Framework for AI strategy

The RISE framework for AI strategy

RISE is my four-phase framework for AI strategy: Research, Implement, Sustain, and Evaluate. It settles why and what before anyone buys a tool, ties every AI use case to a business outcome and a metric, and decides how much autonomy each use case earns before an agent acts on its own. It runs as one program with CARE, my framework for AI security and governance.

RISE and CARE cycle diagram. The outer ring shows the four RISE phases, Research, Implement, Sustain, and Evaluate, moving clockwise. The inner ring pairs each one with a CARE phase: Research with Create, Implement with Adapt, Sustain with Run, and Evaluate with Evolve.

What the RISE framework decides

What AI is for

Research turns a list of ideas into a ranked portfolio. Every use case gets a hypothesis, a baseline, a target metric, a sponsor, and a value-versus-feasibility score. Twelve ideas become two funded bets and ten parked ones, with the reasons written down.

How much autonomy each use case gets

Every use case carries an autonomy tier, from T1 copilots to T4 multi-agent systems. Anything above T1 needs a least-agency justification: why autonomous action beats assisted work, and which tools and permissions were taken away because the job doesn't need them.

Who writes the governance

RISE doesn't write governance policy. Research hands the risk appetite, the accountable executive, and the least-agency justifications to CARE, which writes the policies. Implement then checks that the required CARE controls are live before any agent goes live.

Whether it paid off

Evaluate reports return in three lenses, economic, intangible, and capability, and nets the cost of autonomy against the gain. Every use case ends the cycle with one of three decisions: hold, raise maturity, or lower the tier.

The four phases of the RISE framework

RISE has four phases, ten categories, and fifty activities. Each phase pairs with a CARE phase in the same position on the cycle, so strategy and governance move on the same clock.

  1. Research

    3 categories, 15 activitiesPairs with CARE Create

    Decide what AI is for before choosing tools.

    Categories

    • Value proposition
    • Value narrative
    • Strategic alignment

    What it produces

    A ranked list of use cases, each with an autonomy tier, plus the inputs CARE needs to write policy: risk appetite, permitted tiers, an accountable executive, and a least-agency justification for every agent.

  2. Implement

    3 categories, 15 activitiesPairs with CARE Adapt

    Turn that list into running systems in stages, confirm governance is in place before an agent gets more autonomy, and make sure decision makers can make those calls.

    Categories

    • Execution plan
    • Govern through CARE
    • Decision makers

    What it produces

    Use cases in production at their approved tier, on a roadmap staged by autonomy level with an exit metric and a rollback trigger for every stage.

  3. Sustain

    2 categories, 10 activitiesPairs with CARE Run

    Keep running systems tied to business results, and treat CARE's monitoring and audit findings as input to the strategy.

    Categories

    • Execute and monitor
    • Compliance and ethics

    What it produces

    Scope and tier decisions made on evidence, tracked with agent KPIs: task success rate, blocked actions, approval override rate, and cost per completed task.

  4. Evaluate

    2 categories, 10 activitiesPairs with CARE Evolve

    Measure what came back as economic, intangible, and capability return, decide whether to hold, raise maturity, or lower the tier, and feed that into the next Research cycle.

    Categories

    • Refine the strategy
    • Sustainability

    What it produces

    A decision record for every use case and the portfolio for the next cycle.

Autonomy tiers for agentic AI strategy

How does RISE handle AI agents?

RISE doesn't bolt on a separate track for agents. It adds one decision to every use case, the autonomy tier, and weaves agent questions into the activities that already exist. RISE and CARE share the same four tier definitions word for word, so a strategy workshop and a governance assessment describe the same system the same way.

T1
Assistants and copilots where a human executes every actionWhat it means for strategy: Productivity value with low action risk. A person is still the one acting.
T2
Platform and citizen-built agents that call tools inside a governed platformWhat it means for strategy: Process value with bounded reach. The platform is the guardrail, and shadow agents are the risk.
T3
Custom and code-executing agents with MCP, external communication, or production accessWhat it means for strategy: Automation value with a real blast radius. Approval gates, sandboxing, and a kill switch come first.
T4
Multi-agent and cross-boundary systemsWhat it means for strategy: The biggest prize, with cascading failure modes. Plan for it once the CARE gates for T4 are cleared.

