P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI strategy

AI strategy and adoption

Working out which AI systems and agents an organisation actually needs, and how to adopt them safely under NIST AI RMF, the EU AI Act, and the UK's principles-based approach.

Most organisations do not have an AI strategy problem; they have an AI selection problem. The work answers the questions that matter before any tool is bought: which AI systems and agents the business actually needs, what they should be allowed to do, and which regulations apply to each of them.

Frameworks covered

NIST AI RMF

Risk framing across Govern, Map, Measure, and Manage

EU AI Act

System classification and obligation mapping by risk class

UK approach

The principles-based framework applied by UK regulators

ISO/IEC 42001

Alignment so governance work counts towards certification later

How the work runs

  1. 1

    Discovery and AI inventory

    Map every AI system in use or planned: sanctioned tools, shadow adoption, vendor features, and internal builds. The inventory becomes the register everything else references.

  2. 2

    Use case and agent fit

    Assess where AI and agentic automation genuinely fit your operations, and where they do not. Each candidate use case is scored for value, data sensitivity, and blast radius.

  3. 3

    Risk and regulatory mapping

    Classify each system under the EU AI Act, map NIST AI RMF functions, and record the UK regulatory expectations that apply to your sector.

  4. 4

    Roadmap and architecture

    A sequenced adoption roadmap: which systems to deploy, in what order, with what permissions, and the governance controls each one needs from day one.

  5. 5

    Oversight and board reporting

    Ongoing advisory as delivery proceeds, with board reporting that turns AI risk into decisions directors can actually take.

What you walk away with

  • AI inventory and classification register
  • Use case prioritisation matrix with value and risk scoring
  • Agent capability map: which agents, which tools, which permissions
  • Regulatory obligation map across the EU AI Act, NIST AI RMF, and UK guidance
  • Twelve month adoption roadmap with governance milestones
  • Board reporting pack

How this plays out

Example scenario

A mid-sized professional services firm discovered staff were using more than twenty unsanctioned AI tools across drafting, transcription, and analysis.

The work: Inventory first, policy second: telemetry-based discovery, risk ranking by data sensitivity, then a sanctioned toolset with clear boundaries and staff training.

Shadow use collapsed into an approved set of tools, client data exposure ended, and the firm gained a defensible register to show clients and insurers.

Example scenario

A product company wanted to add agentic features that could act on customer accounts, without understanding the permission and liability implications.

The work: Agent capability mapping and least-privilege design before build, plus EU AI Act classification of the planned system and contractual guardrails for the model vendor.

The feature shipped with scoped, auditable agent permissions and a documented risk classification that satisfied enterprise customer due diligence.

Start the conversation

A question about this area, an invitation to speak, or a role you think fits: write, and you will get a straight answer.

Get in touch

Share this

Send it to whoever owns the budget or the risk.

← All areas

The problem is rarely the one you were told about

Most of this work begins with a stated question: which model should we use, is this vendor safe, do we need a policy. Those are real questions and they are almost never the constraint.

The constraint is usually that nobody can say what AI the organisation already runs. Not because anyone concealed it, but because most of it was never adopted as a decision. A supplier shipped a feature into software already licensed. Somebody expensed a subscription below the procurement threshold. A proof of concept was built, worked, and quietly became load-bearing.

Until that list exists, every other question is being answered about a system whose shape nobody knows. That is why the first phase is an inventory rather than a strategy, and why it usually takes longer than expected and changes what the strategy needed to be.

Record every system in one of three states

AbsentNothing exists.Honest, and cheap to plan around.Documented, not operatingA policy exists. Nobody has run it.Reads as done on a spreadsheet.Operating, with evidenceIt ran, and left a record.The only state that survives an audit.RECORD EVERY REQUIREMENT IN ONE OF THREE STATESMost organisations sit here, and most findings come from here.A two-state assessment, present against absent, puts this column in the wrong one and flatters the result.An auditor does not ask whether a procedure exists. They ask when it last ran, and to see what it produced.
Present against absent is the version most organisations run, and it puts the middle column in the wrong one. A policy that exists and has never operated is where the findings come from, in an audit and in an incident alike.

Governance that produces evidence, not documents

The second failure is a governance programme that generates artefacts nobody uses. Policies written for an auditor, a risk register updated quarterly by one person, an impact assessment that is a data protection assessment with a new cover page.

The test applied here is whether an artefact was produced as a by-product of work actually happening. A review record with a date and a name is evidence. A policy stating that reviews happen is a description of an intention.

That distinction decides what gets built. Ownership that somebody knows they hold. A route for a person affected by a decision to challenge it. Logging of what a system did rather than only what it said. Each is small, and each is the thing an assessor, a regulator or an incident will ask for first.

Where the regulation actually sits

The EU AI Act reaches organisations outside the Union through the market and output tests, so a UK company serving EU customers is often in scope without holding a European entity. Its high-risk obligations moved to December 2027 and August 2028, but three other sets did not move, and Article 50 transparency has applied since August 2026.

ISO 42001 is voluntary and discharges no legal obligation. What it does is produce most of the evidence the law asks for, as a by-product of running the management system, which is a considerably better position than assembling it under time pressure.

Advice here is about which of those matters to you and in what order, rather than about compliance in general. Most organisations need less than they fear and need it sooner than they think.

How the work is done

Personally, by one practitioner, which sets the ceiling on how much runs at once and is the reason the work takes the shapes it does.

No product is resold, no tooling is bundled, and there is no partner arrangement that makes one answer more profitable than another. That independence is worth stating because it is the thing you cannot verify from the outside, and it changes what advice is available to give.