SR
Sumeet RastogiEnterprise Applications Leader
Executive profile
Menu
PortfolioAI LabLeadershipLearningInsightsISB JourneyExecutive profile

Featured / Field notes

Ideas from
the work.

Practical perspectives on Workday delivery, enterprise transformation, AI-enabled operating models, practice growth, and the GCC technology market.

Issue 01 · 2026

A convincing AI answer is not proof

Workday's new AI Research program turns an abstract trust discussion into a delivery requirement: enterprise AI needs repeatable tests for noisy data, changing context, memory, explanations, and controls.

On 19 August, Workday announced a dedicated AI Research team focused on reliable, trustworthy, and efficient enterprise AI. One of its studies tested whether an AI explanation remained dependable when the evidence behind a recommendation was changed. Across four models, explanation consistency averaged only 0.51 on a zero-to-one scale when the researchers introduced common complications such as irrelevant activity, reordered events, changing preferences, or missing information. The important leadership lesson is simple: a fluent answer can still be unstable.

The signal: test the rationale separately from the result

In the study, recommendations could remain similar while the explanation behind them shifted. Workday also reported that severe changes disrupted explanations only about 1.7% more than mild changes, and that using a larger model improved stability but did not remove the problem. The research used controlled, synthetic shopping data—not Workday products, customer data, or workplace decisions—so the enterprise examples are illustrative. Its testing method is still useful: change one piece of evidence at a time and observe whether the system reacts for the right reason.

Build an evidence-to-decision contract

Every AI-enabled Workday use case should define its approved inputs, data freshness, excluded attributes, output, authority level, and expected explanation. A skills recommendation, payroll case summary, supplier-risk alert, or manager assistant should be able to show which evidence mattered. Teams should also define what must not change the outcome—for example an irrelevant field, reordered history, duplicate event, stale record, or missing optional value.

Create a reliability test pack around the workflow

Happy-path demonstrations are not enough. Testers should deliberately introduce incomplete, duplicated, stale, conflicting, and irrelevant data; vary the order and wording of inputs; repeat the same request; and compare both the recommendation and its rationale. For multilingual experiences, test equivalent meaning across supported languages. Workday business-process rules, security, Extend validations, Orchestrate steps, and integration controls should remain deterministic even when the AI output varies.

The AMS opportunity: AI regression testing

Reliability is not frozen at go-live. A model update, prompt change, new data source, altered security group, connected tool, or revised business process can change behaviour. AMS teams can maintain approved test scenarios, expected tolerances, failure thresholds, evidence logs, and rollback criteria. They can run the suite after every material change and monitor production overrides, inconsistent explanations, unusual actions, latency, and cost. This creates a recurring reliability service rather than a one-time AI sign-off.

Why this matters in the GCC

The GCC implication is an inference from the research: enterprises operating across countries, languages, and shared-service environments need one common reliability standard with locally relevant data and scenarios. A regional GCC or capability centre can own the reusable test harness, automation, and evidence repository, while country and process owners validate language, policy, regulatory, and cultural context before release.

Leadership takeaways
  1. Require noisy-data and change-sensitivity tests before approving an AI use case for production.
  2. Score the recommendation and its explanation separately; polished language is not evidence of dependable reasoning.
  3. Make AI regression testing an AMS responsibility after changes to models, prompts, data, tools, security, or workflows.
Back to top ↑

Not every AI action deserves the same autonomy

New workplace AI guidance from Workday and the Future of Privacy Forum gives leaders a practical way to classify risk and bind an agent's authority before it enters an HR process.

The most important question in workplace AI is not whether an agent can complete a task. It is how much authority the organization should give it. On 13 August, Workday highlighted an updated workplace AI framework developed with the Future of Privacy Forum and other HR technology leaders. Its practical contribution is a four-factor risk model and a clear principle: human oversight should be calibrated to context, while people remain accountable for consequential outcomes.

Classify the use case—not the technology label

The same model can create very different risks depending on how it is configured and used. The framework asks leaders to assess four dimensions: the sensitivity and quality of data and inferences; the degree of autonomy and discretion; how close the output sits to a final decision; and the significance and reversibility of the impact. A policy chatbot and an agent that independently approves leave may use similar technology, but they should not receive the same governance or authority.

