Most large enterprises have adopted AI in some form, yet few can point to measurable financial return on that investment. The gap, argues Pankaj Vyas, MD & CEO of Siemens Technology and Services, isn’t a technology problem; it’s an operating-model problem. Adding AI to legacy workflows delivers isolated productivity gains, not transformation. In this conversation, Vyas unpacks why fragmented data remains enterprises’ most neglected weak link, how accountability must shift “upstream” as AI agents move from assisting to acting autonomously, and why performance metrics built for a pre-AI workforce are quietly holding organisations back. He also explains the mechanics of “pilot purgatory” and the three shifts needed to escape it, plus what talent architecture looks like when roles are unbundled into tasks rather than eliminated wholesale. Drawing on Siemens Technology and Services’ internal transformation, Vyas argues that speed without governance is not readiness, and that real value demands redesigning work, not just inserting AI into it.

MD & CEO
Siemens Technology and Services
CISO Forum: McKinsey’s numbers show a wide adoption-versus-impact gap in near-universal AI use, but only a minority are seeing real financial return. From where you sit, what’s causing that gap inside large enterprises?
Pankaj Vyas: An enterprise can introduce AI into individual tasks and see an immediate productivity benefit. But that does not automatically translate into enterprise-wide transformation.
An organisation must redesign how it operates when human and non-human intelligence work together. Many enterprises continue to add AI to existing processes, structures and ways of working. That yields incremental gains, but it does not lead to business model innovation or new value creation. Unlocking those gains requires a fundamental shift in how organisations think about four building blocks: people, infrastructure, data and governance. They cannot be treated as separate AI programmes. AI fluency must spread across the workforce; data needs to be trusted and accessible; infrastructure must support scale; and governance must provide the confidence to deploy responsibly.
Organisations can create sustained value and move beyond pilots by architecting the enterprise around intelligence. The question is no longer where to apply AI. It is how to turn intelligent technology into measurable business outcomes by understanding the existing operating model and rebuilding the right parts of it.
CISO Forum: You talk about four pillars: people, infrastructure, data and governance that need to be built simultaneously. Which of these is most neglected, and what does that neglect look like in practice?
Pankaj Vyas: Many organisations are investing in models, tools and infrastructure, but the underlying data ecosystem is still fragmented. Data sits across functions, legacy systems and different repositories, with inconsistent definitions, limited accessibility and unclear ownership.
You can have strong AI capability and still get a poor business outcome if the data feeding it is incomplete, inconsistent, or hard to access. In practice, this means teams spend too much time cleaning, reconciling and validating data before they can use it. It also makes it difficult to move from a successful pilot to a solution that works reliably across the enterprise. The foundation must be a trusted data environment, with clear ownership, appropriate access and the right governance. Data also needs to be available in a form that can be used across business and engineering workflows, while respecting security, privacy and regulatory requirements.
AI does not create value in isolation. The quality, accessibility and trustworthiness of the data determine whether that capability can be embedded into how the enterprise operates.
CISO Forum: Why isn’t incremental automation enough anymore? What specifically breaks in an organisation’s operating model when it tries to bolt AI agents onto legacy processes rather than redesigning around them?
Pankaj Vyas: Incremental automation optimises pieces of a process that was designed for a world without AI. When AI agents become part of the workflow, simply adding them to existing processes can create new bottlenecks rather than removing them.
The underlying issue is that many processes were designed around human effort, with decisions, approvals and handoffs structured accordingly. If an agent can analyse information or initiate an action much faster but still has to move through the same layers of approval, functional silos and legacy systems, the organisation does not capture the full benefit. In some cases, it simply creates another layer of complexity.
To enable seamless collaboration between humans and AI agents, roles and decision rights need to be clearer, workflows need to be redesigned around outcomes, and technology, data and business teams need to work more closely together. The question is not where an agent can be inserted into an existing process. It is which parts of the process should exist at all when human and non-human intelligence are working together.
CISO Forum: As AI moves from copilot to autonomous agent, decision rights start shifting. How should leadership structures and accountability change when an agent, not a person, is initiating actions?
