←
AI for Government
Proficient · M43 · lesson 43 of 50 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Strategy Capstone: Building Your AI Strategy
📖
now learning

Strategy Capstone: Building Your AI Strategy

15 min

Wilhelmina Achebe had attended three AI strategy workshops in eighteen months. Each produced a framework: a two-by-two matrix, a capability ladder, a priority grid. Each framework went into a slide deck. The slide decks were presented to the executive team of the Minnesota Department of Employment and Economic Development, nodded at, and filed. When Wilhelmina was appointed Deputy Commissioner for Operations in January, one of her first acts was to search the department's SharePoint for all three decks. She found them. She could not find a single document that described what the department was actually going to do, who was responsible for doing it, and how they would know when they had succeeded. She had three frameworks and no strategy.

A strategy is not a framework

A framework is a thinking tool. It helps you organize what you know and identify what you do not know. A strategy is a set of decisions. It names what you will do, what you will not do, who is responsible, what success looks like, and when you expect to get there. The confusion between the two is common in government AI work because frameworks are easier to produce and easier to defend. A strategy commits to something, commitment creates accountability, and accountability creates discomfort. That discomfort is the point, and it is also why the strategy document is the artifact most likely to be replaced by a framework at the last moment.

The good news is that a government AI strategy does not have to be long. Wilhelmina's finished strategy document ran eleven pages, addressed six questions, and contained nothing that could not be evaluated at the end of twelve months. A federal agency strategy is typically longer, because it carries policy-mapping obligations a state department does not, but the underlying test is identical at any level of government: can a reader who was not in the room tell what will happen, who owns it, and how you will know whether it worked? This capstone is about producing that document, and it assumes you have already done the component work the rest of the curriculum covers.

Why the written artifact matters

A written AI strategy is not a rhetorical exercise. It serves five purposes in a government environment, and each of them has statutory or regulatory weight rather than merely organizational value. The first is externalizing your thinking, because gaps appear the moment you write. The gap between "we will use AI for benefits adjudication" and "we will use AI to recommend adjudication outcomes under 5 USC 554, with human review under the applicable OMB minimum practices and an opt-out mechanism for the affected individual" is the difference between a slogan and a commitment. Writing forces specificity in a way that discussion never does.

The second is accountability. The Federal Records Act, 44 USC 3301, requires agencies to preserve records of policy decisions, and a signed AI strategy is a policy record. When GAO reviews your agency, they will ask to see it. When a congressional oversight committee holds a hearing, they will ask to see it. When an Inspector General investigates an incident, they will ask to see it. The third is that it becomes a reference point for routine decisions: when a vendor arrives with a generative AI product, the Chief AI Officer checks the strategy. Is this in our use-case portfolio? Is it rights-impacting? Do we have a minimum-practice plan? Is there an authorized offering available? Those questions become routine rather than improvised.

The fourth purpose is communication. Congress, citizens, advocacy organizations, unions representing employees under chapter 71 of title 5, and state and local partners all need to understand what your agency is doing, and a published strategy lets them understand it without filing a records request. The fifth is continuity. Political transitions are disruptive by design, and a written strategy that the career civil service can execute while political leadership changes is what allows a multi-year AI program to survive an administration change, a continuing resolution, or the departure of the executive who sponsored it.

Three incidents make the pattern concrete. In 2023 the Department of Veterans Affairs paused several predictive analytics deployments after its Office of the Inspector General found no enterprise-level written strategy naming which tools were rights-impacting. In 2022 the Internal Revenue Service rolled back automated selection models after the National Taxpayer Advocate reported on disparate audit rates, and a subsequent GAO review recommended the agency publish an enterprise AI strategy tying audit-selection AI to the Taxpayer Bill of Rights. In 2020 the State of Michigan settled a class action over the MiDAS unemployment fraud-detection system, where no written governance document had authorized its rights-impacting deployment.

The pattern across those cases is consistent. Agencies with a written, socialized and signed AI strategy can respond to an incident within days by pointing to their commitments, their monitoring program and their escalation paths. Agencies without one spend months reconstructing what they were trying to do, why, and under whose authority, and that reconstruction usually happens under the supervision of an Inspector General or a congressional committee. GAO's AI Accountability Framework (GAO-21-519SP) reports the absence of a written, enterprise-level strategy aligning AI to mission as a more common root cause of failed federal AI programs than technology choice. Treat the strategy accordingly: as a legal-grade artifact, not a communications product.

