Developing an Organizational AI Strategy
Beatrice Sandoval, Deputy Assistant Secretary for Program Innovation at a large federal health agency, had been running AI pilots for two years. Twelve of them. Document summarization, benefits eligibility triage, call-center routing, fraud detection, provider directory updates. Each was funded from a different pot, staffed by different contractors, and governed by a different program office. When her agency's Chief Information Officer asked her to present "the AI strategy" to the Secretary's staff, Beatrice looked at her notes and realized she had twelve answers rather than one. She had motion. She did not have direction.
That pattern will be familiar. Excitement about AI builds, a pilot launches, budget pressure arrives, priorities shift, leadership changes, and the project limps along or quietly disappears. The failure almost never starts with the technology. It starts with strategy, or with the absence of one, and this lesson is about building the thing that was missing.
Vehicles Without a Route Map
Think about a city bus system. A collection of buses is not a transit system. A transit system has a map, routes designed around where people actually live and work, schedules coordinated so that connections are possible, and a governance structure that decides where new routes go and which underperforming routes get cut. Without those things you have vehicles. You do not have transit.
Beatrice had twelve buses. Some were running well. Some had almost no riders. Two were duplicating the same route. None of them connected to each other, and nobody had drawn a map. An AI portfolio is a list of projects. An AI strategy is a coordinated plan that ties those projects to mission outcomes, sequences them by priority, connects them to budget and workforce decisions, and defines how the agency will know whether the work is succeeding. Agencies that confuse the two fund pilots indefinitely and scale nothing.
What Strategy Actually Is
Strategy is clarity about how you will create value within constraints. Government AI differs from commercial AI in one decisive respect: success is not measured in revenue or market share, it is measured in public outcomes. Are services delivered faster? Are decisions more accurate? Are vulnerable populations better served? Those are the questions your strategy has to be able to answer, and they are the questions an oversight hearing will actually ask.
A real AI strategy answers four questions. What specific government problems does AI actually help us solve? What capabilities, across data, technical, governance and organisational dimensions, must we build? What has to change in how we work for those capabilities to function? And how will we know whether this is working? Without answers, every downstream decision, meaning budget allocation, hiring, vendor selection and governance design, gets made in the dark. You optimise for the wrong things, waste resources, and lose credibility the moment someone asks why the investment matters.
The difference shows up in the sentence itself. A private company can say it will use AI to cut costs by a set percentage and gain market share. You cannot say that. You can say something closer to using AI to process benefit applications substantially faster, eliminate the processing backlogs that currently delay citizens by months, while improving accuracy and keeping human review for edge cases. That version is specific about outcomes, carries its guardrails inside the statement, and connects explicitly to public benefit. That is what a government AI strategy sounds like.
Five Objectives You Are Balancing at Once
Government AI strategy is complex because you are juggling objectives that sometimes pull against each other. You have to serve the public mission and deliver better outcomes for citizens. You have to maintain democratic accountability, which means citizens and elected officials must be able to understand and trust how AI is used. You have to operate inside legal constraints that a private company does not face, including FOIA, the Privacy Act, accessibility law and civil rights law.
You also have to manage political risk, because elections happen and what you commit to today has to survive a change of leadership. And you have to balance innovation against stability, because you cannot experiment on public systems the way a startup can experiment on its own product. A strategy that optimises hard for any one of these at the expense of the others tends to fail on contact with the ones it ignored, usually at the least convenient moment.
Start With Mission, Not Technology
The wrong first question is what AI tools are available. That produces a vendor fair, not a strategy. The right question is what the top citizen-facing problems are that you have not solved well. Your AI strategy has to flow from why the organisation exists. For a labor ministry, the strategy is not to adopt machine learning. It is to help workers transition to emerging sectors faster, help employers anticipate talent needs, and target training resources where the impact is greatest. The tools follow from that, not the reverse.
There is a simple test. Can you describe your AI strategy in one paragraph to an elected official who knows nothing about AI? If you cannot, it is not aligned to mission, and no amount of technical detail will fix that. The paragraph is not a communications exercise. It is the diagnostic.
Beatrice's agency administered benefits to roughly 2.3 million low-income households. When her team mapped the failure points, meaning where people fell out of the system, where errors accumulated and where waits exceeded any defensible threshold, three problems dominated: re-enrollment paperwork averaging 47 days to process manually, a call center with a 34-minute average hold time for eligibility questions, and a fraud detection backlog associated with an estimated $180 million annually in improper payments. Those three problems defined the strategy. Of the twelve pilots, four addressed one of them. The other eight had no traceable connection to a measurable citizen-facing problem. Beatrice's team called them science projects, and they were not funded through the next budget cycle.
