Business Analysis Canada Blog

From Pilot to Production: How to Create an Enterprise AI Strategy

by
Sep 18, 2026
.
From Pilot to Production: How to Create an Enterprise AI Strategy
Book a Free Call

Most enterprise AI strategies are a list of pilots with a governance appendix. The pilots work and nothing reaches production, because the strategy never said what production means: which decisions AI is allowed to make, on what data, with what authority, reviewed by whom. A strategy that gets pilots into production is short and has four parts: an inventory of the decisions AI would change, a data readiness statement for each, an authority boundary for each, and a sequence from most reversible to least. Gartner's survey of data management leaders found that 63% of organizations either do not have or are not sure they have the right data management practices for AI, and Gartner predicts that through 2026 organizations will abandon 60% of AI projects not supported by AI-ready data. This guide covers the four parts, how to build the inventory, how to sequence it, and what the production bar is.

Introduction

The AI strategy deck has eleven pilots on it. Three are live in a sandbox, two have a vendor attached, six are ideas with a sponsor. There is a page on responsible AI principles and a page on the centre of excellence. There is no page that says which of the eleven will be allowed to make a decision in production, or what has to be true first.

Eighteen months later the three sandbox pilots are still in the sandbox, the vendor pilots have been renewed as pilots, and the board is asking where the value is. The answer is that the strategy planned the experiments and never planned the exits.

What is an enterprise AI strategy, and why do pilots not reach production?

An enterprise AI strategy is the set of decisions an organization makes about which of its own decisions AI will be allowed to make or inform, in what order, under what authority, and with what data, so that a pilot has a defined path to production before it starts.

That definition puts the emphasis in an unusual place. Most strategies are organized around capabilities: what AI can do, which vendors offer it, which teams will learn it. A strategy organized around the organization's decisions is shorter, harder to write, and the only kind that tells a pilot when it is finished.

Pilots stall for two reasons, and both are decided before the pilot begins. The first is data. Gartner's survey of 248 data management leaders found that 63% of organizations either do not have or are unsure whether they have the right data management practices for AI, and Gartner predicts that through 2026, organizations will abandon 60% of AI projects that are not supported by AI-ready data.<sup>[1]</sup> A pilot built on a cleaned extract performs well on the extract. Production runs on the data as it is.

The second is authority. A pilot recommends. Production acts, or informs an action, and the question of who is accountable for that action was never asked because the pilot did not need an answer. The agentic AI post on this site covers that boundary in detail. The strategy is where it gets decided for every candidate at once, rather than discovered one production incident at a time.

Key Takeaway: Pilots stall on data and authority, both of which are strategy decisions the pilot cannot make for itself.

Holding a deck of pilots with no exit criteria? Our AI Implementation practice writes the production path before the next pilot starts. Book a free consultation.

What does an enterprise AI strategy contain?

Four parts. Each one is a document with a test for whether it is done, and together they fit in fewer pages than the current deck.

Part What it states Test for done
Decision inventory Every decision AI would change: who makes it now, on what, how often, what a wrong one costs Each row names a current decision maker and a cost of error in a number
Data readiness per decision The data that decision runs on: where it lives, who owns it, how current it is, what is wrong with it A named owner has signed a statement of what the data is and is not fit for
Authority boundary per decision Whether AI recommends, decides within a threshold, or decides outright; who reviews; how it is reversed The accountable person for a wrong AI action is named and has agreed
Sequence The order, from most reversible and most data-ready to least, with what each one unblocks The first three are in order, dated, and the second depends on nothing the first has not proved

The second row is where the strategy most often becomes honest. Asking a data owner to sign a statement of fitness produces a very different answer from asking whether the data is available. Available means it exists. Fit means the owner will stand behind a decision made on it, and most owners, asked that way, add conditions.

The third row is where the strategy most often becomes short. Once each candidate has to name the person accountable for a wrong AI action, several candidates lose their sponsor, because the sponsor wanted the capability and not the accountability. That is the strategy working.

Most organizations skip the inventory and go straight to use cases, which is why the deck has eleven pilots and no way to compare them. ID Business Analysis Canada builds the four parts as an AI Readiness Assessment, with a business analyst producing the decision inventory from interviews with the people who make each decision today, the data fitness statement signed by each data owner, and the authority boundary agreed by each accountable executive, so that the sequence at the end is derived rather than voted on.

Key Takeaway: Four parts, four tests. The inventory makes candidates comparable; the fitness and authority signatures make the list shorter and truer.

How do you build the decision inventory?

By interviewing the people who make the decisions, not the people who want to automate them.

One row of an AI decision inventory showing the five fields recorded for each decision a strategy considers handing to AI.

Each row of the inventory records one decision, and the fields are chosen so that a reader can compare rows without knowing anything about AI:

  • The decision, in one sentence. "Approve or decline a customer credit limit increase under $25,000." Not "credit risk."
  • Who makes it today, and how many times a week. Volume is what makes a decision worth changing. A decision made twice a year is rarely a candidate whatever the technology.
  • What information it is made on now. The systems, the reports, the phone calls, and the spreadsheet the person keeps on the side.
  • What a wrong decision costs. In a number. Direct loss, rework, a customer, a regulator's attention.
  • Whether it can be reversed. A recommendation ignored costs nothing. A payment released cannot be unreleased.

Two things happen when the inventory is built this way. First, the candidate list changes: several decisions nobody had proposed turn out to be high-volume, low-cost-of-error, and made on data that already exists, which makes them the obvious first moves. Second, several proposed pilots turn out to be aimed at decisions made rarely, on data nobody owns, with an unreversible outcome, which makes them the obvious last moves or no moves at all.

Finance is a useful place to start because it has more explicit decisions per week than most functions and the cost of error is already measured. Invoice matching exceptions, credit holds, expense approvals under a threshold, journal entry classification: each is a decision with a current owner, a volume, a cost, and a reversibility that can be stated in a sentence.

Key Takeaway: One decision per row, described so that a reader who knows nothing about AI can compare the rows. Volume, cost of error, and reversibility do the ranking.

How do you sequence from pilot to production?

By reversibility first and data readiness second, and never by how impressive the demo was.

Two-by-two grid sequencing AI pilots by reversibility and data readiness, with reversible-and-ready decisions going first.

Plot each inventory row on two axes. On one, how reversible a wrong AI action is: a recommendation a person can ignore at one end, an irreversible external action at the other. On the other, how ready the data is: an owner-signed fitness statement at one end, "we think it is in the data lake" at the other.

Four quadrants fall out:

  • Reversible and ready. Go first. These are the pilots that reach production, because a wrong action is cheap and the data will not surprise anyone. They prove the operating model: monitoring, review, rollback, and the audit trail, on a case where failure costs an afternoon.
  • Reversible, not ready. Go second, after the data work. The pilot can start on an extract, but the strategy says it does not reach production until the owner signs the fitness statement, and it says who does that work and when.
  • Irreversible and ready. Go third, with a mandatory human approval step in the authority boundary until the first two quadrants have proved the operating model. Do not let the readiness of the data argue you past the reversibility of the action.
  • Irreversible, not ready. Not yet, and possibly never. These are usually the pilots with the most enthusiastic sponsor and the most vendor attention. The strategy's job is to say so in writing.

An AI transformation strategy for enterprises that follows this order looks unambitious for the first two quarters and then accelerates, because the third and fourth quadrant candidates inherit an operating model that already works. The strategy that starts in the fourth quadrant looks bold and produces the eighteen-month sandbox.

Key Takeaway: Reversible and ready first. The first two quadrants build the operating model the last two need.

What does production mean?

A defined state, written into the strategy, that every pilot either reaches or is retired.

Five conditions, and a pilot is in production when all five are true:

  • A named accountable owner for the decision as AI now makes or informs it, who has signed the authority boundary.
  • Live data, not an extract, with the fitness statement signed and a monitoring rule that detects when the data drifts outside it.
  • Monitoring that reports the rate of AI actions, exceptions, overrides, and reversals, reviewed by the owner on a fixed cadence.
  • A rollback path that has been exercised at least once, not described.
  • A benefits measure tied to the decision inventory row: the cost of error before and after, or the volume handled without a person, measured against the baseline the inventory recorded.

A pilot that cannot meet one of the five is not "almost in production." It is a pilot, and the strategy should say what changes or when it stops. Most sandboxes persist because the exit was never defined and closing an experiment feels like admitting it failed. Defining the exit up front makes retirement a scheduled outcome instead of a confession.

Key Takeaway: Five conditions define production. A pilot meets all five, or the strategy says when it stops.

Frequently Asked Questions

What is the difference between an AI strategy and an AI roadmap?The strategy makes the decisions: which of the organization's decisions AI will change, under what authority, on what data, in what order. The roadmap is the schedule that follows from those decisions. Most organizations have a roadmap of pilots and no strategy, because the roadmap was assembled from proposals and the decisions in the four parts above were never made. A roadmap without the strategy is a list of experiments with dates.

How do we start creating an enterprise AI strategy when we already have pilots running?Build the decision inventory first, then place every running pilot on it. Each pilot maps to a decision row or it does not, and the ones that do not map are the ones to question. Then complete the data fitness and authority boundary for the mapped rows and see which quadrant each pilot lands in. ID Business Analysis Canada runs this as an AI Readiness Assessment on an existing portfolio, with a business analyst producing the inventory, the fitness statements, the authority boundaries, and a sequenced list that shows which running pilots have a production path and which should be retired or re-scoped. The assessment usually takes four to six weeks and typically shortens the portfolio.

Do we need an AI centre of excellence?Not to write the strategy, and not before the first production decision exists. A centre of excellence is useful once there is an operating model to standardize: monitoring, review cadences, rollback practice, and the authority boundary template. Created before that, it becomes the owner of the sandbox and the reason the sandbox persists. Build the first production case with the team that owns the decision, then decide whether the practices are worth centralizing.

Which decisions should never be handed to AI?The ones in the irreversible-and-not-ready quadrant, and any decision where the accountable person will not sign the authority boundary. That second test matters more than any technical assessment. If no executive will put their name to being accountable for a wrong AI action on a given decision, the organization has already decided that decision is not ready, and the strategy should record it rather than work around it.

Conclusion

Eleven pilots, a principles page, and a centre of excellence is not a strategy. It is a description of activity. A strategy is a list of the organization's own decisions, each with a data owner's signature, an accountable executive's signature, and a place in a sequence that starts where being wrong is cheap.

If your AI strategy is currently a portfolio of pilots without exit criteria, ID Business Analysis Canada's AI Implementation practice produces the four-part strategy as an AI Readiness Assessment: the decision inventory, the signed fitness statements, the authority boundaries, and the sequence, with every running pilot placed on it. Book a free consultation and bring the deck.

Sources

  1. Gartner, Lack of AI-Ready Data Puts AI Projects at Risk, press release, February 26, 2025.
  2. Business Analysis Canada, Two Different Contracts: Agentic AI vs Generative AI for Enterprise Requirements, business-analysis.ca blog, September 2026.
  3. Business Analysis Canada, Before the Bot: AI Workflow Automation and the Analysis It Depends On, business-analysis.ca blog, September 2026.

You may also be interested

No items found.