The Executive Summary Subscribe
AI

Building an AI strategy

Building an AI strategy
The only diagram you need

Think of bringing AI into your organisation like inviting an alien to come into the workplace. They're happy to do the work, but if they don't know what good looks like, you're going to get some odd results.

So will your people. Give them an AI tool and say 'do AI, please' and they'll put it in the drawer to look at another day. File under 'looks a bit weird'.

Watch your AI productivity flatline.

As a result of this newsletter, I've had a lot of requests from readers on how to build an AI strategy. I get asked to speak at away days, dinners and for company workshops. (You can check them out here.)

My journey on this started nearly two years ago as people stopped asking me "what's our value proposition?" and instead "what's our AI proposition?", which requires a complete shift in thinking and capability.

So I'm sharing my model with you to help you accelerate your AI journey and I hope it's useful to you.

Before I start I will just say this. Business problems have not changed - but AI has amplified some of them.

The AI strategy fits on a napkin

Draw a triangle. Safety sits at the bottom, productivity sits in the middle and value sits at the top.

Boards often want to start at the top because they think that is where the money lives. But every board that starts at the top ends up back at the bottom six months later with a mess to clean up and a bill for the privilege.

Safety is the foundation

Before bringing a wild dog into your house, you would ensure you had a plan. There would be locked-down areas, a training plan and you would do your research on how this dog behaves.

Wild LLM (large language model) AI is a bit like this, but companies are not putting the safeguards up.

If you knew the cyber threats coming at your organisation, you would put at least 50% of effort into safety. It is terrifying.

Once you know what you are protecting and from what, you can put the lockdowns in place, set the governance and appoint a named person who owns it.

(You need an owner for AI safety, productivity and value.)

Safety splits into two halves.

Data

You need to know where your data goes, which tools your people are pasting it into and keep it out of the big public models where it gets eaten up and never comes back.

Samsung learned this within twenty days of allowing ChatGPT at work, when engineers pasted proprietary semiconductor source code and a confidential meeting transcript into it on three separate occasions, forcing a company-wide ban.

Nobody was malicious. They were trying to do their jobs faster, which is exactly why policy has to come before enthusiasm. Walk your floor and ask people which AI tools they used this week, and you will likely find the same pattern.

There is a bank in the City which allowed its employees to upload gigabytes of customer data to OpenAI without knowing it had broken the rules. 

Get on top of this now so you don't look stupid later.

Cyber

I spent years covering security as a journalist and the threat coming from AI is bigger than anything I covered in that time.

Attackers now have the same tools your staff do, except theirs are pointed at you.

Voice cloning that puts your CFO on the phone asking finance to move money. Spear phishing written and sent by machine at a scale no human gang could manage. Few boards have taken this seriously yet, mostly because the wave has not hit them personally.

On top of which, AI gives hackers productivity and scale never seen before. The threat is huge.

Productivity

Playing with AI looks like activity and feels like progress, but outcomes show up in numbers.

JPMorgan banned consumer chatbots outright, built its own internal platform instead and rolled it out to over 200,000 employees, who now save around four hours a week each on research, drafting and document work.

Octopus Energy gives its service staff an internal assist tool that drafts customer emails for a human to check and send, and those messages score higher on satisfaction than unassisted ones while agents get their time back for complex cases.

Both are staff tools rather than customer-facing products, which is the point of this layer.

Getting there rests on two things that get skipped because they seem too basic to bother with.

The first is a shared language.

You have people in your business who could pass as AI specialists and people who cannot write a prompt, and that gap is a bigger problem than it looks.

Think back to the early days of the office computer. You did not need everyone to be a Word wizard, but you did need everyone to understand what the machine was for, so that when the moment came they could use it.

Every person needs to understand what these tools are, what they can and cannot do and what needs to be true for them to be useful, even if they never touch them daily.

Champions surrounded by colleagues who cannot follow the conversation are just specialists in a silo, and a company that speaks two languages about AI makes decisions in neither.

Level everyone up as early as you can. This is the step people zoom past, and it costs them everything that follows.

The second is segmentation

Each department needs to work out what it has, what it should build and what effort each item takes. That list becomes a backlog and a backlog means productivity time going into building things, which means someone has to watch how that time is allocated.

Whether you delegate that to team leaders or keep someone across the whole picture is your call, but somebody has to see it.

This is where department leaders earn their money, because they need to understand the effort required to get a result before they ask for it. A leader who wants an outcome without grasping the work behind it sends teams down rabbit holes, and rabbit holes are where AI budgets go to die.

