What Is an Enterprise AI Strategy?
An enterprise AI strategy is not a list of AI projects. It is a short set of hard choices: what problem AI must help solve, where it will and will not be used, which shared capabilities to build and where the money goes, all traced back to the business strategy and revisited as the evidence comes in.
After this chapter you can
- Distinguish an AI strategy from a collection of AI projects, using Rumelt's kernel of diagnosis, guiding policy and coherent action.
- Explain why choosing what not to do is part of the strategy, and where the law has already made some refusals.
- Separate strategy from vision, roadmap, architecture and governance.
- Apply the trace-back test to an AI initiative and manage initiatives as a portfolio with shared capability.
- Describe AI strategy as a living management loop, not a document.
In October 2024, the Boston Consulting Group published a survey of 1,000 senior executives in 59 countries. Seventy-four percent of their companies had yet to show tangible value from AI. BCG called the other 26 percent “leaders”: 4 percent with cutting-edge capabilities that produced significant value consistently, and 22 percent beginning to see substantial gains. The striking difference between leaders and the rest was not how much the leaders did. It was how little. The leaders pursued, on average, only about half as many AI opportunities as their less advanced peers, and they expected more than twice the return on investment1. These are self-reported survey figures, and the expected return is a forecast, not a measured result.
Hold that finding against a question that comes up in boardrooms every week. Suppose a company has launched fifty AI projects. Does it have an AI strategy? Perhaps. It may also have fifty experiments, scattered teams, three platforms doing the same job and no shared logic for where the money goes. A count of projects measures activity. It says nothing about whether the activity adds up to anything.
The core idea
An enterprise AI strategy is a coordinated set of choices about how AI will help the organization achieve its strategic objectives: where AI matters most, how the organization will compete and operate with it, which capabilities it must build and where it will invest. Just as important, it says where AI will not be used and what will not be funded.
The difference shows up in the language people use. “Deploy twenty AI assistants this year” is a target. It may be a useful target, but it is not a strategy, because it does not say why twenty, why assistants or what should be different when they are in place. Compare an illustrative sentence, written for this chapter: “We will use AI to cut the time it takes to quote a complex order from days to hours, because quote speed is where we lose to competitors, and we will build the product and pricing data that makes this possible once, for every sales region.” That is not a complete strategy either. But it names a problem, a choice and a capability, and it implies what will not get funded.
What a strategy contains
The most useful definition of strategy for an executive comes from Richard Rumelt. A good strategy, he argues, has a kernel of three parts2.
The diagnosis names what is actually going on and the obstacle that matters most. For AI, that might be, to take an illustrative example, “our claims take three weeks to settle and customers leave in the second week”, or “our engineers spend half their time on maintenance and new products ship late”. The guiding policy is the overall approach to that obstacle: for example, “use AI to settle simple claims the same day, and move our adjusters to the complex ones”. The coherent actions are the commitments that carry out the policy and reinforce one another: the data, the people, the changed process and the budget.
Rumelt also describes the signs of bad strategy. Two of them are common in AI plans. The first is fluff: grand language that sounds strategic but commits to nothing. The second is mistaking goals for strategy. “Become an AI-first enterprise” and “use AI everywhere” are goals, or slogans. They do not diagnose a problem and they do not choose an approach. A plan built only from them will be filled with whatever projects arrive first.
Choosing what not to do
Michael Porter put the point in one sentence that has lasted three decades: “The essence of strategy is choosing what not to do”3. Without trade-offs, he argued, there would be no need for choice, and so no need for strategy. An AI strategy that funds every request is not ambitious. It has simply declined to choose.
The refusals in the figure are illustrations, not recommendations; the right list depends on the diagnosis. Refusals are where strategy becomes real, because they free scarce resources. Talent, clean data, engineering capacity, budget and executive attention are all limited. A refusal such as “we will not build our own foundation models” stops a long and expensive debate before it starts. “We will not let every business unit run its own AI stack” protects the shared investment. “We will not fund a use case simply because AI makes it possible” keeps the portfolio tied to the diagnosis. Behind each refusal sits a trade-off the leadership team has chosen to make explicit: speed against control, local freedom against shared scale, short-term return against long-term capability.
