Every enterprise I talk to has an AI roadmap. Very few have an account structure, network, and identity model that can carry it. And the gap between those two documents — the roadmap and the platform underneath it — is where AI initiatives quietly stall.
Here's the pattern. The AI team needs a place to run. The landing zone was designed years ago for three-tier apps, so the AI workloads get an "exception" account. The data they need lives across four other accounts with no sanctioned path between them, so someone opens a peering connection and a cross-account role with a TODO comment. Six months later there are eleven exception accounts, the security team is reviewing agent workloads through a lens built for web servers, and every new AI use case starts with three weeks of plumbing negotiations.
AI-readiness is a platform property
The things that make an enterprise ready for AI at scale are, almost boringly, the things that make a landing zone production-grade: account vending that stamps out governed environments in hours instead of weeks. Guardrails expressed as policy, not as a review meeting. A network with sanctioned, inspected paths between data and compute — instead of a growing archaeology of peering exceptions. Identity that can mint scoped, short-lived credentials for a workload, because agents are workloads.
None of that appears on an AI roadmap. All of it determines the roadmap's velocity. When a new model, agent, or GPU workload can get a compliant account, network path, and identity in a day, experimentation compounds. When it can't, every initiative pays the platform tax first — and most of them die paying it.
Agents raise the stakes
Assistive AI mostly reads. Agentic AI acts — it calls APIs, moves data, changes systems. That difference lands squarely on the foundation. An agent's blast radius is defined by the account boundaries, network segmentation, and credential scope you give it. Get those right and an agent failure is an incident report. Get them wrong and it's a headline.
This is why I tell clients the landing zone review is the first AI project, not the prerequisite before the first AI project. It sets the ceiling on everything that follows.
The one-quarter test
A useful diagnostic, answerable in an afternoon: if a team needed a new, fully governed environment tomorrow — account, network path to a specific data source, scoped workload identity, egress rules, cost tracking — how long would it actually take, and how many humans would touch the request?
If the honest answer is measured in days and involves fewer people than a pizza order, your AI roadmap is executable. If it's measured in weeks and committee meetings, fix that first. It's cheaper than discovering it one canceled AI initiative at a time.