Ask a leadership team to show you their AI strategy and, more often than not, they will hand you their AI policy. It has a purpose statement, a list of approved tools, a section on data protection and a paragraph on acceptable use. The board has approved it. And it does not tell a single member of staff what the organisation has decided to do.
That is not a criticism of the policy. It is doing its job. The problem is that it has been asked to do a second job it was never designed for, and nobody has noticed, because the organisation feels covered. Staff are compliant. They are not directed. The gap between those two states is where most of the value of AI is currently being lost.
What Is the Difference Between an AI Strategy and an AI Policy?
An AI policy tells people what they must not do; an AI strategy tells them what the organisation has chosen to do, in what order, and why. Everything else about the two documents follows from that.
A policy sets boundaries: which tools are permitted, what information may go into them, who is accountable, and what happens when something goes wrong. It is written mostly in the negative, and it is written for the worst day: the data breach, the complaint, the piece of work that turns out not to be the student's own. A strategy sets direction: where AI effort goes first, where it deliberately does not go yet, who leads it and how you will know it is working. It is written in the positive, it is dated, and it is written for the ordinary Tuesday, when a head of department has a real decision in front of them and needs to know which way the organisation is facing.
| AI policy | AI strategy | |
|---|---|---|
| The question it answers | What may we not do? | What have we chosen to do, and in what order? |
| Written for | The worst day | The ordinary Tuesday |
| Tense | Permanent, until the rules change | Dated, with a "first" and a "not yet" |
| Finished when | It is signed | It is used |
| Owned by | The board, maintained by whoever owns compliance | The executive team, challenged by the board |
| Can you borrow it? | Largely, yes | No |
The last row is the one I find most useful. You can borrow a policy from a template or a neighbouring school and lose very little, because a policy encodes obligations that are mostly shared. You cannot borrow a strategy, because it encodes choices, and your choices are the whole point.
Why Most Organisations Have a Policy and Call It a Strategy
Most organisations end up with a policy called a strategy because a policy is the easier document to write, the safer document to approve, and the one the outside world asks for first. Inspectors, insurers and parents all ask "what is your policy on AI?" Nobody outside the organisation asks "what have you decided to do?" A policy also requires no disagreement: everyone agrees that children's data should be protected. A strategy requires a choice, and a choice means someone's good idea goes second.
The result is an organisation that can answer the second question of the Readiness Test and not the first. As I set it out in my article on what it means to be AI ready: "The Readiness Test is three questions an organisation must be able to answer consistently, from the top to the front line, before it can call itself AI ready: What is AI for here? What may I do with it? Who decides when it goes wrong?" A policy answers the second and the third. Only a strategy answers the first.
When an AI Policy Is the Right Document
An AI policy is the right document when the question on the table is about limits: what is permitted, with which data, by whom, and what happens when it goes wrong. Safeguarding, data protection, assessment integrity and incident response belong in a policy, because those answers should not depend on who is in the room.
Regulation and guidance increasingly write the minimum of that policy for you. The Department for Education's guidance on generative AI in education, last updated on 12 August 2025, requires schools and colleges in England to make sure filtering and monitoring cover generative AI, puts safety first, and then says something leaders should read twice: schools and colleges "are free to make their own choices about the most suitable use cases for generative AI tools in their settings, as long as they comply with their wider statutory obligations". That is a policy frame with a strategy-shaped hole left deliberately open. The department has told you where the guardrails are. It has not told you which road to take, and it is not going to.
The same is true at a larger scale. The European Commission's implementation timeline for the EU AI Act has AI literacy obligations applying since 2 February 2025, transparency rules from 2 August 2026, and the high-risk rules in Annex III, which cover uses in education, now applying from 2 December 2027 after the 2026 digital omnibus postponed them. Every one of those dates is a reason to update a policy. None of them tells you what AI is for in your organisation.
When an AI Strategy Is the Right Document
An AI strategy is the right document when the question is about direction: where AI effort goes first, where it deliberately does not, who leads it, and how you will know whether it is working. The usual sign is that a governor has asked "what is our plan?" and received the policy in reply.