A Vision With Numbers In It
Develop a three to five year vision statement, and make it concrete rather than corporate. A usable one names a timeframe, quantifies its targets and states an equity dimension explicitly: an agency committing to reduce application processing from six months to two weeks within three years, raise first-pass approval accuracy from 82 percent to 94 percent, and ensure equal performance across demographic groups is saying something that can be checked. A vision that cannot be checked cannot be managed, and it will not survive the first leadership change.
Then break the vision into annual objectives with their own metrics. A common and realistic shape is that year one focuses on data readiness and pilot design, year two on running pilots and learning from them, and year three on scaling with confidence. The sequencing matters more than the specific split, because it forces the honest conversation about what cannot start yet, which is the conversation most strategy documents avoid.
The AI Strategy Canvas
A government AI strategy needs six components, which are the six elements of a transit system's operating plan. Remove any one and the system begins to fail in a predictable place.
Mission alignment
Every AI initiative must connect to a goal in the agency's strategic plan. Under GPRA, the Government Performance and Results Act, federal agencies must publish multi-year strategic plans with measurable performance goals. An AI strategy that does not map to those goals will not survive a budget review or an oversight hearing. For each initiative, document which strategic plan goal it supports and how progress will be measured, in that order.
Capability gaps
What skills, data infrastructure and technology capacity does the agency lack today? Beatrice's agency held 14 years of benefits data in a legacy COBOL mainframe that no modern AI tool could read directly. The strategy had to include a data extraction and modernization plan, or no pilot would ever reach production. Mapping the gaps before committing to use cases prevents building a roadmap on infrastructure that does not exist.
Use case portfolio
The strategy must specify which use cases the agency is pursuing, what stage each occupies, and what measurable outcome defines success. Beatrice's team used a three-column table: use case name, current stage as discovery, pilot, scaling or retired, and target metric. The re-enrollment pilot targeted a reduction from 47 days to 15 for 80 percent of cases within 12 months. That specificity is what separates a funded initiative from a science project.
Governance model
Who has authority to approve, oversee and shut down AI systems? The agency's Office of Inspector General, which independently audits programs for waste, fraud and abuse, will eventually ask, and the answer needs to be documented before then. Beatrice's agency established an AI Governance Board with representation from program offices, the Office of General Counsel, the Chief Information Officer, the Privacy Office and the Office of Civil Rights. It met monthly and held authority to pause any AI system pending review.
Workforce plan
Who will build, manage and use these systems, and how will they be trained? Beatrice's workforce plan identified three populations: the technical team building and maintaining the models, program staff using AI outputs in daily work, and supervisors reviewing AI-assisted decisions. Each needed a different curriculum. That design does not happen automatically and has to be resourced explicitly in the strategy rather than assumed into existence.
Budget alignment
What is in the budget request? An initiative not described in the Congressional Justification, the detailed budget document submitted to Congress explaining funding requests, will not receive appropriated funds. Beatrice's budget map showed which fiscal year each initiative was funded in and whether scaling costs had been requested. Two of her twelve pilots had no scaling budget in any future year, which meant they were structurally unable to grow regardless of how well they performed.
The Capability Roadmap Behind the Canvas
Capability gaps deserve more than a line item, because they are usually what determines whether the strategy is executable at all. Four categories matter. Data capabilities: do you have clean, accessible, properly governed data? Most agencies discover they do not, and it is common to need something on the order of 12 to 18 months of data infrastructure work before a first serious AI use case can launch. Technical capabilities: do you have data scientists, machine learning engineers and data engineers, and can you actually hire them? Government salary bands rarely compete with the private sector, so the realistic answers usually involve partnerships, contractors and training rather than direct hiring.
Governance capabilities: do you have processes for assessing algorithmic impact, monitoring for bias and auditing systems in production? If not, build those before the systems that will need them, not afterwards. And change management capabilities: can the organisation absorb significant change, and do you have the leadership attention, communication infrastructure and training programs to support it? A strategy that assumes any of these four and provides for none of them is a plan for a different agency.
Who Has to Believe This
A strategy is only real if the people who have to act on it accept it. Six groups matter. Leadership must provide funding, political cover and accountability. Operations staff must implement it and adapt their workflows. Data owners must release data and vouch for its quality. Compliance and audit must approve the frameworks and provide oversight. Employee representatives matter because the labour implications are real and will be raised whether or not you raise them. And the public, along with advocacy organisations, must be able to understand and trust the AI use.
Each group cares about something different. Leadership cares about outcomes and cost. Operations staff care whether their jobs change and whether they will be trained. Compliance cares about risk and documentation. Build a distinct message for each, and then check the versions against each other, because the fastest way to lose all six at once is to be caught telling them incompatible things. Different emphasis is legitimate. Different facts are not.
The Governance Choice You Make Early
Before you design a board, you make a structural choice: who decides which AI projects the agency pursues, and how priorities are set. Centralized authority, in which a steering committee approves all AI work, makes risk easier to control and alignment easier to maintain, at the cost of speed and responsiveness. A federated model, in which departments propose projects subject to guardrails, is faster and more adaptive, and it is riskier when the guardrails are weak. Hybrid arrangements are common and inherit some of both.
There is no correct answer, only a choice that should be deliberate and written down. What causes trouble is drifting into a model by default, usually a federated one, without the guardrails that make it safe, and then discovering the shape of the arrangement during an audit rather than during a design discussion.
A Worksheet for Drafting the Strategy
The canvas above is what the finished strategy contains. Getting there is easier with a structured set of prompts, and eight work well as a drafting exercise with a leadership team.
- Mission and outcomes. One paragraph on why this matters to government, plus two or three quantified outcomes.
- Current state. What are you doing today, where are the biggest pain points, and where do citizens experience the worst outcomes?
- AI opportunities. Which pain points could AI reasonably address, which have the most impact if solved, and which are feasible with the data and technology you realistically have?
- Prioritized roadmap. Your top three to five use cases for the next three years, sequenced, with the capability gaps that must close first for each.
- Capability building. What data, technical, governance and organisational capabilities are needed, in what order, on what timeline?
- Success metrics. How will you know you are winning? Be specific and quantified, and include equity and fairness dimensions rather than appending them.
- Stakeholder engagement plan. Who needs to understand and support this, and what is the communication approach for each group?
- Risk acknowledgment. What could go wrong, and how are you mitigating the largest risks?
Spend disproportionate time on the first two. What does this organisation exist to do, and where could AI actually help it do that better, are the questions every later decision inherits. Teams that rush them produce documents that read well and cannot be executed.
Connecting to Existing Frameworks
Agencies do not build AI strategy from scratch, and the ones that try produce a document floating outside every structure that allocates money or attention. Three existing frameworks are the anchors. The agency's strategic plan, required under GPRA, sets the mission goals AI initiatives must serve, and the AI strategy should sit inside that plan's implementation structure rather than beside it.
The Congressional Justification, submitted annually to appropriations committees, is where AI investments become real money. If an initiative is not described there, Congress has not funded it, whatever the strategy says. Building an AI roadmap without involving the budget office reliably produces plans with no funding pathway and no way to acquire one mid-cycle.
Congressional mandates and Government Accountability Office recommendations are the third anchor. Some agencies carry AI-specific reporting requirements in authorization legislation. Others face GAO recommendations that effectively require governance actions. Ignoring either creates audit exposure that outlasts any individual initiative and, frequently, any individual official.
Escaping Pilot Purgatory
Pilot purgatory is what happens when agencies run pilots that never scale, and Beatrice had lived in it for two years. The causes are almost always the same three.
First, no success criteria defined upfront. A pilot without a documented definition of success never produces a clear go or no-go decision. It produces a report describing promising results and a request for more time. Second, no budget line for scaling. A pilot in the low hundreds of thousands cannot reach agency-wide deployment without a funding plan covering production infrastructure, the procurement contract and ongoing operations staff. If that plan is not built into the next budget cycle during the pilot phase, the pilot ends without a successor. Third, no executive sponsor with authority. Someone must be empowered to say that this worked and should be funded, and that this failed and should be shut down. Without that assignment, successful pilots stall in review and failed pilots persist because nobody wants to declare the investment lost.
The route out is a pilot-to-production gate: a formal decision point with defined criteria, a named decision-maker and a budget pathway. Beatrice's agency used a 90-day pilot structure. At day 90 the named sponsor reviewed three metrics against pre-defined targets and documented one of three outcomes: proceed to production, extend for a specific reason with a specific end date, or retire. There was no fourth option, and removing the fourth option is most of what the gate accomplishes. A bus that runs forever with no passengers is not a transit success, it is a budget failure nobody had the authority to end.
Scaling costs for pilots that passed the gate went into the next budget submission. The roughly two-year lead time from pilot gate to appropriated funds is not bureaucratic delay, it is the federal budget process, and a strategy that ignores that timeline produces pilots without successors no matter how well they perform.
Three Agencies That Chose a Direction
The examples below come from different levels of government and show what a strategic choice actually buys, along with what it does not.
A large tax authority had scattered AI projects: one team building fraud detection, another automating document processing, a third predicting payment risk. The teams did not talk to each other, each claimed to be the highest priority, budget was limited and leadership was confused. They stepped back and wrote a strategy committing, within three years, to increase voluntary compliance by 8 to 12 percent, raise audit accuracy from 76 percent to 88 percent, and reduce compliance costs for small businesses by 15 percent. That single statement clarified everything downstream. Fraud detection stayed but was refocused. Document automation became priority one because it bore directly on compliance costs. Payment risk modelling was deprioritised as interesting but less connected to the mission. Budget followed the priorities and the teams aligned. The account records that the targets were met over the following three years, which is the agency's own report rather than an independently verified result, and the transferable lesson is the clarifying effect of the statement rather than the specific numbers.
A national health ministry knew AI could improve disease surveillance, speed diagnosis and optimise resources. It also knew that early AI systems in healthcare often performed worse for minority populations, not through intentional bias but because training data was skewed. Its strategic commitment was explicit: it would only deploy AI where it could confidently demonstrate equal or better performance across all demographic groups, and until then AI would augment human decision-making rather than replace it. That choice shaped everything downstream, including the data strategy, which required representative training data; vendor contracts, which carried explicit demographic parity testing; and governance, which required independent fairness audits before deployment.
Two observations about that case. The commitment is a strong one and worth carrying as written, because erring toward caution in health deployment is the right direction of error. It is also worth being precise about what a parity demonstration establishes: it covers the groups you measured, with the data you had, at the time you measured. Groups too small to appear in the evaluation set, or not recorded at all, are not covered by the test, which is an argument for keeping the human-augmentation posture rather than for weakening the commitment. The delay was reported as six to twelve months. Whether that delay prevented specific harm cannot be established, since the harmful deployment never happened; what can be said is that the ministry declined to deploy under conditions it could not evidence, which is a defensible strategic position on its own terms.
A mid-sized municipality wanted to modernise service delivery but had limited IT infrastructure and a small data team. Rather than attempt integrated AI across multiple services, it adopted a constraint: build capabilities sequentially, one high-value use case at a time, going deep and building local expertise before repeating. Year one was permitting process automation, chosen for clear returns, straightforward data and high citizen impact. Year two was pothole detection and road maintenance optimisation, a different domain that allowed skills to transfer. Year three was predictive resource allocation across city services. By year three the municipality had a capable data team, tested governance processes, organisational confidence and a working portfolio. The strategy was to sequence, go deep, and build capability, which is frequently the right answer for a small organisation and is almost never the exciting one.
Anti-Patterns
- Strategy as wishlist. Every division wants its project approved, so the strategy says yes to everything. Resources spread thin, nothing is done well, no capability accumulates because the team is constantly context-switching, and eighteen months later leadership loses patience. One federal agency's initial strategy listed 47 potential use cases across every division; two years later three pilots were running and nothing was deployed, and leadership concluded that AI did not work for them. Real strategy is saying no to most ideas, using decision criteria applied consistently.
- Technology-first strategy. A senior technologist is excited about a technique and it becomes the centre of the plan. Government is measured on outcomes rather than technical sophistication, and a simple model that reliably saves citizens time is worth more than a sophisticated one that is inaccurate and unexplainable. Start with the mission and the problem, then choose the technique, which is sometimes a rule-based system.
- Ignoring organisational capacity. A bold three-year transformation is declared by an organisation with fifty people, no data team, no cloud infrastructure and legacy systems from decades ago. Halfway through, reality arrives: hiring fails, data is unusable, security blocks the architecture. One state agency spent 18 months and $2 million and had a single prototype and no deployed systems, and the strategy lost its credibility entirely. Assess capacity ruthlessly and sequence to it.
- Static strategy. Six months of work produces a comprehensive document that then sits unchanged while data, technology and priorities move. Build in quarterly progress reviews and an annual refresh that asks what has been learned and what should change. The alternative is not stability, it is a document nobody believes.
- Confusing a portfolio with a strategy. Twelve funded pilots feel like momentum and produce a status report rather than a direction. If you cannot say which mission goal each project serves and what happens when it succeeds, you have a list.
- Piloting without a gate. No success criteria, no scaling budget and no sponsor with authority to end things. Successful pilots stall and failed ones continue, because continuation is the only option nobody has to defend.
- Writing the strategy without the budget office. A roadmap developed in isolation from the appropriations calendar produces initiatives with no funding pathway, discovered at the point where the pathway can no longer be created.
- Adding equity at the end. Fairness objectives appended to a finished strategy tend to become reporting obligations rather than design constraints. Put them into the vision statement and the success metrics, where they change decisions.
Practice Prompts
- Mission clarity. Write a one-paragraph AI strategy for your organisation now, using the shape: our agency will use AI to address a specific problem, this will produce a quantified outcome, and we will know we are winning when a stated metric moves. Is it connected to the mission, and would a non-technical leader understand it?
- Capability assessment. For your top three priority use cases, list the capability gaps across data, technical, governance and organisational dimensions. Which are deal-breakers, and which could be closed through training or partnership?
- Stakeholder perspective. Pick three stakeholders, such as frontline staff, executive leadership and compliance, and write the one-sentence version of why AI matters for each. Are those three sentences compatible with one another?
- Sequencing logic. Take five to ten candidate use cases and rank each on mission alignment, feasibility and capability-building potential. Does the ranking surprise you, and what does it say about which project should come first?
- Resilience test. Ask what would have to happen for this work to stop. Budget cut, leadership change, technical setback: how robust is the strategy to each, and what would you change to make it more so?
- Portfolio audit. List every AI activity currently running in your agency and mark which mission goal each serves and what its scaling budget is. The ones with neither are your science projects.
Reflection
Imagine briefing your agency head a year from now on your AI strategy's progress. What will you tell them you accomplished, what metrics will you show, and what will have changed about how the organisation works? Write that briefing now and use it as the reference point for the strategic work in between. Then run the harder test on what you wrote: if the administration changed, the budget tightened, and your executive sponsor moved on, which parts of that briefing would still be true? Whatever survives all three is your actual strategy. The rest is a plan that depends on conditions holding, and it should be labelled as such where leadership can see it.
Glossary
- AI strategy. A coordinated plan tying AI initiatives to mission outcomes, sequencing them, connecting them to budget and workforce decisions, and defining how success will be judged. Distinct from a portfolio, which is a list.
- AI maturity model. A framework for assessing organisational readiness to deploy AI, typically covering data readiness, technical capability, governance sophistication and change management. The MITRE AI Maturity Model and the GSA AI Capability Maturity Model are commonly cited references.
- Capability roadmap. A sequenced plan for building the organisational capabilities the strategy requires, covering data infrastructure, hiring and training, governance establishment and change management.
- Stakeholder map. A representation of who has an interest in the strategy, how much influence each holds, and their likely position, used to tailor engagement without tailoring the facts.
- Use case prioritization. Ranking candidate AI applications by mission alignment, technical feasibility, resource requirements and strategic value. Common frameworks include RICE, covering reach, impact, confidence and effort, and ICE, covering impact, confidence and ease.
- Mission alignment. The degree to which an initiative directly supports why the organisation exists and what it is accountable for delivering. The core test of strategic validity.
- Governance structure. The decision-making framework for approving, prioritising and overseeing AI initiatives. Centralized, federated or hybrid.
- Pilot purgatory. The condition in which an agency runs pilots indefinitely without scaling any of them, caused by missing success criteria, missing scaling budget and missing decision authority.
- Pilot-to-production gate. A formal decision point with pre-defined criteria, a named decision-maker and a budget pathway, producing one of a fixed set of documented outcomes.
- Congressional Justification. The detailed budget document submitted to Congress explaining an agency's funding requests. An initiative absent from it has not been funded.
- GPRA. The Government Performance and Results Act, under which federal agencies publish multi-year strategic plans with measurable performance goals.
Related Lessons
This lesson opens the strategy sequence. AI Maturity Assessment is how you establish the capability baseline the roadmap depends on, Prioritization Frameworks for Government AI is how you choose between candidate use cases, and Building the AI Business Case turns a prioritised initiative into a funded one. AI Roadmap Development sequences the result, and Strategy Capstone: Building Your AI Strategy assembles the whole. For the governance choice, see Establishing an AI Governance Board and Your Agency's AI Governance Structure; for the pilot gate, AI Pilot Program Design and Moving from Pilot to Production. Workforce Planning for AI develops the workforce component, AI Portfolio Management covers running several initiatives at once, and AI Strategy for Different Government Contexts addresses how much of this transfers between federal, state and local settings.
