Back to The Structure ReportArtificial intelligence

PMI Has Published an AI Standard for Project Work: What GCC PMOs Should Operationalise First

PMI’s June 2026 AI standard gives project organisations a common foundation for responsible AI-enabled work. This independent PM Structure interpretation translates it into practical controls for GCC PMOs.

PMO & Transformation MentorPMO & Transformation MentorJul 25, 202613 min read
GCC PMO leaders reviewing AI use and AI projects through a shared governance model.

AI adoption is no longer waiting for an enterprise operating model. Project teams are already using it to summarise meetings, draft communications, cluster risks, test scenarios and support forecasts. At the same time, organisations are commissioning programmes whose product, service or operating capability is itself powered by AI.

The governance gap between those two realities has become a project-management problem.

In June 2026, the Project Management Institute published The Standard for Artificial Intelligence in Portfolio, Program and Project Management. PMI describes it as a technology-agnostic standard for project professionals, PMO leaders, executives and organisations adopting AI. It addresses both the use of AI in project-based work and the management of AI-driven initiatives. PMI’s implementation article of 14 July 2026 frames the urgency directly: adoption has moved faster than organisational alignment. (Project Management Institute) (Project Management Institute) (Project Management Institute)

That matters in GCC portfolios where regulated delivery, major transformation programmes, cross-border suppliers and multi-party governance frequently meet. A recommendation generated in one workstream may influence funding, safety, procurement, workforce or customer decisions elsewhere. The question is therefore not simply whether a team has permission to use an AI tool. It is whether the organisation can explain what the tool influenced, who accepted the result and what evidence supports the decision.

The PMO should not begin by selecting one platform for everyone. It should begin by defining the decisions AI may support, the controls proportionate to those decisions and the evidence that must remain reconstructable.

Two responsibilities, one PMO

The first responsibility is AI used inside ordinary project work.

Examples include drafting a status update, summarising a workshop, proposing schedule scenarios, identifying patterns in risk data or preparing an initial stakeholder analysis. The project’s intended output may have nothing to do with AI, but AI is influencing how the work is planned, governed or delivered.

The second responsibility is an initiative whose product or capability is AI-driven.

Examples include a predictive maintenance service, an automated eligibility workflow, a demand-forecasting model, an AI-enabled customer channel or an organisation-wide capability transformation. Here, data, model behaviour, integration, adoption, operating accountability and ongoing monitoring are part of what the project must deliver.

These responsibilities need connected controls, but not identical ones. A low-consequence drafting aid should not carry the same approval burden as a model influencing safety, employment or financial decisions. Conversely, calling a use case “only a pilot” should not exempt it from scrutiny when it uses sensitive information or affects external stakeholders.

PMI’s standard provides the common foundation. It includes eight guiding principles, five performance domains, human-in-the-loop practices, ethical and legal considerations, lifecycle guidance, tailoring and applied project use cases. It does not depend on a particular vendor or product generation. (Project Management Institute)

The PMO’s role is to translate that foundation into an operating language shared by portfolio owners, delivery teams, legal counsel, audit, cyber security, data teams, procurement and business operations. That translation should sit alongside the organisation’s established project-governance framework, not become a separate technology bureaucracy.

PM Structure’s independent operating interpretation

The controls below are PM Structure’s independent operating interpretation of the issues a PMO should operationalise. They are not PMI’s official checklist and do not reproduce the standard’s proprietary tables.

1. Purpose and value

Every registered AI use should state the problem, intended user, expected benefit and decision it will support. “Use AI to improve productivity” is too broad. “Reduce the time required to prepare a first draft of the weekly portfolio narrative while the portfolio analyst remains accountable for accuracy” is governable.

The business owner should define the baseline and the acceptable result before deployment. Otherwise, the team may celebrate automation without proving project value delivery.

2. Human accountability

Name the person who can accept, challenge or override an AI-influenced output. Human review must be a real control, not a disclaimer placed beneath an automated decision. The accountable owner needs sufficient authority, competence, time and access to evidence.

For material decisions, the record should show what the system proposed, what the human decided and why.

3. Data and source control

Define which data classes and sources are approved, restricted or prohibited. Record source ownership, quality expectations, retention rules and any limits on using confidential project information. An attractive output cannot compensate for an unknown or unsuitable source.

Teams also need a method for checking citations, calculations, completeness and version relevance before an output enters a decision pack.

4. Proportional risk

Controls should scale with consequence, reversibility, affected stakeholders, data sensitivity and the degree of automation. A draft internal agenda and a recommendation affecting contractor eligibility do not belong in the same category.

Risk classification should determine validation depth, approval level, monitoring frequency, evidence retention and escalation.

5. Transparency and traceability

The PMO needs enough information to reconstruct material AI-influenced decisions. That may include the purpose, tool or model version, input source, date, reviewer, validation performed, output used and final decision.

Traceability should be practical. It is not necessary to preserve every experimental prompt, but material recommendations must not arrive in governance forums as untraceable facts.