The six questions every strategy answers

A complete government AI strategy answers all six of the questions below. If any one is missing or answered only in generalities, the strategy is not finished, and the fastest way to test a draft is to hand it to someone outside the program and ask them to find the answers. The six questions are also the outline Wilhelmina used, and they map cleanly onto the longer federal template covered in the next section, so answering them well is not wasted work if your agency needs the fuller artifact.

Question 1: what mission problem are we trying to solve?

Minnesota's Department of Employment and Economic Development serves two core populations: businesses registering for programs, and individuals filing for unemployment insurance or accessing workforce development services. Wilhelmina's strategy identified two specific mission problems. First, the department's unemployment insurance determination process averaged 22 days against a 14-day federal target, with a manual document-review step accounting for roughly 8 of those days. Second, the business licensing call center handled 94,000 inbound calls per year, with an average hold time of 17 minutes and a 23% call-back rate. Every AI initiative in the strategy had to trace back to one of those two problems, and an initiative that could not be connected to a measurable mission problem did not belong in the document.

Question 2: what is our current AI maturity?

Maturity means honestly describing what you have, not what you wish you had. Wilhelmina's department had one AI system in production: a fraud-detection model for unemployment insurance claims, deployed in 2023, with moderate documentation and no formal monitoring schedule. Data was adequate and structured for the unemployment insurance process and poor in business licensing, with duplicate records, inconsistent formatting and no master identifier. IT staff had basic familiarity with AI tools but nobody had machine-learning expertise. The governance framework was a single-page policy that had not been updated since 2022. A federal maturity baseline adds specific detail on top of that picture: which cloud authorizations the agency holds, which environments are approved, the authorization status of identified systems, and the current AI workforce headcount.

That honest picture tells you what you can attempt in twelve months and what needs a longer capability-building runway first. An agency with poor data quality cannot successfully deploy a document-analysis AI in year one; the business case will fail in evaluation because the inputs are wrong. The maturity assessment exists to stop you committing to things your current state cannot support, which is why it is the section most often written aspirationally and the section where aspiration does the most damage.

Question 3: what will we do, and in what order?

The strategy is not a list of everything you might eventually do. It is a prioritized sequence of three to five initiatives with a stated rationale for the sequence. Wilhelmina's strategy had three. First, automate document classification in the unemployment insurance determination process, targeting a reduction from 22 to 16 days within twelve months, which is six days of improvement and deliberately conservative against the eight-day opportunity. Second, deploy an AI-assisted FAQ tool for the business licensing call center, targeting a 15% reduction in hold time within eighteen months. Third, build common data infrastructure for business licensing records, a prerequisite for any more sophisticated work in that program area, targeted for completion in twenty-four months.

The rationale for that sequence is as important as the sequence itself. The unemployment insurance initiative has the best data quality today and the clearest business case. The FAQ tool is lower risk than a fully automated system and builds internal confidence. The data infrastructure is not glamorous but enables everything that follows. Each initiative either delivers value or builds the foundation for the next one, and writing that logic down is what lets a successor understand why the order is what it is rather than reshuffling it on instinct.

Question 4: who is responsible?

Every initiative names a lead: a specific person with a title, not a team or an office. Wilhelmina named herself as strategy owner. She named the Director of Unemployment Insurance Operations as lead for document classification, with a budget of $210,000 and authority to engage vendors through the state's existing IT contract vehicle. She named the Deputy Director for Employer Services as lead for the FAQ tool, with a budget of $85,000. She named the Chief Data Officer as lead for data infrastructure, with a budget of $340,000 over two years. Federal practice uses the same construction under a different label, naming a Senior Accountable Official for each use case in the portfolio.

Named leads with specific budgets change the nature of the accountability relationship. A strategy that says "the IT division will lead AI initiatives" cannot be evaluated at any point by anyone. A strategy that says a named director will deliver a document-classification system reducing determination time from 22 to 16 days by a stated date with a stated budget can be evaluated in any month of the year, by the executive who signed it or by an auditor who did not.

Question 5: how will we govern AI responsibly?

