PPM Summit Frankfurt Roundtable, 23 September 2026
What would you let an AI agent decide about your portfolio, and how would you prove it did the right thing?
A management summary of the roundtable: the argument, the model, two things you can try, and the words we used.
AI is a tool. It does what you let it do, and "letting" is not an instruction you type. It is the architecture you put around it.
Management summary
Nothing in your current PPM has to change. Planisware, Planview, cplace, Smartsheet or whatever runs your portfolio today stays exactly where it is, with its stage-gates, its data and its committees. A governed AI layer sits beside it, reads from it, and hands drafts back to the people who already own the decisions.
What the AI does for you. It gathers the evidence for a gate, runs scenarios, flags capacity conflicts and risks, drafts the recommendation and monitors the portfolio between reviews. The work that today takes an analyst a week is ready in minutes, and the people in the room spend their time on the judgement, not on the collation.
What the AI does not do. It does not classify risk, it does not move the gate, it does not reassign people, and it does not sign anything. Those stay with written rules and with a named person. Not because the model is not clever enough, but because a regulator, an auditor or a CFO will ask who decided and on what basis, and "the model" is not an answer.
The three things that have to be true. Boundaries: what the agent may read, call and spend, enforced by a gateway the agent cannot see or change. Evidence: what it actually did, which inputs, which rule, what it cost, logged where the agent cannot reach. Owner: one named person who signs, with the right to do so written in policy.
Why this fits pharma without a fight. Your portfolio governance already works this way. Stage-gates are decision records. Decision rights are written down. Anything that enters a GxP record is validated. The AI layer does not replace that model; it plugs into it. The only new question is which of the ten rows below your AI can produce today.
Why now. Every PPM vendor is shipping its own agent this year, each with its own log. What nobody ships is the view across all of them: which agents are running, what each was allowed to do, who owns each decision. That is the job that lands on portfolio leadership, and it is easier to design in than to retrofit.
A rules engine that classifies each use of AI by written, cited rules
Decision rights charter
The same charter, now also enforced on agents: who may approve what
GxP validation for anything that enters a regulated record
An AI asset register: every agent, its owner, its policy version, its retirement
Meeting minutes as the decision record
A ten-row decision record assembled from the gateway log, not from the agent
How the AI engine works, in seven layers
Everything the agent depends on sits on the other side of a gateway. The agent asks; the gateway decides. Each layer is a standard building block, not a research project.
1
Identity and permissionsThe agent has its own identity, like a new employee: read-only on the portfolio database, no access to GxP systems, no email. Cheapest control there is, and the one most often skipped.
2
Budget and run limitsA ceiling in money, steps and time, enforced by the gateway. An agent told in its instructions to stop at 100 euros will honour that until it decides the task needs 110. The limit has to sit outside the agent.
3
Tool allow-listThe short list of things the agent may call. Anything else does not exist for it. Ask for something off the list and the gateway refuses and escalates.
4
Rules engineRisk classification by written, versioned rules that cite their source (GxP record, human oversight, capacity conflict, vendor audit rights). No probability, no black box. Changing a rule is change control.
5
Output validationBefore a draft is shown to anyone, a check that every claim points to a real document and the output has the expected structure. Hallucinations do not reach the decision owner.
6
Approval holdAny action with impact pauses until a person with the right decision rights approves it, in the tool they already use. The agent waits.
7
Audit log and decision recordEvery request, refusal, approval and cost, written to a store the agent cannot read or edit. The decision record is assembled from this log, not from the agent's account of itself.
The words we used
AI agent
Software that uses a language model to read, reason and act in steps, calling tools along the way, rather than answering a single question.
Agentic AI
The general term for AI that carries out multi-step work with some autonomy. Uses five to thirty times more computation per task than a chatbot, which is why cost control matters.
Tool
A function the agent may call: read a project, run a scenario, draft a document, or, if allowed, change a gate status. Tools are how an agent touches the world.
MCP (Model Context Protocol)
An open standard for how tools are offered to AI agents. Think of it as a common plug: a PPM platform exposes its functions once, and any agent can connect through a gateway that controls what it sees.