Turn risk into an explicit authority level

Every Workday AI use case should state what the system may do: retrieve or summarize information; draft content; recommend an action; execute only after named human approval; or act autonomously inside a narrow, reversible boundary. Higher sensitivity, autonomy, decision proximity, or impact should trigger stronger testing, transparency, access controls, evidence, and human intervention. Some consequential decisions should remain human even when AI can support the analysis.

Design the control boundary in Workday

Extend experiences, Orchestrate flows, integrations, security, and Workday business processes can make the authority boundary operational. AI can interpret language, assemble context, or recommend the next step; deterministic rules should enforce eligibility, required data, permissions, approvals, and audit evidence. This is more useful than a broad statement that a human is 'in the loop' because it identifies exactly where the human decides and what the system is prevented from doing.

The AMS agenda: reclassify risk as the system changes

Risk classification is not a one-time design document. AMS teams should maintain an inventory of AI use cases, owners, data sources, authority levels, approvals, testing evidence, notices, and observed outcomes. Any change to the model, prompt, tools, connected systems, data, or business process should trigger an impact review. Monitoring should include unexpected actions, overrides, complaints, bias signals, data leakage, and whether the original human-control design still works in practice.

Why this matters in the GCC

The GCC implication is an inference from the framework: multi-country employers can use one enterprise method for risk classification while adapting notices, approvals, data access, and decision rights to local legal and cultural contexts. A regional AI governance council can define the common standard; country and process owners remain accountable for how employment-related AI is configured and used locally.

Leadership takeaways
  1. Score every workplace AI use case by data sensitivity, autonomy, decision proximity, and impact.
  2. Write the agent's authority level into the design—do not rely on the vague phrase 'human in the loop.'
  3. Require AMS and process owners to reassess authority whenever models, tools, data, or workflows change.
Back to top ↑

From AI pilots to a value portfolio: fund the work that matters

Workday's latest AI direction connects a trusted core, governed agents, and usage-based economics. The practical leadership move is to manage AI as a measurable portfolio—not an expanding list of experiments.

Enterprise AI has made experimentation cheap. That creates a new problem: too many working pilots, too little evidence of business value. On 6 August, Workday described a familiar scenario—50 agent projects reduced to 15 because many were costly, difficult to manage, or disconnected from core operations. The lesson is not to slow innovation. It is to create a portfolio discipline that decides where AI should act, what value it must produce, and when it should be scaled, redesigned, or stopped.

The signal: successful pilots can still be poor investments

A pilot can work technically and still fail the enterprise test. Leaders need to ask whether it improves a process that matters, uses trusted context, operates within clear controls, and creates enough value to justify adoption and ongoing consumption. Workday's five-part direction—Sana as the AI layer, the trusted core, the Agent System of Record, Flex Credits, and broader reach—shows that enterprise AI is becoming an operating and economic model, not only a product feature.

Build a value gate before the production gate

Before funding an agent, Extend app, or AI-enabled orchestration, require a named process owner, a measurable baseline, a target outcome, a bounded data and action scope, a human-control design, and an estimated run cost. Examples include fewer payroll exceptions, lower case-handling time, faster financial evidence gathering, or reduced onboarding delay. Production approval should depend on both control readiness and a credible value case.

Connect architecture to AI economics

Workday Flex Credits are designed to be consumed when eligible agents or platform capabilities perform production work, rather than by token volume. Workday says credits can move across Workday-built agents, Workday Data Cloud, and Sana, while the Platform Consumption Console provides usage visibility and balance alerts. This makes architecture choices economic choices: teams must understand which actions consume credits, how often they occur, what exceptions create repeat usage, and whether a deterministic integration or business rule would handle a stable step more efficiently.

The AMS opportunity becomes AI value operations

AMS teams can extend beyond incident resolution into a recurring AI value service: monitor adoption, completed actions, credit consumption, outcome quality, exception patterns, access, and business value. A monthly review should decide whether to scale, tune, redesign, pause, or retire each capability. This connects Workday functional ownership, integrations, Extend, Orchestrate, security, finance, and AI governance in one operating rhythm.