Every initiative answers three governance questions before it launches. Who reviews the AI's outputs before they affect citizens? The document-classification system flags documents for review and does not make determinations; a claims examiner reviews every flagged document before the case moves forward. That human oversight step belongs in the strategy explicitly rather than being worked out during implementation, and it should say what the reviewer is expected to check, because a review step that becomes a routine approval is oversight in name only.

How will we test for fairness? The unemployment insurance system must be tested to ensure that claims from non-English-speaking applicants, applicants in rural counties, and applicants over 55 are not systematically processed more slowly or denied at higher rates. The protocol, meaning which groups, which metrics, and what threshold triggers a hold, is specified in the strategy rather than delegated to the vendor. And what is the incident response process? If the system produces a wrongful denial, who is notified, in what timeframe, and how is it corrected? That question is uncomfortable to answer before deployment and considerably more uncomfortable to answer after a legislative inquiry.

Question 6: how will we measure success?

Success metrics are set before the initiative launches, not after. For each initiative the strategy specifies the baseline metric describing current state, the target metric at twelve or eighteen months, the measurement method, and the review schedule with a named reviewer. The unemployment insurance initiative's primary metric is average days to determination, measured from application date to decision date, reported monthly from the existing case management system. Not a new data collection effort: an existing data point, measured against a documented baseline, evaluated on a fixed schedule. A strategy that cannot be evaluated at month six was never a strategy. It was a plan to make decisions later.

The federal strategy document template

Where a state department may reasonably produce eleven pages, a federal agency strategy carries policy-mapping obligations that make it longer. The template below is the anatomy that federal reviewers expect, with the page targets the source material sets for each section. The targets sum to a minimum of thirteen pages and a maximum of twenty, against a stated overall goal of fifteen to twenty; do the sum yourself for your own draft rather than treating either endpoint as a requirement. Length is not the deliverable. Completeness under challenge is.

SectionPagesWhat it must contain
1. Executive summary1The vision, the three to five strategic priorities, the named Senior Accountable Official, and the date the strategy was signed
2. Organizational context1The agency mission under its authorizing statute, the operating environment, the stakeholder population, and why AI matters to this mission
3. Current AI maturity1 to 2A maturity baseline across data, infrastructure, workforce, governance and partnerships, citing specific cloud authorizations held, approved environments, the authorization status of identified systems, and current AI workforce headcount
4. Vision and strategic objectives1 to 2A three to five year vision with quantified objectives such as cycle-time reduction, citizen-satisfaction targets, backlog reduction or cost avoidance. Each objective must be measurable
5. Strategic priorities and use cases2 to 3The top three to five use cases sequenced over three years. For each: name, one-paragraph description, mission outcome, risk tier, applicable minimum-practice obligations, expected go-live quarter, Senior Accountable Official, and success metric
6. Capability roadmap2 to 3The data, infrastructure, tooling, operations, evaluation, monitoring and workforce capabilities needed to execute, sequenced quarterly and tied to budget
7. Governance framework1 to 2AI Governance Board composition and chair; the intake, review, approval and escalation process; delegation of authority from the Chief AI Officer to program offices; and how risks escalate to the agency head
8. Workforce strategy1 to 2Plans to hire under available hiring authorities, to train covered personnel as policy requires, and to retain talent, including change management for staff who do not work on AI
9. Stakeholder engagement1Congress, unions, advocacy groups, vendors, academic partners and state partners, with the communication plan for each
10. Risk management1 to 2Top risks including mission failure, rights violation, security incident, equity harm, talent loss and vendor concentration, each with a stated mitigation
11. Metrics and accountability1How success is measured and how often, who is accountable to whom, the quarterly review cadence, and the trigger events that force an interim review

Notice how sections 5 through 8 do the work that the six questions do in a shorter document, and how sections 9 through 11 make the strategy auditable rather than merely readable. The section agencies most often shortchange is number 8, workforce, because it is the one whose failure surfaces last. The section reviewers most often reject is number 3, maturity, because it is the one where optimism is easiest and most damaging. Draft those two first, while you still have appetite for uncomfortable answers.

