[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:zh":3,"public-menus:all":38,"post:enterprise-ai-architecture-what-changes-when-ai-enters-a-company:zh":205,"related:post:enterprise-ai-architecture-what-changes-when-ai-enters-a-company:zh:1":3405},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","zh","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":3404},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1561,"featuredImage":1562,"featuredImageAlt":1563,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1564,"publishedAt":1565,"createdAt":1566,"updatedAt":1567,"seoLocalePaths":1568,"categories":1577,"author":1593,"translations":1598},"485","企业AI架构：当AI进入公司时会发生什么变化","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u003Cp>企业AI架构是指当AI成为公司真实系统、数据、决策和运营的一部分时所需的组织级架构。模型只是其中一个组成部分。一旦AI与企业数据、身份、权限、业务流程、外部提供商和生产系统连接，架构还必须定义数据权威、访问边界、风险归属、提供商依赖、可审计性、评估、生命周期控制、合规性和运营责任。因此，企业AI既不同于单一的AI解决方案，也不同于共享的AI平台：它协调众多AI赋能系统如何融入更广泛的组织。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">直接回答\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>当AI进入公司时，什么发生了变化？\u003C\u002Fstrong> 现有的企业架构职责扩展到包括概率性模型行为、新的数据流、检索与接地、模型\u002F提供商依赖、AI特定评估、代理\u002F工具权限、模型与提示生命周期、AI风险管理、透明度义务以及新的运营故障模式。架构必须将这些关注点与公司现有的身份、安全、数据、采购、交付和治理结构连接起来，而不是创建一个平行的“AI宇宙”。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">企业AI不是“更大的聊天机器人”\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">聊天机器人可以是一个用户界面。企业AI架构是其背后的边界体系：AI可以访问哪些数据、哪个来源是权威的、谁可以使用哪种能力、外部提供商是否可以接收数据、代理可以执行哪些操作、输出如何评估、必须记录什么、谁负责事件，以及变更如何被批准和回滚。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">当前来源说明 — 2026年10月8日\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">本文中的架构原则旨在保持稳定。法规、标准和供应商能力对版本敏感。ISO\u002FIEC 42001:2023 和 ISO\u002FIEC 23894:2023 是当前已发布的标准。NIST 表示 AI RMF 1.0 正在修订中。根据当前合并的欧盟AI法案文本，该法规一般自2026年8月2日起适用，而特定的高风险条款有较晚的适用日期。法律分类必须始终根据现行法律和具体用例进行核查。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"目录\">\u003Cstrong class=\"editorjs-toc__title\">目录\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-6\" class=\"editorjs-toc__link\">企业AI架构的真正含义\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-11\" class=\"editorjs-toc__link\">最简单的例子\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-16\" class=\"editorjs-toc__link\">简单例子止步之处\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-19\" class=\"editorjs-toc__link\">当AI进入企业时，架构会发生哪些变化\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-20\" class=\"editorjs-toc__link\">1. 业务所有权成为技术架构的一部分\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-23\" class=\"editorjs-toc__link\">2. 数据访问还不够——必须定义数据权威\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-28\" class=\"editorjs-toc__link\">3. 身份变为多层\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-32\" class=\"editorjs-toc__link\">4. 权限从内容访问转向操作权限\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-35\" class=\"editorjs-toc__link\">5. AI提供商成为企业依赖\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-39\" class=\"editorjs-toc__link\">6. AI风险成为生命周期流程\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-43\" class=\"editorjs-toc__link\">7. 治理成为操作系统，而非政策PDF\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-46\" class=\"editorjs-toc__link\">8. 评估成为生产控制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-50\" class=\"editorjs-toc__link\">9. 可观测性必须包括行为、数据和模型上下文\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-53\" class=\"editorjs-toc__link\">10. AI组件需要明确的生命周期所有权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">11. 事件响应必须包含AI特有的故障模式\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-59\" class=\"editorjs-toc__link\">企业AI创造跨职能所有权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-62\" class=\"editorjs-toc__link\">一个实用的企业AI架构模型\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-66\" class=\"editorjs-toc__link\">将企业AI映射为数据和权限流，而非方框\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-68\" class=\"editorjs-toc__link\">企业需要AI清单才能治理AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-71\" class=\"editorjs-toc__link\">AI治理和企业AI架构相关但不相同\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-73\" class=\"editorjs-toc__link\">法规成为架构输入\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-78\" class=\"editorjs-toc__link\">采购与架构变得相互关联\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-81\" class=\"editorjs-toc__link\">企业架构决定需求实际需要多少AI控制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-84\" class=\"editorjs-toc__link\">AI将变更管理变成行为问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-87\" class=\"editorjs-toc__link\">企业AI仍然需要NFR和ADR\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-91\" class=\"editorjs-toc__link\">企业AI架构必须与交付相连\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-94\" class=\"editorjs-toc__link\">原始项目证据：Enterprise Aaasaasa 0.1\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-101\" class=\"editorjs-toc__link\">来自更广泛平台工作的支持性实施模式\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-104\" class=\"editorjs-toc__link\">主要标准如何协同\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-107\" class=\"editorjs-toc__link\">常见企业AI失败模式\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-109\" class=\"editorjs-toc__link\">常见误解\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-111\" class=\"editorjs-toc__link\">实用的企业AI架构决策序列\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-113\" class=\"editorjs-toc__link\">企业AI架构检查清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-115\" class=\"editorjs-toc__link\">边缘案例和限制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-120\" class=\"editorjs-toc__link\">什么会改变这个答案？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-123\" class=\"editorjs-toc__link\">相关规范知识\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-130\" class=\"editorjs-toc__link\">常见问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-132\" class=\"editorjs-toc__link\">术语表\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-134\" class=\"editorjs-toc__link\">结论\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-138\" class=\"editorjs-toc__link\">主要来源和当前指南\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-6\">企业AI架构的真正含义\u003C\u002Fh2>\n\u003Cp>企业AI架构描述了如何将AI能力集成到现有组织中，而不破坏已经使企业系统可治理的边界：业务所有权、身份、授权、数据分类、记录系统责任、变更管理、采购、审计、连续性和运营。\u003C\u002Fp>\n\u003Cp>企业架构师并不取代AI解决方案架构师或AI平台架构师。企业范围提出了一个不同的问题：多个AI解决方案和共享AI能力如何融入公司的目标架构、政策、数据格局、风险模型和运营模式？\u003C\u002Fp>\n\u003Cp>这使得企业AI架构成为跨越技术和组织的协调学科。一个技术上良好的模型集成如果造成影子数据流、重复身份、绕过采购、无法审计、没有所有者或无法安全变更，仍然可能是企业架构的失败。\u003C\u002Fp>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">解决方案、平台和企业AI架构是不同的范围\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">AI解决方案架构\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">AI平台架构\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">企业AI架构\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">主要范围\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">主要问题\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">所有权重点\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">成功条件\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-11\">最简单的例子\u003C\u002Fh2>\n\u003Cp>一家公司从一个内部文档助手开始。第一个版本搜索已批准的文件，并将检索到的上下文发送给语言模型。在解决方案层面，这看起来可能很简单。\u003C\u002Fp>\n\u003Cp>然后第二个团队想要用于客户支持的AI。第三个团队想要一个可以更新工单的代理。财务部门想要文档分析。人力资源部门想要一个内部助手。开发人员想要编码代理。突然间，公司有了多个提供商、多个数据类别、不同的用户组、重叠的检索索引、不同的日志记录规则、新的工具权限、重复的密钥以及不明确的所有权。\u003C\u002Fp>\n\u003Cp>此时，问题不再是“助手能工作吗？”企业问题变成了：哪些能力被批准，谁拥有它们，哪些数据可以跨越哪个边界，身份和权限如何执行，哪些提供商可以接受，必须审计什么，以及组织如何在不失去控制的情况下更换模型或供应商？\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">从孤立的AI功能到企业架构\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 孤立的用例\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">一个团队将一个模型连接到一个工作流并验证本地价值。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 共享依赖出现\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">多个团队需要提供商、模型访问、检索、身份、密钥、可观测性和评估。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 跨越企业边界\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">AI触及受监管数据、记录系统、外部供应商、特权操作和业务决策。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 所有权必须明确\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">业务、架构、数据、安全、法律\u002F合规、采购和运营需要明确的职责。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 生命周期成为组织性的\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">模型变更、提示变更、提供商变更和新的代理能力成为受治理的变更，而不是本地开发人员的编辑。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 架构变得可重复\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">组织为新的AI工作负载建立可重用的模式、决策记录、控制、例外和验证关口。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-16\">简单例子止步之处\u003C\u002Fh2>\n\u003Cp>企业架构并不意味着每个AI组件都必须集中化。有些能力应该共享；其他能力必须保持领域所有。财务、人力资源、工程和客户支持可能合理地需要不同的数据边界、提供商、评估标准和人机审批规则。\u003C\u002Fp>\n\u003Cp>因此，企业目标不是一个模型、一个向量数据库或一个通用助手。目标是具有明确差异的一致性架构：在减少风险和重复的地方采用通用策略和可重用能力，在业务或监管要求不同的地方采用受控的例外。\u003C\u002Fp>\n\u003Ch2 id=\"section-19\">当AI进入企业时，架构会发生哪些变化\u003C\u002Fh2>\n\u003Ch3 id=\"section-20\">1. 业务所有权成为技术架构的一部分\u003C\u002Fh3>\n\u003Cp>传统应用已经需要业务负责人。AI使这一要求更加明显，因为可接受的行为不能仅由正常运行时间和功能正确性来定义。必须有人负责预期用途、不可接受的用途、输出质量、升级路径以及错误或不适当结果的后果。\u003C\u002Fp>\n\u003Cp>模型团队无法独自决定某个答案对于人力资源、财务、法律或面向客户的使用是否可接受。因此，企业AI架构将技术设计与明确的业务能力、责任所有者、用户群体和决策上下文连接起来。\u003C\u002Fp>\n\u003Ch3 id=\"section-23\">2. 数据访问还不够——必须定义数据权威\u003C\u002Fh3>\n\u003Cp>企业AI经常组合运营数据库、文档、搜索索引、向量存储、数据仓库、SaaS系统和外部知识。架构必须区分信息存储在哪里，以及对于给定声明或操作，哪个来源是权威的。\u003C\u002Fp>\n\u003Cp>向量索引可以改善检索，但不应悄然成为公司的记录系统。模型响应可以总结ERP记录，但不应取代ERP作为权威来源。缓存上下文可以改善延迟，但当权限或底层业务状态发生变化时，它就会变得不安全。\u003C\u002Fp>\n\u003Cp>因此，除了普通的数据集成之外，企业AI还需要来源追踪、新鲜度、来源分类、授权传播和失效规则。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">企业数据规则\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>AI系统可以对企业数据进行转换、检索和推理，但不能成为该数据的权威。\u003C\u002Fstrong> 当用例需要证据、验证或产生后果的操作时，架构应保留一条返回权威来源的路径。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch3 id=\"section-28\">3. 身份变为多层\u003C\u002Fh3>\n\u003Cp>企业AI拥有的身份比人类用户更多。一个请求可能涉及用户身份、应用身份、服务身份、代理身份、提供商凭证、工具凭证以及租户或组织上下文。\u003C\u002Fp>\n\u003Cp>这些身份不应被合并为一个共享的API密钥。授权必须保持可归因于正确的主体，特权工具应仅获得当前操作所需的权限。\u003C\u002Fp>\n\u003Cp>对于代理系统，这一点尤为重要：模型可以提出操作，但运行时必须决定请求身份是否被允许执行该操作。模型能力不等于授权。\u003C\u002Fp>\n\u003Ch3 id=\"section-32\">4. 权限从内容访问转向操作权限\u003C\u002Fh3>\n\u003Cp>只读助手主要需要对信息的受控访问。企业代理可以创建工单、修改记录、发送消息、触发工作流或操作外部系统。这引入了不同的风险类别，因为系统可以改变状态，而不仅仅是描述状态。\u003C\u002Fp>\n\u003Cp>架构应分离读取、写入、审批和管理能力；在后果需要时定义人工介入点；并保留审计跟踪，以识别请求了什么、批准了什么以及实际改变了什么。\u003C\u002Fp>\n\u003Ch3 id=\"section-35\">5. AI提供商成为企业依赖\u003C\u002Fh3>\n\u003Cp>调用模型API也是一种供应商关系。架构可能依赖于提供商可用性、服务条款、数据处理条件、支持区域、模型生命周期、配额、定价、API兼容性、安全控制和变更通知。\u003C\u002Fp>\n\u003Cp>这意味着提供商选择不仅仅是一个基准决策。采购、安全、隐私、法律审查、连续性规划和退出策略都可能成为架构输入。\u003C\u002Fp>\n\u003Cp>提供商抽象可以减少耦合，但仅限于底层能力真正可移植的情况。工具使用、结构化输出、上下文限制、多模态、安全控制、微调和托管代理功能在不同提供商之间可能存在实质性差异。\u003C\u002Fp>\n\u003Ch3 id=\"section-39\">6. AI风险成为生命周期流程\u003C\u002Fh3>\n\u003Cp>AI风险不会在发布前的一次审批中完成。模型、提示、检索语料库、工具集、提供商、用户群体和周边业务流程都可能在部署后发生变化。风险状况也随之改变。\u003C\u002Fp>\n\u003Cp>ISO\u002FIEC 23894:2023明确涉及将AI风险管理整合到组织活动和职能中。NIST AI RMF同样将风险管理框定在整个生命周期中。因此，企业架构应将风险审查作为变更和运营的一部分，而不是一份孤立的合规文件。\u003C\u002Fp>\n\u003Cp>风险也应该是成比例的。一个摘要助手和一个改变生产记录的自主系统不应仅仅因为都使用LLM而接受相同的控制。\u003C\u002Fp>\n\u003Ch3 id=\"section-43\">7. 治理成为操作系统，而非政策PDF\u003C\u002Fh3>\n\u003Cp>ISO\u002FIEC 42001:2023定义了建立、实施、维护和持续改进AI管理系统的要求。架构后果很重要：治理必须将政策与真实的清单、所有权、流程、控制、证据、审查和改进循环连接起来。\u003C\u002Fp>\n\u003Cp>一个未与提供商审批、身份、日志记录、变更管理、评估和事件响应相关联的企业AI政策，其架构效果有限。组织需要使政策可执行或至少可观察的机制。\u003C\u002Fp>\n\u003Ch3 id=\"section-46\">8. 评估成为生产控制\u003C\u002Fh3>\n\u003Cp>传统的验收测试假设相同的输入通常产生相同的确定性结果。生成式AI可能是非确定性的、对上下文敏感，并依赖于不断变化的外部知识。因此，生产验收需要针对特定任务的评估、回归测试套件和可观察的阈值，而不仅仅是单元测试。\u003C\u002Fp>\n\u003Cp>平台可以提供可重用的评估基础设施，但企业仍然需要拥有领域真实基准和发布门禁。一个中央AI团队无法为每个业务领域发明正确答案。\u003C\u002Fp>\n\u003Cp>模型、提示、检索和工具的变更应可追溯到评估证据，前提是该变更可能实质性影响输出行为。\u003C\u002Fp>\n\u003Ch3 id=\"section-50\">9. 可观测性必须包括行为、数据和模型上下文\u003C\u002Fh3>\n\u003Cp>CPU、内存和HTTP错误率对于AI工作负载来说是不够的。生产可观测性可能需要模型\u002F提供商标识符、延迟、令牌使用、成本、检索结果、工具调用、拒绝行为、评估分数、安全事件和故障分类。\u003C\u002Fp>\n\u003Cp>同时，AI遥测可能包含敏感数据。提示和响应日志可能成为影子数据存储。因此，企业架构必须定义可以记录什么、如何脱敏、谁可以访问、保留多长时间以及何时必须禁用详细跟踪。\u003C\u002Fp>\n\u003Ch3 id=\"section-53\">10. AI组件需要明确的生命周期所有权\u003C\u002Fh3>\n\u003Cp>模型可能被提供商重命名、替换、退役或更改。嵌入模型可能使索引策略失效。提示模板和系统指令可能改变行为。代理运行时和协议可能演变。外部工具可能更改其模式和权限。\u003C\u002Fp>\n\u003Cp>企业架构必须决定由谁检测这些变更、由谁测试、由谁批准、如何通知消费者、回滚如何运作，以及在新版本成为默认版本之前需要哪些证据。\u003C\u002Fp>\n\u003Ch3 id=\"section-56\">11. 事件响应必须包含AI特有的故障模式\u003C\u002Fh3>\n\u003Cp>AI事件可能是提供商中断、数据泄露、提示注入路径、授权失败、检索污染、意外模型行为、不安全工具执行、成本激增、知识过时、评估回归或外部模型行为变化。\u003C\u002Fp>\n\u003Cp>因此，企业运行手册需要的不仅仅是“重启服务”。它可能需要禁用模型路由、撤销工具访问、冻结语料库、更改提示版本、禁用代理能力、切换提供商、上报给领域负责人或保留追踪记录以供调查。\u003C\u002Fp>\n\u003Ch2 id=\"section-59\">企业AI创造跨职能所有权\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">关注点\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">典型企业所有者或贡献者\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">架构问题\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务用途\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务所有者\u002F产品所有者\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI被允许支持或自动化哪些决策或工作流？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">解决方案架构\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI\u002F解决方案架构师\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">具体工作负载如何满足其功能和质量要求？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">共享AI能力\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI平台\u002F平台工程\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供哪些可复用的模型、检索、代理和可观测性服务？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">企业一致性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">企业架构\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI系统如何适应目标架构、标准、集成模式和组织所有权？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据权威\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据所有者\u002F领域所有者\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些数据是权威的、当前的、被允许的且得到充分治理的？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份与安全\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">IAM\u002F安全架构\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些身份可以访问哪些数据并执行哪些操作？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险与合规\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险\u002F法律\u002F合规\u002F隐私\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些义务、禁止用途、控制和证据适用于此用例？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应商依赖\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">采购\u002F供应商管理\u002F架构\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商带来哪些合同、运营和退出风险？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">SRE\u002F运营\u002F平台所有者\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">系统如何被监控、支持、降级、恢复和变更？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">领域验收\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务\u002F领域专家\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在此领域中，什么算作正确、安全或有用的结果？\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">RACI图表本身不是架构\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">责任矩阵只有在连接到真实系统边界、审批、数据所有权、接口、运行手册和变更流程时才有用。企业AI需要可问责的所有权，并能追溯到技术控制和运营行动。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-62\">一个实用的企业AI架构模型\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">提议的分层模型\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">以下模型是用于推理企业AI架构的实用综合。它并非作为ISO或NIST标准提出。其目的是使跨组织边界明确化。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">层\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">主要职责\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务与政策\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已批准的用例、可问责的所有者、风险偏好、禁止用途、人类问责、业务验收。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份与权限\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用户\u002F服务\u002F代理身份、角色、租户或组织范围、特权操作、审批路径。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">企业数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">记录系统、文档来源、数据产品、来源、分类、保留、新鲜度和访问。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI平台\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商\u002F模型访问、检索原语、代理运行时、工具代理、评估基础设施、可观测性、配额和密钥。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI解决方案\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">领域工作流、提示\u002F指令、领域检索、业务逻辑、验收标准和用户体验。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">集成与工具\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">API、企业应用、工作流、消息传递、文件系统、外部服务和操作执行。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险与治理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">清单、评估、合规证据、例外管理、模型\u002F提供商审批、审查和审计。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营与生命周期\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部署、监控、事件、发布、模型\u002F提供商变更、弃用、回滚和连续性。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>当每一层都能说明其职责和非职责时，架构最为强大。例如，AI平台可以执行提供商策略并收集追踪记录，而不成为HR数据的真相来源。解决方案可以定义领域提示，而不拥有企业IAM。业务所有者可以批准用例，而不被期望运营推理网关。\u003C\u002Fp>\n\u003Ch2 id=\"section-66\">将企业AI映射为数据和权限流，而非方框\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">一个重要的企业AI请求\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 业务上下文\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">用户在已批准的用例下请求任务，并有可问责的业务所有者。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 身份与授权\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">系统在特权访问之前解析用户、应用程序、服务和租户或组织范围。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 权威数据获取\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">解决方案仅读取或检索当前身份和任务允许的来源。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. AI处理\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">已批准的模型\u002F提供商在定义的路由和数据处理规则下处理最小必要上下文。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 工具或操作边界\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">任何改变状态的操作都独立授权，并可能根据后果需要人工批准。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 验证\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">结果根据解决方案特定的验收、证据或安全规则进行检查。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 审计与可观测性\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">允许的元数据、决策、路由、工具调用和结果被记录，而不创建不受控的敏感数据日志。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 反馈与生命周期\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">失败和评估结果通过受控变更管理反馈到模型、提示、数据、策略和流程变更中。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-68\">企业需要AI清单才能治理AI\u003C\u002Fh2>\n\u003Cp>组织无法管理无法识别的AI系统。企业架构应维护一个对决策有用的清单，而不仅仅是模型名称列表。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">清单字段\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为何重要\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用例和所有者\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">将技术连接到可问责的业务目的。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用户和受影响方\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">定义谁与系统交互或受其影响。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u002F提供商\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">识别外部依赖、能力和生命周期风险。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据来源\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">支持权威、隐私、分类和来源审查。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部署\u002F运行时位置\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">阐明处理位置、连接性和运营控制。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具\u002F操作\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">显示AI是否可以改变外部状态以及后果如何。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">人工监督\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">记录需要审查、批准或上报的地方。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险\u002F分类\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">将系统连接到组织和监管控制。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">评估证据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">显示测试了什么以及在哪些有效性条件下。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">当前版本\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">允许将事件和回归追溯到实际部署状态。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">生命周期状态\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提议、实验、已批准、生产、受限、弃用或退役。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-71\">AI治理和企业AI架构相关但不相同\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">治理与架构\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">AI治理\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">企业AI架构\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">目的\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">示例\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">孤立时的失败\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-73\">法规成为架构输入\u003C\u002Fh2>\n\u003Cp>对于在欧盟运营的组织，AI法案可能产生影响系统设计、文档、透明度、治理和运营流程的要求。架构影响取决于组织在AI价值链中的角色和具体的系统分类；并非每个AI系统都有相同的义务。\u003C\u002Fp>\n\u003Cp>截至2026年10月8日，当前合并文本规定该法规一般从2026年8月2日起适用。治理规则和通用人工智能模型的义务更早开始适用，而特定的高风险系统条款有更晚的日期。委员会还从2026年8月2日起对相关的交互式和合成内容系统开始执行新的透明度要求。\u003C\u002Fp>\n\u003Cp>企业架构的教训不是“把合规放进模型里”。而是使分类、提供者\u002F部署者角色、文档、透明度、监督、日志记录和变更证据可追溯到实际实现用例的系统。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">法律范围因用例而异\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">本文描述架构影响，而非法律建议。企业AI架构应保留法律和合规专家对实际系统进行分类并将义务映射到具体控制所需的信息。架构不应将一种监管解释硬编码，仿佛每个AI工作负载都具有相同的状态。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-78\">采购与架构变得相互关联\u003C\u002Fh2>\n\u003Cp>外部模型或托管AI平台可能成为深度依赖，即使集成只需要少量API调用。因此，企业架构应使采购问题在技术上具体化。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">采购问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">架构后果\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据在哪里处理？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">区域、网络路径、数据驻留和传输控制。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">客户数据是否被保留或用于提供者改进？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据最小化、合同控制和提供者资格。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型如何版本化或退役？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">回归测试、兼容性、回退和生命周期规划。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">配额和服务限制是什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容量架构、准入控制和故障处理。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">集成的可移植性如何？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供者抽象、退出成本和迁移工作量。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">有哪些事件信息可用？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性、取证能力和支持升级。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">涉及哪些子处理者或外部服务？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">依赖映射和风险评估。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">未经客户明确批准会发生哪些变更？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">变更检测、发布门禁和验收策略。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-81\">企业架构决定需求实际需要多少AI控制\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">需求\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">可能的架构响应\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">快速访问托管模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">具有企业身份、网关控制和合同审查的托管提供者。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有数据与托管编排\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管控制平面加上客户控制的执行或私有数据平面（如支持）。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">严格本地化或主权\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">根据实际需求，采用区域限制、主权、私有或自托管架构。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">气隙环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地托管模型、本地检索、本地工具、离线更新\u002F分发和隔离的可观测性。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供者可移植性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用拥有的领域状态加上适配器和合同，在实际可行的情况下隔离提供者特定行为。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">对代理语义的最高控制\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自管理或深度控制的运行时，具有明确的工具、上下文、状态和生命周期所有权。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>控制最多的架构并不自动是最好的企业架构。更多的所有权增加了对补丁、容量、安全、测试、模型运营和事件响应的责任。企业架构应仅在需求证明额外运营负担合理时升级控制。\u003C\u002Fp>\n\u003Ch2 id=\"section-84\">AI将变更管理变成行为问题\u003C\u002Fh2>\n\u003Cp>普通的依赖更新可能改变性能或兼容性。AI变更还可能改变行为。替换模型、更改系统提示、更改检索、添加工具或更改上下文策略，都可能改变系统的解释和响应方式，即使周围的应用程序代码几乎没有变化。\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">生产AI变更路径\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 识别变更\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">提出或检测到模型、提供者、提示、检索源、工具、策略或运行时变更。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 映射影响\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">识别受影响的解决方案、数据类别、用户、风险控制、成本、合同和运营依赖。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 更新架构决策\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">记录重要选择和权衡；被取代的决策保持历史可追溯。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 执行评估\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">运行相关的回归、安全、检索、延迟、成本和领域测试。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 应用批准\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">批准级别遵循后果、风险和组织政策。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 受控推出\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在适当情况下使用版本化发布、金丝雀或分阶段部署。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 收集生产证据\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">监控遥测、事件、反馈和领域结果。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 回滚或验收\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">根据证据接受、限制、回滚或取代变更。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-87\">企业AI仍然需要NFR和ADR\u003C\u002Fh2>\n\u003Cp>AI不会取代普通的架构纪律。非功能需求仍然是目标条件：可用性、延迟、隐私、隔离、可审计性、可恢复性、成本边界、可解释性或其他质量要求。架构决策记录保留所选响应及其权衡。\u003C\u002Fp>\n\u003Cp>AI特有的区别在于，某些质量属性必须以概率或经验方式评估。“答案必须有用”太模糊。生产需求应确定任务、数据、用户群体、可接受的失败条件、测量方法以及实际可行的阈值。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">企业可追溯性链\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>业务需求 → 需求 \u002F NFR → 架构决策 → 实现 → 评估 \u002F 验证 → 生产观察 → 变更决策。\u003C\u002Fstrong> AI为这条链增加了新变量；它不会使这条链变得不必要。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-91\">企业AI架构必须与交付相连\u003C\u002Fh2>\n\u003Cp>从未进入待办事项、实施、验收和运营的架构仍停留在概念层面。因此，企业AI需要从架构决策到交付工作的可追溯性，以及从实施证据回到架构的可追溯性。\u003C\u002Fp>\n\u003Cp>Jira和Confluence是能够支持这种分离的工具示例，前提是有意使用：Confluence可以保存需求、架构、决策、风险和理由；Jira可以管理可操作的交付工作和状态。重要的原则是可追溯性，而不是工具品牌。\u003C\u002Fp>\n\u003Ch2 id=\"section-94\">原始项目证据：Enterprise Aaasaasa 0.1\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">项目证据，而非市场验证声明\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Enterprise Aaasaasa 0.1在此用作结构化企业架构和交付思维的原始项目证据。它是一个PoC\u002F企业项目背景，而非大规模客户采用、企业级生产使用或商业吸引力的证据。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cp>Enterprise Aaasaasa 0.1结合了平台架构、SaaS\u002FAPI概念、国际化、AI集成和结构化项目治理。该项目被有意组织为需求、架构、原型交付、验证和收尾作为独立的里程碑，而非一个未分化的实施阶段。\u003C\u002Fp>\n\u003Cp>架构方向包括多实例\u002F多数据库概念以及API、CRUD、i18n和AI能力。这对企业AI很重要，因为当添加AI功能时，租户或实例边界、数据库所有权和应用服务必须保持明确。\u003C\u002Fp>\n\u003Cp>项目结构还将架构延迟、范围蔓延和AI\u002F数据保护问题视为项目风险，而不是仅在实施过程中才发现它们。利益相关者包括技术、安全、发起人\u002F指导委员会和外部服务视角，这比仅关注模型的原型更接近企业AI真正的跨职能性质。\u003C\u002Fp>\n\u003Cp>因此，有用的证据是架构与交付的整合：业务和项目结构、里程碑、风险、架构、后端\u002FAPI、前端\u002FAI工作、验证和收尾被视为相互关联的职责。这种模式是可复用的，尽管项目本身不应被呈现为外部企业采用的证明。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">项目要素\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">企业AI架构经验\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需求里程碑\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI能力必须从已定义的需求、范围、验收和质量约束开始。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">架构里程碑\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据、API、实例\u002F数据库边界和AI集成是明确的设计工作。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">原型里程碑\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">架构必须足够可执行，以暴露集成风险。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">验证里程碑\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可运行的原型不等同于已验证的验收。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险登记册\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">范围、架构延迟和AI\u002F数据保护问题作为交付风险进行管理。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">利益相关者结构\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">企业AI跨越发起人\u002F业务、架构、安全、外部提供商和交付。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">项目收尾\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">决策、剩余风险和验证证据必须在实施冲刺之后继续存在。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-101\">来自更广泛平台工作的支持性实施模式\u003C\u002Fh2>\n\u003Cp>更广泛的Aaasaasa平台中的独立实施工作提供了企业AI架构必须保留的边界的具体示例：CMS中租户范围的RBAC，Aaasaasa AI Client中明确的提供商\u002F模型\u002F运行时\u002F权限分离，以及Source of Truth Research Engine中来源优先的检索。\u003C\u002Fp>\n\u003Cp>这些项目不应被合并为一个声称的生产平台。它们在此的价值更为狭窄：它们展示了身份范围、提供商边界、受控运行时权限、检索来源和证据可追溯性的已实施模式，这些与企业AI直接相关。\u003C\u002Fp>\n\u003Ch2 id=\"section-104\">主要标准如何协同\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">来源\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">对企业AI架构的贡献\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC 42001:2023\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">组织级AI管理系统：政策、目标、流程、责任、监控和持续改进。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC 23894:2023\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">将AI特定风险管理整合到组织活动和职能中的指南。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">NIST AI RMF 1.0\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">面向生命周期的自愿性AI风险管理框架；围绕治理、映射、测量和管理组织。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">NIST AI 600-1\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">生成式AI配置文件，扩展AI RMF，增加生成式AI特定的风险和行动。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">EU AI Act\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">欧盟具有约束力的监管义务，其适用性取决于角色、系统类型和分类。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">ISO\u002FIEC\u002FIEEE 42010:2022\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用于表达关注点、视角、决策和关系的通用架构描述概念。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>这些来源解决不同的问题。ISO\u002FIEC 42001不能替代技术架构。ISO\u002FIEC 23894和NIST AI RMF并未定义一个强制性的软件栈。EU AI Act是法律，不是平台设计模式。架构必须将适用的组织、风险和法律要求转化为可实施的系统边界和证据。