AI for CIOs and IT leaders in fashion: architecture, data and governance
What fashion CIOs and IT leaders need to get right for AI: product and sales data foundations, integration architecture, build or buy, security, EU AI Act duties and governance frameworks.
KEY TAKEAWAYS Summary by the editors
- For fashion CIOs, the decisive AI work is less about choosing models and more about product, sales and stock data foundations, integration and governance.
- Gartner reported in February 2025 that 63 percent of organisations lack or are unsure whether they have the right data management practices for AI, and predicted that 60 percent of AI projects without AI-ready data will be abandoned through 2026.
- Under the EU AI Omnibus published in July 2026, obligations for high-risk AI systems listed in Annex III, such as some employment uses, now apply from 2 December 2027.
- ISO/IEC 42001:2023 and the voluntary NIST AI Risk Management Framework provide established structures for an AI management system and risk process.
- IT leaders should run AI as a governed portfolio with an inventory of all AI uses, approved tools, data access rules and monitoring, rather than as isolated pilots.
For CIOs and IT leaders in fashion, AI success depends on three things: clean, connected product, sales and stock data; an architecture that lets models and AI services plug into ERP, planning, PIM, commerce and wholesale systems; and governance that covers security, privacy and regulation. Model choice matters less than these foundations, and many projects stall on data and integration.
What is the CIO's role in AI in a fashion company?
Fashion IT landscapes are typically fragmented: ERP, product lifecycle management, product information management, merchandise planning, warehouse, e-commerce, marketplaces, wholesale ordering and retail point of sale, often from different vendors and acquired over many years. Business teams now bring AI requests from every direction: buyers want forecasts, designers want image tools, e-commerce wants assistants, finance wants automation. The CIO's job is to turn this into a coherent portfolio that is secure, compliant and built on shared data, and to stop a sprawl of disconnected tools.
A practical way to do this is a reference architecture with a small number of approved patterns: AI features inside existing platforms, a secure enterprise assistant for general productivity, retrieval over curated company knowledge, and custom models only where data and value justify them. Each pattern comes with standard rules for identity, logging, data access and cost tracking, so new requests can be assessed quickly instead of being treated as one-off projects.
What data foundations does AI need?
Gartner reported in February 2025 that 63 percent of organisations either do not have or are unsure whether they have the right data management practices for AI, and predicted that through 2026 organisations will abandon 60 percent of AI projects unsupported by AI-ready data. Its recommendations include aligning data to specific use cases, evolving metadata management, preparing pipelines and continuously monitoring data quality. In fashion, the priorities are usually:
- A single product record with consistent attributes, images and identifiers across PLM, PIM, ERP and channels.
- Sales, stock and returns at SKU, size and location level across retail, e-commerce and wholesale, including sell-out data from wholesale partners where available.
- Customer data with consent records for personalisation and service.
- Unstructured knowledge (policies, care instructions, supplier documents) prepared for retrieval by language models.
- Metadata and lineage so teams know where data comes from and who owns it.
Which AI capabilities should IT build, buy or enable?
| Task | What AI does | Data needed | Maturity |
|---|---|---|---|
| Forecasting and planning models | Predicts demand and proposes allocation, replenishment, markdowns | Integrated sales, stock, product and price history | Established |
| AI features in existing platforms | Search, recommendations, content generation inside commerce and PIM tools | Clean product and behavioural data | Established |
| Enterprise AI assistants | Secure access to language models for drafting, summarising, analysis | Identity, access rights, data classification | Established |
| Retrieval over company knowledge | Answers questions from policies, product and supplier documents | Curated document stores, permissions | Emerging |
| Product data enrichment | Tags attributes from images, translates and checks data | Images, attribute taxonomy, validation rules | Emerging |
| Agentic workflows across systems | Executes multi-step tasks across ERP, planning and commerce | APIs, permissions, audit trails, approval rules | Experimental |
On build or buy, many fashion companies will buy most capabilities and reserve internal engineering for integration, data and genuinely differentiating use cases. On agents, caution is warranted: Gartner predicted in June 2025 that over 40 percent of agentic AI projects will be cancelled by the end of 2027 and warned of agent washing by vendors rebranding existing products.
What does the EU AI Act mean for fashion IT?
Most fashion use cases (forecasting, recommendations, content) are not high-risk under the EU AI Act, but some are regulated. According to the Future of Privacy Forum's analysis of the AI Omnibus, published in the Official Journal on 24 July 2026, Article 50 transparency duties for chatbots and synthetic content apply from 2 August 2026, and obligations for high-risk systems listed in Annex III, which include certain uses in employment, apply from 2 December 2027. The AI literacy duty in Article 4 remains in force in a softened form, requiring organisations to support the development of AI literacy. HR uses such as AI screening of job applicants therefore need particular attention.
How should IT leaders govern AI?
- Keep an AI inventory of every tool, feature and model in use, including AI switched on inside existing software.
- Classify use cases by risk, including EU AI Act categories, data protection and brand risk.
- Approve tools and data flows: which data classes may go to which providers, and under which contract terms.
- Adopt a framework: ISO/IEC 42001:2023 specifies requirements for an AI management system, and the NIST AI Risk Management Framework, released in January 2023 for voluntary use, organises work into govern, map, measure and manage, with a generative AI profile added in July 2024.
- Monitor in production: quality, drift, cost, security incidents and user feedback.
What stays human, and how can IT leaders start in 30 days?
Architecture decisions, vendor selection, risk acceptance and accountability for security and compliance remain with people, as does the prioritisation of business requests. Skills to build in IT teams include data engineering and product data management, integration and API design, AI security, model monitoring and cost management, and working knowledge of AI regulation.
Frequently asked questions
What should a fashion CIO prioritise for AI?
Data foundations first, especially consistent product data and integrated sales, stock and returns data, followed by integration architecture and governance. These determine whether forecasting, personalisation and assistants can deliver value at scale.
Should fashion companies build or buy AI?
Most capabilities, such as forecasting tools or AI features in commerce platforms, are usually bought, because they need less engineering and come with maintained integrations. Internal teams typically focus on integration, data and differentiating use cases.
Which AI uses in fashion are high-risk under the EU AI Act?
Most typical fashion uses such as forecasting, recommendations and content generation are not high-risk. Uses listed in Annex III, including certain employment uses such as screening job applicants, are, and their obligations apply from 2 December 2027 after the AI Omnibus. Chatbots and synthetic content carry transparency duties.
What is ISO/IEC 42001?
ISO/IEC 42001:2023 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It helps organisations govern the development, provision and use of AI with defined policies, objectives and processes.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- Gartner: Lack of AI-ready data puts AI projects at risk
- Future of Privacy Forum: The AI Act implementation timeline: what changes under the AI Omnibus?
- ISO: ISO/IEC 42001:2023 Artificial intelligence management system
- NIST: AI Risk Management Framework
- Gartner: Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027