AI Academy · Book
Executives & Directors · Module 04 · Chapter 010

AI Talent and Capability Strategy

A hiring number is the last output of an AI talent strategy, not the first input. Start from the capabilities the strategy needs, set a skill target for each role, measure the gap with evidence, and then decide what to build, own, buy or borrow. Talent can be hired; capability has to be built.

≈ 13 min read

After this chapter you can

  • Distinguish AI talent from organizational AI capability.
  • Derive a capability blueprint from the chosen AI ambition.
  • Set a skill target for each role family instead of one program for all.
  • Diagnose capability gaps with evidence and a repeatability test.
  • Decide whether to build, own, buy or borrow each capability, with a transfer plan.

On 7 April 2025, Shopify’s chief executive, Tobi Lütke, published an internal memo. “Reflexive AI usage is now a baseline expectation at Shopify,” it said. Before any team asked for more headcount or resources, it would have to show why the work could not be done with AI, and AI use would become part of performance reviews1.

Whatever you think of the rule, notice what it does to an old conversation. For decades a headcount request was judged on budget and workload. Now it is judged against a capability: what the organization can already do with AI, and what it cannot.

Suppose your finance chief adopts the same rule tomorrow. On Monday a business-unit head asks for three senior AI engineers to speed up its AI program. What would you need to know before saying yes? Not the market salary, and not how many engineers your competitors employ. You would need to know which capability those three people would add, whether that is the capability holding the program back, and whether anyone else in the organization could run it once they arrived. Many executive teams cannot answer those questions today. Being able to answer them is what an AI talent strategy is for.

Talent is counted; capability is repeated

The AI Talent Gap in Module 01 diagnosed where organizations are short of people: the four layers of specialists, translators, AI-enabled professionals and leaders, and the constraint layer that holds them back. Turning that diagnosis into a strategy rests on one distinction.

Talent is the people and skills you can hire, measured as headcount; capability is what the organization can do repeatedly, measured in repeatable results.TALENTThe people and skills youhave and can hireHeadcountCAPABILITYWhat the organization can dowell again and againRepeatable resultsvs
Figure 4.10.1 Talent is an input you can count. Capability is an organizational ability you can rely on.

Talent is the people and skills available: engineers, data scientists, product managers, domain experts. You can count it and you can hire it. Capability is the organization’s ability to perform an activity well, again and again, whoever is on duty. “We can evaluate any AI system against an agreed standard before it reaches customers” is a capability. It needs people, but also a shared method, tools, a rule about what may ship, and more than one person who can apply them.

The distinction matters because the two are acquired differently. Talent arrives in a hiring cycle. Capability is built over years, by people working on real problems inside your processes. C. K. Prahalad and Gary Hamel made the point about core competences a generation ago: outsourcing can deliver a better product quickly, but it does little to build the people-embodied skills behind it, which cannot be “rented in”2. Jay Barney’s resource-based view explains why this is also where advantage lives. Resources that are socially complex, spread across many people and routines, are hard for competitors to copy3. A star hire can be hired away. A capability that lives in fifty people and a method cannot.

Start from a capability blueprint

The list of capabilities you need comes from the strategy, not from a benchmark of what other companies employ. Defining AI Ambition, earlier in this module, set out five levels of ambition. Each level adds capabilities, and the depth needed rises with it.

Efficiency needs safe tool use and training; each higher ambition adds capabilities, up to deep engineering and a shared platform for an AI-native business.AmbitionCapabilities it addsEfficiencySafe tool use, training, adoption supportAugmentationRole-level skills, verification habits, manager coachingWorkflow transformationProduct ownership, process redesign, integration, evaluationAI-enabled productsAI product leadership, experimentation, customer insightAI-nativeDeep engineering, a shared platform, running AI agents in daily operations
Figure 4.10.2 Each level of ambition adds capabilities. Mismatch in either direction wastes money.