\u003C\u002Fp>\n\u003Ch2 id=\"section-107\">常见企业AI失败模式\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">失败模式\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为何失败\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">每个团队独立购买AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">造成影子提供商、重复的密钥、不一致的数据处理和对供应商风险的弱控制力。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">一个中央AI团队拥有所有领域决策\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">集中了技术控制，但失去了领域问责制并造成瓶颈。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">向量数据库成为事实来源\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">检索基础设施悄然取代了权威系统和新鲜度规则。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">所有用户和代理共享一个API密钥\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">破坏了归属、最小权限和有意义的可审计性。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型变更像小库补丁一样部署\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">行为回归可能在未经领域评估的情况下进入生产。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">所有提示和输出永久记录\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性创建了一个不受控的敏感数据存储库。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">治理仅是文档\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">政策存在但没有执行点、证据或运营所有权。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">合规委托给提供商\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">组织自身的角色、用例、数据和运营义务仍未解决。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">代理可以调用工具，因为模型支持工具使用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">将能力误认为授权。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">平台健康等同于业务正确性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">端点正常运行时间和模型可用性并不能证明领域答案质量或可接受的结果。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有模型\u002F提供商依赖的退出策略\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">定价、政策、能力或可用性变化成为紧急迁移。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-109\">常见误解\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">误解\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">更好的模型\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“企业AI意味着全公司范围的聊天机器人。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">聊天机器人只是一个界面；企业AI架构管理底层的数据、身份、提供商、运行时、风险和运营。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“如果我们使用信誉良好的模型提供商，治理问题就解决了。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商的控制措施并不能定义你的用例、数据权限、用户权限、业务验收或法律角色。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“私有AI意味着一切都必须自托管。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">隐私要求可以导致多种架构；所需的控制边界必须被精确地陈述。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“AI治理属于法律部门，架构属于IT部门。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">这两个学科必须连接起来，因为政策义务需要可实施的控制措施和证据。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“一个企业模型更简单。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">标准化可能有帮助，但工作负载可能需要不同的模态、区域、成本、质量水平或控制模型。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“AI风险就是模型风险。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">风险可能来源于数据、提示、检索、身份、工具、界面、运营、用户和组织流程。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“人在回路中使代理安全。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">人工审批只有在审查者拥有有用的上下文、权限、时间和明确的决策点时才有帮助。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“成功的试点证明了企业就绪。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">试点证明了有限的能力；企业就绪还需要集成、治理、生命周期、运营和可重复的控制措施。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-111\">实用的企业AI架构决策序列\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">从机会到受治理的企业能力\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 定义业务能力\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">陈述用户、决策或工作流、预期价值和负责的所有者。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 分类数据和权限\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">识别记录系统、个人\u002F机密数据、保留、新鲜度和来源要求。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 定义身份和行动边界\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确定谁可以读取、生成、决定、批准和更改外部系统。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 选择解决方案和平台职责\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">决定什么属于工作负载、什么可以共享以及什么保持企业所有。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 评估提供商和运行时依赖\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">根据实际需求评估托管、自托管、私有、主权或混合选项。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 映射风险和监管义务\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确定具体系统的风险级别、组织控制和适用的法律责任。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 定义可衡量的验收标准\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">为质量、可靠性、安全性、检索、成本和运营行为创建评估标准。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 记录架构决策\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">保留理由、替代方案、权衡、依赖关系以及会触发重新考虑的条件。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. 将架构与交付连接\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">将设计转化为待办事项、里程碑、验收标准、技术工作和所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. 在生产形态条件下验证\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">测试真实的身份、数据、故障、延迟、提供商、工具和恢复场景，而不仅仅是干净的演示。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">11\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">11. 建立运营和变更控制\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">定义监控、事件响应、模型\u002F提供商更新、回归测试、回滚和退役。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">12\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">12. 将证据反馈到架构中\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">使用生产观察、审计、事件和评估来修订决策和控制措施。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-113\">企业AI架构检查清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">预期证据\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">这个AI支持什么业务能力？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">指定的所有者、用户组、预期决策\u002F工作流和验收目标。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">对于每个重要事实，哪个来源是权威的？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">记录系统、文档权威、来源和新鲜度规则。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">存在哪些身份？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">人类、应用程序、服务、代理、租户\u002F组织和提供商身份是可区分的。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI可以读取什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">授权范围的数据源和明确的敏感数据规则。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI可以更改什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具\u002F行动清单、权限模型、审批和回滚路径。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">使用哪个提供商\u002F模型，为什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">架构决策包括质量、安全性、成本、区域、生命周期和退出考虑。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如果提供商不可用会发生什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">降级模式、回退、拒绝或连续性计划。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">如何评估质量？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">特定任务的数据集、评分器、阈值、回归标准和有效性条件。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">记录了什么？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">遥测模式、编辑、访问、保留和审计目的。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁拥有AI风险？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">与具体系统相关的指定组织责任。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">适用什么法律分类？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基于当前法律和实际用例的书面评估。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u002F提示\u002F检索的更改如何被批准？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">版本控制、评估、架构\u002F变更记录和推出关口。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁响应AI事件？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行手册、技术所有者、业务\u002F领域升级和提供商升级。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">系统如何退役？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据清理、访问撤销、提供商退出、证据保留和依赖移除。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-115\">边缘案例和限制\u003C\u002Fh2>\n\u003Cp>一个只有低风险AI用例的小公司可能不需要正式的企业AI架构职能。同样的原则可以轻量应用：明确的所有者、批准的数据、明确的提供商、基本评估、访问控制和运营责任。\u003C\u002Fp>\n\u003Cp>高度受监管的组织可能需要更强的分离、独立验证、正式合规流程、本地托管或气隙操作。这些控制措施由用例和监管环境驱动，而不是由“企业”这个词驱动。\u003C\u002Fp>\n\u003Cp>组织也可以主要使用SaaS AI产品而不是构建AI系统。企业架构仍然重要，因为身份、数据访问、合同条款、影子AI、保留、审计和供应商集中度仍然是组织关注的问题。\u003C\u002Fp>\n\u003Cp>集中式平台不是强制性的。当领域有实质性不同的需求时，联邦式平台所有权可能是有效的，前提是企业级身份、风险、清单和互操作性职责保持一致。\u003C\u002Fp>\n\u003Ch2 id=\"section-120\">什么会改变这个答案？\u003C\u002Fh2>\n\u003Cp>当组织的风险容忍度、监管分类、数据敏感性、地理范围、提供商策略、内部技能或业务关键性发生变化时，架构就会改变。一个公共营销助手和一个参与就业、金融、医疗或关键基础设施决策的系统不应继承相同的控制模型。\u003C\u002Fp>\n\u003Cp>随着标准、法规和AI平台的发展，实现也会改变。NIST AI RMF 1.0目前正在修订中，欧盟AI法案有分阶段的应用日期，模型\u002F提供商能力继续快速变化。因此，企业架构应保留稳定的职责边界，同时将提供商机制和监管细节视为版本化输入。\u003C\u002Fp>\n\u003Ch2 id=\"section-123\">相关规范知识\u003C\u002Fh2>\n\u003Cp>企业AI架构建立在解决方案和平台架构之上。解决方案层解释一个工作负载。平台层解释可重用的AI能力。企业层将两者连接到组织范围内的数据、身份、治理、风险、采购和运营。\u003C\u002Fp>\n\u003Cp>检索增强生成只是这个架构中的一种机制。RAG可以改善对企业知识的访问，但它本身并不能解决数据权威、权限、治理或答案有效性问题。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">什么是RAG？其工作原理的最简单解释\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">用通俗易懂的英语解释外部知识检索如何连接到语言模型，而不会将检索变成真相的来源。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读RAG基础 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Cp>对于证据密集型企业用例，答案有效性还需要一个明确的边界：输出仅在其产生的证据、版本、范围和假设下才被支持。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">答案有效性边界：相关性与可靠AI答案之间缺失的层次\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">一个框架，用于明确AI主张在何种条件下仍然成立，以及哪些变化需要限制或重新计算。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读答案有效性边界 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Cp>下游企业主题包括AI治理、私有AI、主权AI、气隙AI、多租户AI架构、RBAC与租户隔离、提供商抽象、模型路由和生产AI架构。\u003C\u002Fp>\n\u003Ch2 id=\"section-130\">常见问题\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">企业AI架构常见问题\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么是企业AI架构？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">企业AI架构是一种组织范围的架构，定义了AI解决方案和共享AI能力如何与业务所有权、企业数据、身份、安全、提供商、治理、风险、合规、生命周期和运营集成。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">企业AI架构与AI平台相同吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不相同。AI平台提供可复用的技术能力，如模型访问、检索、代理运行时和可观测性。企业AI架构定义了该平台和各个AI解决方案如何融入组织更广泛的架构和运营模式。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">企业AI需要一个中央模型吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不需要。标准化可以降低复杂性，但不同的工作负载可能需要不同的提供商、模型、区域、控制级别或模态。重要的要求是明确的策略和生命周期所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">为什么数据权威对企业AI很重要？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">因为检索或生成的信息并不自动具有权威性。企业系统需要保留哪个来源是记录系统、数据是否最新、谁可以访问以及生成的声明如何追溯到证据。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">AI治理与企业AI架构有什么区别？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">AI治理定义策略、问责制和决策权。企业AI架构定义系统边界、接口、数据流和技术机制，通过这些机制可以实施和证明这些策略。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">欧盟AI法案是否以相同方式适用于每个企业AI系统？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不是。义务取决于组织的角色、系统的用例和分类以及相关现行条款等因素。法律分类必须根据现行法律对具体系统进行。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq7\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">成功的AI试点是否足以进行企业部署？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不够。试点展示的是有限的能力。企业部署还需要身份、数据权威、安全、提供商治理、评估、生命周期、事件响应、监控、合规和可问责的运营所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq8\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">企业应该自行托管AI吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">只有当需求证明增加的控制和运营责任合理时才应如此。托管、私有、主权、自托管和混合方法是架构选项，其适用性取决于数据、监管、可用性、成本、能力和运营要求。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-132\">术语表\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">关键企业AI架构术语\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"enterprise-ai-architecture\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">企业AI架构\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">组织范围的架构，管理AI系统、平台、数据、身份、提供商、风险控制和运营如何协同。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-management-system\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI管理系统\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">用于建立AI相关策略、目标和流程的组织管理系统；ISO\u002FIEC 42001规定了此类系统的要求。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"data-authority\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">数据权威\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">识别哪个来源或系统对特定事实、记录、状态或决策上下文具有权威性的规则。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"system-of-record\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">记录系统\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">负责业务记录或领域实体官方当前状态的权威系统。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-inventory\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI清单\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">对AI用例、所有者、模型\u002F提供商、数据、工具、风险、评估证据、生命周期状态及相关控制的结构化记录。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"provider-dependency\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">提供商依赖\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">当AI工作负载依赖外部模型或托管平台时产生的技术、合同和运营依赖。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"human-oversight\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">人工监督\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在系统后果、不确定性或法规要求时应用的定义明确的人工审查、批准、干预或升级。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"genaiops\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">GenAIOps\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">针对生成式AI工作负载的运营实践，涵盖模型选择、提示、基础数据、评估、部署、监控和生命周期管理。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-risk-management\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI风险管理\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在整个生命周期中识别、评估、处理、监控和修订与AI系统相关风险的组织流程。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"architecture-decision\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">架构决策\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">重要的设计选择及其上下文、理由、替代方案、权衡和生命周期状态。\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-134\">结论\u003C\u002Fh2>\n\u003Cp>当AI进入公司时，企业不仅仅获得了一个新的软件组件。它获得了一类新的行为和依赖，贯穿数据、身份、供应商、业务决策、安全、运营、治理和变更管理。\u003C\u002Fp>\n\u003Cp>架构上的应对不是将所有事情集中化。而是明确责任：哪些数据具有权威性、哪些身份可以行动、哪些提供商获得批准、哪些控制是共享的、哪些决策仍由领域拥有、如何评估行为、如何处理事件以及系统如何随时间变化。\u003C\u002Fp>\n\u003Cp>这就是企业AI架构的核心区别：它将孤立的AI能力转变为组织上可治理的系统，而不假装模型、平台、业务领域和企业控制是同一回事。\u003C\u002Fp>\n\u003Ch2 id=\"section-138\">主要来源和当前指南\u003C\u002Fh2>\n\u003Cp>以下外部标准、法规和当前供应商架构指南已于2026年10月8日核查。项目特定部分明确标记为原始项目证据，不应被解读为对一般行业事实的主张。\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC 42001:2023 — 人工智能管理系统\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">国际标准，规定了在组织内建立、实施、维护和持续改进AI管理系统的要求。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC 23894:2023 — AI风险管理指南\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">将AI特定风险管理整合到组织活动和职能中的国际指南。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI风险管理框架\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST的志愿性生命周期导向框架，用于管理AI风险。NIST表示AI RMF 1.0目前正在修订中。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI 600-1 — 生成式AI概况\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST配套概况，描述生成式AI特定风险以及与AI RMF一致的风险管理行动。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">EUR-Lex — 欧盟法规 (EU) 2024\u002F1689，合并文本\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">截至2026年10月8日核查的当前合并AI法案文本，用于适用日期和监管结构。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — 人工智能法案监管框架\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">委员会当前对人工智能法案应用阶段的概述，包括2026年的适用性以及特定高风险条款的后续日期。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft Azure 架构良好的框架 — AI 工作负载\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">关于 AI 工作负载的当前架构指导，包括非确定性行为、数据、应用程序设计和操作。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft — 面向 AI 工作负载的 MLOps 和 GenAIOps\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">关于运营生命周期、数据、模型维护、部署、监控和持续演进的当前指导。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft — Azure 工作负载中的负责任 AI\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">将 AI 策略与数据控制、身份、代理可审计性、基于角色的访问和操作保障联系起来的当前指导。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC\u002FIEEE 42010:2022 — 架构描述\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前架构描述标准，支持跨系统架构的明确关注点、视角和关系。\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1560},1791478692639,[214,220,228,235,242,250,255,260,265,270,305,310,315,320,325,351,356,361,366,371,376,381,386,391,396,401,406,412,417,422,427,432,437,442,447,452,457,462,467,472,477,482,487,492,497,502,507,512,517,522,527,532,537,542,547,552,557,562,567,572,621,627,632,638,670,675,680,710,715,720,761,766,790,795,800,805,810,816,821,826,858,863,889,894,899,904,934,939,944,949,955,960,965,970,975,981,986,991,996,1001,1030,1035,1040,1045,1050,1076,1081,1086,1127,1132,1164,1169,1211,1216,1266,1271,1276,1281,1286,1291,1296,1301,1306,1311,1316,1321,1330,1335,1343,1348,1353,1391,1396,1439,1444,1449,1454,1459,1464,1469,1479,1488,1497,1506,1515,1524,1533,1542,1551],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"企业AI架构是指当AI成为公司真实系统、数据、决策和运营的一部分时所需的组织级架构。模型只是其中一个组成部分。一旦AI与企业数据、身份、权限、业务流程、外部提供商和生产系统连接，架构还必须定义数据权威、访问边界、风险归属、提供商依赖、可审计性、评估、生命周期控制、合规性和运营责任。因此，企业AI既不同于单一的AI解决方案，也不同于共享的AI平台：它协调众多AI赋能系统如何融入更广泛的组织。","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct-answer",{"body":223,"title":224,"variant":225},"\u003Cstrong>当AI进入公司时，什么发生了变化？\u003C\u002Fstrong> 现有的企业架构职责扩展到包括概率性模型行为、新的数据流、检索与接地、模型\u002F提供商依赖、AI特定评估、代理\u002F工具权限、模型与提示生命周期、AI风险管理、透明度义务以及新的运营故障模式。架构必须将这些关注点与公司现有的身份、安全、数据、采购、交付和治理结构连接起来，而不是创建一个平行的“AI宇宙”。","直接回答","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"not-bigger-chatbot",{"body":231,"title":232,"variant":233},"聊天机器人可以是一个用户界面。企业AI架构是其背后的边界体系：AI可以访问哪些数据、哪个来源是权威的、谁可以使用哪种能力、外部提供商是否可以接收数据、代理可以执行哪些操作、输出如何评估、必须记录什么、谁负责事件，以及变更如何被批准和回滚。","企业AI不是“更大的聊天机器人”","warning",{},{"id":236,"data":237,"type":226,"tunes":241},"current-date",{"body":238,"title":239,"variant":240},"本文中的架构原则旨在保持稳定。法规、标准和供应商能力对版本敏感。ISO\u002FIEC 42001:2023 和 ISO\u002FIEC 23894:2023 是当前已发布的标准。NIST 表示 AI RMF 1.0 正在修订中。根据当前合并的欧盟AI法案文本，该法规一般自2026年8月2日起适用，而特定的高风险条款有较晚的适用日期。法律分类必须始终根据现行法律和具体用例进行核查。","当前来源说明 — 2026年10月8日","note",{},{"id":243,"data":244,"type":248,"tunes":249},"toc",{"title":245,"maxLevel":246,"minLevel":247},"目录",3,2,"tableOfContents",{},{"id":251,"data":252,"type":42,"tunes":254},"h-meaning",{"text":253,"level":247},"企业AI架构的真正含义",{},{"id":256,"data":257,"type":218,"tunes":259},"p-meaning-1",{"text":258},"企业AI架构描述了如何将AI能力集成到现有组织中，而不破坏已经使企业系统可治理的边界：业务所有权、身份、授权、数据分类、记录系统责任、变更管理、采购、审计、连续性和运营。",{},{"id":261,"data":262,"type":218,"tunes":264},"p-meaning-2",{"text":263},"企业架构师并不取代AI解决方案架构师或AI平台架构师。企业范围提出了一个不同的问题：多个AI解决方案和共享AI能力如何融入公司的目标架构、政策、数据格局、风险模型和运营模式？",{},{"id":266,"data":267,"type":218,"tunes":269},"p-meaning-3",{"text":268},"这使得企业AI架构成为跨越技术和组织的协调学科。一个技术上良好的模型集成如果造成影子数据流、重复身份、绕过采购、无法审计、没有所有者或无法安全变更，仍然可能是企业架构的失败。",{},{"id":271,"data":272,"type":303,"tunes":304},"scope-comparison",{"rows":273,"title":291,"layout":292,"columns":293},[274,279,283,287],{"id":275,"label":276,"values":277},"scope","主要范围",[278,278,278],"",{"id":280,"label":281,"values":282},"question","主要问题",[278,278,278],{"id":284,"label":285,"values":286},"ownership","所有权重点",[278,278,278],{"id":288,"label":289,"values":290},"success","成功条件",[278,278,278],"解决方案、平台和企业AI架构是不同的范围","table",[294,297,300],{"id":295,"label":296},"solution","AI解决方案架构",{"id":298,"label":299},"platform","AI平台架构",{"id":301,"label":302},"enterprise","企业AI架构","comparison",{},{"id":306,"data":307,"type":42,"tunes":309},"h-simple",{"text":308,"level":247},"最简单的例子",{},{"id":311,"data":312,"type":218,"tunes":314},"p-simple-1",{"text":313},"一家公司从一个内部文档助手开始。第一个版本搜索已批准的文件，并将检索到的上下文发送给语言模型。在解决方案层面，这看起来可能很简单。",{},{"id":316,"data":317,"type":218,"tunes":319},"p-simple-2",{"text":318},"然后第二个团队想要用于客户支持的AI。第三个团队想要一个可以更新工单的代理。财务部门想要文档分析。人力资源部门想要一个内部助手。开发人员想要编码代理。突然间，公司有了多个提供商、多个数据类别、不同的用户组、重叠的检索索引、不同的日志记录规则、新的工具权限、重复的密钥以及不明确的所有权。",{},{"id":321,"data":322,"type":218,"tunes":324},"p-simple-3",{"text":323},"此时，问题不再是“助手能工作吗？”企业问题变成了：哪些能力被批准，谁拥有它们，哪些数据可以跨越哪个边界，身份和权限如何执行，哪些提供商可以接受，必须审计什么，以及组织如何在不失去控制的情况下更换模型或供应商？",{},{"id":326,"data":327,"type":349,"tunes":350},"simple-flow",{"steps":328,"title":347,"orientation":348},[329,332,335,338,341,344],{"label":330,"description":331},"1. 孤立的用例","一个团队将一个模型连接到一个工作流并验证本地价值。",{"label":333,"description":334},"2. 共享依赖出现","多个团队需要提供商、模型访问、检索、身份、密钥、可观测性和评估。",{"label":336,"description":337},"3. 跨越企业边界","AI触及受监管数据、记录系统、外部供应商、特权操作和业务决策。",{"label":339,"description":340},"4. 所有权必须明确","业务、架构、数据、安全、法律\u002F合规、采购和运营需要明确的职责。",{"label":342,"description":343},"5. 生命周期成为组织性的","模型变更、提示变更、提供商变更和新的代理能力成为受治理的变更，而不是本地开发人员的编辑。",{"label":345,"description":346},"6. 架构变得可重复","组织为新的AI工作负载建立可重用的模式、决策记录、控制、例外和验证关口。","从孤立的AI功能到企业架构","auto","processFlow",{},{"id":352,"data":353,"type":42,"tunes":355},"h-stop",{"text":354,"level":247},"简单例子止步之处",{},{"id":357,"data":358,"type":218,"tunes":360},"p-stop-1",{"text":359},"企业架构并不意味着每个AI组件都必须集中化。有些能力应该共享；其他能力必须保持领域所有。财务、人力资源、工程和客户支持可能合理地需要不同的数据边界、提供商、评估标准和人机审批规则。",{},{"id":362,"data":363,"type":218,"tunes":365},"p-stop-2",{"text":364},"因此，企业目标不是一个模型、一个向量数据库或一个通用助手。目标是具有明确差异的一致性架构：在减少风险和重复的地方采用通用策略和可重用能力，在业务或监管要求不同的地方采用受控的例外。",{},{"id":367,"data":368,"type":42,"tunes":370},"h-layers",{"text":369,"level":247},"当AI进入企业时，架构会发生哪些变化",{},{"id":372,"data":373,"type":42,"tunes":375},"h-business",{"text":374,"level":246},"1. 业务所有权成为技术架构的一部分",{},{"id":377,"data":378,"type":218,"tunes":380},"p-business-1",{"text":379},"传统应用已经需要业务负责人。AI使这一要求更加明显，因为可接受的行为不能仅由正常运行时间和功能正确性来定义。必须有人负责预期用途、不可接受的用途、输出质量、升级路径以及错误或不适当结果的后果。",{},{"id":382,"data":383,"type":218,"tunes":385},"p-business-2",{"text":384},"模型团队无法独自决定某个答案对于人力资源、财务、法律或面向客户的使用是否可接受。因此，企业AI架构将技术设计与明确的业务能力、责任所有者、用户群体和决策上下文连接起来。",{},{"id":387,"data":388,"type":42,"tunes":390},"h-data-authority",{"text":389,"level":246},"2. 数据访问还不够——必须定义数据权威",{},{"id":392,"data":393,"type":218,"tunes":395},"p-data-authority-1",{"text":394},"企业AI经常组合运营数据库、文档、搜索索引、向量存储、数据仓库、SaaS系统和外部知识。架构必须区分信息存储在哪里，以及对于给定声明或操作，哪个来源是权威的。",{},{"id":397,"data":398,"type":218,"tunes":400},"p-data-authority-2",{"text":399},"向量索引可以改善检索，但不应悄然成为公司的记录系统。模型响应可以总结ERP记录，但不应取代ERP作为权威来源。缓存上下文可以改善延迟，但当权限或底层业务状态发生变化时，它就会变得不安全。",{},{"id":402,"data":403,"type":218,"tunes":405},"p-data-authority-3",{"text":404},"因此，除了普通的数据集成之外，企业AI还需要来源追踪、新鲜度、来源分类、授权传播和失效规则。",{},{"id":407,"data":408,"type":226,"tunes":411},"authority-rule",{"body":409,"title":410,"variant":288},"\u003Cstrong>AI系统可以对企业数据进行转换、检索和推理，但不能成为该数据的权威。\u003C\u002Fstrong> 当用例需要证据、验证或产生后果的操作时，架构应保留一条返回权威来源的路径。","企业数据规则",{},{"id":413,"data":414,"type":42,"tunes":416},"h-identity",{"text":415,"level":246},"3. 身份变为多层",{},{"id":418,"data":419,"type":218,"tunes":421},"p-identity-1",{"text":420},"企业AI拥有的身份比人类用户更多。一个请求可能涉及用户身份、应用身份、服务身份、代理身份、提供商凭证、工具凭证以及租户或组织上下文。",{},{"id":423,"data":424,"type":218,"tunes":426},"p-identity-2",{"text":425},"这些身份不应被合并为一个共享的API密钥。授权必须保持可归因于正确的主体，特权工具应仅获得当前操作所需的权限。",{},{"id":428,"data":429,"type":218,"tunes":431},"p-identity-3",{"text":430},"对于代理系统，这一点尤为重要：模型可以提出操作，但运行时必须决定请求身份是否被允许执行该操作。模型能力不等于授权。",{},{"id":433,"data":434,"type":42,"tunes":436},"h-permissions",{"text":435,"level":246},"4. 权限从内容访问转向操作权限",{},{"id":438,"data":439,"type":218,"tunes":441},"p-permissions-1",{"text":440},"只读助手主要需要对信息的受控访问。企业代理可以创建工单、修改记录、发送消息、触发工作流或操作外部系统。这引入了不同的风险类别，因为系统可以改变状态，而不仅仅是描述状态。",{},{"id":443,"data":444,"type":218,"tunes":446},"p-permissions-2",{"text":445},"架构应分离读取、写入、审批和管理能力；在后果需要时定义人工介入点；并保留审计跟踪，以识别请求了什么、批准了什么以及实际改变了什么。",{},{"id":448,"data":449,"type":42,"tunes":451},"h-provider",{"text":450,"level":246},"5. AI提供商成为企业依赖",{},{"id":453,"data":454,"type":218,"tunes":456},"p-provider-1",{"text":455},"调用模型API也是一种供应商关系。架构可能依赖于提供商可用性、服务条款、数据处理条件、支持区域、模型生命周期、配额、定价、API兼容性、安全控制和变更通知。",{},{"id":458,"data":459,"type":218,"tunes":461},"p-provider-2",{"text":460},"这意味着提供商选择不仅仅是一个基准决策。采购、安全、隐私、法律审查、连续性规划和退出策略都可能成为架构输入。",{},{"id":463,"data":464,"type":218,"tunes":466},"p-provider-3",{"text":465},"提供商抽象可以减少耦合，但仅限于底层能力真正可移植的情况。工具使用、结构化输出、上下文限制、多模态、安全控制、微调和托管代理功能在不同提供商之间可能存在实质性差异。",{},{"id":468,"data":469,"type":42,"tunes":471},"h-risk",{"text":470,"level":246},"6. AI风险成为生命周期流程",{},{"id":473,"data":474,"type":218,"tunes":476},"p-risk-1",{"text":475},"AI风险不会在发布前的一次审批中完成。模型、提示、检索语料库、工具集、提供商、用户群体和周边业务流程都可能在部署后发生变化。风险状况也随之改变。",{},{"id":478,"data":479,"type":218,"tunes":481},"p-risk-2",{"text":480},"ISO\u002FIEC 23894:2023明确涉及将AI风险管理整合到组织活动和职能中。NIST AI RMF同样将风险管理框定在整个生命周期中。因此，企业架构应将风险审查作为变更和运营的一部分，而不是一份孤立的合规文件。",{},{"id":483,"data":484,"type":218,"tunes":486},"p-risk-3",{"text":485},"风险也应该是成比例的。一个摘要助手和一个改变生产记录的自主系统不应仅仅因为都使用LLM而接受相同的控制。",{},{"id":488,"data":489,"type":42,"tunes":491},"h-management-system",{"text":490,"level":246},"7. 治理成为操作系统，而非政策PDF",{},{"id":493,"data":494,"type":218,"tunes":496},"p-management-system-1",{"text":495},"ISO\u002FIEC 42001:2023定义了建立、实施、维护和持续改进AI管理系统的要求。架构后果很重要：治理必须将政策与真实的清单、所有权、流程、控制、证据、审查和改进循环连接起来。",{},{"id":498,"data":499,"type":218,"tunes":501},"p-management-system-2",{"text":500},"一个未与提供商审批、身份、日志记录、变更管理、评估和事件响应相关联的企业AI政策，其架构效果有限。组织需要使政策可执行或至少可观察的机制。",{},{"id":503,"data":504,"type":42,"tunes":506},"h-eval",{"text":505,"level":246},"8. 评估成为生产控制",{},{"id":508,"data":509,"type":218,"tunes":511},"p-eval-1",{"text":510},"传统的验收测试假设相同的输入通常产生相同的确定性结果。生成式AI可能是非确定性的、对上下文敏感，并依赖于不断变化的外部知识。因此，生产验收需要针对特定任务的评估、回归测试套件和可观察的阈值，而不仅仅是单元测试。",{},{"id":513,"data":514,"type":218,"tunes":516},"p-eval-2",{"text":515},"平台可以提供可重用的评估基础设施，但企业仍然需要拥有领域真实基准和发布门禁。一个中央AI团队无法为每个业务领域发明正确答案。",{},{"id":518,"data":519,"type":218,"tunes":521},"p-eval-3",{"text":520},"模型、提示、检索和工具的变更应可追溯到评估证据，前提是该变更可能实质性影响输出行为。",{},{"id":523,"data":524,"type":42,"tunes":526},"h-observability",{"text":525,"level":246},"9. 可观测性必须包括行为、数据和模型上下文",{},{"id":528,"data":529,"type":218,"tunes":531},"p-observability-1",{"text":530},"CPU、内存和HTTP错误率对于AI工作负载来说是不够的。生产可观测性可能需要模型\u002F提供商标识符、延迟、令牌使用、成本、检索结果、工具调用、拒绝行为、评估分数、安全事件和故障分类。",{},{"id":533,"data":534,"type":218,"tunes":536},"p-observability-2",{"text":535},"同时，AI遥测可能包含敏感数据。提示和响应日志可能成为影子数据存储。因此，企业架构必须定义可以记录什么、如何脱敏、谁可以访问、保留多长时间以及何时必须禁用详细跟踪。",{},{"id":538,"data":539,"type":42,"tunes":541},"h-lifecycle",{"text":540,"level":246},"10. AI组件需要明确的生命周期所有权",{},{"id":543,"data":544,"type":218,"tunes":546},"p-lifecycle-1",{"text":545},"模型可能被提供商重命名、替换、退役或更改。嵌入模型可能使索引策略失效。提示模板和系统指令可能改变行为。代理运行时和协议可能演变。外部工具可能更改其模式和权限。",{},{"id":548,"data":549,"type":218,"tunes":551},"p-lifecycle-2",{"text":550},"企业架构必须决定由谁检测这些变更、由谁测试、由谁批准、如何通知消费者、回滚如何运作，以及在新版本成为默认版本之前需要哪些证据。",{},{"id":553,"data":554,"type":42,"tunes":556},"h-operations",{"text":555,"level":246},"11. 事件响应必须包含AI特有的故障模式",{},{"id":558,"data":559,"type":218,"tunes":561},"p-operations-1",{"text":560},"AI事件可能是提供商中断、数据泄露、提示注入路径、授权失败、检索污染、意外模型行为、不安全工具执行、成本激增、知识过时、评估回归或外部模型行为变化。",{},{"id":563,"data":564,"type":218,"tunes":566},"p-operations-2",{"text":565},"因此，企业运行手册需要的不仅仅是“重启服务”。它可能需要禁用模型路由、撤销工具访问、冻结语料库、更改提示版本、禁用代理能力、切换提供商、上报给领域负责人或保留追踪记录以供调查。",{},{"id":568,"data":569,"type":42,"tunes":571},"h-ownership",{"text":570,"level":247},"企业AI创造跨职能所有权",{},{"id":573,"data":574,"type":292,"tunes":620},"ownership-table",{"content":575,"stretched":43,"withHeadings":14},[576,580,584,588,592,596,600,604,608,612,616],[577,578,579],"关注点","典型企业所有者或贡献者","架构问题",[581,582,583],"业务用途","业务所有者\u002F产品所有者","AI被允许支持或自动化哪些决策或工作流？",[585,586,587],"解决方案架构","AI\u002F解决方案架构师","具体工作负载如何满足其功能和质量要求？",[589,590,591],"共享AI能力","AI平台\u002F平台工程","提供哪些可复用的模型、检索、代理和可观测性服务？",[593,594,595],"企业一致性","企业架构","AI系统如何适应目标架构、标准、集成模式和组织所有权？",[597,598,599],"数据权威","数据所有者\u002F领域所有者","哪些数据是权威的、当前的、被允许的且得到充分治理的？",[601,602,603],"身份与安全","IAM\u002F安全架构","哪些身份可以访问哪些数据并执行哪些操作？",[605,606,607],"风险与合规","风险\u002F法律\u002F合规\u002F隐私","哪些义务、禁止用途、控制和证据适用于此用例？",[609,610,611],"供应商依赖","采购\u002F供应商管理\u002F架构","提供商带来哪些合同、运营和退出风险？",[613,614,615],"运营","SRE\u002F运营\u002F平台所有者","系统如何被监控、支持、降级、恢复和变更？",[617,618,619],"领域验收","业务\u002F领域专家","在此领域中，什么算作正确、安全或有用的结果？",{},{"id":622,"data":623,"type":226,"tunes":626},"ownership-warning",{"body":624,"title":625,"variant":233},"责任矩阵只有在连接到真实系统边界、审批、数据所有权、接口、运行手册和变更流程时才有用。企业AI需要可问责的所有权，并能追溯到技术控制和运营行动。","RACI图表本身不是架构",{},{"id":628,"data":629,"type":42,"tunes":631},"h-model",{"text":630,"level":247},"一个实用的企业AI架构模型",{},{"id":633,"data":634,"type":226,"tunes":637},"model-note",{"body":635,"title":636,"variant":240},"以下模型是用于推理企业AI架构的实用综合。它并非作为ISO或NIST标准提出。其目的是使跨组织边界明确化。","提议的分层模型",{},{"id":639,"data":640,"type":292,"tunes":669},"enterprise-model-table",{"content":641,"stretched":43,"withHeadings":14},[642,645,648,651,654,657,660,663,666],[643,644],"层","主要职责",[646,647],"业务与政策","已批准的用例、可问责的所有者、风险偏好、禁止用途、人类问责、业务验收。",[649,650],"身份与权限","用户\u002F服务\u002F代理身份、角色、租户或组织范围、特权操作、审批路径。",[652,653],"企业数据","记录系统、文档来源、数据产品、来源、分类、保留、新鲜度和访问。",[655,656],"AI平台","提供商\u002F模型访问、检索原语、代理运行时、工具代理、评估基础设施、可观测性、配额和密钥。",[658,659],"AI解决方案","领域工作流、提示\u002F指令、领域检索、业务逻辑、验收标准和用户体验。",[661,662],"集成与工具","API、企业应用、工作流、消息传递、文件系统、外部服务和操作执行。",[664,665],"风险与治理","清单、评估、合规证据、例外管理、模型\u002F提供商审批、审查和审计。",[667,668],"运营与生命周期","部署、监控、事件、发布、模型\u002F提供商变更、弃用、回滚和连续性。",{},{"id":671,"data":672,"type":218,"tunes":674},"p-model-1",{"text":673},"当每一层都能说明其职责和非职责时，架构最为强大。例如，AI平台可以执行提供商策略并收集追踪记录，而不成为HR数据的真相来源。解决方案可以定义领域提示，而不拥有企业IAM。业务所有者可以批准用例，而不被期望运营推理网关。",{},{"id":676,"data":677,"type":42,"tunes":679},"h-data-flow",{"text":678,"level":247},"将企业AI映射为数据和权限流，而非方框",{},{"id":681,"data":682,"type":349,"tunes":709},"enterprise-flow",{"steps":683,"title":708,"orientation":348},[684,687,690,693,696,699,702,705],{"label":685,"description":686},"1. 业务上下文","用户在已批准的用例下请求任务，并有可问责的业务所有者。",{"label":688,"description":689},"2. 身份与授权","系统在特权访问之前解析用户、应用程序、服务和租户或组织范围。",{"label":691,"description":692},"3. 权威数据获取","解决方案仅读取或检索当前身份和任务允许的来源。",{"label":694,"description":695},"4. AI处理","已批准的模型\u002F提供商在定义的路由和数据处理规则下处理最小必要上下文。",{"label":697,"description":698},"5. 工具或操作边界","任何改变状态的操作都独立授权，并可能根据后果需要人工批准。",{"label":700,"description":701},"6. 验证","结果根据解决方案特定的验收、证据或安全规则进行检查。",{"label":703,"description":704},"7. 审计与可观测性","允许的元数据、决策、路由、工具调用和结果被记录，而不创建不受控的敏感数据日志。",{"label":706,"description":707},"8. 