For many organisations, the conversation about artificial intelligence starts with tools. Which AI assistant should we choose? Who should receive a Copilot licence? Where could an agent save time? Which business process should we automate first? These are useful questions, but they are not an AI strategy. A genuine AI strategy connects ambition with operational control. It sets out what the organisation wants AI to achieve, what data and identities it can access, how risk will be managed and how value will be measured after deployment. That last point matters. AI does not stop being an operational concern when a licence is assigned or an agent goes live.
It should answer six core questions:
If your current AI plan only answers the first two questions, it is probably an adoption plan rather than an operational AI strategy.
You cannot govern AI that you cannot see.
Employees may already be using AI applications to summarise documents, analyse information, generate content, write code or accelerate everyday tasks. Some of that activity may be legitimate and valuable. Some may involve applications that have not been reviewed or approved.
This is the challenge of Shadow AI, where AI services are used outside an organisation’s recognised technology, security or governance processes.
A recent customer discussion centred on a fundamental question: “What is actually going on in my environment?” That includes understanding which AI services are in use, what agents are operating and whether people are accessing organisational data through non-standard tools.
Visibility should therefore come before restriction. Organisations first need to understand:
A Shadow AI assessment can act as the starting point for this baseline. It can help an organisation review usage, detect Shadow AI activity, monitor data protection controls and identify sensitive or proprietary information being sent to AI applications.
1. Business outcomes and prioritised use cases
Start with the problem, not the product.
An organisation should identify the processes where AI can create measurable value, such as reducing manual effort, improving access to knowledge, supporting service teams or accelerating analysis.
Not every problem requires AI. A conventional workflow or automation may be simpler, more predictable and easier to govern. AI should be introduced where it provides a clear additional benefit.
For every proposed use case, define:
This turns AI from a technology experiment into a governed business capability.
2. Data security and governance
AI systems are only as safe as the information they can reach.
Your AI strategy should define how sensitive, personal, confidential and proprietary information will be protected. It should also establish what information can be used with approved AI services and what information must not be submitted to unapproved tools.
The customer discussion positioned AI control and security posture as closely connected. It also highlighted the need to review whether access to data breaks policy, whether users should have access to that data in the first place and whether work is being completed through non-standard tools.
Key controls may include:
3. Identity and access for people and AI agents
AI governance is becoming an identity issue as well as a data issue.
Employees already require the right access to the right resources. AI agents introduce another category of identity that may be able to retrieve information, initiate actions or work with other agents.
An operational AI strategy should therefore define:
Agent delivery should be connected with identity, data governance and Copilot controls rather than treated as an isolated technology project.
4. Adoption and employee enablement
Governance should make safe AI use easier, not simply block activity.
If employees are already turning to unapproved AI tools, that behaviour may indicate unmet demand. They may need an approved service, practical guidance or role-specific training.
Usage information can help organisations identify:
That creates a more productive response to Shadow AI. Instead of treating every user as a policy problem, the organisation can use the data to improve adoption and direct demand towards approved options.
5. Cost and licence optimisation
An AI strategy also needs a commercial dimension.
Assigning licences is not the same as creating value. Organisations need to know whether licences are being used, whether adoption is sustained and whether the right people have access.
The operating model should review:
The source material also identified Microsoft 365 usage reporting, licence reporting and related recommendations as important elements of a proactive service, alongside monitoring and tenant posture assessments.
6. Continuous monitoring and improvement
AI environments change too quickly for an annual policy review to be sufficient.
New applications appear. Approved services add features. Employees find new use cases. Data access changes. Agents gain additional responsibilities.
Operating cycle
Discover → assess → govern → enable → monitor → improve
In the public-sector example that informed this blog, the discussion moved beyond reactive break-fix support towards monitoring, alerting, proactive actions, tenant posture assessments, tailored change guidance, usage analysis and licence recommendations.
That shift changes the question from “Who fixes the technology when something goes wrong?” to “Who helps us operate this environment securely and improve it continuously?”
Ask the following:
If several answers are “no” or “not yet”, the next step is not necessarily another AI purchase. It is to establish visibility and turn AI ambition into an operational roadmap.
AI can create meaningful business value, but adoption without visibility can introduce risk, unnecessary cost and uncertainty.
A strong AI strategy does not force organisations to choose between innovation and control. It creates the conditions for both.
It gives employees access to approved tools. It protects information. It places accountability around agents and identities. It measures adoption. It improves return on investment. Most importantly, it turns AI from a collection of experiments into a managed organisational capability.
So, what’s your AI strategy?
If you cannot yet see which AI tools are in use, how information is moving or whether your current licences are delivering value, a Shadow AI and AI readiness assessment is a practical place to begin.