana sa isporukom\u003C\u002Fh2>\n\u003Cp>Arhitektura koja nikada ne stigne do backlog-a, implementacije, prihvatanja i operacija ostaje konceptualna. Enterprise AI zato zahteva sledljivost od arhitektonskih odluka do rada na isporuci i nazad od dokaza iz implementacije do arhitekture.\u003C\u002Fp>\n\u003Cp>Jira i Confluence su primeri alata koji mogu podržati ovo razdvajanje kada se koriste namerno: Confluence može da čuva zahteve, arhitekturu, odluke, rizike i obrazloženja; Jira može da upravlja izvršnim radom na isporuci i stanjem. Važan princip je sledljivost, a ne brend alata.\u003C\u002Fp>\n\u003Ch2 id=\"section-94\">Dokazi originalnog projekta: Enterprise Aaasaasa 0.1\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Dokaz projekta, a ne tvrdnja dokazana na tržištu\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Enterprise Aaasaasa 0.1 se ovde koristi kao dokaz originalnog projekta za strukturisano enterprise arhitektonsko i isporučno razmišljanje. To je PoC \u002F enterprise kontekst projekta, a ne dokaz masovnog usvajanja od strane kupaca, enterprise produkcijske upotrebe ili komercijalne trakcije.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cp>Enterprise Aaasaasa 0.1 kombinuje arhitekturu platforme, SaaS\u002FAPI koncepte, internacionalizaciju, AI integraciju i strukturisano upravljanje projektom. Projekat je namerno organizovan tako da su zahtevi, arhitektura, isporuka prototipa, validacija i zatvaranje bili odvojeni miljokazi, a ne jedna nediferencirana faza implementacije.\u003C\u002Fp>\n\u003Cp>Arhitektonski pravac uključuje koncepte multi-instance \u002F multi-database zajedno sa API, CRUD, i18n i AI mogućnostima. To je važno za enterprise AI jer granice zakupaca ili instanci, vlasništvo nad bazom podataka i aplikacione usluge moraju ostati eksplicitne kada se dodaju AI funkcije.\u003C\u002Fp>\n\u003Cp>Struktura projekta je takođe tretirala kašnjenje arhitekture, širenje obima i brige o AI\u002Fzaštiti podataka kao projektne rizike, umesto da ih otkrije tek tokom implementacije. Zainteresovane strane su uključivale tehničke, bezbednosne, sponzorske\u002Fupravljačke i perspektive eksternih servisa, što je bliže stvarnoj unakrsno-funkcionalnoj prirodi enterprise AI nego prototip samo sa modelom.\u003C\u002Fp>\n\u003Cp>Korisni dokaz je zato integracija arhitekture i isporuke: poslovna i projektna struktura, miljokazi, rizici, arhitektura, backend\u002FAPI, frontend\u002FAI rad, validacija i zatvaranje tretiraju se kao povezane odgovornosti. Taj obrazac je ponovo upotrebljiv iako sam projekat ne treba predstavljati kao dokaz eksternog enterprise usvajanja.\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Element projekta\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Lekcija za enterprise AI arhitekturu\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Miljokaz zahteva\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI sposobnost mora početi od definisane potrebe, obima, prihvatanja i ograničenja kvaliteta.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Miljokaz arhitekture\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Podaci, API, granice instanci\u002Fbaza podataka i AI integracija su eksplicitan dizajnerski rad.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Miljokaz prototipa\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitektura mora postati dovoljno izvršna da otkrije rizike integracije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Miljokaz validacije\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Funkcionalni prototip nije isto što i validirano prihvatanje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Registar rizika\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Obim, kašnjenje arhitekture i brige o AI\u002Fzaštiti podataka upravljaju se kao rizici isporuke.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Struktura zainteresovanih strana\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Enterprise AI obuhvata sponzora\u002Fposlovanje, arhitekturu, bezbednost, eksterne provajdere i isporuku.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zatvaranje projekta\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Odluke, preostali rizici i dokazi validacije moraju nadživeti implementacioni sprint.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-101\">Podržavajući obrasci implementacije iz šireg rada na platformi\u003C\u002Fh2>\n\u003Cp>Odvojen rad na implementaciji u široj Aaasaasa platformi pruža konkretne primere granica koje enterprise AI arhitektura mora sačuvati: RBAC ograničen na zakupca u CMS-u, eksplicitno razdvajanje provajdera\u002Fmodela\u002Fruntime-a\u002Fdozvola u Aaasaasa AI Client-u i prvenstveno poreklo pri preuzimanju u Source of Truth Research Engine-u.\u003C\u002Fp>\n\u003Cp>Ovi projekti ne treba da se spoje u jednu tvrđenu produkcijsku platformu. Njihova vrednost ovde je uža: oni demonstriraju implementirane obrasce za obim identiteta, granice provajdera, kontrolisane runtime dozvole, poreklo preuzimanja i sledljivost dokaza koji su direktno relevantni za enterprise AI.\u003C\u002Fp>\n\u003Ch2 id=\"section-104\">Kako se glavni standardi uklapaju\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Izvor\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Šta doprinosi enterprise AI arhitekturi\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC 42001:2023\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sistem upravljanja AI na nivou organizacije: politike, ciljevi, procesi, odgovornost, praćenje i kontinuirano poboljšanje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC 23894:2023\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Smernice za integraciju upravljanja rizicima specifičnim za AI u organizacione aktivnosti i funkcije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">NIST AI RMF 1.0\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Dobrovoljni okvir orijentisan na životni ciklus za upravljanje AI rizicima; organizovan oko Govern, Map, Measure i Manage.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">NIST AI 600-1\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Profil generativne AI koji proširuje AI RMF rizicima i akcijama specifičnim za generativnu AI.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">EU AI Act\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Obavezujuće regulatorne obaveze u EU čija primenljivost zavisi od uloge, tipa sistema i klasifikacije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC\u002FIEEE 42010:2022\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Opšti koncepti opisa arhitekture za izražavanje briga, stanovišta, odluka i odnosa.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Ovi izvori rešavaju različite probleme. ISO\u002FIEC 42001 nije zamena za tehničku arhitekturu. ISO\u002FIEC 23894 i NIST AI RMF ne definišu jedan obavezni softverski stek. EU AI Act je zakon, a ne obrazac dizajna platforme. Arhitektura mora prevesti primenljive organizacione, rizične i pravne zahteve u implementabilne sistemske granice i dokaze.\u003C\u002Fp>\n\u003Ch2 id=\"section-107\">Uobičajeni načini neuspeha enterprise AI\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Način neuspeha\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zašto ne uspeva\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Svaki tim kupuje AI nezavisno\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Stvara shadow provajdere, duplirane tajne, nedosledno rukovanje podacima i slabu polugu nad rizikom dobavljača.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Jedan centralni AI tim poseduje svaku domensku odluku\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Centralizuje tehničku kontrolu ali gubi domensku odgovornost i stvara usko grlo.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vektorska baza podataka postaje izvor istine\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Infrastruktura za preuzimanje tiho zamenjuje autoritativne sisteme i pravila svežine.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Jedan deljeni API ključ za sve korisnike i agente\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Uništava atribuciju, najmanje privilegije i smislenu reviziju.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Promena modela se objavljuje kao manji patch biblioteke\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Regresije u ponašanju mogu stići u produkciju bez domenske evaluacije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Svi promptovi i izlazi se loguju zauvek\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Observability stvara nekontrolisano skladište osetljivih podataka.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Upravljanje je samo dokumentacija\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Politike postoje bez tačaka sprovođenja, dokaza ili operativnog vlasništva.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Usklađenost je delegirana provajderu\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sopstvena uloga organizacije, slučaj upotrebe, podaci i operativne obaveze ostaju nerešeni.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Agent može da poziva alate jer model podržava korišćenje alata\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sposobnost se pogrešno smatra autorizacijom.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zdravlje platforme jednako je poslovnoj ispravnosti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vreme rada endpoint-a i dostupnost modela ne dokazuju kvalitet domenskih odgovora ili prihvatljive ishode.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Nema izlazne strategije za zavisnost od modela\u002Fprovajdera\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Promena cene, politike, sposobnosti ili dostupnosti postaje hitna migracija.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-109\">Uobičajene zablude\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zabluda\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Bolji model\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Enterprise AI znači četbot za celu kompaniju.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Četbot je samo jedan interfejs; arhitektura enterprise AI upravlja podacima, identitetom, provajderom, izvršnim okruženjem, rizikom i operacijama.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Ako koristimo renomiranog provajdera modela, upravljanje je rešeno.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kontrole provajdera ne definišu vaš slučaj upotrebe, nadležnost nad podacima, korisničke dozvole, poslovno prihvatanje ili pravnu ulogu.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Privatni AI znači da sve mora biti samostalno hostovano.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zahtevi privatnosti mogu dovesti do nekoliko arhitektura; potrebna granica kontrole mora biti precizno navedena.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Upravljanje AI pripada pravnoj službi, arhitektura IT-u.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ove dve discipline moraju biti povezane jer obaveze iz politika zahtevaju primenljive kontrole i dokaze.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Jedan enterprise model je jednostavniji.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Standardizacija može pomoći, ali radni zadaci mogu zahtevati različite modalitete, regione, troškove, nivoe kvaliteta ili modele kontrole.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„AI rizik je rizik modela.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rizik može poticati iz podataka, upita, pronalaženja, identiteta, alata, interfejsa, operacija, korisnika i organizacionih procesa.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Human-in-the-loop čini agenta bezbednim.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ljudsko odobrenje pomaže samo ako recenzent ima koristan kontekst, ovlašćenje, vreme i jasnu tačku odlučivanja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Uspešan pilot dokazuje spremnost za enterprise.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pilot dokazuje ograničenu sposobnost; enterprise spremnost takođe zahteva integraciju, upravljanje, životni ciklus, operacije i ponovljive kontrole.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-111\">Praktičan redosled odlučivanja u arhitekturi enterprise AI\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Od prilike do upravljane enterprise sposobnosti\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Definišite poslovnu sposobnost\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Navedite korisnika, odluku ili tok rada, očekivanu vrednost i odgovornog vlasnika.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Klasifikujte podatke i nadležnost\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Identifikujte sisteme evidencije, lične\u002Fpoverljive podatke, zahteve za čuvanjem, svežinom i poreklom.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Definišite granice identiteta i radnji\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Odredite ko može da čita, generiše, odlučuje, odobrava i menja eksterne sisteme.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. Izaberite odgovornosti rešenja i platforme\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Odlučite šta pripada radnom zadatku, šta može biti deljeno i šta ostaje u vlasništvu enterprise-a.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Procenite zavisnost od provajdera i izvršnog okruženja\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Procenite upravljane, samostalno hostovane, privatne, suverene ili hibridne opcije u odnosu na stvarne zahteve.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Mapirajte rizik i regulatorne obaveze\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Odredite nivo rizika, organizacione kontrole i primenljive pravne odgovornosti za konkretan sistem.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. Definišite merljivo prihvatanje\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Kreirajte kriterijume evaluacije za kvalitet, pouzdanost, bezbednost, pronalaženje, troškove i operativno ponašanje.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. Zabeležite arhitekturne odluke\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Sačuvajte obrazloženje, alternative, kompromise, zavisnosti i uslove koji bi pokrenuli preispitivanje.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. Povežite arhitekturu sa isporukom\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Prevedite dizajn u backlog, prekretnice, kriterijume prihvatanja, tehnički rad i vlasništvo.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. Validirajte u uslovima sličnim produkciji\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Testirajte realistične scenarije identiteta, podataka, otkaza, kašnjenja, provajdera, alata i oporavka, a ne samo čiste demo prikaze.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">11\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">11. Uspostavite operacije i kontrolu promena\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Definišite nadzor, odgovor na incidente, ažuriranja modela\u002Fprovajdera, regresiono testiranje, vraćanje i ukidanje.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">12\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">12. Vratite dokaze u arhitekturu\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Koristite produkcijska zapažanja, revizije, incidente i evaluacije za reviziju odluka i kontrola.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-113\">Kontrolna lista za arhitekturu enterprise AI\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Pitanje\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Očekivani dokaz\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koju poslovnu sposobnost ovaj AI podržava?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Imenovani vlasnik, korisnička grupa, nameravana odluka\u002Ftok rada i cilj prihvatanja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji izvor je merodavan za svaku važnu činjenicu?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sistemi evidencije, nadležnost dokumenata, pravila porekla i svežine.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji identiteti postoje?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ljudski, aplikacijski, servisni, agentski, zakupac\u002Forg i identiteti provajdera su razlikovni.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta AI može da čita?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Izvori podataka ograničeni autorizacijom i eksplicitna pravila za osetljive podatke.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta AI može da menja?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Inventar alata\u002Fradnji, model dozvola, odobrenje i put vraćanja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koji provajder\u002Fmodel se koristi i zašto?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitekturna odluka uključujući kvalitet, bezbednost, troškove, region, životni ciklus i razmatranja izlaska.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta se dešava ako provajder nije dostupan?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Režim degradacije, rezervna opcija, odbijanje ili plan kontinuiteta.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se procenjuje kvalitet?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Skupovi podataka specifični za zadatak, ocenjivači, pragovi, kriterijumi regresije i uslovi validnosti.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta se loguje?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šema telemetrije, redakcija, pristup, čuvanje i svrha revizije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ko je vlasnik AI rizika?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Imenovana organizaciona odgovornost povezana sa konkretnim sistemom.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Koja pravna klasifikacija se primenjuje?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Dokumentovana procena zasnovana na važećem zakonu i stvarnom slučaju upotrebe.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se odobravaju promene modela\u002Fupita\u002Fpronalaženja?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Verzionisanje, evaluacija, arhitekturni\u002Fzapis o promeni i kapija za uvođenje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ko reaguje na AI incident?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Runbook, tehnički vlasnik, poslovna\u002Fdomenska eskalacija i eskalacija ka provajderu.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se sistem ukida?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Čišćenje podataka, opoziv pristupa, izlazak od provajdera, čuvanje dokaza i uklanjanje zavisnosti.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-115\">Granični slučajevi i ograničenja\u003C\u002Fh2>\n\u003Cp>Mala kompanija sa jednim AI slučajem upotrebe niskog rizika možda neće imati potrebu za formalnom funkcijom arhitekture enterprise AI. Isti principi mogu se primeniti u laganoj formi: jasan vlasnik, odobreni podaci, eksplicitni provajder, osnovna evaluacija, kontrola pristupa i operativna odgovornost.\u003C\u002Fp>\n\u003Cp>Visoko regulisana organizacija može zahtevati jaču separaciju, nezavisnu validaciju, formalne procese usklađenosti, lokalni hosting ili rad u izolovanoj mreži. Te kontrole su vođene slučajem upotrebe i regulatornim okruženjem, a ne rečju „enterprise“.\u003C\u002Fp>\n\u003Cp>Organizacija takođe može uglavnom koristiti SaaS AI proizvode umesto izgradnje AI sistema. Enterprise arhitektura je i dalje važna jer identitet, pristup podacima, ugovorni uslovi, shadow AI, čuvanje, revizija i koncentracija dobavljača ostaju organizacione brige.\u003C\u002Fp>\n\u003Cp>Centralizovana platforma nije obavezna. Federativno vlasništvo nad platformom može biti validno kada domeni imaju bitno različite zahteve, pod uslovom da odgovornosti za identitet, rizik, inventar i interoperabilnost na nivou enterprise-a ostanu koherentne.\u003C\u002Fp>\n\u003Ch2 id=\"section-120\">Šta bi promenilo ovaj odgovor?\u003C\u002Fh2>\n\u003Cp>Arhitektura se menja kada se promene tolerancija organizacije na rizik, regulatorna klasifikacija, osetljivost podataka, geografski obuhvat, strategija provajdera, interne veštine ili poslovna kritičnost. Javni marketinški asistent i sistem koji učestvuje u odlukama o zapošljavanju, finansijama, zdravstvu ili kritičnoj infrastrukturi ne bi trebalo da naslede identične modele kontrole.\u003C\u002Fp>\n\u003Cp>Implementacija se takođe menja kako se standardi, regulativa i AI platforme razvijaju. NIST AI RMF 1.0 je trenutno u reviziji, EU AI Act ima fazne datume primene, a sposobnosti modela\u002Fprovajdera se i dalje brzo menjaju. Enterprise arhitektura bi stoga trebalo da očuva stabilne granice odgovornosti, dok mehanizme provajdera i regulatorne detalje tretira kao verzionisane ulaze.\u003C\u002Fp>\n\u003Ch2 id=\"section-123\">Povezano kanonsko znanje\u003C\u002Fh2>\n\u003Cp>Arhitektura enterprise AI se nadograđuje na arhitekturu rešenja i platforme. Sloj rešenja objašnjava jedan radni zadatak. Sloj platforme objašnjava AI sposobnosti koje se mogu ponovo koristiti. Enterprise sloj povezuje oba sa podacima, identitetom, upravljanjem, rizikom, nabavkom i operacijama na nivou cele organizacije.\u003C\u002Fp>\n\u003Cp>Retrieval-Augmented Generation je samo jedan mehanizam unutar ove arhitekture. RAG može poboljšati pristup enterprise znanju, ali sam po sebi ne rešava nadležnost nad podacima, dozvole, upravljanje ili validnost odgovora.\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">Šta je RAG? Najjednostavnije objašnjenje kako funkcioniše\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">Objašnjenje jednostavnim jezikom kako se pronalaženje eksternog znanja povezuje sa jezičkim modelom, a da pronalaženje ne postane izvor istine.\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">Pročitajte osnove RAG-a →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Cp>Za poslovne slučajeve upotrebe sa mnogo dokaza, valjanost odgovora takođe zahteva eksplicitnu granicu: izlaz je podržan samo pod dokazima, verzijom, obimom i pretpostavkama koje su ga proizvele.\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">Granica valjanosti odgovora: sloj koji nedostaje između relevantnosti i pouzdanih AI odgovora\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">Okvir za eksplicitno iskazivanje uslova pod kojima AI tvrdnja ostaje podržana i koje promene zahtevaju ograničenje ili ponovno izračunavanje.\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">Pročitajte Granicu valjanosti odgovora →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Cp>Nizvodne poslovne teme uključuju AI upravljanje, privatni AI, suvereni AI, AI u vazdušno izolovanim sistemima, multi-tenant AI arhitekturu, RBAC naspram izolacije zakupaca, apstrakciju provajdera, rutiranje modela i produkcijsku AI arhitekturu.\u003C\u002Fp>\n\u003Ch2 id=\"section-130\">Često postavljana pitanja\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Često postavljana pitanja o poslovnoj AI arhitekturi\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Šta je poslovna AI arhitektura?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Poslovna AI arhitektura je arhitektura na nivou organizacije koja definiše kako se AI rešenja i zajedničke AI sposobnosti integrišu sa poslovnim vlasništvom, poslovnim podacima, identitetom, bezbednošću, provajderima, upravljanjem, rizikom, usklađenošću, životnim ciklusom i operacijama.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li je poslovna AI arhitektura isto što i AI platforma?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. AI platforma pruža tehničke sposobnosti koje se mogu ponovo koristiti, kao što su pristup modelima, pretraživanje, izvršno okruženje agenata i nadzor. Poslovna AI arhitektura definiše kako se ta platforma i pojedinačna AI rešenja uklapaju u širu arhitekturu i operativni model organizacije.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li poslovni AI zahteva jedan centralni model?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Standardizacija može smanjiti složenost, ali različiti radni zadaci mogu zahtevati različite provajdere, modele, regione, nivoe kontrole ili modalitete. Važan zahtev je eksplicitna politika i vlasništvo nad životnim ciklusom.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Zašto je autoritet podataka važan za poslovni AI?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Zato što preuzete ili generisane informacije nisu automatski autoritativne. Poslovni sistemi moraju da očuvaju koji izvor je sistem evidencije, da li su podaci aktuelni, ko može da im pristupi i kako se generisana tvrdnja može pratiti do dokaza.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Koja je razlika između AI upravljanja i poslovne AI arhitekture?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">AI upravljanje definiše politike, odgovornost i prava odlučivanja. Poslovna AI arhitektura definiše granice sistema, interfejse, tokove podataka i tehničke mehanizme kroz koje se te politike mogu sprovesti i dokazati.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li se EU AI Act primenjuje na svaki poslovni AI sistem na isti način?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Obaveze zavise od faktora kao što su uloga organizacije, slučaj upotrebe i klasifikacija sistema, kao i relevantne odredbe koje su na snazi. Pravna klasifikacija mora se izvršiti za konkretan sistem prema važećem zakonu.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq7\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li je uspešan AI pilot dovoljan za poslovno uvođenje?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Pilot pokazuje ograničenu sposobnost. Poslovno uvođenje takođe zahteva identitet, autoritet podataka, bezbednost, upravljanje provajderima, evaluaciju, životni ciklus, odgovor na incidente, praćenje, usklađenost i odgovorno operativno vlasništvo.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq8\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li preduzeća treba sama da hostuju AI?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Samo kada zahtev opravdava dodatnu kontrolu i operativnu odgovornost. Upravljani, privatni, suvereni, samohostovani i hibridni pristupi su arhitektonske opcije čija podobnost zavisi od zahteva u pogledu podataka, propisa, dostupnosti, troškova, sposobnosti i operacija.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-132\">Pojmovnik\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Ključni pojmovi poslovne AI arhitekture\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"enterprise-ai-architecture\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Poslovna AI arhitektura\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Arhitektura na nivou organizacije koja uređuje kako se AI sistemi, platforme, podaci, identiteti, provajderi, kontrole rizika i operacije uklapaju zajedno.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-management-system\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Sistem upravljanja AI\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Organizacioni sistem upravljanja za uspostavljanje politika, ciljeva i procesa vezanih za AI; ISO\u002FIEC 42001 specificira zahteve za takav sistem.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"data-authority\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Autoritet podataka\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Pravilo koje identifikuje koji izvor ili sistem je autoritativan za određenu činjenicu, zapis, stanje ili kontekst odluke.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"system-of-record\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Sistem evidencije\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Autoritativni sistem odgovoran za zvanično trenutno stanje poslovnog zapisa ili entiteta domena.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-inventory\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI inventar\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Strukturirani zapis o AI slučajevima upotrebe, vlasnicima, modelima\u002Fprovajderima, podacima, alatima, riziku, dokazima evaluacije, stanju životnog ciklusa i povezanim kontrolama.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"provider-dependency\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Zavisnost od provajdera\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Tehničko, ugovorno i operativno oslanjanje koje nastaje kada AI radni zadatak zavisi od eksternog modela ili upravljane platforme.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"human-oversight\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Ljudski nadzor\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Definisano ljudsko pregledanje, odobravanje, intervencija ili eskalacija koja se primenjuje tamo gde posledice sistema, neizvesnost ili regulativa to zahtevaju.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"genaiops\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">GenAIOps\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Operativne prakse za generativne AI radne zadatke koje pokrivaju izbor modela, upite, podatke za zasnivanje, evaluaciju, uvođenje, praćenje i upravljanje životnim ciklusom.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-risk-management\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Upravljanje AI rizikom\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Organizacioni proces identifikovanja, procene, tretiranja, praćenja i revizije rizika povezanih sa AI sistemima tokom njihovog životnog ciklusa.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"architecture-decision\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Arhitektonska odluka\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Značajan izbor dizajna zajedno sa njegovim kontekstom, obrazloženjem, alternativama, kompromisima i statusom životnog ciklusa.\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-134\">Zaključak\u003C\u002Fh2>\n\u003Cp>Kada AI uđe u kompaniju, preduzeće ne dobija samo novu softversku komponentu. Ono dobija novu klasu ponašanja i zavisnosti koja seče kroz podatke, identitet, dobavljače, poslovne odluke, bezbednost, operacije, upravljanje i upravljanje promenama.\u003C\u002Fp>\n\u003Cp>Arhitektonski odgovor nije da se sve centralizuje. Već da se odgovornosti učine eksplicitnim: koji podaci su autoritativni, koji identiteti mogu da deluju, koji provajderi su odobreni, koje kontrole su zajedničke, koje odluke ostaju u vlasništvu domena, kako se ponašanje evaluira, kako se incidenti obrađuju i kako se sistem menja tokom vremena.\u003C\u002Fp>\n\u003Cp>To je suštinska razlika poslovne AI arhitekture: ona pretvara izolovanu AI sposobnost u organizaciono upravljiv sistem bez pretvaranja da su modeli, platforme, poslovni domeni i poslovne kontrole ista stvar.\u003C\u002Fp>\n\u003Ch2 id=\"section-138\">Primarni izvori i aktuelne smernice\u003C\u002Fh2>\n\u003Cp>Spoljni standardi, regulativa i aktuelne smernice za arhitekturu dobavljača u nastavku provereni su 8. oktobra 2026. Sekcije specifične za projekat eksplicitno su označene kao originalni dokazi projekta i ne treba ih čitati kao tvrdnje o opštoj industrijskoj činjenici.\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC 42001:2023 — Sistem upravljanja veštačkom inteligencijom\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Međunarodni standard koji specificira zahteve za uspostavljanje, implementaciju, održavanje i kontinuirano poboljšanje sistema upravljanja AI u organizacijama.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC 23894:2023 — Smernice za upravljanje AI rizikom\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Međunarodne smernice za integraciju upravljanja rizikom specifičnog za AI u organizacione aktivnosti i funkcije.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI okvir za upravljanje rizikom\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST-ov dobrovoljni okvir orijentisan na životni ciklus za upravljanje AI rizikom. NIST navodi da je AI RMF 1.0 trenutno u fazi revizije.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI 600-1 — Profil generativne AI\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST-ov prateći profil koji opisuje rizike specifične za generativnu AI i radnje za upravljanje rizikom usklađene sa AI RMF.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">EUR-Lex — Uredba (EU) 2024\u002F1689, konsolidovani tekst\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelni konsolidovani tekst AI akta koji se koristi za datume primene i regulatornu strukturu, proveren 8. oktobra 2026.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Evropska komisija — regulatorni okvir AI akta\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Trenutni pregled Komisije o fazama primene AI akta, uključujući primenu u 2026. i kasnije datume za određene odredbe o visokom riziku.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft Azure Well-Architected — AI radna opterećenja\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Trenutne smernice za arhitekturu AI radnih opterećenja, uključujući nedeterminističko ponašanje, podatke, dizajn aplikacija i operacije.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft — MLOps i GenAIOps za AI radna opterećenja\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Trenutne smernice o operativnom životnom ciklusu, podacima, održavanju modela, implementaciji, nadzoru i kontinuiranom razvoju.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft — Odgovorna AI u Azure radnim opterećenjima\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Trenutne smernice koje povezuju AI politiku sa kontrolom podataka, identitetom, revizijom agenata, pristupom zasnovanim na ulogama i operativnim zaštitnim merama.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC\u002FIEEE 42010:2022 — Opis arhitekture\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Trenutni standard za opis arhitekture koji podržava eksplicitne nedoumice, stanovišta i odnose u sistemskoj arhitekturi.\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1562},1791478362475,[214,220,228,235,242,250,255,260,265,270,305,310,315,320,325,351,356,361,366,371,376,381,386,391,396,401,406,412,417,422,427,432,437,442,447,452,457,462,467,472,477,482,487,492,497,502,507,512,517,522,527,532,537,542,547,552,557,562,567,572,621,627,632,638,670,675,680,710,715,720,761,766,790,795,800,805,810,816,821,826,858,863,889,894,899,904,934,939,944,949,955,960,965,970,975,981,986,991,996,1001,1030,1035,1040,1045,1050,1076,1081,1086,1127,1132,1164,1169,1211,1216,1266,1271,1276,1281,1286,1291,1296,1301,1306,1311,1316,1321,1330,1335,1343,1348,1353,1391,1396,1441,1446,1451,1456,1461,1466,1471,1481,1490,1499,1508,1517,1526,1535,1544,1553],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"Arhitektura enterprise AI je arhitektura na nivou cele organizacije koja je potrebna kada AI postane deo stvarnih sistema, podataka, odluka i operacija kompanije. Model je samo jedna komponenta. Kada se AI poveže sa enterprise podacima, identitetima, dozvolama, poslovnim procesima, eksternim provajderima i produkcionim sistemima, arhitektura mora takođe da definiše autoritet nad podacima, granice pristupa, vlasništvo nad rizikom, zavisnosti od provajdera, proverljivost, evaluaciju, kontrolu životnog ciklusa, usklađenost i operativnu odgovornost. Enterprise AI se stoga razlikuje i od pojedinačnog AI rešenja i od zajedničke AI platforme: ona koordinira kako se mnogi AI-omogućeni sistemi uklapaju u širu organizaciju.","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct-answer",{"body":223,"title":224,"variant":225},"\u003Cstrong>Šta se menja kada AI uđe u kompaniju?\u003C\u002Fstrong> Postojeće odgovornosti enterprise arhitekture se šire tako da uključuju probabilističko ponašanje modela, nove tokove podataka, pretragu i utemeljenje, zavisnosti od modela\u002Fprovajdera, AI-specifičnu evaluaciju, autoritet agenata\u002Falata, životni ciklus modela i promptova, upravljanje AI rizikom, obaveze transparentnosti i nove operativne načine otkaza. Arhitektura mora da poveže ove aspekte sa postojećim strukturama kompanije za identitet, bezbednost, podatke, nabavku, isporuku i upravljanje, umesto da stvori paralelni „AI univerzum“.","Direktan odgovor","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"not-bigger-chatbot",{"body":231,"title":232,"variant":233},"Chatbot može biti korisnički interfejs. Enterprise AI arhitektura je sistem granica iza njega: kojim podacima AI sme da pristupi, koji izvor je merodavan, ko sme da koristi koju mogućnost, da li eksterni provajderi smeju da prime podatke, koje radnje agent sme da izvrši, kako se izlazi evaluiraju, šta mora da se loguje, ko je vlasnik incidenata i kako se promene odobravaju i vraćaju.","Enterprise AI nije „veći chatbot“","warning",{},{"id":236,"data":237,"type":226,"tunes":241},"current-date",{"body":238,"title":239,"variant":240},"Arhitektonski principi u ovom članku imaju za cilj da budu stabilni. Regulativa, standardi i mogućnosti provajdera zavise od verzije. ISO\u002FIEC 42001:2023 i ISO\u002FIEC 23894:2023 su trenutno objavljeni standardi. NIST navodi da se AI RMF 1.0 revidira. Prema trenutnom konsolidovanom tekstu EU AI Act, Uredba se generalno primenjuje od 2. avgusta 2026, dok određene odredbe za visokorizične sisteme imaju kasnije datume primene. Pravna klasifikacija se uvek mora proveriti prema važećem zakonu i konkretnom slučaju upotrebe.","Napomena o aktuelnim izvorima — 8. oktobar 2026.","note",{},{"id":243,"data":244,"type":248,"tunes":249},"toc",{"title":245,"maxLevel":246,"minLevel":247},"Sadržaj",3,2,"tableOfContents",{},{"id":251,"data":252,"type":42,"tunes":254},"h-meaning",{"text":253,"level":247},"Šta enterprise AI arhitektura zaista znači",{},{"id":256,"data":257,"type":218,"tunes":259},"p-meaning-1",{"text":258},"Enterprise AI arhitektura opisuje kako se AI mogućnosti integrišu u postojeću organizaciju bez kršenja granica koje enterprise sisteme već čine upravljivim: poslovno vlasništvo, identitet, autorizacija, klasifikacija podataka, odgovornost sistema evidencije, upravljanje promenama, nabavka, revizija, kontinuitet i operacije.",{},{"id":261,"data":262,"type":218,"tunes":264},"p-meaning-2",{"text":263},"Enterprise arhitekta ne zamenjuje AI Solution Architect ili AI Platform Architect. Enterprise obim postavlja drugačije pitanje: Kako se više AI rešenja i zajedničkih AI mogućnosti uklapaju u ciljnu arhitekturu, politike, pejzaž podataka, model rizika i operativni model kompanije?",{},{"id":266,"data":267,"type":218,"tunes":269},"p-meaning-3",{"text":268},"To čini enterprise AI arhitekturu disciplinom koordinacije kroz tehnologiju i organizaciju. Tehnički dobra integracija modela i dalje može biti neuspeh enterprise arhitekture ako stvara tokove podataka u senci, duplira identitet, zaobilazi nabavku, ne može se revidirati, nema vlasnika ili se ne može bezbedno menjati.",{},{"id":271,"data":272,"type":303,"tunes":304},"scope-comparison",{"rows":273,"title":291,"layout":292,"columns":293},[274,279,283,287],{"id":275,"label":276,"values":277},"scope","Primarni obim",[278,278,278],"",{"id":280,"label":281,"values":282},"question","Primarno pitanje",[278,278,278],{"id":284,"label":285,"values":286},"ownership","Fokus vlasništva",[278,278,278],{"id":288,"label":289,"values":290},"success","Uslov uspeha",[278,278,278],"Arhitektura AI rešenja, platforme i enterprise AI su različiti obimi","table",[294,297,300],{"id":295,"label":296},"solution","Arhitektura AI rešenja",{"id":298,"label":299},"platform","Arhitektura AI platforme",{"id":301,"label":302},"enterprise","Enterprise AI arhitektura","comparison",{},{"id":306,"data":307,"type":42,"tunes":309},"h-simple",{"text":308,"level":247},"Najjednostavniji primer",{},{"id":311,"data":312,"type":218,"tunes":314},"p-simple-1",{"text":313},"Kompanija počinje sa jednim internim asistentom za dokumente. Prva verzija pretražuje odobrene dokumente i šalje pronađeni kontekst jezičkom modelu. Na nivou rešenja, to može izgledati jednostavno.",{},{"id":316,"data":317,"type":218,"tunes":319},"p-simple-2",{"text":318},"Zatim drugi tim želi AI za korisničku podršku. Treći želi agenta koji može da ažurira tikete. Finansije žele analizu dokumenata. HR želi internog asistenta. Programeri žele agente za kodiranje. Odjednom kompanija ima nekoliko provajdera, nekoliko klasa podataka, različite korisničke grupe, indekse pretrage koji se preklapaju, različita pravila logovanja, nove dozvole za alate, duplirane tajne i nejasno vlasništvo.",{},{"id":321,"data":322,"type":218,"tunes":324},"p-simple-3",{"text":323},"U tom trenutku, pitanje više nije „Da li asistent radi?“ Enterprise pitanje postaje: Koje su mogućnosti odobrene, ko je njihov vlasnik, koji podaci mogu da pređu koju granicu, kako se identiteti i dozvole sprovode, koji provajderi su prihvatljivi, šta mora da se revidira i kako organizacija može da menja modele ili dobavljače bez gubitka kontrole?",{},{"id":326,"data":327,"type":349,"tunes":350},"simple-flow",{"steps":328,"title":347,"orientation":348},[329,332,335,338,341,344],{"label":330,"description":331},"1. Izolovan slučaj upotrebe","Jedan tim povezuje jedan model sa jednim tokom rada i validira lokalnu vrednost.",{"label":333,"description":334},"2. Pojavljuju se zajedničke zavisnosti","Više timova zahteva provajdere, pristup modelima, pretragu, identitet, tajne, observabilnost i evaluaciju.",{"label":336,"description":337},"3. Prelaze se enterprise granice","AI dodiruje regulisane podatke, sisteme evidencije, eksterne dobavljače, privilegovane radnje i poslovne odluke.",{"label":339,"description":340},"4. Vlasništvo mora postati eksplicitno","Poslovanje, arhitektura, podaci, bezbednost, pravna služba\u002Fusklađenost, nabavka i operacije moraju imati definisane odgovornosti.",{"label":342,"description":343},"5. Životni ciklus postaje organizacioni","Promene modela, promptova, provajdera i novih mogućnosti agenata postaju upravljane promene, a ne lokalne izmene programera.",{"label":345,"description":346},"6. Arhitektura postaje ponovljiva","Organizacija uspostavlja obrasce koji se mogu ponovo koristiti, zapise o odlukama, kontrole, izuzetke i kapije validacije za nove AI radne zadatke.","Od izolovane AI funkcije do enterprise arhitekture","auto","processFlow",{},{"id":352,"data":353,"type":42,"tunes":355},"h-stop",{"text":354,"level":247},"Gde se jednostavan primer zaustavlja",{},{"id":357,"data":358,"type":218,"tunes":360},"p-stop-1",{"text":359},"Enterprise arhitektura ne znači da svaka AI komponenta mora biti centralizovana. Neke mogućnosti treba deliti; druge moraju ostati u vlasništvu domena. Finansije, HR, inženjering i korisnička podrška mogu legitimno zahtevati različite granice podataka, provajdere, kriterijume evaluacije i pravila ljudskog odobravanja.",{},{"id":362,"data":363,"type":218,"tunes":365},"p-stop-2",{"text":364},"Enterprise cilj stoga nije jedan model, jedna vektorska baza podataka ili jedan univerzalni asistent. Cilj je koherentna arhitektura sa eksplicitnim varijacijama: zajedničke politike i mogućnosti koje se mogu ponovo koristiti tamo gde smanjuju rizik i dupliranje, plus kontrolisani izuzeci tamo gde se poslovni ili regulatorni zahtevi razlikuju.",{},{"id":367,"data":368,"type":42,"tunes":370},"h-layers",{"text":369,"level":247},"Šta se menja u arhitekturi kada AI uđe u preduzeće",{},{"id":372,"data":373,"type":42,"tunes":375},"h-business",{"text":374,"level":246},"1. Vlasništvo nad poslom postaje deo tehničke arhitekture",{},{"id":377,"data":378,"type":218,"tunes":380},"p-business-1",{"text":379},"Tradicionalne aplikacije već zahtevaju vlasnike iz poslovnog domena. AI čini taj zahtev vidljivijim jer prihvatljivo ponašanje ne može biti definisano samo kroz dostupnost i funkcionalnu ispravnost. Neko mora biti odgovoran za nameravanu upotrebu, neprihvatljivu upotrebu, kvalitet izlaza, put eskalacije i posledice pogrešnih ili neprikladnih rezultata.",{},{"id":382,"data":383,"type":218,"tunes":385},"p-business-2",{"text":384},"Model tim ne može sam da odluči da li je odgovor prihvatljiv za HR, finansije, pravni sektor ili upotrebu prema klijentima. Arhitektura AI u preduzeću stoga povezuje tehnički dizajn sa eksplicitnom poslovnom sposobnošću, odgovornim vlasnikom, grupom korisnika i kontekstom odlučivanja.",{},{"id":387,"data":388,"type":42,"tunes":390},"h-data-authority",{"text":389,"level":246},"2. Pristup podacima nije dovoljan — nadležnost nad podacima mora biti definisana",{},{"id":392,"data":393,"type":218,"tunes":395},"p-data-authority-1",{"text":394},"AI u preduzeću često kombinuje operativne baze podataka, dokumente, indekse pretrage, vektorske baze, skladišta podataka, SaaS sisteme i eksterno znanje. Arhitektura mora da razlikuje gde su informacije uskladištene od toga koji je izvor nadležan za datu tvrdnju ili radnju.",{},{"id":397,"data":398,"type":218,"tunes":400},"p-data-authority-2",{"text":399},"Vektorski indeks može da poboljša pronalaženje, ali ne bi trebalo tiho da postane zvanični sistem evidencije kompanije. Odgovor modela može da sumira ERP zapis, ali ne bi trebalo da zameni ERP kao nadležni izvor. Keširani kontekst može da poboljša latenciju, ali postaje nesiguran kada se promene dozvole ili osnovno poslovno stanje.",{},{"id":402,"data":403,"type":218,"tunes":405},"p-data-authority-3",{"text":404},"AI u preduzeću stoga zahteva poreklo, svežinu, klasifikaciju izvora, propagaciju autorizacije i pravila poništavanja pored obične integracije podataka.",{},{"id":407,"data":408,"type":226,"tunes":411},"authority-rule",{"body":409,"title":410,"variant":288},"\u003Cstrong>AI sistem može da transformiše, pronalazi i zaključuje na osnovu podataka preduzeća, a da pritom ne postane nadležan za te podatke.\u003C\u002Fstrong> Arhitektura treba da očuva put nazad do nadležnog izvora kad god slučaj upotrebe zahteva dokaz, verifikaciju ili radnju sa posledicama.","Pravilo za podatke u preduzeću",{},{"id":413,"data":414,"type":42,"tunes":416},"h-identity",{"text":415,"level":246},"3. Identitet postaje višeslojan",{},{"id":418,"data":419,"type":218,"tunes":421},"p-identity-1",{"text":420},"AI u preduzeću ima više identiteta nego ljudski korisnik. Zahtev može da uključi identitet korisnika, identitet aplikacije, identitet servisa, identitet agenta, akreditiv provajdera, akreditiv alata i kontekst zakupca ili organizacije.",{},{"id":423,"data":424,"type":218,"tunes":426},"p-identity-2",{"text":425},"Ovi identiteti ne bi trebalo da se spoje u jedan zajednički API ključ. Autorizacija mora da ostane pripisiva ispravnom principalu, a privilegovani alati bi trebalo da dobiju samo ovlašćenje potrebno za trenutnu operaciju.",{},{"id":428,"data":429,"type":218,"tunes":431},"p-identity-3",{"text":430},"Za agentne sisteme ovo postaje posebno važno: model može da predloži radnju, ali runtime mora da odluči da li identitet koji zahteva sme da je izvrši. Sposobnost modela nije autorizacija.",{},{"id":433,"data":434,"type":42,"tunes":436},"h-permissions",{"text":435,"level":246},"4. Dozvole prelaze sa pristupa sadržaju na ovlašćenje za radnju",{},{"id":438,"data":439,"type":218,"tunes":441},"p-permissions-1",{"text":440},"Asistent samo za čitanje uglavnom zahteva kontrolisan pristup informacijama. Agent u preduzeću može da kreira tikete, menja zapise, šalje poruke, pokreće tokove rada ili upravlja eksternim sistemima. To uvodi drugačiju klasu rizika jer sistem može da menja stanje, a ne samo da ga opisuje.",{},{"id":443,"data":444,"type":218,"tunes":446},"p-permissions-2",{"text":445},"Arhitektura treba da razdvoji mogućnosti čitanja, pisanja, odobravanja i administracije; definiše tačke uključivanja čoveka u proces tamo gde posledice to opravdavaju; i očuva revizorski trag koji identifikuje šta je zatraženo, šta je odobreno i šta je zaista promenjeno.",{},{"id":448,"data":449,"type":42,"tunes":451},"h-provider",{"text":450,"level":246},"5. AI provajder postaje zavisnost preduzeća",{},{"id":453,"data":454,"type":218,"tunes":456},"p-provider-1",{"text":455},"Pozivanje API-ja modela je takođe odnos sa dobavljačem. Arhitektura može da zavisi od dostupnosti provajdera, uslova pružanja usluge, uslova obrade podataka, podržanih regiona, životnog ciklusa modela, kvota, cena, kompatibilnosti API-ja, bezbednosnih kontrola i obaveštenja o promenama.",{},{"id":458,"data":459,"type":218,"tunes":461},"p-provider-2",{"text":460},"To znači da izbor provajdera nije samo odluka o benchmarku. Nabavka, bezbednost, privatnost, pravna revizija, planiranje kontinuiteta i strategija izlaska mogu postati arhitektonski ulazi.",{},{"id":463,"data":464,"type":218,"tunes":466},"p-provider-3",{"text":465},"Apstrakcija provajdera može smanjiti spreganje, ali samo tamo gde su osnovne mogućnosti zaista prenosive. Korišćenje alata, strukturirani izlaz, ograničenja konteksta, multimodalnost, bezbednosne kontrole, fino podešavanje i funkcije hostovanih agenata mogu se značajno razlikovati između provajdera.",{},{"id":468,"data":469,"type":42,"tunes":471},"h-risk",{"text":470,"level":246},"6. AI rizik postaje proces životnog ciklusa",{},{"id":473,"data":474,"type":218,"tunes":476},"p-risk-1",{"text":475},"AI rizik se ne završava jednim odobrenjem pre lansiranja. Model, upit, korpus za preuzimanje, skup alata, provajder, korisnička populacija i okolni poslovni proces mogu se promeniti nakon implementacije. Profil rizika se menja sa njima.",{},{"id":478,"data":479,"type":218,"tunes":481},"p-risk-2",{"text":480},"ISO\u002FIEC 23894:2023 eksplicitno se bavi integracijom upravljanja AI rizikom u organizacione aktivnosti i funkcije. NIST AI RMF na sličan način definiše upravljanje rizikom kroz životni ciklus. Enterprise arhitektura bi stoga trebalo da učini reviziju rizika delom promena i operacija, a ne izolovanim dokumentom o usklađenosti.",{},{"id":483,"data":484,"type":218,"tunes":486},"p-risk-3",{"text":485},"Rizik takođe treba da bude proporcionalan. Asistent za sumiranje i autonomni sistem koji menja proizvodne zapise ne bi trebalo da dobiju identične kontrole samo zato što oba koriste LLM.",{},{"id":488,"data":489,"type":42,"tunes":491},"h-management-system",{"text":490,"level":246},"7. Upravljanje postaje operativni sistem, a ne PDF sa politikama",{},{"id":493,"data":494,"type":218,"tunes":496},"p-management-system-1",{"text":495},"ISO\u002FIEC 42001:2023 definiše zahteve za uspostavljanje, implementaciju, održavanje i kontinuirano poboljšanje AI sistema upravljanja. Arhitektonska posledica je važna: upravljanje mora povezati politiku sa stvarnim inventarima, vlasništvom, procesima, kontrolama, dokazima, revizijama i ciklusima poboljšanja.",{},{"id":498,"data":499,"type":218,"tunes":501},"p-management-system-2",{"text":500},"Enterprise AI politika koja nije povezana sa odobravanjem provajdera, identitetom, evidentiranjem, upravljanjem promenama, evaluacijom i odgovorom na incidente ima ograničen arhitektonski efekat. Organizaciji su potrebni mehanizmi koji politiku čine sprovodivom ili barem vidljivom.",{},{"id":503,"data":504,"type":42,"tunes":506},"h-eval",{"text":505,"level":246},"8. Evaluacija postaje proizvodna kontrola",{},{"id":508,"data":509,"type":218,"tunes":511},"p-eval-1",{"text":510},"Tradicionalno prijemno testiranje pretpostavlja da isti ulaz obično proizvodi isti deterministički rezultat. Generativna AI može biti nedeterministička, osetljiva na kontekst i zavisna od promenljivog spoljnog znanja. Proizvodno prihvatanje stoga zahteva evaluacije specifične za zadatak, regresione skupove i vidljive pragove, a ne samo unit testove.",{},{"id":513,"data":514,"type":218,"tunes":516},"p-eval-2",{"text":515},"Platforma može obezbediti infrastrukturu za evaluaciju koja se može ponovo koristiti, ali enterprise i dalje mora imati vlasništvo nad domenskom osnovnom istinom i kapijama za izdavanje. Centralni AI tim ne može izmisliti tačan odgovor za svaki poslovni domen.",{},{"id":518,"data":519,"type":218,"tunes":521},"p-eval-3",{"text":520},"Promene modela, upita, preuzimanja i alata treba da budu sledljive do dokaza o evaluaciji tamo gde promena može materijalno uticati na ponašanje izlaza.",{},{"id":523,"data":524,"type":42,"tunes":526},"h-observability",{"text":525,"level":246},"9. Vidljivost mora uključivati ponašanje, podatke i kontekst modela",{},{"id":528,"data":529,"type":218,"tunes":531},"p-observability-1",{"text":530},"CPU, memorija i stope HTTP grešaka nisu dovoljni za AI radna opterećenja. Proizvodna vidljivost može zahtevati identifikatore modela\u002Fprovajdera, latenciju, korišćenje tokena, troškove, rezultate preuzimanja, pozive alata, ponašanje odbijanja, ocene evaluacije, bezbednosne događaje i klasifikacije kvarova.",{},{"id":533,"data":534,"type":218,"tunes":536},"p-observability-2",{"text":535},"Istovremeno, AI telemetrija može sadržati osetljive podatke. Evidencije upita i odgovora mogu postati skriveno skladište podataka. Enterprise arhitektura stoga mora definisati šta se može evidentirati, kako se rediguje, ko može pristupiti, koliko dugo se čuva i kada se detaljno praćenje mora onemogućiti.",{},{"id":538,"data":539,"type":42,"tunes":541},"h-lifecycle",{"text":540,"level":246},"10. AI komponente zahtevaju eksplicitno vlasništvo nad životnim ciklusom",{},{"id":543,"data":544,"type":218,"tunes":546},"p-lifecycle-1",{"text":545},"Modeli mogu biti preimenovani, zamenjeni, ukinuti ili promenjeni od strane provajdera. Modeli za ugrađivanje mogu poništiti strategiju indeksiranja. Šabloni upita i sistemska uputstva mogu promeniti ponašanje. Runtime okruženja i protokoli agenata mogu evoluirati. Spoljni alati mogu promeniti svoje šeme i dozvole.",{},{"id":548,"data":549,"type":218,"tunes":551},"p-lifecycle-2",{"text":550},"Enterprise arhitektura mora da odluči ko detektuje ove promene, ko ih testira, ko ih odobrava, kako se potrošači obaveštavaju, kako funkcioniše vraćanje na prethodno stanje i koji dokazi su potrebni pre nego što nova verzija postane podrazumevana.",{},{"id":553,"data":554,"type":42,"tunes":556},"h-operations",{"text":555,"level":246},"11. Reagovanje na incidente mora uključivati specifične načine otkaza AI sistema",{},{"id":558,"data":559,"type":218,"tunes":561},"p-operations-1",{"text":560},"AI incident može biti prekid rada provajdera, curenje podataka, put prompt-injection napada, neuspeh autorizacije, kontaminacija pretrage, neočekivano ponašanje modela, nesigurno izvršavanje alata, skok troškova, zastarelo znanje, regresija evaluacije ili promena u ponašanju eksternog modela.",{},{"id":563,"data":564,"type":218,"tunes":566},"p-operations-2",{"text":565},"Enterprise runbook stoga zahteva više od „restartuj servis“. Može zahtevati onemogućavanje rute modela, opozivanje pristupa alatima, zamrzavanje korpusa, promenu verzije prompta, onemogućavanje sposobnosti agenta, promenu provajdera, eskalaciju do vlasnika domene ili čuvanje tragova za istragu.",{},{"id":568,"data":569,"type":42,"tunes":571},"h-ownership",{"text":570,"level":247},"Enterprise AI stvara vlasništvo koje se proteže kroz više funkcija",{},{"id":573,"data":574,"type":292,"tunes":620},"ownership-table",{"content":575,"stretched":43,"withHeadings":14},[576,580,584,588,592,596,600,604,608,612,616],[577,578,579],"Aspekt","Tipičan enterprise vlasnik ili saradnik","Arhitektonsko pitanje",[581,582,583],"Poslovna upotreba","Poslovni vlasnik \u002F vlasnik proizvoda","Koju odluku ili tok posla AI sme da podrži ili automatizuje?",[585,586,587],"Arhitektura rešenja","AI \u002F arhitekta rešenja","Kako konkretno radno opterećenje ispunjava svoje funkcionalne i kvalitativne zahteve?",[589,590,591],"Deljene AI sposobnosti","AI platforma \u002F platformski inženjering","Koji usluge modela, pretrage, agenata i observabilnosti se pružaju kao ponovo upotrebljive?",[593,594,595],"Enterprise usklađenost","Enterprise arhitektura","Kako se AI sistemi uklapaju u ciljnu arhitekturu, standarde, obrasce integracije i organizaciono vlasništvo?",[597,598,599],"Nadležnost nad podacima","Vlasnik podataka \u002F vlasnik domene","Koji podaci su merodavni, aktuelni, dozvoljeni i dovoljno kontrolisani?",[601,602,603],"Identitet i bezbednost","IAM \u002F bezbednosna arhitektura","Koji identiteti mogu pristupiti kojim podacima i izvršiti koje radnje?",[605,606,607],"Rizik i usklađenost","Rizik \u002F pravni \u002F usklađenost \u002F privatnost","Koje obaveze, zabranjene upotrebe, kontrole i dokazi se primenjuju na ovaj slučaj upotrebe?",[609,610,611],"Zavisnost od dobavljača","Nabavka \u002F upravljanje dobavljačima \u002F arhitektura","Koji ugovorni, operativni i rizici izlaska proizlaze iz provajdera?",[613,614,615],"Operacije","SRE \u002F operacije \u002F vlasnik platforme","Kako se sistem prati, podržava, degradira, oporavlja i menja?",[617,618,619],"Prihvatanje u domeni","Poslovni\u002Fdomenski specijalisti","Šta se smatra ispravnim, bezbednim ili korisnim rezultatom u ovoj domeni?",{},{"id":622,"data":623,"type":226,"tunes":626},"ownership-warning",{"body":624,"title":625,"variant":233},"Matrice odgovornosti su korisne samo kada su povezane sa stvarnim granicama sistema, odobrenjima, vlasništvom nad podacima, interfejsima, runbook-ovima i procesima promene. Enterprise AI zahteva odgovorno vlasništvo koje se može pratiti do tehničkih kontrola i operativnih radnji.","RACI tabela sama po sebi nije arhitektura",{},{"id":628,"data":629,"type":42,"tunes":631},"h-model",{"text":630,"level":247},"Praktičan model enterprise AI arhitekture",{},{"id":633,"data":634,"type":226,"tunes":637},"model-note",{"body":635,"title":636,"variant":240},"Sledeći model je praktična sinteza za razmišljanje o enterprise AI arhitekturi. Nije predstavljen kao ISO ili NIST standard. Njegova svrha je da učini granice između organizacija eksplicitnim.","Predloženi slojeviti model",{},{"id":639,"data":640,"type":292,"tunes":669},"enterprise-model-table",{"content":641,"stretched":43,"withHeadings":14},[642,645,648,651,654,657,660,663,666],[643,644],"Sloj","Primarna odgovornost",[646,647],"Poslovanje i politika","Odobreni slučajevi upotrebe, odgovorni vlasnici, apetit za rizik, zabranjene upotrebe, ljudska odgovornost, poslovno prihvatanje.",[649,650],"Identitet i ovlašćenje","Identiteti korisnika\u002Fservisa\u002Fagenata, uloge, opseg zakupca ili organizacije, privilegovane radnje, putevi odobravanja.",[652,653],"Enterprise podaci","Sistemi evidencije, izvori dokumenata, podaci kao proizvodi, poreklo, klasifikacija, zadržavanje, svežina i pristup.",[655,656],"AI platforma","Pristup provajderu\u002Fmodelu, primitive pretrage, runtime okruženja agenata, brokeri alata, infrastruktura za evaluaciju, observabilnost, kvote i tajne.",[658,659],"AI rešenja","Domenski tokovi posla, promptovi\u002Finstrukcije, domenska pretraga, poslovna logika, kriterijumi prihvatanja i korisničko iskustvo.",[661,662],"Integracija i alati","API-ji, enterprise aplikacije, tokovi posla, razmena poruka, fajl sistemi, eksterne usluge i izvršavanje radnji.",[664,665],"Rizik i upravljanje","Inventar, procena, dokazi o usklađenosti, upravljanje izuzecima, odobravanje modela\u002Fprovajdera, pregled i revizija.",[667,668],"Operacije i životni ciklus","Postavljanje, praćenje, incidenti, izdanja, promene modela\u002Fprovajdera, ukidanje, vraćanje na prethodno stanje i kontinuitet.",{},{"id":671,"data":672,"type":218,"tunes":674},"p-model-1",{"text":673},"Arhitektura je najjača kada svaki sloj može da navede i svoje odgovornosti i svoje ne-odgovornosti. Na primer, AI platforma može da sprovodi politiku provajdera i prikuplja tragove, a da ne postane izvor istine za HR podatke. Rešenje može da definiše domenske promptove, a da ne poseduje enterprise IAM. Poslovni vlasnik može da odobri slučaj upotrebe, a da se od njega ne očekuje da upravlja inference gateway-om.",{},{"id":676,"data":677,"type":42,"tunes":679},"h-data-flow",{"text":678,"level":247},"Mapirajte enterprise AI kao tokove podataka i ovlašćenja, a ne kao kutije",{},{"id":681,"data":682,"type":349,"tunes":709},"enterprise-flow",{"steps":683,"title":708,"orientation":348},[684,687,690,693,696,699,702,705],{"label":685,"description":686},"1. Poslovni kontekst","Korisnik zahteva zadatak u okviru odobrenog slučaja upotrebe sa odgovornim poslovnim vlasnikom.",{"label":688,"description":689},"2. Identitet i autorizacija","Sistem razrešava korisnika, aplikaciju, servis i opseg zakupca ili organizacije pre privilegovanog pristupa.",{"label":691,"description":692},"3. Pribavljanje merodavnih podataka","Rešenje čita ili pretražuje samo izvore dozvoljene za trenutni identitet i zadatak.",{"label":694,"description":695},"4. AI obrada","Odobreni model\u002Fprovajder obrađuje minimalno neophodan kontekst pod definisanim pravilima rutiranja i rukovanja podacima.",{"label":697,"description":698},"5. Granica alata ili radnje","Svaka radnja koja menja stanje je nezavisno autorizovana i može zahtevati ljudsko odobrenje u skladu sa posledicama.",{"label":700,"description":701},"6. Validacija","Rezultat se proverava prema pravilima prihvatanja, dokazima ili bezbednosti specifičnim za rešenje.",{"label":703,"description":704},"7. Revizija i observabilnost","Dozvoljeni metapodaci, odluke, rute, pozivi alata i ishodi se beleže bez stvaranja nekontrolisanih logova osetljivih podataka.",{"label":706,"description":707},"8. Povratna informacija i životni ciklus","Neuspesi i rezultati evaluacije hrane promene modela, promptova, podataka, politike i procesa kroz kontrolisano upravljanje promenama.","Enterprise AI zahtev sa posledicama",{},{"id":711,"data":712,"type":42,"tunes":714},"h-inventory",{"text":713,"level":247},"Enterprise mora imati AI inventar pre nego što može da upravlja AI sistemima",{},{"id":716,"data":717,"type":218,"tunes":719},"p-inventory-1",{"text":718},"Organizacije ne mogu da upravljaju AI sistemima koje ne mogu da identifikuju. Enterprise arhitektura treba da održava inventar na nivou koji je koristan za odluke, a ne samo listu imena modela.",{},{"id":721,"data":722,"type":292,"tunes":760},"inventory-table",{"content":723,"stretched":43,"withHeadings":14},[724,727,730,733,736,739,742,745,748,751,754,757],[725,726],"Polje inventara","Zašto je važno",[728,729],"Slučaj upotrebe i vlasnik","Povezuje tehnologiju sa odgovornom poslovnom svrhom.",[731,732],"Korisnici i pogođene strane","Definiše ko interaguje sa sistemom ili je njime pogođen.",[734,735],"Model\u002Fprovajder","Identifikuje eksternu zavisnost, sposobnost i rizik životnog ciklusa.",[737,738],"Izvori podataka","Podržava proveru nadležnosti, privatnosti, klasifikacije i porekla.",[740,741],"Lokacija postavljanja\u002Fruntime-a","Razjašnjava lokaciju obrade, povezivost i operativnu kontrolu.",[743,744],"Alati\u002Fradnje","Pokazuje da li AI može da promeni eksterno stanje i sa kojim posledicama.",[746,747],"Ljudski nadzor","Beleži gde je potreban pregled, odobrenje ili eskalacija.",[749,750],"Rizik\u002Fklasifikacija","Povezuje sistem sa organizacionim i regulatornim kontrolama.",[752,753],"Dokazi o evaluaciji","Pokazuje šta je testirano i pod kojim uslovima validnosti.",[755,756],"Trenutna verzija","Omogućava da se incidenti i regresije prate do stvarnog stanja u produkciji.",[758,759],"Stanje životnog ciklusa","Predloženo, eksperimentalno, odobreno, produkcija, ograničeno, ukinuto ili povučeno.",{},{"id":762,"data":763,"type":42,"tunes":765},"h-governance",{"text":764,"level":247},"AI upravljanje i enterprise AI arhitektura su povezani, ali nisu isto",{},{"id":767,"data":768,"type":303,"tunes":789},"governance-comparison",{"rows":769,"title":782,"layout":292,"columns":783},[770,774,778],{"id":771,"label":772,"values":773},"purpose","Svrha",[278,278],{"id":775,"label":776,"values":777},"example","Primer",[278,278],{"id":779,"label":780,"values":781},"failure","Neuspeh ako je izolovano",[278,278],"Upravljanje naspram arhitekture",[784,787],{"id":785,"label":786},"governance","AI upravljanje",{"id":788,"label":302},"architecture",{},{"id":791,"data":792,"type":42,"tunes":794},"h-regulation",{"text":793,"level":247},"Regulativa postaje ulazni parametar arhitekture",{},{"id":796,"data":797,"type":218,"tunes":799},"p-regulation-1",{"text":798},"Za organizacije koje posluju u Evropskoj uniji, AI Act može stvoriti zahteve koji utiču na dizajn sistema, dokumentaciju, transparentnost, upravljanje i operativne procese. Arhitektonski uticaj zavisi od uloge