Gateway
The layer between the agent and everything else. Checks identity, budget and allow-list, holds actions with impact, and logs every call. The agent only sees the gateway.
Allow-list
The explicit list of tools an agent may use. Everything not on it is invisible to the agent, not merely forbidden.
Approval hold
A pause enforced by the gateway on any action that changes something, until a person with the right decision rights approves or rejects it.
Decision owner
A named person, not a role or a committee, whose signature turns a draft into a decision, and whose right to sign is written in policy.
Decision rights
Who may decide what, at which gate. Already exists in your governance charter; the gateway enforces the same rules on agents.
Rules engine
A deterministic set of written rules that classify a case (risk tier, validation depth, who must approve) and cite the regulation or policy behind each rule. Not a model.
Human in the loop
A person must act before the outcome takes effect. Contrast with human on the loop (a person can intervene) and autonomous (no person). The EU AI Act calls the general requirement human oversight.
Hallucination
A fluent statement by a model that is not supported by its sources. Handled by output validation, not by asking the model to be careful.
Groundedness
Whether every claim in an AI output can be traced to a specific input document. The check that stops hallucinations reaching a decision.
Drift
The model, the data or the rules change after you validated the system, so last year's evidence no longer describes what runs today. The reason evidence has to be re-run, not filed.
Audit log
An append-only record of every agent call, refusal, approval and cost, stored where the agent cannot write. The raw material of the decision record.
Decision record
Ten rows: decision, signer and time, agent and policy version, allowed to, actually did, inputs, classified by, cost, stored in, linked to. What an auditor or a CFO asks for.
AI asset register
The inventory of every AI system, agent and copilot in use, with owner, policy version and lifecycle state. What gets retired is retired on the register, not lost.
Token
The unit models are billed in, roughly a word fragment. Agents consume many per step; a budget in tokens or money per run is the practical cost control.
GxP
Good practice regulations (GMP, GCP, GLP and others). A GxP record is one a regulator can inspect; anything that creates or alters one must be validated.
Stage-gate
The portfolio decision points between development phases. Each gate is an investment decision with a written record, which is why AI fits the model rather than replacing it.
PTRS
Probability of technical and regulatory success. A standard input to gate decisions and one of the sources an agent reads in the demo.
The checklist: ten rows of a decision record
For any AI you already use in portfolio work, tick each row you could produce today for one real decision. Nothing is saved; this is for you.
You can produce 0 of 10 today.
Six facts we used at the table (all from 2026)
98% have formal AI governance policies, yet 47% bypassed their own process for urgent deployments. 26% of agentic AI users cannot detect unauthorised agents running internally; 36% had an AI incident with material damage. EY, survey of 202 senior AI executives at $1bn+ companies, published 15 Sep 2026
53% of organisations saw agents exceed their permissions and 47% had a security incident involving an AI agent in the past year. Only 21% keep a real-time registry of which agents exist. CSA / Zenity, Apr 2026 (n=445); CSA / Strata, Feb 2026
12 AI agents per organisation on average, growing 67% within two years, half of them in silos with no cross-team visibility. Salesforce Connectivity Benchmark 2026, 1,050 enterprise IT leaders
74% plan agentic AI within two years; only 21% have a mature governance model for agents. Deloitte, 2026
Model inference is roughly 20% of an agentic system's true cost; the other 80% is infrastructure, governance and the people who now watch the AI. Uber spent its entire 2026 AI budget in four months after giving agents to 5,000 engineers. Production audits reported Q2 2026; Uber case reported 2026
The regulator is ahead of most of us. EU AI Act high-risk obligations enforceable since 2 Aug 2026; FDA and EMA published joint AI principles (Jan 2026); FDA gave its own staff agentic AI (Dec 2025). EU, FDA, EMA
Figures as published by the named sources, not our own research.
If you want to run the ten rows against one of your own AI use cases, that is a 30-minute conversation. Write to either of us with the subject "WhySummit Frankfurt".
Atlas. AI lifecycle governance for life sciences. The demo, the map and the decision record are illustrative and simplified for discussion; the principle is not.