反馈与生命周期","失败和评估结果通过受控变更管理反馈到模型、提示、数据、策略和流程变更中。","一个重要的企业AI请求",{},{"id":711,"data":712,"type":42,"tunes":714},"h-inventory",{"text":713,"level":247},"企业需要AI清单才能治理AI",{},{"id":716,"data":717,"type":218,"tunes":719},"p-inventory-1",{"text":718},"组织无法管理无法识别的AI系统。企业架构应维护一个对决策有用的清单，而不仅仅是模型名称列表。",{},{"id":721,"data":722,"type":292,"tunes":760},"inventory-table",{"content":723,"stretched":43,"withHeadings":14},[724,727,730,733,736,739,742,745,748,751,754,757],[725,726],"清单字段","为何重要",[728,729],"用例和所有者","将技术连接到可问责的业务目的。",[731,732],"用户和受影响方","定义谁与系统交互或受其影响。",[734,735],"模型\u002F提供商","识别外部依赖、能力和生命周期风险。",[737,738],"数据来源","支持权威、隐私、分类和来源审查。",[740,741],"部署\u002F运行时位置","阐明处理位置、连接性和运营控制。",[743,744],"工具\u002F操作","显示AI是否可以改变外部状态以及后果如何。",[746,747],"人工监督","记录需要审查、批准或上报的地方。",[749,750],"风险\u002F分类","将系统连接到组织和监管控制。",[752,753],"评估证据","显示测试了什么以及在哪些有效性条件下。",[755,756],"当前版本","允许将事件和回归追溯到实际部署状态。",[758,759],"生命周期状态","提议、实验、已批准、生产、受限、弃用或退役。",{},{"id":762,"data":763,"type":42,"tunes":765},"h-governance",{"text":764,"level":247},"AI治理和企业AI架构相关但不相同",{},{"id":767,"data":768,"type":303,"tunes":789},"governance-comparison",{"rows":769,"title":782,"layout":292,"columns":783},[770,774,778],{"id":771,"label":772,"values":773},"purpose","目的",[278,278],{"id":775,"label":776,"values":777},"example","示例",[278,278],{"id":779,"label":780,"values":781},"failure","孤立时的失败",[278,278],"治理与架构",[784,787],{"id":785,"label":786},"governance","AI治理",{"id":788,"label":302},"architecture",{},{"id":791,"data":792,"type":42,"tunes":794},"h-regulation",{"text":793,"level":247},"法规成为架构输入",{},{"id":796,"data":797,"type":218,"tunes":799},"p-regulation-1",{"text":798},"对于在欧盟运营的组织，AI法案可能产生影响系统设计、文档、透明度、治理和运营流程的要求。架构影响取决于组织在AI价值链中的角色和具体的系统分类；并非每个AI系统都有相同的义务。",{},{"id":801,"data":802,"type":218,"tunes":804},"p-regulation-2",{"text":803},"截至2026年10月8日，当前合并文本规定该法规一般从2026年8月2日起适用。治理规则和通用人工智能模型的义务更早开始适用，而特定的高风险系统条款有更晚的日期。委员会还从2026年8月2日起对相关的交互式和合成内容系统开始执行新的透明度要求。",{},{"id":806,"data":807,"type":218,"tunes":809},"p-regulation-3",{"text":808},"企业架构的教训不是“把合规放进模型里”。而是使分类、提供者\u002F部署者角色、文档、透明度、监督、日志记录和变更证据可追溯到实际实现用例的系统。",{},{"id":811,"data":812,"type":226,"tunes":815},"legal-note",{"body":813,"title":814,"variant":240},"本文描述架构影响，而非法律建议。企业AI架构应保留法律和合规专家对实际系统进行分类并将义务映射到具体控制所需的信息。架构不应将一种监管解释硬编码，仿佛每个AI工作负载都具有相同的状态。","法律范围因用例而异",{},{"id":817,"data":818,"type":42,"tunes":820},"h-procurement",{"text":819,"level":247},"采购与架构变得相互关联",{},{"id":822,"data":823,"type":218,"tunes":825},"p-procurement-1",{"text":824},"外部模型或托管AI平台可能成为深度依赖，即使集成只需要少量API调用。因此，企业架构应使采购问题在技术上具体化。",{},{"id":827,"data":828,"type":292,"tunes":857},"procurement-table",{"content":829,"stretched":43,"withHeadings":14},[830,833,836,839,842,845,848,851,854],[831,832],"采购问题","架构后果",[834,835],"数据在哪里处理？","区域、网络路径、数据驻留和传输控制。",[837,838],"客户数据是否被保留或用于提供者改进？","数据最小化、合同控制和提供者资格。",[840,841],"模型如何版本化或退役？","回归测试、兼容性、回退和生命周期规划。",[843,844],"配额和服务限制是什么？","容量架构、准入控制和故障处理。",[846,847],"集成的可移植性如何？","提供者抽象、退出成本和迁移工作量。",[849,850],"有哪些事件信息可用？","可观测性、取证能力和支持升级。",[852,853],"涉及哪些子处理者或外部服务？","依赖映射和风险评估。",[855,856],"未经客户明确批准会发生哪些变更？","变更检测、发布门禁和验收策略。",{},{"id":859,"data":860,"type":42,"tunes":862},"h-control",{"text":861,"level":247},"企业架构决定需求实际需要多少AI控制",{},{"id":864,"data":865,"type":292,"tunes":888},"control-table",{"content":866,"stretched":43,"withHeadings":14},[867,870,873,876,879,882,885],[868,869],"需求","可能的架构响应",[871,872],"快速访问托管模型","具有企业身份、网关控制和合同审查的托管提供者。",[874,875],"私有数据与托管编排","托管控制平面加上客户控制的执行或私有数据平面（如支持）。",[877,878],"严格本地化或主权","根据实际需求，采用区域限制、主权、私有或自托管架构。",[880,881],"气隙环境","本地托管模型、本地检索、本地工具、离线更新\u002F分发和隔离的可观测性。",[883,884],"提供者可移植性","应用拥有的领域状态加上适配器和合同，在实际可行的情况下隔离提供者特定行为。",[886,887],"对代理语义的最高控制","自管理或深度控制的运行时，具有明确的工具、上下文、状态和生命周期所有权。",{},{"id":890,"data":891,"type":218,"tunes":893},"p-control-1",{"text":892},"控制最多的架构并不自动是最好的企业架构。更多的所有权增加了对补丁、容量、安全、测试、模型运营和事件响应的责任。企业架构应仅在需求证明额外运营负担合理时升级控制。",{},{"id":895,"data":896,"type":42,"tunes":898},"h-change-management",{"text":897,"level":247},"AI将变更管理变成行为问题",{},{"id":900,"data":901,"type":218,"tunes":903},"p-change-1",{"text":902},"普通的依赖更新可能改变性能或兼容性。AI变更还可能改变行为。替换模型、更改系统提示、更改检索、添加工具或更改上下文策略，都可能改变系统的解释和响应方式，即使周围的应用程序代码几乎没有变化。",{},{"id":905,"data":906,"type":349,"tunes":933},"change-process",{"steps":907,"title":932,"orientation":348},[908,911,914,917,920,923,926,929],{"label":909,"description":910},"1. 识别变更","提出或检测到模型、提供者、提示、检索源、工具、策略或运行时变更。",{"label":912,"description":913},"2. 映射影响","识别受影响的解决方案、数据类别、用户、风险控制、成本、合同和运营依赖。",{"label":915,"description":916},"3. 更新架构决策","记录重要选择和权衡；被取代的决策保持历史可追溯。",{"label":918,"description":919},"4. 执行评估","运行相关的回归、安全、检索、延迟、成本和领域测试。",{"label":921,"description":922},"5. 应用批准","批准级别遵循后果、风险和组织政策。",{"label":924,"description":925},"6. 受控推出","在适当情况下使用版本化发布、金丝雀或分阶段部署。",{"label":927,"description":928},"7. 收集生产证据","监控遥测、事件、反馈和领域结果。",{"label":930,"description":931},"8. 回滚或验收","根据证据接受、限制、回滚或取代变更。","生产AI变更路径",{},{"id":935,"data":936,"type":42,"tunes":938},"h-nfr-adr",{"text":937,"level":247},"企业AI仍然需要NFR和ADR",{},{"id":940,"data":941,"type":218,"tunes":943},"p-nfr-adr-1",{"text":942},"AI不会取代普通的架构纪律。非功能需求仍然是目标条件：可用性、延迟、隐私、隔离、可审计性、可恢复性、成本边界、可解释性或其他质量要求。架构决策记录保留所选响应及其权衡。",{},{"id":945,"data":946,"type":218,"tunes":948},"p-nfr-adr-2",{"text":947},"AI特有的区别在于，某些质量属性必须以概率或经验方式评估。“答案必须有用”太模糊。生产需求应确定任务、数据、用户群体、可接受的失败条件、测量方法以及实际可行的阈值。",{},{"id":950,"data":951,"type":226,"tunes":954},"nfr-adr-chain",{"body":952,"title":953,"variant":288},"\u003Cstrong>业务需求 → 需求 \u002F NFR → 架构决策 → 实现 → 评估 \u002F 验证 → 生产观察 → 变更决策。\u003C\u002Fstrong> AI为这条链增加了新变量；它不会使这条链变得不必要。","企业可追溯性链",{},{"id":956,"data":957,"type":42,"tunes":959},"h-delivery",{"text":958,"level":247},"企业AI架构必须与交付相连",{},{"id":961,"data":962,"type":218,"tunes":964},"p-delivery-1",{"text":963},"从未进入待办事项、实施、验收和运营的架构仍停留在概念层面。因此，企业AI需要从架构决策到交付工作的可追溯性，以及从实施证据回到架构的可追溯性。",{},{"id":966,"data":967,"type":218,"tunes":969},"p-delivery-2",{"text":968},"Jira和Confluence是能够支持这种分离的工具示例，前提是有意使用：Confluence可以保存需求、架构、决策、风险和理由；Jira可以管理可操作的交付工作和状态。重要的原则是可追溯性，而不是工具品牌。",{},{"id":971,"data":972,"type":42,"tunes":974},"h-original",{"text":973,"level":247},"原始项目证据：Enterprise Aaasaasa 0.1",{},{"id":976,"data":977,"type":226,"tunes":980},"original-evidence-note",{"body":978,"title":979,"variant":240},"Enterprise Aaasaasa 0.1在此用作结构化企业架构和交付思维的原始项目证据。它是一个PoC\u002F企业项目背景，而非大规模客户采用、企业级生产使用或商业吸引力的证据。","项目证据，而非市场验证声明",{},{"id":982,"data":983,"type":218,"tunes":985},"p-enterprise-aaasaasa-1",{"text":984},"Enterprise Aaasaasa 0.1结合了平台架构、SaaS\u002FAPI概念、国际化、AI集成和结构化项目治理。该项目被有意组织为需求、架构、原型交付、验证和收尾作为独立的里程碑，而非一个未分化的实施阶段。",{},{"id":987,"data":988,"type":218,"tunes":990},"p-enterprise-aaasaasa-2",{"text":989},"架构方向包括多实例\u002F多数据库概念以及API、CRUD、i18n和AI能力。这对企业AI很重要，因为当添加AI功能时，租户或实例边界、数据库所有权和应用服务必须保持明确。",{},{"id":992,"data":993,"type":218,"tunes":995},"p-enterprise-aaasaasa-3",{"text":994},"项目结构还将架构延迟、范围蔓延和AI\u002F数据保护问题视为项目风险，而不是仅在实施过程中才发现它们。利益相关者包括技术、安全、发起人\u002F指导委员会和外部服务视角，这比仅关注模型的原型更接近企业AI真正的跨职能性质。",{},{"id":997,"data":998,"type":218,"tunes":1000},"p-enterprise-aaasaasa-4",{"text":999},"因此，有用的证据是架构与交付的整合：业务和项目结构、里程碑、风险、架构、后端\u002FAPI、前端\u002FAI工作、验证和收尾被视为相互关联的职责。这种模式是可复用的，尽管项目本身不应被呈现为外部企业采用的证明。",{},{"id":1002,"data":1003,"type":292,"tunes":1029},"enterprise-aaasaasa-table",{"content":1004,"stretched":43,"withHeadings":14},[1005,1008,1011,1014,1017,1020,1023,1026],[1006,1007],"项目要素","企业AI架构经验",[1009,1010],"需求里程碑","AI能力必须从已定义的需求、范围、验收和质量约束开始。",[1012,1013],"架构里程碑","数据、API、实例\u002F数据库边界和AI集成是明确的设计工作。",[1015,1016],"原型里程碑","架构必须足够可执行，以暴露集成风险。",[1018,1019],"验证里程碑","可运行的原型不等同于已验证的验收。",[1021,1022],"风险登记册","范围、架构延迟和AI\u002F数据保护问题作为交付风险进行管理。",[1024,1025],"利益相关者结构","企业AI跨越发起人\u002F业务、架构、安全、外部提供商和交付。",[1027,1028],"项目收尾","决策、剩余风险和验证证据必须在实施冲刺之后继续存在。",{},{"id":1031,"data":1032,"type":42,"tunes":1034},"h-supporting",{"text":1033,"level":247},"来自更广泛平台工作的支持性实施模式",{},{"id":1036,"data":1037,"type":218,"tunes":1039},"p-supporting-1",{"text":1038},"更广泛的Aaasaasa平台中的独立实施工作提供了企业AI架构必须保留的边界的具体示例：CMS中租户范围的RBAC，Aaasaasa AI Client中明确的提供商\u002F模型\u002F运行时\u002F权限分离，以及Source of Truth Research Engine中来源优先的检索。",{},{"id":1041,"data":1042,"type":218,"tunes":1044},"p-supporting-2",{"text":1043},"这些项目不应被合并为一个声称的生产平台。它们在此的价值更为狭窄：它们展示了身份范围、提供商边界、受控运行时权限、检索来源和证据可追溯性的已实施模式，这些与企业AI直接相关。",{},{"id":1046,"data":1047,"type":42,"tunes":1049},"h-standards",{"text":1048,"level":247},"主要标准如何协同",{},{"id":1051,"data":1052,"type":292,"tunes":1075},"standards-table",{"content":1053,"stretched":43,"withHeadings":14},[1054,1057,1060,1063,1066,1069,1072],[1055,1056],"来源","对企业AI架构的贡献",[1058,1059],"ISO\u002FIEC 42001:2023","组织级AI管理系统：政策、目标、流程、责任、监控和持续改进。",[1061,1062],"ISO\u002FIEC 23894:2023","将AI特定风险管理整合到组织活动和职能中的指南。",[1064,1065],"NIST AI RMF 1.0","面向生命周期的自愿性AI风险管理框架；围绕治理、映射、测量和管理组织。",[1067,1068],"NIST AI 600-1","生成式AI配置文件，扩展AI RMF，增加生成式AI特定的风险和行动。",[1070,1071],"EU AI Act","欧盟具有约束力的监管义务，其适用性取决于角色、系统类型和分类。",[1073,1074],"ISO\u002FIEC\u002FIEEE 42010:2022","用于表达关注点、视角、决策和关系的通用架构描述概念。",{},{"id":1077,"data":1078,"type":218,"tunes":1080},"p-standards-1",{"text":1079},"这些来源解决不同的问题。ISO\u002FIEC 42001不能替代技术架构。ISO\u002FIEC 23894和NIST AI RMF并未定义一个强制性的软件栈。EU AI Act是法律，不是平台设计模式。架构必须将适用的组织、风险和法律要求转化为可实施的系统边界和证据。",{},{"id":1082,"data":1083,"type":42,"tunes":1085},"h-failures",{"text":1084,"level":247},"常见企业AI失败模式",{},{"id":1087,"data":1088,"type":292,"tunes":1126},"failures-table",{"content":1089,"stretched":43,"withHeadings":14},[1090,1093,1096,1099,1102,1105,1108,1111,1114,1117,1120,1123],[1091,1092],"失败模式","为何失败",[1094,1095],"每个团队独立购买AI","造成影子提供商、重复的密钥、不一致的数据处理和对供应商风险的弱控制力。",[1097,1098],"一个中央AI团队拥有所有领域决策","集中了技术控制，但失去了领域问责制并造成瓶颈。",[1100,1101],"向量数据库成为事实来源","检索基础设施悄然取代了权威系统和新鲜度规则。",[1103,1104],"所有用户和代理共享一个API密钥","破坏了归属、最小权限和有意义的可审计性。",[1106,1107],"模型变更像小库补丁一样部署","行为回归可能在未经领域评估的情况下进入生产。",[1109,1110],"所有提示和输出永久记录","可观测性创建了一个不受控的敏感数据存储库。",[1112,1113],"治理仅是文档","政策存在但没有执行点、证据或运营所有权。",[1115,1116],"合规委托给提供商","组织自身的角色、用例、数据和运营义务仍未解决。",[1118,1119],"代理可以调用工具，因为模型支持工具使用","将能力误认为授权。",[1121,1122],"平台健康等同于业务正确性","端点正常运行时间和模型可用性并不能证明领域答案质量或可接受的结果。",[1124,1125],"没有模型\u002F提供商依赖的退出策略","定价、政策、能力或可用性变化成为紧急迁移。",{},{"id":1128,"data":1129,"type":42,"tunes":1131},"h-misconceptions",{"text":1130,"level":247},"常见误解",{},{"id":1133,"data":1134,"type":292,"tunes":1163},"misconceptions-table",{"content":1135,"stretched":43,"withHeadings":14},[1136,1139,1142,1145,1148,1151,1154,1157,1160],[1137,1138],"误解","更好的模型",[1140,1141],"“企业AI意味着全公司范围的聊天机器人。”","聊天机器人只是一个界面；企业AI架构管理底层的数据、身份、提供商、运行时、风险和运营。",[1143,1144],"“如果我们使用信誉良好的模型提供商，治理问题就解决了。”","提供商的控制措施并不能定义你的用例、数据权限、用户权限、业务验收或法律角色。",[1146,1147],"“私有AI意味着一切都必须自托管。”","隐私要求可以导致多种架构；所需的控制边界必须被精确地陈述。",[1149,1150],"“AI治理属于法律部门，架构属于IT部门。”","这两个学科必须连接起来，因为政策义务需要可实施的控制措施和证据。",[1152,1153],"“一个企业模型更简单。”","标准化可能有帮助，但工作负载可能需要不同的模态、区域、成本、质量水平或控制模型。",[1155,1156],"“AI风险就是模型风险。”","风险可能来源于数据、提示、检索、身份、工具、界面、运营、用户和组织流程。",[1158,1159],"“人在回路中使代理安全。”","人工审批只有在审查者拥有有用的上下文、权限、时间和明确的决策点时才有帮助。",[1161,1162],"“成功的试点证明了企业就绪。”","试点证明了有限的能力；企业就绪还需要集成、治理、生命周期、运营和可重复的控制措施。",{},{"id":1165,"data":1166,"type":42,"tunes":1168},"h-framework",{"text":1167,"level":247},"实用的企业AI架构决策序列",{},{"id":1170,"data":1171,"type":349,"tunes":1210},"decision-framework",{"steps":1172,"title":1209,"orientation":348},[1173,1176,1179,1182,1185,1188,1191,1194,1197,1200,1203,1206],{"label":1174,"description":1175},"1. 定义业务能力","陈述用户、决策或工作流、预期价值和负责的所有者。",{"label":1177,"description":1178},"2. 分类数据和权限","识别记录系统、个人\u002F机密数据、保留、新鲜度和来源要求。",{"label":1180,"description":1181},"3. 定义身份和行动边界","确定谁可以读取、生成、决定、批准和更改外部系统。",{"label":1183,"description":1184},"4. 选择解决方案和平台职责","决定什么属于工作负载、什么可以共享以及什么保持企业所有。",{"label":1186,"description":1187},"5. 评估提供商和运行时依赖","根据实际需求评估托管、自托管、私有、主权或混合选项。",{"label":1189,"description":1190},"6. 映射风险和监管义务","确定具体系统的风险级别、组织控制和适用的法律责任。",{"label":1192,"description":1193},"7. 定义可衡量的验收标准","为质量、可靠性、安全性、检索、成本和运营行为创建评估标准。",{"label":1195,"description":1196},"8. 记录架构决策","保留理由、替代方案、权衡、依赖关系以及会触发重新考虑的条件。",{"label":1198,"description":1199},"9. 将架构与交付连接","将设计转化为待办事项、里程碑、验收标准、技术工作和所有权。",{"label":1201,"description":1202},"10. 在生产形态条件下验证","测试真实的身份、数据、故障、延迟、提供商、工具和恢复场景，而不仅仅是干净的演示。",{"label":1204,"description":1205},"11. 建立运营和变更控制","定义监控、事件响应、模型\u002F提供商更新、回归测试、回滚和退役。",{"label":1207,"description":1208},"12. 将证据反馈到架构中","使用生产观察、审计、事件和评估来修订决策和控制措施。","从机会到受治理的企业能力",{},{"id":1212,"data":1213,"type":42,"tunes":1215},"h-checklist",{"text":1214,"level":247},"企业AI架构检查清单",{},{"id":1217,"data":1218,"type":292,"tunes":1265},"checklist-table",{"content":1219,"stretched":43,"withHeadings":14},[1220,1223,1226,1229,1232,1235,1238,1241,1244,1247,1250,1253,1256,1259,1262],[1221,1222],"问题","预期证据",[1224,1225],"这个AI支持什么业务能力？","指定的所有者、用户组、预期决策\u002F工作流和验收目标。",[1227,1228],"对于每个重要事实，哪个来源是权威的？","记录系统、文档权威、来源和新鲜度规则。",[1230,1231],"存在哪些身份？","人类、应用程序、服务、代理、租户\u002F组织和提供商身份是可区分的。",[1233,1234],"AI可以读取什么？","授权范围的数据源和明确的敏感数据规则。",[1236,1237],"AI可以更改什么？","工具\u002F行动清单、权限模型、审批和回滚路径。",[1239,1240],"使用哪个提供商\u002F模型，为什么？","架构决策包括质量、安全性、成本、区域、生命周期和退出考虑。",[1242,1243],"如果提供商不可用会发生什么？","降级模式、回退、拒绝或连续性计划。",[1245,1246],"如何评估质量？","特定任务的数据集、评分器、阈值、回归标准和有效性条件。",[1248,1249],"记录了什么？","遥测模式、编辑、访问、保留和审计目的。",[1251,1252],"谁拥有AI风险？","与具体系统相关的指定组织责任。",[1254,1255],"适用什么法律分类？","基于当前法律和实际用例的书面评估。",[1257,1258],"模型\u002F提示\u002F检索的更改如何被批准？","版本控制、评估、架构\u002F变更记录和推出关口。",[1260,1261],"谁响应AI事件？","运行手册、技术所有者、业务\u002F领域升级和提供商升级。",[1263,1264],"系统如何退役？","数据清理、访问撤销、提供商退出、证据保留和依赖移除。",{},{"id":1267,"data":1268,"type":42,"tunes":1270},"h-edge",{"text":1269,"level":247},"边缘案例和限制",{},{"id":1272,"data":1273,"type":218,"tunes":1275},"p-edge-1",{"text":1274},"一个只有低风险AI用例的小公司可能不需要正式的企业AI架构职能。同样的原则可以轻量应用：明确的所有者、批准的数据、明确的提供商、基本评估、访问控制和运营责任。",{},{"id":1277,"data":1278,"type":218,"tunes":1280},"p-edge-2",{"text":1279},"高度受监管的组织可能需要更强的分离、独立验证、正式合规流程、本地托管或气隙操作。这些控制措施由用例和监管环境驱动，而不是由“企业”这个词驱动。",{},{"id":1282,"data":1283,"type":218,"tunes":1285},"p-edge-3",{"text":1284},"组织也可以主要使用SaaS AI产品而不是构建AI系统。企业架构仍然重要，因为身份、数据访问、合同条款、影子AI、保留、审计和供应商集中度仍然是组织关注的问题。",{},{"id":1287,"data":1288,"type":218,"tunes":1290},"p-edge-4",{"text":1289},"集中式平台不是强制性的。当领域有实质性不同的需求时，联邦式平台所有权可能是有效的，前提是企业级身份、风险、清单和互操作性职责保持一致。",{},{"id":1292,"data":1293,"type":42,"tunes":1295},"h-change-answer",{"text":1294,"level":247},"什么会改变这个答案？",{},{"id":1297,"data":1298,"type":218,"tunes":1300},"p-change-answer-1",{"text":1299},"当组织的风险容忍度、监管分类、数据敏感性、地理范围、提供商策略、内部技能或业务关键性发生变化时，架构就会改变。一个公共营销助手和一个参与就业、金融、医疗或关键基础设施决策的系统不应继承相同的控制模型。",{},{"id":1302,"data":1303,"type":218,"tunes":1305},"p-change-answer-2",{"text":1304},"随着标准、法规和AI平台的发展，实现也会改变。NIST AI RMF 1.0目前正在修订中，欧盟AI法案有分阶段的应用日期，模型\u002F提供商能力继续快速变化。因此，企业架构应保留稳定的职责边界，同时将提供商机制和监管细节视为版本化输入。",{},{"id":1307,"data":1308,"type":42,"tunes":1310},"h-related",{"text":1309,"level":247},"相关规范知识",{},{"id":1312,"data":1313,"type":218,"tunes":1315},"p-related-1",{"text":1314},"企业AI架构建立在解决方案和平台架构之上。解决方案层解释一个工作负载。平台层解释可重用的AI能力。企业层将两者连接到组织范围内的数据、身份、治理、风险、采购和运营。",{},{"id":1317,"data":1318,"type":218,"tunes":1320},"p-related-2",{"text":1319},"检索增强生成只是这个架构中的一种机制。RAG可以改善对企业知识的访问，但它本身并不能解决数据权威、权限、治理或答案有效性问题。",{},{"id":1322,"data":1323,"type":1328,"tunes":1329},"ref-rag",{"url":1324,"title":1325,"excerpt":1326,"ctaLabel":1327},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","什么是RAG？其工作原理的最简单解释","用通俗易懂的英语解释外部知识检索如何连接到语言模型，而不会将检索变成真相的来源。","阅读RAG基础","referralArticle",{},{"id":1331,"data":1332,"type":218,"tunes":1334},"p-related-3",{"text":1333},"对于证据密集型企业用例，答案有效性还需要一个明确的边界：输出仅在其产生的证据、版本、范围和假设下才被支持。",{},{"id":1336,"data":1337,"type":1328,"tunes":1342},"ref-avb",{"url":1338,"title":1339,"excerpt":1340,"ctaLabel":1341},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","答案有效性边界：相关性与可靠AI答案之间缺失的层次","一个框架，用于明确AI主张在何种条件下仍然成立，以及哪些变化需要限制或重新计算。","阅读答案有效性边界",{},{"id":1344,"data":1345,"type":218,"tunes":1347},"p-related-4",{"text":1346},"下游企业主题包括AI治理、私有AI、主权AI、气隙AI、多租户AI架构、RBAC与租户隔离、提供商抽象、模型路由和生产AI架构。",{},{"id":1349,"data":1350,"type":42,"tunes":1352},"h-faq",{"text":1351,"level":247},"常见问题",{},{"id":1354,"data":1355,"type":1354,"tunes":1390},"faq",{"items":1356,"title":1389},[1357,1361,1365,1369,1373,1377,1381,1385],{"id":1358,"answer":1359,"question":1360},"faq1","企业AI架构是一种组织范围的架构，定义了AI解决方案和共享AI能力如何与业务所有权、企业数据、身份、安全、提供商、治理、风险、合规、生命周期和运营集成。","什么是企业AI架构？",{"id":1362,"answer":1363,"question":1364},"faq2","不相同。AI平台提供可复用的技术能力，如模型访问、检索、代理运行时和可观测性。企业AI架构定义了该平台和各个AI解决方案如何融入组织更广泛的架构和运营模式。","企业AI架构与AI平台相同吗？",{"id":1366,"answer":1367,"question":1368},"faq3","不需要。标准化可以降低复杂性，但不同的工作负载可能需要不同的提供商、模型、区域、控制级别或模态。重要的要求是明确的策略和生命周期所有权。","企业AI需要一个中央模型吗？",{"id":1370,"answer":1371,"question":1372},"faq4","因为检索或生成的信息并不自动具有权威性。企业系统需要保留哪个来源是记录系统、数据是否最新、谁可以访问以及生成的声明如何追溯到证据。","为什么数据权威对企业AI很重要？",{"id":1374,"answer":1375,"question":1376},"faq5","AI治理定义策略、问责制和决策权。企业AI架构定义系统边界、接口、数据流和技术机制，通过这些机制可以实施和证明这些策略。","AI治理与企业AI架构有什么区别？",{"id":1378,"answer":1379,"question":1380},"faq6","不是。义务取决于组织的角色、系统的用例和分类以及相关现行条款等因素。法律分类必须根据现行法律对具体系统进行。","欧盟AI法案是否以相同方式适用于每个企业AI系统？",{"id":1382,"answer":1383,"question":1384},"faq7","不够。试点展示的是有限的能力。企业部署还需要身份、数据权威、安全、提供商治理、评估、生命周期、事件响应、监控、合规和可问责的运营所有权。","成功的AI试点是否足以进行企业部署？",{"id":1386,"answer":1387,"question":1388},"faq8","只有当需求证明增加的控制和运营责任合理时才应如此。托管、私有、主权、自托管和混合方法是架构选项，其适用性取决于数据、监管、可用性、成本、能力和运营要求。","企业应该自行托管AI吗？","企业AI架构常见问题",{},{"id":1392,"data":1393,"type":42,"tunes":1395},"h-glossary",{"text":1394,"level":247},"术语表",{},{"id":1397,"data":1398,"type":1397,"tunes":1438},"glossary",{"title":1399,"entries":1400},"关键企业AI架构术语",[1401,1404,1408,1411,1415,1419,1423,1426,1430,1434],{"term":302,"anchor":1402,"definition":1403},"enterprise-ai-architecture","组织范围的架构，管理AI系统、平台、数据、身份、提供商、风险控制和运营如何协同。",{"term":1405,"anchor":1406,"definition":1407},"AI管理系统","ai-management-system","用于建立AI相关策略、目标和流程的组织管理系统；ISO\u002FIEC 42001规定了此类系统的要求。",{"term":597,"anchor":1409,"definition":1410},"data-authority","识别哪个来源或系统对特定事实、记录、状态或决策上下文具有权威性的规则。",{"term":1412,"anchor":1413,"definition":1414},"记录系统","system-of-record","负责业务记录或领域实体官方当前状态的权威系统。",{"term":1416,"anchor":1417,"definition":1418},"AI清单","ai-inventory","对AI用例、所有者、模型\u002F提供商、数据、工具、风险、评估证据、生命周期状态及相关控制的结构化记录。",{"term":1420,"anchor":1421,"definition":1422},"提供商依赖","provider-dependency","当AI工作负载依赖外部模型或托管平台时产生的技术、合同和运营依赖。",{"term":746,"anchor":1424,"definition":1425},"human-oversight","在系统后果、不确定性或法规要求时应用的定义明确的人工审查、批准、干预或升级。",{"term":1427,"anchor":1428,"definition":1429},"GenAIOps","genaiops","针对生成式AI工作负载的运营实践，涵盖模型选择、提示、基础数据、评估、部署、监控和生命周期管理。",{"term":1431,"anchor":1432,"definition":1433},"AI风险管理","ai-risk-management","在整个生命周期中识别、评估、处理、监控和修订与AI系统相关风险的组织流程。",{"term":1435,"anchor":1436,"definition":1437},"架构决策","architecture-decision","重要的设计选择及其上下文、理由、替代方案、权衡和生命周期状态。",{},{"id":1440,"data":1441,"type":42,"tunes":1443},"h-conclusion",{"text":1442,"level":247},"结论",{},{"id":1445,"data":1446,"type":218,"tunes":1448},"p-conclusion-1",{"text":1447},"当AI进入公司时，企业不仅仅获得了一个新的软件组件。它获得了一类新的行为和依赖，贯穿数据、身份、供应商、业务决策、安全、运营、治理和变更管理。",{},{"id":1450,"data":1451,"type":218,"tunes":1453},"p-conclusion-2",{"text":1452},"架构上的应对不是将所有事情集中化。而是明确责任：哪些数据具有权威性、哪些身份可以行动、哪些提供商获得批准、哪些控制是共享的、哪些决策仍由领域拥有、如何评估行为、如何处理事件以及系统如何随时间变化。",{},{"id":1455,"data":1456,"type":218,"tunes":1458},"p-conclusion-3",{"text":1457},"这就是企业AI架构的核心区别：它将孤立的AI能力转变为组织上可治理的系统，而不假装模型、平台、业务领域和企业控制是同一回事。",{},{"id":1460,"data":1461,"type":42,"tunes":1463},"h-sources",{"text":1462,"level":247},"主要来源和当前指南",{},{"id":1465,"data":1466,"type":218,"tunes":1468},"p-sources-note",{"text":1467},"以下外部标准、法规和当前供应商架构指南已于2026年10月8日核查。项目特定部分明确标记为原始项目证据，不应被解读为对一般行业事实的主张。",{},{"id":1470,"data":1471,"type":1477,"tunes":1478},"src-iso-42001",{"link":1472,"meta":1473},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001",{"image":1474,"title":1475,"description":1476},{"url":278},"ISO\u002FIEC 42001:2023 — 人工智能管理系统","国际标准，规定了在组织内建立、实施、维护和持续改进AI管理系统的要求。","linkTool",{},{"id":1480,"data":1481,"type":1477,"tunes":1487},"src-iso-23894",{"link":1482,"meta":1483},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html",{"image":1484,"title":1485,"description":1486},{"url":278},"ISO\u002FIEC 23894:2023 — AI风险管理指南","将AI特定风险管理整合到组织活动和职能中的国际指南。",{},{"id":1489,"data":1490,"type":1477,"tunes":1496},"src-nist-rmf",{"link":1491,"meta":1492},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",{"image":1493,"title":1494,"description":1495},{"url":278},"NIST AI风险管理框架","NIST的志愿性生命周期导向框架，用于管理AI风险。NIST表示AI RMF 1.0目前正在修订中。",{},{"id":1498,"data":1499,"type":1477,"tunes":1505},"src-nist-genai",{"link":1500,"meta":1501},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence",{"image":1502,"title":1503,"description":1504},{"url":278},"NIST AI 600-1 — 生成式AI概况","NIST配套概况，描述生成式AI特定风险以及与AI RMF一致的风险管理行动。",{},{"id":1507,"data":1508,"type":1477,"tunes":1514},"src-eu-consolidated",{"link":1509,"meta":1510},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng",{"image":1511,"title":1512,"description":1513},{"url":278},"EUR-Lex — 欧盟法规 (EU) 2024\u002F1689，合并文本","截至2026年10月8日核查的当前合并AI法案文本，用于适用日期和监管结构。",{},{"id":1516,"data":1517,"type":1477,"tunes":1523},"src-eu-timeline",{"link":1518,"meta":1519},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"image":1520,"title":1521,"description":1522},{"url":278},"欧盟委员会 — 人工智能法案监管框架","委员会当前对人工智能法案应用阶段的概述，包括2026年的适用性以及特定高风险条款的后续日期。",{},{"id":1525,"data":1526,"type":1477,"tunes":1532},"src-ms-ai",{"link":1527,"meta":1528},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started",{"image":1529,"title":1530,"description":1531},{"url":278},"Microsoft Azure 架构良好的框架 — AI 工作负载","关于 AI 工作负载的当前架构指导，包括非确定性行为、数据、应用程序设计和操作。",{},{"id":1534,"data":1535,"type":1477,"tunes":1541},"src-ms-ops",{"link":1536,"meta":1537},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops",{"image":1538,"title":1539,"description":1540},{"url":278},"Microsoft — 面向 AI 工作负载的 MLOps 和 GenAIOps","关于运营生命周期、数据、模型维护、部署、监控和持续演进的当前指导。",{},{"id":1543,"data":1544,"type":1477,"tunes":1550},"src-ms-responsible",{"link":1545,"meta":1546},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai",{"image":1547,"title":1548,"description":1549},{"url":278},"Microsoft — Azure 工作负载中的负责任 AI","将 AI 策略与数据控制、身份、代理可审计性、基于角色的访问和操作保障联系起来的当前指导。",{},{"id":1552,"data":1553,"type":1477,"tunes":1559},"src-iso-42010",{"link":1554,"meta":1555},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html",{"image":1556,"title":1557,"description":1558},{"url":278},"ISO\u002FIEC\u002FIEEE 42010:2022 — 架构描述","当前架构描述标准，支持跨系统架构的明确关注点、视角和关系。",{},"2.31","企业AI架构阐释了AI如何在数据权限、身份、许可、提供商、风险、治理、评估、合规和运营方面改变公司系统。","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","enterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq","PUBLISHED","2026-10-08T10:48:00.000Z","2026-10-08T16:48:07.244Z","2026-10-08T17:02:36.954Z",{"en":1569,"de":1570,"sr":1571,"es":1572,"fr":1573,"it":1574,"ru":1575,"zh":1576},"\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fde\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fsr\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fes\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Ffr\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fit\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fru\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company","\u002Fzh\u002Fblog\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company",[1578,1581,1585,1589],{"id":1579,"name":1580,"slug":785},59,"治理与可审计性",{"id":1582,"name":1583,"slug":1584},57,"数据边界","data-boundaries",{"id":1586,"name":1587,"slug":1588},80,"访问与身份","access-and-identity",{"id":1590,"name":1591,"slug":1592},84,"策略与数据边界","policy-and-data",{"id":1594,"login":1595,"email":1596,"displayName":1597},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1599,2744],{"lang":1600,"title":1601,"content":1602,"contentJson":1603,"excerpt":2743},"en","Enterprise AI Architecture: What Changes When AI Enters a Company","{\"time\":1791478189041,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture is the organization-wide architecture required when AI becomes part of a company's real systems, data, decisions and operations. The model is only one component. Once AI is connected to enterprise data, identities, permissions, business processes, external providers and production systems, the architecture must also define data authority, access boundaries, risk ownership, provider dependencies, auditability, evaluation, lifecycle control, compliance and operational responsibility. Enterprise AI therefore differs from both a single AI solution and a shared AI platform: it coordinates how many AI-enabled systems fit into the wider organization.\"},\"tunes\":{}},{\"id\":\"direct-answer\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"\u003Cstrong>What changes when AI enters a company?\u003C\u002Fstrong> Existing enterprise architecture responsibilities expand to include probabilistic model behavior, new data flows, retrieval and grounding, model\u002Fprovider dependencies, AI-specific evaluation, agent\u002Ftool authority, model and prompt lifecycle, AI risk management, transparency obligations, and new operational failure modes. The architecture must connect these concerns to the company's existing identity, security, data, procurement, delivery and governance structures instead of creating a parallel “AI universe.”\"},\"tunes\":{}},{\"id\":\"not-bigger-chatbot\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Enterprise AI is not “a bigger chatbot”\",\"body\":\"A chatbot can be a user interface. Enterprise AI architecture is the system of boundaries behind it: what data the AI may access, which source is authoritative, who may use which capability, whether external providers may receive the data, what actions an agent may execute, how outputs are evaluated, what must be logged, who owns incidents, and how changes are approved and rolled back.\"},\"tunes\":{}},{\"id\":\"current-date\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"The architectural principles in this article are intended to be stable. Regulation, standards and vendor capabilities are version-sensitive. ISO\u002FIEC 42001:2023 and ISO\u002FIEC 23894:2023 are current published standards. NIST states that AI RMF 1.0 is being revised. Under the current consolidated EU AI Act text, the Regulation applies generally from 2 August 2026, while specified high-risk provisions have later application dates. Legal classification must always be checked against the current law and the concrete use case.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What enterprise AI architecture really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture describes how AI capabilities are integrated into an existing organization without breaking the boundaries that already make enterprise systems governable: business ownership, identity, authorization, data classification, system-of-record responsibility, change management, procurement, audit, continuity and operations.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise architect does not replace the AI Solution Architect or AI Platform Architect. The enterprise scope asks a different question: How do multiple AI solutions and shared AI capabilities fit into the company's target architecture, policies, data landscape, risk model and operating model?\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This makes enterprise AI architecture a coordination discipline across technology and organization. A technically good model integration can still be an enterprise architecture failure if it creates shadow data flows, duplicates identity, bypasses procurement, cannot be audited, has no owner, or cannot be safely changed.\"},\"tunes\":{}},{\"id\":\"scope-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Solution, platform and enterprise AI architecture are different scopes\",\"layout\":\"table\",\"columns\":[{\"id\":\"solution\",\"label\":\"AI Solution Architecture\"},{\"id\":\"platform\",\"label\":\"AI Platform Architecture\"},{\"id\":\"enterprise\",\"label\":\"Enterprise AI Architecture\"}],\"rows\":[{\"id\":\"scope\",\"label\":\"Primary scope\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"question\",\"label\":\"Primary question\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"ownership\",\"label\":\"Ownership focus\",\"values\":[\"\",\"\",\"\"]},{\"id\":\"success\",\"label\":\"Success condition\",\"values\":[\"\",\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A company starts with one internal document assistant. The first version searches approved documents and sends retrieved context to a language model. At solution level, this may look straightforward.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Then a second team wants AI for customer support. A third wants an agent that can update tickets. Finance wants document analysis. HR wants an internal assistant. Developers want coding agents. Suddenly the company has several providers, several data classes, different user groups, overlapping retrieval indexes, different logging rules, new tool permissions, duplicated secrets and unclear ownership.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"At that point, the question is no longer “Does the assistant work?” The enterprise question becomes: Which capabilities are approved, who owns them, what data can cross which boundary, how are identities and permissions enforced, which providers are acceptable, what must be audited, and how can the organization change models or suppliers without losing control?