Organisations should rethink their Configuration Management in the age of Artificial Intelligence, says Cam Bianchi.
Over the last few decades, we’ve seen that every technology cycle has its silver bullet. Cloud promised unlimited agility. Automation promised operational efficiencies. Now Artificial Intelligence promises to solve decades of Configuration Management challenges.
“Turn on AI within your ITSM platform, connect your discovery tools, point it at your data sources and you’ll have an accurate, trustworthy CMDB!”. Unfortunately, it doesn’t work quite like that.
AI is incredibly good at recognising patterns, identifying anomalies and supporting human decision making. What it can’t do is invent governance or decide what “good” looks like for your organisation. Like every other technology investment before it, AI simply amplifies the quality of the foundations beneath it.
If your strategy for configuration management is poorly defined, AI won’t fix this. It will simply help you fail faster… and potentially at a greater cost to your business.
AI Is only as good as the data you give it
I’m sure every IT professional has heard the phrase: “Garbage in, garbage out.” AI hasn’t changed that principle. In fact, in many ways, it has made it even more important.
Machine learning models excel at recognising relationships and patterns between information. They can identify duplicate Configuration Items at pace, spot unusual or unauthorised changes, recommend appropriate relationships and can even predict where data quality issues are likely to exist. These are exactly the capabilities that make AI so valuable in Configuration Management.
But none of these matter if the underlying data lacks consistency. If your organisation and its suppliers have five different naming conventions for the same type of server, business application records exist without owners, software assets cannot be linked to hardware… AI has no reliable definition of what “correct” looks like. Instead of creating trust, it just creates a confidence in inaccurate information which leads organisations down the pathway of untrustworthy data. Which I’d argue is more dangerous than not jumping into AI at all.
It’s no different to asking a satnav to navigate using an outdated map. It will still give you directions, it just can’t guarantee it’s the best route to lead you to the destination you intended.
Strategy before technology
One of the biggest mistakes organisations make is treating AI as a feature instead of a capability. Switching on AI isn’t a strategy but adopting it effectively is.
Start with three questions: Why do we need a CMDB to exist? Who owns and manages the accuracy of the data? Which outcomes do we need to deliver? These questions existed long before AI.
The difference now is that AI forces organisations to answer them. Without clear answers, AI simply exposes the weaknesses that already existed.
Another trend I see is organisations being encouraged to start again with a clean CMDB, so AI has a pristine baseline to learn from. While that sounds attractive, there’s a risk of discarding years of operational knowledge in pursuit of perfection. Of course, legacy data contains noise, but it often contains invaluable business context too. Good Configuration Management isn’t about erasing history; it’s about understanding which of it still creates value.
Building AI principles and use cases into your strategy
AI often enters Configuration Management almost by default because it’s embedded within your ITSM tooling. Rather than allowing the technology to dictate how it is used, organisations should design the Configuration Management standards, governance and controls that enable AI to support clearly defined business outcomes in a trusted and controlled manner.
The four foundations of your strategy that I would focus on first would be:
Data standards
AI needs consistency to be powerful such as a minimum dataset with consistent CI classes and definitions, standard naming conventions, defined relationships, mandatory ownership and lifecycle states, all documented and translates data standards into meaning something to everyone.
These standards give AI a definition of “good” but without them, every analysis and recommendation AI produces becomes subjective depending on the user’s interpretation and knowledge of the maturity of the individual fields and values being assessed.
Business-led use cases
Don’t collect Configuration Items just because the platform allows you to. Collect them because they answer business questions. When I work with organisations to develop configuration management strategies and policies, I always guide them towards a baseline understanding of their existing related strategies (like their Digital, Data and ITSM strategies) and get them to ask questions like:
- Does tracking this help improve your cyber resilience?
- Does tracking this improve our understanding of related services, dependencies or risks?
- Can this help assess change risk?
- Does this help with our financial decision-making & technology budget planning?
And remember that tracking a CI has a cost attached! If a CI contributes to none of these outcomes, you really must ask whether it belongs in your CMDB at all.
Data quality
Data quality shouldn’t just become a quarterly clean-up exercise for your Configuration Management team; it needs to become an operational discipline that’s supported by your people and technology.
This is where I find AI begins to provide real value to the practice. It shouldn’t add value by replacing all important data quality governance, but by continuously reinforcing it, as guided by the data policy your people have designed. Use AI as your data quality investigator and champion, showing you where the misaligned or miscategorised data is before they become a road blocker for your ITSM function. This keeps the human-in-the-loop because people apply the judgement to the evidence AI brings.
Governance
It should be reassuring to all of us in the IT industry that AI still requires human judgement. After all, our goal should be to become AI-enabled, not AI-replaced.
For example, AI may identify a recurring relationship between two CI classes and recommend adding it to your service model. What it cannot decide is whether that relationship reflects how your organisation delivers services or who should own them. Those decisions remain firmly with people.