6. Ethical, legal and contractual duties

AI use may engage privacy, intellectual property, employment, consumer, sector, contractual or records-management obligations. The relevant specialists must interpret those duties. The PMO’s responsibility is to identify the interfaces early, route decisions to the right authority and retain evidence of the outcome.

Reading a standard or this article does not establish legal or regulatory compliance.

7. Lifecycle monitoring

Approval at go-live is not the end of control. Data changes, supplier updates, model changes, user workarounds and operating drift can alter performance. The owner needs review triggers, thresholds and a retirement or replacement plan.

8. Stakeholder readiness

Users must understand what the AI capability can and cannot do, when human judgement is required and how to report concerns. Readiness includes operating procedures, decision rights, training, communications and support—not merely access to a tool.

A three-tier AI-use register

A practical PMO needs visibility before it can govern proportionately. The following three-tier register is an original PM Structure model, not a classification issued by PMI.

Tier 1 — Assistive or low consequence

This tier covers drafting, formatting, summarising or idea generation where a competent person reviews the output before use and an error would be readily reversible.

Minimum register fields should include the business purpose, named owner, approved data types, review expectation and approved environment. The human author remains responsible for the final content. Confidential information should not be entered into an unapproved service simply because the output is “only a draft”.

Tier 2 — Analytical or materially influential

This tier includes forecasting, prioritisation, risk scoring, anomaly detection, resource recommendations or analysis that can materially influence a project decision.

The PMO should require an accountable decision owner, defined input sources, validation against a baseline or control sample, known limitations, a record of the recommendation and evidence of the human decision. Thresholds should specify when the output must be challenged, independently checked or escalated.

The business case should also explain what improves: forecast reliability, decision speed, risk detection, rework or another outcome—not just the number of reports generated.

Tier 3 — High consequence or externally impactful

This tier covers AI-influenced decisions affecting safety, employment, eligibility, finance, regulatory outcomes, public services, contractual rights or significant customer interests.

Controls should include formal cross-functional approval, explicit human authority, stronger validation, documented impact assessment, security and data review, contractual safeguards, change control, incident handling, audit evidence and scheduled monitoring. Deployment should not proceed until ownership in business-as-usual operations is accepted.

The tier does not determine whether a use is permissible. It determines the minimum route for organisational review. Legal, regulatory and sector authorities remain responsible for their respective conclusions.

Across all three tiers, the register should answer six questions: What is the use? Who owns it? Which data and system are involved? What decision can it influence? What validation and monitoring apply? Where is the evidence retained?

Connect legal, audit, cyber, procurement and delivery

AI governance often fails at interfaces. Legal reviews an agreement, cyber reviews access, procurement reviews price and the project team reviews schedule—but nobody owns the complete control chain.

The PMO can solve this by creating one cross-functional approval path triggered by the AI-use tier and lifecycle stage. It need not make every function approve every use. It should make responsibilities and hand-offs explicit.

For externally supplied capability, procurement and contract owners may need to address:

  • permitted data use and data location;
  • ownership and permitted use of inputs, outputs and intellectual property;
  • supplier notification of material model, service or subcontractor changes;
  • security, incident notification and service-continuity obligations;
  • access to evidence and audit rights proportionate to the engagement;
  • performance, acceptance and remediation provisions;
  • transition, portability and exit arrangements.

These are control topics for qualified commercial, legal, cyber and procurement specialists to resolve. They are not template clauses to copy without review.

Audit needs evidence that connects the approval to operating reality: the registered use, risk tier, accountable owner, review result, accepted limitations and monitoring history. Delivery teams need those requirements early enough to build them into scope, acceptance criteria, backlog items, stage gates and supplier deliverables.

A monthly AI governance forum is useful only if decisions reach the work. The stronger mechanism is a defined route from the register to planning, procurement, design, testing, deployment and benefits review.

Govern the lifecycle, not only go-live

PMI explicitly includes lifecycle and tailoring considerations, and describes application across predictive, adaptive and hybrid environments. (Project Management Institute) The PMO can therefore combine formal stage gates with iterative product reviews rather than choosing one method for every initiative.

At concept and business case, define the intended value, affected stakeholders, decision boundaries and initial tier. Ask whether AI is necessary or whether a simpler solution would deliver the outcome with less risk.

At data and design, document data ownership, quality, permitted use, key assumptions, user roles and human decision points. Identify what must be explainable and to whom.

At testing and validation, assess performance against agreed measures and realistic scenarios. Include weak data, edge cases, foreseeable misuse and affected stakeholder perspectives where relevant. Record limitations rather than hiding them in technical documentation.

At deployment readiness, confirm operating ownership, user preparation, support, monitoring, incident response, supplier obligations, evidence retention and rollback or containment options.

During operation, monitor more than uptime. Review output quality, drift, control exceptions, overrides, incidents, adoption and realised value. A material supplier or model change should trigger reassessment, not be treated as routine maintenance.

