Skip to content
Insight · August 2026

Institutional AI strategy in Europe: from pilot theatre to operating posture

Pilots are cheap and prove nothing. A European institution's AI strategy is the set of commitments it can still honour when the vendor, the regulator or the politics change.

Ask a European institution for its AI strategy and you will usually receive a portfolio of pilots. Twelve to forty of them, each defensible, each sponsored, almost none of them in production. This is not a failure of ambition or of talent. It is what happens when the word "strategy" is used to mean "list of experiments" — and it is the central pathology of institutional AI strategy in Europe today.

Pilot theatre and why it persists

Pilots persist because they are structurally rewarded. A pilot needs no mandate analysis, no conformity assessment, no continuity plan and no board sign-off. It produces a slide. It carries no downside for its sponsor. Production carries all of it.

The result is an institution that can demonstrate activity indefinitely while its actual operating capability does not move. The tell is simple and worth applying honestly: how many AI systems currently make or materially shape a decision the institution is legally answerable for? For most European institutions in 2026, the honest number is between zero and three.

The second tell: when a pilot does cross into production, who signs? If the answer is "the programme" rather than a named person against a named mandate line, the crossing has not really happened.

Strategy as operating posture

A strategy is not a set of intentions. It is the set of commitments an institution can still honour when the conditions change — when the vendor is acquired, the regulator publishes guidance, the model degrades, or the politics reverse. Written that way, an AI strategy becomes a short document, and a much harder one.

The useful format is not a roadmap. It is a statement of posture: what this institution will do with AI, what it will not do, what it must control itself, and what it is willing to depend on others for. Three pages. Signed. Revisited annually, not quarterly — a posture that changes quarterly is a mood.

The five commitments

  1. Mandate. Which decisions this institution will allow an AI system to shape, and which it will never delegate — expressed against the enabling statute, not against a risk appetite score. This is the commitment that makes all others decidable.
  2. Portfolio. A small number of production commitments with named owners and dates, rather than a long list of explorations. Three systems in production beat thirty in pilot, and are cheaper.
  3. Sovereignty. Which dependencies the institution accepts and which it refuses, with the substitution window written down. Sovereignty here is operational, not rhetorical — see digital sovereignty as resilience.
  4. Capability. What the institution builds internally, what it buys, and what it will never outsource — in particular, evaluation and oversight.
  5. Assurance. How the institution proves, to itself first, that the above four are true. Unassured commitments decay within a year.

Running the portfolio

Institutional AI portfolios fail in a specific direction: they optimise for the number of use cases rather than the depth of the operating spine. The spine — identity, data lineage, evaluation harness, logging, oversight tooling, incident routing — is shared across every system and is the only part that compounds.

A workable allocation for the first two years is roughly two thirds of effort into the spine and one third into use cases. This is an unpopular ratio inside institutions because the spine produces no demonstrations. It is also the only ratio under which the fourth use case costs less than the first.

Prioritisation should follow reversibility, not value. Start with systems where an error is detectable and recoverable within the same operating day. Institutional credibility is spent once; spend it on a class of system where being wrong is survivable.

Capability: what to build, buy and never outsource

Buy: foundation models, infrastructure, most tooling. There is no institutional advantage in operating what the market operates better, provided the dependency terms are written and the substitution window is rehearsed.

Build: the evaluation harness against the institution's own operating distribution, the oversight interfaces used by staff, and the data lineage layer. These encode the mandate and cannot be bought generically.

Never outsource: classification decisions, acceptance criteria, incident judgement, and the relationship with the supervisor. An institution that has outsourced its judgement about whether a system is acceptable has outsourced the mandate itself, which it is not permitted to do.

Staffing follows from this and is smaller than most programmes assume: a mandate-literate owner, two or three engineers who own the spine, an evaluation lead, and a risk partner with real veto authority. Scale comes from the spine, not from headcount.

Frequently asked

What is institutional AI strategy? The set of written commitments — mandate, portfolio, sovereignty, capability, assurance — that determine how an institution deploys AI inside its legal responsibilities, and which survive changes of vendor, regulation or leadership.

How is it different from a corporate AI strategy? A corporate strategy optimises for return under competitive constraints. An institutional strategy optimises for defensibility under a mandate: the institution must be able to explain, contest and reverse consequential outputs. That constraint changes which systems are worth deploying at all.

How long before production? For a first high-risk system with the spine built alongside it, nine to fifteen months is realistic in a European institution. Anything promising ninety days is describing a pilot.


First published August 2026 · Frankfurt am Main.

← All insights

© UberConsul · Frankfurt am Main
"Quality is not an act, it is a habit." · Aristotle