\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"From isolated AI feature to enterprise architecture\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Isolated use case\",\"description\":\"One team connects one model to one workflow and validates local value.\"},{\"label\":\"2. Shared dependencies appear\",\"description\":\"Multiple teams need providers, model access, retrieval, identity, secrets, observability and evaluation.\"},{\"label\":\"3. Enterprise boundaries are crossed\",\"description\":\"AI touches regulated data, systems of record, external vendors, privileged actions and business decisions.\"},{\"label\":\"4. Ownership must become explicit\",\"description\":\"Business, architecture, data, security, legal\u002Fcompliance, procurement and operations need defined responsibilities.\"},{\"label\":\"5. Lifecycle becomes organizational\",\"description\":\"Model changes, prompt changes, provider changes and new agent capabilities become governed changes rather than local developer edits.\"},{\"label\":\"6. Architecture becomes repeatable\",\"description\":\"The organization establishes reusable patterns, decision records, controls, exceptions and validation gates for new AI workloads.\"}]},\"tunes\":{}},{\"id\":\"h-stop\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stop-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise architecture does not mean that every AI component must be centralized. Some capabilities should be shared; others must remain domain-owned. Finance, HR, engineering and customer support may legitimately require different data boundaries, providers, evaluation criteria and human-approval rules.\"},\"tunes\":{}},{\"id\":\"p-stop-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise objective is therefore not one model, one vector database or one universal assistant. The objective is coherent architecture with explicit variation: common policies and reusable capabilities where they reduce risk and duplication, plus controlled exceptions where business or regulatory requirements differ.\"},\"tunes\":{}},{\"id\":\"h-layers\",\"type\":\"header\",\"data\":{\"text\":\"What changes in the architecture when AI enters the enterprise\",\"level\":2},\"tunes\":{}},{\"id\":\"h-business\",\"type\":\"header\",\"data\":{\"text\":\"1. Business ownership becomes part of the technical architecture\",\"level\":3},\"tunes\":{}},{\"id\":\"p-business-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Traditional applications already need business owners. AI makes that requirement more visible because acceptable behavior cannot be defined only by uptime and functional correctness. Someone must own the intended use, unacceptable use, output quality, escalation path and consequences of wrong or inappropriate results.\"},\"tunes\":{}},{\"id\":\"p-business-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A model team cannot decide alone whether an answer is acceptable for HR, finance, legal or customer-facing use. Enterprise AI architecture therefore connects technical design to an explicit business capability, accountable owner, user group and decision context.\"},\"tunes\":{}},{\"id\":\"h-data-authority\",\"type\":\"header\",\"data\":{\"text\":\"2. Data access is not enough — data authority must be defined\",\"level\":3},\"tunes\":{}},{\"id\":\"p-data-authority-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI frequently combines operational databases, documents, search indexes, vector stores, data warehouses, SaaS systems and external knowledge. The architecture must distinguish where information is stored from which source is authoritative for a given claim or action.\"},\"tunes\":{}},{\"id\":\"p-data-authority-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A vector index can improve retrieval but should not silently become the company's system of record. A model response can summarize an ERP record but should not replace the ERP as the authoritative source. Cached context can improve latency but becomes unsafe when permissions or underlying business state change.\"},\"tunes\":{}},{\"id\":\"p-data-authority-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI therefore needs provenance, freshness, source classification, authorization propagation and invalidation rules in addition to ordinary data integration.\"},\"tunes\":{}},{\"id\":\"authority-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Enterprise data rule\",\"body\":\"\u003Cstrong>The AI system may transform, retrieve and reason over enterprise data without becoming the authority for that data.\u003C\u002Fstrong> The architecture should preserve a path back to the authoritative source whenever the use case requires evidence, verification or consequential action.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"3. Identity becomes multi-layered\",\"level\":3},\"tunes\":{}},{\"id\":\"p-identity-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI has more identities than the human user. A request may involve a user identity, application identity, service identity, agent identity, provider credential, tool credential and tenant or organizational context.\"},\"tunes\":{}},{\"id\":\"p-identity-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"These identities should not be collapsed into one shared API key. Authorization must remain attributable to the correct principal, and privileged tools should receive only the authority required for the current operation.\"},\"tunes\":{}},{\"id\":\"p-identity-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For agentic systems, this becomes especially important: a model can propose an action, but the runtime must decide whether the requesting identity is allowed to execute it. Model capability is not authorization.\"},\"tunes\":{}},{\"id\":\"h-permissions\",\"type\":\"header\",\"data\":{\"text\":\"4. Permissions move from content access to action authority\",\"level\":3},\"tunes\":{}},{\"id\":\"p-permissions-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A read-only assistant mainly needs controlled access to information. An enterprise agent can create tickets, modify records, send messages, trigger workflows or operate external systems. That introduces a different risk class because the system can change state rather than merely describe it.\"},\"tunes\":{}},{\"id\":\"p-permissions-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture should separate read, write, approval and administrative capabilities; define human-in-the-loop points where consequence justifies them; and preserve an audit trail that identifies what was requested, what was approved and what actually changed.\"},\"tunes\":{}},{\"id\":\"h-provider\",\"type\":\"header\",\"data\":{\"text\":\"5. The AI provider becomes an enterprise dependency\",\"level\":3},\"tunes\":{}},{\"id\":\"p-provider-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Calling a model API is also a supplier relationship. The architecture may depend on provider availability, service terms, data-processing conditions, supported regions, model lifecycle, quotas, pricing, API compatibility, security controls and change notices.\"},\"tunes\":{}},{\"id\":\"p-provider-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"This means provider selection is not only a benchmark decision. Procurement, security, privacy, legal review, continuity planning and exit strategy can all become architecture inputs.\"},\"tunes\":{}},{\"id\":\"p-provider-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction can reduce coupling, but only where the underlying capabilities are genuinely portable. Tool use, structured output, context limits, multimodality, safety controls, fine-tuning and hosted-agent features may differ materially between providers.\"},\"tunes\":{}},{\"id\":\"h-risk\",\"type\":\"header\",\"data\":{\"text\":\"6. AI risk becomes a lifecycle process\",\"level\":3},\"tunes\":{}},{\"id\":\"p-risk-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI risk is not completed by one approval before launch. The model, prompt, retrieval corpus, tool set, provider, user population and surrounding business process can all change after deployment. The risk profile changes with them.\"},\"tunes\":{}},{\"id\":\"p-risk-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"ISO\u002FIEC 23894:2023 explicitly addresses integration of AI risk management into organizational activities and functions. NIST AI RMF similarly frames risk management across the lifecycle. Enterprise architecture should therefore make risk review part of change and operations rather than an isolated compliance document.\"},\"tunes\":{}},{\"id\":\"p-risk-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Risk should also be proportional. A summarization assistant and an autonomous system that changes production records should not receive identical controls merely because both use an LLM.\"},\"tunes\":{}},{\"id\":\"h-management-system\",\"type\":\"header\",\"data\":{\"text\":\"7. Governance becomes an operating system, not a policy PDF\",\"level\":3},\"tunes\":{}},{\"id\":\"p-management-system-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"ISO\u002FIEC 42001:2023 defines requirements for establishing, implementing, maintaining and continually improving an AI management system. The architecture consequence is important: governance must connect policy to real inventories, ownership, processes, controls, evidence, reviews and improvement loops.\"},\"tunes\":{}},{\"id\":\"p-management-system-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An enterprise AI policy that is not connected to provider approval, identity, logging, change management, evaluation and incident response has limited architectural effect. The organization needs mechanisms that make policy enforceable or at least observable.\"},\"tunes\":{}},{\"id\":\"h-eval\",\"type\":\"header\",\"data\":{\"text\":\"8. Evaluation becomes a production control\",\"level\":3},\"tunes\":{}},{\"id\":\"p-eval-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Traditional acceptance testing assumes that the same input normally produces the same deterministic result. Generative AI can be nondeterministic, sensitive to context and dependent on changing external knowledge. Production acceptance therefore needs task-specific evals, regression suites and observable thresholds rather than only unit tests.\"},\"tunes\":{}},{\"id\":\"p-eval-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The platform can provide reusable evaluation infrastructure, but the enterprise still needs ownership of domain ground truth and release gates. A central AI team cannot invent the correct answer for every business domain.\"},\"tunes\":{}},{\"id\":\"p-eval-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model, prompt, retrieval and tool changes should be traceable to evaluation evidence where the change can materially affect output behavior.\"},\"tunes\":{}},{\"id\":\"h-observability\",\"type\":\"header\",\"data\":{\"text\":\"9. Observability must include behavior, data and model context\",\"level\":3},\"tunes\":{}},{\"id\":\"p-observability-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"CPU, memory and HTTP error rates are not sufficient for AI workloads. Production observability may need model\u002Fprovider identifiers, latency, token usage, cost, retrieval results, tool calls, refusal behavior, evaluation scores, safety events and failure classifications.\"},\"tunes\":{}},{\"id\":\"p-observability-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"At the same time, AI telemetry can contain sensitive data. Prompt and response logs may become a shadow data store. Enterprise architecture must therefore define what can be logged, how it is redacted, who can access it, how long it is retained and when detailed tracing must be disabled.\"},\"tunes\":{}},{\"id\":\"h-lifecycle\",\"type\":\"header\",\"data\":{\"text\":\"10. AI components need explicit lifecycle ownership\",\"level\":3},\"tunes\":{}},{\"id\":\"p-lifecycle-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Models can be renamed, replaced, retired or changed by providers. Embedding models can invalidate an index strategy. Prompt templates and system instructions can change behavior. Agent runtimes and protocols can evolve. External tools can change their schemas and permissions.\"},\"tunes\":{}},{\"id\":\"p-lifecycle-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise architecture must decide who detects these changes, who tests them, who approves them, how consumers are notified, how rollback works and what evidence is required before a new version becomes the default.\"},\"tunes\":{}},{\"id\":\"h-operations\",\"type\":\"header\",\"data\":{\"text\":\"11. Incident response must include AI-specific failure modes\",\"level\":3},\"tunes\":{}},{\"id\":\"p-operations-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI incident may be a provider outage, data leak, prompt-injection path, authorization failure, retrieval contamination, unexpected model behavior, unsafe tool execution, cost spike, stale knowledge, evaluation regression or a change in external model behavior.\"},\"tunes\":{}},{\"id\":\"p-operations-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise runbook therefore needs more than “restart the service.” It may require disabling a model route, revoking tool access, freezing a corpus, changing a prompt version, disabling an agent capability, switching provider, escalating to a domain owner or preserving traces for investigation.\"},\"tunes\":{}},{\"id\":\"h-ownership\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI creates cross-functional ownership\",\"level\":2},\"tunes\":{}},{\"id\":\"ownership-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Concern\",\"Typical enterprise owner or contributor\",\"Architecture question\"],[\"Business use\",\"Business owner \u002F product owner\",\"What decision or workflow is AI allowed to support or automate?\"],[\"Solution architecture\",\"AI \u002F solution architect\",\"How does the concrete workload meet its functional and quality requirements?\"],[\"Shared AI capabilities\",\"AI platform \u002F platform engineering\",\"Which reusable model, retrieval, agent and observability services are provided?\"],[\"Enterprise coherence\",\"Enterprise architecture\",\"How do AI systems fit target architecture, standards, integration patterns and organizational ownership?\"],[\"Data authority\",\"Data owner \u002F domain owner\",\"Which data is authoritative, current, permitted and sufficiently governed?\"],[\"Identity and security\",\"IAM \u002F security architecture\",\"Which identities can access which data and execute which actions?\"],[\"Risk and compliance\",\"Risk \u002F legal \u002F compliance \u002F privacy\",\"Which obligations, prohibited uses, controls and evidence apply to this use case?\"],[\"Supplier dependency\",\"Procurement \u002F vendor management \u002F architecture\",\"What contractual, operational and exit risks arise from the provider?\"],[\"Operations\",\"SRE \u002F operations \u002F platform owner\",\"How is the system monitored, supported, degraded, recovered and changed?\"],[\"Domain acceptance\",\"Business\u002Fdomain specialists\",\"What counts as a correct, safe or useful result in this domain?\"]]},\"tunes\":{}},{\"id\":\"ownership-warning\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"A RACI chart is not architecture by itself\",\"body\":\"Responsibility matrices are useful only when they connect to real system boundaries, approvals, data ownership, interfaces, runbooks and change processes. Enterprise AI needs accountable ownership that can be traced to technical controls and operational actions.\"},\"tunes\":{}},{\"id\":\"h-model\",\"type\":\"header\",\"data\":{\"text\":\"A practical enterprise AI architecture model\",\"level\":2},\"tunes\":{}},{\"id\":\"model-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Proposed layered model\",\"body\":\"The following model is a practical synthesis for reasoning about enterprise AI architecture. It is not presented as an ISO or NIST standard. Its purpose is to make cross-organizational boundaries explicit.\"},\"tunes\":{}},{\"id\":\"enterprise-model-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"Primary responsibility\"],[\"Business and policy\",\"Approved use cases, accountable owners, risk appetite, prohibited uses, human accountability, business acceptance.\"],[\"Identity and authority\",\"User\u002Fservice\u002Fagent identities, roles, tenant or organizational scope, privileged actions, approval paths.\"],[\"Enterprise data\",\"Systems of record, document sources, data products, provenance, classification, retention, freshness and access.\"],[\"AI platform\",\"Provider\u002Fmodel access, retrieval primitives, agent runtimes, tool brokers, evaluation infrastructure, observability, quotas and secrets.\"],[\"AI solutions\",\"Domain workflows, prompts\u002Finstructions, domain retrieval, business logic, acceptance criteria and user experience.\"],[\"Integration and tools\",\"APIs, enterprise applications, workflows, messaging, file systems, external services and action execution.\"],[\"Risk and governance\",\"Inventory, assessment, compliance evidence, exception management, model\u002Fprovider approval, review and audit.\"],[\"Operations and lifecycle\",\"Deployment, monitoring, incidents, releases, model\u002Fprovider changes, deprecation, rollback and continuity.\"]]},\"tunes\":{}},{\"id\":\"p-model-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture is strongest when each layer can state both its responsibilities and its non-responsibilities. For example, the AI platform can enforce provider policy and collect traces without becoming the source of truth for HR data. A solution can define domain prompts without owning enterprise IAM. A business owner can approve a use case without being expected to operate the inference gateway.\"},\"tunes\":{}},{\"id\":\"h-data-flow\",\"type\":\"header\",\"data\":{\"text\":\"Map enterprise AI as data and authority flows, not boxes\",\"level\":2},\"tunes\":{}},{\"id\":\"enterprise-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A consequential enterprise AI request\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Business context\",\"description\":\"The user requests a task under an approved use case with an accountable business owner.\"},{\"label\":\"2. Identity and authorization\",\"description\":\"The system resolves user, application, service and tenant or organizational scope before privileged access.\"},{\"label\":\"3. Authoritative data acquisition\",\"description\":\"The solution reads or retrieves only sources permitted for the current identity and task.\"},{\"label\":\"4. AI processing\",\"description\":\"An approved model\u002Fprovider processes the minimum necessary context under defined routing and data-handling rules.\"},{\"label\":\"5. Tool or action boundary\",\"description\":\"Any state-changing action is independently authorized and may require human approval according to consequence.\"},{\"label\":\"6. Validation\",\"description\":\"The result is checked against solution-specific acceptance, evidence or safety rules.\"},{\"label\":\"7. Audit and observability\",\"description\":\"Permitted metadata, decisions, routes, tool calls and outcomes are recorded without creating uncontrolled sensitive-data logs.\"},{\"label\":\"8. Feedback and lifecycle\",\"description\":\"Failures and evaluation results feed model, prompt, data, policy and process changes through controlled change management.\"}]},\"tunes\":{}},{\"id\":\"h-inventory\",\"type\":\"header\",\"data\":{\"text\":\"An enterprise needs an AI inventory before it can govern AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-inventory-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Organizations cannot manage AI systems they cannot identify. Enterprise architecture should maintain an inventory at a level that is useful for decisions, not merely a list of model names.\"},\"tunes\":{}},{\"id\":\"inventory-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Inventory field\",\"Why it matters\"],[\"Use case and owner\",\"Connects technology to accountable business purpose.\"],[\"Users and affected parties\",\"Defines who interacts with or is affected by the system.\"],[\"Model\u002Fprovider\",\"Identifies external dependency, capability and lifecycle risk.\"],[\"Data sources\",\"Supports authority, privacy, classification and provenance review.\"],[\"Deployment\u002Fruntime location\",\"Clarifies processing location, connectivity and operational control.\"],[\"Tools\u002Factions\",\"Shows whether the AI can change external state and at what consequence.\"],[\"Human oversight\",\"Records where review, approval or escalation is required.\"],[\"Risk\u002Fclassification\",\"Connects the system to organizational and regulatory controls.\"],[\"Evaluation evidence\",\"Shows what was tested and under which validity conditions.\"],[\"Current version\",\"Allows incidents and regressions to be traced to actual deployed state.\"],[\"Lifecycle state\",\"Proposed, experimental, approved, production, restricted, deprecated or retired.\"]]},\"tunes\":{}},{\"id\":\"h-governance\",\"type\":\"header\",\"data\":{\"text\":\"AI governance and enterprise AI architecture are related but not the same\",\"level\":2},\"tunes\":{}},{\"id\":\"governance-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Governance versus architecture\",\"layout\":\"table\",\"columns\":[{\"id\":\"governance\",\"label\":\"AI Governance\"},{\"id\":\"architecture\",\"label\":\"Enterprise AI Architecture\"}],\"rows\":[{\"id\":\"purpose\",\"label\":\"Purpose\",\"values\":[\"\",\"\"]},{\"id\":\"example\",\"label\":\"Example\",\"values\":[\"\",\"\"]},{\"id\":\"failure\",\"label\":\"Failure if isolated\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"h-regulation\",\"type\":\"header\",\"data\":{\"text\":\"Regulation becomes an architecture input\",\"level\":2},\"tunes\":{}},{\"id\":\"p-regulation-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"For organizations operating in the European Union, the AI Act can create requirements that affect system design, documentation, transparency, governance and operating processes. The architectural impact depends on the organization's role in the AI value chain and the concrete system classification; not every AI system has the same obligations.\"},\"tunes\":{}},{\"id\":\"p-regulation-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"As of 8 October 2026, the current consolidated text states that the Regulation generally applies from 2 August 2026. Governance rules and obligations for general-purpose AI models began applying earlier, while specified high-risk system provisions have later dates. The Commission also began enforcing new transparency requirements from 2 August 2026 for relevant interactive and synthetic-content systems.\"},\"tunes\":{}},{\"id\":\"p-regulation-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The enterprise architecture lesson is not “put compliance in the model.” It is to make classification, provider\u002Fdeployer role, documentation, transparency, oversight, logging and change evidence traceable to the system that actually implements the use case.\"},\"tunes\":{}},{\"id\":\"legal-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Legal scope is use-case specific\",\"body\":\"This article describes architecture implications, not legal advice. Enterprise AI architecture should preserve the information needed for legal and compliance specialists to classify the actual system and map obligations to concrete controls. Architecture should not hard-code one regulatory interpretation as if every AI workload had the same status.\"},\"tunes\":{}},{\"id\":\"h-procurement\",\"type\":\"header\",\"data\":{\"text\":\"Procurement and architecture become connected\",\"level\":2},\"tunes\":{}},{\"id\":\"p-procurement-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An external model or managed AI platform can become a deep dependency even when integration requires only a few API calls. Enterprise architecture should therefore make procurement questions technically concrete.\"},\"tunes\":{}},{\"id\":\"procurement-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Procurement question\",\"Architecture consequence\"],[\"Where is data processed?\",\"Region, network path, data residency and transfer controls.\"],[\"Is customer data retained or used for provider improvement?\",\"Data minimization, contractual controls and provider eligibility.\"],[\"How are models versioned or retired?\",\"Regression testing, compatibility, fallback and lifecycle planning.\"],[\"What are quotas and service limits?\",\"Capacity architecture, admission control and failure handling.\"],[\"How portable is the integration?\",\"Provider abstraction, exit cost and migration effort.\"],[\"What incident information is available?\",\"Observability, forensic capability and support escalation.\"],[\"Which subprocessors or external services are involved?\",\"Dependency mapping and risk assessment.\"],[\"What changes without explicit customer approval?\",\"Change detection, release gates and acceptance strategy.\"]]},\"tunes\":{}},{\"id\":\"h-control\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise architecture decides how much AI control the requirement actually needs\",\"level\":2},\"tunes\":{}},{\"id\":\"control-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Requirement\",\"Possible architectural response\"],[\"Fast access to managed models\",\"Managed provider with enterprise identity, gateway controls and contractual review.\"],[\"Private data with managed orchestration\",\"Managed control plane plus customer-controlled execution or private data plane where supported.\"],[\"Strict locality or sovereignty\",\"Region-restricted, sovereign, private or self-hosted architecture according to the real requirement.\"],[\"Air-gapped environment\",\"Locally hosted models, local retrieval, local tooling, offline update\u002Fdistribution and isolated observability.\"],[\"Provider portability\",\"Application-owned domain state plus adapters and contracts that isolate provider-specific behavior where practical.\"],[\"Highest control of agent semantics\",\"Self-managed or deeply controlled runtime with explicit tool, context, state and lifecycle ownership.\"]]},\"tunes\":{}},{\"id\":\"p-control-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The most controlled architecture is not automatically the best enterprise architecture. More ownership increases responsibility for patching, capacity, security, testing, model operations and incident response. Enterprise architecture should escalate control only where the requirement justifies the additional operational burden.\"},\"tunes\":{}},{\"id\":\"h-change-management\",\"type\":\"header\",\"data\":{\"text\":\"AI turns change management into a behavioral problem\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A normal dependency update can alter performance or compatibility. An AI change can also alter behavior. Replacing a model, changing a system prompt, changing retrieval, adding a tool or changing the context policy can modify how the system interprets and responds even if the surrounding application code barely changes.\"},\"tunes\":{}},{\"id\":\"change-process\",\"type\":\"processFlow\",\"data\":{\"title\":\"A production AI change path\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Change identified\",\"description\":\"Model, provider, prompt, retrieval source, tool, policy or runtime change is proposed or detected.\"},{\"label\":\"2. Impact mapped\",\"description\":\"Affected solutions, data classes, users, risk controls, cost, contracts and operational dependencies are identified.\"},{\"label\":\"3. Architecture decision updated\",\"description\":\"Material choices and trade-offs are recorded; superseded decisions remain historically traceable.\"},{\"label\":\"4. Evaluation executed\",\"description\":\"Relevant regression, safety, retrieval, latency, cost and domain tests are run.\"},{\"label\":\"5. Approval applied\",\"description\":\"Approval level follows consequence, risk and organizational policy.\"},{\"label\":\"6. Controlled rollout\",\"description\":\"Versioned release, canary or staged deployment is used where appropriate.\"},{\"label\":\"7. Production evidence collected\",\"description\":\"Telemetry, incidents, feedback and domain outcomes are monitored.\"},{\"label\":\"8. Rollback or acceptance\",\"description\":\"The change is accepted, restricted, rolled back or superseded based on evidence.