organizacije u AI lancu vrednosti i konkretne klasifikacije sistema; nema svaki AI sistem iste obaveze.",{},{"id":801,"data":802,"type":218,"tunes":804},"p-regulation-2",{"text":803},"Od 8. oktobra 2026, trenutni konsolidovani tekst navodi da se Regulativa generalno primenjuje od 2. avgusta 2026. Pravila upravljanja i obaveze za modele opšte namene počeli su da se primenjuju ranije, dok određene odredbe za sisteme visokog rizika imaju kasnije datume. Komisija je takođe počela da sprovodi nove zahteve transparentnosti od 2. avgusta 2026. za relevantne interaktivne sisteme i sisteme sintetičkog sadržaja.",{},{"id":806,"data":807,"type":218,"tunes":809},"p-regulation-3",{"text":808},"Lekcija za arhitekturu preduzeća nije „staviti usklađenost u model“. Već učiniti klasifikaciju, ulogu pružaoca\u002Fkorisnika, dokumentaciju, transparentnost, nadzor, evidentiranje i dokaze o promenama sledljivim do sistema koji zaista implementira slučaj upotrebe.",{},{"id":811,"data":812,"type":226,"tunes":815},"legal-note",{"body":813,"title":814,"variant":240},"Ovaj članak opisuje arhitektonske implikacije, a ne pravni savet. Arhitektura AI u preduzeću treba da sačuva informacije potrebne pravnim i compliance stručnjacima da klasifikuju stvarni sistem i mapiraju obaveze na konkretne kontrole. Arhitektura ne treba da ugrađuje jedno regulatorno tumačenje kao da svaki AI radni zadatak ima isti status.","Pravni obim zavisi od slučaja upotrebe",{},{"id":817,"data":818,"type":42,"tunes":820},"h-procurement",{"text":819,"level":247},"Nabavka i arhitektura postaju povezane",{},{"id":822,"data":823,"type":218,"tunes":825},"p-procurement-1",{"text":824},"Spoljni model ili upravljana AI platforma može postati duboka zavisnost čak i kada integracija zahteva samo nekoliko API poziva. Arhitektura preduzeća zato treba da učini pitanja nabavke tehnički konkretnim.",{},{"id":827,"data":828,"type":292,"tunes":857},"procurement-table",{"content":829,"stretched":43,"withHeadings":14},[830,833,836,839,842,845,848,851,854],[831,832],"Pitanje nabavke","Arhitektonska posledica",[834,835],"Gde se podaci obrađuju?","Region, mrežna putanja, rezidentnost podataka i kontrole prenosa.",[837,838],"Da li se podaci korisnika čuvaju ili koriste za poboljšanje kod pružaoca?","Minimizacija podataka, ugovorne kontrole i podobnost pružaoca.",[840,841],"Kako se modeli verzioniraju ili povlače?","Regresiono testiranje, kompatibilnost, rezervni plan i planiranje životnog ciklusa.",[843,844],"Koji su kvote i ograničenja usluge?","Arhitektura kapaciteta, kontrola prijema i rukovanje otkazima.",[846,847],"Koliko je integracija prenosiva?","Apstrakcija pružaoca, trošak izlaska i napor migracije.",[849,850],"Koje informacije o incidentima su dostupne?","Opservabilnost, forenzičke mogućnosti i eskalacija podrške.",[852,853],"Koji podprocesori ili spoljne usluge su uključeni?","Mapiranje zavisnosti i procena rizika.",[855,856],"Šta se menja bez izričitog odobrenja korisnika?","Detekcija promena, kapije izdanja i strategija prihvatanja.",{},{"id":859,"data":860,"type":42,"tunes":862},"h-control",{"text":861,"level":247},"Arhitektura preduzeća odlučuje koliko kontrole nad AI zahtev zaista zahteva",{},{"id":864,"data":865,"type":292,"tunes":888},"control-table",{"content":866,"stretched":43,"withHeadings":14},[867,870,873,876,879,882,885],[868,869],"Zahtev","Mogući arhitektonski odgovor",[871,872],"Brz pristup upravljanim modelima","Upravljani pružalac sa identitetom preduzeća, kontrolama mrežnog prolaza i ugovornim pregledom.",[874,875],"Privatni podaci sa upravljanom orkestracijom","Upravljana kontrolna ravan plus izvršavanje pod kontrolom korisnika ili privatna ravan podataka gde je podržano.",[877,878],"Stroga lokalnost ili suverenost","Region-restriktivna, suverena, privatna ili samo-hostovana arhitektura u skladu sa stvarnim zahtevom.",[880,881],"Vazdušno izolovano okruženje","Lokalno hostovani modeli, lokalno pretraživanje, lokalni alati, vanmrežno ažuriranje\u002Fdistribucija i izolovana opservabilnost.",[883,884],"Prenosivost između pružalaca","Stanje domena u vlasništvu aplikacije plus adapteri i ugovori koji izoluju ponašanje specifično za pružaoca gde je praktično.",[886,887],"Najviša kontrola nad semantikom agenata","Samo-upravljano ili duboko kontrolisano izvršno okruženje sa izričitim vlasništvom nad alatima, kontekstom, stanjem i životnim ciklusom.",{},{"id":890,"data":891,"type":218,"tunes":893},"p-control-1",{"text":892},"Najkontrolisanija arhitektura nije automatski najbolja arhitektura preduzeća. Veće vlasništvo povećava odgovornost za zakrpe, kapacitet, bezbednost, testiranje, operacije modela i odgovor na incidente. Arhitektura preduzeća treba da poveća kontrolu samo tamo gde zahtev opravdava dodatni operativni teret.",{},{"id":895,"data":896,"type":42,"tunes":898},"h-change-management",{"text":897,"level":247},"AI pretvara upravljanje promenama u problem ponašanja",{},{"id":900,"data":901,"type":218,"tunes":903},"p-change-1",{"text":902},"Uobičajeno ažuriranje zavisnosti može promeniti performanse ili kompatibilnost. AI promena može takođe promeniti ponašanje. Zamena modela, promena sistemskog upita, promena pretraživanja, dodavanje alata ili promena politike konteksta može izmeniti način na koji sistem tumači i odgovara čak i ako se okolni aplikativni kod jedva menja.",{},{"id":905,"data":906,"type":349,"tunes":933},"change-process",{"steps":907,"title":932,"orientation":348},[908,911,914,917,920,923,926,929],{"label":909,"description":910},"1. Promena identifikovana","Predlaže se ili detektuje promena modela, pružaoca, upita, izvora pretraživanja, alata, politike ili izvršnog okruženja.",{"label":912,"description":913},"2. Uticaj mapiran","Identifikuju se pogođena rešenja, klase podataka, korisnici, kontrole rizika, troškovi, ugovori i operativne zavisnosti.",{"label":915,"description":916},"3. Arhitektonska odluka ažurirana","Materijalni izbori i kompromisi se beleže; zamenjene odluke ostaju istorijski sledljive.",{"label":918,"description":919},"4. Evaluacija sprovedena","Pokreću se relevantni regresioni, bezbednosni, testovi pretraživanja, latencije, troškova i domena.",{"label":921,"description":922},"5. Odobrenje primenjeno","Nivo odobrenja prati posledice, rizik i organizacionu politiku.",{"label":924,"description":925},"6. Kontrolisano uvođenje","Verzionirano izdanje, kanarinac ili fazno uvođenje se koristi gde je prikladno.",{"label":927,"description":928},"7. Prikupljeni dokazi iz produkcije","Telemetrija, incidenti, povratne informacije i ishodi domena se prate.",{"label":930,"description":931},"8. Povratak ili prihvatanje","Promena se prihvata, ograničava, povlači ili zamenjuje na osnovu dokaza.","Put promene AI u produkciji",{},{"id":935,"data":936,"type":42,"tunes":938},"h-nfr-adr",{"text":937,"level":247},"AI u preduzeću i dalje zahteva NFR i ADR",{},{"id":940,"data":941,"type":218,"tunes":943},"p-nfr-adr-1",{"text":942},"AI ne zamenjuje običnu arhitektonsku disciplinu. Nefunkcionalni zahtevi ostaju ciljni uslovi: dostupnost, latencija, privatnost, izolacija, revizibilnost, oporavak, granice troškova, objašnjivost ili drugi zahtevi kvaliteta. Zapisnici o arhitektonskim odlukama čuvaju izabrani odgovor i njegove kompromise.",{},{"id":945,"data":946,"type":218,"tunes":948},"p-nfr-adr-2",{"text":947},"AI-specifična razlika je da se neki atributi kvaliteta moraju evaluirati probabilistički ili empirijski. „Odgovori moraju biti korisni“ je previše neodređeno. Produkcijski zahtev treba da identifikuje zadatak, podatke, korisničku populaciju, prihvatljive uslove neuspeha, metodu merenja i prag gde je praktično.",{},{"id":950,"data":951,"type":226,"tunes":954},"nfr-adr-chain",{"body":952,"title":953,"variant":288},"\u003Cstrong>Poslovna potreba → zahtev \u002F NFR → arhitektonska odluka → implementacija → evaluacija \u002F validacija → posmatranje u produkciji → odluka o promeni.\u003C\u002Fstrong> AI dodaje nove varijable u ovaj lanac; ne čini lanac nepotrebnim.","Lanac sledljivosti u preduzeću",{},{"id":956,"data":957,"type":42,"tunes":959},"h-delivery",{"text":958,"level":247},"Arhitektura enterprise AI mora biti povezana sa isporukom",{},{"id":961,"data":962,"type":218,"tunes":964},"p-delivery-1",{"text":963},"Arhitektura koja nikada ne stigne do backlog-a, implementacije, prihvatanja i operacija ostaje konceptualna. Enterprise AI zato zahteva sledljivost od arhitektonskih odluka do rada na isporuci i nazad od dokaza iz implementacije do arhitekture.",{},{"id":966,"data":967,"type":218,"tunes":969},"p-delivery-2",{"text":968},"Jira i Confluence su primeri alata koji mogu podržati ovo razdvajanje kada se koriste namerno: Confluence može da čuva zahteve, arhitekturu, odluke, rizike i obrazloženja; Jira može da upravlja izvršnim radom na isporuci i stanjem. Važan princip je sledljivost, a ne brend alata.",{},{"id":971,"data":972,"type":42,"tunes":974},"h-original",{"text":973,"level":247},"Dokazi originalnog projekta: Enterprise Aaasaasa 0.1",{},{"id":976,"data":977,"type":226,"tunes":980},"original-evidence-note",{"body":978,"title":979,"variant":240},"Enterprise Aaasaasa 0.1 se ovde koristi kao dokaz originalnog projekta za strukturisano enterprise arhitektonsko i isporučno razmišljanje. To je PoC \u002F enterprise kontekst projekta, a ne dokaz masovnog usvajanja od strane kupaca, enterprise produkcijske upotrebe ili komercijalne trakcije.","Dokaz projekta, a ne tvrdnja dokazana na tržištu",{},{"id":982,"data":983,"type":218,"tunes":985},"p-enterprise-aaasaasa-1",{"text":984},"Enterprise Aaasaasa 0.1 kombinuje arhitekturu platforme, SaaS\u002FAPI koncepte, internacionalizaciju, AI integraciju i strukturisano upravljanje projektom. Projekat je namerno organizovan tako da su zahtevi, arhitektura, isporuka prototipa, validacija i zatvaranje bili odvojeni miljokazi, a ne jedna nediferencirana faza implementacije.",{},{"id":987,"data":988,"type":218,"tunes":990},"p-enterprise-aaasaasa-2",{"text":989},"Arhitektonski pravac uključuje koncepte multi-instance \u002F multi-database zajedno sa API, CRUD, i18n i AI mogućnostima. To je važno za enterprise AI jer granice zakupaca ili instanci, vlasništvo nad bazom podataka i aplikacione usluge moraju ostati eksplicitne kada se dodaju AI funkcije.",{},{"id":992,"data":993,"type":218,"tunes":995},"p-enterprise-aaasaasa-3",{"text":994},"Struktura projekta je takođe tretirala kašnjenje arhitekture, širenje obima i brige o AI\u002Fzaštiti podataka kao projektne rizike, umesto da ih otkrije tek tokom implementacije. Zainteresovane strane su uključivale tehničke, bezbednosne, sponzorske\u002Fupravljačke i perspektive eksternih servisa, što je bliže stvarnoj unakrsno-funkcionalnoj prirodi enterprise AI nego prototip samo sa modelom.",{},{"id":997,"data":998,"type":218,"tunes":1000},"p-enterprise-aaasaasa-4",{"text":999},"Korisni dokaz je zato integracija arhitekture i isporuke: poslovna i projektna struktura, miljokazi, rizici, arhitektura, backend\u002FAPI, frontend\u002FAI rad, validacija i zatvaranje tretiraju se kao povezane odgovornosti. Taj obrazac je ponovo upotrebljiv iako sam projekat ne treba predstavljati kao dokaz eksternog enterprise usvajanja.",{},{"id":1002,"data":1003,"type":292,"tunes":1029},"enterprise-aaasaasa-table",{"content":1004,"stretched":43,"withHeadings":14},[1005,1008,1011,1014,1017,1020,1023,1026],[1006,1007],"Element projekta","Lekcija za enterprise AI arhitekturu",[1009,1010],"Miljokaz zahteva","AI sposobnost mora početi od definisane potrebe, obima, prihvatanja i ograničenja kvaliteta.",[1012,1013],"Miljokaz arhitekture","Podaci, API, granice instanci\u002Fbaza podataka i AI integracija su eksplicitan dizajnerski rad.",[1015,1016],"Miljokaz prototipa","Arhitektura mora postati dovoljno izvršna da otkrije rizike integracije.",[1018,1019],"Miljokaz validacije","Funkcionalni prototip nije isto što i validirano prihvatanje.",[1021,1022],"Registar rizika","Obim, kašnjenje arhitekture i brige o AI\u002Fzaštiti podataka upravljaju se kao rizici isporuke.",[1024,1025],"Struktura zainteresovanih strana","Enterprise AI obuhvata sponzora\u002Fposlovanje, arhitekturu, bezbednost, eksterne provajdere i isporuku.",[1027,1028],"Zatvaranje projekta","Odluke, preostali rizici i dokazi validacije moraju nadživeti implementacioni sprint.",{},{"id":1031,"data":1032,"type":42,"tunes":1034},"h-supporting",{"text":1033,"level":247},"Podržavajući obrasci implementacije iz šireg rada na platformi",{},{"id":1036,"data":1037,"type":218,"tunes":1039},"p-supporting-1",{"text":1038},"Odvojen rad na implementaciji u široj Aaasaasa platformi pruža konkretne primere granica koje enterprise AI arhitektura mora sačuvati: RBAC ograničen na zakupca u CMS-u, eksplicitno razdvajanje provajdera\u002Fmodela\u002Fruntime-a\u002Fdozvola u Aaasaasa AI Client-u i prvenstveno poreklo pri preuzimanju u Source of Truth Research Engine-u.",{},{"id":1041,"data":1042,"type":218,"tunes":1044},"p-supporting-2",{"text":1043},"Ovi projekti ne treba da se spoje u jednu tvrđenu produkcijsku platformu. Njihova vrednost ovde je uža: oni demonstriraju implementirane obrasce za obim identiteta, granice provajdera, kontrolisane runtime dozvole, poreklo preuzimanja i sledljivost dokaza koji su direktno relevantni za enterprise AI.",{},{"id":1046,"data":1047,"type":42,"tunes":1049},"h-standards",{"text":1048,"level":247},"Kako se glavni standardi uklapaju",{},{"id":1051,"data":1052,"type":292,"tunes":1075},"standards-table",{"content":1053,"stretched":43,"withHeadings":14},[1054,1057,1060,1063,1066,1069,1072],[1055,1056],"Izvor","Šta doprinosi enterprise AI arhitekturi",[1058,1059],"ISO\u002FIEC 42001:2023","Sistem upravljanja AI na nivou organizacije: politike, ciljevi, procesi, odgovornost, praćenje i kontinuirano poboljšanje.",[1061,1062],"ISO\u002FIEC 23894:2023","Smernice za integraciju upravljanja rizicima specifičnim za AI u organizacione aktivnosti i funkcije.",[1064,1065],"NIST AI RMF 1.0","Dobrovoljni okvir orijentisan na životni ciklus za upravljanje AI rizicima; organizovan oko Govern, Map, Measure i Manage.",[1067,1068],"NIST AI 600-1","Profil generativne AI koji proširuje AI RMF rizicima i akcijama specifičnim za generativnu AI.",[1070,1071],"EU AI Act","Obavezujuće regulatorne obaveze u EU čija primenljivost zavisi od uloge, tipa sistema i klasifikacije.",[1073,1074],"ISO\u002FIEC\u002FIEEE 42010:2022","Opšti koncepti opisa arhitekture za izražavanje briga, stanovišta, odluka i odnosa.",{},{"id":1077,"data":1078,"type":218,"tunes":1080},"p-standards-1",{"text":1079},"Ovi izvori rešavaju različite probleme. ISO\u002FIEC 42001 nije zamena za tehničku arhitekturu. ISO\u002FIEC 23894 i NIST AI RMF ne definišu jedan obavezni softverski stek. EU AI Act je zakon, a ne obrazac dizajna platforme. Arhitektura mora prevesti primenljive organizacione, rizične i pravne zahteve u implementabilne sistemske granice i dokaze.",{},{"id":1082,"data":1083,"type":42,"tunes":1085},"h-failures",{"text":1084,"level":247},"Uobičajeni načini neuspeha enterprise AI",{},{"id":1087,"data":1088,"type":292,"tunes":1126},"failures-table",{"content":1089,"stretched":43,"withHeadings":14},[1090,1093,1096,1099,1102,1105,1108,1111,1114,1117,1120,1123],[1091,1092],"Način neuspeha","Zašto ne uspeva",[1094,1095],"Svaki tim kupuje AI nezavisno","Stvara shadow provajdere, duplirane tajne, nedosledno rukovanje podacima i slabu polugu nad rizikom dobavljača.",[1097,1098],"Jedan centralni AI tim poseduje svaku domensku odluku","Centralizuje tehničku kontrolu ali gubi domensku odgovornost i stvara usko grlo.",[1100,1101],"Vektorska baza podataka postaje izvor istine","Infrastruktura za preuzimanje tiho zamenjuje autoritativne sisteme i pravila svežine.",[1103,1104],"Jedan deljeni API ključ za sve korisnike i agente","Uništava atribuciju, najmanje privilegije i smislenu reviziju.",[1106,1107],"Promena modela se objavljuje kao manji patch biblioteke","Regresije u ponašanju mogu stići u produkciju bez domenske evaluacije.",[1109,1110],"Svi promptovi i izlazi se loguju zauvek","Observability stvara nekontrolisano skladište osetljivih podataka.",[1112,1113],"Upravljanje je samo dokumentacija","Politike postoje bez tačaka sprovođenja, dokaza ili operativnog vlasništva.",[1115,1116],"Usklađenost je delegirana provajderu","Sopstvena uloga organizacije, slučaj upotrebe, podaci i operativne obaveze ostaju nerešeni.",[1118,1119],"Agent može da poziva alate jer model podržava korišćenje alata","Sposobnost se pogrešno smatra autorizacijom.",[1121,1122],"Zdravlje platforme jednako je poslovnoj ispravnosti","Vreme rada endpoint-a i dostupnost modela ne dokazuju kvalitet domenskih odgovora ili prihvatljive ishode.",[1124,1125],"Nema izlazne strategije za zavisnost od modela\u002Fprovajdera","Promena cene, politike, sposobnosti ili dostupnosti postaje hitna migracija.",{},{"id":1128,"data":1129,"type":42,"tunes":1131},"h-misconceptions",{"text":1130,"level":247},"Uobičajene zablude",{},{"id":1133,"data":1134,"type":292,"tunes":1163},"misconceptions-table",{"content":1135,"stretched":43,"withHeadings":14},[1136,1139,1142,1145,1148,1151,1154,1157,1160],[1137,1138],"Zabluda","Bolji model",[1140,1141],"„Enterprise AI znači četbot za celu kompaniju.“","Četbot je samo jedan interfejs; arhitektura enterprise AI upravlja podacima, identitetom, provajderom, izvršnim okruženjem, rizikom i operacijama.",[1143,1144],"„Ako koristimo renomiranog provajdera modela, upravljanje je rešeno.“","Kontrole provajdera ne definišu vaš slučaj upotrebe, nadležnost nad podacima, korisničke dozvole, poslovno prihvatanje ili pravnu ulogu.",[1146,1147],"„Privatni AI znači da sve mora biti samostalno hostovano.“","Zahtevi privatnosti mogu dovesti do nekoliko arhitektura; potrebna granica kontrole mora biti precizno navedena.",[1149,1150],"„Upravljanje AI pripada pravnoj službi, arhitektura IT-u.“","Ove dve discipline moraju biti povezane jer obaveze iz politika zahtevaju primenljive kontrole i dokaze.",[1152,1153],"„Jedan enterprise model je jednostavniji.“","Standardizacija može pomoći, ali radni zadaci mogu zahtevati različite modalitete, regione, troškove, nivoe kvaliteta ili modele kontrole.",[1155,1156],"„AI rizik je rizik modela.“","Rizik može poticati iz podataka, upita, pronalaženja, identiteta, alata, interfejsa, operacija, korisnika i organizacionih procesa.",[1158,1159],"„Human-in-the-loop čini agenta bezbednim.“","Ljudsko odobrenje pomaže samo ako recenzent ima koristan kontekst, ovlašćenje, vreme i jasnu tačku odlučivanja.",[1161,1162],"„Uspešan pilot dokazuje spremnost za enterprise.“","Pilot dokazuje ograničenu sposobnost; enterprise spremnost takođe zahteva integraciju, upravljanje, životni ciklus, operacije i ponovljive kontrole.",{},{"id":1165,"data":1166,"type":42,"tunes":1168},"h-framework",{"text":1167,"level":247},"Praktičan redosled odlučivanja u arhitekturi enterprise AI",{},{"id":1170,"data":1171,"type":349,"tunes":1210},"decision-framework",{"steps":1172,"title":1209,"orientation":348},[1173,1176,1179,1182,1185,1188,1191,1194,1197,1200,1203,1206],{"label":1174,"description":1175},"1. Definišite poslovnu sposobnost","Navedite korisnika, odluku ili tok rada, očekivanu vrednost i odgovornog vlasnika.",{"label":1177,"description":1178},"2. Klasifikujte podatke i nadležnost","Identifikujte sisteme evidencije, lične\u002Fpoverljive podatke, zahteve za čuvanjem, svežinom i poreklom.",{"label":1180,"description":1181},"3. Definišite granice identiteta i radnji","Odredite ko može da čita, generiše, odlučuje, odobrava i menja eksterne sisteme.",{"label":1183,"description":1184},"4. Izaberite odgovornosti rešenja i platforme","Odlučite šta pripada radnom zadatku, šta može biti deljeno i šta ostaje u vlasništvu enterprise-a.",{"label":1186,"description":1187},"5. Procenite zavisnost od provajdera i izvršnog okruženja","Procenite upravljane, samostalno hostovane, privatne, suverene ili hibridne opcije u odnosu na stvarne zahteve.",{"label":1189,"description":1190},"6. Mapirajte rizik i regulatorne obaveze","Odredite nivo rizika, organizacione kontrole i primenljive pravne odgovornosti za konkretan sistem.",{"label":1192,"description":1193},"7. Definišite merljivo prihvatanje","Kreirajte kriterijume evaluacije za kvalitet, pouzdanost, bezbednost, pronalaženje, troškove i operativno ponašanje.",{"label":1195,"description":1196},"8. Zabeležite arhitekturne odluke","Sačuvajte obrazloženje, alternative, kompromise, zavisnosti i uslove koji bi pokrenuli preispitivanje.",{"label":1198,"description":1199},"9. Povežite arhitekturu sa isporukom","Prevedite dizajn u backlog, prekretnice, kriterijume prihvatanja, tehnički rad i vlasništvo.",{"label":1201,"description":1202},"10. Validirajte u uslovima sličnim produkciji","Testirajte realistične scenarije identiteta, podataka, otkaza, kašnjenja, provajdera, alata i oporavka, a ne samo čiste demo prikaze.",{"label":1204,"description":1205},"11. Uspostavite operacije i kontrolu promena","Definišite nadzor, odgovor na incidente, ažuriranja modela\u002Fprovajdera, regresiono testiranje, vraćanje i ukidanje.",{"label":1207,"description":1208},"12. Vratite dokaze u arhitekturu","Koristite produkcijska zapažanja, revizije, incidente i evaluacije za reviziju odluka i kontrola.","Od prilike do upravljane enterprise sposobnosti",{},{"id":1212,"data":1213,"type":42,"tunes":1215},"h-checklist",{"text":1214,"level":247},"Kontrolna lista za arhitekturu enterprise AI",{},{"id":1217,"data":1218,"type":292,"tunes":1265},"checklist-table",{"content":1219,"stretched":43,"withHeadings":14},[1220,1223,1226,1229,1232,1235,1238,1241,1244,1247,1250,1253,1256,1259,1262],[1221,1222],"Pitanje","Očekivani dokaz",[1224,1225],"Koju poslovnu sposobnost ovaj AI podržava?","Imenovani vlasnik, korisnička grupa, nameravana odluka\u002Ftok rada i cilj prihvatanja.",[1227,1228],"Koji izvor je merodavan za svaku važnu činjenicu?","Sistemi evidencije, nadležnost dokumenata, pravila porekla i svežine.",[1230,1231],"Koji identiteti postoje?","Ljudski, aplikacijski, servisni, agentski, zakupac\u002Forg i identiteti provajdera su razlikovni.",[1233,1234],"Šta AI može da čita?","Izvori podataka ograničeni autorizacijom i eksplicitna pravila za osetljive podatke.",[1236,1237],"Šta AI može da menja?","Inventar alata\u002Fradnji, model dozvola, odobrenje i put vraćanja.",[1239,1240],"Koji provajder\u002Fmodel se koristi i zašto?","Arhitekturna odluka uključujući kvalitet, bezbednost, troškove, region, životni ciklus i razmatranja izlaska.",[1242,1243],"Šta se dešava ako provajder nije dostupan?","Režim degradacije, rezervna opcija, odbijanje ili plan kontinuiteta.",[1245,1246],"Kako se procenjuje kvalitet?","Skupovi podataka specifični za zadatak, ocenjivači, pragovi, kriterijumi regresije i uslovi validnosti.",[1248,1249],"Šta se loguje?","Šema telemetrije, redakcija, pristup, čuvanje i svrha revizije.",[1251,1252],"Ko je vlasnik AI rizika?","Imenovana organizaciona odgovornost povezana sa konkretnim sistemom.",[1254,1255],"Koja pravna klasifikacija se primenjuje?","Dokumentovana procena zasnovana na važećem zakonu i stvarnom slučaju upotrebe.",[1257,1258],"Kako se odobravaju promene modela\u002Fupita\u002Fpronalaženja?","Verzionisanje, evaluacija, arhitekturni\u002Fzapis o promeni i kapija za uvođenje.",[1260,1261],"Ko reaguje na AI incident?","Runbook, tehnički vlasnik, poslovna\u002Fdomenska eskalacija i eskalacija ka provajderu.",[1263,1264],"Kako se sistem ukida?","Čišćenje podataka, opoziv pristupa, izlazak od provajdera, čuvanje dokaza i uklanjanje zavisnosti.",{},{"id":1267,"data":1268,"type":42,"tunes":1270},"h-edge",{"text":1269,"level":247},"Granični slučajevi i ograničenja",{},{"id":1272,"data":1273,"type":218,"tunes":1275},"p-edge-1",{"text":1274},"Mala kompanija sa jednim AI slučajem upotrebe niskog rizika možda neće imati potrebu za formalnom funkcijom arhitekture enterprise AI. Isti principi mogu se primeniti u laganoj formi: jasan vlasnik, odobreni podaci, eksplicitni provajder, osnovna evaluacija, kontrola pristupa i operativna odgovornost.",{},{"id":1277,"data":1278,"type":218,"tunes":1280},"p-edge-2",{"text":1279},"Visoko regulisana organizacija može zahtevati jaču separaciju, nezavisnu validaciju, formalne procese usklađenosti, lokalni hosting ili rad u izolovanoj mreži. Te kontrole su vođene slučajem upotrebe i regulatornim okruženjem, a ne rečju „enterprise“.",{},{"id":1282,"data":1283,"type":218,"tunes":1285},"p-edge-3",{"text":1284},"Organizacija takođe može uglavnom koristiti SaaS AI proizvode umesto izgradnje AI sistema. Enterprise arhitektura je i dalje važna jer identitet, pristup podacima, ugovorni uslovi, shadow AI, čuvanje, revizija i koncentracija dobavljača ostaju organizacione brige.",{},{"id":1287,"data":1288,"type":218,"tunes":1290},"p-edge-4",{"text":1289},"Centralizovana platforma nije obavezna. Federativno vlasništvo nad platformom može biti validno kada domeni imaju bitno različite zahteve, pod uslovom da odgovornosti za identitet, rizik, inventar i interoperabilnost na nivou enterprise-a ostanu koherentne.",{},{"id":1292,"data":1293,"type":42,"tunes":1295},"h-change-answer",{"text":1294,"level":247},"Šta bi promenilo ovaj odgovor?",{},{"id":1297,"data":1298,"type":218,"tunes":1300},"p-change-answer-1",{"text":1299},"Arhitektura se menja kada se promene tolerancija organizacije na rizik, regulatorna klasifikacija, osetljivost podataka, geografski obuhvat, strategija provajdera, interne veštine ili poslovna kritičnost. Javni marketinški asistent i sistem koji učestvuje u odlukama o zapošljavanju, finansijama, zdravstvu ili kritičnoj infrastrukturi ne bi trebalo da naslede identične modele kontrole.",{},{"id":1302,"data":1303,"type":218,"tunes":1305},"p-change-answer-2",{"text":1304},"Implementacija se takođe menja kako se standardi, regulativa i AI platforme razvijaju. NIST AI RMF 1.0 je trenutno u reviziji, EU AI Act ima fazne datume primene, a sposobnosti modela\u002Fprovajdera se i dalje brzo menjaju. Enterprise arhitektura bi stoga trebalo da očuva stabilne granice odgovornosti, dok mehanizme provajdera i regulatorne detalje tretira kao verzionisane ulaze.",{},{"id":1307,"data":1308,"type":42,"tunes":1310},"h-related",{"text":1309,"level":247},"Povezano kanonsko znanje",{},{"id":1312,"data":1313,"type":218,"tunes":1315},"p-related-1",{"text":1314},"Arhitektura enterprise AI se nadograđuje na arhitekturu rešenja i platforme. Sloj rešenja objašnjava jedan radni zadatak. Sloj platforme objašnjava AI sposobnosti koje se mogu ponovo koristiti. Enterprise sloj povezuje oba sa podacima, identitetom, upravljanjem, rizikom, nabavkom i operacijama na nivou cele organizacije.",{},{"id":1317,"data":1318,"type":218,"tunes":1320},"p-related-2",{"text":1319},"Retrieval-Augmented Generation je samo jedan mehanizam unutar ove arhitekture. RAG može poboljšati pristup enterprise znanju, ali sam po sebi ne rešava nadležnost nad podacima, dozvole, upravljanje ili validnost odgovora.",{},{"id":1322,"data":1323,"type":1328,"tunes":1329},"ref-rag",{"url":1324,"title":1325,"excerpt":1326,"ctaLabel":1327},"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","Šta je RAG? Najjednostavnije objašnjenje kako funkcioniše","Objašnjenje jednostavnim jezikom kako se pronalaženje eksternog znanja povezuje sa jezičkim modelom, a da pronalaženje ne postane izvor istine.","Pročitajte osnove RAG-a","referralArticle",{},{"id":1331,"data":1332,"type":218,"tunes":1334},"p-related-3",{"text":1333},"Za poslovne slučajeve upotrebe sa mnogo dokaza, valjanost odgovora takođe zahteva eksplicitnu granicu: izlaz je podržan samo pod dokazima, verzijom, obimom i pretpostavkama koje su ga proizvele.",{},{"id":1336,"data":1337,"type":1328,"tunes":1342},"ref-avb",{"url":1338,"title":1339,"excerpt":1340,"ctaLabel":1341},"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","Granica valjanosti odgovora: sloj koji nedostaje između relevantnosti i pouzdanih AI odgovora","Okvir za eksplicitno iskazivanje uslova pod kojima AI tvrdnja ostaje podržana i koje promene zahtevaju ograničenje ili ponovno izračunavanje.","Pročitajte Granicu valjanosti odgovora",{},{"id":1344,"data":1345,"type":218,"tunes":1347},"p-related-4",{"text":1346},"Nizvodne poslovne teme uključuju AI upravljanje, privatni AI, suvereni AI, AI u vazdušno izolovanim sistemima, multi-tenant AI arhitekturu, RBAC naspram izolacije zakupaca, apstrakciju provajdera, rutiranje modela i produkcijsku AI arhitekturu.",{},{"id":1349,"data":1350,"type":42,"tunes":1352},"h-faq",{"text":1351,"level":247},"Često postavljana pitanja",{},{"id":1354,"data":1355,"type":1354,"tunes":1390},"faq",{"items":1356,"title":1389},[1357,1361,1365,1369,1373,1377,1381,1385],{"id":1358,"answer":1359,"question":1360},"faq1","Poslovna AI arhitektura je arhitektura na nivou organizacije koja definiše kako se AI rešenja i zajedničke AI sposobnosti integrišu sa poslovnim vlasništvom, poslovnim podacima, identitetom, bezbednošću, provajderima, upravljanjem, rizikom, usklađenošću, životnim ciklusom i operacijama.","Šta je poslovna AI arhitektura?",{"id":1362,"answer":1363,"question":1364},"faq2","Ne. AI platforma pruža tehničke sposobnosti koje se mogu ponovo koristiti, kao što su pristup modelima, pretraživanje, izvršno okruženje agenata i nadzor. Poslovna AI arhitektura definiše kako se ta platforma i pojedinačna AI rešenja uklapaju u širu arhitekturu i operativni model organizacije.","Da li je poslovna AI arhitektura isto što i AI platforma?",{"id":1366,"answer":1367,"question":1368},"faq3","Ne. Standardizacija može smanjiti složenost, ali različiti radni zadaci mogu zahtevati različite provajdere, modele, regione, nivoe kontrole ili modalitete. Važan zahtev je eksplicitna politika i vlasništvo nad životnim ciklusom.","Da li poslovni AI zahteva jedan centralni model?",{"id":1370,"answer":1371,"question":1372},"faq4","Zato što preuzete ili generisane informacije nisu automatski autoritativne. Poslovni sistemi moraju da očuvaju koji izvor je sistem evidencije, da li su podaci aktuelni, ko može da im pristupi i kako se generisana tvrdnja može pratiti do dokaza.","Zašto je autoritet podataka važan za poslovni AI?",{"id":1374,"answer":1375,"question":1376},"faq5","AI upravljanje definiše politike, odgovornost i prava odlučivanja. Poslovna AI arhitektura definiše granice sistema, interfejse, tokove podataka i tehničke mehanizme kroz koje se te politike mogu sprovesti i dokazati.","Koja je razlika između AI upravljanja i poslovne AI arhitekture?",{"id":1378,"answer":1379,"question":1380},"faq6","Ne. Obaveze zavise od faktora kao što su uloga organizacije, slučaj upotrebe i klasifikacija sistema, kao i relevantne odredbe koje su na snazi. Pravna klasifikacija mora se izvršiti za konkretan sistem prema važećem zakonu.","Da li se EU AI Act primenjuje na svaki poslovni AI sistem na isti način?",{"id":1382,"answer":1383,"question":1384},"faq7","Ne. Pilot pokazuje ograničenu sposobnost. Poslovno uvođenje takođe zahteva identitet, autoritet podataka, bezbednost, upravljanje provajderima, evaluaciju, životni ciklus, odgovor na incidente, praćenje, usklađenost i odgovorno operativno vlasništvo.","Da li je uspešan AI pilot dovoljan za poslovno uvođenje?",{"id":1386,"answer":1387,"question":1388},"faq8","Samo kada zahtev opravdava dodatnu kontrolu i operativnu odgovornost. Upravljani, privatni, suvereni, samohostovani i hibridni pristupi su arhitektonske opcije čija podobnost zavisi od zahteva u pogledu podataka, propisa, dostupnosti, troškova, sposobnosti i operacija.","Da li preduzeća treba sama da hostuju AI?","Često postavljana pitanja o poslovnoj AI arhitekturi",{},{"id":1392,"data":1393,"type":42,"tunes":1395},"h-glossary",{"text":1394,"level":247},"Pojmovnik",{},{"id":1397,"data":1398,"type":1397,"tunes":1440},"glossary",{"title":1399,"entries":1400},"Ključni pojmovi poslovne AI arhitekture",[1401,1405,1409,1413,1417,1421,1425,1428,1432,1436],{"term":1402,"anchor":1403,"definition":1404},"Poslovna AI arhitektura","enterprise-ai-architecture","Arhitektura na nivou organizacije koja uređuje kako se AI sistemi, platforme, podaci, identiteti, provajderi, kontrole rizika i operacije uklapaju zajedno.",{"term":1406,"anchor":1407,"definition":1408},"Sistem upravljanja AI","ai-management-system","Organizacioni sistem upravljanja za uspostavljanje politika, ciljeva i procesa vezanih za AI; ISO\u002FIEC 42001 specificira zahteve za takav