Insights: AI Strategy & Governance

Your AI strategy questions, answered

Practical answers on building an AI strategy, evaluating your AI governance and readiness, and closing the gaps most organisations miss, grounded in the MASTER-AI™ framework and Alchemy's own market research.

$9–11B Converging analyst estimate for the 2026 agentic AI market
40% Enterprise apps forecast to run task-specific AI agents by end of 2026
86% IT leaders concerned agents add complexity without proper integration
Aug 2026 EU AI Act transparency and AI literacy rules now in force
Getting started
How do I build an AI strategy for my company?

Good AI strategy starts with where AI actually sits in your business, not with which tool to buy next. A practical sequence has four steps.

First, an inventory. Most organisations do not have a complete list of where AI is already in use, particularly where it arrived inside a third-party platform rather than being deployed deliberately. Second, classification. Separate simple productivity use (drafting, summarising) from agentic use, where AI is executing multi-step tasks autonomously across systems, since the two carry very different risk and governance requirements.

Third, architecture. Decide deliberately how your AI governance layer, the identity controls, policy engine, and human oversight that sit between your business systems and your AI tools, will work, rather than letting whichever vendor you buy from default it for you. Fourth, a roadmap tied to business value rather than to a list of tools, so each investment can be traced through to an outcome the board actually cares about.

Fundamentals
Agentic AI vs generative AI: why does the difference matter for my strategy?

Generative AI responds. You prompt it, it answers, and it only acts for the duration of that conversation. Agentic AI acts. It perceives its environment, sets sub-goals, executes multi-step tasks across multiple systems, handles exceptions, and loops back to assess its own output, without a human holding its hand at each step.

"Generative AI lives inside a conversation. Agentic AI lives inside your business processes."

Catalyst, The Enterprise AI Operating System Architecture

That distinction is not semantic, and it changes the decision you are actually making. Generative AI is largely a productivity-tool decision. Agentic AI is a governance decision: what is this agent allowed to touch, who is accountable when it gets something wrong, and how do you prove that after the fact. Most organisations that have "done the generative AI stuff" and are now being asked what's next are really being asked whether they are ready to make that second, harder kind of decision.

Who to ask
Who can help me with AI governance and readiness?

Three routes exist, and they are not equivalent. Your internal CIO or IT leadership can own it if they have the capacity and a genuinely cross-platform mandate. The platform vendors themselves each offer some governance tooling, but it is generally strongest where it protects their own stack.

3 Platform giants each staking a governance claim
0 Vendors covering all five control capabilities well
1 Independent, vendor-neutral view across your stack

Workday, ServiceNow, and Salesforce have each built credible controls, but each has a structural blind spot outside its own platform, and no single vendor currently covers model lifecycle, identity, policy, monitoring, and compliance well across a multi-vendor estate. The third route is an independent, vendor-neutral adviser, such as a fractional Chief AI Officer, whose recommendations are not tied to any platform's commercial interest. For most mid-market organisations building genuine cross-platform governance rather than single-tool compliance, that independence is the deciding factor.

Readiness
How do I know if my technology and AI setup is fit for purpose?

Start with a fast, honest diagnostic before commissioning anything larger. At a simple level, that could be a quick AI Readiness Check: a ten-minute self-assessment across strategy, culture, data, use cases, and momentum that surfaces the obvious gaps quickly.

The next step is a fixed-price Technology MOT. This technology discovery exercise culminates in a board report, covering the domains of Strategic Alignment, Client-Facing Technology, Enterprise Technology, AI Readiness, Security and Compliance, and Team and Capability. A key deliverable is an as-is and to-be assessment of your current technology stack, with recommendations and a roadmap to improve your AI architecture and governance. See the next question below.

Architecture
What is a good technical architecture for AI governance?

A good Enterprise AI Operating System Architecture has three layers. Your existing business systems (ERP, CRM, HR, finance) sit at the bottom as your systems of record, nothing moves here. Your AI services (models, tools, data pipelines) sit at the top. The layer that actually matters, and where most organisations currently have the least thinking and the most accumulating risk, sits in the middle: the AI governance layer, covering identity and access, policy enforcement, monitoring, compliance, and the human-in-the-loop controls that keep autonomous AI inside defined boundaries.

That middle layer needs five capabilities, run in sequence: define (model inventory, risk classification, accountability), access (what a person or an agent is actually permitted to do), control (real-time policy enforcement), observe (monitoring and drift detection), and prove (the audit trail). An architecture that can demonstrate that chain end to end is genuine governance. One that can only show parts of it is process theatre with a dashboard attached.

Framework
What does good AI governance actually look like in practice?

In the MASTER-AI™ framework, genuine AI governance follows a natural sequence: define, access, control, observe, prove. Define covers model inventory, risk classification, and accountability, the rules and responsibilities. Access covers identity and access management, including what an autonomous agent is actually permitted to do.

Control is the runtime brain: the policy enforcement, human-in-the-loop triggers, and risk-based decisions that happen in real time. Observe is monitoring: drift detection, data lineage, and user interaction tracking. Prove is compliance: the audit trail, the evidence, and the regulatory reporting that demonstrate the first four stages actually happened.

An organisation that can demonstrate that sequence end to end, with evidence at every stage, has genuine governance. An organisation that can only demonstrate parts of it has what I call process theatre.

Sequencing
Where should I actually start: policy, or planning?

Planning, not policy, and this is the single most common sequencing mistake. Most organisations jump straight to buying guardrails and monitoring tools before they have established governance and planning: a model inventory, a risk classification, and clear accountability structures.

"This is backwards. You cannot enforce policies you haven't defined, against risks you haven't classified, for systems you haven't documented."

Catalyst, The Enterprise AI Operating System Architecture

The unglamorous first step, working out what AI you actually have and who owns it, is also the step that makes every subsequent pound of governance spend effective rather than decorative.

Biggest risk
What's the single biggest gap in most organisations' AI governance right now?

The human element. Across every organisation this comes up in, the domain covering AI literacy, escalation pathways, and the cultural conditions that let people challenge an AI system's output is consistently the most underdeveloped. Vendors provide almost no tooling for it, because it is an organisational design problem, not a software procurement problem, and boards rarely ask about it because it does not show up on a dashboard.

It is also where regulation is explicit: the EU AI Act mandates a baseline level of AI literacy among staff, and most organisations are nowhere near meeting that requirement. Given that an estimated quarter of 2026 enterprise security breaches have been traced back to AI agent misconfiguration or misuse, this is not a soft afterthought. It is where the risk actually sits.

This page draws on Alchemy's Catalyst newsletter analysis, "The Enterprise AI Operating System Architecture" (April 2026), and the MASTER-AI™ governance framework. Market figures are drawn from third-party analyst estimates current as of mid-2026 and will move as the market matures.