IMPAKT
Back to Decision Library
Updated AI Roadmap, Enterprise AI Strategy, AI Governance

An Enterprise AI Roadmap From 30 Days to 60 Months

Sequence enterprise AI from one bounded workload through matched evidence, narrow operation, selective industrialization, and annual renewal. The 30-day, 90-day, 365-day, and 12-to-60-month roadmap gives every horizon an owner, executable budget, exit gate, evidence trigger, and renew, reroute, resize, or retire decision.

A field note by for IMPAKT.

Sequence enterprise artificial intelligence (AI) by evidence before elapsed time. This roadmap sets the capital-review cadence; the eight-stage evidence-to-decision loop defines the method inside each horizon. In 30 days, bound one workload and preserve a manual path. By 90 days, run matched tests and decide whether to release narrowly or stop. By 365 days, operate only the approved boundary and close weak pilots. From 12 to 60 months, industrialize repeated qualified demand, exercise continuity, and reclassify every material scope annually.

Start with three capital buckets and a 30-day decision

Separate the portfolio into NOW, OPTIONS, and WATCH.

NOW contains capabilities required across plausible futures: workload contracts, acceptance evidence, identity, data and tool authority, release and rollback, accepted-workflow economics, incident response, and manual or reduced continuity. Fund them to a depth proportional to consequence.

OPTIONS preserve a right without assuming it will win. An option may cover another supplier, model-access family, private or edge route, regional cell, agent runtime, capacity reservation, or assurance package. Give it a carrying-cost boundary, evidence milestones, exercise condition, expiry, and abandon authority.

WATCH tracks volatile signals only when they reopen a named decision. Record the source, baseline, owner, cadence, boundary, action, and falsifier. Watching model launches without a workload exposure or capital implication is passive theater.

The UK Government Futures Toolkit supports structured use of scenarios, signposts, and options in decision work. IMPAKT separately synthesizes the portfolio buckets and time horizons as operating recommendations.

First 30 days: bound one decision

Select one workload with a real owner and current baseline. Define the decision, alternatives, start and accepted end state, non-goals, affected people, data path, quality threshold, severe failures, demand, latency, authority, tools, recovery, and economic unit.

Classify required control demand and demonstrated capacity. Assign decision, funding, veto, stop, recovery, and restart rights. Archive the baseline and mark each material input observed, sourced, assumed, or unknown with an owner, test, and date.

Keep a manual or reduced-service path. Stop the first horizon when the workload has no owner, every candidate is ineligible, or an eligibility-changing unknown lacks a credible test.

The output is an executable workload and decision record prepared before any demo.

Synthetic roadmap workload — support-case summary. At day 30, SUP-SUM-01 is bounded to an evidence-linked summary after a support ticket closes for named reviewers. Unsupported claims are a severe failure, and the current manual summary is the fallback. Owners record latency in milliseconds, review minutes, accepted summaries, and cost per accepted summary; targets remain organization-set and results remain to measure.

By 90 days: produce matched evidence

Compare only eligible complete configurations. Use representative ordinary, difficult, edge, invalid, tool-error, and severe cases. Hold workload, acceptance, service, authority, and cost units stable; disclose material asymmetries.

Complete the benchmark, failure-control-evidence ledger, completed-workflow cost record, release card, affected-party recourse, and recovery exercise. Preserve raw outputs, traces, timings, evaluator decisions, tool effects, failures, and interventions.

The NIST Generative AI Profile offers suggested actions for generative-AI risk management. Use it to strengthen failure discovery and control review; release still depends on the workload gate.

The exit is explicit: stop, redesign, remain limited, or release narrowly. Evidence promotes the pilot; time spent leaves its status unchanged.

For SUP-SUM-01, day 90 compares eligible configurations on identical closed cases and citation rules. A missing source right, unowned recovery path, or failure to beat the manual decision hurdle closes the work here. Passing evidence permits only summary preparation for the named reviewers.

By 365 days: operate the approved boundary

Operate only the approved users, data, actions, tools, service class, and capacity. Observe accepted outcomes, severe failures, intervention, latency, retries, exceptions, review burden, cost, incidents, overrides, recourse, and recovery.