Mapping the strategy to policy obligations

A federal strategy has to survive challenge from people whose job is to check it against written policy. Four bodies of obligation account for most of that challenge. OMB Memorandum M-24-10, issued in 2024, sets out enterprise-level requirements that CFO Act agency strategies must satisfy. Counting the source's own list, there are ten: designate a Chief AI Officer at senior executive level; establish an AI Governance Board chaired by the Deputy Secretary or equivalent; inventory AI use cases annually; identify and manage risks from AI affecting safety or rights; implement minimum practices; publish compliance plans; remove barriers to responsible AI use; promote innovation; advance equity; and manage workforce implications.

The minimum practices for rights-impacting and safety-impacting AI translate into concrete agency commitments rather than restatements of policy. Those commitments include pre-deployment testing protocols, ongoing monitoring, human review, opt-out mechanisms for consequential decisions, and a termination plan for AI that fails a minimum practice. That last one is the commitment most often omitted and the one an Inspector General is most likely to ask about, because it is the only commitment that describes what the agency will do when its own controls report a failure.

The NIST AI Risk Management Framework supplies the second body. It is voluntary and non-binding, and its value here is structural: mapping each strategic commitment to one of the four functions, Govern, Map, Measure and Manage, and to the associated playbook actions, lets an auditor trace a policy statement to a control to a measurable artifact. The GAO AI Accountability Framework supplies the third, with four principal areas, Governance, Data, Performance and Monitoring, that can be audited directly against your written commitments. Aligning to both is not duplication; the NIST functions describe what you do and the GAO areas describe what an auditor will look for.

The fourth body is statutory and historical. Executive Order 14110 on safe, secure and trustworthy AI set obligations concerning dual-use foundation models, including reporting for models trained above a threshold of 10^26 floating-point operations, red-teaming, a national AI research resource pilot, an AI talent surge, and agency-level obligations on equity, labor, privacy and consumer protection. Those obligations sat alongside continuing responsibilities under the Privacy Act of 1974, FISMA, FedRAMP and Section 508. Separately, the public AI use-case inventory required under Section 7225 of the Advancing American AI Act obliges agencies to describe their use cases publicly, including rights-impacting and safety-impacting designations. Executive orders change with administrations; verify the current instrument before citing one in a document you intend to sign.

On top of the government-wide floor, sector-specific layers apply. Health, defense, homeland security, veterans affairs, financial regulation and securities regulation each publish their own AI guidance, and several of those instruments predate the AI-specific policy entirely. Defense autonomy policy under DoD Directive 3000.09 and the model risk management guidance known as SR 11-7 are both examples of frameworks that a modern AI strategy has to reconcile with rather than replace. Identify your sector layer early, because a strategy that satisfies the government-wide requirements and contradicts your own component's directive will be returned by your own counsel.

Connecting to budget and procurement

A strategy that exists only as a document fails. It has to connect to the two levers that actually move things in government: budget and procurement. On the budget side, Wilhelmina's strategy was submitted to the department's legislative budget request for the following fiscal year, with the three initiatives and their budgets as line items. That meant the strategy had to be defensible to legislative staff, which is to say specific, evidence-based and tied to outcomes legislators already cared about, since unemployment insurance processing time had been a topic at two hearings. It also had to survive a two-year horizon, because that is the Minnesota budget cycle, so initiatives scoped at three and six months did not fit the legislative timeline.

On the procurement side, the strategy was shared with the state's central IT procurement office before it was finalized. That office identified two existing contract vehicles that could support the first initiative without a new solicitation, estimated the FAQ tool procurement at six months rather than the three Wilhelmina had assumed, and flagged that the data infrastructure project would need a competitive solicitation because it exceeded the delegated purchasing threshold. Those adjustments changed the implementation timeline before it was committed to, which is a considerably better place to discover procurement constraints than six months after announcing a deadline.

Federal resourcing has its own vocabulary for the same constraint. The strategy has to connect to appropriations cycles, to IT portfolio governance under FITARA, to funding mechanisms such as the Technology Modernization Fund, and to interagency shared services provided by bodies including GSA and NIST. The principle is identical at both levels: any commitment in the strategy that has no funding path and no acquisition path is a statement of intent, and stakeholders learn quickly to read those sections as decoration. Mark them honestly as unfunded rather than letting them sit next to funded commitments in the same list.

Drafting, challenge and publication

A signable strategy is produced on a schedule with named participants, not written by one person over a long weekend. A workable cadence runs four to six weeks across six to eight working sessions. The source's session list has eight: context and maturity; vision and objectives; use-case portfolio; capability roadmap; governance and workforce; stakeholder engagement and risk; draft integration and review; and leadership approval. Each session produces text rather than notes, which is the discipline that separates a drafting process from a series of meetings about drafting.

Peer review is where a draft becomes a document an agency head can sign. The protocol uses three instruments: a redline, a challenge-question set, and a resolution log recording how each challenge was answered. Route the draft through compliance counsel, the CIO, the Senior Agency Official for Privacy, Equal Employment Opportunity, procurement and mission-program leadership, and expect the document to change. A strategy drafted with the Office of General Counsel, the privacy official, the CISO, the Chief Data Officer, the Chief Acquisition Officer and the Chief Human Capital Officer in the room is slower to produce and considerably harder to dismantle in a hearing.

Publication is the step most often treated as an afterthought. Publish consistently with the public use-case inventory, with proactive disclosure expectations under FOIA, and with Privacy Act system-of-records-notice timelines, and coordinate with public affairs before anything goes out. The signature matters too: the document should be signed by an official with the authority to bind the agency, and the signature date should appear in the executive summary, because a strategy nobody signed is a draft regardless of how finished it looks.

The strategy as a living document

Wilhelmina scheduled two strategy reviews per year, at month six and month twelve. The month-six review asked whether initiatives were on track, whether assumptions had changed, and whether priorities needed to shift. The month-twelve review asked what the outcomes were, what had been learned, and what goes into next year's strategy. Each review produced a brief update document rather than a rewrite: an explicit accounting of what changed and why. Federal practice adds a shorter beat, a quarterly pulse review against the metrics section, with a full annual revision.

Trigger events force an interim update regardless of the calendar. A major incident, a change of administration and a significant budget change each invalidate assumptions the strategy rests on, and a document that survives such an event unchanged is usually a document nobody is using. This cadence matters because government AI strategy has a half-life: technology changes, budget situations change, staff turn over, and a strategy that was right in January may need adjustment by September. The review cadence does not create instability. It creates structured adaptation, and the alternative, treating the strategy as fixed until something goes badly wrong, is what produces the graveyard of outdated frameworks Wilhelmina found when she arrived.

Anti-Patterns

  • Producing a framework and filing it as a strategy. Frameworks are safer to present because they commit nobody to anything, and an executive team can approve one without accepting a consequence. The tell is that no sentence in the document names a person or a date. Before circulating a draft, highlight every named owner and every date; if the highlighting is sparse, you have a framework.
  • Writing the maturity section aspirationally. The maturity baseline is where honesty is most expensive, because an accurate account of poor data quality kills initiatives people have already announced. So it gets softened, and the initiatives proceed on inputs that cannot support them. Write the maturity section first, have someone outside the program verify each claim, and treat a disagreement about maturity as a finding rather than a tone problem.
  • Committing without a funding or acquisition path. An initiative appears in the strategy with a target date and no budget line and no contract vehicle, sitting in the same list as fully resourced work. Readers cannot tell the difference and stop trusting the list. Mark unfunded commitments explicitly as unfunded, and take the resulting conversation with the budget office early.
  • Delegating the fairness protocol to the vendor. The strategy says fairness will be tested and leaves which groups, which metrics and what threshold to be determined during implementation, which in practice means determined by whoever builds the system. Specify the groups, the metrics and the threshold that triggers a hold in the strategy itself, where they are reviewable before anyone has an interest in the answer.
  • Treating human review as the safeguard and stopping there. Naming a human reviewer satisfies a minimum practice on paper and does very little on its own, because a reviewer processing volume under a throughput target reliably becomes an approver. Say what the reviewer is expected to check, how much time that takes, how often reviewers disagree with the system, and what happens when that disagreement rate falls to zero.
  • Skipping the termination plan. Every other minimum practice describes how the agency will detect a problem; the termination plan is the only one describing what it will then do. It is uncomfortable to write because it concedes that the system might have to be switched off. Write it anyway, name who can order it, and state what happens to pending cases when it happens.
  • Publishing without the signature. A strategy circulated in draft indefinitely, never signed by an official with authority to bind the agency, has all the appearance of a commitment and none of the force. Set the signature as the last working session's deliverable and treat the unsigned document as unfinished work rather than as a soft launch.
  • Letting the strategy go stale between reviews. The document is approved, the reviews are scheduled, and then a change of administration or a major incident invalidates its assumptions six weeks later while everyone waits for the month-six meeting. Define trigger events in the document itself, name who calls the interim review, and make calling one uncontroversial.