\"}]},\"tunes\":{}},{\"id\":\"h-nfr-adr\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI still needs NFRs and ADRs\",\"level\":2},\"tunes\":{}},{\"id\":\"p-nfr-adr-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI does not replace ordinary architecture discipline. Non-functional requirements remain the target conditions: availability, latency, privacy, isolation, auditability, recoverability, cost boundaries, explainability or other quality requirements. Architecture Decision Records preserve the chosen response and its trade-offs.\"},\"tunes\":{}},{\"id\":\"p-nfr-adr-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The AI-specific difference is that some quality attributes must be evaluated probabilistically or empirically. “Answers must be useful” is too vague. A production requirement should identify the task, data, user population, acceptable failure conditions, measurement method and threshold where practical.\"},\"tunes\":{}},{\"id\":\"nfr-adr-chain\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Enterprise traceability chain\",\"body\":\"\u003Cstrong>Business need → requirement \u002F NFR → architecture decision → implementation → evaluation \u002F validation → production observation → change decision.\u003C\u002Fstrong> AI adds new variables to this chain; it does not make the chain unnecessary.\"},\"tunes\":{}},{\"id\":\"h-delivery\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI architecture must connect to delivery\",\"level\":2},\"tunes\":{}},{\"id\":\"p-delivery-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Architecture that never reaches backlog, implementation, acceptance and operations remains conceptual. Enterprise AI therefore needs traceability from architecture decisions into delivery work and back from implementation evidence into architecture.\"},\"tunes\":{}},{\"id\":\"p-delivery-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Jira and Confluence are examples of tools that can support this separation when used deliberately: Confluence can preserve requirements, architecture, decisions, risks and rationale; Jira can manage actionable delivery work and state. The important principle is the traceability, not the brand of tool.\"},\"tunes\":{}},{\"id\":\"h-original\",\"type\":\"header\",\"data\":{\"text\":\"Original project evidence: Enterprise Aaasaasa 0.1\",\"level\":2},\"tunes\":{}},{\"id\":\"original-evidence-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Project evidence, not market-proof claim\",\"body\":\"Enterprise Aaasaasa 0.1 is used here as original project evidence for structured enterprise architecture and delivery thinking. It is a PoC \u002F enterprise project context, not evidence of mass customer adoption, enterprise-scale production usage or commercial traction.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise Aaasaasa 0.1 combines platform architecture, SaaS\u002FAPI concepts, internationalization, AI integration and structured project governance. The project was deliberately organized so that requirements, architecture, prototype delivery, validation and closure were separate milestones rather than one undifferentiated implementation phase.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture direction includes multi-instance \u002F multi-database concepts together with API, CRUD, i18n and AI capabilities. That matters for enterprise AI because tenant or instance boundaries, database ownership and application services must remain explicit when AI features are added.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The project structure also treated architecture delay, scope creep and AI\u002Fdata-protection concerns as project risks rather than discovering them only during implementation. Stakeholders included technical, security, sponsor\u002Fsteering and external-service perspectives, which is closer to the real cross-functional nature of enterprise AI than a model-only prototype.\"},\"tunes\":{}},{\"id\":\"p-enterprise-aaasaasa-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"The useful evidence is therefore the integration of architecture and delivery: business and project structure, milestones, risks, architecture, backend\u002FAPI, frontend\u002FAI work, validation and closure are treated as connected responsibilities. That pattern is reusable even though the project itself should not be presented as proof of external enterprise adoption.\"},\"tunes\":{}},{\"id\":\"enterprise-aaasaasa-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Project element\",\"Enterprise AI architecture lesson\"],[\"Requirements milestone\",\"AI capability must begin from defined need, scope, acceptance and quality constraints.\"],[\"Architecture milestone\",\"Data, API, instance\u002Fdatabase boundaries and AI integration are explicit design work.\"],[\"Prototype milestone\",\"Architecture must become executable enough to expose integration risks.\"],[\"Validation milestone\",\"A functioning prototype is not the same as validated acceptance.\"],[\"Risk register\",\"Scope, architecture delay and AI\u002Fdata-protection concerns are managed as delivery risks.\"],[\"Stakeholder structure\",\"Enterprise AI spans sponsor\u002Fbusiness, architecture, security, external providers and delivery.\"],[\"Project closure\",\"Decisions, remaining risks and validation evidence must survive beyond the implementation sprint.\"]]},\"tunes\":{}},{\"id\":\"h-supporting\",\"type\":\"header\",\"data\":{\"text\":\"Supporting implementation patterns from the wider platform work\",\"level\":2},\"tunes\":{}},{\"id\":\"p-supporting-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Separate implementation work in the wider Aaasaasa platform provides concrete examples of boundaries that enterprise AI architecture must preserve: tenant-scoped RBAC in the CMS, explicit provider\u002Fmodel\u002Fruntime\u002Fpermission separation in Aaasaasa AI Client, and provenance-first retrieval in the Source of Truth Research Engine.\"},\"tunes\":{}},{\"id\":\"p-supporting-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"These projects should not be collapsed into one claimed production platform. Their value here is narrower: they demonstrate implemented patterns for identity scope, provider boundaries, controlled runtime permissions, retrieval provenance and evidence traceability that are directly relevant to enterprise AI.\"},\"tunes\":{}},{\"id\":\"h-standards\",\"type\":\"header\",\"data\":{\"text\":\"How the main standards fit together\",\"level\":2},\"tunes\":{}},{\"id\":\"standards-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Source\",\"What it contributes to enterprise AI architecture\"],[\"ISO\u002FIEC 42001:2023\",\"Organization-level AI management system: policies, objectives, processes, responsibility, monitoring and continual improvement.\"],[\"ISO\u002FIEC 23894:2023\",\"Guidance for integrating AI-specific risk management into organizational activities and functions.\"],[\"NIST AI RMF 1.0\",\"Voluntary lifecycle-oriented framework for managing AI risks; organized around Govern, Map, Measure and Manage.\"],[\"NIST AI 600-1\",\"Generative AI profile extending AI RMF with generative-AI-specific risks and actions.\"],[\"EU AI Act\",\"Binding regulatory obligations in the EU whose applicability depends on role, system type and classification.\"],[\"ISO\u002FIEC\u002FIEEE 42010:2022\",\"General architecture-description concepts for expressing concerns, viewpoints, decisions and relationships.\"]]},\"tunes\":{}},{\"id\":\"p-standards-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"These sources solve different problems. ISO\u002FIEC 42001 is not a replacement for technical architecture. ISO\u002FIEC 23894 and NIST AI RMF do not define one mandatory software stack. The EU AI Act is law, not a platform design pattern. Architecture must translate the applicable organizational, risk and legal requirements into implementable system boundaries and evidence.\"},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common enterprise AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failures-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"Why it fails\"],[\"Every team buys AI independently\",\"Creates shadow providers, duplicated secrets, inconsistent data handling and weak leverage over supplier risk.\"],[\"One central AI team owns every domain decision\",\"Centralizes technical control but loses domain accountability and creates a bottleneck.\"],[\"Vector database becomes the source of truth\",\"Retrieval infrastructure silently replaces authoritative systems and freshness rules.\"],[\"One shared API key for all users and agents\",\"Destroys attribution, least privilege and meaningful auditability.\"],[\"Model change deployed like a minor library patch\",\"Behavioral regressions can reach production without domain evaluation.\"],[\"All prompts and outputs are logged forever\",\"Observability creates an uncontrolled sensitive-data repository.\"],[\"Governance is only documentation\",\"Policies exist without enforcement points, evidence or operational ownership.\"],[\"Compliance is delegated to the provider\",\"The organization's own role, use case, data and operational obligations remain unresolved.\"],[\"Agent can call tools because the model supports tool use\",\"Capability is mistaken for authorization.\"],[\"Platform health equals business correctness\",\"Endpoint uptime and model availability do not prove domain answer quality or acceptable outcomes.\"],[\"No exit strategy for model\u002Fprovider dependency\",\"A pricing, policy, capability or availability change becomes an emergency migration.\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Better model\"],[\"“Enterprise AI means a company-wide chatbot.”\",\"The chatbot is one interface; enterprise AI architecture governs the underlying data, identity, provider, runtime, risk and operations.\"],[\"“If we use a reputable model provider, governance is solved.”\",\"Provider controls do not define your use case, data authority, user permissions, business acceptance or legal role.\"],[\"“Private AI means everything must be self-hosted.”\",\"Privacy requirements can lead to several architectures; the required control boundary must be stated precisely.\"],[\"“AI governance belongs to legal, architecture belongs to IT.”\",\"The two disciplines must connect because policy obligations need implementable controls and evidence.\"],[\"“One enterprise model is simpler.”\",\"Standardization can help, but workloads can require different modalities, regions, costs, quality levels or control models.\"],[\"“AI risk is model risk.”\",\"Risk can originate in data, prompts, retrieval, identity, tools, interfaces, operations, users and organizational process.\"],[\"“Human-in-the-loop makes an agent safe.”\",\"Human approval helps only if the reviewer has useful context, authority, time and a clear decision point.\"],[\"“A successful pilot proves enterprise readiness.”\",\"A pilot proves bounded capability; enterprise readiness also requires integration, governance, lifecycle, operations and repeatable controls.\"]]},\"tunes\":{}},{\"id\":\"h-framework\",\"type\":\"header\",\"data\":{\"text\":\"A practical enterprise AI architecture decision sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"decision-framework\",\"type\":\"processFlow\",\"data\":{\"title\":\"From opportunity to governed enterprise capability\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define the business capability\",\"description\":\"State the user, decision or workflow, expected value and accountable owner.\"},{\"label\":\"2. Classify data and authority\",\"description\":\"Identify systems of record, personal\u002Fconfidential data, retention, freshness and provenance requirements.\"},{\"label\":\"3. Define identity and action boundaries\",\"description\":\"Determine who may read, generate, decide, approve and change external systems.\"},{\"label\":\"4. Select solution and platform responsibilities\",\"description\":\"Decide what belongs to the workload, what can be shared and what remains enterprise-owned.\"},{\"label\":\"5. Assess provider and runtime dependency\",\"description\":\"Evaluate managed, self-hosted, private, sovereign or hybrid options against real requirements.\"},{\"label\":\"6. Map risk and regulatory obligations\",\"description\":\"Determine risk level, organizational controls and applicable legal responsibilities for the concrete system.\"},{\"label\":\"7. Define measurable acceptance\",\"description\":\"Create evaluation criteria for quality, reliability, safety, retrieval, cost and operational behavior.\"},{\"label\":\"8. Record architecture decisions\",\"description\":\"Preserve rationale, alternatives, trade-offs, dependencies and conditions that would trigger reconsideration.\"},{\"label\":\"9. Connect architecture to delivery\",\"description\":\"Translate the design into backlog, milestones, acceptance criteria, technical work and ownership.\"},{\"label\":\"10. Validate in production-shaped conditions\",\"description\":\"Test realistic identity, data, failure, latency, provider, tool and recovery scenarios rather than only clean demos.\"},{\"label\":\"11. Establish operations and change control\",\"description\":\"Define monitoring, incident response, model\u002Fprovider updates, regression testing, rollback and retirement.\"},{\"label\":\"12. Feed evidence back into architecture\",\"description\":\"Use production observations, audits, incidents and evaluations to revise decisions and controls.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Enterprise AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"What business capability does this AI support?\",\"Named owner, user group, intended decision\u002Fworkflow and acceptance objective.\"],[\"Which source is authoritative for each important fact?\",\"Systems of record, document authority, provenance and freshness rules.\"],[\"Which identities exist?\",\"Human, application, service, agent, tenant\u002Forg and provider identities are distinguishable.\"],[\"What can the AI read?\",\"Authorization-scoped data sources and explicit sensitive-data rules.\"],[\"What can the AI change?\",\"Tool\u002Faction inventory, permission model, approval and rollback path.\"],[\"Which provider\u002Fmodel is used and why?\",\"Architecture decision including quality, security, cost, region, lifecycle and exit considerations.\"],[\"What happens if the provider is unavailable?\",\"Degraded mode, fallback, refusal or continuity plan.\"],[\"How is quality evaluated?\",\"Task-specific datasets, graders, thresholds, regression criteria and validity conditions.\"],[\"What is logged?\",\"Telemetry schema, redaction, access, retention and audit purpose.\"],[\"Who owns AI risk?\",\"Named organizational responsibility connected to the concrete system.\"],[\"What legal classification applies?\",\"Documented assessment based on the current law and the actual use case.\"],[\"How are model\u002Fprompt\u002Fretrieval changes approved?\",\"Versioning, evaluation, architecture\u002Fchange record and rollout gate.\"],[\"Who responds to an AI incident?\",\"Runbook, technical owner, business\u002Fdomain escalation and provider escalation.\"],[\"How is the system retired?\",\"Data cleanup, access revocation, provider exit, evidence retention and dependency removal.\"]]},\"tunes\":{}},{\"id\":\"h-edge\",\"type\":\"header\",\"data\":{\"text\":\"Edge cases and limits\",\"level\":2},\"tunes\":{}},{\"id\":\"p-edge-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A small company with one low-risk AI use case may not need a formal enterprise AI architecture function. The same principles can be applied lightly: clear owner, approved data, explicit provider, basic evaluation, access control and operational responsibility.\"},\"tunes\":{}},{\"id\":\"p-edge-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A highly regulated organization may need stronger separation, independent validation, formal conformity processes, local hosting or air-gapped operation. Those controls are driven by the use case and regulatory environment, not by the word “enterprise.”\"},\"tunes\":{}},{\"id\":\"p-edge-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An organization can also use mostly SaaS AI products rather than building AI systems. Enterprise architecture still matters because identity, data access, contractual terms, shadow AI, retention, audit and supplier concentration remain organizational concerns.\"},\"tunes\":{}},{\"id\":\"p-edge-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"A centralized platform is not mandatory. Federated platform ownership can be valid when domains have materially different requirements, provided enterprise-level identity, risk, inventory and interoperability responsibilities remain coherent.\"},\"tunes\":{}},{\"id\":\"h-change-answer\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-answer-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture changes when the organization's risk tolerance, regulatory classification, data sensitivity, geographic scope, provider strategy, internal skills or business criticality changes. A public marketing assistant and a system participating in employment, finance, healthcare or critical infrastructure decisions should not inherit identical control models.\"},\"tunes\":{}},{\"id\":\"p-change-answer-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The implementation also changes as standards, regulation and AI platforms evolve. NIST AI RMF 1.0 is currently under revision, the EU AI Act has phased application dates, and model\u002Fprovider capabilities continue to change rapidly. Enterprise architecture should therefore preserve stable responsibility boundaries while treating provider mechanisms and regulatory details as versioned inputs.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI architecture builds on solution and platform architecture. The solution layer explains one workload. The platform layer explains reusable AI capabilities. The enterprise layer connects both to organization-wide data, identity, governance, risk, procurement and operations.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Retrieval-Augmented Generation is only one mechanism inside this architecture. RAG can improve access to enterprise knowledge, but it does not solve data authority, permissions, governance or answer validity by itself.\"},\"tunes\":{}},{\"id\":\"ref-rag\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\",\"title\":\"What Is RAG? The Simplest Explanation of How It Works\",\"excerpt\":\"A plain-English explanation of how external knowledge retrieval connects to the language model without turning retrieval into the source of truth.\",\"ctaLabel\":\"Read the RAG foundation\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For evidence-heavy enterprise use cases, answer validity also needs an explicit boundary: an output is only supported under the evidence, version, scope and assumptions that produced it.\"},\"tunes\":{}},{\"id\":\"ref-avb\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\",\"title\":\"The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers\",\"excerpt\":\"A framework for making explicit the conditions under which an AI claim remains supported and what changes require restriction or recalculation.\",\"ctaLabel\":\"Read the Answer Validity Boundary\"},\"tunes\":{}},{\"id\":\"p-related-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"Downstream enterprise topics include AI Governance, Private AI, Sovereign AI, Air-Gapped AI, Multi-Tenant AI Architecture, RBAC versus Tenant Isolation, Provider Abstraction, Model Routing and Production AI Architecture.\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Enterprise AI architecture FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is enterprise AI architecture?\",\"answer\":\"Enterprise AI architecture is the organization-wide architecture that defines how AI solutions and shared AI capabilities integrate with business ownership, enterprise data, identity, security, providers, governance, risk, compliance, lifecycle and operations.\"},{\"id\":\"faq2\",\"question\":\"Is enterprise AI architecture the same as an AI platform?\",\"answer\":\"No. An AI platform provides reusable technical capabilities such as model access, retrieval, agent runtimes and observability. Enterprise AI architecture defines how that platform and individual AI solutions fit into the organization's wider architecture and operating model.\"},{\"id\":\"faq3\",\"question\":\"Does enterprise AI require one central model?\",\"answer\":\"No. Standardization can reduce complexity, but different workloads may require different providers, models, regions, control levels or modalities. The important requirement is explicit policy and lifecycle ownership.\"},{\"id\":\"faq4\",\"question\":\"Why is data authority important for enterprise AI?\",\"answer\":\"Because retrieved or generated information is not automatically authoritative. Enterprise systems need to preserve which source is the system of record, whether data is current, who may access it and how a generated claim can be traced back to evidence.\"},{\"id\":\"faq5\",\"question\":\"What is the difference between AI governance and enterprise AI architecture?\",\"answer\":\"AI governance defines policies, accountability and decision rights. Enterprise AI architecture defines the system boundaries, interfaces, data flows and technical mechanisms through which those policies can be implemented and evidenced.\"},{\"id\":\"faq6\",\"question\":\"Does the EU AI Act apply to every enterprise AI system in the same way?\",\"answer\":\"No. Obligations depend on factors such as the organization's role, the system's use case and classification, and the relevant provisions in force. Legal classification must be performed for the concrete system under the current law.\"},{\"id\":\"faq7\",\"question\":\"Is a successful AI pilot enough for enterprise deployment?\",\"answer\":\"No. A pilot demonstrates bounded capability. Enterprise deployment also needs identity, data authority, security, provider governance, evaluation, lifecycle, incident response, monitoring, compliance and accountable operational ownership.\"},{\"id\":\"faq8\",\"question\":\"Should enterprises self-host AI?\",\"answer\":\"Only when the requirement justifies the added control and operational responsibility. Managed, private, sovereign, self-hosted and hybrid approaches are architecture options whose fit depends on data, regulatory, availability, cost, capability and operational requirements.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key enterprise AI architecture terms\",\"entries\":[{\"term\":\"Enterprise AI architecture\",\"definition\":\"Organization-wide architecture governing how AI systems, platforms, data, identities, providers, risk controls and operations fit together.\",\"anchor\":\"enterprise-ai-architecture\"},{\"term\":\"AI management system\",\"definition\":\"An organizational management system for establishing AI-related policies, objectives and processes; ISO\u002FIEC 42001 specifies requirements for such a system.\",\"anchor\":\"ai-management-system\"},{\"term\":\"Data authority\",\"definition\":\"The rule that identifies which source or system is authoritative for a particular fact, record, state or decision context.\",\"anchor\":\"data-authority\"},{\"term\":\"System of record\",\"definition\":\"The authoritative system responsible for the official current state of a business record or domain entity.\",\"anchor\":\"system-of-record\"},{\"term\":\"AI inventory\",\"definition\":\"A structured record of AI use cases, owners, models\u002Fproviders, data, tools, risk, evaluation evidence, lifecycle state and related controls.\",\"anchor\":\"ai-inventory\"},{\"term\":\"Provider dependency\",\"definition\":\"The technical, contractual and operational reliance created when an AI workload depends on an external model or managed platform.\",\"anchor\":\"provider-dependency\"},{\"term\":\"Human oversight\",\"definition\":\"Defined human review, approval, intervention or escalation applied where system consequence, uncertainty or regulation requires it.\",\"anchor\":\"human-oversight\"},{\"term\":\"GenAIOps\",\"definition\":\"Operational practices for generative-AI workloads covering model selection, prompts, grounding data, evaluation, deployment, monitoring and lifecycle management.\",\"anchor\":\"genaiops\"},{\"term\":\"AI risk management\",\"definition\":\"The organizational process of identifying, assessing, treating, monitoring and revising risks associated with AI systems across their lifecycle.\",\"anchor\":\"ai-risk-management\"},{\"term\":\"Architecture decision\",\"definition\":\"A material design choice together with its context, rationale, alternatives, trade-offs and lifecycle status.\",\"anchor\":\"architecture-decision\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"When AI enters a company, the enterprise does not merely gain a new software component. It gains a new class of behavior and dependency that cuts across data, identity, suppliers, business decisions, security, operations, governance and change management.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architectural response is not to centralize everything. It is to make responsibilities explicit: which data is authoritative, which identities may act, which providers are approved, which controls are shared, which decisions remain domain-owned, how behavior is evaluated, how incidents are handled and how the system changes over time.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That is the core distinction of enterprise AI architecture: it turns isolated AI capability into an organizationally governable system without pretending that models, platforms, business domains and enterprise controls are the same thing.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current guidance\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"External standards, regulation and current vendor architecture guidance below were checked on 8 October 2026. Project-specific sections are explicitly marked as original project evidence and should not be read as claims of general industry fact.\"},\"tunes\":{}},{\"id\":\"src-iso-42001\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC 42001:2023 — Artificial intelligence management system\",\"description\":\"International standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system within organizations.\"}},\"tunes\":{}},{\"id\":\"src-iso-23894\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F77304.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC 23894:2023 — Guidance on AI risk management\",\"description\":\"International guidance for integrating AI-specific risk management into organizational activities and functions.\"}},\"tunes\":{}},{\"id\":\"src-nist-rmf\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI Risk Management Framework\",\"description\":\"NIST's voluntary lifecycle-oriented framework for managing AI risk. NIST states that AI RMF 1.0 is currently being revised.\"}},\"tunes\":{}},{\"id\":\"src-nist-genai\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI 600-1 — Generative AI Profile\",\"description\":\"NIST companion profile describing generative-AI-specific risks and risk-management actions aligned to the AI RMF.\"}},\"tunes\":{}},{\"id\":\"src-eu-consolidated\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002F2026-07-27\u002Feng\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"EUR-Lex — Regulation (EU) 2024\u002F1689, consolidated text\",\"description\":\"Current consolidated AI Act text used for application dates and regulatory structure as checked on 8 October 2026.\"}},\"tunes\":{}},{\"id\":\"src-eu-timeline\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — AI Act regulatory framework\",\"description\":\"Current Commission overview of AI Act application phases, including 2026 applicability and later dates for specified high-risk provisions.\"}},\"tunes\":{}},{\"id\":\"src-ms-ai\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft Azure Well-Architected — AI workloads\",\"description\":\"Current architecture guidance on AI workloads, including nondeterministic behavior, data, application design and operations.\"}},\"tunes\":{}},{\"id\":\"src-ms-ops\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fmlops-genaiops\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft — MLOps and GenAIOps for AI workloads\",\"description\":\"Current guidance on operational lifecycle, data, model maintenance, deployment, monitoring and continuous evolution.\"}},\"tunes\":{}},{\"id\":\"src-ms-responsible\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fresponsible-ai\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft — Responsible AI in Azure workloads\",\"description\":\"Current guidance connecting AI policy to data control, identity, agent auditability, role-based access and operational safeguards.\"}},\"tunes\":{}},{\"id\":\"src-iso-42010\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description\",\"description\":\"Current architecture-description standard supporting explicit concerns, viewpoints and relationships across system architecture.