AI Infrastructure
How to build an AI Operating Layer: start with one process
An AI Operating Layer is an organisation’s shared infrastructure on which its different artificial-intelligence systems operate: data, context, tools, permissions, agents and execution in a single governed layer. It sounds like a multi-year project. It does not have to be: it is built by accumulation, one process at a time.
The architecture, bottom-up
- Enterprise Systems & Data: ERP, CRM, SAP, Salesforce, databases, documents, email, conversations, internal software and legacy applications.
- Enterprise Data Layer / Data Lake: ingestion, normalisation and data quality.
- Company Memory: entity model, knowledge and context accessible with permissions.
- MCP / APIs / tools: reusable capabilities that expose the systems.
- AI Operating Layer: identity, permissions, policies, traceability and the Agent Gateway.
- Digital Workers and authorised agents, A2A collaboration and business execution.
Stage 1: choose a process, not a strategy
The first step is not an AI committee. It is a concrete process with measurable pain: reception, customer service, training, logistics, administration, bookings, operations or sales. Its current cost, capacity needed, automatable share and expected return are calculated. That is the business case for the first digital worker.
Stage 2: build the worker and, with it, the reusable components
This is the difference between an isolated agent and a layer. When the first digital worker is built, the following are deliberately created as independent pieces: the connections with the systems involved, the data model and the first version of the Company Memory, permissions and identities, MCP capabilities, workflows and business rules and the traceability log. None of those pieces belong to the worker: they belong to the layer.
Start with one process. Build the AI layer for your entire company.
Stage 3: the second worker costs less
When the second process arrives, the ERP connection already exists, the Company Memory already knows the customers and the permissions are already modelled. The second digital worker reuses most of the infrastructure and adds only what is specific. The third, even less. It is the "connect once, use everywhere" effect applied to the whole organisation.
Stage 4: open the layer to authorised agents
With several workers operating, the layer is already an asset. The next step is to allow, when the customer decides, other agents to use it: corporate copilots, the customer’s own agents, partner, supplier or customer agents. The Enterprise Agent Gateway controls identity, authorisation, scopes, accessible information, allowed actions, limits, audit and human approval. A customer agent can look up its orders; never other customers’ orders nor the whole Data Lake.
Stage 5: agent-to-agent collaboration (A2A)
From there, agents can collaborate with each other just as different teams do: a customer agent asks for a delivery change, the order agent checks availability, the logistics agent proposes a date and the result comes back confirmed. Open protocols such as A2A (agent-to-agent) make this collaboration interoperable with third-party agents as well.
Mistakes worth avoiding
- Starting with the platform instead of a process: months of infrastructure without a single business result.
- Building integrations inside the agent: every new agent starts from scratch.
- Exposing databases instead of capabilities: no scopes or audit possible.
- Ignoring escalation to people: the layer must know when not to decide.
Frequently asked questions
How long does it take to build an AI Operating Layer?
It is not built in one go. The first digital worker is deployed in weeks and leaves the first components; the layer grows with every following process.
Do I need a Data Lake before starting?
Not necessarily. The Company Memory is built on existing sources; if a Data Lake already exists, it is used as the data layer.
Does the layer work for agents that are not Twinny’s?
Yes, when the customer authorises it: controlled capabilities are exposed via MCP and the Agent Gateway to copilots, own or third-party agents.
References
Want to see how much you could save in your case?