sistem.",{"term":1410,"anchor":1411,"definition":1412},"Autoritet podataka","data-authority","Pravilo koje identifikuje koji izvor ili sistem je autoritativan za određenu činjenicu, zapis, stanje ili kontekst odluke.",{"term":1414,"anchor":1415,"definition":1416},"Sistem evidencije","system-of-record","Autoritativni sistem odgovoran za zvanično trenutno stanje poslovnog zapisa ili entiteta domena.",{"term":1418,"anchor":1419,"definition":1420},"AI inventar","ai-inventory","Strukturirani zapis o AI slučajevima upotrebe, vlasnicima, modelima\u002Fprovajderima, podacima, alatima, riziku, dokazima evaluacije, stanju životnog ciklusa i povezanim kontrolama.",{"term":1422,"anchor":1423,"definition":1424},"Zavisnost od provajdera","provider-dependency","Tehničko, ugovorno i operativno oslanjanje koje nastaje kada AI radni zadatak zavisi od eksternog modela ili upravljane platforme.",{"term":746,"anchor":1426,"definition":1427},"human-oversight","Definisano ljudsko pregledanje, odobravanje, intervencija ili eskalacija koja se primenjuje tamo gde posledice sistema, neizvesnost ili regulativa to zahtevaju.",{"term":1429,"anchor":1430,"definition":1431},"GenAIOps","genaiops","Operativne prakse za generativne AI radne zadatke koje pokrivaju izbor modela, upite, podatke za zasnivanje, evaluaciju, uvođenje, praćenje i upravljanje životnim ciklusom.",{"term":1433,"anchor":1434,"definition":1435},"Upravljanje AI rizikom","ai-risk-management","Organizacioni proces identifikovanja, procene, tretiranja, praćenja i revizije rizika povezanih sa AI sistemima tokom njihovog životnog ciklusa.",{"term":1437,"anchor":1438,"definition":1439},"Arhitektonska odluka","architecture-decision","Značajan izbor dizajna zajedno sa njegovim kontekstom, obrazloženjem, alternativama, kompromisima i statusom životnog ciklusa.",{},{"id":1442,"data":1443,"type":42,"tunes":1445},"h-conclusion",{"text":1444,"level":247},"Zaključak",{},{"id":1447,"data":1448,"type":218,"tunes":1450},"p-conclusion-1",{"text":1449},"Kada AI uđe u kompaniju, preduzeće ne dobija samo novu softversku komponentu. Ono dobija novu klasu ponašanja i zavisnosti koja seče kroz podatke, identitet, dobavljače, poslovne odluke, bezbednost, operacije, upravljanje i upravljanje promenama.",{},{"id":1452,"data":1453,"type":218,"tunes":1455},"p-conclusion-2",{"text":1454},"Arhitektonski odgovor nije da se sve centralizuje. Već da se odgovornosti učine eksplicitnim: koji podaci su autoritativni, koji identiteti mogu da deluju, koji provajderi su odobreni, koje kontrole su zajedničke, koje odluke ostaju u vlasništvu domena, kako se ponašanje evaluira, kako se incidenti obrađuju i kako se sistem menja tokom vremena.",{},{"id":1457,"data":1458,"type":218,"tunes":1460},"p-conclusion-3",{"text":1459},"To je suštinska razlika poslovne AI arhitekture: ona pretvara izolovanu AI sposobnost u organizaciono upravljiv sistem bez pretvaranja da su modeli, platforme, poslovni domeni i poslovne kontrole ista stvar.",{},{"id":1462,"data":1463,"type":42,"tunes":1465},"h-sources",{"text":1464,"level":247},"Primarni izvori i aktuelne smernice",{},{"id":1467,"data":1468,"type":218,"tunes":1470},"p-sources-note",{"text":1469},"Spoljni standardi, regulativa i aktuelne smernice za arhitekturu dobavljača u nastavku provereni su 8. oktobra 2026. Sekcije specifične za projekat eksplicitno su označene kao originalni dokazi projekta i ne treba ih čitati kao tvrdnje o opštoj industrijskoj činjenici.",{},{"id":1472,"data":1473,"type":1479,"tunes":1480},"src-iso-42001",{"link":1474,"meta":1475},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001",{"image":1476,"title":1477,"description":1478},{"url":278},"ISO\u002FIEC 42001:2023 — Sistem upravljanja veštačkom inteligencijom","Međunarodni standard koji specificira zahteve za uspostavljanje, implementaciju, održavanje i kontinuirano poboljšanje sistema upravljanja AI u organizacijama.","linkTool",{},{"id":1482,"data":1483,"type":1479,"tunes":1489},"src-iso-23894",{"link":1484,"meta":1485},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html",{"image":1486,"title":1487,"description":1488},{"url":278},"ISO\u002FIEC 23894:2023 — Smernice za upravljanje AI rizikom","Međunarodne smernice za integraciju upravljanja rizikom specifičnog za AI u organizacione aktivnosti i funkcije.",{},{"id":1491,"data":1492,"type":1479,"tunes":1498},"src-nist-rmf",{"link":1493,"meta":1494},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",{"image":1495,"title":1496,"description":1497},{"url":278},"NIST AI okvir za upravljanje rizikom","NIST-ov dobrovoljni okvir orijentisan na životni ciklus za upravljanje AI rizikom. NIST navodi da je AI RMF 1.0 trenutno u fazi revizije.",{},{"id":1500,"data":1501,"type":1479,"tunes":1507},"src-nist-genai",{"link":1502,"meta":1503},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence",{"image":1504,"title":1505,"description":1506},{"url":278},"NIST AI 600-1 — Profil generativne AI","NIST-ov prateći profil koji opisuje rizike specifične za generativnu AI i radnje za upravljanje rizikom usklađene sa AI RMF.",{},{"id":1509,"data":1510,"type":1479,"tunes":1516},"src-eu-consolidated",{"link":1511,"meta":1512},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng",{"image":1513,"title":1514,"description":1515},{"url":278},"EUR-Lex — Uredba (EU) 2024\u002F1689, konsolidovani tekst","Aktuelni konsolidovani tekst AI akta koji se koristi za datume primene i regulatornu strukturu, proveren 8. oktobra 2026.",{},{"id":1518,"data":1519,"type":1479,"tunes":1525},"src-eu-timeline",{"link":1520,"meta":1521},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"image":1522,"title":1523,"description":1524},{"url":278},"Evropska komisija — regulatorni okvir AI akta","Trenutni pregled Komisije o fazama primene AI akta, uključujući primenu u 2026. i kasnije datume za određene odredbe o visokom riziku.",{},{"id":1527,"data":1528,"type":1479,"tunes":1534},"src-ms-ai",{"link":1529,"meta":1530},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started",{"image":1531,"title":1532,"description":1533},{"url":278},"Microsoft Azure Well-Architected — AI radna opterećenja","Trenutne smernice za arhitekturu AI radnih opterećenja, uključujući nedeterminističko ponašanje, podatke, dizajn aplikacija i operacije.",{},{"id":1536,"data":1537,"type":1479,"tunes":1543},"src-ms-ops",{"link":1538,"meta":1539},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops",{"image":1540,"title":1541,"description":1542},{"url":278},"Microsoft — MLOps i GenAIOps za AI radna opterećenja","Trenutne smernice o operativnom životnom ciklusu, podacima, održavanju modela, implementaciji, nadzoru i kontinuiranom razvoju.",{},{"id":1545,"data":1546,"type":1479,"tunes":1552},"src-ms-responsible",{"link":1547,"meta":1548},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai",{"image":1549,"title":1550,"description":1551},{"url":278},"Microsoft — Odgovorna AI u Azure radnim opterećenjima","Trenutne smernice koje povezuju AI politiku sa kontrolom podataka, identitetom, revizijom agenata, pristupom zasnovanim na ulogama i operativnim zaštitnim merama.",{},{"id":1554,"data":1555,"type":1479,"tunes":1561},"src-iso-42010",{"link":1556,"meta":1557},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html",{"image":1558,"title":1559,"description":1560},{"url":278},"ISO\u002FIEC\u002FIEEE 42010:2022 — Opis arhitekture","Trenutni standard za opis arhitekture koji podržava eksplicitne nedoumice, stanovišta i odnose u sistemskoj arhitekturi.",{},"2.31","Enterprise AI arhitektura objašnjava kako AI menja korporativne sisteme kroz autoritet podataka, identitet, dozvole, provajdere, rizik, upravljanje, evaluaciju, usklađenost i operacije.","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","enterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq","PUBLISHED","2026-10-08T10:48:00.000Z","2026-10-08T16:48:07.244Z","2026-10-08T17:02:36.954Z",{"en":1571,"de":1572,"sr":1573,"es":1574,"fr":1575,"it":1576,"ru":1577,"zh":1578},"\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fde\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fsr\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fes\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Ffr\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fit\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fru\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fzh\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company",[1580,1583,1587,1591],{"id":1581,"name":1582,"slug":785},59,"Upravljanje i audit",{"id":1584,"name":1585,"slug":1586},57,"Granice podataka","data-boundaries",{"id":1588,"name":1589,"slug":1590},80,"Pristup i identitet","access-and-identity",{"id":1592,"name":1593,"slug":1594},84,"Politike i granice podataka","policy-and-data",{"id":1596,"login":1597,"email":1598,"displayName":1599},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1601,2746],{"lang":1602,"title":1603,"content":1604,"contentJson":1605,"excerpt":2745},"en","Enterprise AI Architecture: What Changes When AI Enters a Company","{\"time\":1791478189041,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture is the organization-wide architecture required when AI becomes part of a company's real systems, data, decisions and operations. The model is only one component. Once AI is connected to enterprise data, identities, permissions, business processes, external providers and production systems, the architecture must also define data authority, access boundaries, risk ownership, provider dependencies, auditability, evaluation, lifecycle control, compliance and operational responsibility. Enterprise AI therefore differs from both a single AI solution and a shared AI platform: it coordinates how many AI-enabled systems fit into the wider organization.\"},\"tunes\":{}},{\"id\":\"direct-answer\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"\u003Cstrong>What changes when AI enters a company?\u003C\u002Fstrong> Existing enterprise architecture responsibilities expand to include probabilistic model behavior, new data flows, retrieval and grounding, model\u002Fprovider dependencies, AI-specific evaluation, agent\u002Ftool authority, model and prompt lifecycle, AI risk management, transparency obligations, and new operational failure modes. The architecture must connect these concerns to the company's existing identity, security, data, procurement, delivery and governance structures instead of creating a parallel “AI universe.”\"},\"tunes\":{}},{\"id\":\"not-bigger-chatbot\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Enterprise AI is not “a bigger chatbot”\",\"body\":\"A chatbot can be a user interface. Enterprise AI architecture is the system of boundaries behind it: what data the AI may access, which source is authoritative, who may use which capability, whether external providers may receive the data, what actions an agent may execute, how outputs are evaluated, what must be logged, who owns incidents, and how changes are approved and rolled back.\"},\"tunes\":{}},{\"id\":\"current-date\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"The architectural principles in this article are intended to be stable. Regulation, standards and vendor capabilities are version-sensitive. ISO\u002FIEC 42001:2023 and ISO\u002FIEC 23894:2023 are current published standards. NIST states that AI RMF 1.0 is being revised. Under the current consolidated EU AI Act text, the Regulation applies generally from 2 August 2026, while specified high-risk provisions have later application dates. Legal classification must always be checked against the current law and the concrete use case.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What enterprise AI architecture really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture describes how AI capabilities are integrated into an existing organization without breaking the boundaries that already make enterprise systems governable: business ownership, identity, authorization, data classification, system-of-record responsibility, change management, procurement, audit, continuity and operations.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise architect does not replace the AI Solution Architect or AI Platform Architect. The enterprise scope asks a different question: How do multiple AI solutions and shared AI capabilities fit into the company's target architecture, policies, data landscape, risk model and operating model?\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This makes enterprise AI architecture a coordination discipline across technology and organization. A technically good model integration can still be an enterprise architecture failure if it creates shadow data flows, duplicates identity, bypasses procurement, cannot be audited, has no owner, or cannot be safely changed.\"},\"tunes\":{}},{\"id\":\"scope-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Solution, platform and enterprise AI architecture are different scopes\",\"layout\":\"table\",\"columns\":[{\"id\":\"solution\",\"label\":\"AI Solution Architecture\"},{\"id\":\"platform\",\"label\":\"AI Platform Architecture\"},{\"id\":\"enterprise\",\"label\":\"Enterprise AI Architecture\"}],\"rows\":[{\"id\":\"scope\",\"label\":\"Primary scope\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"question\",\"label\":\"Primary question\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"ownership\",\"label\":\"Ownership focus\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"success\",\"label\":\"Success condition\",\"values\":[\"\",\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A company starts with one internal document assistant. The first version searches approved documents and sends retrieved context to a language model. At solution level, this may look straightforward.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Then a second team wants AI for customer support. A third wants an agent that can update tickets. Finance wants document analysis. HR wants an internal assistant. Developers want coding agents. Suddenly the company has several providers, several data classes, different user groups, overlapping retrieval indexes, different logging rules, new tool permissions, duplicated secrets and unclear ownership.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"At that point, the question is no longer “Does the assistant work?” The enterprise question becomes: Which capabilities are approved, who owns them, what data can cross which boundary, how are identities and permissions enforced, which providers are acceptable, what must be audited, and how can the organization change models or suppliers without losing control?\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"From isolated AI feature to enterprise architecture\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Isolated use case\",\"description\":\"One team connects one model to one workflow and validates local value.\"},{\"label\":\"2. Shared dependencies appear\",\"description\":\"Multiple teams need providers, model access, retrieval, identity, secrets, observability and evaluation.\"},{\"label\":\"3. Enterprise boundaries are crossed\",\"description\":\"AI touches regulated data, systems of record, external vendors, privileged actions and business decisions.\"},{\"label\":\"4. Ownership must become explicit\",\"description\":\"Business, architecture, data, security, legal\u002Fcompliance, procurement and operations need defined responsibilities.\"},{\"label\":\"5. Lifecycle becomes organizational\",\"description\":\"Model changes, prompt changes, provider changes and new agent capabilities become governed changes rather than local developer edits.\"},{\"label\":\"6. Architecture becomes repeatable\",\"description\":\"The organization establishes reusable patterns, decision records, controls, exceptions and validation gates for new AI workloads.\"}]},\"tunes\":{}},{\"id\":\"h-stop\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stop-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise architecture does not mean that every AI component must be centralized. Some capabilities should be shared; others must remain domain-owned. Finance, HR, engineering and customer support may legitimately require different data boundaries, providers, evaluation criteria and human-approval rules.\"},\"tunes\":{}},{\"id\":\"p-stop-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise objective is therefore not one model, one vector database or one universal assistant. The objective is coherent architecture with explicit variation: common policies and reusable capabilities where they reduce risk and duplication, plus controlled exceptions where business or regulatory requirements differ.\"},\"tunes\":{}},{\"id\":\"h-layers\",\"type\":\"header\",\"data\":{\"text\":\"What changes in the architecture when AI enters the enterprise\",\"level\":2},\"tunes\":{}},{\"id\":\"h-business\",\"type\":\"header\",\"data\":{\"text\":\"1. Business ownership becomes part of the technical architecture\",\"level\":3},\"tunes\":{}},{\"id\":\"p-business-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Traditional applications already need business owners. AI makes that requirement more visible because acceptable behavior cannot be defined only by uptime and functional correctness. Someone must own the intended use, unacceptable use, output quality, escalation path and consequences of wrong or inappropriate results.\"},\"tunes\":{}},{\"id\":\"p-business-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A model team cannot decide alone whether an answer is acceptable for HR, finance, legal or customer-facing use. Enterprise AI architecture therefore connects technical design to an explicit business capability, accountable owner, user group and decision context.\"},\"tunes\":{}},{\"id\":\"h-data-authority\",\"type\":\"header\",\"data\":{\"text\":\"2. Data access is not enough — data authority must be defined\",\"level\":3},\"tunes\":{}},{\"id\":\"p-data-authority-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI frequently combines operational databases, documents, search indexes, vector stores, data warehouses, SaaS systems and external knowledge. The architecture must distinguish where information is stored from which source is authoritative for a given claim or action.\"},\"tunes\":{}},{\"id\":\"p-data-authority-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A vector index can improve retrieval but should not silently become the company's system of record. A model response can summarize an ERP record but should not replace the ERP as the authoritative source. Cached context can improve latency but becomes unsafe when permissions or underlying business state change.\"},\"tunes\":{}},{\"id\":\"p-data-authority-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI therefore needs provenance, freshness, source classification, authorization propagation and invalidation rules in addition to ordinary data integration.\"},\"tunes\":{}},{\"id\":\"authority-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Enterprise data rule\",\"body\":\"\u003Cstrong>The AI system may transform, retrieve and reason over enterprise data without becoming the authority for that data.\u003C\u002Fstrong> The architecture should preserve a path back to the authoritative source whenever the use case requires evidence, verification or consequential action.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"3. Identity becomes multi-layered\",\"level\":3},\"tunes\":{}},{\"id\":\"p-identity-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI has more identities than the human user. A request may involve a user identity, application identity, service identity, agent identity, provider credential, tool credential and tenant or organizational context.\"},\"tunes\":{}},{\"id\":\"p-identity-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"These identities should not be collapsed into one shared API key. Authorization must remain attributable to the correct principal, and privileged tools should receive only the authority required for the current operation.\"},\"tunes\":{}},{\"id\":\"p-identity-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For agentic systems, this becomes especially important: a model can propose an action, but the runtime must decide whether the requesting identity is allowed to execute it. Model capability is not authorization.\"},\"tunes\":{}},{\"id\":\"h-permissions\",\"type\":\"header\",\"data\":{\"text\":\"4. Permissions move from content access to action authority\",\"level\":3},\"tunes\":{}},{\"id\":\"p-permissions-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A read-only assistant mainly needs controlled access to information. An enterprise agent can create tickets, modify records, send messages, trigger workflows or operate external systems. That introduces a different risk class because the system can change state rather than merely describe it.\"},\"tunes\":{}},{\"id\":\"p-permissions-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture should separate read, write, approval and administrative capabilities; define human-in-the-loop points where consequence justifies them; and preserve an audit trail that identifies what was requested, what was approved and what actually changed.\"},\"tunes\":{}},{\"id\":\"h-provider\",\"type\":\"header\",\"data\":{\"text\":\"5. The AI provider becomes an enterprise dependency\",\"level\":3},\"tunes\":{}},{\"id\":\"p-provider-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Calling a model API is also a supplier relationship. The architecture may depend on provider availability, service terms, data-processing conditions, supported regions, model lifecycle, quotas, pricing, API compatibility, security controls and change notices.\"},\"tunes\":{}},{\"id\":\"p-provider-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This means provider selection is not only a benchmark decision. Procurement, security, privacy, legal review, continuity planning and exit strategy can all become architecture inputs.\"},\"tunes\":{}},{\"id\":\"p-provider-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction can reduce coupling, but only where the underlying capabilities are genuinely portable. Tool use, structured output, context limits, multimodality, safety controls, fine-tuning and hosted-agent features may differ materially between providers.\"},\"tunes\":{}},{\"id\":\"h-risk\",\"type\":\"header\",\"data\":{\"text\":\"6. AI risk becomes a lifecycle process\",\"level\":3},\"tunes\":{}},{\"id\":\"p-risk-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI risk is not completed by one approval before launch. The model, prompt, retrieval corpus, tool set, provider, user population and surrounding business process can all change after deployment. The risk profile changes with them.\"},\"tunes\":{}},{\"id\":\"p-risk-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"ISO\u002FIEC 23894:2023 explicitly addresses integration of AI risk management into organizational activities and functions. NIST AI RMF similarly frames risk management across the lifecycle. Enterprise architecture should therefore make risk review part of change and operations rather than an isolated compliance document.\"},\"tunes\":{}},{\"id\":\"p-risk-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Risk should also be proportional. A summarization assistant and an autonomous system that changes production records should not receive identical controls merely because both use an LLM.\"},\"tunes\":{}},{\"id\":\"h-management-system\",\"type\":\"header\",\"data\":{\"text\":\"7. Governance becomes an operating system, not a policy PDF\",\"level\":3},\"tunes\":{}},{\"id\":\"p-management-system-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"ISO\u002FIEC 42001:2023 defines requirements for establishing, implementing, maintaining and continually improving an AI management system. The architecture consequence is important: governance must connect policy to real inventories, ownership, processes, controls, evidence, reviews and improvement loops.\"},\"tunes\":{}},{\"id\":\"p-management-system-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An enterprise AI policy that is not connected to provider approval, identity, logging, change management, evaluation and incident response has limited architectural effect. The organization needs mechanisms that make policy enforceable or at least observable.\"},\"tunes\":{}},{\"id\":\"h-eval\",\"type\":\"header\",\"data\":{\"text\":\"8. Evaluation becomes a production control\",\"level\":3},\"tunes\":{}},{\"id\":\"p-eval-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Traditional acceptance testing assumes that the same input normally produces the same deterministic result. Generative AI can be nondeterministic, sensitive to context and dependent on changing external knowledge. Production acceptance therefore needs task-specific evals, regression suites and observable thresholds rather than only unit tests.\"},\"tunes\":{}},{\"id\":\"p-eval-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The platform can provide reusable evaluation infrastructure, but the enterprise still needs ownership of domain ground truth and release gates. A central AI team cannot invent the correct answer for every business domain.\"},\"tunes\":{}},{\"id\":\"p-eval-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model, prompt, retrieval and tool changes should be traceable to evaluation evidence where the change can materially affect output behavior.\"},\"tunes\":{}},{\"id\":\"h-observability\",\"type\":\"header\",\"data\":{\"text\":\"9. Observability must include behavior, data and model context\",\"level\":3},\"tunes\":{}},{\"id\":\"p-observability-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"CPU, memory and HTTP error rates are not sufficient for AI workloads. Production observability may need model\u002Fprovider identifiers, latency, token usage, cost, retrieval results, tool calls, refusal behavior, evaluation scores, safety events and failure classifications.\"},\"tunes\":{}},{\"id\":\"p-observability-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"At the same time, AI telemetry can contain sensitive data. Prompt and response logs may become a shadow data store. Enterprise architecture must therefore define what can be logged, how it is redacted, who can access it, how long it is retained and when detailed tracing must be disabled.\"},\"tunes\":{}},{\"id\":\"h-lifecycle\",\"type\":\"header\",\"data\":{\"text\":\"10. AI components need explicit lifecycle ownership\",\"level\":3},\"tunes\":{}},{\"id\":\"p-lifecycle-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Models can be renamed, replaced, retired or changed by providers. Embedding models can invalidate an index strategy. Prompt templates and system instructions can change behavior. Agent runtimes and protocols can evolve. External tools can change their schemas and permissions.\"},\"tunes\":{}},{\"id\":\"p-lifecycle-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise architecture must decide who detects these changes, who tests them, who approves them, how consumers are notified, how rollback works and what evidence is required before a new version becomes the default.\"},\"tunes\":{}},{\"id\":\"h-operations\",\"type\":\"header\",\"data\":{\"text\":\"11. Incident response must include AI-specific failure modes\",\"level\":3},\"tunes\":{}},{\"id\":\"p-operations-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI incident may be a provider outage, data leak, prompt-injection path, authorization failure, retrieval contamination, unexpected model behavior, unsafe tool execution, cost spike, stale knowledge, evaluation regression or a change in external model behavior.\"},\"tunes\":{}},{\"id\":\"p-operations-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise runbook therefore needs more than “restart the service.” It may require disabling a model route, revoking tool access, freezing a corpus, changing a prompt version, disabling an agent capability, switching provider, escalating to a domain owner or preserving traces for investigation.\"},\"tunes\":{}},{\"id\":\"h-ownership\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI creates cross-functional ownership\",\"level\":2},\"tunes\":{}},{\"id\":\"ownership-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Concern\",\"Typical enterprise owner or contributor\",\"Architecture question\"],[\"Business use\",\"Business owner \u002F product owner\",\"What decision or workflow is AI allowed to support or automate?\"],[\"Solution architecture\",\"AI \u002F solution architect\",\"How does the concrete workload meet its functional and quality requirements?\"],[\"Shared AI capabilities\",\"AI platform \u002F platform engineering\",\"Which reusable model, retrieval, agent and observability services are provided?\"],[\"Enterprise coherence\",\"Enterprise architecture\",\"How do AI systems fit target architecture, standards, integration patterns and organizational ownership?\"],[\"Data authority\",\"Data owner \u002F domain owner\",\"Which data is authoritative, current, permitted and sufficiently governed?\"],[\"Identity and security\",\"IAM \u002F security architecture\",\"Which identities can access which data and execute which actions?\"],[\"Risk and compliance\",\"Risk \u002F legal \u002F compliance \u002F privacy\",\"Which obligations, prohibited uses, controls and evidence apply to this use case?\"],[\"Supplier dependency\",\"Procurement \u002F vendor management \u002F architecture\",\"What contractual, operational and exit risks arise from the provider?\"],[\"Operations\",\"SRE \u002F operations \u002F platform owner\",\"How is the system monitored, supported, degraded, recovered and changed?\"],[\"Domain acceptance\",\"Business\u002Fdomain specialists\",\"What counts as a correct, safe or useful result in this domain?\"]]},\"tunes\":{}},{\"id\":\"ownership-warning\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"A RACI chart is not architecture by itself\",\"body\":\"Responsibility matrices are useful only when they connect to real system boundaries, approvals, data ownership, interfaces, runbooks and change processes. Enterprise AI needs accountable ownership that can be traced to technical controls and operational actions.\"},\"tunes\":{}},{\"id\":\"h-model\",\"type\":\"header\",\"data\":{\"text\":\"A practical enterprise AI architecture model\",\"level\":2},\"tunes\":{}},{\"id\":\"model-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Proposed layered model\",\"body\":\"The following model is a practical synthesis for reasoning about enterprise AI architecture. It is not presented as an ISO or NIST standard. Its purpose is to make cross-organizational boundaries explicit.\"},\"tunes\":{}},{\"id\":\"enterprise-model-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"Primary responsibility\"],[\"Business and policy\",\"Approved use cases, accountable owners, risk appetite, prohibited uses, human accountability, business acceptance.\"],[\"Identity and authority\",\"User\u002Fservice\u002Fagent identities, roles, tenant or organizational scope, privileged actions, approval paths.\"],[\"Enterprise data\",\"Systems of record, document sources, data products, provenance, classification, retention, freshness and access.\"],[\"AI platform\",\"Provider\u002Fmodel access, retrieval primitives, agent runtimes, tool brokers, evaluation infrastructure, observability, quotas and secrets.\"],[\"AI solutions\",\"Domain workflows, prompts\u002Finstructions, domain retrieval, business logic, acceptance criteria and user experience.\"],[\"Integration and tools\",\"APIs, enterprise applications, workflows, messaging, file systems, external services and action execution.\"],[\"Risk and governance\",\"Inventory, assessment, compliance evidence, exception management, model\u002Fprovider approval, review and audit.\"],[\"Operations and lifecycle\",\"Deployment, monitoring, incidents, releases, model\u002Fprovider changes, deprecation, rollback and continuity.