Fruit growers have long understood this. An unpruned tree is a picture of activity: it grows a great deal of wood and leaf, and its fruit is small and late. Pruning cuts healthy branches on purpose, so the tree’s energy goes where the grower wants fruit. Nothing about the cut branches was wrong. They were simply not the priority. Strategic refusals work the same way, and they need to be repeated every season, because new growth always comes back.
Some refusals have already been made for you. Law sets an outer boundary that every AI strategy has to respect, and the details belong to the governance chapters in Module 07.
What an AI strategy is not
Four other documents are often presented as the AI strategy. Each is useful, and each answers a narrower question.
A vision describes an aspiration. It can inspire, but it does not tell anyone where to invest or what to stop. A roadmap describes timing: a platform this quarter, an assistant next quarter. It should follow from the strategy, because a sequence of initiatives without a reason for each one is just a calendar. Architecture describes how the technology is structured, which answers how to build, not what to build or why. Governance sets policies, roles and risk limits. A strategy cannot be delivered without it, but governance on its own decides nothing about where AI should create value. The order matters: strategy first, then priorities, then the roadmap and the architecture that serve them.
Every initiative traces back
An AI strategy sits underneath the business strategy, never beside it. Start With Business Strategy, two chapters on, shows how to begin from the business objectives. The principle to hold here is simpler: every level of AI work should trace upward to the level above it.
The trace gives leaders a practical test for any AI proposal. Which business priority does it serve? Why AI rather than a simpler fix? Which capability does it need, and can that capability be reused by the next initiative? What outcome should it create, and how will we know? A proposal that cannot answer these questions is not necessarily bad. It may be a sensible experiment or an ordinary productivity tool. But it should be funded as one, not as a strategic bet.
A portfolio, not a pile
Once initiatives trace back, they can be managed together as a portfolio rather than approved one at a time. The BCG finding that opened this chapter is a portfolio finding: the companies getting value had chosen fewer bets and backed them harder1.
A balanced portfolio usually mixes three kinds of work. Some initiatives improve the core business with proven approaches. Some build new sources of growth. A few are options on the future: uncertain, but strategically important enough to explore. This is the logic of the three horizons of growth that McKinsey consultants described more than a quarter of a century ago, and it applies to AI without much translation4. Alongside the three sits the shared capability that every horizon draws on: data, platforms, skills and governance.
That shared capability is where AI strategy differs most from a list of projects. Marco Iansiti and Karim Lakhani argue that the firms that gain most from AI do not bolt it onto individual products. They rebuild their operating model around a reusable “AI factory” of data, algorithms and experimentation that improves with every use5. That is an argument built from case studies of digital firms, not a measured result across industries, but the economics behind it are plain. A project list cannot make that investment, because no single project can justify it. Only a strategy can.
Run it as a loop
A strategy also fails when it stays a document. AI capabilities, costs and competitors move too quickly for a plan written once and filed.
The loop starts with the priorities and funds a portfolio against them. It delivers, and then it measures outcomes for the business rather than activity such as logins or the number of pilots. What it learns feeds back into the choices. A sensible rhythm is a formal review at least once a year, with an update whenever the business, the technology or the regulation shifts materially. An organization does not need certainty before it acts. It needs a clear direction, and experiments that stay aligned with it.
Story: a university that refused the easy route
Put yourself in the leadership of a large public university in Atlanta in 2011. A growing share of its students come from low-income homes, and many are the kind of student universities often fail to graduate. Its graduation rate, though rising, has long been poor: in 2003, only 32 percent of students finished within six years. State and federal support is getting less generous. Leadership wants a much better completion rate, and two broad routes are open.
The first route is familiar across higher education: become more selective. Admit students who are more likely to graduate anyway, and the rate improves without changing much else. The second route is harder: keep the doors open, and redesign how the university supports the students it already has, using its own data to find the moment each student starts to drift. Before reading on, decide which route you would choose, and what you would refuse to do.
Georgia State University chose the second route and wrote the choice into its 2011 strategic plan. The first goal was to “become a national model for undergraduate education by demonstrating that students from all backgrounds can achieve academic and career success at high rates”6. That sentence is a diagnosis and a guiding policy at once, and it contains a refusal: the university would not buy a better graduation rate by changing who it admitted.
