2 Adoption Models for GenAI
This chapter covers
- How SaaS, API, and self-hosted GenAI models shift control and risk
- What Agentic AI offers and which risks it introduces
- Key risk dimensions across deployment choices
- A primer on emerging Agentic AI
- MediAssist, a fictional use case moving through all three adoption models
Before setting up governance controls or assessing compliance needs, even before you decide which compliance requirements apply, you need to answer a simple question: How is your organization actually adopting GenAI? It’s tempting to think the answer is obvious. After all, using these tools seems straightforward: type a prompt, get a response. But what happens behind the scenes can vary dramatically depending on the adoption path you choose. That choice determines where accountability sits, how much oversight you must perform, and how your compliance exposure shifts.
We call this your GenAI posture; your operational stance toward generative AI. Identifying which model fits your organization is important because it shapes how you manage data, security, and regulatory compliance as you deploy AI solutions.
Most organizations will fit into one or more of three broad postures: