tl;dr (i.e. Dan's hot take)
It's too early for AI strategy as we currently think about strategy. Instead we should acknowledge and exploit the underlying nature of what a strategy actually is, rather than what it usually claims to be.
Richard Rumelt, in Good Strategy Bad Strategy, notes that at the heart of a good strategy is a Kernel, containing a Diagnosis, a Guiding Policy, and a set of Coherent Actions to achieve outcomes. It's explicitly not about goals or targets, and nor is it fluffy (i.e. no Weasel Words).
Narrowing that to the technology field, Michael Porter describes a technology strategy as an approach to selecting, developing, and exploiting technology to drive competitive advantage and industry structure.
Let's be honest though, strategy is basically just a combination of assertions and hypotheses that we're going to treat as prescriptions to define the things we do to drive and grow the business. In the case of AI, at this moment in time, I think we need to explicitly acknowledge that, and craft our strategy accordingly. Specifically, we need to think about it in the true sense of its essence, as an expression of the scientific method.
Don't get me wrong - strategy is super important, and I really like Rumelt's approach. But it relies on the diagnosis (an assertion) being correct, which I don't think is something we can rely on at this time. The coherent actions are really hypotheses that are consistent with the assertion, that will be tested on the appropriate battlefield - commercial, technical, political etc. So let's use that experimental aspect.
No-one knows anything
Let's start with a (currently) foundational truism: no-one knows anything. Not really. We're all figuring this out. Evidence:
- It's not at all clear where we are in the technology lifecycle - maybe approaching the top of the s-curve, when capability improvements are becoming asymptotic - but maybe not. Opinions are wildly divergent.
- We remain remarkably limited in our ability to define and capture value, with no well understood path to achieve it. Most of the value I've seen expressed really boils down to vibes. Leaders feel they are getting value from AI, but the data is mixed, and anecdotally, the CIO's I've spoken to have described limited to no measurable business value - public statements to the contrary notwithstanding. But bottom line, expensive consultants notwithstanding, no-one really has this figured out yet. Which means...
- The economics of AI are still very much unclear. Demand side is subject to ROI, which is based on value and cost, and supply side is dependent on debt-financed investment with no clear path to profitability, and potentially increased legal exposure.
- What might be the clearest evidence we're still figuring this out is how quickly tools and techniques are evolving. In the last few years, we've seen constant evolution - prompt engineering, spec-driven development, context engineering, harness engineering, loop engineering etc. MCP, A2A, AP2, ACP, UCP etc.: protocols have emerged, merged and evolved.
So what does that mean?
An AI strategy based on the knowledge, tech, and techniques we have now is stale before the first reader has finished it - things are moving so fast, winners and losers haven't been identified at any level, and the providers are all trying to come up with value added services.
At best it might be mildly helpful. At worst, it sets us on a path to costly failure. More likely, it gives clarity, and yields some benefits, but offset by expense, and misdirected efforts.
We all experience corporate pressure to come up with an AI strategy. On the one hand, we need time to see how this all shakes out a bit more, but on the other, there are things we legitimately need to think about, learn about, experiment with, and simply do for a strategy to work.
So for now, the AI strategy should be focused on resolving ambiguity, and establishing what will become the actual strategy. It should cover three areas:
- Outcomes
- Hypothesis framework
- Enablers
Outcomes
What is the strategy designed to achieve? Not objectives, which can too quickly become tactical and banal, but outcome-oriented. Some of these I suspect will be common across strategies, since most organisations need to figure these things out. These outcomes should be the ones we assert will lead us to a full strategy if we figure them out.
For example:
- Governance. How are we going to manage the AI infrastructure, processes, financials etc? Who gets to decide.
- Guardrails, security, and quality lifecycle. How are we going to secure our AI tooling and agents, and monitor and manage quality to prevent gradual or acute degradation as models or context changes.
- Agentic observability. Guardrails are great, but we need robust tooling to observe, diagnose, and resolve when things go boom. And they will at some point, especially with non-deterministic systems. This observability will look completely different to that needed for SAP, a monolith, or microservices architectures.
- Lifecycle management. How we're going to manage lifecycle, so the agents of today don't become the zombies of tomorrow, when they're no longer delivering ROI.
- Value thesis. What do we think is the core value proposition(s) that AI will deliver. I.e. when/where do we think we should use it.