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":1604,"blocks":1605,"version":2742},1791478189041,[1606,1610,1615,1620,1625,1629,1633,1637,1641,1645,1669,1673,1677,1681,1685,1708,1712,1716,1720,1724,1728,1732,1736,1740,1744,1748,1752,1757,1761,1765,1769,1773,1777,1781,1785,1789,1793,1797,1801,1805,1809,1813,1817,1821,1825,1829,1833,1837,1841,1845,1849,1853,1857,1861,1865,1869,1873,1877,1881,1885,1933,1938,1942,1947,1978,1982,1986,2015,2019,2023,2063,2067,2085,2089,2093,2097,2101,2106,2110,2114,2145,2149,2174,2178,2182,2186,2215,2219,2223,2227,2232,2236,2240,2244,2248,2253,2257,2261,2265,2269,2297,2301,2305,2309,2313,2332,2336,2340,2380,2384,2415,2419,2460,2464,2513,2517,2521,2525,2529,2533,2537,2541,2545,2549,2553,2557,2564,2568,2575,2579,2583,2612,2616,2648,2652,2656,2660,2664,2668,2672,2679,2686,2693,2700,2707,2714,2721,2728,2735],{"id":215,"data":1607,"type":218,"tunes":1609},{"text":1608},"Enterprise AI architecture is the organization-wide architecture required when AI becomes part of a company's real systems, data, decisions and operations. The model is only one component. Once AI is connected to enterprise data, identities, permissions, business processes, external providers and production systems, the architecture must also define data authority, access boundaries, risk ownership, provider dependencies, auditability, evaluation, lifecycle control, compliance and operational responsibility. Enterprise AI therefore differs from both a single AI solution and a shared AI platform: it coordinates how many AI-enabled systems fit into the wider organization.",{},{"id":221,"data":1611,"type":226,"tunes":1614},{"body":1612,"title":1613,"variant":225},"\u003Cstrong>What changes when AI enters a company?\u003C\u002Fstrong> Existing enterprise architecture responsibilities expand to include probabilistic model behavior, new data flows, retrieval and grounding, model\u002Fprovider dependencies, AI-specific evaluation, agent\u002Ftool authority, model and prompt lifecycle, AI risk management, transparency obligations, and new operational failure modes. The architecture must connect these concerns to the company's existing identity, security, data, procurement, delivery and governance structures instead of creating a parallel “AI universe.”","Direct answer",{},{"id":229,"data":1616,"type":226,"tunes":1619},{"body":1617,"title":1618,"variant":233},"A chatbot can be a user interface. Enterprise AI architecture is the system of boundaries behind it: what data the AI may access, which source is authoritative, who may use which capability, whether external providers may receive the data, what actions an agent may execute, how outputs are evaluated, what must be logged, who owns incidents, and how changes are approved and rolled back.","Enterprise AI is not “a bigger chatbot”",{},{"id":236,"data":1621,"type":226,"tunes":1624},{"body":1622,"title":1623,"variant":240},"The architectural principles in this article are intended to be stable. Regulation, standards and vendor capabilities are version-sensitive. ISO\u002FIEC 42001:2023 and ISO\u002FIEC 23894:2023 are current published standards. NIST states that AI RMF 1.0 is being revised. Under the current consolidated EU AI Act text, the Regulation applies generally from 2 August 2026, while specified high-risk provisions have later application dates. Legal classification must always be checked against the current law and the concrete use case.","Current-source note — 8 October 2026",{},{"id":243,"data":1626,"type":248,"tunes":1628},{"title":1627,"maxLevel":246,"minLevel":247},"Contents",{},{"id":251,"data":1630,"type":42,"tunes":1632},{"text":1631,"level":247},"What enterprise AI architecture really means",{},{"id":256,"data":1634,"type":218,"tunes":1636},{"text":1635},"Enterprise AI architecture describes how AI capabilities are integrated into an existing organization without breaking the boundaries that already make enterprise systems governable: business ownership, identity, authorization, data classification, system-of-record responsibility, change management, procurement, audit, continuity and operations.",{},{"id":261,"data":1638,"type":218,"tunes":1640},{"text":1639},"The enterprise architect does not replace the AI Solution Architect or AI Platform Architect. The enterprise scope asks a different question: How do multiple AI solutions and shared AI capabilities fit into the company's target architecture, policies, data landscape, risk model and operating model?",{},{"id":266,"data":1642,"type":218,"tunes":1644},{"text":1643},"This makes enterprise AI architecture a coordination discipline across technology and organization. A technically good model integration can still be an enterprise architecture failure if it creates shadow data flows, duplicates identity, bypasses procurement, cannot be audited, has no owner, or cannot be safely changed.",{},{"id":271,"data":1646,"type":303,"tunes":1668},{"rows":1647,"title":1660,"layout":292,"columns":1661},[1648,1651,1654,1657],{"id":275,"label":1649,"values":1650},"Primary scope",[278,278,278],{"id":280,"label":1652,"values":1653},"Primary question",[278,278,278],{"id":284,"label":1655,"values":1656},"Ownership focus",[278,278,278],{"id":288,"label":1658,"values":1659},"Success condition",[278,278,278],"Solution, platform and enterprise AI architecture are different scopes",[1662,1664,1666],{"id":295,"label":1663},"AI Solution Architecture",{"id":298,"label":1665},"AI Platform Architecture",{"id":301,"label":1667},"Enterprise AI Architecture",{},{"id":306,"data":1670,"type":42,"tunes":1672},{"text":1671,"level":247},"The simplest example",{},{"id":311,"data":1674,"type":218,"tunes":1676},{"text":1675},"A company starts with one internal document assistant. The first version searches approved documents and sends retrieved context to a language model. At solution level, this may look straightforward.",{},{"id":316,"data":1678,"type":218,"tunes":1680},{"text":1679},"Then a second team wants AI for customer support. A third wants an agent that can update tickets. Finance wants document analysis. HR wants an internal assistant. Developers want coding agents. Suddenly the company has several providers, several data classes, different user groups, overlapping retrieval indexes, different logging rules, new tool permissions, duplicated secrets and unclear ownership.",{},{"id":321,"data":1682,"type":218,"tunes":1684},{"text":1683},"At that point, the question is no longer “Does the assistant work?” The enterprise question becomes: Which capabilities are approved, who owns them, what data can cross which boundary, how are identities and permissions enforced, which providers are acceptable, what must be audited, and how can the organization change models or suppliers without losing control?",{},{"id":326,"data":1686,"type":349,"tunes":1707},{"steps":1687,"title":1706,"orientation":348},[1688,1691,1694,1697,1700,1703],{"label":1689,"description":1690},"1. Isolated use case","One team connects one model to one workflow and validates local value.",{"label":1692,"description":1693},"2. Shared dependencies appear","Multiple teams need providers, model access, retrieval, identity, secrets, observability and evaluation.",{"label":1695,"description":1696},"3. Enterprise boundaries are crossed","AI touches regulated data, systems of record, external vendors, privileged actions and business decisions.",{"label":1698,"description":1699},"4. Ownership must become explicit","Business, architecture, data, security, legal\u002Fcompliance, procurement and operations need defined responsibilities.",{"label":1701,"description":1702},"5. Lifecycle becomes organizational","Model changes, prompt changes, provider changes and new agent capabilities become governed changes rather than local developer edits.",{"label":1704,"description":1705},"6. Architecture becomes repeatable","The organization establishes reusable patterns, decision records, controls, exceptions and validation gates for new AI workloads.","From isolated AI feature to enterprise architecture",{},{"id":352,"data":1709,"type":42,"tunes":1711},{"text":1710,"level":247},"Where the simple example stops",{},{"id":357,"data":1713,"type":218,"tunes":1715},{"text":1714},"Enterprise architecture does not mean that every AI component must be centralized. Some capabilities should be shared; others must remain domain-owned. Finance, HR, engineering and customer support may legitimately require different data boundaries, providers, evaluation criteria and human-approval rules.",{},{"id":362,"data":1717,"type":218,"tunes":1719},{"text":1718},"The enterprise objective is therefore not one model, one vector database or one universal assistant. The objective is coherent architecture with explicit variation: common policies and reusable capabilities where they reduce risk and duplication, plus controlled exceptions where business or regulatory requirements differ.",{},{"id":367,"data":1721,"type":42,"tunes":1723},{"text":1722,"level":247},"What changes in the architecture when AI enters the enterprise",{},{"id":372,"data":1725,"type":42,"tunes":1727},{"text":1726,"level":246},"1. Business ownership becomes part of the technical architecture",{},{"id":377,"data":1729,"type":218,"tunes":1731},{"text":1730},"Traditional applications already need business owners. AI makes that requirement more visible because acceptable behavior cannot be defined only by uptime and functional correctness. Someone must own the intended use, unacceptable use, output quality, escalation path and consequences of wrong or inappropriate results.",{},{"id":382,"data":1733,"type":218,"tunes":1735},{"text":1734},"A model team cannot decide alone whether an answer is acceptable for HR, finance, legal or customer-facing use. Enterprise AI architecture therefore connects technical design to an explicit business capability, accountable owner, user group and decision context.",{},{"id":387,"data":1737,"type":42,"tunes":1739},{"text":1738,"level":246},"2. Data access is not enough — data authority must be defined",{},{"id":392,"data":1741,"type":218,"tunes":1743},{"text":1742},"Enterprise AI frequently combines operational databases, documents, search indexes, vector stores, data warehouses, SaaS systems and external knowledge. The architecture must distinguish where information is stored from which source is authoritative for a given claim or action.",{},{"id":397,"data":1745,"type":218,"tunes":1747},{"text":1746},"A vector index can improve retrieval but should not silently become the company's system of record. A model response can summarize an ERP record but should not replace the ERP as the authoritative source. Cached context can improve latency but becomes unsafe when permissions or underlying business state change.",{},{"id":402,"data":1749,"type":218,"tunes":1751},{"text":1750},"Enterprise AI therefore needs provenance, freshness, source classification, authorization propagation and invalidation rules in addition to ordinary data integration.",{},{"id":407,"data":1753,"type":226,"tunes":1756},{"body":1754,"title":1755,"variant":288},"\u003Cstrong>The AI system may transform, retrieve and reason over enterprise data without becoming the authority for that data.\u003C\u002Fstrong> The architecture should preserve a path back to the authoritative source whenever the use case requires evidence, verification or consequential action.","Enterprise data rule",{},{"id":413,"data":1758,"type":42,"tunes":1760},{"text":1759,"level":246},"3. Identity becomes multi-layered",{},{"id":418,"data":1762,"type":218,"tunes":1764},{"text":1763},"Enterprise AI has more identities than the human user. A request may involve a user identity, application identity, service identity, agent identity, provider credential, tool credential and tenant or organizational context.",{},{"id":423,"data":1766,"type":218,"tunes":1768},{"text":1767},"These identities should not be collapsed into one shared API key. Authorization must remain attributable to the correct principal, and privileged tools should receive only the authority required for the current operation.",{},{"id":428,"data":1770,"type":218,"tunes":1772},{"text":1771},"For agentic systems, this becomes especially important: a model can propose an action, but the runtime must decide whether the requesting identity is allowed to execute it. Model capability is not authorization.",{},{"id":433,"data":1774,"type":42,"tunes":1776},{"text":1775,"level":246},"4. Permissions move from content access to action authority",{},{"id":438,"data":1778,"type":218,"tunes":1780},{"text":1779},"A read-only assistant mainly needs controlled access to information. An enterprise agent can create tickets, modify records, send messages, trigger workflows or operate external systems. That introduces a different risk class because the system can change state rather than merely describe it.",{},{"id":443,"data":1782,"type":218,"tunes":1784},{"text":1783},"The architecture should separate read, write, approval and administrative capabilities; define human-in-the-loop points where consequence justifies them; and preserve an audit trail that identifies what was requested, what was approved and what actually changed.",{},{"id":448,"data":1786,"type":42,"tunes":1788},{"text":1787,"level":246},"5. The AI provider becomes an enterprise dependency",{},{"id":453,"data":1790,"type":218,"tunes":1792},{"text":1791},"Calling a model API is also a supplier relationship. The architecture may depend on provider availability, service terms, data-processing conditions, supported regions, model lifecycle, quotas, pricing, API compatibility, security controls and change notices.",{},{"id":458,"data":1794,"type":218,"tunes":1796},{"text":1795},"This means provider selection is not only a benchmark decision. Procurement, security, privacy, legal review, continuity planning and exit strategy can all become architecture inputs.",{},{"id":463,"data":1798,"type":218,"tunes":1800},{"text":1799},"Provider abstraction can reduce coupling, but only where the underlying capabilities are genuinely portable. Tool use, structured output, context limits, multimodality, safety controls, fine-tuning and hosted-agent features may differ materially between providers.",{},{"id":468,"data":1802,"type":42,"tunes":1804},{"text":1803,"level":246},"6. AI risk becomes a lifecycle process",{},{"id":473,"data":1806,"type":218,"tunes":1808},{"text":1807},"AI risk is not completed by one approval before launch. The model, prompt, retrieval corpus, tool set, provider, user population and surrounding business process can all change after deployment. The risk profile changes with them.",{},{"id":478,"data":1810,"type":218,"tunes":1812},{"text":1811},"ISO\u002FIEC 23894:2023 explicitly addresses integration of AI risk management into organizational activities and functions. NIST AI RMF similarly frames risk management across the lifecycle. Enterprise architecture should therefore make risk review part of change and operations rather than an isolated compliance document.",{},{"id":483,"data":1814,"type":218,"tunes":1816},{"text":1815},"Risk should also be proportional. A summarization assistant and an autonomous system that changes production records should not receive identical controls merely because both use an LLM.",{},{"id":488,"data":1818,"type":42,"tunes":1820},{"text":1819,"level":246},"7. Governance becomes an operating system, not a policy PDF",{},{"id":493,"data":1822,"type":218,"tunes":1824},{"text":1823},"ISO\u002FIEC 42001:2023 defines requirements for establishing, implementing, maintaining and continually improving an AI management system. The architecture consequence is important: governance must connect policy to real inventories, ownership, processes, controls, evidence, reviews and improvement loops.",{},{"id":498,"data":1826,"type":218,"tunes":1828},{"text":1827},"An enterprise AI policy that is not connected to provider approval, identity, logging, change management, evaluation and incident response has limited architectural effect. The organization needs mechanisms that make policy enforceable or at least observable.",{},{"id":503,"data":1830,"type":42,"tunes":1832},{"text":1831,"level":246},"8. Evaluation becomes a production control",{},{"id":508,"data":1834,"type":218,"tunes":1836},{"text":1835},"Traditional acceptance testing assumes that the same input normally produces the same deterministic result. Generative AI can be nondeterministic, sensitive to context and dependent on changing external knowledge. Production acceptance therefore needs task-specific evals, regression suites and observable thresholds rather than only unit tests.",{},{"id":513,"data":1838,"type":218,"tunes":1840},{"text":1839},"The platform can provide reusable evaluation infrastructure, but the enterprise still needs ownership of domain ground truth and release gates. A central AI team cannot invent the correct answer for every business domain.",{},{"id":518,"data":1842,"type":218,"tunes":1844},{"text":1843},"Model, prompt, retrieval and tool changes should be traceable to evaluation evidence where the change can materially affect output behavior.",{},{"id":523,"data":1846,"type":42,"tunes":1848},{"text":1847,"level":246},"9. Observability must include behavior, data and model context",{},{"id":528,"data":1850,"type":218,"tunes":1852},{"text":1851},"CPU, memory and HTTP error rates are not sufficient for AI workloads. Production observability may need model\u002Fprovider identifiers, latency, token usage, cost, retrieval results, tool calls, refusal behavior, evaluation scores, safety events and failure classifications.",{},{"id":533,"data":1854,"type":218,"tunes":1856},{"text":1855},"At the same time, AI telemetry can contain sensitive data. Prompt and response logs may become a shadow data store. Enterprise architecture must therefore define what can be logged, how it is redacted, who can access it, how long it is retained and when detailed tracing must be disabled.",{},{"id":538,"data":1858,"type":42,"tunes":1860},{"text":1859,"level":246},"10. AI components need explicit lifecycle ownership",{},{"id":543,"data":1862,"type":218,"tunes":1864},{"text":1863},"Models can be renamed, replaced, retired or changed by providers. Embedding models can invalidate an index strategy. Prompt templates and system instructions can change behavior. Agent runtimes and protocols can evolve. External tools can change their schemas and permissions.",{},{"id":548,"data":1866,"type":218,"tunes":1868},{"text":1867},"Enterprise architecture must decide who detects these changes, who tests them, who approves them, how consumers are notified, how rollback works and what evidence is required before a new version becomes the default.",{},{"id":553,"data":1870,"type":42,"tunes":1872},{"text":1871,"level":246},"11. Incident response must include AI-specific failure modes",{},{"id":558,"data":1874,"type":218,"tunes":1876},{"text":1875},"An AI incident may be a provider outage, data leak, prompt-injection path, authorization failure, retrieval contamination, unexpected model behavior, unsafe tool execution, cost spike, stale knowledge, evaluation regression or a change in external model behavior.",{},{"id":563,"data":1878,"type":218,"tunes":1880},{"text":1879},"The enterprise runbook therefore needs more than “restart the service.” It may require disabling a model route, revoking tool access, freezing a corpus, changing a prompt version, disabling an agent capability, switching provider, escalating to a domain owner or preserving traces for investigation.",{},{"id":568,"data":1882,"type":42,"tunes":1884},{"text":1883,"level":247},"Enterprise AI creates cross-functional ownership",{},{"id":573,"data":1886,"type":292,"tunes":1932},{"content":1887,"stretched":43,"withHeadings":14},[1888,1892,1896,1900,1904,1908,1912,1916,1920,1924,1928],[1889,1890,1891],"Concern","Typical enterprise owner or contributor","Architecture question",[1893,1894,1895],"Business use","Business owner \u002F product owner","What decision or workflow is AI allowed to support or automate?",[1897,1898,1899],"Solution architecture","AI \u002F solution architect","How does the concrete workload meet its functional and quality requirements?",[1901,1902,1903],"Shared AI capabilities","AI platform \u002F platform engineering","Which reusable model, retrieval, agent and observability services are provided?",[1905,1906,1907],"Enterprise coherence","Enterprise architecture","How do AI systems fit target architecture, standards, integration patterns and organizational ownership?",[1909,1910,1911],"Data authority","Data owner \u002F domain owner","Which data is authoritative, current, permitted and sufficiently governed?",[1913,1914,1915],"Identity and security","IAM \u002F security architecture","Which identities can access which data and execute which actions?",[1917,1918,1919],"Risk and compliance","Risk \u002F legal \u002F compliance \u002F privacy","Which obligations, prohibited uses, controls and evidence apply to this use case?",[1921,1922,1923],"Supplier dependency","Procurement \u002F vendor management \u002F architecture","What contractual, operational and exit risks arise from the provider?",[1925,1926,1927],"Operations","SRE \u002F operations \u002F platform owner","How is the system monitored, supported, degraded, recovered and changed?",[1929,1930,1931],"Domain acceptance","Business\u002Fdomain specialists","What counts as a correct, safe or useful result in this domain?",{},{"id":622,"data":1934,"type":226,"tunes":1937},{"body":1935,"title":1936,"variant":233},"Responsibility matrices are useful only when they connect to real system boundaries, approvals, data ownership, interfaces, runbooks and change processes. Enterprise AI needs accountable ownership that can be traced to technical controls and operational actions.","A RACI chart is not architecture by itself",{},{"id":628,"data":1939,"type":42,"tunes":1941},{"text":1940,"level":247},"A practical enterprise AI architecture model",{},{"id":633,"data":1943,"type":226,"tunes":1946},{"body":1944,"title":1945,"variant":240},"The following model is a practical synthesis for reasoning about enterprise AI architecture. It is not presented as an ISO or NIST standard. Its purpose is to make cross-organizational boundaries explicit.","Proposed layered model",{},{"id":639,"data":1948,"type":292,"tunes":1977},{"content":1949,"stretched":43,"withHeadings":14},[1950,1953,1956,1959,1962,1965,1968,1971,1974],[1951,1952],"Layer","Primary responsibility",[1954,1955],"Business and policy","Approved use cases, accountable owners, risk appetite, prohibited uses, human accountability, business acceptance.",[1957,1958],"Identity and authority","User\u002Fservice\u002Fagent identities, roles, tenant or organizational scope, privileged actions, approval paths.",[1960,1961],"Enterprise data","Systems of record, document sources, data products, provenance, classification, retention, freshness and access.",[1963,1964],"AI platform","Provider\u002Fmodel access, retrieval primitives, agent runtimes, tool brokers, evaluation infrastructure, observability, quotas and secrets.",[1966,1967],"AI solutions","Domain workflows, prompts\u002Finstructions, domain retrieval, business logic, acceptance criteria and user experience.",[1969,1970],"Integration and tools","APIs, enterprise applications, workflows, messaging, file systems, external services and action execution.",[1972,1973],"Risk and governance","Inventory, assessment, compliance evidence, exception management, model\u002Fprovider approval, review and audit.",[1975,1976],"Operations and lifecycle","Deployment, monitoring, incidents, releases, model\u002Fprovider changes, deprecation, rollback and continuity.",{},{"id":671,"data":1979,"type":218,"tunes":1981},{"text":1980},"The architecture is strongest when each layer can state both its responsibilities and its non-responsibilities. For example, the AI platform can enforce provider policy and collect traces without becoming the source of truth for HR data. A solution can define domain prompts without owning enterprise IAM. A business owner can approve a use case without being expected to operate the inference gateway.",{},{"id":676,"data":1983,"type":42,"tunes":1985},{"text":1984,"level":247},"Map enterprise AI as data and authority flows, not boxes",{},{"id":681,"data":1987,"type":349,"tunes":2014},{"steps":1988,"title":2013,"orientation":348},[1989,1992,1995,1998,2001,2004,2007,2010],{"label":1990,"description":1991},"1. Business context","The user requests a task under an approved use case with an accountable business owner.",{"label":1993,"description":1994},"2. Identity and authorization","The system resolves user, application, service and tenant or organizational scope before privileged access.",{"label":1996,"description":1997},"3. Authoritative data acquisition","The solution reads or retrieves only sources permitted for the current identity and task.",{"label":1999,"description":2000},"4. AI processing","An approved model\u002Fprovider processes the minimum necessary context under defined routing and data-handling rules.",{"label":2002,"description":2003},"5. Tool or action boundary","Any state-changing action is independently authorized and may require human approval according to consequence.",{"label":2005,"description":2006},"6. Validation","The result is checked against solution-specific acceptance, evidence or safety rules.",{"label":2008,"description":2009},"7. Audit and observability","Permitted metadata, decisions, routes, tool calls and outcomes are recorded without creating uncontrolled sensitive-data logs.",{"label":2011,"description":2012},"8. Feedback and lifecycle","Failures and evaluation results feed model, prompt, data, policy and process changes through controlled change management.","A consequential enterprise AI request",{},{"id":711,"data":2016,"type":42,"tunes":2018},{"text":2017,"level":247},"An enterprise needs an AI inventory before it can govern AI",{},{"id":716,"data":2020,"type":218,"tunes":2022},{"text":2021},"Organizations cannot manage AI systems they cannot identify. Enterprise architecture should maintain an inventory at a level that is useful for decisions, not merely a list of model names.",{},{"id":721,"data":2024,"type":292,"tunes":2062},{"content":2025,"stretched":43,"withHeadings":14},[2026,2029,2032,2035,2038,2041,2044,2047,2050,2053,2056,2059],[2027,2028],"Inventory field","Why it matters",[2030,2031],"Use case and owner","Connects technology to accountable business purpose.",[2033,2034],"Users and affected parties","Defines who interacts with or is affected by the system.",[2036,2037],"Model\u002Fprovider","Identifies external dependency, capability and lifecycle risk.",[2039,2040],"Data sources","Supports authority, privacy, classification and provenance review.",[2042,2043],"Deployment\u002Fruntime location","Clarifies processing location, connectivity and operational control.",[2045,2046],"Tools\u002Factions","Shows whether the AI can change external state and at what consequence.",[2048,2049],"Human oversight","Records where review, approval or escalation is required.",[2051,2052],"Risk\u002Fclassification","Connects the system to organizational and regulatory controls.",[2054,2055],"Evaluation evidence","Shows what was tested and under which validity conditions.",[2057,2058],"Current version","Allows incidents and regressions to be traced to actual deployed state.",[2060,2061],"Lifecycle state","Proposed, experimental, approved, production, restricted, deprecated or retired.",{},{"id":762,"data":2064,"type":42,"tunes":2066},{"text":2065,"level":247},"AI governance and enterprise AI architecture are related but not the same",{},{"id":767,"data":2068,"type":303,"tunes":2084},{"rows":2069,"title":2079,"layout":292,"columns":2080},[2070,2073,2076],{"id":771,"label":2071,"values":2072},"Purpose",[278,278],{"id":775,"label":2074,"values":2075},"Example",[278,278],{"id":779,"label":2077,"values":2078},"Failure if isolated",[278,278],"Governance versus architecture",[2081,2083],{"id":785,"label":2082},"AI Governance",{"id":788,"label":1667},{},{"id":791,"data":2086,"type":42,"tunes":2088},{"text":2087,"level":247},"Regulation becomes an architecture input",{},{"id":796,"data":2090,"type":218,"tunes":2092},{"text":2091},"For organizations operating in the European Union, the AI Act can create requirements that affect system design, documentation, transparency, governance and operating processes. The architectural impact depends on the organization's role in the AI value chain and the concrete system classification; not every AI system has the same obligations.",{},{"id":801,"data":2094,"type":218,"tunes":2096},{"text":2095},"As of 8 October 2026, the current consolidated text states that