Buying access to artificial intelligence is easy compared with deciding what it should change. A late-2025 survey reported that only 26 percent of companies budgeting for AI had an implementation strategy. The rest were running isolated pilots or only planning systematic work. That gap did not mean experimentation was useless. It meant budgets, data, models, workflows, controls and accountable outcomes had not yet been organised into one operating architecture.

The survey measured strategy among AI budget holders

On 19 December 2025, Vedomosti reported results from the MTS Web Services study “Technology Strategies of Business”. It combined a survey of more than seven hundred companies with in-depth interviews.

Only 26 percent of surveyed companies that allocated budget to AI said they had an implementation strategy. This was not a claim that exactly three quarters of every company in Russia lacked any idea about AI.

The denominator matters: organisations with planned spending were being compared on strategic maturity. The remaining respondents were described as pursuing individual pilots or preparing more systematic work.

A survey also records reported practice at a point in time. It does not independently prove whether a written strategy was strong, whether a pilot succeeded, or whether a budget produced economic value.

AI lagged cloud and cybersecurity strategy

The study reported cloud strategies at 44 percent and cybersecurity strategies at 42 percent, both well above AI's 26 percent. That difference is plausible because cloud and security have clearer operating boundaries.

Infrastructure teams can map systems, service levels, recovery targets and control requirements. AI cuts across products, operations, data, legal risk, workforce design and customer experience.

The comparison should not imply that cloud or security strategy was complete. It shows that businesses had more established planning disciplines for those domains.

AI can learn from them: inventories, reference architectures, risk tiers, ownership, lifecycle controls and measurable standards turn a collection of purchases into a managed capability.

A budget is a permission, not a thesis

Budget allocation proves that management considers a technology worth exploring. It does not specify the customer problem, expected improvement, process owner or threshold for further investment.

Without a thesis, proposals compete on novelty and presentation. Teams select accessible demonstrations rather than the constraints that matter most to the business.

A useful strategy explains where AI can create differentiated revenue, lower operating cost, improve decisions, reduce risk or release scarce expertise. It also identifies areas where deterministic automation is better.

The thesis must be falsifiable. If no measurable result would cause the company to stop, the initiative is sponsorship rather than disciplined investment.

Pilots were evidence, not the opposite of strategy

An isolated pilot can be rational when uncertainty is high. It tests data availability, model performance, user behaviour, integration and cost before a broad commitment.

The problem is not the word pilot; it is a pilot without a decision it is designed to inform. A demonstration that cannot pass into production or close cleanly creates no option value.

Every experiment needs a baseline, hypothesis, owner, time box and gate. The next step may be scaling, redesign, more evidence or termination.

A portfolio then connects experiments. Shared findings about data quality, security, vendors and user adoption should change the next pilot rather than being rediscovered by another department.

A text-free business architecture carries workflow objects through transparent data channels, a compact model engine, a guarded decision gate and amber outcome blocks
A model becomes an operating capability only when the complete path from business input to controlled decision and measured result is designed.

Company size did not create a simple maturity ladder

Among surveyed companies with revenue from two to fifteen billion rubles, 36 percent reported an AI strategy. In the group above fifteen billion, the share was lower at 25 percent.

Small and medium revenue bands up to two billion rubles reported 22 percent. The pattern does not support a simple conclusion that more revenue automatically means clearer strategy.

Larger businesses have resources and data, but also more legacy systems, stakeholders and competing initiatives. A strategy may take longer to align across a complex group.

Mid-sized organisations can sometimes focus on fewer processes and move faster, while smaller firms may lack specialists. These are hypotheses, not causal findings established by the survey.

Use cases should begin inside the workflow

“Deploy AI” is not a use case. A useful description names the decision or task, current actors, inputs, delays, errors, customer impact and the point where a model changes work.

For example, assisting a service agent differs from automating a response. The first keeps human judgement in the loop; the second requires stronger confidence, controls and recovery.

Process mapping often reveals that the constraint is missing data, unclear policy or fragmented responsibility. A model cannot repair an undefined operating process by itself.

Teams should compare AI with simpler alternatives: search, rules, workflow redesign, better training or conventional analytics. The cheapest reliable solution is strategically superior to unnecessary complexity.

Value needed a baseline before a model

Economic effect cannot be measured if the current process is unknown. Baselines include labour time, throughput, conversion, error, loss, delay, customer satisfaction and risk events.

The model metric is only an intermediate indicator. Higher accuracy may not improve the business if users ignore recommendations or integration adds extra work.

A complete benefit case subtracts inference, infrastructure, licence, data preparation, monitoring, review, change management and incident costs.

It also recognises distribution. Average improvement can hide serious harm to a customer segment or rare high-consequence errors.

Data readiness was an operating responsibility

AI strategy often becomes a data strategy under pressure. Important information may be incomplete, inconsistent, inaccessible, poorly labelled or collected for another purpose.

Ownership cannot sit only with a central data team. Business units define meaning, source-system teams control capture, and risk owners set allowed use.

A data product needs a named owner, quality measures, lineage, access rules and a change process. Otherwise every model builds a temporary copy and multiplies inconsistency.

More data is not always better. Retention, consent, commercial confidentiality and minimisation should define what the company is entitled to use.

Architecture determined whether pilots could scale

A demonstration may run on a spreadsheet and a vendor interface. Production requires identity, integration, versioning, observability, resilience, cost control and support.

Reference architecture creates a paved road: approved model access, retrieval, logging, evaluation, secrets management and deployment patterns that teams can reuse.