Compare the result with the archived baseline and counterfactual. Add a supplier route, private tier, or greater authority only after its own gate. Close weak pilots. Revoke unused credentials. Retire stale prompts, models, indexes, caches, and tools. Assign supplier-transition, workforce-transition, and stranded costs rather than leaving them outside the business case.

At this horizon, the operating record matters more than the original sponsor narrative. Close a pilot that lacks current evidence or an accountable owner.

At day 365, renew SUP-SUM-01 only if accepted summaries, review burden, incidents, and recovery remain inside the approved boundary. Otherwise reroute, narrow, or retire it and restore the archived manual path.

At 12 to 24 months: industrialize repeated qualified demand

Industrialize only patterns that recur across qualified workloads. Build common identity, policy, tool mediation, configuration registry, evaluation infrastructure, trace semantics, release records, incident response, and portability where reuse exceeds centralization burden.

Strengthen service operations, domain evaluation, people transition, affected-party recourse, and continuity. Exercise supplier substitution and manual recovery; an unexercised fallback remains a hypothesis.

Expire unsupported options. An internal serving fleet, regional cell, model-conversion pipeline, or broad agent runtime must pass reuse, utilization, accepted-workflow economics, operator, recovery, and exit gates. Exclude prestige infrastructure from the strategic-asset ledger.

From 12 to 24 months, reuse only the controls that another qualified workload genuinely shares. One successful summary workflow supports its bounded control pattern; a general agent platform or private serving fleet needs broader qualified demand.

At 24 to 60 months: renew the portfolio annually

Reclassify every material workload, jurisdiction, consequence class, and capital decision at least annually. Refresh cases, affected populations, laws, contracts, suppliers, prices, models, tools, capacity, incidents, and scenario signposts.

Renew when the evidence basis still passes and the owner funds it. Reroute when another eligible configuration now wins. Resize when scope, authority, capacity, or budget should change. Retire when the owner, outcome, permission, evidence, or value no longer supports operation.

The review should also unwind weakened bets. Remove obsolete infrastructure, credentials, duplicated routes, and unsupported options. Preserve transition and recovery funding so exit remains executable.

From 24 to 60 months, SUP-SUM-01 stays intentionally bounded, changes route, or retires as evidence dictates. Its review remains a conditional decision rather than an automatic expansion milestone. A missed owner, expired evidence package, failed recovery exercise, or better manual counterfactual triggers retirement funding and credential removal.

Put reopen triggers on the board agenda

Boards and CTOs should govern the workload, authority, evidence, capital, and reversal path rather than a model score. For each material scope, ask:

  • Who owns the outcome, funding, veto, stop, recovery, and restart?
  • What current evidence shows accepted completion against the baseline?
  • Which severe failure or hard gate can stop operation immediately?
  • What budget includes demand, incident reserve, exit, transition, and stranded cost?
  • Which model, tool, law, supplier, population, or recovery change reopens the decision?
  • What happens by default when evidence expires or the response owner misses the deadline?

The NIST AI Risk Management Framework is a voluntary reference for ongoing governance and risk management. Accountable enterprise rights and board approval remain separate.

Repeated overrides, missing owners, failed recovery, and expired evidence are governance events. Default to remain limited or stop instead of silent continuation.

Use one roadmap record

For every horizon, record actions, owner, budget source and cap, demand denominator, included and excluded work, evidence gate, expiry, transition, and stranded-cost owner. Link each horizon to the same workload and configuration IDs so evidence remains traceable.

Keep later horizons bounded until repeated qualified demand and operating evidence earn industrialization. One workflow may remain intentionally small; another may retire at 90 days.

Decision rule

Advance by evidence before elapsed time. Fund NOW to the workload's control demand, fund OPTIONS to milestones, and fund WATCH as evidence ownership. End every horizon with an executable renew, reroute, resize, or retire decision.

What this does not prove

The horizons are recommended review points, not claims that every organization can or should deploy within 30, 90, or 365 days. They do not forecast capability, adoption, savings, regulation, or production maturity. NIST and UK foresight materials inform risk and scenario practice; they do not approve this roadmap or any workload.

Editorial process

This article was extracted from the IMPAKT LLM Operating Playbook with AI-assisted structure, drafting, editing, and metadata preparation. It underwent an independent critique and substantive revision loop against IMPAKT's publication rubric; primary sources are linked beside supported claims, and synthesis, recommendations, and evidence boundaries remain explicit.

Sources