Closing
The trap most practitioners fall into is jumping straight to tactics: hire data scientists, stand up a governance board, launch a pilot. Those things matter, and without the strategic foundation underneath them you are building on sand, which is exactly how an agency ends up with twelve pilots and no direction. Work the canvas with your leadership team before anything else, and spend real time on the two questions that everything else inherits: what does this organisation exist to do, and where could AI actually help it do that better?
Building an AI strategy is ultimately an institutional question rather than a technical one. What kind of government organisation do we want to be, what does AI make possible that is not possible today, and how do we implement it in ways that strengthen public trust and equitable outcomes? Agencies that sustain AI adoption through budget cycles and changes of administration are rarely the ones with the most advanced models. They are the ones that could say, clearly and in one paragraph, what they were trying to accomplish and why it mattered.
Key Takeaways
- A portfolio is not a strategy. A list of AI projects is not a coordinated plan. Strategy requires mission alignment, sequencing, governance, workforce integration and budget connection.
- Start with citizen problems, not technology options. The first question is which unresolved citizen-facing problems matter most. Technology selection comes after that answer is clear.
- Pass the one-paragraph test. If you cannot explain the strategy to an elected official who knows nothing about AI, it is not aligned to mission, and no amount of detail will compensate.
- The canvas has six required elements. Mission alignment, capability gaps, use case portfolio, governance model, workforce plan and budget alignment. Missing any one produces a failure at a predictable point.
- Balance five competing objectives. Public mission, democratic accountability, legal constraints, political risk and the tension between innovation and stability all apply at once, and a strategy that optimises for one fails on the others.
- Be ruthlessly realistic about capacity. Data infrastructure work commonly precedes a first serious use case by many months. An ambitious strategy you cannot execute costs more credibility than a modest one you can.
- Prioritisation is the whole point. Real strategy means saying no to most ideas so that a few get focus and resources. A strategy that says yes to everything is a wishlist.
- Anchor inside existing planning frameworks. The agency strategic plan, the Congressional Justification and congressional or GAO requirements are what make AI investments durable across budget cycles and administrations.
- Pilot purgatory has three specific causes. No upfront success criteria, no scaling budget and no named decision-maker with authority to end or fund. Each has a fix that must be in place before the pilot starts.
- Strategy is not static. Build in quarterly progress reviews and an annual refresh, because priorities move, capabilities emerge, and a plan that never changes stops being believed.
Frequently Asked Questions
How long should a government AI strategy be?
Short enough that the people who have to act on it read it, which in practice means the six canvas components with specifics rather than a long document with generalities. The test is whether a program office can look at it and know which of its initiatives are funded, what each has to demonstrate, and who decides. If that is unclear, length is not the problem.
We are a small local agency. Does any of this apply?
The canvas applies, the scale does not. A municipality with a small data team should choose sequential depth over breadth: one high-value use case at a time, building expertise before moving on. The failure mode for small organisations is not lack of ambition, it is attempting an integrated program with the capacity for a single project.
How do we handle the pilots we already have that do not fit the strategy?
Put them through the gate rather than cancelling them by announcement. Define the criteria, name the decision-maker, set the date, and document the outcome as proceed, extend with a specific end date, or retire. Initiatives ended through a stated process create far less organisational damage than initiatives ended by an abrupt decision, and the process is what you will reuse.
Should equity commitments be in the strategy or in the governance framework?
In both, but the strategy is where they change behaviour. Written into the vision statement and the success metrics, they constrain which use cases proceed and what evidence is required. Confined to a governance annex, they tend to become a reporting obligation checked after the design decisions have already been made.
What if leadership changes halfway through?
Assume it will. That is why the strategy anchors into the agency's strategic plan, the budget submission and any statutory or GAO-driven requirements, all of which outlast individuals. The parts of your plan that depend entirely on one sponsor's enthusiasm should be identified as such, so leadership can decide knowingly whether to accept that exposure.
How do we choose between centralized and federated governance?
By deciding which risk you would rather carry. Centralized control aligns work and slows it. Federated approaches move faster and depend entirely on the strength of the guardrails. What causes trouble is neither model but drifting into one by default and discovering its shape during an audit. Make the choice explicitly, write it down, and revisit it at the annual refresh.
Skill.re