\"]]},\"tunes\":{}},{\"id\":\"p-model-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture is strongest when each layer can state both its responsibilities and its non-responsibilities. For example, the AI platform can enforce provider policy and collect traces without becoming the source of truth for HR data. A solution can define domain prompts without owning enterprise IAM. A business owner can approve a use case without being expected to operate the inference gateway.\"},\"tunes\":{}},{\"id\":\"h-data-flow\",\"type\":\"header\",\"data\":{\"text\":\"Map enterprise AI as data and authority flows, not boxes\",\"level\":2},\"tunes\":{}},{\"id\":\"enterprise-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A consequential enterprise AI request\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Business context\",\"description\":\"The user requests a task under an approved use case with an accountable business owner.\"},{\"label\":\"2. Identity and authorization\",\"description\":\"The system resolves user, application, service and tenant or organizational scope before privileged access.\"},{\"label\":\"3. Authoritative data acquisition\",\"description\":\"The solution reads or retrieves only sources permitted for the current identity and task.\"},{\"label\":\"4. AI processing\",\"description\":\"An approved model\u002Fprovider processes the minimum necessary context under defined routing and data-handling rules.\"},{\"label\":\"5. Tool or action boundary\",\"description\":\"Any state-changing action is independently authorized and may require human approval according to consequence.\"},{\"label\":\"6. Validation\",\"description\":\"The result is checked against solution-specific acceptance, evidence or safety rules.\"},{\"label\":\"7. Audit and observability\",\"description\":\"Permitted metadata, decisions, routes, tool calls and outcomes are recorded without creating uncontrolled sensitive-data logs.\"},{\"label\":\"8. Feedback and lifecycle\",\"description\":\"Failures and evaluation results feed model, prompt, data, policy and process changes through controlled change management.\"}]},\"tunes\":{}},{\"id\":\"h-inventory\",\"type\":\"header\",\"data\":{\"text\":\"An enterprise needs an AI inventory before it can govern AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-inventory-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Organizations cannot manage AI systems they cannot identify. Enterprise architecture should maintain an inventory at a level that is useful for decisions, not merely a list of model names.\"},\"tunes\":{}},{\"id\":\"inventory-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Inventory field\",\"Why it matters\"],[\"Use case and owner\",\"Connects technology to accountable business purpose.\"],[\"Users and affected parties\",\"Defines who interacts with or is affected by the system.\"],[\"Model\u002Fprovider\",\"Identifies external dependency, capability and lifecycle risk.\"],[\"Data sources\",\"Supports authority, privacy, classification and provenance review.\"],[\"Deployment\u002Fruntime location\",\"Clarifies processing location, connectivity and operational control.\"],[\"Tools\u002Factions\",\"Shows whether the AI can change external state and at what consequence.\"],[\"Human oversight\",\"Records where review, approval or escalation is required.\"],[\"Risk\u002Fclassification\",\"Connects the system to organizational and regulatory controls.\"],[\"Evaluation evidence\",\"Shows what was tested and under which validity conditions.\"],[\"Current version\",\"Allows incidents and regressions to be traced to actual deployed state.\"],[\"Lifecycle state\",\"Proposed, experimental, approved, production, restricted, deprecated or retired.\"]]},\"tunes\":{}},{\"id\":\"h-governance\",\"type\":\"header\",\"data\":{\"text\":\"AI governance and enterprise AI architecture are related but not the same\",\"level\":2},\"tunes\":{}},{\"id\":\"governance-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Governance versus architecture\",\"layout\":\"table\",\"columns\":[{\"id\":\"governance\",\"label\":\"AI Governance\"},{\"id\":\"architecture\",\"label\":\"Enterprise AI Architecture\"}],\"rows\":[{\"id\":\"purpose\",\"label\":\"Purpose\",\"values\":[\"\",\"\"]},{\"id\":\"example\",\"label\":\"Example\",\"values\":[\"\",\"\"]},{\"id\":\"failure\",\"label\":\"Failure if isolated\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-regulation\",\"type\":\"header\",\"data\":{\"text\":\"Regulation becomes an architecture input\",\"level\":2},\"tunes\":{}},{\"id\":\"p-regulation-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"For organizations operating in the European Union, the AI Act can create requirements that affect system design, documentation, transparency, governance and operating processes. The architectural impact depends on the organization's role in the AI value chain and the concrete system classification; not every AI system has the same obligations.\"},\"tunes\":{}},{\"id\":\"p-regulation-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"As of 8 October 2026, the current consolidated text states that the Regulation generally applies from 2 August 2026. Governance rules and obligations for general-purpose AI models began applying earlier, while specified high-risk system provisions have later dates. The Commission also began enforcing new transparency requirements from 2 August 2026 for relevant interactive and synthetic-content systems.\"},\"tunes\":{}},{\"id\":\"p-regulation-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise architecture lesson is not “put compliance in the model.” It is to make classification, provider\u002Fdeployer role, documentation, transparency, oversight, logging and change evidence traceable to the system that actually implements the use case.\"},\"tunes\":{}},{\"id\":\"legal-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Legal scope is use-case specific\",\"body\":\"This article describes architecture implications, not legal advice. Enterprise AI architecture should preserve the information needed for legal and compliance specialists to classify the actual system and map obligations to concrete controls. Architecture should not hard-code one regulatory interpretation as if every AI workload had the same status.\"},\"tunes\":{}},{\"id\":\"h-procurement\",\"type\":\"header\",\"data\":{\"text\":\"Procurement and architecture become connected\",\"level\":2},\"tunes\":{}},{\"id\":\"p-procurement-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An external model or managed AI platform can become a deep dependency even when integration requires only a few API calls. Enterprise architecture should therefore make procurement questions technically concrete.\"},\"tunes\":{}},{\"id\":\"procurement-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Procurement question\",\"Architecture consequence\"],[\"Where is data processed?\",\"Region, network path, data residency and transfer controls.\"],[\"Is customer data retained or used for provider improvement?\",\"Data minimization, contractual controls and provider eligibility.\"],[\"How are models versioned or retired?\",\"Regression testing, compatibility, fallback and lifecycle planning.\"],[\"What are quotas and service limits?\",\"Capacity architecture, admission control and failure handling.\"],[\"How portable is the integration?\",\"Provider abstraction, exit cost and migration effort.\"],[\"What incident information is available?\",\"Observability, forensic capability and support escalation.\"],[\"Which subprocessors or external services are involved?\",\"Dependency mapping and risk assessment.\"],[\"What changes without explicit customer approval?\",\"Change detection, release gates and acceptance strategy.\"]]},\"tunes\":{}},{\"id\":\"h-control\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise architecture decides how much AI control the requirement actually needs\",\"level\":2},\"tunes\":{}},{\"id\":\"control-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Requirement\",\"Possible architectural response\"],[\"Fast access to managed models\",\"Managed provider with enterprise identity, gateway controls and contractual review.\"],[\"Private data with managed orchestration\",\"Managed control plane plus customer-controlled execution or private data plane where supported.\"],[\"Strict locality or sovereignty\",\"Region-restricted, sovereign, private or self-hosted architecture according to the real requirement.\"],[\"Air-gapped environment\",\"Locally hosted models, local retrieval, local tooling, offline update\u002Fdistribution and isolated observability.\"],[\"Provider portability\",\"Application-owned domain state plus adapters and contracts that isolate provider-specific behavior where practical.\"],[\"Highest control of agent semantics\",\"Self-managed or deeply controlled runtime with explicit tool, context, state and lifecycle ownership.\"]]},\"tunes\":{}},{\"id\":\"p-control-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The most controlled architecture is not automatically the best enterprise architecture. More ownership increases responsibility for patching, capacity, security, testing, model operations and incident response. Enterprise architecture should escalate control only where the requirement justifies the additional operational burden.\"},\"tunes\":{}},{\"id\":\"h-change-management\",\"type\":\"header\",\"data\":{\"text\":\"AI turns change management into a behavioral problem\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A normal dependency update can alter performance or compatibility. An AI change can also alter behavior. Replacing a model, changing a system prompt, changing retrieval, adding a tool or changing the context policy can modify how the system interprets and responds even if the surrounding application code barely changes.\"},\"tunes\":{}},{\"id\":\"change-process\",\"type\":\"processFlow\",\"data\":{\"title\":\"A production AI change path\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Change identified\",\"description\":\"Model, provider, prompt, retrieval source, tool, policy or runtime change is proposed or detected.\"},{\"label\":\"2. Impact mapped\",\"description\":\"Affected solutions, data classes, users, risk controls, cost, contracts and operational dependencies are identified.\"},{\"label\":\"3. Architecture decision updated\",\"description\":\"Material choices and trade-offs are recorded; superseded decisions remain historically traceable.\"},{\"label\":\"4. Evaluation executed\",\"description\":\"Relevant regression, safety, retrieval, latency, cost and domain tests are run.\"},{\"label\":\"5. Approval applied\",\"description\":\"Approval level follows consequence, risk and organizational policy.\"},{\"label\":\"6. Controlled rollout\",\"description\":\"Versioned release, canary or staged deployment is used where appropriate.\"},{\"label\":\"7. Production evidence collected\",\"description\":\"Telemetry, incidents, feedback and domain outcomes are monitored.\"},{\"label\":\"8. Rollback or acceptance\",\"description\":\"The change is accepted, restricted, rolled back or superseded based on evidence.\"}]},\"tunes\":{}},{\"id\":\"h-nfr-adr\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI still needs NFRs and ADRs\",\"level\":2},\"tunes\":{}},{\"id\":\"p-nfr-adr-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI does not replace ordinary architecture discipline. Non-functional requirements remain the target conditions: availability, latency, privacy, isolation, auditability, recoverability, cost boundaries, explainability or other quality requirements. Architecture Decision Records preserve the chosen response and its trade-offs.\"},\"tunes\":{}},{\"id\":\"p-nfr-adr-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The AI-specific difference is that some quality attributes must be evaluated probabilistically or empirically. “Answers must be useful” is too vague. A production requirement should identify the task, data, user population, acceptable failure conditions, measurement method and threshold where practical.\"},\"tunes\":{}},{\"id\":\"nfr-adr-chain\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Enterprise traceability chain\",\"body\":\"\u003Cstrong>Business need → requirement \u002F NFR → architecture decision → implementation → evaluation \u002F validation → production observation → change decision.\u003C\u002Fstrong> AI adds new variables to this chain; it does not make the chain unnecessary.\"},\"tunes\":{}},{\"id\":\"h-delivery\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI architecture must connect to delivery\",\"level\":2},\"tunes\":{}},{\"id\":\"p-delivery-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Architecture that never reaches backlog, implementation, acceptance and operations remains conceptual. Enterprise AI therefore needs traceability from architecture decisions into delivery work and back from implementation evidence into architecture.\"},\"tunes\":{}},{\"id\":\"p-delivery-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Jira and Confluence are examples of tools that can support this separation when used deliberately: Confluence can preserve requirements, architecture, decisions, risks and rationale; Jira can manage actionable delivery work and state. The important principle is the traceability, not the brand of tool.\"},\"tunes\":{}},{\"id\":\"h-original\",\"type\":\"header\",\"data\":{\"text\":\"Original project evidence: Enterprise Aaasaasa 0.1\",\"level\":2},\"tunes\":{}},{\"id\":\"original-evidence-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Project evidence, not market-proof claim\",\"body\":\"Enterprise Aaasaasa 0.1 is used here as original project evidence for structured enterprise architecture and delivery thinking. It is a PoC \u002F enterprise project context, not evidence of mass customer adoption, enterprise-scale production usage or commercial traction.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise Aaasaasa 0.1 combines platform architecture, SaaS\u002FAPI concepts, internationalization, AI integration and structured project governance. The project was deliberately organized so that requirements, architecture, prototype delivery, validation and closure were separate milestones rather than one undifferentiated implementation phase.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture direction includes multi-instance \u002F multi-database concepts together with API, CRUD, i18n and AI capabilities. That matters for enterprise AI because tenant or instance boundaries, database ownership and application services must remain explicit when AI features are added.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The project structure also treated architecture delay, scope creep and AI\u002Fdata-protection concerns as project risks rather than discovering them only during implementation. Stakeholders included technical, security, sponsor\u002Fsteering and external-service perspectives, which is closer to the real cross-functional nature of enterprise AI than a model-only prototype.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"The useful evidence is therefore the integration of architecture and delivery: business and project structure, milestones, risks, architecture, backend\u002FAPI, frontend\u002FAI work, validation and closure are treated as connected responsibilities. That pattern is reusable even though the project itself should not be presented as proof of external enterprise adoption.\"},\"tunes\":{}},{\"id\":\"enterprise-aaasaasa-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Project element\",\"Enterprise AI architecture lesson\"],[\"Requirements milestone\",\"AI capability must begin from defined need, scope, acceptance and quality constraints.\"],[\"Architecture milestone\",\"Data, API, instance\u002Fdatabase boundaries and AI integration are explicit design work.\"],[\"Prototype milestone\",\"Architecture must become executable enough to expose integration risks.\"],[\"Validation milestone\",\"A functioning prototype is not the same as validated acceptance.\"],[\"Risk register\",\"Scope, architecture delay and AI\u002Fdata-protection concerns are managed as delivery risks.\"],[\"Stakeholder structure\",\"Enterprise AI spans sponsor\u002Fbusiness, architecture, security, external providers and delivery.\"],[\"Project closure\",\"Decisions, remaining risks and validation evidence must survive beyond the implementation sprint.\"]]},\"tunes\":{}},{\"id\":\"h-supporting\",\"type\":\"header\",\"data\":{\"text\":\"Supporting implementation patterns from the wider platform work\",\"level\":2},\"tunes\":{}},{\"id\":\"p-supporting-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Separate implementation work in the wider Aaasaasa platform provides concrete examples of boundaries that enterprise AI architecture must preserve: tenant-scoped RBAC in the CMS, explicit provider\u002Fmodel\u002Fruntime\u002Fpermission separation in Aaasaasa AI Client, and provenance-first retrieval in the Source of Truth Research Engine.\"},\"tunes\":{}},{\"id\":\"p-supporting-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"These projects should not be collapsed into one claimed production platform. Their value here is narrower: they demonstrate implemented patterns for identity scope, provider boundaries, controlled runtime permissions, retrieval provenance and evidence traceability that are directly relevant to enterprise AI.\"},\"tunes\":{}},{\"id\":\"h-standards\",\"type\":\"header\",\"data\":{\"text\":\"How the main standards fit together\",\"level\":2},\"tunes\":{}},{\"id\":\"standards-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Source\",\"What it contributes to enterprise AI architecture\"],[\"ISO\u002FIEC 42001:2023\",\"Organization-level AI management system: policies, objectives, processes, responsibility, monitoring and continual improvement.\"],[\"ISO\u002FIEC 23894:2023\",\"Guidance for integrating AI-specific risk management into organizational activities and functions.\"],[\"NIST AI RMF 1.0\",\"Voluntary lifecycle-oriented framework for managing AI risks; organized around Govern, Map, Measure and Manage.\"],[\"NIST AI 600-1\",\"Generative AI profile extending AI RMF with generative-AI-specific risks and actions.\"],[\"EU AI Act\",\"Binding regulatory obligations in the EU whose applicability depends on role, system type and classification.\"],[\"ISO\u002FIEC\u002FIEEE 42010:2022\",\"General architecture-description concepts for expressing concerns, viewpoints, decisions and relationships.\"]]},\"tunes\":{}},{\"id\":\"p-standards-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"These sources solve different problems. ISO\u002FIEC 42001 is not a replacement for technical architecture. ISO\u002FIEC 23894 and NIST AI RMF do not define one mandatory software stack. The EU AI Act is law, not a platform design pattern. Architecture must translate the applicable organizational, risk and legal requirements into implementable system boundaries and evidence.\"},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common enterprise AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failures-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"Why it fails\"],[\"Every team buys AI independently\",\"Creates shadow providers, duplicated secrets, inconsistent data handling and weak leverage over supplier risk.\"],[\"One central AI team owns every domain decision\",\"Centralizes technical control but loses domain accountability and creates a bottleneck.\"],[\"Vector database becomes the source of truth\",\"Retrieval infrastructure silently replaces authoritative systems and freshness rules.\"],[\"One shared API key for all users and agents\",\"Destroys attribution, least privilege and meaningful auditability.\"],[\"Model change deployed like a minor library patch\",\"Behavioral regressions can reach production without domain evaluation.\"],[\"All prompts and outputs are logged forever\",\"Observability creates an uncontrolled sensitive-data repository.\"],[\"Governance is only documentation\",\"Policies exist without enforcement points, evidence or operational ownership.\"],[\"Compliance is delegated to the provider\",\"The organization's own role, use case, data and operational obligations remain unresolved.\"],[\"Agent can call tools because the model supports tool use\",\"Capability is mistaken for authorization.\"],[\"Platform health equals business correctness\",\"Endpoint uptime and model availability do not prove domain answer quality or acceptable outcomes.\"],[\"No exit strategy for model\u002Fprovider dependency\",\"A pricing, policy, capability or availability change becomes an emergency migration.\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Better model\"],[\"“Enterprise AI means a company-wide chatbot.”\",\"The chatbot is one interface; enterprise AI architecture governs the underlying data, identity, provider, runtime, risk and operations.\"],[\"“If we use a reputable model provider, governance is solved.”\",\"Provider controls do not define your use case, data authority, user permissions, business acceptance or legal role.\"],[\"“Private AI means everything must be self-hosted.”\",\"Privacy requirements can lead to several architectures; the required control boundary must be stated precisely.\"],[\"“AI governance belongs to legal, architecture belongs to IT.”\",\"The two disciplines must connect because policy obligations need implementable controls and evidence.\"],[\"“One enterprise model is simpler.”\",\"Standardization can help, but workloads can require different modalities, regions, costs, quality levels or control models.\"],[\"“AI risk is model risk.”\",\"Risk can originate in data, prompts, retrieval, identity, tools, interfaces, operations, users and organizational process.\"],[\"“Human-in-the-loop makes an agent safe.”\",\"Human approval helps only if the reviewer has useful context, authority, time and a clear decision point.\"],[\"“A successful pilot proves enterprise readiness.”\",\"A pilot proves bounded capability; enterprise readiness also requires integration, governance, lifecycle, operations and repeatable controls.\"]]},\"tunes\":{}},{\"id\":\"h-framework\",\"type\":\"header\",\"data\":{\"text\":\"A practical enterprise AI architecture decision sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"decision-framework\",\"type\":\"processFlow\",\"data\":{\"title\":\"From opportunity to governed enterprise capability\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define the business capability\",\"description\":\"State the user, decision or workflow, expected value and accountable owner.\"},{\"label\":\"2. Classify data and authority\",\"description\":\"Identify systems of record, personal\u002Fconfidential data, retention, freshness and provenance requirements.\"},{\"label\":\"3. Define identity and action boundaries\",\"description\":\"Determine who may read, generate, decide, approve and change external systems.\"},{\"label\":\"4. Select solution and platform responsibilities\",\"description\":\"Decide what belongs to the workload, what can be shared and what remains enterprise-owned.\"},{\"label\":\"5. Assess provider and runtime dependency\",\"description\":\"Evaluate managed, self-hosted, private, sovereign or hybrid options against real requirements.\"},{\"label\":\"6. Map risk and regulatory obligations\",\"description\":\"Determine risk level, organizational controls and applicable legal responsibilities for the concrete system.\"},{\"label\":\"7. Define measurable acceptance\",\"description\":\"Create evaluation criteria for quality, reliability, safety, retrieval, cost and operational behavior.\"},{\"label\":\"8. Record architecture decisions\",\"description\":\"Preserve rationale, alternatives, trade-offs, dependencies and conditions that would trigger reconsideration.\"},{\"label\":\"9. Connect architecture to delivery\",\"description\":\"Translate the design into backlog, milestones, acceptance criteria, technical work and ownership.\"},{\"label\":\"10. Validate in production-shaped conditions\",\"description\":\"Test realistic identity, data, failure, latency, provider, tool and recovery scenarios rather than only clean demos.\"},{\"label\":\"11. Establish operations and change control\",\"description\":\"Define monitoring, incident response, model\u002Fprovider updates, regression testing, rollback and retirement.\"},{\"label\":\"12. Feed evidence back into architecture\",\"description\":\"Use production observations, audits, incidents and evaluations to revise decisions and controls.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"What business capability does this AI support?\",\"Named owner, user group, intended decision\u002Fworkflow and acceptance objective.\"],[\"Which source is authoritative for each important fact?\",\"Systems of record, document authority, provenance and freshness rules.\"],[\"Which identities exist?\",\"Human, application, service, agent, tenant\u002Forg and provider identities are distinguishable.\"],[\"What can the AI read?\",\"Authorization-scoped data sources and explicit sensitive-data rules.\"],[\"What can the AI change?\",\"Tool\u002Faction inventory, permission model, approval and rollback path.\"],[\"Which provider\u002Fmodel is used and why?\",\"Architecture decision including quality, security, cost, region, lifecycle and exit considerations.\"],[\"What happens if the provider is unavailable?\",\"Degraded mode, fallback, refusal or continuity plan.\"],[\"How is quality evaluated?\",\"Task-specific datasets, graders, thresholds, regression criteria and validity conditions.\"],[\"What is logged?\",\"Telemetry schema, redaction, access, retention and audit purpose.\"],[\"Who owns AI risk?\",\"Named organizational responsibility connected to the concrete system.\"],[\"What legal classification applies?\",\"Documented assessment based on the current law and the actual use case.\"],[\"How are model\u002Fprompt\u002Fretrieval changes approved?\",\"Versioning, evaluation, architecture\u002Fchange record and rollout gate.\"],[\"Who responds to an AI incident?\",\"Runbook, technical owner, business\u002Fdomain escalation and provider escalation.\"],[\"How is the system retired?\",\"Data cleanup, access revocation, provider exit, evidence retention and dependency removal.\"]]},\"tunes\":{}},{\"id\":\"h-edge\",\"type\":\"header\",\"data\":{\"text\":\"Edge cases and limits\",\"level\":2},\"tunes\":{}},{\"id\":\"p-edge-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A small company with one low-risk AI use case may not need a formal enterprise AI architecture function. The same principles can be applied lightly: clear owner, approved data, explicit provider, basic evaluation, access control and operational responsibility.\"},\"tunes\":{}},{\"id\":\"p-edge-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A highly regulated organization may need stronger separation, independent validation, formal conformity processes, local hosting or air-gapped operation. Those controls are driven by the use case and regulatory environment, not by the word “enterprise.”\"},\"tunes\":{}},{\"id\":\"p-edge-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An organization can also use mostly SaaS AI products rather than building AI systems. Enterprise architecture still matters because identity, data access, contractual terms, shadow AI, retention, audit and supplier concentration remain organizational concerns.\"},\"tunes\":{}},{\"id\":\"p-edge-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"A centralized platform is not mandatory. Federated platform ownership can be valid when domains have materially different requirements, provided enterprise-level identity, risk, inventory and interoperability responsibilities remain coherent.\"},\"tunes\":{}},{\"id\":\"h-change-answer\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-answer-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture changes when the organization's risk tolerance, regulatory classification, data sensitivity, geographic scope, provider strategy, internal skills or business criticality changes. A public marketing assistant and a system participating in employment, finance, healthcare or critical infrastructure decisions should not inherit identical control models.\"},\"tunes\":{}},{\"id\":\"p-change-answer-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The implementation also changes as standards, regulation and AI platforms evolve. NIST AI RMF 1.0 is currently under revision, the EU AI Act has phased application dates, and model\u002Fprovider capabilities continue to change rapidly. Enterprise architecture should therefore preserve stable responsibility boundaries while treating provider mechanisms and regulatory details as versioned inputs.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture builds on solution and platform architecture. The solution layer explains one workload. The platform layer explains reusable AI capabilities. The enterprise layer connects both to organization-wide data, identity, governance, risk, procurement and operations.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Retrieval-Augmented Generation is only one mechanism inside this architecture. RAG can improve access to enterprise knowledge, but it does not solve data authority, permissions, governance or answer validity by itself.\"},\"tunes\":{}},{\"id\":\"ref-rag\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\",\"title\":\"What Is RAG? The Simplest Explanation of How It Works\",\"excerpt\":\"A plain-English explanation of how external knowledge retrieval connects to the language model without turning retrieval into the source of truth.\",\"ctaLabel\":\"Read the RAG foundation\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For evidence-heavy enterprise use cases, answer validity also needs an explicit boundary: an output is only supported under the evidence, version, scope and assumptions that produced it.\"},\"tunes\":{}},{\"id\":\"ref-avb\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\",\"title\":\"The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers\",\"excerpt\":\"A framework for making explicit the conditions under which an AI claim remains supported and what changes require restriction or recalculation.\",\"ctaLabel\":\"Read the Answer Validity Boundary\"},\"tunes\":{}},{\"id\":\"p-related-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"Downstream enterprise topics include AI Governance, Private AI, Sovereign AI, Air-Gapped AI, Multi-Tenant AI Architecture, RBAC versus Tenant Isolation, Provider Abstraction, Model Routing and Production AI Architecture.\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Enterprise AI architecture FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is enterprise AI architecture?\",\"answer\":\"Enterprise AI architecture is the organization-wide architecture that defines how AI solutions and shared AI capabilities integrate with business ownership, enterprise data, identity, security, providers, governance, risk, compliance, lifecycle and operations.\"},{\"id\":\"faq2\",\"question\":\"Is enterprise AI architecture the same as an AI platform?\",\"answer\":\"No. An AI platform provides reusable technical capabilities such as model access, retrieval, agent runtimes and observability. Enterprise AI architecture defines how that platform and individual AI solutions fit into the organization's wider architecture and operating model.\"},{\"id\":\"faq3\",\"question\":\"Does enterprise AI require one central model?\",\"answer\":\"No. Standardization can reduce complexity, but different workloads may require different providers, models, regions, control levels or modalities. The important requirement is explicit policy and lifecycle ownership.\"},{\"id\":\"faq4\",\"question\":\"Why is data authority important for enterprise AI?\",\"answer\":\"Because retrieved or generated information is not automatically authoritative. Enterprise systems need to preserve which source is the system of record, whether data is current, who may access it and how a generated claim can be traced back to evidence.\"},{\"id\":\"faq5\",\"question\":\"What is the difference between AI governance and enterprise AI architecture?