the Regulation generally applies from 2 August 2026. Governance rules and obligations for general-purpose AI models began applying earlier, while specified high-risk system provisions have later dates. The Commission also began enforcing new transparency requirements from 2 August 2026 for relevant interactive and synthetic-content systems.",{},{"id":806,"data":2098,"type":218,"tunes":2100},{"text":2099},"The enterprise architecture lesson is not “put compliance in the model.” It is to make classification, provider\u002Fdeployer role, documentation, transparency, oversight, logging and change evidence traceable to the system that actually implements the use case.",{},{"id":811,"data":2102,"type":226,"tunes":2105},{"body":2103,"title":2104,"variant":240},"This article describes architecture implications, not legal advice. Enterprise AI architecture should preserve the information needed for legal and compliance specialists to classify the actual system and map obligations to concrete controls. Architecture should not hard-code one regulatory interpretation as if every AI workload had the same status.","Legal scope is use-case specific",{},{"id":817,"data":2107,"type":42,"tunes":2109},{"text":2108,"level":247},"Procurement and architecture become connected",{},{"id":822,"data":2111,"type":218,"tunes":2113},{"text":2112},"An external model or managed AI platform can become a deep dependency even when integration requires only a few API calls. Enterprise architecture should therefore make procurement questions technically concrete.",{},{"id":827,"data":2115,"type":292,"tunes":2144},{"content":2116,"stretched":43,"withHeadings":14},[2117,2120,2123,2126,2129,2132,2135,2138,2141],[2118,2119],"Procurement question","Architecture consequence",[2121,2122],"Where is data processed?","Region, network path, data residency and transfer controls.",[2124,2125],"Is customer data retained or used for provider improvement?","Data minimization, contractual controls and provider eligibility.",[2127,2128],"How are models versioned or retired?","Regression testing, compatibility, fallback and lifecycle planning.",[2130,2131],"What are quotas and service limits?","Capacity architecture, admission control and failure handling.",[2133,2134],"How portable is the integration?","Provider abstraction, exit cost and migration effort.",[2136,2137],"What incident information is available?","Observability, forensic capability and support escalation.",[2139,2140],"Which subprocessors or external services are involved?","Dependency mapping and risk assessment.",[2142,2143],"What changes without explicit customer approval?","Change detection, release gates and acceptance strategy.",{},{"id":859,"data":2146,"type":42,"tunes":2148},{"text":2147,"level":247},"Enterprise architecture decides how much AI control the requirement actually needs",{},{"id":864,"data":2150,"type":292,"tunes":2173},{"content":2151,"stretched":43,"withHeadings":14},[2152,2155,2158,2161,2164,2167,2170],[2153,2154],"Requirement","Possible architectural response",[2156,2157],"Fast access to managed models","Managed provider with enterprise identity, gateway controls and contractual review.",[2159,2160],"Private data with managed orchestration","Managed control plane plus customer-controlled execution or private data plane where supported.",[2162,2163],"Strict locality or sovereignty","Region-restricted, sovereign, private or self-hosted architecture according to the real requirement.",[2165,2166],"Air-gapped environment","Locally hosted models, local retrieval, local tooling, offline update\u002Fdistribution and isolated observability.",[2168,2169],"Provider portability","Application-owned domain state plus adapters and contracts that isolate provider-specific behavior where practical.",[2171,2172],"Highest control of agent semantics","Self-managed or deeply controlled runtime with explicit tool, context, state and lifecycle ownership.",{},{"id":890,"data":2175,"type":218,"tunes":2177},{"text":2176},"The most controlled architecture is not automatically the best enterprise architecture. More ownership increases responsibility for patching, capacity, security, testing, model operations and incident response. Enterprise architecture should escalate control only where the requirement justifies the additional operational burden.",{},{"id":895,"data":2179,"type":42,"tunes":2181},{"text":2180,"level":247},"AI turns change management into a behavioral problem",{},{"id":900,"data":2183,"type":218,"tunes":2185},{"text":2184},"A normal dependency update can alter performance or compatibility. An AI change can also alter behavior. Replacing a model, changing a system prompt, changing retrieval, adding a tool or changing the context policy can modify how the system interprets and responds even if the surrounding application code barely changes.",{},{"id":905,"data":2187,"type":349,"tunes":2214},{"steps":2188,"title":2213,"orientation":348},[2189,2192,2195,2198,2201,2204,2207,2210],{"label":2190,"description":2191},"1. Change identified","Model, provider, prompt, retrieval source, tool, policy or runtime change is proposed or detected.",{"label":2193,"description":2194},"2. Impact mapped","Affected solutions, data classes, users, risk controls, cost, contracts and operational dependencies are identified.",{"label":2196,"description":2197},"3. Architecture decision updated","Material choices and trade-offs are recorded; superseded decisions remain historically traceable.",{"label":2199,"description":2200},"4. Evaluation executed","Relevant regression, safety, retrieval, latency, cost and domain tests are run.",{"label":2202,"description":2203},"5. Approval applied","Approval level follows consequence, risk and organizational policy.",{"label":2205,"description":2206},"6. Controlled rollout","Versioned release, canary or staged deployment is used where appropriate.",{"label":2208,"description":2209},"7. Production evidence collected","Telemetry, incidents, feedback and domain outcomes are monitored.",{"label":2211,"description":2212},"8. Rollback or acceptance","The change is accepted, restricted, rolled back or superseded based on evidence.","A production AI change path",{},{"id":935,"data":2216,"type":42,"tunes":2218},{"text":2217,"level":247},"Enterprise AI still needs NFRs and ADRs",{},{"id":940,"data":2220,"type":218,"tunes":2222},{"text":2221},"AI does not replace ordinary architecture discipline. Non-functional requirements remain the target conditions: availability, latency, privacy, isolation, auditability, recoverability, cost boundaries, explainability or other quality requirements. Architecture Decision Records preserve the chosen response and its trade-offs.",{},{"id":945,"data":2224,"type":218,"tunes":2226},{"text":2225},"The AI-specific difference is that some quality attributes must be evaluated probabilistically or empirically. “Answers must be useful” is too vague. A production requirement should identify the task, data, user population, acceptable failure conditions, measurement method and threshold where practical.",{},{"id":950,"data":2228,"type":226,"tunes":2231},{"body":2229,"title":2230,"variant":288},"\u003Cstrong>Business need → requirement \u002F NFR → architecture decision → implementation → evaluation \u002F validation → production observation → change decision.\u003C\u002Fstrong> AI adds new variables to this chain; it does not make the chain unnecessary.","Enterprise traceability chain",{},{"id":956,"data":2233,"type":42,"tunes":2235},{"text":2234,"level":247},"Enterprise AI architecture must connect to delivery",{},{"id":961,"data":2237,"type":218,"tunes":2239},{"text":2238},"Architecture that never reaches backlog, implementation, acceptance and operations remains conceptual. Enterprise AI therefore needs traceability from architecture decisions into delivery work and back from implementation evidence into architecture.",{},{"id":966,"data":2241,"type":218,"tunes":2243},{"text":2242},"Jira and Confluence are examples of tools that can support this separation when used deliberately: Confluence can preserve requirements, architecture, decisions, risks and rationale; Jira can manage actionable delivery work and state. The important principle is the traceability, not the brand of tool.",{},{"id":971,"data":2245,"type":42,"tunes":2247},{"text":2246,"level":247},"Original project evidence: Enterprise Aaasaasa 0.1",{},{"id":976,"data":2249,"type":226,"tunes":2252},{"body":2250,"title":2251,"variant":240},"Enterprise Aaasaasa 0.1 is used here as original project evidence for structured enterprise architecture and delivery thinking. It is a PoC \u002F enterprise project context, not evidence of mass customer adoption, enterprise-scale production usage or commercial traction.","Project evidence, not market-proof claim",{},{"id":982,"data":2254,"type":218,"tunes":2256},{"text":2255},"Enterprise Aaasaasa 0.1 combines platform architecture, SaaS\u002FAPI concepts, internationalization, AI integration and structured project governance. The project was deliberately organized so that requirements, architecture, prototype delivery, validation and closure were separate milestones rather than one undifferentiated implementation phase.",{},{"id":987,"data":2258,"type":218,"tunes":2260},{"text":2259},"The architecture direction includes multi-instance \u002F multi-database concepts together with API, CRUD, i18n and AI capabilities. That matters for enterprise AI because tenant or instance boundaries, database ownership and application services must remain explicit when AI features are added.",{},{"id":992,"data":2262,"type":218,"tunes":2264},{"text":2263},"The project structure also treated architecture delay, scope creep and AI\u002Fdata-protection concerns as project risks rather than discovering them only during implementation. Stakeholders included technical, security, sponsor\u002Fsteering and external-service perspectives, which is closer to the real cross-functional nature of enterprise AI than a model-only prototype.",{},{"id":997,"data":2266,"type":218,"tunes":2268},{"text":2267},"The useful evidence is therefore the integration of architecture and delivery: business and project structure, milestones, risks, architecture, backend\u002FAPI, frontend\u002FAI work, validation and closure are treated as connected responsibilities. That pattern is reusable even though the project itself should not be presented as proof of external enterprise adoption.",{},{"id":1002,"data":2270,"type":292,"tunes":2296},{"content":2271,"stretched":43,"withHeadings":14},[2272,2275,2278,2281,2284,2287,2290,2293],[2273,2274],"Project element","Enterprise AI architecture lesson",[2276,2277],"Requirements milestone","AI capability must begin from defined need, scope, acceptance and quality constraints.",[2279,2280],"Architecture milestone","Data, API, instance\u002Fdatabase boundaries and AI integration are explicit design work.",[2282,2283],"Prototype milestone","Architecture must become executable enough to expose integration risks.",[2285,2286],"Validation milestone","A functioning prototype is not the same as validated acceptance.",[2288,2289],"Risk register","Scope, architecture delay and AI\u002Fdata-protection concerns are managed as delivery risks.",[2291,2292],"Stakeholder structure","Enterprise AI spans sponsor\u002Fbusiness, architecture, security, external providers and delivery.",[2294,2295],"Project closure","Decisions, remaining risks and validation evidence must survive beyond the implementation sprint.",{},{"id":1031,"data":2298,"type":42,"tunes":2300},{"text":2299,"level":247},"Supporting implementation patterns from the wider platform work",{},{"id":1036,"data":2302,"type":218,"tunes":2304},{"text":2303},"Separate implementation work in the wider Aaasaasa platform provides concrete examples of boundaries that enterprise AI architecture must preserve: tenant-scoped RBAC in the CMS, explicit provider\u002Fmodel\u002Fruntime\u002Fpermission separation in Aaasaasa AI Client, and provenance-first retrieval in the Source of Truth Research Engine.",{},{"id":1041,"data":2306,"type":218,"tunes":2308},{"text":2307},"These projects should not be collapsed into one claimed production platform. Their value here is narrower: they demonstrate implemented patterns for identity scope, provider boundaries, controlled runtime permissions, retrieval provenance and evidence traceability that are directly relevant to enterprise AI.",{},{"id":1046,"data":2310,"type":42,"tunes":2312},{"text":2311,"level":247},"How the main standards fit together",{},{"id":1051,"data":2314,"type":292,"tunes":2331},{"content":2315,"stretched":43,"withHeadings":14},[2316,2319,2321,2323,2325,2327,2329],[2317,2318],"Source","What it contributes to enterprise AI architecture",[1058,2320],"Organization-level AI management system: policies, objectives, processes, responsibility, monitoring and continual improvement.",[1061,2322],"Guidance for integrating AI-specific risk management into organizational activities and functions.",[1064,2324],"Voluntary lifecycle-oriented framework for managing AI risks; organized around Govern, Map, Measure and Manage.",[1067,2326],"Generative AI profile extending AI RMF with generative-AI-specific risks and actions.",[1070,2328],"Binding regulatory obligations in the EU whose applicability depends on role, system type and classification.",[1073,2330],"General architecture-description concepts for expressing concerns, viewpoints, decisions and relationships.",{},{"id":1077,"data":2333,"type":218,"tunes":2335},{"text":2334},"These sources solve different problems. ISO\u002FIEC 42001 is not a replacement for technical architecture. ISO\u002FIEC 23894 and NIST AI RMF do not define one mandatory software stack. The EU AI Act is law, not a platform design pattern. Architecture must translate the applicable organizational, risk and legal requirements into implementable system boundaries and evidence.",{},{"id":1082,"data":2337,"type":42,"tunes":2339},{"text":2338,"level":247},"Common enterprise AI failure modes",{},{"id":1087,"data":2341,"type":292,"tunes":2379},{"content":2342,"stretched":43,"withHeadings":14},[2343,2346,2349,2352,2355,2358,2361,2364,2367,2370,2373,2376],[2344,2345],"Failure mode","Why it fails",[2347,2348],"Every team buys AI independently","Creates shadow providers, duplicated secrets, inconsistent data handling and weak leverage over supplier risk.",[2350,2351],"One central AI team owns every domain decision","Centralizes technical control but loses domain accountability and creates a bottleneck.",[2353,2354],"Vector database becomes the source of truth","Retrieval infrastructure silently replaces authoritative systems and freshness rules.",[2356,2357],"One shared API key for all users and agents","Destroys attribution, least privilege and meaningful auditability.",[2359,2360],"Model change deployed like a minor library patch","Behavioral regressions can reach production without domain evaluation.",[2362,2363],"All prompts and outputs are logged forever","Observability creates an uncontrolled sensitive-data repository.",[2365,2366],"Governance is only documentation","Policies exist without enforcement points, evidence or operational ownership.",[2368,2369],"Compliance is delegated to the provider","The organization's own role, use case, data and operational obligations remain unresolved.",[2371,2372],"Agent can call tools because the model supports tool use","Capability is mistaken for authorization.",[2374,2375],"Platform health equals business correctness","Endpoint uptime and model availability do not prove domain answer quality or acceptable outcomes.",[2377,2378],"No exit strategy for model\u002Fprovider dependency","A pricing, policy, capability or availability change becomes an emergency migration.",{},{"id":1128,"data":2381,"type":42,"tunes":2383},{"text":2382,"level":247},"Common misconceptions",{},{"id":1133,"data":2385,"type":292,"tunes":2414},{"content":2386,"stretched":43,"withHeadings":14},[2387,2390,2393,2396,2399,2402,2405,2408,2411],[2388,2389],"Misconception","Better model",[2391,2392],"“Enterprise AI means a company-wide chatbot.”","The chatbot is one interface; enterprise AI architecture governs the underlying data, identity, provider, runtime, risk and operations.",[2394,2395],"“If we use a reputable model provider, governance is solved.”","Provider controls do not define your use case, data authority, user permissions, business acceptance or legal role.",[2397,2398],"“Private AI means everything must be self-hosted.”","Privacy requirements can lead to several architectures; the required control boundary must be stated precisely.",[2400,2401],"“AI governance belongs to legal, architecture belongs to IT.”","The two disciplines must connect because policy obligations need implementable controls and evidence.",[2403,2404],"“One enterprise model is simpler.”","Standardization can help, but workloads can require different modalities, regions, costs, quality levels or control models.",[2406,2407],"“AI risk is model risk.”","Risk can originate in data, prompts, retrieval, identity, tools, interfaces, operations, users and organizational process.",[2409,2410],"“Human-in-the-loop makes an agent safe.”","Human approval helps only if the reviewer has useful context, authority, time and a clear decision point.",[2412,2413],"“A successful pilot proves enterprise readiness.”","A pilot proves bounded capability; enterprise readiness also requires integration, governance, lifecycle, operations and repeatable controls.",{},{"id":1165,"data":2416,"type":42,"tunes":2418},{"text":2417,"level":247},"A practical enterprise AI architecture decision sequence",{},{"id":1170,"data":2420,"type":349,"tunes":2459},{"steps":2421,"title":2458,"orientation":348},[2422,2425,2428,2431,2434,2437,2440,2443,2446,2449,2452,2455],{"label":2423,"description":2424},"1. Define the business capability","State the user, decision or workflow, expected value and accountable owner.",{"label":2426,"description":2427},"2. Classify data and authority","Identify systems of record, personal\u002Fconfidential data, retention, freshness and provenance requirements.",{"label":2429,"description":2430},"3. Define identity and action boundaries","Determine who may read, generate, decide, approve and change external systems.",{"label":2432,"description":2433},"4. Select solution and platform responsibilities","Decide what belongs to the workload, what can be shared and what remains enterprise-owned.",{"label":2435,"description":2436},"5. Assess provider and runtime dependency","Evaluate managed, self-hosted, private, sovereign or hybrid options against real requirements.",{"label":2438,"description":2439},"6. Map risk and regulatory obligations","Determine risk level, organizational controls and applicable legal responsibilities for the concrete system.",{"label":2441,"description":2442},"7. Define measurable acceptance","Create evaluation criteria for quality, reliability, safety, retrieval, cost and operational behavior.",{"label":2444,"description":2445},"8. Record architecture decisions","Preserve rationale, alternatives, trade-offs, dependencies and conditions that would trigger reconsideration.",{"label":2447,"description":2448},"9. Connect architecture to delivery","Translate the design into backlog, milestones, acceptance criteria, technical work and ownership.",{"label":2450,"description":2451},"10. Validate in production-shaped conditions","Test realistic identity, data, failure, latency, provider, tool and recovery scenarios rather than only clean demos.",{"label":2453,"description":2454},"11. Establish operations and change control","Define monitoring, incident response, model\u002Fprovider updates, regression testing, rollback and retirement.",{"label":2456,"description":2457},"12. Feed evidence back into architecture","Use production observations, audits, incidents and evaluations to revise decisions and controls.","From opportunity to governed enterprise capability",{},{"id":1212,"data":2461,"type":42,"tunes":2463},{"text":2462,"level":247},"Enterprise AI architecture checklist",{},{"id":1217,"data":2465,"type":292,"tunes":2512},{"content":2466,"stretched":43,"withHeadings":14},[2467,2470,2473,2476,2479,2482,2485,2488,2491,2494,2497,2500,2503,2506,2509],[2468,2469],"Question","Expected evidence",[2471,2472],"What business capability does this AI support?","Named owner, user group, intended decision\u002Fworkflow and acceptance objective.",[2474,2475],"Which source is authoritative for each important fact?","Systems of record, document authority, provenance and freshness rules.",[2477,2478],"Which identities exist?","Human, application, service, agent, tenant\u002Forg and provider identities are distinguishable.",[2480,2481],"What can the AI read?","Authorization-scoped data sources and explicit sensitive-data rules.",[2483,2484],"What can the AI change?","Tool\u002Faction inventory, permission model, approval and rollback path.",[2486,2487],"Which provider\u002Fmodel is used and why?","Architecture decision including quality, security, cost, region, lifecycle and exit considerations.",[2489,2490],"What happens if the provider is unavailable?","Degraded mode, fallback, refusal or continuity plan.",[2492,2493],"How is quality evaluated?","Task-specific datasets, graders, thresholds, regression criteria and validity conditions.",[2495,2496],"What is logged?","Telemetry schema, redaction, access, retention and audit purpose.",[2498,2499],"Who owns AI risk?","Named organizational responsibility connected to the concrete system.",[2501,2502],"What legal classification applies?","Documented assessment based on the current law and the actual use case.",[2504,2505],"How are model\u002Fprompt\u002Fretrieval changes approved?","Versioning, evaluation, architecture\u002Fchange record and rollout gate.",[2507,2508],"Who responds to an AI incident?","Runbook, technical owner, business\u002Fdomain escalation and provider escalation.",[2510,2511],"How is the system retired?","Data cleanup, access revocation, provider exit, evidence retention and dependency removal.",{},{"id":1267,"data":2514,"type":42,"tunes":2516},{"text":2515,"level":247},"Edge cases and limits",{},{"id":1272,"data":2518,"type":218,"tunes":2520},{"text":2519},"A small company with one low-risk AI use case may not need a formal enterprise AI architecture function. The same principles can be applied lightly: clear owner, approved data, explicit provider, basic evaluation, access control and operational responsibility.",{},{"id":1277,"data":2522,"type":218,"tunes":2524},{"text":2523},"A highly regulated organization may need stronger separation, independent validation, formal conformity processes, local hosting or air-gapped operation. Those controls are driven by the use case and regulatory environment, not by the word “enterprise.”",{},{"id":1282,"data":2526,"type":218,"tunes":2528},{"text":2527},"An organization can also use mostly SaaS AI products rather than building AI systems. Enterprise architecture still matters because identity, data access, contractual terms, shadow AI, retention, audit and supplier concentration remain organizational concerns.",{},{"id":1287,"data":2530,"type":218,"tunes":2532},{"text":2531},"A centralized platform is not mandatory. Federated platform ownership can be valid when domains have materially different requirements, provided enterprise-level identity, risk, inventory and interoperability responsibilities remain coherent.",{},{"id":1292,"data":2534,"type":42,"tunes":2536},{"text":2535,"level":247},"What would change this answer?",{},{"id":1297,"data":2538,"type":218,"tunes":2540},{"text":2539},"The architecture changes when the organization's risk tolerance, regulatory classification, data sensitivity, geographic scope, provider strategy, internal skills or business criticality changes. A public marketing assistant and a system participating in employment, finance, healthcare or critical infrastructure decisions should not inherit identical control models.",{},{"id":1302,"data":2542,"type":218,"tunes":2544},{"text":2543},"The implementation also changes as standards, regulation and AI platforms evolve. NIST AI RMF 1.0 is currently under revision, the EU AI Act has phased application dates, and model\u002Fprovider capabilities continue to change rapidly. Enterprise architecture should therefore preserve stable responsibility boundaries while treating provider mechanisms and regulatory details as versioned inputs.",{},{"id":1307,"data":2546,"type":42,"tunes":2548},{"text":2547,"level":247},"Related canonical knowledge",{},{"id":1312,"data":2550,"type":218,"tunes":2552},{"text":2551},"Enterprise AI architecture builds on solution and platform architecture. The solution layer explains one workload. The platform layer explains reusable AI capabilities. The enterprise layer connects both to organization-wide data, identity, governance, risk, procurement and operations.",{},{"id":1317,"data":2554,"type":218,"tunes":2556},{"text":2555},"Retrieval-Augmented Generation is only one mechanism inside this architecture. RAG can improve access to enterprise knowledge, but it does not solve data authority, permissions, governance or answer validity by itself.",{},{"id":1322,"data":2558,"type":1328,"tunes":2563},{"url":2559,"title":2560,"excerpt":2561,"ctaLabel":2562},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","What Is RAG? The Simplest Explanation of How It Works","A plain-English explanation of how external knowledge retrieval connects to the language model without turning retrieval into the source of truth.","Read the RAG foundation",{},{"id":1331,"data":2565,"type":218,"tunes":2567},{"text":2566},"For evidence-heavy enterprise use cases, answer validity also needs an explicit boundary: an output is only supported under the evidence, version, scope and assumptions that produced it.",{},{"id":1336,"data":2569,"type":1328,"tunes":2574},{"url":2570,"title":2571,"excerpt":2572,"ctaLabel":2573},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","A framework for making explicit the conditions under which an AI claim remains supported and what changes require restriction or recalculation.","Read the Answer Validity Boundary",{},{"id":1344,"data":2576,"type":218,"tunes":2578},{"text":2577},"Downstream enterprise topics include AI Governance, Private AI, Sovereign AI, Air-Gapped AI, Multi-Tenant AI Architecture, RBAC versus Tenant Isolation, Provider Abstraction, Model Routing and Production AI Architecture.",{},{"id":1349,"data":2580,"type":42,"tunes":2582},{"text":2581,"level":247},"Frequently asked questions",{},{"id":1354,"data":2584,"type":1354,"tunes":2611},{"items":2585,"title":2610},[2586,2589,2592,2595,2598,2601,2604,2607],{"id":1358,"answer":2587,"question":2588},"Enterprise AI architecture is the organization-wide architecture that defines how AI solutions and shared AI capabilities integrate with business ownership, enterprise data, identity, security, providers, governance, risk, compliance, lifecycle and operations.","What is enterprise AI architecture?",{"id":1362,"answer":2590,"question":2591},"No. An AI platform provides reusable technical capabilities such as model access, retrieval, agent runtimes and observability. Enterprise AI architecture defines how that platform and individual AI solutions fit into the organization's wider architecture and operating model.","Is enterprise AI architecture the same as an AI platform?",{"id":1366,"answer":2593,"question":2594},"No. Standardization can reduce complexity, but different workloads may require different providers, models, regions, control levels or modalities. The important requirement is explicit policy and lifecycle ownership.","Does enterprise AI require one central model?",{"id":1370,"answer":2596,"question":2597},"Because retrieved or generated information is not automatically authoritative. Enterprise systems need to preserve which source is the system of record, whether data is current, who may access it and how a generated claim can be traced back to evidence.","Why is data authority important for enterprise AI?",{"id":1374,"answer":2599,"question":2600},"AI governance defines policies, accountability and decision rights. Enterprise AI architecture defines the system boundaries, interfaces, data flows and technical mechanisms through which those policies can be implemented and evidenced.","What is the difference between AI governance and enterprise AI architecture?",{"id":1378,"answer":2602,"question":2603},"No. Obligations depend on factors such as the organization's role, the system's use case and classification, and the relevant provisions in force. Legal classification must be performed for the concrete system under the current law.","Does the EU AI Act apply to every enterprise AI system in the same way?",{"id":1382,"answer":2605,"question":2606},"No. A pilot demonstrates bounded