The IT Director’s Guide to Answering “What’s Our AI Strategy?”

An IT director man and a friendly robot assistant leaning over a glowing chessboard, the man moving a piece forward

It usually arrives without warning. A CEO back from a conference, or a board member who read an article, turns to the IT director and asks: “So, what’s our AI strategy?” The room waits. And the honest answer, for most mid-size organizations, is that there isn’t one yet; there’s a collection of tools, some experiments, and a lot of questions.

There are three tempting responses, and all of them go badly. A list of the AI tools you’ve licensed sounds like a shopping list, not a strategy. “We’re evaluating our options” sounds like stalling. A promise of a comprehensive strategy document next quarter buys time but sets up a forty-page report nobody will read. What works is a one-page strategy that starts from the business, is honest about readiness, and says clearly what you will and won’t do. This post covers how an IT director can build that in about three weeks.

What an AI strategy actually is

An AI strategy isn’t a technology plan. It’s a business plan with an AI component: which business outcomes AI should help achieve, where the organization will start, what it won’t do yet, and what has to be true for any of it to work. IT’s role is to own the enabling parts, such as readiness, platforms, security, and governance, and to facilitate the business parts, such as choosing use cases and measuring value. An IT AI strategy written by IT alone, about technology alone, will be politely received and quietly ignored.

The asset: a one-page AI strategy

Eight short sections. If it doesn’t fit on one page, cut until it does.

  1. Ambition. One or two sentences tied to stated business goals. “Use AI to handle growth in customer inquiries without adding headcount” is a strategy. “Become an AI-first organization” isn’t.
  2. Where we’ll start. Three to five specific use cases, each with a business owner, drawn from your use-case register.
  3. What we won’t do yet. Explicit boundaries, such as no autonomous customer-facing AI this year, and no AI decisions about individuals without human review. This section builds more trust than any other.
  4. Foundations we’ll build. The readiness gaps that must close, taken from an honest assessment: typically permissions, policy, data ownership, and training.
  5. Platforms. The approved assistant, where building will happen if it happens, and the principle that guides buy-versus-build decisions.
  6. People. Training for everyone, deeper skills for a few, and champions in the business.
  7. Governance. Who decides which AI tools and uses are approved, and how.
  8. Measures and funding. How you’ll know it’s working, and how funding will be released in stages as results come in.

Writing the ambition statement

The ambition is the hardest line to write, and the one that most often goes vague. Compare a few:

  • Weak: “Use AI to drive innovation across the business.” It commits to nothing and can’t be measured.
  • Better: “Use AI to improve efficiency in customer service.” It names an area, but not an outcome.
  • Strong: “Within a year, use AI to cut the time our service team spends on routine inquiries, so we can absorb growth without adding headcount.” It names the area, the outcome, the reason, and a timeframe.

A strong ambition gives every later section something to point to. If a proposed use case doesn’t serve it, that’s a reason to question the use case.

Guiding principles

Add three to five principles beneath the eight sections. They let people make consistent decisions without asking you every time. Some that work well for mid-size organizations:

  • Buy before build. Use capable off-the-shelf tools first; build only where a proven need isn’t met.
  • Start where our data and identity already live, so AI inherits the controls we already manage.
  • A person reviews anything consequential before it reaches a customer or affects an employee.
  • Measure before we scale. Every pilot has a baseline and a decision date.
  • Fix risks before adding reach. We clean up permissions and publish policy before broad rollouts.

Building it in three weeks

Week 1: get the facts. Score your readiness across the six dimensions, even roughly, so the foundations section is grounded in evidence. The AI readiness checklist lists the questions. At the same time, collect painful processes from department heads to start the use-case register.

Week 2: run a leadership workshop. Sixty to ninety minutes with the executive team. Agree the ambition, the boundaries, and the first use cases. Bring the readiness results so the conversation stays realistic. Leave with decisions, not a list of ideas.

Week 3: write, review, approve. Draft the page, circulate it to the workshop group for one round of comments, and get it approved. Then publish it internally, because a strategy people can’t see can’t guide them.

Who should be in the workshop

Keep it small enough to decide. The chief executive or chief operating officer as sponsor. The chief financial officer, because funding will follow. The heads of the two or three departments with the most promising use cases, because they’ll own them. Legal or compliance, so boundaries are set with them rather than challenged by them later. HR, because AI affects roles and people will ask. The IT director facilitates, presents the readiness facts, and holds the pen. Seven or eight people is about the limit for a session that ends in decisions.

Answering the question on the spot

If you’re asked before the strategy exists, you still need an answer that isn’t “we’re evaluating.” Try three sentences: what you’re doing now, what you’re building toward, and when leadership will see the plan. For example: “We’ve approved an assistant for staff and we’re cleaning up permissions so it’s safe to expand. Our focus is using AI to take pressure off customer service and internal documentation. I’ll bring a one-page strategy to the leadership team in three weeks, with the first two use cases and how we’ll measure them.” That answer shows direction, candor, and a date.

Connecting strategy to the first 90 days

A strategy is only as good as the first steps that follow it. The sequence that works is risks first, foundations second, then a measured pilot. Your first 90 days of AI lays it out action by action, and how to pitch your CFO on an AI budget covers the funding conversation that usually comes next.

Keeping it alive

Review the page quarterly: update the use cases as pilots finish, adjust the boundaries as your controls mature, and report the measures. Rewrite it once a year. A strategy that hasn’t changed in a year is either perfect or ignored, and it’s usually ignored.

Mistakes I see

A tool list dressed as a strategy. Tools are means. Start with outcomes.

A strategy only IT wrote. Without business owners and executive agreement, it has no authority.

No “won’t do” section. Boundaries are what make the rest credible to cautious leaders and to employees.

Too long. Nobody acts on a document they didn’t finish.

No measures. Without them, next year’s strategy starts from opinion again.

Where does your team actually stand?

An honest readiness score is the foundation of a credible strategy. The free AI Readiness Score uses 10 of the 24 assessment questions and gives you a score in a few minutes.

Get your free AI Readiness Score →

The full report is written to be forwarded to leadership. Flip through the 38-page sample to see how.

Related guides

Frequently asked questions

What should an IT AI strategy include?

One page with eight sections: an ambition tied to business goals, where you'll start, what you won't do yet, the foundations you'll build, platforms, people, governance, and measures and funding, plus three to five guiding principles beneath them.

How long does it take to write an AI strategy?

About three weeks: a week to score readiness and collect painful processes, a week for a 60 to 90 minute leadership workshop to agree the ambition, boundaries, and first use cases, and a week to write, review, and approve the page.

How do you answer what's our AI strategy when there isn't one yet?

In three sentences: what you're doing now, what you're building toward, and when leadership will see the plan. That shows direction, candor, and a date, which is far better than saying you're evaluating options.

Why should an AI strategy say what we won't do?

Explicit boundaries, such as no autonomous customer-facing AI this year, make the rest of the strategy credible to cautious leaders and employees. They also stop the plan from quietly expanding into risks nobody agreed to take.

Scroll to Top