Notes on Strategy, Governance and the AI Rush

Reading notes

This note emerged from my reading of Robert M. Grant’s Contemporary Strategy Analysis, Peter M. Ginter, W. Jack Duncan and Linda E. Swayne’s Strategic Management of Health Care Organisations, Sunil Gupta’s Driving Digital Strategy, and Michael Porter’s What Is Strategy?; David J. Collis and Michael G. Rukstad’s Can You Say What Your Strategy Is?; Brian McCullough’s writing on the dot-com bubble; and Eli Ofek and Matthew Richardson’s DotCom Mania: The Rise and Fall of Internet Stock Prices.


This week I began studying competitive strategy. I expected to spend most of my time thinking about markets, positioning and how organisations create advantage. Instead, I found myself returning repeatedly to AI governance. This was not entirely surprising to me, as governance does not happen outside the organisation it is supposed to govern. The decisions made about AI are shaped by what an organisation believes it is trying to achieve, what it considers valuable and what it is prepared to sacrifice along the way. Still, I had not previously thought enough about strategy as the place where many governance decisions first become visible.

Michael Porter’s What Is Strategy? distinguishes strategy from operational effectiveness. An organisation can become faster, cheaper or more productive without making a meaningful strategic choice. Strategy requires deciding where to act, how to create value and, perhaps most importantly, what not to do. It made me think about the way organisations currently speak about AI adoption. Almost any investment in automation, generative AI or data infrastructure can be described as a strategic transformation, yet introducing a new technical capability can simply be an activity.

The unresolved question is what the technology is for, meaning what a particular system can do. In this sense, I'm asking why the organisation has decided that this capability belongs within its work at all? What problem has been identified? What has made AI appear to be the appropriate response? What becomes possible through its adoption, and what might become more difficult to see? David Collis and Michael Rukstad offer a deceptively simple way of thinking about this. In "Can You Say What Your Strategy Is?," they argue that a strategy statement needs three elements: an objective, a scope, and an advantage. These terms are drawn from business strategy, but they also sound remarkably like the beginnings of a governance framework.

What is the organisation attempting to achieve? Where, how and for whom will the system be used? What value is expected to justify its introduction? Without clear answers, it becomes difficult to determine what responsible use would mean in practice. A system might comply with an organisation’s technical requirements while remaining disconnected from any coherent institutional purpose. It might also function exactly as intended, even as the intention itself remains largely unexamined.

This is where I began to wonder whether AI governance often enters the process too late. We tend to locate governance around the moment of procurement or deployment. We ask whether the data is protected, whether the risks have been documented, whether someone remains accountable, and whether the system meets the relevant legal or technical standards. But by the time they are being asked, several other decisions may already have hardened around them. The organisation has defined the problem, selected the range of acceptable solutions and decided that AI belongs somewhere within the answer. Those earlier choices are also governance choices, even when they are described as strategy.

Sunil Gupta’s Driving Digital Strategy further develops the question. His argument is that digital transformation cannot be treated as a separate technical project. Digital technologies alter the organisation itself, including its business model, operations and relationship with the people it serves. I’d argue the same is true of AI in that an organisation cannot introduce systems that redistribute knowledge, judgment, or decision-making while assuming that everything surrounding those systems will remain unchanged.

This presents a difficulty for governance frameworks. A policy can establish boundaries, but it cannot easily correct the incentives of the organisation applying it. An institution that consistently rewards speed over deliberation will carry that preference into its use of automated systems. An organisation that treats data primarily as something to be extracted will not necessarily abandon that logic simply because it has adopted a set of ethical principles. The technology may be new; however, institutional habits travelling through it often are not.

Richard Rumelt’s distinction between good and bad strategy stayed with me for a similar reason. A good strategy begins with a diagnosis. It identifies the difficulty, develops a guiding approach and coordinates action around it. A bad strategy often replaces this work with ambition, slogans, and lists of desirable outcomes. The language surrounding AI is full of these substitutions. Organisations want to become AI-first, future-ready or innovation-led. The phrase establishes a direction without necessarily identifying the problem that makes the direction necessary.

AI becomes the answer before the organisation has completed the diagnosis.

I find this particularly interesting because governance is then asked to manage the consequences of a decision it was never permitted to question. It can assess a proposed system, establish controls and document foreseeable harms. It may have much less authority to ask whether the system should exist within that setting in the first place.

The readings on the dot-com bubble complicated this further. Brian McCullough’s account of the period and Eli Ofek and Matthew Richardson’s analysis of internet stock prices describe a market in which expectations about technological transformation became increasingly detached from underlying value. I however would not liken this current adoption and trend of AI to a repetition of the dot-com period. The technologies and material conditions differ; even so, I recognise something familiar in the pressure to adopt first and establish purpose afterwards.

When enough institutions accept that a technology is inevitable, refusing or delaying adoption begins to appear irrational. Organisations imitate one another, not necessarily because they have reached the same strategic conclusion, but because no one wants to be seen as falling behind. At that point, governance addresses more than the risks of individual systems. It is also dealing with a collective narrative about progress, competition and institutional survival.

So then my question becomes, what meaningful governance can be done under those conditions? Perhaps AI governance needs to move further upstream, into the spaces where organisational problems are named, and technological futures are imagined, and perhaps it must be able to question the diagnosis rather than simply regulate the proposed treatment. But this also creates another tension: if governance becomes inseparable from strategy, it cannot remain a narrow compliance function. It must participate in decisions about purpose, value, resources, and the kinds of institutions organisations are trying to become.

That demands more from governance. It also gives it considerably more to interrupt. For now, the question I am carrying forward is a simple one: before asking how an organisation should govern its use of AI, should we first ask whether it can say what its AI strategy actually is?

And if it cannot, what exactly are its governance processes governing?

Next
Next

Can you govern AI you do not know you have?