How RISE and CARE work together

RISE decides what your organization will do with AI and how much autonomy it grants. CARE, my framework for AI security and governance, decides how those systems get governed and secured. They run as one cycle, and each phase hands something specific to its partner.

  • Research pairs with Create

    Research hands over the risk appetite with permitted tiers, the accountable executive, and the use-case portfolio. Create writes the policies and returns the tier gates the portfolio has to clear.

  • Implement pairs with Adapt

    Implement hands over the staged roadmap, the tool and platform choices, and the approval design. Adapt fits the program to what Create learned and returns whether each tier is cleared, conditional, or not cleared.

  • Sustain pairs with Run

    Sustain hands over the KPI thresholds that trigger a review and the autonomy expansions planned next. Run returns audit results, runtime indicators, and incident summaries.

  • Evaluate pairs with Evolve

    Evaluate hands over the realized-value record and any proposed tier changes. Evolve returns the management review decision on which tiers stay open.

The shared rule: when a use case needs a tier your organization hasn't cleared, you have two moves. Raise maturity or lower the tier.

Why AI strategy needs a framework

Most AI initiatives don't fail because the model was wrong. They fail because nobody decided what the model was for, and agents raise the stakes because they act on the answer.

80%+of AI projects fail by some estimates, twice the rate of IT projects without AI. The first root cause RAND names is misunderstanding or miscommunicating the problem AI is meant to solve.Source: RAND, 2024
$62Mspent over four years on MD Anderson's Watson oncology advisor. The IBM contract was extended 12 times, and the system never entered clinical use.Source: PCWorld, 2017
40%+of agentic AI projects will be canceled by the end of 2027 over escalating costs, unclear business value, or inadequate risk controls.Source: Gartner, 2025

What a RISE strategy workshop delivers

I run RISE as a one-day or two-half-day executive workshop. You leave with working artifacts, not a slide deck.

  • A use-case portfolio with an autonomy tier, value and feasibility scores, a sponsor, and four KPI slots on every row.
  • An AI Value Proposition Canvas for each use case, one printable page apiece.
  • Readiness scores from 0 to 5 across all ten categories, each one marked as opinion, observed, or measured.
  • A now, next, and later roadmap built straight from the portfolio.
  • A CARE handoff that lists the governance gates your highest-tier use case has to clear.

RISE framework FAQ

What is the RISE framework for AI strategy?
RISE is a four-phase framework for AI strategy: Research, Implement, Sustain, and Evaluate. It ranks AI use cases by value, feasibility, and least agency, ties each one to a metric, assigns an autonomy tier from T1 to T4, and measures the return in economic, intangible, and capability terms.
Is this the RISE prompt framework?
No. The RISE prompt template (Role, Input, Steps, Expectation) is a way to structure a single prompt for a chatbot. The RISE framework on this page is an organizational strategy framework for deciding which AI use cases to fund, how much autonomy each one gets, and whether the return justified it.
What does RISE stand for?
Research, Implement, Sustain, Evaluate. Research decides what AI is for. Implement puts use cases into production in stages. Sustain keeps them tied to business results. Evaluate measures the return and starts the next cycle.
How is RISE different from CARE?
RISE is the strategy framework and CARE is the security and governance framework. RISE decides what to build with AI and how much autonomy to grant. CARE writes the policies and scores the controls that make that autonomy safe. Research pairs with Create, Implement with Adapt, Sustain with Run, and Evaluate with Evolve.
What is a least-agency justification?
It's a short written case for why a use case needs an agent acting on its own instead of a person working with an assistant, and which tools and permissions were removed because the job doesn't need them. RISE requires one for every use case above T1.
Do I need CARE to use RISE?
You can run RISE on its own, and it still won't skip governance. Six CARE controls have to be at Tier 2 or better before any use case above T1 goes live: a governance framework with an accountable executive, acceptable use guidelines, a risk appetite with go and no-go thresholds, an AI system and agent inventory, human approval gates, and a kill switch with credential revocation.
Does RISE map to the NIST AI RMF or ISO/IEC 42001?
RISE doesn't map control by control. That mapping lives in CARE, which maps its controls to ISO/IEC 42001, the NIST AI RMF, the EU AI Act, and other frameworks and laws. RISE feeds CARE, so a RISE portfolio reaches those frameworks through CARE.

Put RISE to work on your AI portfolio

Tell me what you're trying to decide, and I'll tell you whether a RISE workshop is the right place to start.