AI Leadership and Strategy

AI Strategy vs AI Policy: What Is the Difference?

A policy tells people what they must not do. A strategy tells them what the organisation has chosen to do, in what order and why. Most organisations have the first and call it the second, which is why their staff are compliant but not directed. Here is how to tell the two apart, and which to write first.

A black hand-drawn chair pulled up to a blue cut-paper table, standing for the decision an AI strategy makes at the leadership table that a policy alone never does.

In brief

An AI policy tells people what they must not do; an AI strategy tells them what the organisation has chosen to do, in what order, and why. According to Dan Fitzpatrick, founder of The AI Educator, most organisations have a policy and call it a strategy, which is why their staff are compliant but not directed. Both documents are needed, but the order matters: make the strategy's decisions first, then write the policy as its guardrail. The practical way to tell them apart is the Prevent or Direct Test: does the document change a decision someone would otherwise make, or only prevent one? A document that only prevents is a policy, whatever it is called; a document that changes decisions is a strategy.

Ask a leadership team to show you their AI strategy and, more often than not, they will hand you their AI policy. It has a purpose statement, a list of approved tools, a section on data protection and a paragraph on acceptable use. The board has approved it. And it does not tell a single member of staff what the organisation has decided to do.

That is not a criticism of the policy. It is doing its job. The problem is that it has been asked to do a second job it was never designed for, and nobody has noticed, because the organisation feels covered. Staff are compliant. They are not directed. The gap between those two states is where most of the value of AI is currently being lost.

What Is the Difference Between an AI Strategy and an AI Policy?

An AI policy tells people what they must not do; an AI strategy tells them what the organisation has chosen to do, in what order, and why. Everything else about the two documents follows from that.

A policy sets boundaries: which tools are permitted, what information may go into them, who is accountable, and what happens when something goes wrong. It is written mostly in the negative, and it is written for the worst day: the data breach, the complaint, the piece of work that turns out not to be the student's own. A strategy sets direction: where AI effort goes first, where it deliberately does not go yet, who leads it and how you will know it is working. It is written in the positive, it is dated, and it is written for the ordinary Tuesday, when a head of department has a real decision in front of them and needs to know which way the organisation is facing.

AI policy AI strategy
The question it answers What may we not do? What have we chosen to do, and in what order?
Written for The worst day The ordinary Tuesday
Tense Permanent, until the rules change Dated, with a "first" and a "not yet"
Finished when It is signed It is used
Owned by The board, maintained by whoever owns compliance The executive team, challenged by the board
Can you borrow it? Largely, yes No

The last row is the one I find most useful. You can borrow a policy from a template or a neighbouring school and lose very little, because a policy encodes obligations that are mostly shared. You cannot borrow a strategy, because it encodes choices, and your choices are the whole point.

Why Most Organisations Have a Policy and Call It a Strategy

Most organisations end up with a policy called a strategy because a policy is the easier document to write, the safer document to approve, and the one the outside world asks for first. Inspectors, insurers and parents all ask "what is your policy on AI?" Nobody outside the organisation asks "what have you decided to do?" A policy also requires no disagreement: everyone agrees that children's data should be protected. A strategy requires a choice, and a choice means someone's good idea goes second.

The result is an organisation that can answer the second question of the Readiness Test and not the first. As I set it out in my article on what it means to be AI ready: "The Readiness Test is three questions an organisation must be able to answer consistently, from the top to the front line, before it can call itself AI ready: What is AI for here? What may I do with it? Who decides when it goes wrong?" A policy answers the second and the third. Only a strategy answers the first.

When an AI Policy Is the Right Document

An AI policy is the right document when the question on the table is about limits: what is permitted, with which data, by whom, and what happens when it goes wrong. Safeguarding, data protection, assessment integrity and incident response belong in a policy, because those answers should not depend on who is in the room.

Regulation and guidance increasingly write the minimum of that policy for you. The Department for Education's guidance on generative AI in education, last updated on 12 August 2025, requires schools and colleges in England to make sure filtering and monitoring cover generative AI, puts safety first, and then says something leaders should read twice: schools and colleges "are free to make their own choices about the most suitable use cases for generative AI tools in their settings, as long as they comply with their wider statutory obligations". That is a policy frame with a strategy-shaped hole left deliberately open. The department has told you where the guardrails are. It has not told you which road to take, and it is not going to.