Write the blueprint as a short list of capabilities stated as verbs: we can define a problem and own its outcome; we can evaluate a system before release; we can redesign a workflow and get people to adopt it. Phrasing them this way keeps the list about what the organization must be able to do, not about which job titles it should create. It also exposes the two classic mismatches. One is the efficiency ambition staffed like a research lab, with deep specialists who have nothing deep to do. The other is the transformation ambition staffed with a training program, where people learn to use tools but no one owns the redesigned workflow.

Set a skill target for every role

Most employees do not need to become AI engineers. They need the right level of skill for their role, and the strategy’s job is to set that level deliberately rather than offer the same course to everyone.

Five skill levels from literacy for everyone, through fluent users and workflow redesigners, to fewer builders and a small group of specialists.SpecialistsEvaluation, safety, advanced engineeringBuildersBuild and integrate production systemsWorkflowredesignersRebuild part of their own work around AIFluent usersUse AI well and check it in their roleLiteracyKnow what AI can do, its limits and safe useDEEPERSKILLS,FEWERPEOPLE
Figure 4.10.3 Every role gets a target level. Literacy is for everyone; each step up needs fewer, deeper people.

The levels are a planning tool. For each role family you name a target: literacy for every employee, fluency for most knowledge workers, workflow redesign for the people who own key processes, building for a smaller technical group, and deep specialism for a few. Targets turn a vague ambition, “an AI-ready workforce”, into a budget and a timetable you can check. They also show where the investment is likely to go. Because the lower levels cover so many more people, the largest spend is often not on the few specialists at the top but on moving many people from literacy to fluency.

That move does not happen by memo. Boston Consulting Group’s 2025 survey of more than 10,600 employees found that regular use of AI was sharply higher among people who had received at least five hours of training, and that only about a third said they had been properly trained4. A rule like Shopify’s sets an expectation. The skill target, and the training and practice behind it, is what lets people meet it.

In the EU, the literacy level also meets a legal duty: since Regulation (EU) 2026/1744, providers and deployers must take measures to support AI literacy, with no specific level guaranteed5. The AI Adoption Curve, in Module 01, covers it.

Measure the gap with evidence, not opinion

Richard Rumelt’s advice on strategy applies here as well as anywhere: good strategy starts with a diagnosis of what is actually going on7. For capability, the diagnosis is a comparison. For each capability in the blueprint, what level does the ambition require, what level can the organization repeat today, and how large is the difference?

Leadership rates each capability in the blueprint on a simple scale from 0 (absent) to 5 (repeatable across the business). An illustrative result for five capabilities looks like this.

In illustrative ratings, the largest gaps are owning the problem and evaluating before release; AI engineering already meets the requirement.CapabilityRequiredTodayGapOwn the problem andthe outcome41LargeEvaluate before release41LargeRedesign the workflow andadopt it42MediumData and integration32SmallAI engineering33None
Figure 4.10.4 An illustrative gap diagnosis. The binding gaps are ownership and evaluation, not engineering.

The ratings are invented to show a pattern worth checking for. The capability most visible on the organization chart, engineering, is already adequate. The binding gaps sit in the places no job advertisement targets: who owns the problem, and who decides that a system is good enough to use. A hiring plan written before the diagnosis would have added engineers and left both gaps open.

Two disciplines make the diagnosis credible. The first is evidence. A rating based on one manager’s impression is an opinion; a rating that combines self-assessment, managers’ views and evidence from real work, such as projects delivered and systems in use, is a measurement. The second is honesty about repeatability. A capability that worked once, because one talented person happened to be available, scores low. The question is not “have we done it?” but “could we do it again next month with a different team?”

Build, own, buy or borrow each capability

Build vs Buy vs Partner applied the differentiation and control tests to technology. The same logic applies to people, with one difference: every choice to build creates a long-term obligation to develop, pay and keep the people who hold the capability.