Why this matters in the GCC

The GCC implication is an inference from Workday's direction: fast-growing, multi-entity enterprises can use a shared governance and consumption model while allowing local teams to prioritize use cases by country, function, language, and regulatory context. A central capability team can set architecture, security, measurement, and reusable patterns; local owners remain accountable for process value and adoption. The result is controlled speed without creating disconnected AI islands.

Leadership takeaways
  1. Approve AI initiatives against a measurable process outcome—not a compelling demonstration.
  2. Track controls, adoption, completed actions, consumption, and realized value in one portfolio view.
  3. Give AMS teams a recurring mandate to scale, tune, pause, or retire AI capabilities after go-live.
Back to top ↑

Before AI agents act: govern them like enterprise integrations

The practical path from AI pilot to production is not more autonomy. It is a clear control plane for identity, access, testing, observability, ownership, and retirement.

The last seven days did not produce a sufficiently consequential Workday product announcement to justify another news-led note. A more useful leadership question is already in front of most enterprises: what must be true before an AI agent is allowed to act on Workday data or business processes? The answer looks familiar to integration leaders. Every production agent needs an identity, a bounded purpose, controlled access, test evidence, operational monitoring, and an accountable owner.

Treat the agent as a production integration

An AI agent may reason differently from a traditional interface, but it still crosses trust boundaries, reads sensitive data, invokes services, and can change enterprise records. The same delivery disciplines therefore remain essential: least-privilege access, explicit data contracts, environment promotion, exception handling, audit evidence, support ownership, and a controlled path to disable the capability.

Workday is building the control plane

Workday's generally available Agent System of Record provides a unified view of Workday-built and third-party agents, records interactions, applies identity and permissioning, and supports a lifecycle from registration through deactivation. Workday's announced Agent Passport adds a complementary assurance layer: pre-production testing, signed attestations against public standards, continuous monitoring, and the ability to allow, block, route, limit, or revoke agent actions. Agent Passport is planned for early access in the second half of 2026, with general availability projected before year-end.

A practical production-readiness gate

Before launch, leaders should require six answers: who owns the agent; which users, data, and actions it can access; which decisions remain deterministic or require human approval; how its behavior was tested; what telemetry and service levels will be monitored; and how it will be restricted or retired. This converts responsible AI from a policy document into a repeatable delivery gate.

The AMS opportunity starts after go-live

Agent operations create a recurring managed-services agenda. Teams must review usage and value, investigate unexpected outcomes, retest after model or prompt changes, tune permissions, maintain knowledge sources, manage consumption, and retire agents that no longer perform or justify their cost. The support model should connect AI governance, Workday security, integrations, functional ownership, and enterprise risk rather than place the agent in an isolated innovation queue.

Why this matters in the GCC

The regional implication is an inference from these capabilities and the NIST AI Risk Management Framework: multi-entity GCC organizations can scale innovation faster when every agent has consistent global controls plus clear local ownership for data, policy, language, and regulatory context. A sensible starting point is one bounded workflow with reversible actions and visible human review—not a broad licence for autonomous access across HR and finance.

Leadership takeaways
  1. Give every production agent a named business owner, technical owner, identity, purpose, and retirement path.
  2. Separate AI reasoning from deterministic rules, approvals, and controls that must remain authoritative.
  3. Fund ongoing agent operations—monitoring, retesting, permission reviews, value measurement, and incident response—not only the initial build.
Back to top ↑

From course catalog to capability engine: what Workday Learning + Sana changes

Workday Learning, powered by Sana is now generally available. The strategic opportunity is not faster course production alone—it is a learning system that responds to role, skills, location, and business change.

Most enterprise learning systems are good at recording completion. They are less effective at answering a more important question: can our people perform the work the business now requires? Workday's July 22 announcement points toward a different model—one where trusted workforce context, AI-native learning, content creation, and learning operations work as a connected capability system.