Pankaj Vyas: As AI moves from assisting people to initiating actions, the question of accountability becomes much more important. Organisations need to define what an agent can decide and execute independently, where human approval is required, and where an agent should not act at all. Those boundaries will vary by the risk and consequence of the decision. In safety-critical or high-impact situations, human decision authority remains essential. When an agent initiates an action, accountability shifts upstream to whoever defined the agent’s permissions, boundaries, and the conditions under which it could act. Engineering teams need an owner for that authorisation layer, not just an owner for outcomes.
This also requires changes to leadership structures. Leaders need visibility into how agents are operating, what data they are using, what decisions they are making and when humans are intervening. Governance cannot happen after deployment. It must be built into the operating model from the start, and leadership needs to build that governance in step with the teams actually running the process, not apart from them.
CISO Forum: What does a redesigned performance metric look like for a Human + AI workforce? Are enterprises still measuring people against pre-AI benchmarks without realising it?
Pankaj Vyas: Many organisations still measure people against metrics designed for a workforce where humans did most of the analysis and execution themselves. That becomes less relevant when AI is taking on parts of the workflow.
The focus should shift to the outcome created when humans and AI work together. That could be productivity, quality, speed of decision-making or the value delivered to the customer, depending on the role. The key point is that we should measure results, not simply the amount of activity an individual performs. This does not reduce human accountability. In fact, it makes judgement and decision-making more important. If AI handles repetitive work, people can spend more time on problem-solving, innovation, collaboration and decisions that require context and experience. Performance measures should recognise that shift.
It also means leaders need to understand where AI is actually improving the workflow and where human intervention remains essential. Otherwise, organisations risk adopting new technology while still managing people based on old assumptions.
The objective is not only to align the metrics but also to measure how effectively the enterprise creates value when human and non-human intelligence work together, and to redesign existing roles to move beyond simple technology adoption and achieve true business impact.
CISO Forum: You’ve emphasised AI fluency across the entire workforce over specialist AI talent. How do you build that fluency at scale without diluting depth where it’s genuinely needed?
Pankaj Vyas: The objective is to create an AI-native workforce where people understand how AI can be applied to their work, what its limitations are and how to work with it responsibly. That requires a balanced approach. Organisations need deep expertise in areas such as AI research, engineering, data and architecture. Still, they also need people across functions who can adopt these capabilities in their day-to-day work. This is a combination of researchers, developers and adopters, rather than trying to turn the entire workforce into AI scientists.
Building that fluency at scale requires continuous learning and adaptability. It has to be part of how people work, supported by structured learning, collaboration and practical application, rather than being treated as a one-time training programme.
At the same time, specialist depth should continue to be strengthened through expert communities, partnerships with academia and institutions, and focused development in areas where deeper technical capability is essential. The balance is important. Broad AI literacy allows the organisation to use intelligence effectively across functions. At the same time, specialist expertise ensures that the technology is engineered with the depth, discipline and judgement required to create real value.
CISO Forum: Speed of transformation is now a competitive advantage. What’s the risk calculus? How does an enterprise move fast on AI deployment without compounding governance and data risk?
Pankaj Vyas: Speed matters because the pace of AI development is much faster than traditional technology cycles. But moving quickly does not mean lowering the standards for security, data or governance. It means building those controls into the way AI is designed and deployed.
Companies need to establish clear boundaries around how data can be used, what decisions an AI system can make and where human oversight is required. Data needs to be trusted, protected and accessible to the right people and systems. Governance should also cover how AI outputs are validated, how misuse is managed and how autonomous systems operate within defined limits.
Competitive pressure is driving adoption today, but you need to build a foundation that can support it. While speed has become the visible marker of progress, it is not the same as readiness. Data quality remains one of the biggest implementation barriers; deploy AI with incident-response playbooks for failure, adversarial testing, and privacy and consent baked into the system from the outset. If these critical aspects are left unaddressed, risk expands at the same pace as the deployment.
