AI strategy in one page: the template we use
The one-page AI strategy we write with clients: six boxes, no vision statement. The template, an example, and how to fill it in one afternoon.
The short answer
An AI strategy for a small or mid-sized business fits on one page, because its job is to answer practical questions quickly: may we use this tool, for this task, with this data, and who says so. Below is the template we fill in with clients, box by box, in an afternoon.
The template
| Box | Question it answers | Example content |
|---|---|---|
| 1. Where we use AI | Which tasks and processes are AI allowed or encouraged in? | Drafting replies, summarising meetings, sorting inbound email, first-draft proposals, code assistance |
| 2. Where we do not | Which tasks stay fully human, and why? | Final hiring decisions, pricing changes, anything a customer would expect a person to have judged, legal advice |
| 3. Data rules | What may never go into an external AI tool? | Customer records, contracts, financial and health data, source code, anything under NDA |
| 4. Approved tools | Which tools, on which accounts, with which settings? | Company accounts only, data training disabled, list of two or three tools per purpose |
| 5. Who decides | Who approves a new tool or a new use, and how do you ask? | One named person, a simple request form, an answer within a week |
| 6. Next three projects | What will we actually build or automate next? | Email triage, quote follow-up, invoice intake, in that order, with an owner each |
How to fill it in, in one afternoon
- Invite the right people. A decision maker and two or three staff who already use AI tools. Ninety minutes.
- Start with box 4. List every AI tool anyone in the room uses for work today, on which account. This is usually the most surprising ten minutes of the session.
- Do box 3 next. Agree the data that must never leave the company through any tool. Keep it to five or six categories.
- Fill boxes 1 and 2 from what you learned. Where AI is already helping becomes box 1. Where anyone in the room felt uneasy becomes box 2.
- Name the person for box 5. One name, one way to ask, one response time.
- Pick three projects for box 6. Dull, frequent, measurable. Give each an owner and a month.
- Set the review date. One quarter out. Put it in the calendar before the meeting ends.
An example, filled in
A twenty-person service business:
- Where we use AI: drafting emails and proposals, meeting summaries, sorting the info@ inbox, translating client material for internal use.
- Where we do not: anything sent to a client without a person reading it, hiring, pricing, contract wording.
- Data rules: no client names with project details, no contracts, no financial data, no personal data of staff, in any tool outside the approved list.
- Approved tools: one assistant on company accounts with training disabled; one meeting summariser; the automation platform run by our partner. Anything else: ask.
- Who decides: the operations manager, via a two-line message, answer within five working days.
- Next three projects: inbox triage (October, owner: office manager), quote follow-up (November, owner: sales lead), weekly report (December, owner: operations).
What this means for you
Block an afternoon, invite the people who already use the tools, and fill in the six boxes. You will leave with a document that answers the daily questions, prevents the expensive incident, and points at the first three projects. That is a strategy, and it took less time than the meeting about whether to have one.
Frequently asked questions
Why one page? Is that not too simple?
One page is what gets read and used. The purpose is that anyone in the company can answer 'may I use this tool for that?' by looking at it. A longer document answers that question less well, not better. Detail lives in procedures behind the page, when needed.
Who should write it?
The owner or a manager who can make decisions, together with two or three people who already use AI tools in their work. Not a consultant alone, and not IT alone. The decisions have to be owned by the business; the practical knowledge sits with the users.
What if we do not know yet where AI fits?
Then box one starts with the small, safe uses everyone already has: drafting, summarising, sorting. Box six, the next three projects, is where you find out more, by picking one dull process and automating it. The page is allowed to be modest; it is not allowed to be vague.
How does this relate to compliance and the EU AI Act?
The page is where you record the decisions that compliance later asks about: what you use AI for, what data goes where, who is accountable, and where humans stay in control. Specific legal obligations depend on what you build and your sector; the page makes it easy to answer those questions when they come.