Build differentiating capabilities by developing your own people, own critical controls, hire scarce long-term depth, and borrow specialist or temporary skills with a plan to transfer them.If the capability isSource it byTypical exampleA differentiatorBuilding: develop and move your own peopleProduct ownership in the core businessA critical controlOwning: build or hire, never only borrowEvaluation and risk judgmentScarce depth neededfor yearsBuying: hire a few to seed itSenior AI architectsSpecialist or temporaryBorrowing: partners, with a transfer planA first agent build
Figure 4.10.5 Build what differentiates, own what controls, hire scarce depth to seed it, and borrow the rest with an exit.

Build where the capability differentiates you, because that is where outside talent knows least about your customers, processes and constraints. Building means developing and moving your own people, often seeded by a few hires. Own the critical controls, such as evaluating systems and judging risk, even when they do not differentiate you, because the judgment about what is safe to release cannot be delegated outside the organization. Buy scarce depth that you will need for years, and use it to teach others rather than to do all the work. Borrow specialists for a defined period, and write the transfer of knowledge into the contract, so that the capability stays when the partner leaves.

Large employers already use every lever at once. In the World Economic Forum’s 2025 survey of more than 1,000 employers, representing more than 14 million workers, 63 percent named skill gaps as the biggest barrier to transformation over 2025 to 20308. That figure is the share of employers naming a barrier; the bars below are a different question, the share planning to use each response.

Of employers surveyed, 85 percent plan to prioritize upskilling, 70 percent to hire staff with new skills, 50 percent to move staff to growing roles and 40 percent to reduce staff.Upskill the workforce85%Hire staff with new skills70%Move staff to growing roles50%Reduce staff withoutdated skills40%Source: World Economic Forum, Future of Jobs Report 2025 · 2025-2030 plans
Figure 4.10.6 Employers plan to use several levers together. Upskilling leads; hiring is one lever among four.

How much should stay inside? McKinsey’s practitioner guidance for digital and AI transformations sets an aspiration of 70 to 80 percent of digital talent in-house, with the outside share focused on specialized skills and flexibility9. Treat that as a consultancy benchmark, not a law of nature. The principle behind it is sound: you can borrow speed, but you cannot borrow the capability to make your own decisions.

Make the capability outlast its experts

The final test of a capability is that it does not depend on any one person. In the early stage of an AI program it usually does. One person knows how to test the systems, one knows how the data flows, one can translate between the business and the engineers. When that person is on leave or leaves, the capability goes with them. Operational and Workforce Risk, in Module 06, treats that concentration as a risk. Here it is a design problem with a known answer.

A capability grows from one expert, to a written method, to tools, to a rule that work cannot ship without it, to a bench of people who can run it.ExpertOne personwho cando itMethodHow it isdone iswritten downToolsThe methodis builtinto toolsRuleWork doesnot shipwithout itBenchSeveralpeople canrun itCapability is the expert, plus everything that lets others repeat the work
Figure 4.10.7 Turning an expert into a capability. Each step makes the result less dependent on one person.

Where the scarce specialists sit, and who directs them, belongs to the operating model, the subject of the next chapter.

Story: blueprint first, then measure

In early 2020, Johnson & Johnson set out to strengthen digital expertise among its 4,000 technologists. The company did not start with a hiring target. It started with a blueprint: 41 “future-ready” skills, such as master data management and robotic process automation, grouped into 11 capabilities and derived from the business strategy1011.

Like many organizations, J&J lacked a clear view of which skills its people actually held, the problem the researchers see holding back most digital workforce efforts12. J&J trained a model on four sources of evidence, the HR system, the recruiting database, the learning system and a project-management platform, to estimate each technologist’s proficiency on a 0-to-5 scale. Employees rated themselves on the same scale, and the model’s scores were treated as usable when the two were within one point. Leaders made one deliberate choice early: the scores would be used for development, not for performance evaluation, and data would be de-identified and used in aggregate, with an option to opt out10.