Practice Prompts

  • Answer the six questions in one sitting. Write a single page answering all six for your own agency, without consulting anyone. The questions you cannot answer are your agenda for the drafting sessions, and the ones you answer in generalities are usually the ones where the organization has not actually decided.
  • Write the maturity section honestly and have it challenged. Draft the current-state baseline across data, infrastructure, workforce, governance and partnerships. Then give it to someone who runs one of those areas and ask them to mark every claim they consider optimistic. Rewrite from their markup rather than arguing with it.
  • Sequence three initiatives and defend the order. Choose three initiatives that trace to a measurable mission problem, sequence them, and write the rationale for the sequence in one paragraph. Then ask a colleague to propose a different order. If you cannot say why yours is better, the sequence was assumed rather than decided.
  • Map one commitment through to a control. Take a single sentence from your draft, map it to a NIST AI RMF function, to the GAO accountability area an auditor would use, and to the artifact that would evidence it. If the chain breaks at the artifact, the commitment is not yet auditable.
  • Run the peer review for real. Circulate a section to compliance counsel, the CIO, the privacy official, procurement and a mission-program lead, using a redline, a challenge-question set and a resolution log. Record every challenge and its resolution. The log is a deliverable in its own right and the thing an Inspector General will value most.
  • Write the termination plan. For your highest-risk use case, write the plan for switching it off: what triggers it, who can order it, what happens to pending cases, what the fallback process is, and how affected people are told. One page is enough. Almost nobody has this page.

Reflection

  • Which of the six questions can your agency answer today with a specific, evaluable sentence rather than a general commitment?
  • If an Inspector General asked tomorrow for the document authorizing your highest-risk AI deployment, what would you hand over?
  • Which commitments in your current plan have no funding path and no acquisition path, and who else knows that?
  • Who has the authority to sign your strategy, and have they seen the version you would want them to sign?
  • What trigger events would force an interim review of your strategy, and has one of them already happened?
  • Which section would you least want a skeptical committee staffer to read closely, and what does that reaction tell you about the draft?

Glossary

  • Strategy. A set of decisions naming what you will do, what you will not do, who is responsible, what success looks like, and when. Distinct from a framework, which organizes thinking without committing to action.
  • Maturity baseline. An honest current-state assessment across data, infrastructure, workforce, governance and partnerships, used to determine what is achievable in the planning horizon.
  • Use-case portfolio. The prioritized, sequenced set of AI use cases in the strategy, each with a risk tier, an accountable official, a go-live target and a success metric.
  • Senior Accountable Official. The named individual responsible for a specific use case, as distinct from an office or a division.
  • Rights-impacting and safety-impacting AI. Policy risk designations that determine which minimum practices apply to a given use case.
  • Minimum practices. The required controls for higher-risk AI use cases, including pre-deployment testing, ongoing monitoring, human review, opt-out mechanisms and a termination plan.
  • Termination plan. The documented plan for withdrawing an AI system from use when it fails a required practice, including who can order it and what happens to work in progress.
  • Resolution log. The record produced during peer review capturing each challenge to the draft and how it was answered.
  • Trigger event. A defined occurrence, such as a major incident, an administration change or a significant budget change, that forces an interim review of the strategy.

Closing

The capstone deliverable is a document, and the temptation with any capstone is to produce the artifact and stop. Resist it. A strategy earns its keep in the moments nobody plans for: the vendor conversation where you can say this is not in our portfolio, the hearing where you can show what you committed to and when, the incident where you can point to a monitoring program and an escalation path instead of reconstructing intent from email. Those moments are why the document is written to a legal-grade standard rather than a presentational one, and they are also why the signature and the date matter more than the prose.