- ROI measurement. How are we going to measure that value, and attribute expense, so we can objectively tell if our AI pays for itself?
- Cultural impacts. If we buy into the idea that agents are basically a digital employee (not sure I do - I suspect they'll always be clankers to a material chunk of the team), what impact will that have on our culture, and what do we believe we need to change, in order to succeed.
- Long term organizational health and sustainability. I've written about this before. Skills will be prone to atrophy. Cognitive debt will increase. There's evidence that output and knowledge will degrade over time. How are we going to identify, monitor, and manage things that may not begin to visibly impact for years?
Understanding the outcomes will give us the tools to form our diagnosis and guiding policy of the future strategy.
Hypothesis Framework
If the purpose of the strategy is really to gain enough insight, and experimental/empirical data to form a coherent actionable strategy, then we need to be intentional about how we're going to manage and optimise our experimental context. I think about this in a few ways:
- Core Hypotheses. The most obvious is that we should lay out the core set of hypotheses we need to test to arrive at our outcomes.
- Hypothesis curation. The framework we have to cultivate, add, answer, and retire hypotheses. We can't know everything we want to experiment with, so we need some way to manage and cultivate new ones, and kill off the ones that were simply the wrong question to begin with.
- Experimentation culture. It's becoming clear that AI needs to be democratised to figure out what works and doesn't. How are we going to make it safe for our people to experiment, and encourage and incentivize them to do so. How are we going to know about, and harvest the results of these experiments, and extract the underlying, or resultant hypotheses?
- The knowledge repository. In an agentic world, Confluences, Wikis, Sharepoints etc are suboptimal. Data should be easily accessible, navigable and usable by humans and agents. Markdown works well in this context. How are we going to make that work? Ideally, throw it all in markdown into git or similar, and give agentic tooling access. There's a lot of detail to be worked out, but we need to figure this out - again likely through experimentation and learning.
Enablers
What do we need to be true in order to execute our AI strategy, and get our outcomes. I think this will likely be very common across organizations. Likely it will include:
- Quality data, structured appropriately, and accessible to AI tooling.
- A semantic and/or ontological layer: the organizational metadata and taxonomy that will maximise our chances of success.
- Digital encoding of organizational data that's biologically encoded now. My friend Geoff Underwood has a well thought out theory that one of the key inhibitors of successful AI deployment is that much of the knowledge of how an organization really works is tied up in human brains. It needs to be externalized and encoded digitally, so AI can actually use it.
What kind of AI organisation do we want to be?
Finally, we have a key decision to make. What kind of AI organisation do we want to be? OK that's a big question, but there's a few permutations I think:
- AI-assisted organization: The org is going to use tools like copilots, chatbots, etc. In this model, humans are clearly in the lead. AI is a side-of-desk set of tooling. This is IMO probably the safest option, with both the least upside, but also limited downside.
- AI-powered organization: We're using AI tools in systems and tools, and redefining workflows to maximise the value of AI. This is probably the middle way. We can benefit from COTS AI tools, and get more than peripheral value from AI, but without betting the business.
- AI-led organization: We're going to rearticulate everything, on the guiding premise that AI is a profound game changer. This includes processes, technology, skills, and the organization itself; teams are smaller, with completely different skillsets, built around the AI, rather than the AI being built for the teams. I think this is pretty much the "bet the company" one-way door decision. If the decision is right, the payoff is enormous. If it's wrong, the consequences are catastrophic. This risk is compounded by the questionable economic viability of the current frontier models.
I think that probably needs to be directionally stated up front since it will inform our hypotheses, and clarified/validated in the strategy as we execute. I could also see that being a key outcome.
Most organizations will likely end up AI-assisted or AI-powered. Only the big, bold audacious ones, and most startups will be AI-led. And like the startups of today and yesterday, I suspect there'll be at least as many misses as hits in organisations that adopt this model. History is littered with failed startups making big big bets.
With validated hypotheses, key enablers, and the resulting outcomes, I think we can put together a robust strategy in the Rumelt model, with a solid Diagnosis, experience-led Guiding Policy, and informed Coherent actions. We'll be able to select, shape, and exploit AI in a context that's right for the organization, is built on experience gained, and validated against the corporate context. It's just too early, too volatile, and too emergent to believe we can reliably do that in this moment.