The development: AI-native learning enters the Workday core

Workday Learning, powered by Sana is generally available globally as an integrated solution for Workday HCM customers. It combines Workday's people and skills data with personal AI tutoring, smart search, personalized learning paths, AI-assisted course creation, translation, assignments, campaigns, reporting, and controls. Workday notes that separate guidance still applies in certain regulated and sovereign environments.

The operating-model shift

The important change is contextual learning. Recommendations can reflect an employee's role, skills, organization, and location; learning paths can update when people join, change roles, or move regions. This moves learning closer to the flow of work. The leadership challenge is to connect skills taxonomy, job architecture, content ownership, security, and business outcomes—rather than treating the platform as an isolated L&D tool.

Evidence from Workday's own L&D team

Workday reports that its internal use of Sana Learn increased completion rates by 25%, made new course creation 50% faster, accelerated migration of existing courses by 60%, and reduced annual content-update time by 70%. These are Workday-reported internal results, not universal benchmarks, but they show where leaders can establish value hypotheses and baselines for their own programs.

Delivery and AMS opportunities

The work extends beyond enabling a feature. Organizations will need content inventory and migration, role and skills mapping, localization governance, security review, integration with surrounding learning content, reporting design, release management, and ongoing measurement. For Workday practices and AMS teams, this creates a recurring optimization agenda: keep content current, tune recommendations, monitor adoption, and connect learning activity to mobility, performance, compliance, and retention signals.

Why this matters in the GCC

The GCC implication is an inference from the product capabilities: enterprises operating across countries, languages, regulatory contexts, and fast-changing skill needs can use one governed foundation while adapting learning to role and location. A sensible starting point is one high-value journey—such as manager onboarding, regulatory training, national talent development, or enterprise-technology reskilling—with clear human review of AI-generated content and measurable capability outcomes.

Leadership takeaways
  1. Measure learning by demonstrated capability and business outcomes—not completion alone.
  2. Treat role, skills, location, content ownership, and governance as one connected design.
  3. Start with one high-value learning journey and baseline speed, engagement, quality, and operational effort.
Back to top ↑

Beyond the copy/paste economy: put AI inside the workflow

Workday's latest research sharpens the enterprise AI question: are we making isolated tasks faster, or removing the manual joins between systems, decisions, and approvals?

The next productivity breakthrough will not come from giving every employee another AI window. It will come from removing the work people perform between windows: reconciling data, translating context, re-entering information, checking policies, and chasing approvals. Workday's research gives leaders a useful test for every AI investment—does it accelerate a task, or improve the end-to-end flow of work?

The signal: employees are still the integration layer

Workday's global study of 6,100 active AI users found that 82% spend significant time translating, copying, and pasting information between systems. Only 27% said their organizations had embedded AI into core business workflows. The outcome gap is important: where AI is embedded in core systems, 60% report time savings of 25% or more; where it sits outside, fewer than one in four report savings at that level.

The practical Workday opportunity

Start with a high-friction process that crosses Workday and another enterprise system—onboarding, absence, payroll exceptions, benefits eligibility, approval routing, or financial close. Use deterministic Workday business rules, security, approvals, and audit trails as the control plane. Apply AI where reasoning helps: interpreting an exception, assembling context, recommending the next action, or guiding a user. Extend, Orchestrate, APIs, and agent-ready tools can then connect the experience without weakening accountability.

Design the boundary between AI and automation

Not every step should be agentic. Stable validations, calculations, transformations, and regulatory controls belong in deterministic logic. AI is most useful where the work is ambiguous, language-heavy, or context-dependent. A strong architecture makes that boundary explicit, keeps consequential decisions reviewable, and records what the AI recommended, what the system enforced, and who approved the outcome.

Why this matters in the GCC

The regional implication is an inference, not a reported Workday statistic: organizations modernizing quickly across multiple entities, jurisdictions, languages, and service providers should prioritize cross-system friction. The practical starting point is a portfolio of measurable workflow interventions—each with a local process owner, data boundary, control design, adoption plan, and value baseline—rather than a broad mandate to deploy copilots everywhere.