\",\"answer\":\"AI governance defines policies, accountability and decision rights. Enterprise AI architecture defines the system boundaries, interfaces, data flows and technical mechanisms through which those policies can be implemented and evidenced.\"},{\"id\":\"faq6\",\"question\":\"Does the EU AI Act apply to every enterprise AI system in the same way?\",\"answer\":\"No. Obligations depend on factors such as the organization's role, the system's use case and classification, and the relevant provisions in force. Legal classification must be performed for the concrete system under the current law.\"},{\"id\":\"faq7\",\"question\":\"Is a successful AI pilot enough for enterprise deployment?\",\"answer\":\"No. A pilot demonstrates bounded capability. Enterprise deployment also needs identity, data authority, security, provider governance, evaluation, lifecycle, incident response, monitoring, compliance and accountable operational ownership.\"},{\"id\":\"faq8\",\"question\":\"Should enterprises self-host AI?\",\"answer\":\"Only when the requirement justifies the added control and operational responsibility. Managed, private, sovereign, self-hosted and hybrid approaches are architecture options whose fit depends on data, regulatory, availability, cost, capability and operational requirements.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key enterprise AI architecture terms\",\"entries\":[{\"term\":\"Enterprise AI architecture\",\"definition\":\"Organization-wide architecture governing how AI systems, platforms, data, identities, providers, risk controls and operations fit together.\",\"anchor\":\"enterprise-ai-architecture\"},{\"term\":\"AI management system\",\"definition\":\"An organizational management system for establishing AI-related policies, objectives and processes; ISO\u002FIEC 42001 specifies requirements for such a system.\",\"anchor\":\"ai-management-system\"},{\"term\":\"Data authority\",\"definition\":\"The rule that identifies which source or system is authoritative for a particular fact, record, state or decision context.\",\"anchor\":\"data-authority\"},{\"term\":\"System of record\",\"definition\":\"The authoritative system responsible for the official current state of a business record or domain entity.\",\"anchor\":\"system-of-record\"},{\"term\":\"AI inventory\",\"definition\":\"A structured record of AI use cases, owners, models\u002Fproviders, data, tools, risk, evaluation evidence, lifecycle state and related controls.\",\"anchor\":\"ai-inventory\"},{\"term\":\"Provider dependency\",\"definition\":\"The technical, contractual and operational reliance created when an AI workload depends on an external model or managed platform.\",\"anchor\":\"provider-dependency\"},{\"term\":\"Human oversight\",\"definition\":\"Defined human review, approval, intervention or escalation applied where system consequence, uncertainty or regulation requires it.\",\"anchor\":\"human-oversight\"},{\"term\":\"GenAIOps\",\"definition\":\"Operational practices for generative-AI workloads covering model selection, prompts, grounding data, evaluation, deployment, monitoring and lifecycle management.\",\"anchor\":\"genaiops\"},{\"term\":\"AI risk management\",\"definition\":\"The organizational process of identifying, assessing, treating, monitoring and revising risks associated with AI systems across their lifecycle.\",\"anchor\":\"ai-risk-management\"},{\"term\":\"Architecture decision\",\"definition\":\"A material design choice together with its context, rationale, alternatives, trade-offs and lifecycle status.\",\"anchor\":\"architecture-decision\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"When AI enters a company, the enterprise does not merely gain a new software component. It gains a new class of behavior and dependency that cuts across data, identity, suppliers, business decisions, security, operations, governance and change management.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architectural response is not to centralize everything. It is to make responsibilities explicit: which data is authoritative, which identities may act, which providers are approved, which controls are shared, which decisions remain domain-owned, how behavior is evaluated, how incidents are handled and how the system changes over time.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That is the core distinction of enterprise AI architecture: it turns isolated AI capability into an organizationally governable system without pretending that models, platforms, business domains and enterprise controls are the same thing.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current guidance\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"External standards, regulation and current vendor architecture guidance below were checked on 8 October 2026. Project-specific sections are explicitly marked as original project evidence and should not be read as claims of general industry fact.\"},\"tunes\":{}},{\"id\":\"src-iso-42001\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC 42001:2023 — Artificial intelligence management system\",\"description\":\"International standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system within organizations.\"}},\"tunes\":{}},{\"id\":\"src-iso-23894\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC 23894:2023 — Guidance on AI risk management\",\"description\":\"International guidance for integrating AI-specific risk management into organizational activities and functions.\"}},\"tunes\":{}},{\"id\":\"src-nist-rmf\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI Risk Management Framework\",\"description\":\"NIST's voluntary lifecycle-oriented framework for managing AI risk. NIST states that AI RMF 1.0 is currently being revised.\"}},\"tunes\":{}},{\"id\":\"src-nist-genai\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI 600-1 — Generative AI Profile\",\"description\":\"NIST companion profile describing generative-AI-specific risks and risk-management actions aligned to the AI RMF.\"}},\"tunes\":{}},{\"id\":\"src-eu-consolidated\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"EUR-Lex — Regulation (EU) 2024\u002F1689, consolidated text\",\"description\":\"Current consolidated AI Act text used for application dates and regulatory structure as checked on 8 October 2026.\"}},\"tunes\":{}},{\"id\":\"src-eu-timeline\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — AI Act regulatory framework\",\"description\":\"Current Commission overview of AI Act application phases, including 2026 applicability and later dates for specified high-risk provisions.\"}},\"tunes\":{}},{\"id\":\"src-ms-ai\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft Azure Well-Architected — AI workloads\",\"description\":\"Current architecture guidance on AI workloads, including nondeterministic behavior, data, application design and operations.\"}},\"tunes\":{}},{\"id\":\"src-ms-ops\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft — MLOps and GenAIOps for AI workloads\",\"description\":\"Current guidance on operational lifecycle, data, model maintenance, deployment, monitoring and continuous evolution.\"}},\"tunes\":{}},{\"id\":\"src-ms-responsible\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft — Responsible AI in Azure workloads\",\"description\":\"Current guidance connecting AI policy to data control, identity, agent auditability, role-based access and operational safeguards.\"}},\"tunes\":{}},{\"id\":\"src-iso-42010\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description\",\"description\":\"Current architecture-description standard supporting explicit concerns, viewpoints and relationships across system architecture.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":1606,"blocks":1607,"version":2744},1791478189041,[1608,1612,1617,1622,1627,1631,1635,1639,1643,1647,1671,1675,1679,1683,1687,1710,1714,1718,1722,1726,1730,1734,1738,1742,1746,1750,1754,1759,1763,1767,1771,1775,1779,1783,1787,1791,1795,1799,1803,1807,1811,1815,1819,1823,1827,1831,1835,1839,1843,1847,1851,1855,1859,1863,1867,1871,1875,1879,1883,1887,1935,1940,1944,1949,1980,1984,1988,2017,2021,2025,2065,2069,2087,2091,2095,2099,2103,2108,2112,2116,2147,2151,2176,2180,2184,2188,2217,2221,2225,2229,2234,2238,2242,2246,2250,2255,2259,2263,2267,2271,2299,2303,2307,2311,2315,2334,2338,2342,2382,2386,2417,2421,2462,2466,2515,2519,2523,2527,2531,2535,2539,2543,2547,2551,2555,2559,2566,2570,2577,2581,2585,2614,2618,2650,2654,2658,2662,2666,2670,2674,2681,2688,2695,2702,2709,2716,2723,2730,2737],{"id":215,"data":1609,"type":218,"tunes":1611},{"text":1610},"Enterprise AI architecture is the organization-wide architecture required when AI becomes part of a company's real systems, data, decisions and operations. The model is only one component. Once AI is connected to enterprise data, identities, permissions, business processes, external providers and production systems, the architecture must also define data authority, access boundaries, risk ownership, provider dependencies, auditability, evaluation, lifecycle control, compliance and operational responsibility. Enterprise AI therefore differs from both a single AI solution and a shared AI platform: it coordinates how many AI-enabled systems fit into the wider organization.",{},{"id":221,"data":1613,"type":226,"tunes":1616},{"body":1614,"title":1615,"variant":225},"\u003Cstrong>What changes when AI enters a company?\u003C\u002Fstrong> Existing enterprise architecture responsibilities expand to include probabilistic model behavior, new data flows, retrieval and grounding, model\u002Fprovider dependencies, AI-specific evaluation, agent\u002Ftool authority, model and prompt lifecycle, AI risk management, transparency obligations, and new operational failure modes. The architecture must connect these concerns to the company's existing identity, security, data, procurement, delivery and governance structures instead of creating a parallel “AI universe.”","Direct answer",{},{"id":229,"data":1618,"type":226,"tunes":1621},{"body":1619,"title":1620,"variant":233},"A chatbot can be a user interface. Enterprise AI architecture is the system of boundaries behind it: what data the AI may access, which source is authoritative, who may use which capability, whether external providers may receive the data, what actions an agent may execute, how outputs are evaluated, what must be logged, who owns incidents, and how changes are approved and rolled back.","Enterprise AI is not “a bigger chatbot”",{},{"id":236,"data":1623,"type":226,"tunes":1626},{"body":1624,"title":1625,"variant":240},"The architectural principles in this article are intended to be stable. Regulation, standards and vendor capabilities are version-sensitive. ISO\u002FIEC 42001:2023 and ISO\u002FIEC 23894:2023 are current published standards. NIST states that AI RMF 1.0 is being revised. Under the current consolidated EU AI Act text, the Regulation applies generally from 2 August 2026, while specified high-risk provisions have later application dates. Legal classification must always be checked against the current law and the concrete use case.","Current-source note — 8 October 2026",{},{"id":243,"data":1628,"type":248,"tunes":1630},{"title":1629,"maxLevel":246,"minLevel":247},"Contents",{},{"id":251,"data":1632,"type":42,"tunes":1634},{"text":1633,"level":247},"What enterprise AI architecture really means",{},{"id":256,"data":1636,"type":218,"tunes":1638},{"text":1637},"Enterprise AI architecture describes how AI capabilities are integrated into an existing organization without breaking the boundaries that already make enterprise systems governable: business ownership, identity, authorization, data classification, system-of-record responsibility, change management, procurement, audit, continuity and operations.",{},{"id":261,"data":1640,"type":218,"tunes":1642},{"text":1641},"The enterprise architect does not replace the AI Solution Architect or AI Platform Architect. The enterprise scope asks a different question: How do multiple AI solutions and shared AI capabilities fit into the company's target architecture, policies, data landscape, risk model and operating model?",{},{"id":266,"data":1644,"type":218,"tunes":1646},{"text":1645},"This makes enterprise AI architecture a coordination discipline across technology and organization. A technically good model integration can still be an enterprise architecture failure if it creates shadow data flows, duplicates identity, bypasses procurement, cannot be audited, has no owner, or cannot be safely changed.",{},{"id":271,"data":1648,"type":303,"tunes":1670},{"rows":1649,"title":1662,"layout":292,"columns":1663},[1650,1653,1656,1659],{"id":275,"label":1651,"values":1652},"Primary scope",[278,278,278],{"id":280,"label":1654,"values":1655},"Primary question",[278,278,278],{"id":284,"label":1657,"values":1658},"Ownership focus",[278,278,278],{"id":288,"label":1660,"values":1661},"Success condition",[278,278,278],"Solution, platform and enterprise AI architecture are different scopes",[1664,1666,1668],{"id":295,"label":1665},"AI Solution Architecture",{"id":298,"label":1667},"AI Platform Architecture",{"id":301,"label":1669},"Enterprise AI Architecture",{},{"id":306,"data":1672,"type":42,"tunes":1674},{"text":1673,"level":247},"The simplest example",{},{"id":311,"data":1676,"type":218,"tunes":1678},{"text":1677},"A company starts with one internal document assistant. The first version searches approved documents and sends retrieved context to a language model. At solution level, this may look straightforward.",{},{"id":316,"data":1680,"type":218,"tunes":1682},{"text":1681},"Then a second team wants AI for customer support. A third wants an agent that can update tickets. Finance wants document analysis. HR wants an internal assistant. Developers want coding agents. Suddenly the company has several providers, several data classes, different user groups, overlapping retrieval indexes, different logging rules, new tool permissions, duplicated secrets and unclear ownership.",{},{"id":321,"data":1684,"type":218,"tunes":1686},{"text":1685},"At that point, the question is no longer “Does the assistant work?” The enterprise question becomes: Which capabilities are approved, who owns them, what data can cross which boundary, how are identities and permissions enforced, which providers are acceptable, what must be audited, and how can the organization change models or suppliers without losing control?",{},{"id":326,"data":1688,"type":349,"tunes":1709},{"steps":1689,"title":1708,"orientation":348},[1690,1693,1696,1699,1702,1705],{"label":1691,"description":1692},"1. Isolated use case","One team connects one model to one workflow and validates local value.",{"label":1694,"description":1695},"2. Shared dependencies appear","Multiple teams need providers, model access, retrieval, identity, secrets, observability and evaluation.",{"label":1697,"description":1698},"3. Enterprise boundaries are crossed","AI touches regulated data, systems of record, external vendors, privileged actions and business decisions.",{"label":1700,"description":1701},"4. Ownership must become explicit","Business, architecture, data, security, legal\u002Fcompliance, procurement and operations need defined responsibilities.",{"label":1703,"description":1704},"5. Lifecycle becomes organizational","Model changes, prompt changes, provider changes and new agent capabilities become governed changes rather than local developer edits.",{"label":1706,"description":1707},"6. Architecture becomes repeatable","The organization establishes reusable patterns, decision records, controls, exceptions and validation gates for new AI workloads.","From isolated AI feature to enterprise architecture",{},{"id":352,"data":1711,"type":42,"tunes":1713},{"text":1712,"level":247},"Where the simple example stops",{},{"id":357,"data":1715,"type":218,"tunes":1717},{"text":1716},"Enterprise architecture does not mean that every AI component must be centralized. Some capabilities should be shared; others must remain domain-owned. Finance, HR, engineering and customer support may legitimately require different data boundaries, providers, evaluation criteria and human-approval rules.",{},{"id":362,"data":1719,"type":218,"tunes":1721},{"text":1720},"The enterprise objective is therefore not one model, one vector database or one universal assistant. The objective is coherent architecture with explicit variation: common policies and reusable capabilities where they reduce risk and duplication, plus controlled exceptions where business or regulatory requirements differ.",{},{"id":367,"data":1723,"type":42,"tunes":1725},{"text":1724,"level":247},"What changes in the architecture when AI enters the enterprise",{},{"id":372,"data":1727,"type":42,"tunes":1729},{"text":1728,"level":246},"1. Business ownership becomes part of the technical architecture",{},{"id":377,"data":1731,"type":218,"tunes":1733},{"text":1732},"Traditional applications already need business owners. AI makes that requirement more visible because acceptable behavior cannot be defined only by uptime and functional correctness. Someone must own the intended use, unacceptable use, output quality, escalation path and consequences of wrong or inappropriate results.",{},{"id":382,"data":1735,"type":218,"tunes":1737},{"text":1736},"A model team cannot decide alone whether an answer is acceptable for HR, finance, legal or customer-facing use. Enterprise AI architecture therefore connects technical design to an explicit business capability, accountable owner, user group and decision context.",{},{"id":387,"data":1739,"type":42,"tunes":1741},{"text":1740,"level":246},"2. Data access is not enough — data authority must be defined",{},{"id":392,"data":1743,"type":218,"tunes":1745},{"text":1744},"Enterprise AI frequently combines operational databases, documents, search indexes, vector stores, data warehouses, SaaS systems and external knowledge. The architecture must distinguish where information is stored from which source is authoritative for a given claim or action.",{},{"id":397,"data":1747,"type":218,"tunes":1749},{"text":1748},"A vector index can improve retrieval but should not silently become the company's system of record. A model response can summarize an ERP record but should not replace the ERP as the authoritative source. Cached context can improve latency but becomes unsafe when permissions or underlying business state change.",{},{"id":402,"data":1751,"type":218,"tunes":1753},{"text":1752},"Enterprise AI therefore needs provenance, freshness, source classification, authorization propagation and invalidation rules in addition to ordinary data integration.",{},{"id":407,"data":1755,"type":226,"tunes":1758},{"body":1756,"title":1757,"variant":288},"\u003Cstrong>The AI system may transform, retrieve and reason over enterprise data without becoming the authority for that data.\u003C\u002Fstrong> The architecture should preserve a path back to the authoritative source whenever the use case requires evidence, verification or consequential action.","Enterprise data rule",{},{"id":413,"data":1760,"type":42,"tunes":1762},{"text":1761,"level":246},"3. Identity becomes multi-layered",{},{"id":418,"data":1764,"type":218,"tunes":1766},{"text":1765},"Enterprise AI has more identities than the human user. A request may involve a user identity, application identity, service identity, agent identity, provider credential, tool credential and tenant or organizational context.",{},{"id":423,"data":1768,"type":218,"tunes":1770},{"text":1769},"These identities should not be collapsed into one shared API key. Authorization must remain attributable to the correct principal, and privileged tools should receive only the authority required for the current operation.",{},{"id":428,"data":1772,"type":218,"tunes":1774},{"text":1773},"For agentic systems, this becomes especially important: a model can propose an action, but the runtime must decide whether the requesting identity is allowed to execute it. Model capability is not authorization.",{},{"id":433,"data":1776,"type":42,"tunes":1778},{"text":1777,"level":246},"4. Permissions move from content access to action authority",{},{"id":438,"data":1780,"type":218,"tunes":1782},{"text":1781},"A read-only assistant mainly needs controlled access to information. An enterprise agent can create tickets, modify records, send messages, trigger workflows or operate external systems. That introduces a different risk class because the system can change state rather than merely describe it.",{},{"id":443,"data":1784,"type":218,"tunes":1786},{"text":1785},"The architecture should separate read, write, approval and administrative capabilities; define human-in-the-loop points where consequence justifies them; and preserve an audit trail that identifies what was requested, what was approved and what actually changed.",{},{"id":448,"data":1788,"type":42,"tunes":1790},{"text":1789,"level":246},"5. The AI provider becomes an enterprise dependency",{},{"id":453,"data":1792,"type":218,"tunes":1794},{"text":1793},"Calling a model API is also a supplier relationship. The architecture may depend on provider availability, service terms, data-processing conditions, supported regions, model lifecycle, quotas, pricing, API compatibility, security controls and change notices.",{},{"id":458,"data":1796,"type":218,"tunes":1798},{"text":1797},"This means provider selection is not only a benchmark decision. Procurement, security, privacy, legal review, continuity planning and exit strategy can all become architecture inputs.",{},{"id":463,"data":1800,"type":218,"tunes":1802},{"text":1801},"Provider abstraction can reduce coupling, but only where the underlying capabilities are genuinely portable. Tool use, structured output, context limits, multimodality, safety controls, fine-tuning and hosted-agent features may differ materially between providers.",{},{"id":468,"data":1804,"type":42,"tunes":1806},{"text":1805,"level":246},"6. AI risk becomes a lifecycle process",{},{"id":473,"data":1808,"type":218,"tunes":1810},{"text":1809},"AI risk is not completed by one approval before launch. The model, prompt, retrieval corpus, tool set, provider, user population and surrounding business process can all change after deployment. The risk profile changes with them.",{},{"id":478,"data":1812,"type":218,"tunes":1814},{"text":1813},"ISO\u002FIEC 23894:2023 explicitly addresses integration of AI risk management into organizational activities and functions. NIST AI RMF similarly frames risk management across the lifecycle. Enterprise architecture should therefore make risk review part of change and operations rather than an isolated compliance document.",{},{"id":483,"data":1816,"type":218,"tunes":1818},{"text":1817},"Risk should also be proportional. A summarization assistant and an autonomous system that changes production records should not receive identical controls merely because both use an LLM.",{},{"id":488,"data":1820,"type":42,"tunes":1822},{"text":1821,"level":246},"7. Governance becomes an operating system, not a policy PDF",{},{"id":493,"data":1824,"type":218,"tunes":1826},{"text":1825},"ISO\u002FIEC 42001:2023 defines requirements for establishing, implementing, maintaining and continually improving an AI management system. The architecture consequence is important: governance must connect policy to real inventories, ownership, processes, controls, evidence, reviews and improvement loops.",{},{"id":498,"data":1828,"type":218,"tunes":1830},{"text":1829},"An enterprise AI policy that is not connected to provider approval, identity, logging, change management, evaluation and incident response has limited architectural effect. The organization needs mechanisms that make policy enforceable or at least observable.",{},{"id":503,"data":1832,"type":42,"tunes":1834},{"text":1833,"level":246},"8. Evaluation becomes a production control",{},{"id":508,"data":1836,"type":218,"tunes":1838},{"text":1837},"Traditional acceptance testing assumes that the same input normally produces the same deterministic result. Generative AI can be nondeterministic, sensitive to context and dependent on changing external knowledge. Production acceptance therefore needs task-specific evals, regression suites and observable thresholds rather than only unit tests.",{},{"id":513,"data":1840,"type":218,"tunes":1842},{"text":1841},"The platform can provide reusable evaluation infrastructure, but the enterprise still needs ownership of domain ground truth and release gates. A central AI team cannot invent the correct answer for every business domain.",{},{"id":518,"data":1844,"type":218,"tunes":1846},{"text":1845},"Model, prompt, retrieval and tool changes should be traceable to evaluation evidence where the change can materially affect output behavior.",{},{"id":523,"data":1848,"type":42,"tunes":1850},{"text":1849,"level":246},"9. Observability must include behavior, data and model context",{},{"id":528,"data":1852,"type":218,"tunes":1854},{"text":1853},"CPU, memory and HTTP error rates are not sufficient for AI workloads. Production observability may need model\u002Fprovider identifiers, latency, token usage, cost, retrieval results, tool calls, refusal behavior, evaluation scores, safety events and failure classifications.",{},{"id":533,"data":1856,"type":218,"tunes":1858},{"text":1857},"At the same time, AI telemetry can contain sensitive data. Prompt and response logs may become a shadow data store. Enterprise architecture must therefore define what can be logged, how it is redacted, who can access it, how long it is retained and when detailed tracing must be disabled.",{},{"id":538,"data":1860,"type":42,"tunes":1862},{"text":1861,"level":246},"10. AI components need explicit lifecycle ownership",{},{"id":543,"data":1864,"type":218,"tunes":1866},{"text":1865},"Models can be renamed, replaced, retired or changed by providers. Embedding models can invalidate an index strategy. Prompt templates and system instructions can change behavior. Agent runtimes and protocols can evolve. External tools can change their schemas and permissions.",{},{"id":548,"data":1868,"type":218,"tunes":1870},{"text":1869},"Enterprise architecture must decide who detects these changes, who tests them, who approves them, how consumers are notified, how rollback works and what evidence is required before a new version becomes the default.",{},{"id":553,"data":1872,"type":42,"tunes":1874},{"text":1873,"level":246},"11. Incident response must include AI-specific failure modes",{},{"id":558,"data":1876,"type":218,"tunes":1878},{"text":1877},"An AI incident may be a provider outage, data leak, prompt-injection path, authorization failure, retrieval contamination, unexpected model behavior, unsafe tool execution, cost spike, stale knowledge, evaluation regression or a change in external model behavior.",{},{"id":563,"data":1880,"type":218,"tunes":1882},{"text":1881},"The enterprise runbook therefore needs more than “restart the service.” It may require disabling a model route, revoking tool access, freezing a corpus, changing a prompt version, disabling an agent capability, switching provider, escalating to a domain owner or preserving traces for investigation.",{},{"id":568,"data":1884,"type":42,"tunes":1886},{"text":1885,"level":247},"Enterprise AI creates cross-functional ownership",{},{"id":573,"data":1888,"type":292,"tunes":1934},{"content":1889,"stretched":43,"withHeadings":14},[1890,1894,1898,1902,1906,1910,1914,1918,1922,1926,1930],[1891,1892,1893],"Concern","Typical enterprise owner or contributor","Architecture question",[1895,1896,1897],"Business use","Business owner \u002F product owner","What decision or workflow is AI allowed to support or automate?",[1899,1900,1901],"Solution architecture","AI \u002F solution architect","How does the concrete workload meet its functional and quality requirements?",[1903,1904,1905],"Shared AI capabilities","AI platform \u002F platform engineering","Which reusable model, retrieval, agent and observability services are provided?",[1907,1908,1909],"Enterprise coherence","Enterprise architecture","How do AI systems fit target architecture, standards, integration patterns and organizational ownership?",[1911,1912,1913],"Data authority","Data owner \u002F domain owner","Which data is authoritative, current, permitted and sufficiently governed?",[1915,1916,1917],"Identity and security","IAM \u002F security architecture","Which identities can access which data and execute which actions?",[1919,1920,1921],"Risk and compliance","Risk \u002F legal \u002F compliance \u002F privacy","Which obligations, prohibited uses, controls and evidence apply to this use case?",[1923,1924,1925],"Supplier dependency","Procurement \u002F vendor management \u002F architecture","What contractual, operational and exit risks arise from the provider?",[1927,1928,1929],"Operations","SRE \u002F operations \u002F platform owner","How is the system monitored, supported, degraded, recovered and changed?",[1931,1932,1933],"Domain acceptance","Business\u002Fdomain specialists","What counts as a correct, safe or useful result in this domain?",{},{"id":622,"data":1936,"type":226,"tunes":1939},{"body":1937,"title":1938,"variant":233},"Responsibility matrices are useful only when they connect to real system boundaries, approvals, data ownership, interfaces, runbooks and change processes. Enterprise AI needs accountable ownership that can be traced to technical controls and operational actions.","A RACI chart is not architecture by itself",{},{"id":628,"data":1941,"type":42,"tunes":1943},{"text":1942,"level":247},"A practical enterprise AI architecture model",{},{"id":633,"data":1945,"type":226,"tunes":1948},{"body":1946,"title":1947,"variant":240},"The following model is a practical synthesis for reasoning about enterprise AI architecture. It is not presented as an ISO or NIST standard. Its purpose is to make cross-organizational boundaries explicit.","Proposed layered model",{},{"id":639,"data":1950,"type":292,"tunes":1979},{"content":1951,"stretched":43,"withHeadings":14},[1952,1955,1958,1961,1964,1967,1970,1973,1976],[1953,1954],"Layer","Primary responsibility",[1956,1957],"Business and policy","Approved use cases, accountable owners, risk appetite, prohibited uses, human accountability, business acceptance.",[1959,1960],"Identity and authority","User\u002Fservice\u002Fagent identities, roles, tenant or organizational scope, privileged actions, approval paths.",[1962,1963],"Enterprise data","Systems of record, document sources, data products, provenance, classification, retention, freshness and access.",[1965,1966],"AI platform","Provider\u002Fmodel access, retrieval primitives, agent runtimes, tool brokers, evaluation infrastructure, observability, quotas and secrets.",[1968,1969],"AI solutions","Domain workflows, prompts\u002Finstructions, domain retrieval, business logic, acceptance criteria and user experience.",[1971,1972],"Integration and tools","APIs, enterprise applications, workflows, messaging, file systems, external services and action execution.",[1974,1975],"Risk and governance","Inventory, assessment, compliance evidence, exception management, model\u002Fprovider approval, review and audit.",[1977,1978],"Operations and lifecycle","Deployment, monitoring, incidents, releases, model\u002Fprovider changes, deprecation, rollback and continuity.",{},{"id":671,"data":1981,"type":218,"tunes":1983},{"text":1982},"The architecture is strongest when each layer can state both its responsibilities and its non-responsibilities. For example, the AI platform can enforce provider policy and collect traces without becoming the source of truth for HR data. A solution can define domain prompts without owning enterprise IAM. A business owner can approve a use case without being expected to operate the inference gateway.",{},{"id":676,"data":1985,"type":42,"tunes":1987},{"text":1986,"level":247},"Map enterprise AI as data and authority flows, not boxes",{},{"id":681,"data":1989,"type":349,"tunes":2016},{"steps":1990,"title":2015,"orientation":348},[1991,1994,1997,2000,2003,2006,2009,2012],{"label":1992,"description":1993},"1. Business context","The user requests a task under an approved use case