Article · Vision & Strategy
How to Write an AI Strategy for Executives in Two Pages
A useful AI strategy fits in two pages and contains decisions, not aspirations. If yours runs to forty slides and talks about “harnessing the potential of artificial intelligence,” you do not have a strategy: you have a statement of intent that nobody can execute or audit. This piece is the outline I use to write one: the four decisions it must contain, what to delete, and the order in which the committee has to answer each question.
The test of whether a strategy works is simple: hand it to a process owner and ask what they have to do on Monday. If they can answer, the strategy decides. If they have to interpret it, it is a public-relations text aimed at the board.
The four decisions it must contain
An AI strategy that gets executed answers four questions and puts them in writing with names and numbers. Everything else is context.
1. Which processes. Not “the areas where AI can add value,” but the concrete list of processes that will enter, in what order, with their owner and the business number each must move. Three named processes are worth more than thirty areas of opportunity. How to select and prepare them I develop in prepare your company for agents.
2. What structure: build, buy or contract. Who will operate and maintain the agents. Building in-house requires creating and retaining a technical team. Buying platforms solves bounded cases and leaves you the integration. Contracting a managed operation shifts maintenance to the provider and the demand to the contract. It is a structural decision with consequences in fixed cost and risk, and I cover it in depth in buy, build or contract AI and in-house, consultancy or boutique. Its organizational version, whether to stand up an AI center of excellence, is decided with the same criterion.
3. What controls. The limits under which agents operate: what they may read and write, up to what amount they decide, which cases they escalate to a person, who can stop the system, and how every decision is recorded. This is not a technical appendix: it governs the company’s real risk and belongs in the strategy. The full framework is in AI agent governance.
4. How it is measured. Against what baseline each process is judged, and when you decide to continue, stop or correct. Without a measure agreed in advance, any result can be narrated as a success. How to frame the return in front of a board I develop in AI operations ROI.
These four decisions (which processes, what structure, what controls, how it is measured) are the operating model of your AI adoption. The organizational redesign behind them I cover in the essay an AI-first organization is not a company that uses AI tools, which is the frame this strategy hangs from.
What is superfluous in an AI strategy
What bloats AI strategies until they cannot be executed is almost always the same.
- Mission statements about AI. “We want to be leaders in artificial intelligence” is not a decision, it is a wish. It does not say which process changes or who answers for it. Delete it: it takes space and obliges nobody.
- Technology lists. Enumerating models, frameworks or platforms confuses the catalog with the strategy. Models are a utility selected by task and swapped when it suits. Fixing them in the strategy ties it to decisions that will change in months. The strategy decides what work gets done and who maintains it, not with which specific tool.
- State-of-the-art briefings. Half a strategy spent explaining what generative AI is helps the committee decide nothing. That context goes in an appendix, at most.
- Ambitions without a sequence. “We will transform the entire operation” without saying which process comes first is a promise, not a plan. Transformation advances process by process, as I argue in the AI transformation playbook.
The rule I apply: if a sentence does not name a process, an owner, a control or a measure, it is not strategy. It is filler, and filler dilutes the decisions that do matter.
What the strategy does not decide and still has to name
The four decisions are choices. There is a fifth block that is not, and leaving it outside the two pages is what has most often forced me to rewrite them in month three. These are the duties already in force, and they consume calendar, budget and decision rights like any other line.
Three lines are enough, and there is no need to turn them into a legal annex:
- The inventory of uses with its classification. Which agents exist, what they decide and about whom, with the risk band assigned. It feeds everything else, and the framework is in the EU AI Act and AI agents.
- The perimeter of people and their competence. Who works with those systems, on your payroll and off it, and what evidence you keep that they understand them. It is the one duty that does not fall when the risk falls, and I develop its reach in the AI literacy obligation.
- The agreed transparency. When a customer or an employee is told an AI is involved, and who writes it.
The reason to put them in the strategy is managerial before it is legal. Each has an owner and a date, and none resolves itself while the committee argues about which process goes first. A strategy that only decides, without naming what already constrains it, arrives at the review meeting with two immaculate pages and a calendar that will not hold.
The order to answer in: the committee’s questions
The order is not cosmetic. Answering these questions in sequence avoids the most common error, which is deciding the technology before knowing what work it will do.
- Which process first, and why that one? One with an owner, volume, bounded exceptions and a result measurable against revenue, margin or service. This question is answered before any other: it defines everything else.
- Who answers for its result? The business owner, with real authority to change the process around the agent. Without this name, the process does not enter.
- Do we build, buy or contract the capability to operate it? The structural decision, taken for this process and revisable for the next ones.
- Under what controls does it operate, and who can stop it? The agent’s mandate, human escalation, traceability and stop authority.
- Against what number do we measure it, and when do we decide to continue or stop? The baseline and the decision point, agreed before starting.
- What is the next process? Answered later, with the evidence from the first, not on the opening page.
A committee that answers these six questions with names and numbers has an executable strategy in two pages. One that leaves them in generalities has a document that will sound good to the board and will not change one operation. And if the answer to “who operates and maintains” is a third party, the strategy rests on the contract: which is why it pays to be clear on the buying criteria I cover in how to choose an AI agent provider.
Frequently Asked Questions
What must an AI strategy contain at minimum?
Four decisions in writing: which processes enter and in what order, what structure operates and maintains them (build, buy or contract), under what controls the agents operate, and against what number each process is measured. If any of the four is missing, the strategy cannot be executed.
Why should it fit in two pages?
Because length usually hides a lack of decision. A long strategy fills up with context, briefings and statements that oblige nobody. Two pages force you to keep what decides: processes, owners, controls and measures.
Should the strategy fix which models or technology to use?
No. Models are a utility selected by task and swapped when it suits. Fixing them in the strategy ties it to decisions that expire in months. The strategy decides what work gets done, who operates it and how it is measured, not the specific tool.
Does an AI strategy have to talk about compliance?
Enough that it does not surprise anyone later. Three lines: the inventory of uses with its risk classification, the perimeter of people who work with those systems and what evidence you keep of their competence, and when customers and employees are told. Each with an owner and a date. The legal opinion goes elsewhere, but if those three are missing from the two pages they turn up in month three and wreck the calendar.
How often should an AI strategy be rewritten?
When one of the four decisions changes, not on a calendar. In practice you touch it when the first process closes, because that is when you have real evidence on timelines, exceptions and cost, and that is the moment to decide the next one. Reviewing it every quarter out of routine produces documents that age while nobody decides anything.
Who should write the AI strategy?
The executive committee, because the decisions it contains (which processes, what structure, what controls) redistribute decision rights between functions, and only leadership can arbitrate that. The technical team or the provider bring judgment, but the strategy is not a document from the IT department.