So start with the mundane.

Take tasks off people. The copying and pasting, the reformatting, the chasing, the summarising, the report that takes a day to assemble and thirty seconds to read.

Removing that work is the fastest win available, it builds belief across the workforce and it frees the people you hired for their brains from moving text between systems.

Value comes last

The top of the triangle is value for customers, employees and investors.

Nobody trusts an AI product from a company that has not made itself safe, and nobody should trust AI advice from a company that has not done the transformation to itself first.

You have to go through it to understand it.

The scars are the qualification. When you have levelled your workforce, cleared the mundane and learned what these tools do well and badly inside your own walls, you will see customer opportunities that were invisible before and you will be able to build them without embarrassing yourself.

Octopus shows what the top looks like when you climb in order. Its new customer assistant Arlo just came through an early trial scoring 76% customer satisfaction against 72% for comparable human responses.

The detail worth noticing is the guardrails. Arlo handles routine enquiries only, never touches vulnerable customers or sensitive cases and always leaves a route to a person.

That is a company that did safety and productivity first, then earned the right to put AI in front of customers. Compare that with Air Canada's bot confidently inventing policy and the triangle becomes a P&L decision.

Where you probably are right now

Put businesses on an AI maturity ladder and the climb has five stages.

  • Initial means AI is happening to the company rather than in it. Projects sit in silos, individuals experiment in corners, there is no policy and no shared tooling and nobody could tell you the company's position on AI because there isn't one.
  • Repeatable means individual teams can reproduce their own wins, but the knowledge stays local, so what marketing has learned finance has no idea about, and success depends on specific people rather than the company.
  • Defined is the prize of this whole article, the stage where AI stops being personal habit and becomes company process, with a written safety standard, a named owner, a shared language, a prioritised backlog per department and real decisions made about what to pursue and what to leave alone.
  • Managed and measured means you now measure what you standardised, with ROI tracked per use case, time allocation visible and department targets carrying numbers, so you know what AI is worth to the business rather than believing it.
  • Optimised means the measurement feeds improvement on its own, so the company retires what underperforms, doubles down on what works and adapts as the frontier moves.

The companies in this article sit at readable points on that ladder. JPMorgan is operating at Managed, tracking hours saved and value per use case across 200,000 people.

Octopus climbed through Defined and Managed internally before Arlo ever met a customer. Air Canada and Klarna tried to skip from the bottom rungs to the top, and the ladder does not allow it.

Notably, a company's HR department could be further ahead, say, than its marketing department, but without communication, this will be an unknown.

Getting out of chaos

The businesses I see mostly sit at Initial, and the wider data agrees. MIT research found the majority of enterprise AI pilots producing no measurable return, which I wrote about in the disillusionment piece alongside the companies rehiring the people they cut.

But smaller organisations can change this really fast.

The pattern in both stories is the same: tools handed out, expectation never set, value never defined. If that describes your company, you are in good company, and the fix starts with people rather than technology.

Get everybody in the room

The first move is to bring the leadership team, and others if needed, into a room to look at AI properly from the ground up.

They need to properly look at what AI is and how it affects the business. Which parts need it most? What are other organisations doing? What should we be doing, and just as important, what should we leave alone?

It's also important to know where the frontier now and where is it heading next?

Before the workshop do the homework and then follow this sequence.

You need to run something monthly with your safety, productivity and value AI leaders who should be reporting metrics, wins, risks and decisions to leadership.

Outside experience helps enormously along the way (I would say this), because someone who has watched dozens of companies attempt this can save you from the mistakes of the first forty.

The objective is to get you from siloed to Defined. To segment, understand and prioritise the business's focus on AI while giving each department targets to innovate without the day-to-day suffering.

To have a company that speaks the same language, sees AI in different contexts for different departments and understands that safety and productivity first is the only path to customer value.

And to build the roadmap from reference points and knowing the way, rather than using the tools and hoping for the best. You will stay in Initial Mode that way.

Draw the triangle. Put safety at the bottom. Get everyone in the room and answer the above questions.

And if you want a hand with this, you know where to find me.

Bonne chance.

Dan x x

PS - Next week is the last week of The Executive Summary's awesome newsletters before a very nice summer break. If there's anything you want me to cover (and don't say Andy Burnham as it's too soon), just shout.

CEOs read The Executive Summary. Do you?

The AI and growth briefing for the people in the room when the decisions get made.