with an accountable business owner.",{"label":1995,"description":1996},"2. Identity and authorization","The system resolves user, application, service and tenant or organizational scope before privileged access.",{"label":1998,"description":1999},"3. Authoritative data acquisition","The solution reads or retrieves only sources permitted for the current identity and task.",{"label":2001,"description":2002},"4. AI processing","An approved model\u002Fprovider processes the minimum necessary context under defined routing and data-handling rules.",{"label":2004,"description":2005},"5. Tool or action boundary","Any state-changing action is independently authorized and may require human approval according to consequence.",{"label":2007,"description":2008},"6. Validation","The result is checked against solution-specific acceptance, evidence or safety rules.",{"label":2010,"description":2011},"7. Audit and observability","Permitted metadata, decisions, routes, tool calls and outcomes are recorded without creating uncontrolled sensitive-data logs.",{"label":2013,"description":2014},"8. Feedback and lifecycle","Failures and evaluation results feed model, prompt, data, policy and process changes through controlled change management.","A consequential enterprise AI request",{},{"id":711,"data":2018,"type":42,"tunes":2020},{"text":2019,"level":247},"An enterprise needs an AI inventory before it can govern AI",{},{"id":716,"data":2022,"type":218,"tunes":2024},{"text":2023},"Organizations cannot manage AI systems they cannot identify. Enterprise architecture should maintain an inventory at a level that is useful for decisions, not merely a list of model names.",{},{"id":721,"data":2026,"type":292,"tunes":2064},{"content":2027,"stretched":43,"withHeadings":14},[2028,2031,2034,2037,2040,2043,2046,2049,2052,2055,2058,2061],[2029,2030],"Inventory field","Why it matters",[2032,2033],"Use case and owner","Connects technology to accountable business purpose.",[2035,2036],"Users and affected parties","Defines who interacts with or is affected by the system.",[2038,2039],"Model\u002Fprovider","Identifies external dependency, capability and lifecycle risk.",[2041,2042],"Data sources","Supports authority, privacy, classification and provenance review.",[2044,2045],"Deployment\u002Fruntime location","Clarifies processing location, connectivity and operational control.",[2047,2048],"Tools\u002Factions","Shows whether the AI can change external state and at what consequence.",[2050,2051],"Human oversight","Records where review, approval or escalation is required.",[2053,2054],"Risk\u002Fclassification","Connects the system to organizational and regulatory controls.",[2056,2057],"Evaluation evidence","Shows what was tested and under which validity conditions.",[2059,2060],"Current version","Allows incidents and regressions to be traced to actual deployed state.",[2062,2063],"Lifecycle state","Proposed, experimental, approved, production, restricted, deprecated or retired.",{},{"id":762,"data":2066,"type":42,"tunes":2068},{"text":2067,"level":247},"AI governance and enterprise AI architecture are related but not the same",{},{"id":767,"data":2070,"type":303,"tunes":2086},{"rows":2071,"title":2081,"layout":292,"columns":2082},[2072,2075,2078],{"id":771,"label":2073,"values":2074},"Purpose",[278,278],{"id":775,"label":2076,"values":2077},"Example",[278,278],{"id":779,"label":2079,"values":2080},"Failure if isolated",[278,278],"Governance versus architecture",[2083,2085],{"id":785,"label":2084},"AI Governance",{"id":788,"label":1669},{},{"id":791,"data":2088,"type":42,"tunes":2090},{"text":2089,"level":247},"Regulation becomes an architecture input",{},{"id":796,"data":2092,"type":218,"tunes":2094},{"text":2093},"For organizations operating in the European Union, the AI Act can create requirements that affect system design, documentation, transparency, governance and operating processes. The architectural impact depends on the organization's role in the AI value chain and the concrete system classification; not every AI system has the same obligations.",{},{"id":801,"data":2096,"type":218,"tunes":2098},{"text":2097},"As of 8 October 2026, the current consolidated text states that the Regulation generally applies from 2 August 2026. Governance rules and obligations for general-purpose AI models began applying earlier, while specified high-risk system provisions have later dates. The Commission also began enforcing new transparency requirements from 2 August 2026 for relevant interactive and synthetic-content systems.",{},{"id":806,"data":2100,"type":218,"tunes":2102},{"text":2101},"The enterprise architecture lesson is not “put compliance in the model.” It is to make classification, provider\u002Fdeployer role, documentation, transparency, oversight, logging and change evidence traceable to the system that actually implements the use case.",{},{"id":811,"data":2104,"type":226,"tunes":2107},{"body":2105,"title":2106,"variant":240},"This article describes architecture implications, not legal advice. Enterprise AI architecture should preserve the information needed for legal and compliance specialists to classify the actual system and map obligations to concrete controls. Architecture should not hard-code one regulatory interpretation as if every AI workload had the same status.","Legal scope is use-case specific",{},{"id":817,"data":2109,"type":42,"tunes":2111},{"text":2110,"level":247},"Procurement and architecture become connected",{},{"id":822,"data":2113,"type":218,"tunes":2115},{"text":2114},"An external model or managed AI platform can become a deep dependency even when integration requires only a few API calls. Enterprise architecture should therefore make procurement questions technically concrete.",{},{"id":827,"data":2117,"type":292,"tunes":2146},{"content":2118,"stretched":43,"withHeadings":14},[2119,2122,2125,2128,2131,2134,2137,2140,2143],[2120,2121],"Procurement question","Architecture consequence",[2123,2124],"Where is data processed?","Region, network path, data residency and transfer controls.",[2126,2127],"Is customer data retained or used for provider improvement?","Data minimization, contractual controls and provider eligibility.",[2129,2130],"How are models versioned or retired?","Regression testing, compatibility, fallback and lifecycle planning.",[2132,2133],"What are quotas and service limits?","Capacity architecture, admission control and failure handling.",[2135,2136],"How portable is the integration?","Provider abstraction, exit cost and migration effort.",[2138,2139],"What incident information is available?","Observability, forensic capability and support escalation.",[2141,2142],"Which subprocessors or external services are involved?","Dependency mapping and risk assessment.",[2144,2145],"What changes without explicit customer approval?","Change detection, release gates and acceptance strategy.",{},{"id":859,"data":2148,"type":42,"tunes":2150},{"text":2149,"level":247},"Enterprise architecture decides how much AI control the requirement actually needs",{},{"id":864,"data":2152,"type":292,"tunes":2175},{"content":2153,"stretched":43,"withHeadings":14},[2154,2157,2160,2163,2166,2169,2172],[2155,2156],"Requirement","Possible architectural response",[2158,2159],"Fast access to managed models","Managed provider with enterprise identity, gateway controls and contractual review.",[2161,2162],"Private data with managed orchestration","Managed control plane plus customer-controlled execution or private data plane where supported.",[2164,2165],"Strict locality or sovereignty","Region-restricted, sovereign, private or self-hosted architecture according to the real requirement.",[2167,2168],"Air-gapped environment","Locally hosted models, local retrieval, local tooling, offline update\u002Fdistribution and isolated observability.",[2170,2171],"Provider portability","Application-owned domain state plus adapters and contracts that isolate provider-specific behavior where practical.",[2173,2174],"Highest control of agent semantics","Self-managed or deeply controlled runtime with explicit tool, context, state and lifecycle ownership.",{},{"id":890,"data":2177,"type":218,"tunes":2179},{"text":2178},"The most controlled architecture is not automatically the best enterprise architecture. More ownership increases responsibility for patching, capacity, security, testing, model operations and incident response. Enterprise architecture should escalate control only where the requirement justifies the additional operational burden.",{},{"id":895,"data":2181,"type":42,"tunes":2183},{"text":2182,"level":247},"AI turns change management into a behavioral problem",{},{"id":900,"data":2185,"type":218,"tunes":2187},{"text":2186},"A normal dependency update can alter performance or compatibility. An AI change can also alter behavior. Replacing a model, changing a system prompt, changing retrieval, adding a tool or changing the context policy can modify how the system interprets and responds even if the surrounding application code barely changes.",{},{"id":905,"data":2189,"type":349,"tunes":2216},{"steps":2190,"title":2215,"orientation":348},[2191,2194,2197,2200,2203,2206,2209,2212],{"label":2192,"description":2193},"1. Change identified","Model, provider, prompt, retrieval source, tool, policy or runtime change is proposed or detected.",{"label":2195,"description":2196},"2. Impact mapped","Affected solutions, data classes, users, risk controls, cost, contracts and operational dependencies are identified.",{"label":2198,"description":2199},"3. Architecture decision updated","Material choices and trade-offs are recorded; superseded decisions remain historically traceable.",{"label":2201,"description":2202},"4. Evaluation executed","Relevant regression, safety, retrieval, latency, cost and domain tests are run.",{"label":2204,"description":2205},"5. Approval applied","Approval level follows consequence, risk and organizational policy.",{"label":2207,"description":2208},"6. Controlled rollout","Versioned release, canary or staged deployment is used where appropriate.",{"label":2210,"description":2211},"7. Production evidence collected","Telemetry, incidents, feedback and domain outcomes are monitored.",{"label":2213,"description":2214},"8. Rollback or acceptance","The change is accepted, restricted, rolled back or superseded based on evidence.","A production AI change path",{},{"id":935,"data":2218,"type":42,"tunes":2220},{"text":2219,"level":247},"Enterprise AI still needs NFRs and ADRs",{},{"id":940,"data":2222,"type":218,"tunes":2224},{"text":2223},"AI does not replace ordinary architecture discipline. Non-functional requirements remain the target conditions: availability, latency, privacy, isolation, auditability, recoverability, cost boundaries, explainability or other quality requirements. Architecture Decision Records preserve the chosen response and its trade-offs.",{},{"id":945,"data":2226,"type":218,"tunes":2228},{"text":2227},"The AI-specific difference is that some quality attributes must be evaluated probabilistically or empirically. “Answers must be useful” is too vague. A production requirement should identify the task, data, user population, acceptable failure conditions, measurement method and threshold where practical.",{},{"id":950,"data":2230,"type":226,"tunes":2233},{"body":2231,"title":2232,"variant":288},"\u003Cstrong>Business need → requirement \u002F NFR → architecture decision → implementation → evaluation \u002F validation → production observation → change decision.\u003C\u002Fstrong> AI adds new variables to this chain; it does not make the chain unnecessary.","Enterprise traceability chain",{},{"id":956,"data":2235,"type":42,"tunes":2237},{"text":2236,"level":247},"Enterprise AI architecture must connect to delivery",{},{"id":961,"data":2239,"type":218,"tunes":2241},{"text":2240},"Architecture that never reaches backlog, implementation, acceptance and operations remains conceptual. Enterprise AI therefore needs traceability from architecture decisions into delivery work and back from implementation evidence into architecture.",{},{"id":966,"data":2243,"type":218,"tunes":2245},{"text":2244},"Jira and Confluence are examples of tools that can support this separation when used deliberately: Confluence can preserve requirements, architecture, decisions, risks and rationale; Jira can manage actionable delivery work and state. The important principle is the traceability, not the brand of tool.",{},{"id":971,"data":2247,"type":42,"tunes":2249},{"text":2248,"level":247},"Original project evidence: Enterprise Aaasaasa 0.1",{},{"id":976,"data":2251,"type":226,"tunes":2254},{"body":2252,"title":2253,"variant":240},"Enterprise Aaasaasa 0.1 is used here as original project evidence for structured enterprise architecture and delivery thinking. It is a PoC \u002F enterprise project context, not evidence of mass customer adoption, enterprise-scale production usage or commercial traction.","Project evidence, not market-proof claim",{},{"id":982,"data":2256,"type":218,"tunes":2258},{"text":2257},"Enterprise Aaasaasa 0.1 combines platform architecture, SaaS\u002FAPI concepts, internationalization, AI integration and structured project governance. The project was deliberately organized so that requirements, architecture, prototype delivery, validation and closure were separate milestones rather than one undifferentiated implementation phase.",{},{"id":987,"data":2260,"type":218,"tunes":2262},{"text":2261},"The architecture direction includes multi-instance \u002F multi-database concepts together with API, CRUD, i18n and AI capabilities. That matters for enterprise AI because tenant or instance boundaries, database ownership and application services must remain explicit when AI features are added.",{},{"id":992,"data":2264,"type":218,"tunes":2266},{"text":2265},"The project structure also treated architecture delay, scope creep and AI\u002Fdata-protection concerns as project risks rather than discovering them only during implementation. Stakeholders included technical, security, sponsor\u002Fsteering and external-service perspectives, which is closer to the real cross-functional nature of enterprise AI than a model-only prototype.",{},{"id":997,"data":2268,"type":218,"tunes":2270},{"text":2269},"The useful evidence is therefore the integration of architecture and delivery: business and project structure, milestones, risks, architecture, backend\u002FAPI, frontend\u002FAI work, validation and closure are treated as connected responsibilities. That pattern is reusable even though the project itself should not be presented as proof of external enterprise adoption.",{},{"id":1002,"data":2272,"type":292,"tunes":2298},{"content":2273,"stretched":43,"withHeadings":14},[2274,2277,2280,2283,2286,2289,2292,2295],[2275,2276],"Project element","Enterprise AI architecture lesson",[2278,2279],"Requirements milestone","AI capability must begin from defined need, scope, acceptance and quality constraints.",[2281,2282],"Architecture milestone","Data, API, instance\u002Fdatabase boundaries and AI integration are explicit design work.",[2284,2285],"Prototype milestone","Architecture must become executable enough to expose integration risks.",[2287,2288],"Validation milestone","A functioning prototype is not the same as validated acceptance.",[2290,2291],"Risk register","Scope, architecture delay and AI\u002Fdata-protection concerns are managed as delivery risks.",[2293,2294],"Stakeholder structure","Enterprise AI spans sponsor\u002Fbusiness, architecture, security, external providers and delivery.",[2296,2297],"Project closure","Decisions, remaining risks and validation evidence must survive beyond the implementation sprint.",{},{"id":1031,"data":2300,"type":42,"tunes":2302},{"text":2301,"level":247},"Supporting implementation patterns from the wider platform work",{},{"id":1036,"data":2304,"type":218,"tunes":2306},{"text":2305},"Separate implementation work in the wider Aaasaasa platform provides concrete examples of boundaries that enterprise AI architecture must preserve: tenant-scoped RBAC in the CMS, explicit provider\u002Fmodel\u002Fruntime\u002Fpermission separation in Aaasaasa AI Client, and provenance-first retrieval in the Source of Truth Research Engine.",{},{"id":1041,"data":2308,"type":218,"tunes":2310},{"text":2309},"These projects should not be collapsed into one claimed production platform. Their value here is narrower: they demonstrate implemented patterns for identity scope, provider boundaries, controlled runtime permissions, retrieval provenance and evidence traceability that are directly relevant to enterprise AI.",{},{"id":1046,"data":2312,"type":42,"tunes":2314},{"text":2313,"level":247},"How the main standards fit together",{},{"id":1051,"data":2316,"type":292,"tunes":2333},{"content":2317,"stretched":43,"withHeadings":14},[2318,2321,2323,2325,2327,2329,2331],[2319,2320],"Source","What it contributes to enterprise AI architecture",[1058,2322],"Organization-level AI management system: policies, objectives, processes, responsibility, monitoring and continual improvement.",[1061,2324],"Guidance for integrating AI-specific risk management into organizational activities and functions.",[1064,2326],"Voluntary lifecycle-oriented framework for managing AI risks; organized around Govern, Map, Measure and Manage.",[1067,2328],"Generative AI profile extending AI RMF with generative-AI-specific risks and actions.",[1070,2330],"Binding regulatory obligations in the EU whose applicability depends on role, system type and classification.",[1073,2332],"General architecture-description concepts for expressing concerns, viewpoints, decisions and relationships.",{},{"id":1077,"data":2335,"type":218,"tunes":2337},{"text":2336},"These sources solve different problems. ISO\u002FIEC 42001 is not a replacement for technical architecture. ISO\u002FIEC 23894 and NIST AI RMF do not define one mandatory software stack. The EU AI Act is law, not a platform design pattern. Architecture must translate the applicable organizational, risk and legal requirements into implementable system boundaries and evidence.",{},{"id":1082,"data":2339,"type":42,"tunes":2341},{"text":2340,"level":247},"Common enterprise AI failure modes",{},{"id":1087,"data":2343,"type":292,"tunes":2381},{"content":2344,"stretched":43,"withHeadings":14},[2345,2348,2351,2354,2357,2360,2363,2366,2369,2372,2375,2378],[2346,2347],"Failure mode","Why it fails",[2349,2350],"Every team buys AI independently","Creates shadow providers, duplicated secrets, inconsistent data handling and weak leverage over supplier risk.",[2352,2353],"One central AI team owns every domain decision","Centralizes technical control but loses domain accountability and creates a bottleneck.",[2355,2356],"Vector database becomes the source of truth","Retrieval infrastructure silently replaces authoritative systems and freshness rules.",[2358,2359],"One shared API key for all users and agents","Destroys attribution, least privilege and meaningful auditability.",[2361,2362],"Model change deployed like a minor library patch","Behavioral regressions can reach production without domain evaluation.",[2364,2365],"All prompts and outputs are logged forever","Observability creates an uncontrolled sensitive-data repository.",[2367,2368],"Governance is only documentation","Policies exist without enforcement points, evidence or operational ownership.",[2370,2371],"Compliance is delegated to the provider","The organization's own role, use case, data and operational obligations remain unresolved.",[2373,2374],"Agent can call tools because the model supports tool use","Capability is mistaken for authorization.",[2376,2377],"Platform health equals business correctness","Endpoint uptime and model availability do not prove domain answer quality or acceptable outcomes.",[2379,2380],"No exit strategy for model\u002Fprovider dependency","A pricing, policy, capability or availability change becomes an emergency migration.",{},{"id":1128,"data":2383,"type":42,"tunes":2385},{"text":2384,"level":247},"Common misconceptions",{},{"id":1133,"data":2387,"type":292,"tunes":2416},{"content":2388,"stretched":43,"withHeadings":14},[2389,2392,2395,2398,2401,2404,2407,2410,2413],[2390,2391],"Misconception","Better model",[2393,2394],"“Enterprise AI means a company-wide chatbot.”","The chatbot is one interface; enterprise AI architecture governs the underlying data, identity, provider, runtime, risk and operations.",[2396,2397],"“If we use a reputable model provider, governance is solved.”","Provider controls do not define your use case, data authority, user permissions, business acceptance or legal role.",[2399,2400],"“Private AI means everything must be self-hosted.”","Privacy requirements can lead to several architectures; the required control boundary must be stated precisely.",[2402,2403],"“AI governance belongs to legal, architecture belongs to IT.”","The two disciplines must connect because policy obligations need implementable controls and evidence.",[2405,2406],"“One enterprise model is simpler.”","Standardization can help, but workloads can require different modalities, regions, costs, quality levels or control models.",[2408,2409],"“AI risk is model risk.”","Risk can originate in data, prompts, retrieval, identity, tools, interfaces, operations, users and organizational process.",[2411,2412],"“Human-in-the-loop makes an agent safe.”","Human approval helps only if the reviewer has useful context, authority, time and a clear decision point.",[2414,2415],"“A successful pilot proves enterprise readiness.”","A pilot proves bounded capability; enterprise readiness also requires integration, governance, lifecycle, operations and repeatable controls.",{},{"id":1165,"data":2418,"type":42,"tunes":2420},{"text":2419,"level":247},"A practical enterprise AI architecture decision sequence",{},{"id":1170,"data":2422,"type":349,"tunes":2461},{"steps":2423,"title":2460,"orientation":348},[2424,2427,2430,2433,2436,2439,2442,2445,2448,2451,2454,2457],{"label":2425,"description":2426},"1. Define the business capability","State the user, decision or workflow, expected value and accountable owner.",{"label":2428,"description":2429},"2. Classify data and authority","Identify systems of record, personal\u002Fconfidential data, retention, freshness and provenance requirements.",{"label":2431,"description":2432},"3. Define identity and action boundaries","Determine who may read, generate, decide, approve and change external systems.",{"label":2434,"description":2435},"4. Select solution and platform responsibilities","Decide what belongs to the workload, what can be shared and what remains enterprise-owned.",{"label":2437,"description":2438},"5. Assess provider and runtime dependency","Evaluate managed, self-hosted, private, sovereign or hybrid options against real requirements.",{"label":2440,"description":2441},"6. Map risk and regulatory obligations","Determine risk level, organizational controls and applicable legal responsibilities for the concrete system.",{"label":2443,"description":2444},"7. Define measurable acceptance","Create evaluation criteria for quality, reliability, safety, retrieval, cost and operational behavior.",{"label":2446,"description":2447},"8. Record architecture decisions","Preserve rationale, alternatives, trade-offs, dependencies and conditions that would trigger reconsideration.",{"label":2449,"description":2450},"9. Connect architecture to delivery","Translate the design into backlog, milestones, acceptance criteria, technical work and ownership.",{"label":2452,"description":2453},"10. Validate in production-shaped conditions","Test realistic identity, data, failure, latency, provider, tool and recovery scenarios rather than only clean demos.",{"label":2455,"description":2456},"11. Establish operations and change control","Define monitoring, incident response, model\u002Fprovider updates, regression testing, rollback and retirement.",{"label":2458,"description":2459},"12. Feed evidence back into architecture","Use production observations, audits, incidents and evaluations to revise decisions and controls.","From opportunity to governed enterprise capability",{},{"id":1212,"data":2463,"type":42,"tunes":2465},{"text":2464,"level":247},"Enterprise AI architecture checklist",{},{"id":1217,"data":2467,"type":292,"tunes":2514},{"content":2468,"stretched":43,"withHeadings":14},[2469,2472,2475,2478,2481,2484,2487,2490,2493,2496,2499,2502,2505,2508,2511],[2470,2471],"Question","Expected evidence",[2473,2474],"What business capability does this AI support?","Named owner, user group, intended decision\u002Fworkflow and acceptance objective.",[2476,2477],"Which source is authoritative for each important fact?","Systems of record, document authority, provenance and freshness rules.",[2479,2480],"Which identities exist?","Human, application, service, agent, tenant\u002Forg and provider identities are distinguishable.",[2482,2483],"What can the AI read?","Authorization-scoped data sources and explicit sensitive-data rules.",[2485,2486],"What can the AI change?","Tool\u002Faction inventory, permission model, approval and rollback path.",[2488,2489],"Which provider\u002Fmodel is used and why?","Architecture decision including quality, security, cost, region, lifecycle and exit considerations.",[2491,2492],"What happens if the provider is unavailable?","Degraded mode, fallback, refusal or continuity plan.",[2494,2495],"How is quality evaluated?","Task-specific datasets, graders, thresholds, regression criteria and validity conditions.",[2497,2498],"What is logged?","Telemetry schema, redaction, access, retention and audit purpose.",[2500,2501],"Who owns AI risk?","Named organizational responsibility connected to the concrete system.",[2503,2504],"What legal classification applies?","Documented assessment based on the current law and the actual use case.",[2506,2507],"How are model\u002Fprompt\u002Fretrieval changes approved?","Versioning, evaluation, architecture\u002Fchange record and rollout gate.",[2509,2510],"Who responds to an AI incident?","Runbook, technical owner, business\u002Fdomain escalation and provider escalation.",[2512,2513],"How is the system retired?","Data cleanup, access revocation, provider exit, evidence retention and dependency removal.",{},{"id":1267,"data":2516,"type":42,"tunes":2518},{"text":2517,"level":247},"Edge cases and limits",{},{"id":1272,"data":2520,"type":218,"tunes":2522},{"text":2521},"A small company with one low-risk AI use case may not need a formal enterprise AI architecture function. The same principles can be applied lightly: clear owner, approved data, explicit provider, basic evaluation, access control and operational responsibility.",{},{"id":1277,"data":2524,"type":218,"tunes":2526},{"text":2525},"A highly regulated organization may need stronger separation, independent validation, formal conformity processes, local hosting or air-gapped operation. Those controls are driven by the use case and regulatory environment, not by the word “enterprise.”",{},{"id":1282,"data":2528,"type":218,"tunes":2530},{"text":2529},"An organization can also use mostly SaaS AI products rather than building AI systems. Enterprise architecture still matters because identity, data access, contractual terms, shadow AI, retention, audit and supplier concentration remain organizational concerns.",{},{"id":1287,"data":2532,"type":218,"tunes":2534},{"text":2533},"A centralized platform is not mandatory. Federated platform ownership can be valid when domains have materially different requirements, provided enterprise-level identity, risk, inventory and interoperability responsibilities remain coherent.",{},{"id":1292,"data":2536,"type":42,"tunes":2538},{"text":2537,"level":247},"What would change this answer?",{},{"id":1297,"data":2540,"type":218,"tunes":2542},{"text":2541},"The architecture changes when the organization's risk tolerance, regulatory classification, data sensitivity, geographic scope, provider strategy, internal skills or business criticality changes. A public marketing assistant and a system participating in employment, finance, healthcare or critical infrastructure decisions should not inherit identical control models.",{},{"id":1302,"data":2544,"type":218,"tunes":2546},{"text":2545},"The implementation also changes as standards, regulation and AI platforms evolve. NIST AI RMF 1.0 is currently under revision, the EU AI Act has phased application dates, and model\u002Fprovider capabilities continue to change rapidly. Enterprise architecture should therefore preserve stable responsibility boundaries while treating provider mechanisms and regulatory details as versioned inputs.",{},{"id":1307,"data":2548,"type":42,"tunes":2550},{"text":2549,"level":247},"Related canonical knowledge",{},{"id":1312,"data":2552,"type":218,"tunes":2554},{"text":2553},"Enterprise AI architecture builds on solution and platform architecture. The solution layer explains one workload. The platform layer explains reusable AI capabilities. The enterprise layer connects both to organization-wide data, identity, governance, risk, procurement and operations.",{},{"id":1317,"data":2556,"type":218,"tunes":2558},{"text":2557},"Retrieval-Augmented Generation is only one mechanism inside this architecture. RAG can improve access to enterprise knowledge, but it does not solve data authority, permissions, governance or answer validity by itself.",{},{"id":1322,"data":2560,"type":1328,"tunes":2565},{"url":2561,"title":2562,"excerpt":2563,"ctaLabel":2564},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","What Is RAG? The Simplest Explanation of How It Works","A plain-English explanation of how external knowledge retrieval connects to the language model without turning retrieval into the source of truth.","Read the RAG foundation",{},{"id":1331,"data":2567,"type":218,"tunes":2569},{"text":2568},"For evidence-heavy enterprise use cases, answer validity also needs an explicit boundary: an output is only supported under the evidence, version, scope and assumptions that produced it.",{},{"id":1336,"data":2571,"type":1328,"tunes":2576},{"url":2572,"title":2573,"excerpt":2574,"ctaLabel":2575},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","A framework for making explicit the conditions under which an AI claim remains supported and what changes require restriction or recalculation.","Read the Answer Validity Boundary",{},{"id":1344,"data":2578,"type":218,"tunes":2580},{"text":2579},"Downstream enterprise topics include AI Governance, Private AI, Sovereign AI, Air-Gapped AI, Multi-Tenant AI Architecture, RBAC versus Tenant Isolation, Provider Abstraction, Model Routing and Production AI Architecture.",{},{"id":1349,"data":2582,"type":42,"tunes":2584},{"text":2583,"level":247},"Frequently asked questions",{},{"id":1354,"data":2586,"type":1354,"tunes":2613},{"items":2587,"title":2612},[2588,2591,2594,2597,2600,2603,2606,2609],{"id":1358,"answer":2589,"question":2590},"Enterprise AI architecture is the organization-wide architecture that defines how AI solutions and shared AI capabilities integrate with business ownership, enterprise data, identity, security, providers, governance, risk, compliance, lifecycle and operations.","What is enterprise AI architecture?",{"id":1362,"answer":2592,"question":2593},"No. An AI platform provides reusable technical capabilities such as model access, retrieval, agent runtimes and observability. Enterprise AI architecture defines how that platform and individual AI solutions fit into the organization's wider architecture and operating model.","Is enterprise AI architecture the same as an AI platform?",{"id":1366,"answer":2595,"question":2596},"No. Standardization can reduce complexity, but different workloads may require different providers, models, regions, control levels or modalities. The important requirement is explicit policy and lifecycle ownership.","Does enterprise AI require one central model?",{"id":1370,"answer":2598,"question":2599},"Because retrieved or generated information is not automatically authoritative. Enterprise systems need to preserve which source is the system of record, whether data is current, who may access it and how a