The model is not the system: Why curated AI pipelines matter

Detail of screen displaying data
  • Blog
  • 3 minute read
  • July 2026

Much of the current AI debate still starts with the model: which provider, which version and whether the latest features unlock more value. That is understandable, but it is becoming the wrong level of analysis.

In practice, an AI service is more than a model. The model sits within a wider harness of approved data, prompts, tools, permissions, rules, validation, monitoring and human intervention. The pipeline determines how work moves through those components. Together, they define what the system is allowed to do and how much reliance can sensibly be placed on its output.

This explains why two AI tools can look almost identical in use and still present very different risks. Both may produce fluent summaries or recommendations. One may be restricted to approved sources, checked against defined rules and required to escalate uncertainty. The other may be a general-purpose model connected directly to business data. The user experience may be similar. The control environment is not.

The same point applies to small language models (SLMs). By 2027, firms are likely to use more SLMs running locally or within their own infrastructure, partly to reduce token costs and partly to improve privacy, latency and resilience. A small model may perform very well when extracting names, dates or clauses from a defined document set. That does not mean it should interpret policy, resolve a complex ownership structure or determine whether a customer requires enhanced due diligence. Suitability depends on the task, the evidence available, the surrounding controls and the consequence of error — not model size alone.

A curated pipeline assigns each part of the work to the component best suited to it. An SLM might handle routine extraction. Retrieval can provide approved source material. Deterministic code or a rules engine can apply clear policy requirements. A stronger model can address harder interpretation, with material judgement reserved for an accountable human. The pipeline should also determine when work moves between those stages and retain enough evidence to explain what happened.

This is particularly important in regulated processes. In customer onboarding, AI can help identify missing documents, summarise ownership structures and prepare a file for review. It should not quietly become the mechanism that determines the risk rating or whether an escalation rule has been met. Fluency is not the same as controlled policy execution.

The JFSC’s guidance issued on 14 July takes a similarly proportionate view. It does not create new requirements but expects firms to apply existing obligations according to the impact of the use case. Low-impact productivity tools may justify lighter controls; customer onboarding, lending decisions and investment advice warrant stronger ones. The Commission’s central point is uncomplicated: firms remain accountable for outcomes when they use AI.

For boards and executives, the question is no longer simply which model has been selected. It is whether the overall pipeline has been deliberately curated: which data it can access, what guard rails are in place including how the output is tested and validated, where human judgement sits, how changes are controlled and what evidence will be available afterwards.

The model matters. The curated system around it matters more.

Contact us

Christopher Eaton

Christopher Eaton

Chief Technical Officer Advisory and Head of Risk Assurance, PwC Channel Islands

Mark Hunter

Mark Hunter

Advisory Partner, PwC Channel Islands

Follow us