Standardisation should not freeze innovation. It should make routine controls cheap while allowing justified exceptions with accountable review.

The strategy also decides build, buy and partner boundaries. Owning every layer wastes resources; outsourcing the differentiating workflow can surrender control.

Security had to surround the lifecycle

AI introduces familiar security risks in new combinations: sensitive prompts, data leakage, malicious inputs, vulnerable dependencies, excessive permissions and opaque external services.

Controls begin with classification and least privilege. They continue through supplier diligence, protected development, testing, monitoring and incident response.

Generative systems need explicit treatment of prompt injection, unsafe tool use and untrusted retrieved content. A fluent response is not proof of authorised action.

Security strategy should enable safe patterns rather than force teams into unsanctioned tools. Fast approved access can reduce shadow AI more effectively than prohibition alone.

Governance needed tiers, not one committee for everything

A spelling assistant and a model influencing credit, safety or employment do not need identical review. Risk tiers allocate attention according to consequence, autonomy and affected people.

Low-risk tools can use standard controls and local approval. High-risk applications require independent validation, legal review, human override, audit evidence and stronger monitoring.

A central council sets policy and resolves shared issues; product owners remain responsible for outcomes. Governance fails when approval transfers accountability away from the business.

Registers should track models, versions, data, owners, vendors, decisions and retirement dates. Unknown systems cannot be governed.

Human adoption was part of model performance

A technically capable assistant creates no value if employees distrust it, duplicate its work or cannot tell when it is wrong. Adoption is a design problem, not a launch announcement.

Users should help define workflow, feedback and escalation. Training must include limitations and verification, not merely buttons.

Automation changes roles. Time saved will not become productivity unless managers redesign queues, capacity, incentives and service expectations.

Workforce dialogue also reduces hidden resistance. People engage more honestly when the organisation explains what will change, what remains human and how skills will develop.

Vendor choice was a portfolio decision

Teams can accumulate overlapping copilots, model contracts and point solutions. Each looks inexpensive alone while identity, data and support fragmentation raise total cost.

A platform approach can consolidate controls and volume, but excessive dependence creates pricing, roadmap and exit risk. Portability should be designed where it matters.

Evaluation must use representative tasks and data. Public benchmark leadership may not translate into better accuracy, latency, language performance or cost in the company's workflow.

Contracts need clarity on data use, retention, model improvement, service levels, security events, intellectual property and termination assistance.

A strategy gate for every AI initiative

  1. Name the workflow problem and accountable business owner.
  2. Measure the current baseline and define the target outcome.
  3. Compare AI with simpler process and software alternatives.
  4. Confirm data rights, quality, lineage and security classification.
  5. Select the human decision boundary and risk tier.
  6. Estimate full lifecycle cost, not only pilot access.
  7. Test with representative users and downside cases.
  8. Scale, redesign or stop according to predetermined evidence.

Production required continuous evaluation

Models and context change after launch. Inputs shift, users adapt, vendors update systems and business policy moves, so initial acceptance is not permanent assurance.

Monitoring should combine technical quality, business outcome, cost, latency, user behaviour and risk indicators. No single dashboard metric can represent the system.

Sampling and human review remain important where ground truth arrives late. Incidents should feed tests so that the same failure becomes harder to repeat.

Every system also needs a fallback and retirement plan. Continuing a degraded model because no manual route exists turns optimisation into dependency.

Portfolio funding should move with evidence

An annual budget fixed by department encourages every sponsor to protect a pilot. A strategic portfolio releases funding in stages as uncertainty falls.

Early money pays for problem discovery and evidence. Larger commitments follow only when data, integration, user demand and economics support production.

Shared capabilities such as model access, evaluation, data products and security should be funded as infrastructure when reuse is demonstrated.

Stopping is a productive outcome when it occurs early and documents learning. A portfolio that never closes a project is not necessarily successful; it may lack honest gates.

The strategy had to choose what not to automate

Some decisions require empathy, legitimacy, negotiation or accountability that should remain visibly human. Others have too little volume to justify a complex system.

Automation can also remove learning opportunities from junior staff or weaken organisational memory. The operating model must preserve skill development and critical review.

Strategic restraint protects trust. Customers and employees should know when AI materially shapes an interaction and how to obtain review where appropriate.

A clear exclusion list gives teams more confidence elsewhere. Boundaries reduce fear that every process is an undeclared experiment.

An operating cadence kept strategy alive

A strategy written once becomes obsolete as models, prices, regulation and company priorities change. Management needs a regular cadence linking portfolio review, architecture, risk and realised value.

Monthly operating reviews can address delivery and incidents; quarterly reviews can reallocate capital, close weak use cases and revise shared capabilities. Different horizons prevent governance from becoming either frantic or ceremonial.

Decision records should show why a system scaled, paused or changed. This protects organisational memory when sponsors, vendors and technical teams move.

Strategy becomes credible when the same evidence changes both technology and budget. A dashboard that never causes a decision is reporting, not management.

AI strategy was business architecture

The survey's 26 percent figure captured a maturity gap, not a verdict on three quarters of companies. Many were still learning through pilots or preparing systematic work.

The next step was not to write a decorative strategy document. It was to connect priorities, workflows, data, architecture, security, people, finance and measurable outcomes.

Cloud and cybersecurity offered useful precedents: capabilities mature when inventories, standards, owners and lifecycle controls become ordinary operations.

An AI budget becomes strategic when it buys evidence and repeatable business capability. Until then, it buys experiments—and experiments are valuable only when they lead to a decision.