At retirement or replacement, control the removal of access, data retention or deletion, downstream dependencies, record preservation and transition of affected users or processes.

The governance cadence should be tailored. A Tier 1 drafting aid may receive periodic control sampling. A Tier 2 forecasting workflow may need monthly accuracy and override reviews. A Tier 3 capability may require continuous monitoring and formal governance reporting. Proportionality makes governance usable; it does not make accountability optional.

Measure value without rewarding uncontrolled automation

Time saved is useful evidence, but it is not a complete value case.

If a reporting workflow becomes faster while inaccuracies, rework or governance exceptions rise, the portfolio has not necessarily improved. If a forecast arrives earlier but decision-makers do not trust it, adoption remains weak. If automation shifts effort from analysts to reviewers without measuring the new load, the benefit is overstated.

Each AI use should therefore have a baseline, a benefit owner and a balanced set of measures. Depending on the use, those may include:

  • decision quality or forecast accuracy;
  • cycle time and effort released;
  • rework and defect rates;
  • adoption and appropriate override rates;
  • control exceptions and incidents;
  • stakeholder confidence;
  • customer, safety, financial or delivery outcomes;
  • the cost of monitoring and maintaining the capability.

No universal return-on-investment figure should be invented. The organisation should agree what value means for the specific decision or workflow, then compare actual performance with the baseline and the cost of control.

What the refreshed PMP signals to professionals

The refreshed PMP examination launched in July 2026 incorporates AI in project-based scenarios and increases the emphasis on judgement, value and business impact. PMI’s exam information also places AI alongside sustainability, stakeholder engagement and adaptive delivery rather than treating it as a list of software features. (Project Management Institute) (Project Management Institute)

That signals an important development for practitioners: professional competence is not demonstrated by memorising tool brands. It is demonstrated by making defensible decisions about purpose, data, risk, stakeholders, human accountability and value.

A candidate should be able to reason through questions such as:

  • When is an AI output advisory, and when has it become a material decision input?
  • Who should validate it?
  • What changes the level of risk?
  • Which stakeholders need to be involved?
  • What evidence supports acceptance or override?
  • How will value and unintended effects be monitored?

Our PMP exam 2026 guide connects these judgement demands to wider preparation. Professionals developing organisational capability can also explore AI in project management.

A 30-day PMO starting sequence

The first month should create visibility and one working control loop—not a large policy library.

Week 1: inventory the reality

Ask portfolio, programme and project leads to identify both AI used in ordinary delivery and initiatives delivering AI-enabled capability. Capture purpose, owner, affected decision, data, supplier and current status. Include informal uses already influencing work.

Week 2: classify and assign

Apply the three-tier register as an initial screening model. Confirm an accountable business owner and identify the required legal, cyber, data, audit, procurement and operational interfaces. Escalate uncertain or potentially high-consequence uses rather than forcing a premature classification.

Week 3: define minimum controls and evidence

For each tier, agree the minimum approval, validation, human review, record, monitoring and change-control expectations. Define where evidence will be stored and who can retrieve it. Align controls with existing governance forums and delivery methods.

Week 4: pilot one real workflow

Select one material but manageable portfolio or project workflow. Apply the register, validate the output, record the human decision, test monitoring and review the experience with all control functions. Use the findings to improve the operating model before expanding it.

PM Structure can support organisations that need an independent discussion about governance design, PMO controls and value delivery through our project-management advisory service.

The executive question at the end of the first month should be:

Which AI-influenced decisions can we reconstruct and defend?

If the answer is unclear, the priority is not another AI demonstration. It is accountable delivery.

Source and limitation note

This article was reviewed on 25 July 2026 against PMI’s official standard page, announcement, implementation article, AI learning resources and refreshed PMP materials. The control model, three-tier register and 30-day sequence are PM Structure’s independent operating interpretation. They do not replace the PMI standard, professional legal or regulatory advice, contractual review, cyber-security assessment or sector-specific authority.

References

  1. Project Management Institute — The Standard for Artificial Intelligence in Portfolio, Program and Project Management
  2. Project Management Institute — PMI Publishes World’s First Global Standard for AI in Project Work, 9 June 2026
  3. Project Management Institute — The New AI Standard: A Shared Foundation for Responsible Adoption, 14 July 2026
  4. Project Management Institute — Artificial Intelligence in Project Management
  5. Project Management Institute — New PMP exam launched in July 2026
  6. Project Management Institute — PMP Examination Content Outline, July 2026
PMO & Transformation Mentor

PM Structure Editorial Role

PMO & Transformation Mentor

A PM Structure editorial role covering PMO governance, transformation, portfolio delivery, and organisational capability.

View all articles by PMO & Transformation Mentor

This article is editorial content from PM Structure. It does not replace official certification-body guidance. For pathway and readiness support, explore certifications.

Take the next structured step

Use this article as a decision aid, then speak with PM Structure about your pathway and readiness.