Wilhelmina's eleven pages were not better written than the three frameworks she inherited. They were more useful because they named people, dates, budgets and limits, and because someone with authority signed them. Whatever length your context requires, that is the test to apply to your own draft: hand it to somebody who was not in the room, and ask them to tell you what will happen, who owns it, what will not be attempted, and how anyone will know whether it worked. If they can answer, you have a strategy. If they hand you back a description of your thinking, you have another framework, and the filing cabinet already has three.

Key Takeaways

  • A strategy is a set of decisions, not a framework. It names what you will do, what you will not do, who is responsible, what success looks like and when. Frameworks help you think; strategies commit you to action and to being evaluated.
  • The six questions are the minimum. Mission problem, current maturity, prioritized sequence, named leads with budgets, governance covering oversight and fairness and incident response, and pre-specified metrics with measurement methods. A draft that cannot answer all six is not finished.
  • The federal template is longer for a reason. Eleven sections carry the policy mapping, the risk register and the accountability structure that make a strategy auditable. Draft the maturity and workforce sections first, because they are the ones reviewers reject and programs shortchange.
  • Map commitments to policy and to controls. Enterprise requirements, minimum practices for rights-impacting and safety-impacting use, the NIST AI RMF functions and the GAO accountability areas let an auditor trace a policy statement to a control to an artifact. Verify which instruments are current before citing them.
  • Write the termination plan. Every other practice tells you how a problem is detected. The termination plan is the only one that says what the agency does next, who can order it, and what happens to pending work.
  • Maturity assessment prevents overreach. An honest account of data quality, staff capability and governance tells you what is achievable in twelve months. Committing to initiatives your current state cannot support produces failure, not learning.
  • Named leads with specific budgets create real accountability. A named director delivering a stated outcome by a stated date with a stated budget can be evaluated in any month. "The IT division will support AI initiatives" cannot be evaluated at all.
  • Connect to budget and procurement before finalizing. Share with the acquisition office, identify existing vehicles, verify timeline assumptions, and put the initiatives into the budget request. Mark anything unfunded as unfunded rather than hiding it in the same list.
  • Sign it, publish it, and review it on a cadence. An unsigned document does not bind an agency. Quarterly pulse reviews, an annual revision and defined trigger events keep it current, and a strategy that survives a change of administration unchanged is usually one nobody is using.

Frequently Asked Questions

How long should our strategy actually be? Long enough to answer the six questions specifically and to carry whatever policy mapping your jurisdiction requires, and no longer. A state department produced eleven usable pages; the federal template's per-section targets sum to between thirteen and twenty. Neither number is a requirement. The failure mode at both ends is real: too short and the commitments are too vague to evaluate, too long and nobody outside the drafting team ever reads past the executive summary.

We have no AI in production yet. Is it too early for a strategy? No, and the pre-deployment strategy is the easier one to write honestly, because nothing has been announced that the maturity section might contradict. Your maturity baseline will be short, your use-case portfolio will be small, and your capability roadmap will carry most of the weight. That is a legitimate strategy. What is not legitimate is deploying first and writing the authorizing document afterwards, which is precisely the sequence the incidents in this lesson describe.

Who should actually own the drafting? One person owns the pen and the deadline; the content comes from the review group. Splitting the pen across offices produces a document with several voices, several definitions of the same term, and no one accountable for the whole. The owner should be senior enough to convene the CIO, counsel, privacy, procurement and human capital, and available enough to write between sessions.

What if leadership will not commit to specific targets? Find out which kind of reluctance it is. Sometimes the honest answer is that the baseline is unknown, in which case the commitment is to establish the baseline by a date, which is itself specific and evaluable. Sometimes the reluctance is about accountability, in which case a phased commitment with an explicit decision point at the end of phase one is usually acceptable where an eighteen-month target is not. What does not work is publishing a directional aspiration and calling it an objective.

How does this capstone relate to the other capstones in the curriculum? This one produces the authorizing artifact for the whole portfolio: what the agency will do, under whose authority, against which policy obligations. Scaling Capstone: From Your Pilot to Enterprise takes a single proven pilot through the transition to enterprise operation, and Capstone Lab: End-to-End AI Integration Project builds and integrates a working system end to end. They are complementary rather than overlapping, and the sequence that usually works is strategy first, because the other two need something to be accountable to.