When an organization decides to “do something with AI,” the first instinct is usually to start a pilot. It’s visible, it’s exciting, and it shows leadership that something is happening. It’s also usually the wrong first move, because a pilot started before the basics are in place inherits every risk the organization has: overshared documents, no policy, no idea which tools people already use.
The 90-day AI plan that works runs in the opposite order. Close the risk gaps first. Build the foundations second. Then run a pilot that proves value, on ground that can support it. It’s the same sequence I use in the 90-day plan of every AI readiness report, and this post lays it out action by action, with an owner for each.
Why the order matters
If you fund a pilot first and fix governance later, the pilot carries every unresolved risk forward. The assistant connects to overshared content. People use it without a policy. Nobody captured a baseline, so the results can’t be proven. By the time the gaps are fixed, the pilot’s reputation is set, often for the worse.
Closing the risks first costs a few weeks. It pays back in a pilot that can run cleanly, be measured honestly, and scale without a pause for cleanup.
Days 1 to 30: close the risk gaps
- Publish the AI acceptable use policy and run a short training session. Owner: IT director. Outcome: everyone knows what data can go where. Template here.
- Roll out an approved AI tool and restrict unapproved AI sites. Owner: security lead. Outcome: shadow AI drops and usage becomes visible. The approach is in the shadow AI policy your IT team actually needs.
- Clean up sharing on your most sensitive sites. Owner: collaboration platform administrator. Outcome: oversharing is contained before any assistant connects to company content. See fixing oversharing before Copilot.
- Build the first AI inventory and stand up a small AI council. Owner: IT director. Outcome: one list of AI in use and one group that decides.
- Start the baseline for your pilot process, and start team training. Owner: the pilot’s business owner and the IT director. Outcome: evidence and skills build while the guardrails go in.
Days 31 to 60: build the foundations
- Extend sensitivity labels and DLP to your most sensitive data types. Owner: security lead. Outcome: sensitive data is labeled and protected, including in AI tools. See labels and DLP before AI.
- Name owners for the data your pilot depends on. Owner: executive sponsor. Outcome: someone is accountable for the data AI will use. See who should own data quality.
- Map the regulations and contract terms that apply. Owner: compliance lead. Outcome: known obligations before the pilot touches real data.
- Complete the team training, and start certifications for key roles. Owner: IT director. Outcome: a shared AI baseline across the team.
- Curate the content the pilot will use, and finalize its scope with the council. Owner: the pilot’s business owner. Outcome: the pilot answers from trusted content, against agreed metrics.
Days 61 to 90: prove value with a pilot
- Launch the pilot with a small group, with a person reviewing every output. Owner: the pilot’s business owner. Outcome: a working pilot on real work.
- Compare pilot results with the baseline every two weeks. Owner: the pilot’s business owner. Outcome: measured results leadership can trust.
- Set budgets and alerts for any usage-based AI services. Owner: cloud engineer. Outcome: no surprise invoices. See budgets and alerts for usage-based AI spend.
- Present results and a scale-or-stop decision to the council. Owner: IT director. Outcome: a funded next step based on evidence.
The asset: a 90-day plan template
Put the plan in a simple table with five columns: action, owner role, expected outcome, due date, and status. Use owner roles rather than names at first, so you can assign people on day one without rewriting the plan. Then add one habit that holds it together: a 30-minute weekly check-in with the owners, reviewing only what’s late or blocked. Plans slip one missed week at a time; a weekly check-in catches the slip while it’s still small.
What leadership should see at each checkpoint
At day 30: the policy is published and acknowledged, an approved tool is in use, the most sensitive sites are cleaned up, and the inventory shows what AI is in use. Leadership sees risk going down.
At day 60: data owners are named, obligations are mapped, the team is trained, and the pilot’s baseline and scope are agreed. Leadership sees foundations in place.
At day 90: pilot results against the baseline, and a recommendation to scale, adjust, or stop. Leadership sees evidence, and makes a decision based on it.
What the plan costs
Most of the first 30 days is internal time, not spending: writing a policy, running reports, cleaning up permissions, and holding meetings. The main costs come later and are modest: licenses for the approved tool and the pilot group, any usage-based costs for the pilot, and training or certification fees. That makes the plan easy to start before a larger budget is approved, and the day-90 results become the evidence for that larger budget.
Picking the pilot
Choose the pilot in the first week, even though it launches in the third month, because the baseline needs time. The right first pilot is frequent, text-heavy, reviewable, low-risk, measurable, and has an engaged business owner. The service desk is often a good choice, because IT owns the process. Picking your first AI use case covers the criteria in detail.
Adapting the plan
If you’re further along, skip what’s done and move the pilot earlier, but confirm each foundation with evidence rather than assuming it.
If you’re in a regulated industry, move the regulatory mapping into the first 30 days, and don’t let the pilot touch regulated data until it’s complete.
If your team is small, one person may hold several owner roles. That’s fine, as long as each action still has exactly one owner.
Day 91 and beyond
The 90 days end with a decision, not a finish line. What worked gets scaled; what didn’t gets retired. Months four to twelve are about turning one proven use case into a repeatable pattern: the same baseline, pilot, and measure loop, applied to the next item on your use-case list, while the governance you built keeps pace with adoption.
Mistakes I see
Starting with the pilot. It’s the most common mistake, and the one this plan exists to prevent.
Doing everything at once. Fifteen actions in three phases is manageable. Fifteen actions all starting on day one isn’t.
No owners. An action without an owner is a wish.
Letting the pilot drift past day 90. Make the decision on schedule, even if the decision is to extend with a specific change.
Where does your team actually stand?
Your readiness score tells you which parts of this plan you can skip and which need the most attention. The free AI Readiness Score uses 10 of the 24 assessment questions and gives you a score in a few minutes.
Get your free AI Readiness Score →
See a complete 90-day plan written for a specific organization: flip through the 38-page sample report.
Related guides
- Publish Your AI Acceptable-Use Policy This Month (3-Tier Template)
- The Shadow AI Policy Your IT Team Actually Needs (With Template)
- Fix SharePoint Oversharing Before You Turn On Copilot
- Sensitivity Labels and DLP Before AI: The 30-Day Rollout
- Who Should Own Data Quality? Why “Nobody” Breaks Your First AI Project
Frequently asked questions
What should the first 90 days of an AI program focus on?
Close the risk gaps in days 1 to 30, build the foundations in days 31 to 60, and prove value with a measured pilot in days 61 to 90. Starting with the pilot means it inherits every unresolved risk.
What happens in the first 30 days of an AI plan?
Publish the acceptable use policy with short training, roll out an approved AI tool and restrict unapproved sites, clean up sharing on your most sensitive sites, build the first AI inventory, stand up a small AI council, and start the pilot's baseline and team training.
What does a 90-day AI plan cost?
Most of the first 30 days is internal time, not spending. The main costs come later and are modest: licenses for the approved tool and pilot group, usage costs for the pilot, and training or certification fees. The day-90 results become the case for any larger budget.
What happens after the 90 days?
A decision, not a finish line. What worked gets scaled and what didn't gets retired. Months four to twelve apply the same baseline, pilot, and measure loop to the next item on the use-case list, while governance keeps pace with adoption.