Leadership takeaways
  1. Fund AI use cases around end-to-end process friction, not the novelty of the interface.
  2. Keep Workday rules, security, approvals, and auditability as the deterministic control plane.
  3. Measure hours removed from reconciliation, re-entry, exception handling, and approval latency.
Back to top ↑

The AI-enabled delivery model: beyond individual productivity

The real opportunity is not a faster consultant. It is a delivery system that learns, reuses knowledge, and improves quality with every engagement.

Most enterprise AI conversations begin with personal productivity: faster notes, faster drafts, faster analysis. Those gains matter, but they are only the first layer. A delivery organization creates lasting advantage when AI improves how the whole system works—not just how quickly one person completes a task.

Move from assistance to operating model

An AI-enabled delivery model connects the work consultants do every day with reusable organizational knowledge. Requirements, mappings, design decisions, test evidence, defects, and runbooks should not disappear inside project folders. They should strengthen the next engagement.

Design for three levels of leverage

At the individual level, AI accelerates research, analysis, and documentation. At the team level, common prompts, templates, review standards, and accelerators create consistency. At the organizational level, governed knowledge and feedback loops turn delivery experience into institutional capability.

Keep accountability human

Enterprise delivery still depends on judgment. Architecture, security, regulatory impact, and production readiness require accountable owners. AI should widen the team's field of view and reduce avoidable effort while experienced leaders remain responsible for the decision.

Leadership takeaways
  1. Start with one repeatable delivery workflow, not a broad AI mandate.
  2. Capture reusable knowledge as part of delivery—not as a separate cleanup activity.
  3. Measure quality, cycle time, and reuse alongside individual productivity.
Back to top ↑

Scaling an integration practice without diluting quality

Growth becomes sustainable when capability, governance, and ownership scale together—not when a team simply adds more people.

A growing integration practice faces a predictable tension: demand expands faster than experienced leadership. The easy response is to focus on capacity. The stronger response is to build a capability system that helps more people make good decisions independently.

Create visible capability pathways

Certifications are useful milestones, but real capability comes from progressive ownership. Shadowing, paired design, bounded build responsibility, structured reviews, and client-facing leadership should form a deliberate path rather than an informal sequence of opportunities.

Standardize the repeatable, review the consequential

Templates, patterns, and checklists should remove variation from routine work. Senior attention can then focus on architecture, data risk, security, performance, and the decisions that materially affect client outcomes.

Make ownership the unit of scale

A practice becomes scalable when people own outcomes—not only tasks. Clear expectations, early escalation, transparent status, and responsibility for quality create a stronger operating rhythm than layers of coordination.

Leadership takeaways
  1. Plan capability growth with the same rigor as revenue and utilization.
  2. Use reusable assets to create consistency, not to replace design judgment.
  3. Reward ownership, knowledge sharing, and mentoring as delivery outcomes.
Back to top ↑

What enterprise HR technology leaders should watch in the GCC

A practical view of the delivery models, ecosystem relationships, and AI expectations shaping the region's next transformation cycle.

The GCC enterprise technology market is increasingly defined by ambitious transformation agendas, regional scale, and high expectations for speed. For HR technology leaders, the opportunity is not simply to implement platforms—it is to create operating models that can keep evolving after go-live.

Regional presence and global capability must work together

Clients value market context, trusted relationships, and proximity to decision-makers. They also need the depth, coverage, and economics of global delivery. The strongest models connect regional leadership with accountable capability centers rather than treating them as separate worlds.

The ecosystem is part of the strategy

Platform vendors, implementation partners, payroll providers, and specialist firms all influence transformation outcomes. Leaders who understand how the ecosystem moves can make better decisions about ownership, sourcing, and long-term support.

AI expectations will move quickly from demo to delivery

Executives will increasingly ask how AI changes employee experience, service delivery, controls, and the cost of operating enterprise platforms. Technology leaders need a practical roadmap that connects innovation with data governance and measurable value.

Leadership takeaways
  1. Build relationships in the regional ecosystem before a specific opportunity appears.
  2. Design the post-production operating model during—not after—the transformation.
  3. Frame AI around business outcomes, governance, and adoption rather than novelty.
Back to top ↑