generated claim can be traced back to evidence.","Why is data authority important for enterprise AI?",{"id":1374,"answer":2601,"question":2602},"AI governance defines policies, accountability and decision rights. Enterprise AI architecture defines the system boundaries, interfaces, data flows and technical mechanisms through which those policies can be implemented and evidenced.","What is the difference between AI governance and enterprise AI architecture?",{"id":1378,"answer":2604,"question":2605},"No. Obligations depend on factors such as the organization's role, the system's use case and classification, and the relevant provisions in force. Legal classification must be performed for the concrete system under the current law.","Does the EU AI Act apply to every enterprise AI system in the same way?",{"id":1382,"answer":2607,"question":2608},"No. A pilot demonstrates bounded capability. Enterprise deployment also needs identity, data authority, security, provider governance, evaluation, lifecycle, incident response, monitoring, compliance and accountable operational ownership.","Is a successful AI pilot enough for enterprise deployment?",{"id":1386,"answer":2610,"question":2611},"Only when the requirement justifies the added control and operational responsibility. Managed, private, sovereign, self-hosted and hybrid approaches are architecture options whose fit depends on data, regulatory, availability, cost, capability and operational requirements.","Should enterprises self-host AI?","Enterprise AI architecture FAQ",{},{"id":1392,"data":2615,"type":42,"tunes":2617},{"text":2616,"level":247},"Glossary",{},{"id":1397,"data":2619,"type":1397,"tunes":2649},{"title":2620,"entries":2621},"Key enterprise AI architecture terms",[2622,2625,2628,2630,2633,2636,2639,2641,2643,2646],{"term":2623,"anchor":1403,"definition":2624},"Enterprise AI architecture","Organization-wide architecture governing how AI systems, platforms, data, identities, providers, risk controls and operations fit together.",{"term":2626,"anchor":1407,"definition":2627},"AI management system","An organizational management system for establishing AI-related policies, objectives and processes; ISO\u002FIEC 42001 specifies requirements for such a system.",{"term":1911,"anchor":1411,"definition":2629},"The rule that identifies which source or system is authoritative for a particular fact, record, state or decision context.",{"term":2631,"anchor":1415,"definition":2632},"System of record","The authoritative system responsible for the official current state of a business record or domain entity.",{"term":2634,"anchor":1419,"definition":2635},"AI inventory","A structured record of AI use cases, owners, models\u002Fproviders, data, tools, risk, evaluation evidence, lifecycle state and related controls.",{"term":2637,"anchor":1423,"definition":2638},"Provider dependency","The technical, contractual and operational reliance created when an AI workload depends on an external model or managed platform.",{"term":2050,"anchor":1426,"definition":2640},"Defined human review, approval, intervention or escalation applied where system consequence, uncertainty or regulation requires it.",{"term":1429,"anchor":1430,"definition":2642},"Operational practices for generative-AI workloads covering model selection, prompts, grounding data, evaluation, deployment, monitoring and lifecycle management.",{"term":2644,"anchor":1434,"definition":2645},"AI risk management","The organizational process of identifying, assessing, treating, monitoring and revising risks associated with AI systems across their lifecycle.",{"term":2647,"anchor":1438,"definition":2648},"Architecture decision","A material design choice together with its context, rationale, alternatives, trade-offs and lifecycle status.",{},{"id":1442,"data":2651,"type":42,"tunes":2653},{"text":2652,"level":247},"Conclusion",{},{"id":1447,"data":2655,"type":218,"tunes":2657},{"text":2656},"When AI enters a company, the enterprise does not merely gain a new software component. It gains a new class of behavior and dependency that cuts across data, identity, suppliers, business decisions, security, operations, governance and change management.",{},{"id":1452,"data":2659,"type":218,"tunes":2661},{"text":2660},"The architectural response is not to centralize everything. It is to make responsibilities explicit: which data is authoritative, which identities may act, which providers are approved, which controls are shared, which decisions remain domain-owned, how behavior is evaluated, how incidents are handled and how the system changes over time.",{},{"id":1457,"data":2663,"type":218,"tunes":2665},{"text":2664},"That is the core distinction of enterprise AI architecture: it turns isolated AI capability into an organizationally governable system without pretending that models, platforms, business domains and enterprise controls are the same thing.",{},{"id":1462,"data":2667,"type":42,"tunes":2669},{"text":2668,"level":247},"Primary sources and current guidance",{},{"id":1467,"data":2671,"type":218,"tunes":2673},{"text":2672},"External standards, regulation and current vendor architecture guidance below were checked on 8 October 2026. Project-specific sections are explicitly marked as original project evidence and should not be read as claims of general industry fact.",{},{"id":1472,"data":2675,"type":1479,"tunes":2680},{"link":1474,"meta":2676},{"image":2677,"title":2678,"description":2679},{"url":278},"ISO\u002FIEC 42001:2023 — Artificial intelligence management system","International standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system within organizations.",{},{"id":1482,"data":2682,"type":1479,"tunes":2687},{"link":1484,"meta":2683},{"image":2684,"title":2685,"description":2686},{"url":278},"ISO\u002FIEC 23894:2023 — Guidance on AI risk management","International guidance for integrating AI-specific risk management into organizational activities and functions.",{},{"id":1491,"data":2689,"type":1479,"tunes":2694},{"link":1493,"meta":2690},{"image":2691,"title":2692,"description":2693},{"url":278},"NIST AI Risk Management Framework","NIST's voluntary lifecycle-oriented framework for managing AI risk. NIST states that AI RMF 1.0 is currently being revised.",{},{"id":1500,"data":2696,"type":1479,"tunes":2701},{"link":1502,"meta":2697},{"image":2698,"title":2699,"description":2700},{"url":278},"NIST AI 600-1 — Generative AI Profile","NIST companion profile describing generative-AI-specific risks and risk-management actions aligned to the AI RMF.",{},{"id":1509,"data":2703,"type":1479,"tunes":2708},{"link":1511,"meta":2704},{"image":2705,"title":2706,"description":2707},{"url":278},"EUR-Lex — Regulation (EU) 2024\u002F1689, consolidated text","Current consolidated AI Act text used for application dates and regulatory structure as checked on 8 October 2026.",{},{"id":1518,"data":2710,"type":1479,"tunes":2715},{"link":1520,"meta":2711},{"image":2712,"title":2713,"description":2714},{"url":278},"European Commission — AI Act regulatory framework","Current Commission overview of AI Act application phases, including 2026 applicability and later dates for specified high-risk provisions.",{},{"id":1527,"data":2717,"type":1479,"tunes":2722},{"link":1529,"meta":2718},{"image":2719,"title":2720,"description":2721},{"url":278},"Microsoft Azure Well-Architected — AI workloads","Current architecture guidance on AI workloads, including nondeterministic behavior, data, application design and operations.",{},{"id":1536,"data":2724,"type":1479,"tunes":2729},{"link":1538,"meta":2725},{"image":2726,"title":2727,"description":2728},{"url":278},"Microsoft — MLOps and GenAIOps for AI workloads","Current guidance on operational lifecycle, data, model maintenance, deployment, monitoring and continuous evolution.",{},{"id":1545,"data":2731,"type":1479,"tunes":2736},{"link":1547,"meta":2732},{"image":2733,"title":2734,"description":2735},{"url":278},"Microsoft — Responsible AI in Azure workloads","Current guidance connecting AI policy to data control, identity, agent auditability, role-based access and operational safeguards.",{},{"id":1554,"data":2738,"type":1479,"tunes":2743},{"link":1556,"meta":2739},{"image":2740,"title":2741,"description":2742},{"url":278},"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description","Current architecture-description standard supporting explicit concerns, viewpoints and relationships across system architecture.",{},"2.31.6","Enterprise AI architecture explains how AI changes company systems across data authority, identity, permissions, providers, risk, governance, evaluation, compliance and operations.",{"lang":7,"title":208,"content":210,"contentJson":2747,"excerpt":1563},{"time":212,"blocks":2748,"version":1562},[2749,2752,2755,2758,2761,2764,2767,2770,2773,2776,2792,2795,2798,2801,2804,2814,2817,2820,2823,2826,2829,2832,2835,2838,2841,2844,2847,2850,2853,2856,2859,2862,2865,2868,2871,2874,2877,2880,2883,2886,2889,2892,2895,2898,2901,2904,2907,2910,2913,2916,2919,2922,2925,2928,2931,2934,2937,2940,2943,2946,2961,2964,2967,2970,2983,2986,2989,3001,3004,3007,3023,3026,3039,3042,3045,3048,3051,3054,3057,3060,3073,3076,3087,3090,3093,3096,3108,3111,3114,3117,3120,3123,3126,3129,3132,3135,3138,3141,3144,3147,3159,3162,3165,3168,3171,3182,3185,3188,3204,3207,3220,3223,3239,3242,3261,3264,3267,3270,3273,3276,3279,3282,3285,3288,3291,3294,3297,3300,3303,3306,3309,3321,3324,3338,3341,3344,3347,3350,3353,3356,3361,3366,3371,3376,3381,3386,3391,3396,3401],{"id":215,"data":2750,"type":218,"tunes":2751},{"text":217},{},{"id":221,"data":2753,"type":226,"tunes":2754},{"body":223,"title":224,"variant":225},{},{"id":229,"data":2756,"type":226,"tunes":2757},{"body":231,"title":232,"variant":233},{},{"id":236,"data":2759,"type":226,"tunes":2760},{"body":238,"title":239,"variant":240},{},{"id":243,"data":2762,"type":248,"tunes":2763},{"title":245,"maxLevel":246,"minLevel":247},{},{"id":251,"data":2765,"type":42,"tunes":2766},{"text":253,"level":247},{},{"id":256,"data":2768,"type":218,"tunes":2769},{"text":258},{},{"id":261,"data":2771,"type":218,"tunes":2772},{"text":263},{},{"id":266,"data":2774,"type":218,"tunes":2775},{"text":268},{},{"id":271,"data":2777,"type":303,"tunes":2791},{"rows":2778,"title":291,"layout":292,"columns":2787},[2779,2781,2783,2785],{"id":275,"label":276,"values":2780},[278,278,278],{"id":280,"label":281,"values":2782},[278,278,278],{"id":284,"label":285,"values":2784},[278,278,278],{"id":288,"label":289,"values":2786},[278,278,278],[2788,2789,2790],{"id":295,"label":296},{"id":298,"label":299},{"id":301,"label":302},{},{"id":306,"data":2793,"type":42,"tunes":2794},{"text":308,"level":247},{},{"id":311,"data":2796,"type":218,"tunes":2797},{"text":313},{},{"id":316,"data":2799,"type":218,"tunes":2800},{"text":318},{},{"id":321,"data":2802,"type":218,"tunes":2803},{"text":323},{},{"id":326,"data":2805,"type":349,"tunes":2813},{"steps":2806,"title":347,"orientation":348},[2807,2808,2809,2810,2811,2812],{"label":330,"description":331},{"label":333,"description":334},{"label":336,"description":337},{"label":339,"description":340},{"label":342,"description":343},{"label":345,"description":346},{},{"id":352,"data":2815,"type":42,"tunes":2816},{"text":354,"level":247},{},{"id":357,"data":2818,"type":218,"tunes":2819},{"text":359},{},{"id":362,"data":2821,"type":218,"tunes":2822},{"text":364},{},{"id":367,"data":2824,"type":42,"tunes":2825},{"text":369,"level":247},{},{"id":372,"data":2827,"type":42,"tunes":2828},{"text":374,"level":246},{},{"id":377,"data":2830,"type":218,"tunes":2831},{"text":379},{},{"id":382,"data":2833,"type":218,"tunes":2834},{"text":384},{},{"id":387,"data":2836,"type":42,"tunes":2837},{"text":389,"level":246},{},{"id":392,"data":2839,"type":218,"tunes":2840},{"text":394},{},{"id":397,"data":2842,"type":218,"tunes":2843},{"text":399},{},{"id":402,"data":2845,"type":218,"tunes":2846},{"text":404},{},{"id":407,"data":2848,"type":226,"tunes":2849},{"body":409,"title":410,"variant":288},{},{"id":413,"data":2851,"type":42,"tunes":2852},{"text":415,"level":246},{},{"id":418,"data":2854,"type":218,"tunes":2855},{"text":420},{},{"id":423,"data":2857,"type":218,"tunes":2858},{"text":425},{},{"id":428,"data":2860,"type":218,"tunes":2861},{"text":430},{},{"id":433,"data":2863,"type":42,"tunes":2864},{"text":435,"level":246},{},{"id":438,"data":2866,"type":218,"tunes":2867},{"text":440},{},{"id":443,"data":2869,"type":218,"tunes":2870},{"text":445},{},{"id":448,"data":2872,"type":42,"tunes":2873},{"text":450,"level":246},{},{"id":453,"data":2875,"type":218,"tunes":2876},{"text":455},{},{"id":458,"data":2878,"type":218,"tunes":2879},{"text":460},{},{"id":463,"data":2881,"type":218,"tunes":2882},{"text":465},{},{"id":468,"data":2884,"type":42,"tunes":2885},{"text":470,"level":246},{},{"id":473,"data":2887,"type":218,"tunes":2888},{"text":475},{},{"id":478,"data":2890,"type":218,"tunes":2891},{"text":480},{},{"id":483,"data":2893,"type":218,"tunes":2894},{"text":485},{},{"id":488,"data":2896,"type":42,"tunes":2897},{"text":490,"level":246},{},{"id":493,"data":2899,"type":218,"tunes":2900},{"text":495},{},{"id":498,"data":2902,"type":218,"tunes":2903},{"text":500},{},{"id":503,"data":2905,"type":42,"tunes":2906},{"text":505,"level":246},{},{"id":508,"data":2908,"type":218,"tunes":2909},{"text":510},{},{"id":513,"data":2911,"type":218,"tunes":2912},{"text":515},{},{"id":518,"data":2914,"type":218,"tunes":2915},{"text":520},{},{"id":523,"data":2917,"type":42,"tunes":2918},{"text":525,"level":246},{},{"id":528,"data":2920,"type":218,"tunes":2921},{"text":530},{},{"id":533,"data":2923,"type":218,"tunes":2924},{"text":535},{},{"id":538,"data":2926,"type":42,"tunes":2927},{"text":540,"level":246},{},{"id":543,"data":2929,"type":218,"tunes":2930},{"text":545},{},{"id":548,"data":2932,"type":218,"tunes":2933},{"text":550},{},{"id":553,"data":2935,"type":42,"tunes":2936},{"text":555,"level":246},{},{"id":558,"data":2938,"type":218,"tunes":2939},{"text":560},{},{"id":563,"data":2941,"type":218,"tunes":2942},{"text":565},{},{"id":568,"data":2944,"type":42,"tunes":2945},{"text":570,"level":247},{},{"id":573,"data":2947,"type":292,"tunes":2960},{"content":2948,"stretched":43,"withHeadings":14},[2949,2950,2951,2952,2953,2954,2955,2956,2957,2958,2959],[577,578,579],[581,582,583],[585,586,587],[589,590,591],[593,594,595],[597,598,599],[601,602,603],[605,606,607],[609,610,611],[613,614,615],[617,618,619],{},{"id":622,"data":2962,"type":226,"tunes":2963},{"body":624,"title":625,"variant":233},{},{"id":628,"data":2965,"type":42,"tunes":2966},{"text":630,"level":247},{},{"id":633,"data":2968,"type":226,"tunes":2969},{"body":635,"title":636,"variant":240},{},{"id":639,"data":2971,"type":292,"tunes":2982},{"content":2972,"stretched":43,"withHeadings":14},[2973,2974,2975,2976,2977,2978,2979,2980,2981],[643,644],[646,647],[649,650],[652,653],[655,656],[658,659],[661,662],[664,665],[667,668],{},{"id":671,"data":2984,"type":218,"tunes":2985},{"text":673},{},{"id":676,"data":2987,"type":42,"tunes":2988},{"text":678,"level":247},{},{"id":681,"data":2990,"type":349,"tunes":3000},{"steps":2991,"title":708,"orientation":348},[2992,2993,2994,2995,2996,2997,2998,2999],{"label":685,"description":686},{"label":688,"description":689},{"label":691,"description":692},{"label":694,"description":695},{"label":697,"description":698},{"label":700,"description":701},{"label":703,"description":704},{"label":706,"description":707},{},{"id":711,"data":3002,"type":42,"tunes":3003},{"text":713,"level":247},{},{"id":716,"data":3005,"type":218,"tunes":3006},{"text":718},{},{"id":721,"data":3008,"type":292,"tunes":3022},{"content":3009,"stretched":43,"withHeadings":14},[3010,3011,3012,3013,3014,3015,3016,3017,3018,3019,3020,3021],[725,726],[728,729],[731,732],[734,735],[737,738],[740,741],[743,744],[746,747],[749,750],[752,753],[755,756],[758,759],{},{"id":762,"data":3024,"type":42,"tunes":3025},{"text":764,"level":247},{},{"id":767,"data":3027,"type":303,"tunes":3038},{"rows":3028,"title":782,"layout":292,"columns":3035},[3029,3031,3033],{"id":771,"label":772,"values":3030},[278,278],{"id":775,"label":776,"values":3032},[278,278],{"id":779,"label":780,"values":3034},[278,278],[3036,3037],{"id":785,"label":786},{"id":788,"label":302},{},{"id":791,"data":3040,"type":42,"tunes":3041},{"text":793,"level":247},{},{"id":796,"data":3043,"type":218,"tunes":3044},{"text":798},{},{"id":801,"data":3046,"type":218,"tunes":3047},{"text":803},{},{"id":806,"data":3049,"type":218,"tunes":3050},{"text":808},{},{"id":811,"data":3052,"type":226,"tunes":3053},{"body":813,"title":814,"variant":240},{},{"id":817,"data":3055,"type":42,"tunes":3056},{"text":819,"level":247},{},{"id":822,"data":3058,"type":218,"tunes":3059},{"text":824},{},{"id":827,"data":3061,"type":292,"tunes":3072},{"content":3062,"stretched":43,"withHeadings":14},[3063,3064,3065,3066,3067,3068,3069,3070,3071],[831,832],[834,835],[837,838],[840,841],[843,844],[846,847],[849,850],[852,853],[855,856],{},{"id":859,"data":3074,"type":42,"tunes":3075},{"text":861,"level":247},{},{"id":864,"data":3077,"type":292,"tunes":3086},{"content":3078,"stretched":43,"withHeadings":14},[3079,3080,3081,3082,3083,3084,3085],[868,869],[871,872],[874,875],[877,878],[880,881],[883,884],[886,887],{},{"id":890,"data":3088,"type":218,"tunes":3089},{"text":892},{},{"id":895,"data":3091,"type":42,"tunes":3092},{"text":897,"level":247},{},{"id":900,"data":3094,"type":218,"tunes":3095},{"text":902},{},{"id":905,"data":3097,"type":349,"tunes":3107},{"steps":3098,"title":932,"orientation":348},[3099,3100,3101,3102,3103,3104,3105,3106],{"label":909,"description":910},{"label":912,"description":913},{"label":915,"description":916},{"label":918,"description":919},{"label":921,"description":922},{"label":924,"description":925},{"label":927,"description":928},{"label":930,"description":931},{},{"id":935,"data":3109,"type":42,"tunes":3110},{"text":937,"level":247},{},{"id":940,"data":3112,"type":218,"tunes":3113},{"text":942},{},{"id":945,"data":3115,"type":218,"tunes":3116},{"text":947},{},{"id":950,"data":3118,"type":226,"tunes":3119},{"body":952,"title":953,"variant":288},{},{"id":956,"data":3121,"type":42,"tunes":3122},{"text":958,"level":247},{},{"id":961,"data":3124,"type":218,"tunes":3125},{"text":963},{},{"id":966,"data":3127,"type":218,"tunes":3128},{"text":968},{},{"id":971,"data":3130,"type":42,"tunes":3131},{"text":973,"level":247},{},{"id":976,"data":3133,"type":226,"tunes":3134},{"body":978,"title":979,"variant":240},{},{"id":982,"data":3136,"type":218,"tunes":3137},{"text":984},{},{"id":987,"data":3139,"type":218,"tunes":3140},{"text":989},{},{"id":992,"data":3142,"type":218,"tunes":3143},{"text":994},{},{"id":997,"data":3145,"type":218,"tunes":3146},{"text":999},{},{"id":1002,"data":3148,"type":292,"tunes":3158},{"content":3149,"stretched":43,"withHeadings":14},[3150,3151,3152,3153,3154,3155,3156,3157],[1006,1007],[1009,1010],[1012,1013],[1015,1016],[1018,1019],[1021,1022],[1024,1025],[1027,1028],{},{"id":1031,"data":3160,"type":42,"tunes":3161},{"text":1033,"level":247},{},{"id":1036,"data":3163,"type":218,"tunes":3164},{"text":1038},{},{"id":1041,"data":3166,"type":218,"tunes":3167},{"text":1043},{},{"id":1046,"data":3169,"type":42,"tunes":3170},{"text":1048,"level":247},{},{"id":1051,"data":3172,"type":292,"tunes":3181},{"content":3173,"stretched":43,"withHeadings":14},[3174,3175,3176,3177,3178,3179,3180],[1055,1056],[1058,1059],[1061,1062],[1064,1065],[1067,1068],[1070,1071],[1073,1074],{},{"id":1077,"data":3183,"type":218,"tunes":3184},{"text":1079},{},{"id":1082,"data":3186,"type":42,"tunes":3187},{"text":1084,"level":247},{},{"id":1087,"data":3189,"type":292,"tunes":3203},{"content":3190,"stretched":43,"withHeadings":14},[3191,3192,3193,3194,3195,3196,3197,3198,3199,3200,3201,3202],[1091,1092],[1094,1095],[1097,1098],[1100,1101],[1103,1104],[1106,1107],[1109,1110],[1112,1113],[1115,1116],[1118,1119],[1121,1122],[1124,1125],{},{"id":1128,"data":3205,"type":42,"tunes":3206},{"text":1130,"level":247},{},{"id":1133,"data":3208,"type":292,"tunes":3219},{"content":3209,"stretched":43,"withHeadings":14},[3210,3211,3212,3213,3214,3215,3216,3217,3218],[1137,1138],[1140,1141],[1143,1144],[1146,1147],[1149,1150],[1152,1153],[1155,1156],[1158,1159],[1161,1162],{},{"id":1165,"data":3221,"type":42,"tunes":3222},{"text":1167,"level":247},{},{"id":1170,"data":3224,"type":349,"tunes":3238},{"steps":3225,"title":1209,"orientation":348},[3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237],{"label":1174,"description":1175},{"label":1177,"description":1178},{"label":1180,"description":1181},{"label":1183,"description":1184},{"label":1186,"description":1187},{"label":1189,"description":1190},{"label":1192,"description":1193},{"label":1195,"description":1196},{"label":1198,"description":1199},{"label":1201,"description":1202},{"label":1204,"description":1205},{"label":1207,"description":1208},{},{"id":1212,"data":3240,"type":42,"tunes":3241},{"text":1214,"level":247},{},{"id":1217,"data":3243,"type":292,"tunes":3260},{"content":3244,"stretched":43,"withHeadings":14},[3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257,3258,3259],[1221,1222],[1224,1225],[1227,1228],[1230,1231],[1233,1234],[1236,1237],[1239,1240],[1242,1243],[1245,1246],[1248,1249],[1251,1252],[1254,1255],[1257,1258],[1260,1261],[1263,1264],{},{"id":1267,"data":3262,"type":42,"tunes":3263},{"text":1269,"level":247},{},{"id":1272,"data":3265,"type":218,"tunes":3266},{"text":1274},{},{"id":1277,"data":3268,"type":218,"tunes":3269},{"text":1279},{},{"id":1282,"data":3271,"type":218,"tunes":3272},{"text":1284},{},{"id":1287,"data":3274,"type":218,"tunes":3275},{"text":1289},{},{"id":1292,"data":3277,"type":42,"tunes":3278},{"text":1294,"level":247},{},{"id":1297,"data":3280,"type":218,"tunes":3281},{"text":1299},{},{"id":1302,"data":3283,"type":218,"tunes":3284},{"text":1304},{},{"id":1307,"data":3286,"type":42,"tunes":3287},{"text":1309,"level":247},{},{"id":1312,"data":3289,"type":218,"tunes":3290},{"text":1314},{},{"id":1317,"data":3292,"type":218,"tunes":3293},{"text":1319},{},{"id":1322,"data":3295,"type":1328,"tunes":3296},{"url":1324,"title":1325,"excerpt":1326,"ctaLabel":1327},{},{"id":1331,"data":3298,"type":218,"tunes":3299},{"text":1333},{},{"id":1336,"data":3301,"type":1328,"tunes":3302},{"url":1338,"title":1339,"excerpt":1340,"ctaLabel":1341},{},{"id":1344,"data":3304,"type":218,"tunes":3305},{"text":1346},{},{"id":1349,"data":3307,"type":42,"tunes":3308},{"text":1351,"level":247},{},{"id":1354,"data":3310,"type":1354,"tunes":3320},{"items":3311,"title":1389},[3312,3313,3314,3315,3316,3317,3318,3319],{"id":1358,"answer":1359,"question":1360},{"id":1362,"answer":1363,"question":1364},{"id":1366,"answer":1367,"question":1368},{"id":1370,"answer":1371,"question":1372},{"id":1374,"answer":1375,"question":1376},{"id":1378,"answer":1379,"question":1380},{"id":1382,"answer":1383,"question":1384},{"id":1386,"answer":1387,"question":1388},{},{"id":1392,"data":3322,"type":42,"tunes":3323},{"text":1394,"level":247},{},{"id":1397,"data":3325,"type":1397,"tunes":3337},{"title":1399,"entries":3326},[3327,3328,3329,3330,3331,3332,3333,3334,3335,3336],{"term":1402,"anchor":1403,"definition":1404},{"term":1406,"anchor":1407,"definition":1408},{"term":1410,"anchor":1411,"definition":1412},{"term":1414,"anchor":1415,"definition":1416},{"term":1418,"anchor":1419,"definition":1420},{"term":1422,"anchor":1423,"definition":1424},{"term":746,"anchor":1426,"definition":1427},{"term":1429,"anchor":1430,"definition":1431},{"term":1433,"anchor":1434,"definition":1435},{"term":1437,"anchor":1438,"definition":1439},{},{"id":1442,"data":3339,"type":42,"tunes":3340},{"text":1444,"level":247},{},{"id":1447,"data":3342,"type":218,"tunes":3343},{"text":1449},{},{"id":1452,"data":3345,"type":218,"tunes":3346},{"text":1454},{},{"id":1457,"data":3348,"type":218,"tunes":3349},{"text":1459},{},{"id":1462,"data":3351,"type":42,"tunes":3352},{"text":1464,"level":247},{},{"id":1467,"data":3354,"type":218,"tunes":3355},{"text":1469},{},{"id":1472,"data":3357,"type":1479,"tunes":3360},{"link":1474,"meta":3358},{"image":3359,"title":1477,"description":1478},{"url":278},{},{"id":1482,"data":3362,"type":1479,"tunes":3365},{"link":1484,"meta":3363},{"image":3364,"title":1487,"description":1488},{"url":278},{},{"id":1491,"data":3367,"type":1479,"tunes":3370},{"link":1493,"meta":3368},{"image":3369,"title":1496,"description":1497},{"url":278},{},{"id":1500,"data":3372,"type":1479,"tunes":3375},{"link":1502,"meta":3373},{"image":3374,"title":1505,"description":1506},{"url":278},{},{"id":1509,"data":3377,"type":1479,"tunes":3380},{"link":1511,"meta":3378},{"image":3379,"title":1514,"description":1515},{"url":278},{},{"id":1518,"data":3382,"type":1479,"tunes":3385},{"link":1520,"meta":3383},{"image":3384,"title":1523,"description":1524},{"url":278},{},{"id":1527,"data":3387,"type":1479,"tunes":3390},{"link":1529,"meta":3388},{"image":3389,"title":1532,"description":1533},{"url":278},{},{"id":1536,"data":3392,"type":1479,"tunes":3395},{"link":1538,"meta":3393},{"image":3394,"title":1541,"description":1542},{"url":278},{},{"id":1545,"data":3397,"type":1479,"tunes":3400},{"link":1547,"meta":3398},{"image":3399,"title":1550,"description":1551},{"url":278},{},{"id":1554,"data":3402,"type":1479,"tunes":3405},{"link":1556,"meta":3403},{"image":3404,"title":1559,"description":1560},{"url":278},{},"Post erfolgreich abgerufen",{"items":3408,"source":3493,"manualIds":3494,"manualMatchedIds":3495},[3409,3416,3423,3430,3437,3444,3451,3458,3465,3472,3479,3486],{"id":3410,"slug":3411,"title":3412,"excerpt":3413,"featuredImage":3414,"publishedAt":3415},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP objašnjen: Šta povezuje, šta ne radi i gde se uklapa","Model Context Protocol povezuje AI aplikacije sa eksternim alatima, resursima i promptovima kroz standardnu granicu klijent-server. Saznajte šta MCP radi, šta ne radi i gde se uklapa u arhitekturu agenata.","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":3417,"slug":3418,"title":3419,"excerpt":3420,"featuredImage":3421,"publishedAt":3422},"480","when-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger","Kada bi AI trebalo da prestane da veruje sopstvenom znanju? — Okidač za pretragu","AI model ne zahteva pretragu za svako pitanje. Važan problem je znati kada njegovo interno znanje više nije dovoljno. Okidač za pretragu je praktična granica odlučivanja koja određuje kada AI sistem treba da prestane da se oslanja isključivo na znanje modela i pribavi spoljne dokaze pre odgovaranja.","\u002Fuploads\u002F2026\u002F09\u002Fwhen-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger-1790574991244-f4rpyg.webp","2026-09-28T01:49:00.000Z",{"id":3424,"slug":3425,"title":3426,"excerpt":3427,"featuredImage":3428,"publishedAt":3429},"460","ai-agent-reliability-why-the-final-answer-is-not-enough","Pouzdanost AI agenata: Zašto konačni odgovor nije dovoljan","Tačan rezultat ne dokazuje ispravno razmišljanje, bezbedno izvršavanje ili pouzdan sistem.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-reliability-why-the-final-answer-is-not-enough-1788955466306-pl0qhz.webp","2026-09-09T04:01:00.000Z",{"id":3431,"slug":3432,"title":3433,"excerpt":3434,"featuredImage":3435,"publishedAt":3436},"490","rbac-vs-tenant-isolation-two-different-security-boundaries","RBAC naspram izolacije zakupaca: dve različite bezbednosne granice","RBAC kontroliše šta korisnik sme da radi; izolacija zakupaca kontroliše kojim resursima tog zakupca ta radnja može da pristupi. Saznajte zašto bezbednost višekorisničkog SaaS-a zahteva obe granice.","\u002Fuploads\u002F2026\u002F10\u002Frbac-vs-tenant-isolation-two-different-security-boundaries-1791485111528-qqtzby.webp","2026-10-08T14:43:00.000Z",{"id":3438,"slug":3439,"title":3440,"excerpt":3441,"featuredImage":3442,"publishedAt":3443},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","Memorija AI agenta nije RAG: Kako razdvojiti memoriju, pronalaženje, stanje i kontekst","Memorija agenta, RAG, stanje i kontekst često se koriste kao da su međusobno zamenjivi. Oni to nisu. Ovaj praktični arhitektonski model razdvaja ova četiri sloja, pokazuje gde svaki pripada i objašnjava šta se kvari kada ih sistemi stope u jedno.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":3445,"slug":3446,"title":3447,"excerpt":3448,"featuredImage":3449,"publishedAt":3450},"476","mcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI: Objašnjen stek agentskih protokola","MCP, A2A, UCP, AP2 i A2UI se često predstavljaju kao konkurentski standardi za agente. Oni uglavnom rešavaju različite probleme interoperabilnosti. Ovaj vodič mapira svaki protokol na granicu koju zapravo standardizuje—i pokazuje kako oni mogu da rade zajedno u jednom produkcionom sistemu.","\u002Fuploads\u002F2026\u002F09\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained-1790352625869-2ezle0.webp","2026-09-25T12:09:00.000Z",{"id":3452,"slug":3453,"title":3454,"excerpt":3455,"featuredImage":3456,"publishedAt":3457},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","Odakle LLM dobija svoje podatke? RAG izvori podataka u Python-u","LLM ne zna magično vaše fajlove, baze podataka ili API-je. Ovaj praktični nastavak RAG serije pokazuje, uz jednostavan Python, kako eksterni podaci postaju dokazi koji se mogu pronaći: od tekstualnih fajlova i SQL-a do pretrage punog teksta, embeddinga, sastavljanja konteksta i konačnog LLM poziva.","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":3459,"slug":3460,"title":3461,"excerpt":3462,"featuredImage":3463,"publishedAt":3464},"494","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","Air-Gapped AI: Kako AI sistemi funkcionišu bez interneta ili pristupa oblaku","Air-gapped AI pokreće modele, RAG i AI aplikacije unutar izolovanog bezbednosnog domena bez internet ili cloud zavisnosti. Saznajte kako modeli, podaci, ažuriranja i alati funkcionišu offline.","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","2026-10-08T11:32:00.000Z",{"id":3466,"slug":3467,"title":3468,"excerpt":3469,"featuredImage":3470,"publishedAt":3471},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","Šta bi AI agent trebalo da zapamti, zaboravi, ponovo izračuna ili ponovo preuzme?","Dugotrajni agenti ne bi trebalo da pamte sve. Ovaj članak pruža praktičan model životnog ciklusa za odlučivanje o tome šta pripada trajnoj memoriji, šta bi trebalo ponovo preuzeti, šta je bezbednije ponovo izračunati i šta bi trebalo da istekne ili bude zamenjeno.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":3473,"slug":3474,"title":3475,"excerpt":3476,"featuredImage":3477,"publishedAt":3478},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","Šta je arhitekta AI platforme? Modeli, podaci, izvršno okruženje, bezbednost i operacije","Arhitekta AI platforme projektuje višekratno upotrebljive AI temelje kroz modele, provajdere, pretragu, agente, identitet, bezbednost, evaluaciju, opservabilnost i operacije.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":3480,"slug":3481,"title":3482,"excerpt":3483,"featuredImage":3484,"publishedAt":3485},"381","enterprise-grade-multi-tenant-architecture-for-an-international-platform","Višezakupna arhitektura korporativnog nivoa za međunarodnu platformu","Loving Rocks je platforma za venčanja poslovne klase, dizajnirana sa istinskom više-zakupnom arhitekturom, izolovanim bazama podataka po zakupcu i ugrađenom internacionalizacijom za globalnu skalabilnost, bezbednost i dugoročnu operativnu stabilnost.","\u002Fuploads\u002F2026\u002F01\u002Fenterprise-grade-multi-tenant-architecture-for-an-international-platform-1769789121298-b6v7ak.webp","2026-01-30T12:04:00.000Z",{"id":3487,"slug":3488,"title":3489,"excerpt":3490,"featuredImage":3491,"publishedAt":3492},"481","generative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing","Generativna veštačka inteligencija objašnjena: modeli, pretraga, alati i aplikacije nisu ista stvar","Generativna AI je više od modela. Saznajte kako se modeli, pretraga, alati, kontekst, okruženja i aplikacije uklapaju u produkcione AI sisteme.","\u002Fuploads\u002F2026\u002F10\u002Fgenerative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing-1791475411822-pp0dvz.webp","2026-10-08T12:00:00.000Z","fallback",[],[]]