An AI strategy is a written plan that names the workflows AI will change, the business outcomes expected, the investment required and the governance that applies. The executive team owns it, and it ends with a 90-day roadmap to production.
Many strategies stop at a slide deck. The ones that change operations share a structure: five questions answered in order, seven known pitfalls avoided, and a short plan with named owners. This article covers all three.
What should an AI strategy include?
An AI strategy should include target workflows, an operating model, measured outcomes, governance and a first constraint to remove. A useful test: every section points to a decision someone has to make.
| Section | What it states | Who signs off |
|---|---|---|
| Target workflows | Where AI will be used first, and why there | Executive sponsor |
| Operating model | How work, roles and handoffs look in 18 months | COO or equivalent |
| Outcomes and baselines | Current metrics, target change, measurement date | CFO or finance lead |
| Governance | Owner, data allowed, decision authority, audit trail, shutdown procedure | Privacy officer, legal |
| Binding constraint | The one blocker to remove first | Executive team |
| Roadmap | 30/60/90-day plan, then waves | Programme lead |
What framework should you use to build an AI strategy?
Use a five-question framework and answer the questions in order. Skipping one tends to produce tools attached to old processes.
- Where is judgment-heavy work the constraint on growth? Look for workflows where adding people does not add proportional output: a claims queue with flat throughput, a support backlog that grows with ticket volume, contracts waiting weeks for review. AI returns concentrate there.
- What does the operating model look like in 18 months? Describe which steps become automated, which are supervised and which stay human. Describe how roles change and which new roles appear, such as exception handling and AI operations.
- What measurable outcomes will this produce? State the current baseline, the target change, the time horizon and the measurement method. Without a baseline, no result can be checked.
- What governance applies, and who is accountable? For each system: the accountable owner, the data classes it may touch, its decision authority (automated, advisory or prohibited), the audit trail, the incident plan and a shutdown procedure.
- What is the binding constraint, and what fixes it first? It may be data quality, undocumented processes, leadership commitment or an open regulatory question. The first 90 days go to removing it.
An outside AI readiness assessment is one way to answer question 5 quickly when internal views differ.
What does a 30/60/90-day AI strategy roadmap look like?
A 30/60/90-day roadmap moves from audit to design to a first production system with measured impact. Each block ends with one deliverable.
| Period | Work | Deliverable |
|---|---|---|
| Days 1–30 | Interviews with 8–12 leaders; data audit on the top 3 workflows; baseline measurement on the top 1–2 | One document naming the first workflow, its baseline KPIs and the binding constraint |
| Days 31–60 | Operating model for the chosen workflow; governance scaffolding; architecture and build plan | A specification an integrator could build from |
| Days 61–90 | Build; pilot with a small user group and full output review; wider rollout with monitoring | A system in production, measured against the day-30 baseline |
Days 1–30: audit and target selection. Interviews rank the workflows where judgment-heavy work limits growth. The data audit scores quality, integration readiness and privacy obligations for each candidate. Baseline KPIs such as cycle time, error rate and cost per transaction are captured before anything is built.
Days 31–60: operating model and first wave. Workflow diagrams mark automated, supervised and human-only steps. Governance covers data classes, decision authority, audit logs, incident response and shutdown. The build plan names the model provider, orchestration, monitoring and integrations.
Days 61–90: build, pilot, measure. Existing platforms come first; custom development is reserved for real differentiators. The pilot runs with daily feedback to find failure modes the specification missed. Rollout follows, measured against the day-30 baseline.
This roadmap is the core of Remolda's two-week AI Opportunity Audit and roadmap, which ranks 10 or more use cases and ends with a 12-month plan.
Why do AI strategies fail?
AI strategies usually stall for one of seven predictable reasons. Each has a countermeasure that costs little when planned early.
| Pitfall | What happens | Countermeasure |
|---|---|---|
| Strategy as a document | Board sign-off, then no change in how work is done | Every section tied to a 30/60/90-day commitment with a named owner |
| Tool-first thinking | A platform is chosen and the workflow bends to it | Write the operating model before naming any tool |
| Underfunded people side | Staff push back and there is no plan | A change plan with communications, training waves and incentives |
| Optimistic timelines | Work runs over and credibility erodes | Waves that each deliver measurable value within 90 days |
| No baseline | Nobody can prove the result six months later | Measure KPIs in the first 30 days |
| Privacy review last | The system is pulled after launch | Privacy, security and legal review scheduled in the first 30 days |
| Accidental lock-in | Switching costs grow and pricing leverage disappears | Abstractions that allow model swaps; a second provider for critical workflows |
On lock-in: as of September 2026, Anthropic, OpenAI and Google each offer several model tiers at different prices, and prices change often. A strategy that can swap models keeps that choice open. A structured vendor selection step helps before multi-year licences are signed.
Who should own the AI strategy?
The executive team owns the AI strategy, with one named executive sponsor and a programme lead. Responsibility is shared across functions:
- Executive sponsor: priorities, budget, trade-offs between teams.
- Operations: workflow redesign and adoption.
- IT: architecture, security, integration.
- HR: training, role changes, and hiring rules such as Ontario's AI disclosure in job postings.
- Privacy and legal: PIPEDA, Quebec Law 25 and sector rules.
A culture that can use AI well depends on all of these functions. Leaving it to IT alone is one of the fastest ways to stall adoption.
Which Canadian rules should an AI strategy account for in 2026?
A Canadian AI strategy in 2026 plans around existing privacy law, with no federal AI act in force. Four points belong in the governance section:
- PIPEDA applies to personal information in commercial activity. Bill C-27, which contained AIDA, died when Parliament was prorogued in January 2025.
- Bill C-36, the proposed Protecting Privacy and Consumer Data Act, had first reading on June 15, 2026 and would add transparency duties for automated decision-making.
- Quebec Law 25 requires a privacy impact assessment for new information systems that handle personal information (s. 3.3) and notice of decisions based exclusively on automated processing (s. 12.1).
- Ontario requires employers with 25 or more employees to disclose AI use for screening, assessing or selecting applicants in publicly advertised job postings, since January 1, 2026.
Federal institutions also follow the Treasury Board Directive on Automated Decision-Making.
If you have less than 90 days
With less time, compress the plan. Pick the workflow the COO already knows is the bottleneck. Use a hosted model API from Anthropic, OpenAI or Google with simple orchestration. Apply your existing data-handling policy and publish a short AI use policy for staff in the first week. The result is less defensible and can ship in about 30 days.
To start with a clear position, Remolda's one-week AI Readiness Review costs $490 CAD + HST, and the two-week AI Opportunity Audit with a 12-month roadmap costs $2,900 CAD + HST. Both are listed on the pricing page.