Most AI projects don't fail because the model is bad. They fail because nobody was in the room when the real problem was being explained. A slide deck gets built, a proof-of-concept gets demoed, everyone nods — and then it dies in the gap between the vendor's assumptions and the client's actual workflow. If you've ever signed off on an AI initiative that looked brilliant in the pitch and evaporated in production, you already understand the problem this article is about.
Forward Deployed AI Engineering (FDAI) exists to close that gap. Not as a marketing label, but as an operating model. And it stands in direct opposition to the way most AI agencies still work.
What "Forward Deployed" Actually Means
The term comes from a simple military and enterprise idea: you put your best engineers where the problem lives, not where the office is. Instead of a client filing a ticket and waiting for a remote team to interpret it, a forward deployed engineer sits inside the client's environment — attending their standups, reading their logs, watching their analysts work, and building alongside them.
This is a fundamentally different posture from the traditional agency. The ordinary model looks like this:
- Discovery workshop (a few days of interviews)
- Scope document and statement of work
- Development happens off-site, behind a wall
- Delivery, handover, and an invoice
By the time the deliverable arrives, the business has moved on, the threat landscape has shifted, and the tool solves a problem that was accurately described three months ago. FDAI collapses that cycle. The engineer learns the context in real time and ships small, working increments that get tested against reality every week.
The difference isn't the AI. It's the proximity. Proximity is what turns a generic model into an operational tool.
Why the Ordinary Agency Model Fails
The agency model isn't stupid — it's optimised for the wrong thing. Agencies are built to be repeatable and scalable, which means they gravitate toward templated solutions they can resell. That works fine for a website or a marketing campaign. It falls apart for AI, because AI's value is almost entirely in the specifics.
Consider a South African bank trying to detect fraudulent transactions. An off-the-shelf fraud model trained on US or European data will flag legitimate behaviour it doesn't understand — a customer sending money home across the border, a spaza shop owner making dozens of small cash deposits, a spike in activity around month-end payday that looks nothing like Northern Hemisphere patterns. The model isn't wrong; it's foreign. It has no idea what normal looks like here.
The three structural failures of the agency approach:
- Context loss. Requirements get flattened into a document and everything nuanced gets lost. The engineer who builds the thing never met the analyst who has to use it.
- Slow feedback loops. When you only show the client the result at the end, you've bet the entire budget on a single interpretation being correct.
- Ownership handover. The agency leaves. The client is now sitting on a system nobody internally understands, hoping it keeps working. When it drifts — and AI models always drift — there's no one to call.
For a CISO, that last point is the killer. You don't just want a detection model delivered. You need something your team can operate, tune, and defend at 2am during an incident.
What This Looks Like in a Real Security Environment
Let's make it concrete. Imagine a mid-sized South African insurer that wants to reduce the noise its SOC analysts drown in every day. The traditional agency answer is "we'll build you an anomaly detection model." Fine. But which anomalies? Ranked how? Integrated into which console? Escalated to whom?
A forward deployed engineer approaches it differently:
- Spends the first week shadowing analysts, watching which alerts they dismiss instantly and which ones make them nervous. That tacit knowledge never makes it into a requirements doc.
- Discovers that half the "urgent" alerts are actually caused by load-shedding — systems dropping offline and reconnecting, generating auth failures and session anomalies that look like attacks but aren't. A generic model would keep screaming about these forever.
- Builds a first version that suppresses the load-shedding noise and surfaces the twelve alerts that actually matter, then sits with the team to see if that ranking feels right.
- Iterates weekly, tuning against feedback, until the analysts trust the output enough to act on it without second-guessing.
That's the entire game. An AI tool is only as valuable as the degree to which the people using it trust and act on it. Trust is built through proximity and iteration, not through a polished handover deck.
The POPIA and Sovereignty Dimension
There's a specifically South African reason FDAI matters more here than in many other markets: data can't always leave the building. Under POPIA, moving personal information around — especially to offshore models and third-party APIs — carries real compliance weight. Many enterprises, particularly in financial services and healthcare, simply cannot ship their sensitive data to an external agency's cloud environment for training and testing.
The forward deployed model handles this naturally. The engineer works inside your environment, with your data governance in place, your access controls respected, and your data residency requirements honoured. Nothing gets exported to be processed in a vendor's sandbox. The AI is built where the data lives, under your rules.
This isn't a minor compliance footnote. For a South African CISO, it's often the deciding factor between an AI project being viable and being a legal non-starter. An agency that wants to take your customer data offshore to build a model is asking you to accept a risk you probably shouldn't.
The Rand Economics of Getting It Right
There's also a hard financial argument. AI projects are expensive, and in rand terms the cost of a failed initiative is brutal — you've paid international-grade rates for something that never made it into production. The traditional agency model front-loads risk: you commit a large budget against a scope that may not survive contact with reality.
FDAI de-risks the spend by structuring it around small, verifiable increments. You see working software early. You can kill or pivot a direction before it consumes the whole budget. And because the engineer transfers knowledge to your team as they go, you're not left dependent on an external party forever, paying retainer after retainer just to keep the lights on.
Better ROI here isn't a slogan. It comes from three concrete mechanics: less rework, faster time to actual production use, and internal capability that outlives the engagement.
Takeaways for Security Leaders
If you're a CISO or technology leader evaluating how to bring AI into your defence strategy, here's what to hold onto:
- Judge vendors on proximity, not polish. Ask how they'll embed with your team. If the answer is "we'll take your requirements and come back in eight weeks," you're buying the old model.
- Insist on working increments. Value should show up in weeks, not at the end. Short feedback loops are your best protection against a wasted budget.
- Make data sovereignty non-negotiable. Under POPIA, where and how your data is processed is your problem, not the vendor's. Build inside your own walls where possible.
- Demand knowledge transfer. The goal isn't a black box you can't touch. It's a tool your own people understand, operate, and improve after the engineer leaves.
- Remember that trust is the real deliverable. A model your analysts ignore is worth nothing. One they act on decisively is worth everything.
The threats aren't slowing down, and neither is the pressure to "do something with AI." The organisations that win won't be the ones that bought the flashiest platform. They'll be the ones who put skilled engineers next to real problems, in their own environment, and built something that actually works. That's what Forward Deployed AI Engineering means — and it's why the ordinary agency model keeps falling short.
How are you currently integrating AI into your defence strategy — and where has the traditional vendor model let you down? We'd genuinely like to hear about it.