The coherent actions followed. Georgia State hired 42 new advisers, more than doubling the staff and cutting the load from about 1,500 students per adviser to about 300. In 2012 it launched a predictive advising system that checked every student’s record against more than 800 alerts, from registering for a course that does not count toward the student’s major to a low grade in a key prerequisite. The money tells the story of the priorities. The case study puts the cost at about 1.6 million dollars for adviser salaries and about 150,000 for the analytics software6. Less than a tenth of the spending went to the technology. The rest went to the people who acted on what it found.
By 2014 the six-year graduation rate had reached 54 percent. Over roughly the same period, the share of students eligible for federal Pell grants nearly doubled, from 31 to 58 percent, and the average incoming SAT score fell by about 20 points. African-American, Hispanic and Pell-eligible students came to graduate at higher rates than the university average6. The gains cannot be credited to analytics alone; Georgia State had been building learning communities, tutoring and redesigned math courses since 1999. That is the point. The technology worked because it was one of several coherent actions serving one guiding policy.
The strategy also told the university where AI belonged next. In 2016 it tested an AI text assistant that answered admitted students’ questions about financial aid, transcripts and enrollment over the summer. In a randomized trial, students who had it were 3.3 percentage points more likely to enroll on time, with less burden on staff7. The new tool did not need its own strategy. It fitted the existing one.
What this means for leaders
Four practical consequences follow. First, ask for the diagnosis before the projects: if your AI plan cannot name the obstacle it is meant to overcome, it is a list. Second, make the refusals explicit and write them down, because unwritten refusals are reopened in every budget round. Third, fund shared capability deliberately, since no single project will ever pay for the data and platforms that every project needs. Fourth, treat the strategy as a loop, reviewed against outcomes, not as a document that is approved and filed.
Check yourself
- An organization with fifty AI projects has, by definition, an AI strategy.
- “Become an AI-first enterprise” is a strategy.
- Deciding what the organization will not do with AI is part of the strategy.
- The AI roadmap and the AI strategy are the same document.
- In BCG’s 2024 survey, AI leaders pursued more opportunities than other companies.
- At Georgia State, most of the money for predictive advising went to the analytics software.
Reflection
What comes next
A strategy decides where and why AI should matter. It does not, by itself, get anyone to change how they work. Many organizations mistake high usage for strategic progress, and others write fine strategies that nobody adopts. The next chapter, AI Strategy vs AI Adoption, separates the two ideas and shows why an enterprise needs both.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
EU Digital Omnibus on AI · EU
Regulation (EU) 2026/1744
First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.
- 2026-07-24 — Published in the Official Journal
- 2026-07-27 — Entered into force
- 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
- 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))
Last verified 2026-10-10 · official text
References
- Boston Consulting Group. Where's the Value in AI?. Boston Consulting Group. 2024.
- Richard Rumelt. Good Strategy/Bad Strategy: The Difference and Why It Matters. Crown Business. 2011.
- Michael E. Porter. What Is Strategy?. Harvard Business Review (November-December 1996). 1996.
- Mehrdad Baghai, Stephen Coley and David White. The Alchemy of Growth: Practical Insights for Building the Enduring Enterprise. Perseus Books. 1999.
- Marco Iansiti and Karim R. Lakhani. Competing in the Age of AI: Strategy and Leadership When Algorithms and Networks Run the World. Harvard Business Review Press. 2020.
- Martin Kurzweil and D. Derek Wu. Building a Pathway to Student Success at Georgia State University. Ithaka S+R. 2015.
- Lindsay C. Page and Hunter Gehlbach. How an Artificially Intelligent Virtual Assistant Helps Students Navigate the Road to College. AERA Open, vol. 3, no. 4. 2017.
Further reading
- Richard Rumelt. Good Strategy/Bad Strategy: The Difference and Why It Matters. Crown Business. 2011.
- Michael E. Porter. What Is Strategy?. Harvard Business Review (November-December 1996). 1996.
Sources last verified 2026-10-10.