Your board wants an AI strategy. Here’s the shortest honest one.
At some point in the last year, a sentence appeared in your board minutes: “We need an AI strategy.” Everyone nodded. Nobody was assigned. And the sentence has been reappearing, slightly more impatient, ever since.
The trouble is that the sentence has no natural owner in most established companies. The IT function reads it as infrastructure, the ops director reads it as someone else’s job, and the person who wrote it mostly means “I keep being asked about this and would like to stop being embarrassed”. So the default outcome is one of two theatres: a vendor arrives with a deck and a pilot that mostly demonstrates the vendor, or an internal document gets written that lists capabilities — we could do chatbots, we could do forecasting — and decides nothing.
Here is the alternative. It is short because the length was the problem.
What a strategy actually is
A strategy is a set of decisions someone can be held to. It says what you will do, what you will not do, who owns it, what it costs, and how you will know it failed. Anything that cannot disappoint you is not a strategy; it is literature.
By that bar, an honest AI strategy for a normal company — not a lab, not a startup, a business with customers and margins — is five questions answered in writing. An afternoon for the first draft. The hard part is not the writing; it is that each answer closes a door someone enjoyed keeping open.
The five questions
1. Where does the business actually leak time or money? Not “where could we use AI” — that question produces a technology looking for a home. List the processes: the quote that takes four days, the inbox two people triage, the report assembled by hand each month, the customer questions answered identically two hundred times. Rank by cost. AI is only interesting where this list is expensive, and the list is worth writing even if you never touch AI.
2. What data do we have, and may we use it? Most AI ambition dies here, so find out early. Where does the relevant data live, how clean is it, and — the question UK boards keep skipping — are you allowed to process it this way? Customer data, employee data, anything personal: if nobody has written down the lawful basis and what your contracts and privacy notices permit, do that before any vendor conversation. “We’ll check compliance later” is how pilots meet legal departments, and pilots lose those meetings.
3. What is our build-versus-buy default? For almost every established SME the honest default is buy — or more precisely, adopt: the AI features appearing inside tools you already pay for, and the mature products that solve one process well. Building bespoke is justified only where the process is genuinely yours — the thing competitors can’t copy — and where you accept you’re signing up to own software, with the maintenance that implies. Write the default down so every future proposal has to argue against it, not relitigate it.
4. What is the one pilot, and when does it die? One. Not a portfolio — a portfolio of pilots is a portfolio of meetings. Pick the top item from question one that survives questions two and three, and give it three things in writing: an owner whose actual job improves if it works, a number it must move, and a date on which it is either extended or killed. A pilot with a kill date is an experiment. A pilot without one is a subscription.
5. What will we not do? The most useful section and the one no deck contains. We will not put customer personal data through consumer AI tools. We will not build a chatbot because a competitor has one. We will not sign multi-year AI contracts this year. We will not automate the conversations where a human is the product. The not-doing list is what makes the rest credible — it proves choices were made, and it is the part the board can actually police.
A worked sketch
To make it concrete, take an invented but ordinary company: a forty-person regional distributor. Question one’s list, ranked by cost, comes out as: quotes assembled by hand from three systems (about four hours each, twenty a week), an inbox where two coordinators triage delivery queries, and a monthly management report that eats a day. Question two finds the quote data lives in a well-kept ERP the company controls — usable — while the delivery inbox is full of customer personal data, so anything touching it needs the privacy homework done first. Question three sets the default to buy. Question four therefore picks the quotes: the pilot is “draft quotes for human approval”, owned by the sales manager, target of halving quote turnaround, reviewed on a date three months out. Question five rules out: customer data in consumer AI tools, a public-facing chatbot this year, and any contract longer than twelve months.
Two pages. Nothing visionary in it — and for precisely that reason, next quarter the board can ask exactly one question (“did quote turnaround halve?”) instead of the one they keep asking now.
What this looks like on paper
Two pages, at most. The process list with costs against it. The data answer, including the legal one. The default and its exceptions. One pilot: owner, number, date. The not-list. Signatures.
Compare that with what usually gets produced, and notice the difference is not polish — it is that every line can fail. The forty-slide version cannot fail, which is why boards keep asking for the strategy they were already given: nothing in it committed anyone to anything, and everyone in the room could feel it.
Who should write it
Someone with three properties: technical enough to call nonsense on both the hype and the fear; close enough to the business to rank the process list honestly; and — this is the one that gets missed — not selling the answer. A vendor cannot write question three. An agency that builds things will struggle with “buy”. An enthusiastic manager with a ChatGPT subscription can absolutely write the first draft of question one, and should.
If nobody inside the building holds all three properties, borrow the judgement for a few days rather than hiring for it — this is a decisions problem, not a headcount problem, and a fixed-scope AI Readiness Review is one way to borrow exactly that much of it. What matters is that the person who writes it would be comfortable being wrong in public, because the document has their name on it and a date twelve months out when everyone can check.
Taking it to vendors
The document earns its keep the first time a vendor visits. Instead of receiving their deck, you hand them your page: here is the process (question one), here is the number it must move and the date it’s judged on (question four), here is what we won’t do (question five). Then three requests: show us this working on a process like ours, not a demo of your platform; give us a reference customer with this problem, whom we may ring; and price the exit — what leaving you costs and what we take with us.
Watch what happens. Vendors with substance relax, because specific buyers are their easiest deals. Vendors selling atmosphere start renegotiating your questions — the number is “hard to isolate”, the reference is “under NDA”, the pilot really needs a year. Every minute of that renegotiation is the document working. You have converted a sales meeting about their technology into a procurement meeting about your process, which is the only meeting worth having.
Build in the expiry date
One more clause worth adding to the document: this strategy expires in twelve months. That isn’t an admission of weakness — it is the only honest way to plan around a technology whose costs, capabilities and vendors change quarterly. A three-year AI strategy is a work of fiction with a long shelf life; a one-year strategy with a renewal date is a working document.
The renewal is one meeting. Re-rank the process list from question one — costs move. Re-check question two against whatever data you’ve since accumulated or promised away. Ask whether the buy default earned any exceptions. Read the pilot’s number against its date, and either write the next pilot or write down why not. And prune the not-list: some of last year’s refusals will have become sensible, and noticing that on schedule — rather than when a competitor does — is most of what “keeping up with AI” actually requires of a normal company.
That is the whole trick, really. The board doesn’t want an AI strategy. The board wants to stop being anxious about a sentence. Five answered questions, with names attached, do that — and have the incidental side effect of being an actual plan.
Drizzlelabs is an independent software studio in Bristol that ships its own AI-assisted tools — the reasoning behind them is on this blog, and the about page has the rest.