Policies. Decision makers. Defined ownership and escalation paths. The organisations that will succeed in the advent of AI won’t have fewer governance processes but simply have smarter ones that deliver outcomes faster and more cost effectively. And that’s because these organisations use their people who know their culture and how the business operates, to work with AI to develop governance and necessary workflows that are robust and achievable without affecting delivery.
Think of data standards, governance and ownership being the equivalent of keeping the map up to date. Without continual maintenance, even the smartest navigation system gradually becomes less reliable.
Where AI can truly add value to Configuration Management
When these strategic foundations exist, AI becomes incredibly powerful. Not because it replaces Configuration Managers but because it removes the bottleneck of the repetitive work.
Imagine if AI is used to continuously:
- Detect orphaned Configuration Items and unusual relationships before a Change Request gets to CAB.
- Identify conflicting discovery records and recommend reconciliation actions.
- Validate new service models against defined standards before the busy service owner must commit their time to a weeklong review.
- Prepare audit reports and evidence for monthly governance meetings.
- Identify trends before they become operational issues that the service desk bares the pain of.
- Highlighting legacy technology and technology debt that could put your business at risk.
Unlike people, AI doesn’t experience review and decision fatigue. It doesn’t become bored after reviewing thousands of CI records. It doesn’t overlook anomalies because it’s Friday afternoon and you’re already busy supporting resolving a major incident. Instead, it becomes the analytical engine that supports Configuration Management teams while allowing experienced practitioners to focus on governance, stakeholder engagement, identifying technical debt, strategic decision-making and continual improvement of the practice.
Think of AI less as an autonomous Configuration Manager and more as an exceptionally capable sidekick that accelerates the heartbeat of your ITSM function.
Don’t ignore the risks
Of course, there is another very important side to this conversation. I often describe the CMDB, if done right, as the crown jewels of any organisation’s IT operations. And that’s for good reason, because it doesn’t just contain an inventory list of servers and applications. A mature CMDB can contain infrastructure locations, network information, IP and MAC addressing, vulnerability information, software deployments, service dependencies, business criticality and ownership data all in one place. When you take all this together, that’s an extraordinarily detailed blueprint of how an organisation operates.
Exactly the type of information a threat actor would love to obtain. And introducing AI into your environment requires careful consideration, especially if you don’t have Robert De Niro-style character on hand to sign off on its entry into your organisation’s ‘circle of trust’!
Questions that you should be asking are “where is the model hosted?” “Which data is being shared and what data is ringfenced in a dedicated environment for privileged access?”, “What information from prompting is retained and does it align to your retention policy?” and “How is sensitive information protected?”.
These questions should be answered with your security, cyber and risk teams, not after you’ve been blinded by the limitless capabilities AI can offer. AI governance should become a part of your configuration management and broader data information governance, not treated as a separate discipline.
AI as a configuration item
Ironically, in the rush of AI, many organisations are overlooking one final point around how AI itself is managed.
Whether it’s an embedded capability within your ITSM platform or an enterprise AI service used across multiple departments, it is still an application providing business capability.
Which means it has models and versions, owners and suppliers, licences, integrations, security requirements, lifecycle activities, and business dependencies. And let’s not forget modern considerations like prompt history, approval workflows and decision logs.
This all sounds familiar…oh yes, it’s exactly how I help organisations define the characteristics of what is a Configuration Item. Yes, AI is essentially another CI that needs to be controlled.
Tomorrow’s auditors may ask which model produced a recommendation, which version was in use and whether the output was reviewed by a human. That makes AI not just an application, but another Configuration Item that deserves governance, just like every other critical business application.
Final thoughts
The conversation shouldn’t be whether AI will replace Configuration Management. In my opinion, it won’t. The real goal should be building a Configuration Management practice that enables AI to deliver meaningful business value.
The organisations that succeed won’t necessarily have the most advanced AI solution. It will be the ones that have the clearest strategy, that supports them in understanding their data, knowing which outcomes they must deliver and a governance that people can trust and implement.
And they’ll use AI exactly as it should be used, not as a replacement for good Configuration Management, but as a multiplier for it.
In the end, AI is an enabler, not the strategy. Your strategy is what gives your practice and AI capability its direction, purpose and guardrails. Build that foundation well, and AI won’t just help you manage your estate more effectively; it’ll help you make better decisions across the organisation.
Think of AI as your organisation’s satnav. It can optimise the journey, warn of obstacles and help you reach your destination more efficiently. But your configuration management strategy provides the map. Keep that map accurate, governed and aligned to where the organisation needs to go, and AI becomes a powerful guide. Neglect it, and even the smartest navigation system can confidently take you down the wrong road.

Cam Bianchi
Cam Bianchi is a Managing ITSM Consultant at CGI