1300 CODIFY

Why AI Is Forcing CIOs to Revisit Their Azure Foundations

by | 17 Aug, 2026 | Blog

For many organisations, Azure has already delivered on its first promise. Workloads were migrated, environments were hardened and the platform became stable enough to support day-to-day operations.

That is a good outcome. In fact, many organisations that moved to Azure around 2019 have spent the years since improving security, testing recovery, tightening access, responding to audits and aligning controls to frameworks such as the Essential Eight.

The challenge now is that AI is creating a very different demand on the same environment.

IT operations teams are being asked to keep the lights on and protect the assets they have been told to guard. At the same time, AI project teams are arriving with a dozen use cases, limited funding and a mandate to move quickly, test ideas and fail fast.

The promise of public cloud is that both needs can coexist. So why are so many IT teams still stuck wondering whether to create a new subscription, reuse an existing resource group, relax a policy exemption or give a project team broader access than anyone is comfortable with?

AI Is Creating a Bimodal Azure Problem

Most mature Azure environments were designed for predictable operations. They favour stability, repeatable change control, centralised networking, known support models and a clear understanding of what should and should not change.

AI proof-of-concepts work differently. Teams need to evaluate new services, connect to data, experiment with models, deploy infrastructure-as-code, measure cost and iterate quickly enough to learn what is worth taking forward.

This creates a bimodal requirement. One part of the environment must remain tightly governed and operationally dependable. Another part needs enough freedom to support controlled experimentation without turning every AI idea into a security exception.

That is where the Microsoft Cloud Adoption Framework becomes useful. Its Azure landing zone guidance separates the platform foundation from workload landing zones, so shared services, policy, identity, networking, monitoring and cost controls can be applied consistently while workload teams still have a defined space to deliver.

 

The Foundation Gap AI Is Exposing

1. Stable Architecture Is Not the Same as AI-Ready Architecture

A small number of subscriptions and a consolidated workload model can be mature and efficient. It can also make it harder to introduce new project-led services without blurring accountability or expanding permissions beyond what is comfortable.

AI readiness often means moving from a historically convenient structure to a Cloud Adoption Framework-aligned model with clearer management groups, subscription boundaries and workload landing zones.

2. Platform Services Need to Be Separated from Workloads

Hub virtual networks, firewalls and shared services should not be tangled with every workload that depends on them. Established workloads, such as application services, file servers or spatial platforms, have different lifecycle expectations from an AI initiative that needs faster iteration.

Separating platform services from workload landing zones gives infrastructure teams control where they need it, while giving project teams a governed space to move.

3. Support Ownership Becomes a Design Decision

AI delivery introduces a bi-modal operating model. Some workloads need stable IT operations and managed service support. Others need project-led delivery, infrastructure-as-code, pipelines and controlled access to new Azure services.

If that ownership model is not designed up front, accountability becomes messy. Who supports the landing zone? Who approves new services? Who owns cost, security and lifecycle management once the pilot becomes production?

4. Innovation Needs Guardrails, Not Workarounds

The answer is not to unwind the secure foundation that has taken years to build. It is to give AI teams a governed environment where they can move quickly inside clear boundaries.

That means deciding where AI workloads should live, which policies apply, how access is granted, how data is exposed, how budgets are tracked and what happens when a proof-of-concept becomes a production service.

 

What Leading CIOs Are Doing Differently

The strongest AI programs are treating Azure AI Foundry and related services as part of a broader cloud platform strategy, not as a standalone experiment.

They are using the Cloud Adoption Framework as a practical reference point: separating platform and workload layers, clarifying support ownership, applying policy through the right hierarchy and creating AI landing zones that balance speed with control.

This lets IT operations keep protecting the stable estate while giving the AI project team a safe place to test use cases, understand costs, access the right data and learn what is worth scaling.

Final Thoughts

The first step in a successful AI program may not be building an agent, choosing a model or writing a prompt.

It may be creating the right Azure landing zone so innovation can happen without weakening the controls the organisation has already invested in.

That is the real lesson for CIOs right now: AI is not starting a new cloud journey. It is exposing where the original cloud model needs to evolve.

If you are considering Azure AI Foundry or other AI proof-of-concepts, start by asking whether your Azure foundation supports both operating modes: stable, governed operations and controlled innovation.

Codify can help assess the architecture, governance, security and cost controls needed before AI adds another layer of complexity.

Ready to connect with Codify to discuss your next cloud project?

I know what I want:

I don’t know what I need:

Ready to connect with Codify to discuss your next cloud project?

I know what I want:

I don't know what I need: