← Research
Research

Our AI strategy was written eighteen months ago. What is now wrong with it?

Probably not the tools it names. Five things have changed since early 2025 that a strategy written then could not have settled, and each is a decision rather than an upgrade.

Last reviewed: 15 September 2026

An AI strategy written in early 2025 is not wrong about the tools; it is silent on five things that have changed since: agents that act, the reversals, the regulation now in force, the shadow use running ahead of the official use, and what the frontier labs now say about their own control. What to check, and what to rewrite. An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Question this page answersAll 811 questions this research covers

An AI strategy written eighteen months ago is probably not wrong about the tools. The tools have changed, but a strategy that depends on which model it names was never a strategy. What has changed is the set of decisions the document could not have been asked to make, because the questions did not exist in a usable form in early 2025. Five of them do now. Each is a decision rather than an upgrade, and none of them will be found in the vendor section.

The answer, in one line

The tools section probably is and does not matter much.

Share as a card

One: the systems now act#

In early 2025 the strategy assumed a machine that answers and a person who acts on the answer. Agents invert that. Gartner's June 2025 forecast that over 40 per cent of agentic AI projects will be cancelled by 2027 names inadequate risk controls as one of three reasons, and its estimate that about 130 of the thousands of vendors claiming agentic products are real tells you most of what is in the market is a chatbot with a new name. The 33-author preprint of September 2026 that set out five levels of self-improvement places industrial systems at levels one to four, with 'experts retain control over consequential corrections and deployment'. The strategy needs a sentence it did not have: which actions a system may take without a person, who can stop it, and how the organisation knows it stopped.

Two: the reversals have happened#

The 2024 strategy had Klarna's assistant doing the work of 700 agents as a case study. In May 2025 Klarna's chief executive said cost had been 'a too predominant evaluation factor' and that the result was lower quality, and the company recruited people again. Duolingo declared AI-first in April 2025 and its chief executive walked it back in May. IBM cut a few hundred roles and, by its own account, reinvested and grew. The cases are operator accounts without figures, and their lesson is not that automation fails. It is that a strategy which does not say where a human must remain, and what the freed money is for, finds those answers in public. The record is at what happened to the companies that cut staff for AI.

Three: the regulation is in force#

Article 4 of the EU AI Act, on AI literacy, has applied since February 2025. Article 14, on human oversight of high-risk systems, has applied since August 2026, and Annex III lists what counts as high-risk, including recruitment, promotion, termination and access to education. A strategy written before either applied may name them as coming. It cannot have decided what meaningful oversight looks like in this organisation, who exercises it, or whether they can. The test for that is at meaningful human oversight.

Four: the shadow use is ahead of the plan#

MIT NANDA's 2025 report found workers at over 90 per cent of surveyed companies using personal AI tools for work while only 40 per cent of companies had bought an official one. The figure rests on a small sample and the report says so, but the direction is not in doubt. The strategy from eighteen months ago described a programme the organisation would run. The organisation's people have been running their own, and the strategy has no view on it. The question that follows is at what to do when people work around the AI policy.

Five: the builders have asked for oversight of themselves#

In September 2026 the chief executive of Anthropic asked for outside evaluators embedded inside AI companies with employee-level access, and Microsoft published rules under which its models 'will never resist human interruption, correction, or shutdown'. Neither says where those humans come from or what happens if the ones nominally in charge have stopped practising the judgement the role needs. A strategy written in early 2025 treated the vendor as a settled quantity. The vendors are now saying, in public, that they are not. That does not change what an organisation buys. It changes how much of its own judgement it can afford to hand over.

What to check, in order#

Open the old document and look for one list: the organisation's consequential decisions, each marked inform, recommend, execute or never, with an owner against each, the work the organisation keeps unaided, and how often human reviewers disagree with the machine. If it is there, the strategy has a rules layer and the five changes above are revisions to it. If it is not, the document was a roadmap, and the roadmap was written before the rules. The rewrite does not start with the vendors. It starts with the list, which takes a day with the executive team, and the roadmap is then revised against it, which is the order it should have had the first time. The rules are at rules before tools, the argument for who writes them at AI leadership.

What nobody has measured#

There is no study of AI strategies by vintage and outcome. McKinsey's 2025 survey found the redesign of workflows and the chief executive's ownership of the rules to be the attributes most associated with reported profit, and both are things a strategy either contains or does not, but the survey does not date the strategies. The five changes above are documented events; the claim that a strategy silent on them is the worse for it is an argument from their shape.

Key sources

The rules layer is at rules before tools and the definition at AI leadership. On agents specifically, AI agents and human judgement. On when to reverse a deployment, deployment is not a ratchet. On the September 2026 frontier week, neither hype nor doom.

About this research#

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. He has run, grown, bought and advised businesses with AI in them. Findings are attributed to the studies and statements that produced them and kept separate from the interpretation. This is a living reference, reviewed and updated as significant new evidence appears.

How this research works  ·  Reviewed quarterly  ·  Found an error? Tell me and it is corrected on the page.

Explainer · SS-2026-247 · Graded against the published rubric

Cite this page

Hirji, R. (2026). Our AI strategy was written eighteen months ago. What is now wrong with it?. The SuperSkills evidence base, SS-2026-247. https://thesuperskills.com/research/what-is-wrong-with-an-ai-strategy-written-eighteen-months-ago. Last reviewed 15 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Is an AI strategy from early 2025 out of date?

The tools section probably is and does not matter much. What matters is what the strategy is silent on: agents that act rather than answer, the public reversals at companies that cut on cost, Article 14 of the EU AI Act in force since August 2026, the personal AI use that runs ahead of the official programme, and the fact that the frontier laboratories now say in public that they need outside oversight of themselves. Each of those needs a decision the old document did not make.

What should we check first in an old AI strategy?

Whether it contains the allocation: which decisions the machine may inform, recommend or execute, which it may never own, who owns each, and what the organisation keeps practising unaided. If that list is absent, the strategy was a roadmap, and the rewrite starts there rather than with the vendors.

Do we need to rewrite the whole strategy?

Rarely. The rules layer is usually missing rather than wrong, and it can be written in a day with the executive team. The roadmap then gets revised against it, which is the order it should have had originally.

In this hub

Definitions

The terms this field uses, defined against their primary sources.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Five public changes since it was written. Reading the old strategy against them with the executive team, and writing the rules layer it never had, is the engagement. Board advisory.

This argument is one a board usually meets for the first time in the room. There is the boards and leadership version, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.