capability. Enterprise deployment also needs identity, data authority, security, provider governance, evaluation, lifecycle, incident response, monitoring, compliance and accountable operational ownership.","Is a successful AI pilot enough for enterprise deployment?",{"id":1386,"answer":2608,"question":2609},"Only when the requirement justifies the added control and operational responsibility. Managed, private, sovereign, self-hosted and hybrid approaches are architecture options whose fit depends on data, regulatory, availability, cost, capability and operational requirements.","Should enterprises self-host AI?","Enterprise AI architecture FAQ",{},{"id":1392,"data":2613,"type":42,"tunes":2615},{"text":2614,"level":247},"Glossary",{},{"id":1397,"data":2617,"type":1397,"tunes":2647},{"title":2618,"entries":2619},"Key enterprise AI architecture terms",[2620,2623,2626,2628,2631,2634,2637,2639,2641,2644],{"term":2621,"anchor":1402,"definition":2622},"Enterprise AI architecture","Organization-wide architecture governing how AI systems, platforms, data, identities, providers, risk controls and operations fit together.",{"term":2624,"anchor":1406,"definition":2625},"AI management system","An organizational management system for establishing AI-related policies, objectives and processes; ISO\u002FIEC 42001 specifies requirements for such a system.",{"term":1909,"anchor":1409,"definition":2627},"The rule that identifies which source or system is authoritative for a particular fact, record, state or decision context.",{"term":2629,"anchor":1413,"definition":2630},"System of record","The authoritative system responsible for the official current state of a business record or domain entity.",{"term":2632,"anchor":1417,"definition":2633},"AI inventory","A structured record of AI use cases, owners, models\u002Fproviders, data, tools, risk, evaluation evidence, lifecycle state and related controls.",{"term":2635,"anchor":1421,"definition":2636},"Provider dependency","The technical, contractual and operational reliance created when an AI workload depends on an external model or managed platform.",{"term":2048,"anchor":1424,"definition":2638},"Defined human review, approval, intervention or escalation applied where system consequence, uncertainty or regulation requires it.",{"term":1427,"anchor":1428,"definition":2640},"Operational practices for generative-AI workloads covering model selection, prompts, grounding data, evaluation, deployment, monitoring and lifecycle management.",{"term":2642,"anchor":1432,"definition":2643},"AI risk management","The organizational process of identifying, assessing, treating, monitoring and revising risks associated with AI systems across their lifecycle.",{"term":2645,"anchor":1436,"definition":2646},"Architecture decision","A material design choice together with its context, rationale, alternatives, trade-offs and lifecycle status.",{},{"id":1440,"data":2649,"type":42,"tunes":2651},{"text":2650,"level":247},"Conclusion",{},{"id":1445,"data":2653,"type":218,"tunes":2655},{"text":2654},"When AI enters a company, the enterprise does not merely gain a new software component. It gains a new class of behavior and dependency that cuts across data, identity, suppliers, business decisions, security, operations, governance and change management.",{},{"id":1450,"data":2657,"type":218,"tunes":2659},{"text":2658},"The architectural response is not to centralize everything. It is to make responsibilities explicit: which data is authoritative, which identities may act, which providers are approved, which controls are shared, which decisions remain domain-owned, how behavior is evaluated, how incidents are handled and how the system changes over time.",{},{"id":1455,"data":2661,"type":218,"tunes":2663},{"text":2662},"That is the core distinction of enterprise AI architecture: it turns isolated AI capability into an organizationally governable system without pretending that models, platforms, business domains and enterprise controls are the same thing.",{},{"id":1460,"data":2665,"type":42,"tunes":2667},{"text":2666,"level":247},"Primary sources and current guidance",{},{"id":1465,"data":2669,"type":218,"tunes":2671},{"text":2670},"External standards, regulation and current vendor architecture guidance below were checked on 8 October 2026. Project-specific sections are explicitly marked as original project evidence and should not be read as claims of general industry fact.",{},{"id":1470,"data":2673,"type":1477,"tunes":2678},{"link":1472,"meta":2674},{"image":2675,"title":2676,"description":2677},{"url":278},"ISO\u002FIEC 42001:2023 — Artificial intelligence management system","International standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system within organizations.",{},{"id":1480,"data":2680,"type":1477,"tunes":2685},{"link":1482,"meta":2681},{"image":2682,"title":2683,"description":2684},{"url":278},"ISO\u002FIEC 23894:2023 — Guidance on AI risk management","International guidance for integrating AI-specific risk management into organizational activities and functions.",{},{"id":1489,"data":2687,"type":1477,"tunes":2692},{"link":1491,"meta":2688},{"image":2689,"title":2690,"description":2691},{"url":278},"NIST AI Risk Management Framework","NIST's voluntary lifecycle-oriented framework for managing AI risk. NIST states that AI RMF 1.0 is currently being revised.",{},{"id":1498,"data":2694,"type":1477,"tunes":2699},{"link":1500,"meta":2695},{"image":2696,"title":2697,"description":2698},{"url":278},"NIST AI 600-1 — Generative AI Profile","NIST companion profile describing generative-AI-specific risks and risk-management actions aligned to the AI RMF.",{},{"id":1507,"data":2701,"type":1477,"tunes":2706},{"link":1509,"meta":2702},{"image":2703,"title":2704,"description":2705},{"url":278},"EUR-Lex — Regulation (EU) 2024\u002F1689, consolidated text","Current consolidated AI Act text used for application dates and regulatory structure as checked on 8 October 2026.",{},{"id":1516,"data":2708,"type":1477,"tunes":2713},{"link":1518,"meta":2709},{"image":2710,"title":2711,"description":2712},{"url":278},"European Commission — AI Act regulatory framework","Current Commission overview of AI Act application phases, including 2026 applicability and later dates for specified high-risk provisions.",{},{"id":1525,"data":2715,"type":1477,"tunes":2720},{"link":1527,"meta":2716},{"image":2717,"title":2718,"description":2719},{"url":278},"Microsoft Azure Well-Architected — AI workloads","Current architecture guidance on AI workloads, including nondeterministic behavior, data, application design and operations.",{},{"id":1534,"data":2722,"type":1477,"tunes":2727},{"link":1536,"meta":2723},{"image":2724,"title":2725,"description":2726},{"url":278},"Microsoft — MLOps and GenAIOps for AI workloads","Current guidance on operational lifecycle, data, model maintenance, deployment, monitoring and continuous evolution.",{},{"id":1543,"data":2729,"type":1477,"tunes":2734},{"link":1545,"meta":2730},{"image":2731,"title":2732,"description":2733},{"url":278},"Microsoft — Responsible AI in Azure workloads","Current guidance connecting AI policy to data control, identity, agent auditability, role-based access and operational safeguards.",{},{"id":1552,"data":2736,"type":1477,"tunes":2741},{"link":1554,"meta":2737},{"image":2738,"title":2739,"description":2740},{"url":278},"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description","Current architecture-description standard supporting explicit concerns, viewpoints and relationships across system architecture.",{},"2.31.6","Enterprise AI architecture explains how AI changes company systems across data authority, identity, permissions, providers, risk, governance, evaluation, compliance and operations.",{"lang":7,"title":208,"content":210,"contentJson":2745,"excerpt":1561},{"time":212,"blocks":2746,"version":1560},[2747,2750,2753,2756,2759,2762,2765,2768,2771,2774,2790,2793,2796,2799,2802,2812,2815,2818,2821,2824,2827,2830,2833,2836,2839,2842,2845,2848,2851,2854,2857,2860,2863,2866,2869,2872,2875,2878,2881,2884,2887,2890,2893,2896,2899,2902,2905,2908,2911,2914,2917,2920,2923,2926,2929,2932,2935,2938,2941,2944,2959,2962,2965,2968,2981,2984,2987,2999,3002,3005,3021,3024,3037,3040,3043,3046,3049,3052,3055,3058,3071,3074,3085,3088,3091,3094,3106,3109,3112,3115,3118,3121,3124,3127,3130,3133,3136,3139,3142,3145,3157,3160,3163,3166,3169,3180,3183,3186,3202,3205,3218,3221,3237,3240,3259,3262,3265,3268,3271,3274,3277,3280,3283,3286,3289,3292,3295,3298,3301,3304,3307,3319,3322,3336,3339,3342,3345,3348,3351,3354,3359,3364,3369,3374,3379,3384,3389,3394,3399],{"id":215,"data":2748,"type":218,"tunes":2749},{"text":217},{},{"id":221,"data":2751,"type":226,"tunes":2752},{"body":223,"title":224,"variant":225},{},{"id":229,"data":2754,"type":226,"tunes":2755},{"body":231,"title":232,"variant":233},{},{"id":236,"data":2757,"type":226,"tunes":2758},{"body":238,"title":239,"variant":240},{},{"id":243,"data":2760,"type":248,"tunes":2761},{"title":245,"maxLevel":246,"minLevel":247},{},{"id":251,"data":2763,"type":42,"tunes":2764},{"text":253,"level":247},{},{"id":256,"data":2766,"type":218,"tunes":2767},{"text":258},{},{"id":261,"data":2769,"type":218,"tunes":2770},{"text":263},{},{"id":266,"data":2772,"type":218,"tunes":2773},{"text":268},{},{"id":271,"data":2775,"type":303,"tunes":2789},{"rows":2776,"title":291,"layout":292,"columns":2785},[2777,2779,2781,2783],{"id":275,"label":276,"values":2778},[278,278,278],{"id":280,"label":281,"values":2780},[278,278,278],{"id":284,"label":285,"values":2782},[278,278,278],{"id":288,"label":289,"values":2784},[278,278,278],[2786,2787,2788],{"id":295,"label":296},{"id":298,"label":299},{"id":301,"label":302},{},{"id":306,"data":2791,"type":42,"tunes":2792},{"text":308,"level":247},{},{"id":311,"data":2794,"type":218,"tunes":2795},{"text":313},{},{"id":316,"data":2797,"type":218,"tunes":2798},{"text":318},{},{"id":321,"data":2800,"type":218,"tunes":2801},{"text":323},{},{"id":326,"data":2803,"type":349,"tunes":2811},{"steps":2804,"title":347,"orientation":348},[2805,2806,2807,2808,2809,2810],{"label":330,"description":331},{"label":333,"description":334},{"label":336,"description":337},{"label":339,"description":340},{"label":342,"description":343},{"label":345,"description":346},{},{"id":352,"data":2813,"type":42,"tunes":2814},{"text":354,"level":247},{},{"id":357,"data":2816,"type":218,"tunes":2817},{"text":359},{},{"id":362,"data":2819,"type":218,"tunes":2820},{"text":364},{},{"id":367,"data":2822,"type":42,"tunes":2823},{"text":369,"level":247},{},{"id":372,"data":2825,"type":42,"tunes":2826},{"text":374,"level":246},{},{"id":377,"data":2828,"type":218,"tunes":2829},{"text":379},{},{"id":382,"data":2831,"type":218,"tunes":2832},{"text":384},{},{"id":387,"data":2834,"type":42,"tunes":2835},{"text":389,"level":246},{},{"id":392,"data":2837,"type":218,"tunes":2838},{"text":394},{},{"id":397,"data":2840,"type":218,"tunes":2841},{"text":399},{},{"id":402,"data":2843,"type":218,"tunes":2844},{"text":404},{},{"id":407,"data":2846,"type":226,"tunes":2847},{"body":409,"title":410,"variant":288},{},{"id":413,"data":2849,"type":42,"tunes":2850},{"text":415,"level":246},{},{"id":418,"data":2852,"type":218,"tunes":2853},{"text":420},{},{"id":423,"data":2855,"type":218,"tunes":2856},{"text":425},{},{"id":428,"data":2858,"type":218,"tunes":2859},{"text":430},{},{"id":433,"data":2861,"type":42,"tunes":2862},{"text":435,"level":246},{},{"id":438,"data":2864,"type":218,"tunes":2865},{"text":440},{},{"id":443,"data":2867,"type":218,"tunes":2868},{"text":445},{},{"id":448,"data":2870,"type":42,"tunes":2871},{"text":450,"level":246},{},{"id":453,"data":2873,"type":218,"tunes":2874},{"text":455},{},{"id":458,"data":2876,"type":218,"tunes":2877},{"text":460},{},{"id":463,"data":2879,"type":218,"tunes":2880},{"text":465},{},{"id":468,"data":2882,"type":42,"tunes":2883},{"text":470,"level":246},{},{"id":473,"data":2885,"type":218,"tunes":2886},{"text":475},{},{"id":478,"data":2888,"type":218,"tunes":2889},{"text":480},{},{"id":483,"data":2891,"type":218,"tunes":2892},{"text":485},{},{"id":488,"data":2894,"type":42,"tunes":2895},{"text":490,"level":246},{},{"id":493,"data":2897,"type":218,"tunes":2898},{"text":495},{},{"id":498,"data":2900,"type":218,"tunes":2901},{"text":500},{},{"id":503,"data":2903,"type":42,"tunes":2904},{"text":505,"level":246},{},{"id":508,"data":2906,"type":218,"tunes":2907},{"text":510},{},{"id":513,"data":2909,"type":218,"tunes":2910},{"text":515},{},{"id":518,"data":2912,"type":218,"tunes":2913},{"text":520},{},{"id":523,"data":2915,"type":42,"tunes":2916},{"text":525,"level":246},{},{"id":528,"data":2918,"type":218,"tunes":2919},{"text":530},{},{"id":533,"data":2921,"type":218,"tunes":2922},{"text":535},{},{"id":538,"data":2924,"type":42,"tunes":2925},{"text":540,"level":246},{},{"id":543,"data":2927,"type":218,"tunes":2928},{"text":545},{},{"id":548,"data":2930,"type":218,"tunes":2931},{"text":550},{},{"id":553,"data":2933,"type":42,"tunes":2934},{"text":555,"level":246},{},{"id":558,"data":2936,"type":218,"tunes":2937},{"text":560},{},{"id":563,"data":2939,"type":218,"tunes":2940},{"text":565},{},{"id":568,"data":2942,"type":42,"tunes":2943},{"text":570,"level":247},{},{"id":573,"data":2945,"type":292,"tunes":2958},{"content":2946,"stretched":43,"withHeadings":14},[2947,2948,2949,2950,2951,2952,2953,2954,2955,2956,2957],[577,578,579],[581,582,583],[585,586,587],[589,590,591],[593,594,595],[597,598,599],[601,602,603],[605,606,607],[609,610,611],[613,614,615],[617,618,619],{},{"id":622,"data":2960,"type":226,"tunes":2961},{"body":624,"title":625,"variant":233},{},{"id":628,"data":2963,"type":42,"tunes":2964},{"text":630,"level":247},{},{"id":633,"data":2966,"type":226,"tunes":2967},{"body":635,"title":636,"variant":240},{},{"id":639,"data":2969,"type":292,"tunes":2980},{"content":2970,"stretched":43,"withHeadings":14},[2971,2972,2973,2974,2975,2976,2977,2978,2979],[643,644],[646,647],[649,650],[652,653],[655,656],[658,659],[661,662],[664,665],[667,668],{},{"id":671,"data":2982,"type":218,"tunes":2983},{"text":673},{},{"id":676,"data":2985,"type":42,"tunes":2986},{"text":678,"level":247},{},{"id":681,"data":2988,"type":349,"tunes":2998},{"steps":2989,"title":708,"orientation":348},[2990,2991,2992,2993,2994,2995,2996,2997],{"label":685,"description":686},{"label":688,"description":689},{"label":691,"description":692},{"label":694,"description":695},{"label":697,"description":698},{"label":700,"description":701},{"label":703,"description":704},{"label":706,"description":707},{},{"id":711,"data":3000,"type":42,"tunes":3001},{"text":713,"level":247},{},{"id":716,"data":3003,"type":218,"tunes":3004},{"text":718},{},{"id":721,"data":3006,"type":292,"tunes":3020},{"content":3007,"stretched":43,"withHeadings":14},[3008,3009,3010,3011,3012,3013,3014,3015,3016,3017,3018,3019],[725,726],[728,729],[731,732],[734,735],[737,738],[740,741],[743,744],[746,747],[749,750],[752,753],[755,756],[758,759],{},{"id":762,"data":3022,"type":42,"tunes":3023},{"text":764,"level":247},{},{"id":767,"data":3025,"type":303,"tunes":3036},{"rows":3026,"title":782,"layout":292,"columns":3033},[3027,3029,3031],{"id":771,"label":772,"values":3028},[278,278],{"id":775,"label":776,"values":3030},[278,278],{"id":779,"label":780,"values":3032},[278,278],[3034,3035],{"id":785,"label":786},{"id":788,"label":302},{},{"id":791,"data":3038,"type":42,"tunes":3039},{"text":793,"level":247},{},{"id":796,"data":3041,"type":218,"tunes":3042},{"text":798},{},{"id":801,"data":3044,"type":218,"tunes":3045},{"text":803},{},{"id":806,"data":3047,"type":218,"tunes":3048},{"text":808},{},{"id":811,"data":3050,"type":226,"tunes":3051},{"body":813,"title":814,"variant":240},{},{"id":817,"data":3053,"type":42,"tunes":3054},{"text":819,"level":247},{},{"id":822,"data":3056,"type":218,"tunes":3057},{"text":824},{},{"id":827,"data":3059,"type":292,"tunes":3070},{"content":3060,"stretched":43,"withHeadings":14},[3061,3062,3063,3064,3065,3066,3067,3068,3069],[831,832],[834,835],[837,838],[840,841],[843,844],[846,847],[849,850],[852,853],[855,856],{},{"id":859,"data":3072,"type":42,"tunes":3073},{"text":861,"level":247},{},{"id":864,"data":3075,"type":292,"tunes":3084},{"content":3076,"stretched":43,"withHeadings":14},[3077,3078,3079,3080,3081,3082,3083],[868,869],[871,872],[874,875],[877,878],[880,881],[883,884],[886,887],{},{"id":890,"data":3086,"type":218,"tunes":3087},{"text":892},{},{"id":895,"data":3089,"type":42,"tunes":3090},{"text":897,"level":247},{},{"id":900,"data":3092,"type":218,"tunes":3093},{"text":902},{},{"id":905,"data":3095,"type":349,"tunes":3105},{"steps":3096,"title":932,"orientation":348},[3097,3098,3099,3100,3101,3102,3103,3104],{"label":909,"description":910},{"label":912,"description":913},{"label":915,"description":916},{"label":918,"description":919},{"label":921,"description":922},{"label":924,"description":925},{"label":927,"description":928},{"label":930,"description":931},{},{"id":935,"data":3107,"type":42,"tunes":3108},{"text":937,"level":247},{},{"id":940,"data":3110,"type":218,"tunes":3111},{"text":942},{},{"id":945,"data":3113,"type":218,"tunes":3114},{"text":947},{},{"id":950,"data":3116,"type":226,"tunes":3117},{"body":952,"title":953,"variant":288},{},{"id":956,"data":3119,"type":42,"tunes":3120},{"text":958,"level":247},{},{"id":961,"data":3122,"type":218,"tunes":3123},{"text":963},{},{"id":966,"data":3125,"type":218,"tunes":3126},{"text":968},{},{"id":971,"data":3128,"type":42,"tunes":3129},{"text":973,"level":247},{},{"id":976,"data":3131,"type":226,"tunes":3132},{"body":978,"title":979,"variant":240},{},{"id":982,"data":3134,"type":218,"tunes":3135},{"text":984},{},{"id":987,"data":3137,"type":218,"tunes":3138},{"text":989},{},{"id":992,"data":3140,"type":218,"tunes":3141},{"text":994},{},{"id":997,"data":3143,"type":218,"tunes":3144},{"text":999},{},{"id":1002,"data":3146,"type":292,"tunes":3156},{"content":3147,"stretched":43,"withHeadings":14},[3148,3149,3150,3151,3152,3153,3154,3155],[1006,1007],[1009,1010],[1012,1013],[1015,1016],[1018,1019],[1021,1022],[1024,1025],[1027,1028],{},{"id":1031,"data":3158,"type":42,"tunes":3159},{"text":1033,"level":247},{},{"id":1036,"data":3161,"type":218,"tunes":3162},{"text":1038},{},{"id":1041,"data":3164,"type":218,"tunes":3165},{"text":1043},{},{"id":1046,"data":3167,"type":42,"tunes":3168},{"text":1048,"level":247},{},{"id":1051,"data":3170,"type":292,"tunes":3179},{"content":3171,"stretched":43,"withHeadings":14},[3172,3173,3174,3175,3176,3177,3178],[1055,1056],[1058,1059],[1061,1062],[1064,1065],[1067,1068],[1070,1071],[1073,1074],{},{"id":1077,"data":3181,"type":218,"tunes":3182},{"text":1079},{},{"id":1082,"data":3184,"type":42,"tunes":3185},{"text":1084,"level":247},{},{"id":1087,"data":3187,"type":292,"tunes":3201},{"content":3188,"stretched":43,"withHeadings":14},[3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200],[1091,1092],[1094,1095],[1097,1098],[1100,1101],[1103,1104],[1106,1107],[1109,1110],[1112,1113],[1115,1116],[1118,1119],[1121,1122],[1124,1125],{},{"id":1128,"data":3203,"type":42,"tunes":3204},{"text":1130,"level":247},{},{"id":1133,"data":3206,"type":292,"tunes":3217},{"content":3207,"stretched":43,"withHeadings":14},[3208,3209,3210,3211,3212,3213,3214,3215,3216],[1137,1138],[1140,1141],[1143,1144],[1146,1147],[1149,1150],[1152,1153],[1155,1156],[1158,1159],[1161,1162],{},{"id":1165,"data":3219,"type":42,"tunes":3220},{"text":1167,"level":247},{},{"id":1170,"data":3222,"type":349,"tunes":3236},{"steps":3223,"title":1209,"orientation":348},[3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235],{"label":1174,"description":1175},{"label":1177,"description":1178},{"label":1180,"description":1181},{"label":1183,"description":1184},{"label":1186,"description":1187},{"label":1189,"description":1190},{"label":1192,"description":1193},{"label":1195,"description":1196},{"label":1198,"description":1199},{"label":1201,"description":1202},{"label":1204,"description":1205},{"label":1207,"description":1208},{},{"id":1212,"data":3238,"type":42,"tunes":3239},{"text":1214,"level":247},{},{"id":1217,"data":3241,"type":292,"tunes":3258},{"content":3242,"stretched":43,"withHeadings":14},[3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257],[1221,1222],[1224,1225],[1227,1228],[1230,1231],[1233,1234],[1236,1237],[1239,1240],[1242,1243],[1245,1246],[1248,1249],[1251,1252],[1254,1255],[1257,1258],[1260,1261],[1263,1264],{},{"id":1267,"data":3260,"type":42,"tunes":3261},{"text":1269,"level":247},{},{"id":1272,"data":3263,"type":218,"tunes":3264},{"text":1274},{},{"id":1277,"data":3266,"type":218,"tunes":3267},{"text":1279},{},{"id":1282,"data":3269,"type":218,"tunes":3270},{"text":1284},{},{"id":1287,"data":3272,"type":218,"tunes":3273},{"text":1289},{},{"id":1292,"data":3275,"type":42,"tunes":3276},{"text":1294,"level":247},{},{"id":1297,"data":3278,"type":218,"tunes":3279},{"text":1299},{},{"id":1302,"data":3281,"type":218,"tunes":3282},{"text":1304},{},{"id":1307,"data":3284,"type":42,"tunes":3285},{"text":1309,"level":247},{},{"id":1312,"data":3287,"type":218,"tunes":3288},{"text":1314},{},{"id":1317,"data":3290,"type":218,"tunes":3291},{"text":1319},{},{"id":1322,"data":3293,"type":1328,"tunes":3294},{"url":1324,"title":1325,"excerpt":1326,"ctaLabel":1327},{},{"id":1331,"data":3296,"type":218,"tunes":3297},{"text":1333},{},{"id":1336,"data":3299,"type":1328,"tunes":3300},{"url":1338,"title":1339,"excerpt":1340,"ctaLabel":1341},{},{"id":1344,"data":3302,"type":218,"tunes":3303},{"text":1346},{},{"id":1349,"data":3305,"type":42,"tunes":3306},{"text":1351,"level":247},{},{"id":1354,"data":3308,"type":1354,"tunes":3318},{"items":3309,"title":1389},[3310,3311,3312,3313,3314,3315,3316,3317],{"id":1358,"answer":1359,"question":1360},{"id":1362,"answer":1363,"question":1364},{"id":1366,"answer":1367,"question":1368},{"id":1370,"answer":1371,"question":1372},{"id":1374,"answer":1375,"question":1376},{"id":1378,"answer":1379,"question":1380},{"id":1382,"answer":1383,"question":1384},{"id":1386,"answer":1387,"question":1388},{},{"id":1392,"data":3320,"type":42,"tunes":3321},{"text":1394,"level":247},{},{"id":1397,"data":3323,"type":1397,"tunes":3335},{"title":1399,"entries":3324},[3325,3326,3327,3328,3329,3330,3331,3332,3333,3334],{"term":302,"anchor":1402,"definition":1403},{"term":1405,"anchor":1406,"definition":1407},{"term":597,"anchor":1409,"definition":1410},{"term":1412,"anchor":1413,"definition":1414},{"term":1416,"anchor":1417,"definition":1418},{"term":1420,"anchor":1421,"definition":1422},{"term":746,"anchor":1424,"definition":1425},{"term":1427,"anchor":1428,"definition":1429},{"term":1431,"anchor":1432,"definition":1433},{"term":1435,"anchor":1436,"definition":1437},{},{"id":1440,"data":3337,"type":42,"tunes":3338},{"text":1442,"level":247},{},{"id":1445,"data":3340,"type":218,"tunes":3341},{"text":1447},{},{"id":1450,"data":3343,"type":218,"tunes":3344},{"text":1452},{},{"id":1455,"data":3346,"type":218,"tunes":3347},{"text":1457},{},{"id":1460,"data":3349,"type":42,"tunes":3350},{"text":1462,"level":247},{},{"id":1465,"data":3352,"type":218,"tunes":3353},{"text":1467},{},{"id":1470,"data":3355,"type":1477,"tunes":3358},{"link":1472,"meta":3356},{"image":3357,"title":1475,"description":1476},{"url":278},{},{"id":1480,"data":3360,"type":1477,"tunes":3363},{"link":1482,"meta":3361},{"image":3362,"title":1485,"description":1486},{"url":278},{},{"id":1489,"data":3365,"type":1477,"tunes":3368},{"link":1491,"meta":3366},{"image":3367,"title":1494,"description":1495},{"url":278},{},{"id":1498,"data":3370,"type":1477,"tunes":3373},{"link":1500,"meta":3371},{"image":3372,"title":1503,"description":1504},{"url":278},{},{"id":1507,"data":3375,"type":1477,"tunes":3378},{"link":1509,"meta":3376},{"image":3377,"title":1512,"description":1513},{"url":278},{},{"id":1516,"data":3380,"type":1477,"tunes":3383},{"link":1518,"meta":3381},{"image":3382,"title":1521,"description":1522},{"url":278},{},{"id":1525,"data":3385,"type":1477,"tunes":3388},{"link":1527,"meta":3386},{"image":3387,"title":1530,"description":1531},{"url":278},{},{"id":1534,"data":3390,"type":1477,"tunes":3393},{"link":1536,"meta":3391},{"image":3392,"title":1539,"description":1540},{"url":278},{},{"id":1543,"data":3395,"type":1477,"tunes":3398},{"link":1545,"meta":3396},{"image":3397,"title":1548,"description":1549},{"url":278},{},{"id":1552,"data":3400,"type":1477,"tunes":3403},{"link":1554,"meta":3401},{"image":3402,"title":1557,"description":1558},{"url":278},{},"Post erfolgreich abgerufen",{"items":3406,"source":3491,"manualIds":3492,"manualMatchedIds":3493},[3407,3414,3421,3428,3435,3442,3449,3456,3463,3470,3477,3484],{"id":3408,"slug":3409,"title":3410,"excerpt":3411,"featuredImage":3412,"publishedAt":3413},"490","rbac-vs-tenant-isolation-two-different-security-boundaries","RBAC与租户隔离：两种不同的安全边界","RBAC 控制用户可以做什么；租户隔离控制该操作可以触及哪个租户的资源。了解为什么多租户 SaaS 安全需要这两道边界。","\u002Fuploads\u002F2026\u002F10\u002Frbac-vs-tenant-isolation-two-different-security-boundaries-1791485111528-qqtzby.webp","2026-10-08T14:43:00.000Z",{"id":3415,"slug":3416,"title":3417,"excerpt":3418,"featuredImage":3419,"publishedAt":3420},"478","what-is-rag-the-simplest-explanation-of-how-it-works","什么是RAG？对其工作原理的最简单解释","RAG听起来很复杂，但想法很简单：在AI回答之前，它先从知识源查找有用的信息，并将该信息提供给语言模型。本指南使用一个简单的思维模型来解释RAG、LLM、状态、记忆和工具。","\u002Fuploads\u002F2026\u002F09\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works-1790377492124-khjagt.webp","2026-09-25T19:03:00.000Z",{"id":3422,"slug":3423,"title":3424,"excerpt":3425,"featuredImage":3426,"publishedAt":3427},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","什么是AI平台架构师？模型、数据、运行时、安全与运维","AI平台架构师负责跨模型、提供商、检索、智能体、身份、安全、评估、可观测性和运营设计可复用的AI基础。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":3429,"slug":3430,"title":3431,"excerpt":3432,"featuredImage":3433,"publishedAt":3434},"381","enterprise-grade-multi-tenant-architecture-for-an-international-platform","企业级多租户架构，适用于国际平台","Loving Rocks 是一款企业级婚礼平台，采用真正的多租户架构设计，实现租户间数据库隔离，并内置国际化支持，以确保全球可扩展性、安全性及长期运营稳定性。","\u002Fuploads\u002F2026\u002F01\u002Fenterprise-grade-multi-tenant-architecture-for-an-international-platform-1769789121298-b6v7ak.webp","2026-01-30T12:04:00.000Z",{"id":3436,"slug":3437,"title":3438,"excerpt":3439,"featuredImage":3440,"publishedAt":3441},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","向量数据库、嵌入和重排序：检索的三个不同部分","嵌入表示含义，向量数据库检索候选结果，重排序器则精炼结果。了解这三个检索层在RAG中如何不同并协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":3443,"slug":3444,"title":3445,"excerpt":3446,"featuredImage":3447,"publishedAt":3448},"495","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","主权人工智能：模型、数据、基础设施与依赖关系的控制","主权人工智能关乎对模型、数据、基础设施、软件、运营和战略依赖的有效控制——而不仅仅是人工智能模型托管在哪里。","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","2026-10-08T15:45:00.000Z",{"id":3450,"slug":3451,"title":3452,"excerpt":3453,"featuredImage":3454,"publishedAt":3455},"480","when-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger","人工智能何时应停止信任自身知识？——检索触发机制","AI 模型并非每个问题都需要检索。重要的问题在于知道何时其内部知识已不再足够。检索触发器是一个实用的决策边界，它决定 AI 系统何时应停止仅依赖模型知识，并在回答前获取外部证据。","\u002Fuploads\u002F2026\u002F09\u002Fwhen-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger-1790574991244-f4rpyg.webp","2026-09-28T01:49:00.000Z",{"id":3457,"slug":3458,"title":3459,"excerpt":3460,"featuredImage":3461,"publishedAt":3462},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP 解析：它连接什么、不做什么以及它适用于何处","模型上下文协议通过标准的客户端-服务器边界，将AI应用程序连接到外部工具、资源和提示。了解MCP能做什么、不能做什么，以及它在智能体架构中的定位。","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":3464,"slug":3465,"title":3466,"excerpt":3467,"featuredImage":3468,"publishedAt":3469},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","什么是AI解决方案架构师？系统边界、职责与权衡","AI解决方案架构师将业务需求转化为生产就绪的AI系统，涵盖数据、模型、工具、安全、运行时、评估和运维。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":3471,"slug":3472,"title":3473,"excerpt":3474,"featuredImage":3475,"publishedAt":3476},"481","generative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing","生成式人工智能解析：模型、检索、工具与应用并非同一回事","生成式AI不仅仅是一个模型。了解模型、检索、工具、上下文、运行时和应用程序如何在生产AI系统中协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fgenerative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing-1791475411822-pp0dvz.webp","2026-10-08T12:00:00.000Z",{"id":3478,"slug":3479,"title":3480,"excerpt":3481,"featuredImage":3482,"publishedAt":3483},"494","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","气隙AI：AI系统如何在没有互联网或云访问的情况下工作","气隙AI在隔离的安全域内运行模型、RAG和AI应用，无需互联网或云依赖。了解模型、数据、更新和工具如何离线运行。","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","2026-10-08T11:32:00.000Z",{"id":3485,"slug":3486,"title":3487,"excerpt":3488,"featuredImage":3489,"publishedAt":3490},"460","ai-agent-reliability-why-the-final-answer-is-not-enough","AI Agent可靠性：为什么最终答案并不足够","正确的输出并不能证明推理的正确性、执行的安全性，或系统的可信赖性。","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-reliability-why-the-final-answer-is-not-enough-1788955466306-pl0qhz.webp","2026-09-09T04:01:00.000Z","fallback",[],[]]