# AI in a group of companies: what to share and what to leave local.

> In this field note, veridive sets out a playbook for AI in a group of companies. The group shares foundations such as model access, contracts, security patterns, evaluation practice and training, while each company chooses and owns its workflows. It covers choosing first workflows across companies, spreading patterns that work, cost allocation and keeping data apart.

In a group, share the foundations: model access, security patterns, evaluation practice, contracts and training. Let each company choose and own its workflows. A group-wide platform mandate before any workflow works usually slows everyone down.

## Key takeaways

- Share the foundations across the group: model access, contracts, security patterns, evaluation practice and training.
- Let each company choose, own and integrate its workflows; the group asks for evidence, not uniformity.
- Spread patterns that work, not copies: each company re-baselines and adds its own cases to the evaluation set.
- Fund foundations centrally and workflows locally, and ask counsel how data may move between group companies.

The group office announces one AI platform that every company must use. The retail company has a returns backlog that can’t wait, the manufacturer’s data sits in a different ERP, and the energy company’s security team hasn’t approved the platform’s hosting region. A year later, three companies are still waiting for one platform.

In a group, share the foundations: model access, security patterns, evaluation practice, contracts and training. Let each company choose and own its workflows. A group-wide platform mandate before any workflow works usually slows everyone down.

## Why is AI different in a group than in a single company?

Because the companies differ in almost everything a workflow depends on: their business, their systems, their data, their regulators and how ready their people are. A retailer and an energy producer may share a board, but not a returns policy or an ERP.

Two things differ in kind as well. Group companies are usually separate legal entities, so data doesn’t move between them as freely as it does inside one company. And the group office has weight the companies lack, in contracts, security reviews and hiring, but little knowledge of how each company’s work actually runs. A good group strategy uses that weight and leaves the knowledge where it lives. Timing differs too: one company may be in the middle of an ERP change while another is ready to start.

## What should the group share?

Item by item, the split looks like this:

| Item | Where it sits | Why |
|---|---|---|
| Model provider contracts and data terms | Group | Better terms, one legal and security review |
| Model access, usage limits and billing | Group, billed per company | One set of controls, costs traceable |
| Security review patterns | Group | Reviewed once, reused by every company |
| Evaluation templates and practice | Group | The same standard of evidence everywhere |
| Training and the champions network | Group design, local delivery | Common basics, taught on each company’s own work |
| Workflow choice | Company | Only the company knows which work matters |
| Ownership and results | Company | The owner must be close to the work |
| Integration with local systems | Company, using group patterns | Systems differ; patterns travel |

Shared components, such as a retrieval service or logging, join the shared list when two companies need the same thing, not before.

> Share what every company needs. Leave local what only one company knows.

## What should each company own?

Everything that depends on knowing its own work: which workflows to change, who owns each one, the baseline, the reference answers written by its own experts, the review design, the integration with its systems and the results. The budget for its workflows sits with it too.

The group office asks for evidence, not uniformity: a named owner, a baseline, an evaluation set and a gate for every workflow in production, recorded in one group register. How each company gets there is its own business, within the shared standards. A company that needs more than the standard, such as stricter review in a regulated business, should be free to add it. A small [central team](https://veridive.com/insights/ai-center-of-excellence/) at group level can hold the shared list and the register without owning any company’s workflows.

## How do you choose the first workflows across companies?

In three steps. First, each company runs the four tests on its own candidates (frequent, bounded, reachable data, a named owner) and brings a shortlist. Second, the group looks for work that recurs across companies, because a pattern proven once can be adapted many times. Third, it picks one company to go first, where the owner is strongest and the data easiest to reach, with a second company lined up to adapt the result.

Take an illustrative group with retail, manufacturing and energy companies. Supplier invoices appear in all three: read the invoice, match it to the purchase order and receipt, draft the entry, and have an accountant approve it. The manufacturer goes first, because its accounts payable lead is keen and read access to its ERP is already agreed. Retail adapts the pattern next: many small suppliers bring high volume, and structured e-invoices arrive as data rather than documents. The energy company follows, adding contractor invoices checked against service records.

What travels is the pattern: the extraction and matching approach, the evaluation template, the review screen design, the security review and the provider contract. What stays local is each ERP integration, the approval thresholds, the language mix and the reference answers from each company’s own accountants.

## How do you spread what works?

As patterns, not copies. A pattern is a package: the design and the reasons behind it, the evaluation template, prompts, the review screen, the runbook and the known failure modes. Each adopting company re-baselines its own work, adds its own cases to the evaluation set before go-live and reports its results separately, because its cases, language and systems differ.

Then make success visible. Owners from different companies meet regularly to compare results and problems, the group register shows which patterns run where, and each company’s leadership sees what a pattern did for a sister company, measured against a baseline. Success in one company is a better argument for the others than any mandate. The group [AI roadmap](https://veridive.com/insights/ai-roadmap-template/) then shows each company’s lines, with shared foundations attached to the lines that need them.

## How should costs and data be kept apart?

**Costs.** Three common options:

- **Central foundations, local workflows,** the sensible default: the group funds contracts, shared components, evaluation practice and training, and each company funds building and running its own workflows.
- **Full recharge:** foundations are recharged to companies by usage, which is fairer but slower to agree.
- **Seed funding:** the group funds each company’s first workflow, then company budgets take over.

Whichever you choose, tag model usage by company from the start, so running costs can be traced and recharged without argument.

**Data.** Because group companies are usually separate legal entities, ask counsel and your data protection officer how data may move between them under KVKK or GDPR, including transfers between countries; [the questions to ask your DPO](https://veridive.com/insights/kvkk-gdpr-ai-questions/) are a good starting list. By default, keep each company’s data, search indexes and access separate, share patterns and templates rather than data, and put anonymized or synthetic examples into shared material only where counsel agrees.

## Look for the workflow that recurs

Ask each company for three candidate workflows with named owners, and look for the one that recurs. [AI strategy and discovery](https://veridive.com/services/ai-strategy/) can map it across companies, [data and AI foundations](https://veridive.com/services/data-ai-foundations/) covers the shared layer, and an [Executive Build Day](https://veridive.com/services/#ways-in) with the group’s leadership is a practical first step.

This note is general information, not legal advice.

## Frequently asked questions

### How should a holding company approach AI?

Share what every company needs and shouldn’t buy or build alone: model access and contracts, security patterns, evaluation practice and training. Leave the choice of workflows, their ownership and their integration to each company, which knows its own work. Start with a workflow that recurs across companies, prove it in one, then adapt the pattern in the others.

### Can companies in a group share AI systems and data?

They can usually share patterns, templates, contracts and components more easily than data. Group companies are often separate legal entities, so moving personal or confidential data between them, even for a shared evaluation set or search index, is a question for counsel and the data protection officer under KVKK or GDPR. By default, keep each company’s data, indexes and access separate.