The evidence on direction is stark. PwC's global AI performance study, published on 13 April 2026 and drawing on 1,217 senior executives across 25 sectors, found that 74 per cent of the economic value from AI is being captured by 20 per cent of organisations. The leading fifth were twice as likely to redesign how work is done rather than add AI tools to existing work, and 1.5 times more likely to have a cross-functional governance board. The top performers are not choosing between governance and direction. They have both, and it is the direction that separates them from the majority, who are governed, compliant and going nowhere in particular.
A strategy that does that job makes five decisions explicitly: purpose, priorities, permissions, people and proof. I have written about each of them in how to create an AI strategy that people actually use. Permissions is the one to notice here, because it is where strategy and policy meet: the strategy grants permission, the policy sets the limit, and the two should describe the same list of tools.
The Mistake I See Most Often
The mistake I see most often is writing the policy first, feeling finished, and never getting to the strategy. Across the schools, trusts and districts I work with, the sequence is nearly always the same. Something happens: an incident, a headline, a question from a governor. A policy is drafted quickly from a template, approved at the next meeting and circulated. Relief. Then months of nothing, because the pressure that produced the policy has gone. Meanwhile the confident staff carry on, the cautious ones stop altogether, and both groups can truthfully say they are following the policy.
The second mistake is subtler: putting the strategy inside the policy. Many AI policies open with a page of "strategic aims" before the rules begin. In practice the organisation's choices get approved as rules, in the one document nobody revisits until the law changes, and the aims quietly fossilise. Keep them apart: the policy short and hard, the strategy short and dated.
The third is a strategy that is really a policy in a positive voice. "We will use AI responsibly, ethically and in line with our values" is not a decision; nobody could disagree with it, and nobody could act on it. It is a distinction I keep returning to in my writing for Forbes and in my books on AI in education, because the organisations that struggle with AI are rarely the ones without rules. They are the ones without a choice.
The Prevent or Direct Test
The Prevent or Direct Test is one question to ask of any AI document: does it change a decision someone would otherwise make, or only prevent one? A document that only prevents is a policy, whatever it is called. A document that changes decisions is a strategy.
Three follow-up questions settle the close cases.
Does it have a "first" and a "not yet"? Policies have no sequence, because obligations do not queue. If the document names what comes first this year and what has been deliberately deferred, it is doing strategy work.
Could another organisation adopt it unchanged? If a neighbouring school or a competitor could change the name on the cover and lose nothing, it is a policy, or it is nothing. A strategy would not survive the transfer.
Who would notice if it vanished? If only the data protection officer, the board and the compliance lead would miss it, it is a policy. If the middle leaders planning next term would miss it, it is a strategy.
When leadership teams do this exercise with me, the usual outcome is a pile of documents in the "prevent" column and nothing in the "direct" column. That is not a failure of the documents. It is guardrails around an empty road.
Which to Write First, and How They Fit Together
Write the strategy first, or at least make the decisions in it, and then write the policy as its guardrail; a policy written before any direction exists will end up guarding whatever people happen to be doing. The order feels wrong because the policy feels urgent. But a guardrail is defined by the road it runs beside. If you have not chosen the road, the policy defaults to the vaguest boundary available: the "responsible and ethical use" paragraph that protects nobody and guides nobody.
If you already have a policy, do not scrap it. Write the strategy, then revise the policy against it, starting with permissions. Give the two documents different owners and different rhythms: the board approves the policy and it changes when the rules change, so the regulatory dates above give you the diary; the executive team owns the strategy and it changes when the priorities should, at least every term, with a version number on the front. Curiosity over fear does not mean fewer rules. It means the rules serve a direction that has been chosen, rather than standing in for one.
What to Do This Term
The practical next step is to put every AI document you have on the table, run the Prevent or Direct Test on each, and be honest about which column is empty. If the "direct" column is empty, make the five decisions of a strategy in a page, with the leadership team in a room, before anyone drafts anything longer. Then revise the policy against those decisions and put both review dates in the diary.
Finally, ask three members of staff at three levels what AI is for here. If you get three versions of the same answer, the strategy has reached them. If you get three versions of the policy, it has not.
The Next Step
If your organisation has an AI policy everyone can quote and a strategy nobody can find, or the two have started to contradict each other, this is the kind of work I support through AI strategy sessions and policy advisory with leadership teams.
Dan Fitzpatrick is the founder of The AI Educator, a Forbes contributor and the author of bestselling books on AI in education. He works with schools, trusts, districts and organisations on AI strategy and policy. More about Dan.