The objective should be to create a repeatable model in which experimentation can proceed quickly, while the path to production remains controlled and accountable. Speed is important, but speed without trust does not create sustainable enterprise value.
CISO Forum: “Pilot purgatory” is a phrase getting a lot of use in this conversation. What’s the actual mechanism that traps organisations there, and what’s the fastest way out?
Pankaj Vyas: “Pilot purgatory” usually happens when you treat AI as a technology experiment rather than a business transformation. Organisations can demonstrate that a technology works and still struggle to translate that into enterprise value.
One reason is that AI is often introduced into processes that were designed around very different ways of working. If we automate one activity but leave the surrounding approvals, hand-offs, systems and decision rights untouched, we may make a task faster without materially improving the end-to-end outcome.
There is also a measurement challenge. Before deploying AI, you need to be clear about the business problem you are trying to solve and establish the baseline against which you’ll measure improvement. Otherwise, a pilot may demonstrate impressive technical performance, but you still won’t be able to answer a basic question: what value did it create for the business?
Three shifts can help organisations move beyond this stage.
First, start with purpose and outcomes. Do not begin with the question, “Where can we use GenAI?” Begin with an important business problem and define what should improve, whether that is cycle time, quality, productivity, cost, customer experience or another meaningful outcome.
Second, redesign the workflow end to end. The real value will not come from inserting AI into isolated tasks. It comes from reconsidering how work moves across people, systems and increasingly AI agents, and then designing the operating model around that.
Third, move decision-making closer to the work. Central teams have an important role in platforms, architecture, cybersecurity, governance and standards, but the people who understand the workflow must have meaningful ownership of the transformation. Empowered teams with clear decision rights can identify where AI creates value, adapt the process and remain accountable for the outcome.
Ultimately, getting out of pilot purgatory requires moving from experimentation to ownership. AI creates enterprise value when there is a clear purpose, the workflow is redesigned around the capability, and teams are accountable for measurable outcomes.
CISO Forum: Talent architecture 2.0: what does the org chart of an intelligence-driven enterprise look like five years out, and which roles disappear, merge, or get invented?
Pankaj Vyas: AI is changing how tasks get done. Jobs are increasingly being ‘unbundled’ into discrete tasks, with AI reshaping the value of these activities rather than entire roles. AI and automation will increasingly handle work that is repetitive, rules-based or heavily administrative. Some roles will merge as people take broader responsibility across technology, data and domain areas. At the same time, we will see greater demand for people who can connect disciplines rather than operate within only one.
A polymath engineer will become increasingly important. That is someone who combines software and data skills with domain knowledge and an understanding of how systems operate in the real world. We will also need stronger product managers, systems integrators and people who can orchestrate human and AI capabilities across a workflow.
The organisation will still need deep specialists in areas such as AI, cybersecurity, architecture and advanced engineering. The difference is that these experts will increasingly work through platforms and expert communities, allowing their knowledge to scale across the enterprise.
The future organisation is therefore not simply smaller. It is more connected, more outcome-led and designed around how work is actually delivered.
CISO Forum: At Siemens Technology and Services specifically, what’s one internal transformation decision a pillar you prioritised, a workflow you redesigned that you’d point to as proof this isn’t just theory?
Pankaj Vyas: At Siemens Technology and Services, we are building AI capability into the way our engineering teams work. We have established Communities of Experts around critical areas such as AI, cloud, edge computing, and cybersecurity, so deep expertise isn’t confined to individual projects but can be applied across the organisation.
At the same time, we are focusing on AI-enabled development to shorten development and release cycles, including AI-assisted code generation, validation, testing, and simulation. This allows engineers to spend more time on higher-value engineering problems while maintaining the quality and discipline required in industrial technology. This combination of specialist expertise, AI-enabled development and cross-functional collaboration gives us a way to move from experimentation towards repeatable capabilities.
The impact of this internal transformation is visible in how quickly these capabilities are moving from our engineering environments into industrial applications. We are bringing generative AI, industrial copilots, and digital twins directly to the factory floor to help manufacturers address skills shortages, automate faster, and improve productivity.
