AI strategy gets written last
In the model, strategy heads the list. In a mid-sized company, writing it first produces a document, not a capability.
The reason is simple: an AI strategy drafted before you have a single instrumented use case is an exercise in imagination. It sets priorities on assumptions nobody measured, commits budget against savings nobody has seen, and ages the moment the first real pilot returns data. We have read a fair number of them. Most look alike, because they all come from the same place: from what gets read, not from what gets operated.
What does work is the reverse order. One measured case generates three things no paper strategy can: a real cost figure, a real savings or capacity figure, and a lesson about where your bottleneck actually sits. With that, the strategy writes itself in two pages, with your own numbers.
The caveat, and it matters: this holds for mid-sized companies without severe sector supervision. In banking, life and health insurance or healthcare, governance and strategy move to the front, because the cost of being wrong is not a failed pilot but a regulatory file.
The seven layers, in business language
Before the route, the map. These are the seven dimensions of Gartner's model (2025), translated into the question each one answers:
| Layer | The question it answers |
|---|---|
| AI value | What do I gain, how much, and how will I know? |
| AI data | Do I have the material this is built from? |
| AI governance | What is forbidden, who decides, what gets logged? |
| AI engineering | How does it go from demo to something that survives a Tuesday? |
| AI people and culture | Who will actually use it, and why would they? |
| AI organization | Who owns this, and with what budget? |
| AI strategy | Where are we going, and what are we not doing? |
Seven is an awkward number. Nobody attacks seven fronts at once, least of all a mid-sized company. Which is why the useful part of the model is not the list: it is understanding that these layers are not equally urgent, and that the most urgent one is almost never where people start.
Where most companies enter, and why it fails
The usual entry point is engineering: buy a tool, run a pilot. It is the natural entry because it is the only one with a vendor knocking at the door.
It is also where the failures pile up. In July 2024 Gartner forecast that at least 30% of generative AI projects would be abandoned after proof of concept by the end of 2025; its 2026 reading puts that figure above 50%. RAND documented in 2024 that more than 80% of AI projects fail to deliver the intended business value. And MIT's The GenAI Divide (2025) produced the most quoted headline of the year: 95% of generative AI pilots show no measurable P&L impact.
That last figure deserves more care than it usually gets. The MIT study rests on 153 executive responses, 52 interviews and a review of more than 300 publicly disclosed initiatives between January and June 2025, and it has drawn well-founded criticism over its sampling. It is not a law of physics. But even its critics agree on the direction: there is far more activity than transformation.
The interesting question is not how many fail, but where. In our experience taking AI to production, a project rarely dies in the layer it entered through. It dies two layers down:
- The engineering pilot dies because nobody defined in value what winning looked like, so six months in there is no way to defend it to the board.
- The case dies because in data the knowledge it needed lived in three people's heads and a folder of PDFs. Gartner estimates 60% of AI projects will be abandoned through 2026 due to inadequate data foundations, and that 63% of organisations lack — or are unsure they have — data management practices fit for AI.
- The tool dies because in people it was rolled out to 400 employees without anyone changing a single process, and eight weeks later eleven were using it.
That is the pattern. You enter at the top and die at the bottom.
The sequence we propose
Against seven parallel layers, this is the route we apply in mid-sized companies. It is not the order of the diagram; it is the order in which each layer unlocks the next.
- Value. Pick one case and baseline it before touching anything. If you cannot say what the process costs today, you do not have a case: you have a hunch. It comes first because it is the only layer that unlocks budget for the rest.
- Data. Only what that case needs. Not a corporate data strategy: the minimum viable preparation for one concrete case. The difference between the two is eighteen months.
- Governance. The required minimum, which in 2026 is no longer optional: the transparency obligations of the EU AI Act apply from 2 August 2026. Three questions: what is forbidden, who decides, what gets logged.
- Engineering. Now yes. Build or buy for that case, judged on exit cost.
- People and culture. The team that will operate it. Not generic training: redesigning the work of the specific people who touch that process.
- Organisation. Once two or three cases are live, not before. A committee for one pilot is bureaucracy; a committee for a portfolio is governance.
- Strategy. With your own evidence on the table. Two pages and your own numbers.
In mid-market, correct maturity is uneven
There is an implicit instruction in almost every maturity model: advance evenly across all dimensions. That is good advice for a company of twenty thousand and bad advice for one of three hundred.
A mid-sized company does not have the executive bandwidth for seven fronts. What it can do — and what we see work — is a deliberately uneven shape: real depth in two layers, minimum viable in the other five, and clarity about which is which. Being deliberately immature in organisation while excellent in value and data is not a gap: it is resource allocation.
The mistake is not the unevenness. The mistake is when it is accidental.
How to tell which layer you are stuck in
Three questions separate the companies that will advance from the ones that will accumulate pilots:
- Can you say, in money or hours, what the process you want to improve costs today? If not, you are stuck in value, even if you think you are in engineering.
- If tomorrow you wanted a system to answer with your company's judgement, where would that judgement come from? If the answer is "from our people", you are stuck in data.
- Who signs off that an AI output can go to a client? If there is no name, you are stuck in governance, and it is a matter of time before an incident proves it.
None of the three is technical. All three are business questions. That is precisely the point of this series.
Before this, and after this
If you are still deciding whether to start rather than how, the prior piece is the three legitimate reasons to wait six months. This series assumes that decision is already made.
And if what you want is not the map but the first-quarter action list, it is in where a CEO starts: the five axes of the first quarter. That piece answers "what do I do now"; this one answers "where am I and in what order do I advance".
Conclusion
Gartner's maturity model answers "what does doing this well look like?" well. It does not answer "what do I do, at my size, with my team and my budget?". That translation is the work, and it is not done by reading: it is done by measuring one case.
If you know you need to start but not which of the seven layers your bottleneck sits in, that diagnosis is exactly where we begin.
Frequently asked questions
What are the 7 layers of the AI maturity model?
Strategy, value, organisation, people and culture, governance, engineering and data. It is the framework Gartner published in 2025. It describes the dimensions in which an organisation matures; it does not prescribe the order a given company should travel through them.
Where should a mid-sized company start with AI?
With the value layer: pick one use case and measure its baseline before buying anything. It is the only layer that unlocks budget for the rest, and a missing baseline is the most common reason a pilot does not survive its first board review.
How long does it take to reach AI maturity?
There is no honest single figure. What is measurable is the first stretch: one instrumented use case, with a baseline and a go/no-go decision, resolves in a quarter. Anyone quoting a timeline to "be mature in AI" without knowing your data is selling.
Do you have to advance across all seven layers at once?
No, and in a mid-sized company attempting it is counterproductive. The shape that works is deliberately uneven: depth in two layers, minimum viable in the rest, knowing which is which.
Why do so many AI projects fail?
Because they enter through the wrong layer. Gartner puts generative AI projects abandoned after proof of concept above 50%, and attributes 60% of abandonments through 2026 to inadequate data foundations. A project rarely dies where it started: it dies in the layer that was skipped.

Jordi García is Tech Lead at onext. He works on bringing AI into governed production across development and product teams —with Spec-Driven Development, context engineering and human verification at every step— and authors onext's technical insights on the method, quality and cost of applied AI.
LinkedIn →