The same is true at a larger scale. The European Commission's implementation timeline for the EU AI Act has AI literacy obligations applying since 2 February 2025, transparency rules from 2 August 2026, and the high-risk rules in Annex III, which cover uses in education, now applying from 2 December 2027 after the 2026 digital omnibus postponed them. Every one of those dates is a reason to update a policy. None of them tells you what AI is for in your organisation.

When an AI Strategy Is the Right Document

An AI strategy is the right document when the question is about direction: where AI effort goes first, where it deliberately does not, who leads it, and how you will know whether it is working. The usual sign is that a governor has asked "what is our plan?" and received the policy in reply.

The evidence on direction is stark. PwC's global AI performance study, published on 13 April 2026 and drawing on 1,217 senior executives across 25 sectors, found that 74 per cent of the economic value from AI is being captured by 20 per cent of organisations. The leading fifth were twice as likely to redesign how work is done rather than add AI tools to existing work, and 1.5 times more likely to have a cross-functional governance board. The top performers are not choosing between governance and direction. They have both, and it is the direction that separates them from the majority, who are governed, compliant and going nowhere in particular.

A strategy that does that job makes five decisions explicitly: purpose, priorities, permissions, people and proof. I have written about each of them in how to create an AI strategy that people actually use. Permissions is the one to notice here, because it is where strategy and policy meet: the strategy grants permission, the policy sets the limit, and the two should describe the same list of tools.

The Mistake I See Most Often

The mistake I see most often is writing the policy first, feeling finished, and never getting to the strategy. Across the schools, trusts and districts I work with, the sequence is nearly always the same. Something happens: an incident, a headline, a question from a governor. A policy is drafted quickly from a template, approved at the next meeting and circulated. Relief. Then months of nothing, because the pressure that produced the policy has gone. Meanwhile the confident staff carry on, the cautious ones stop altogether, and both groups can truthfully say they are following the policy.

The second mistake is subtler: putting the strategy inside the policy. Many AI policies open with a page of "strategic aims" before the rules begin. In practice the organisation's choices get approved as rules, in the one document nobody revisits until the law changes, and the aims quietly fossilise. Keep them apart: the policy short and hard, the strategy short and dated.

The third is a strategy that is really a policy in a positive voice. "We will use AI responsibly, ethically and in line with our values" is not a decision; nobody could disagree with it, and nobody could act on it. It is a distinction I keep returning to in my writing for Forbes and in my books on AI in education, because the organisations that struggle with AI are rarely the ones without rules. They are the ones without a choice.

The Prevent or Direct Test

The Prevent or Direct Test is one question to ask of any AI document: does it change a decision someone would otherwise make, or only prevent one? A document that only prevents is a policy, whatever it is called. A document that changes decisions is a strategy.

Three follow-up questions settle the close cases.

Does it have a "first" and a "not yet"? Policies have no sequence, because obligations do not queue. If the document names what comes first this year and what has been deliberately deferred, it is doing strategy work.

Could another organisation adopt it unchanged? If a neighbouring school or a competitor could change the name on the cover and lose nothing, it is a policy, or it is nothing. A strategy would not survive the transfer.

Who would notice if it vanished? If only the data protection officer, the board and the compliance lead would miss it, it is a policy. If the middle leaders planning next term would miss it, it is a strategy.

When leadership teams do this exercise with me, the usual outcome is a pile of documents in the "prevent" column and nothing in the "direct" column. That is not a failure of the documents. It is guardrails around an empty road.

Which to Write First, and How They Fit Together

Write the strategy first, or at least make the decisions in it, and then write the policy as its guardrail; a policy written before any direction exists will end up guarding whatever people happen to be doing. The order feels wrong because the policy feels urgent. But a guardrail is defined by the road it runs beside. If you have not chosen the road, the policy defaults to the vaguest boundary available: the "responsible and ethical use" paragraph that protects nobody and guides nobody.

If you already have a policy, do not scrap it. Write the strategy, then revise the policy against it, starting with permissions. Give the two documents different owners and different rhythms: the board approves the policy and it changes when the rules change, so the regulatory dates above give you the diary; the executive team owns the strategy and it changes when the priorities should, at least every term, with a version number on the front. Curiosity over fear does not mean fewer rules. It means the rules serve a direction that has been chosen, rather than standing in for one.