J&J defined 41 future-ready skills in 11 capabilities; after the first measurement round, use of its development tools rose 20 percent, and 90 percent of technologists were on the learning platform by March 2024.41Future-ready skillsIn 11 capabilities, defined beforeanyone was measured+20%Use of development toolsAfter the first roundof measurement90%Of technologistsOn the learning platform byMarch 2024Source: MIT Sloan, reporting MIT CISR research · 2020-2024
Figure 4.10.8 J&J defined the capabilities first, then measured the gap, then invested where the gap was.

After the first round, use of J&J’s development tools rose by 20 percent, and by March 2024, 90 percent of its technologists had accessed the learning platform. Executives gained heat maps of proficiency by region and business line, which fed strategic workforce planning10. The approach later expanded to a global workforce of more than 130,000, and the researchers report increased internal mobility, better alignment of people to digital roles and lower voluntary attrition in digital and data roles, without publishing figures for those outcomes12. The published numbers measure use of development tools, not business results, so the case shows that the method can run at scale rather than what it earned.

The researchers’ main lesson is not about the model. They identify three organizational practices: a workforce blueprint drawn from the business strategy, careful management of employee data, including engagement with worker representatives, and ways for employees and managers to review and correct the AI’s results11. The sequence is the whole method in miniature: blueprint, evidence, gap, then investment. What J&J built was not a bigger team but a repeatable way to see and close its skill gaps.

What this means for leaders

When an AI talent question reaches the executive table, it usually arrives as a number. The job of leadership is to turn it back into a capability question before the number is agreed. That means owning the blueprint, insisting on evidence for the gap, and choosing the sourcing deliberately, with a view of the long-term obligations each choice creates. It also means looking at your own level: executives need enough fluency to question the economics, risks and investments of AI, not to build it.

Check yourself

  1. The size of the AI team is a good measure of an organization’s AI capability.
  2. Every employee needs to reach the same level of AI skill.
  3. Critical controls such as evaluation should stay inside the organization even when they do not differentiate it.
  4. Most large employers plan to close skill gaps mainly by hiring.
  5. J&J began its skills program by defining the skills it needed before measuring anyone.
  6. A capability that worked once with one expert should score high in a gap diagnosis.

Reflection: one capability, not one hire

What comes next

A capability blueprint says what the organization must be able to do and where the people come from. It does not say who decides which AI work gets funded, where the scarce specialists sit, or how AI is run week after week. Those questions belong to the next chapter, AI Operating Model.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

References

  1. Digital Commerce 360. Internal memo: Shopify CEO declares AI 'non-optional'. Digital Commerce 360. 2025.
  2. C. K. Prahalad and Gary Hamel. The Core Competence of the Corporation. Harvard Business Review 68(3), May-June 1990, pp. 79-91. 1990.
  3. Jay B. Barney. Firm Resources and Sustained Competitive Advantage. Journal of Management, vol. 17, no. 1, pp. 99-120. 1991.
  4. Boston Consulting Group. AI at Work 2025: Momentum Builds, but Gaps Remain. Boston Consulting Group. 2025.
  5. Law and Technology. AI literacy: the Digital Omnibus rewrites Article 4 of the AI Act. lawandtechnology.eu. 2026.
  6. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
  7. Richard Rumelt. Good Strategy/Bad Strategy: The Difference and Why It Matters. Crown Business. 2011.
  8. World Economic Forum. The Future of Jobs Report 2025. World Economic Forum. 2025.
  9. Eric Lamarre, Kate Smaje and Rodney Zemmel. Rewired to outcompete. McKinsey Quarterly. 2023.
  10. Brian Eastwood. How companies can use AI to find and close skills gaps. MIT Sloan School of Management, Ideas Made to Matter. 2024.
  11. Olgerta Tona, Dorothy E. Leidner, Nick van der Meulen, Barbara Wixom, Juliana Nunes and Doug Shagam. The Deployment of AI to Infer Employee Skills: Insights From Johnson & Johnson's Digital-First Workforce Initiative. Information Systems Journal 35(6), pp. 1516-1527. 2025.
  12. University of Gothenburg. AI for mapping employee skills. University of Gothenburg news. 2025.

Further reading

Sources last verified 2026-10-10.