What to Do This Term

The practical next step is to put every AI document you have on the table, run the Prevent or Direct Test on each, and be honest about which column is empty. If the "direct" column is empty, make the five decisions of a strategy in a page, with the leadership team in a room, before anyone drafts anything longer. Then revise the policy against those decisions and put both review dates in the diary.

Finally, ask three members of staff at three levels what AI is for here. If you get three versions of the same answer, the strategy has reached them. If you get three versions of the policy, it has not.

The Next Step

If your organisation has an AI policy everyone can quote and a strategy nobody can find, or the two have started to contradict each other, this is the kind of work I support through AI strategy sessions and policy advisory with leadership teams.

Dan Fitzpatrick is the founder of The AI Educator, a Forbes contributor and the author of bestselling books on AI in education. He works with schools, trusts, districts and organisations on AI strategy and policy. More about Dan.

Key takeaways

  • An AI policy tells people what they must not do; an AI strategy tells them what the organisation has chosen to do, in what order, and why.
  • Most organisations have an AI policy and call it a strategy, because a policy is easier to write, safer to approve and the document the outside world asks for first; the result is staff who are compliant but not directed.
  • A policy is written for the worst day and is finished when it is signed; a strategy is written for the ordinary Tuesday and is finished only when it is used.
  • You can borrow an AI policy from a template or a neighbouring organisation and lose very little, because it encodes shared obligations; you cannot borrow a strategy, because it encodes your choices.
  • The Department for Education's generative AI guidance (updated 12 August 2025) and the EU AI Act timeline set the minimum of a policy for you; neither tells you what AI is for in your organisation.
  • PwC's April 2026 study of 1,217 executives found 74 per cent of AI's economic value going to 20 per cent of organisations, and the leaders were both more likely to have governance boards and twice as likely to redesign work rather than add tools: they have direction as well as rules.
  • Dan Fitzpatrick's Prevent or Direct Test asks one question of any AI document: does it change a decision someone would otherwise make, or only prevent one? Write the strategy first and the policy as its guardrail.

Frequently Asked Questions

What is the difference between an AI strategy and an AI policy?

An AI policy sets limits: what people must not do with AI, which tools are permitted, what data may be used and who is accountable when something goes wrong. An AI strategy sets direction: what the organisation has chosen to do with AI, in what order, and why. A policy prevents decisions; a strategy changes them.

Do we need both an AI strategy and an AI policy?

Yes. A policy protects the organisation and a strategy directs it, and neither does the other's job. An organisation with only a policy is compliant but not directed; one with only a strategy has chosen a road with no guardrails. The two should share one list of permitted tools, described in the same words.

Which should come first, the AI strategy or the AI policy?

The strategy, or at least the decisions in it. A policy written before any direction exists ends up guarding whatever people happen to be doing, and defaults to a vague responsible-use paragraph. If a policy already exists, keep it, make the strategy's decisions, then revise the policy against them, starting with permissions.

What should an AI policy include?

An AI policy should cover permitted tools, the information that may and may not be entered into them, safeguarding and data protection requirements, assessment integrity or acceptable use, accountability and incident response, and how the policy is reviewed when guidance or law changes. Keep it short, hard and free of strategic aims.

What should an AI strategy include?

An AI strategy should make five decisions explicitly: purpose (what AI is for here and what it is not for), priorities (where effort goes first and where it does not yet), permissions (what staff may do now), people (who owns it and how capability grows) and proof (how you will know it is working). It should be dated and versioned.

Can a school use a template AI policy?

A template is a reasonable starting point for a policy, because most of the obligations it encodes are shared: safeguarding, data protection, filtering and monitoring. It is not a starting point for a strategy, because a strategy encodes the school's own choices. Adapt the template to your context, then write the strategy yourself.

Who should own the AI policy and who should own the AI strategy?

The board or governing body approves the AI policy, and whoever owns compliance maintains it. The executive team or senior leadership team owns the AI strategy and answers to the board for it. Giving the two documents different owners and different review rhythms stops the strategy fossilising inside the policy.

If your leadership team is working through these questions, this is the kind of work I support through AI strategy sessions and advisory work.

Learn more about working together
D
Dan Fitzpatrick

Delivered training to 150K+ educators | Founder of The AI Educator and AI Educator Tools | Forbes Contributor | International Keynote Speaker | 4 x #1 Bestselling Author