Do you need an AI strategy? A plain-language test for small and mid-sized businesses
A small business needs a page of decisions, not a strategy document. Seven questions that tell you which one you are, and what the page contains.
The short answer
If you run a small or mid-sized business, you probably do not need an AI strategy in the sense of a long document with a vision statement. You almost certainly need something else that often goes by the same name: a short, written set of decisions about how your company uses AI, what it will not do with it, and who decides.
The difference matters. The document version gets written once and ignored. The decision version gets used every time someone asks “can we use this tool for that?”
The seven-question test
Answer honestly. Each “yes” is a reason the page is overdue.
- Are staff already using AI tools for work? Drafting emails, summarising documents, writing code. If yes, decisions are being made without you.
- Has customer or employee data ever been pasted into a public AI tool? If you do not know, the answer is yes.
- Has a vendor switched on an AI feature inside software you already use? CRM, accounting, email, support tools all do this now.
- Has a customer or partner asked about your use of AI? Tenders and security questionnaires increasingly include it.
- Have you said no to an AI project without being able to explain why? Or yes?
- Is a repetitive process costing hours every week that nobody has looked at? That is where the first project hides.
- Would two managers give different answers to “what is our position on AI”?
Three or more “yes” answers: write the page this month. One or two: write it this quarter. Zero: you are either very small or not being honest, and either way it is still an afternoon well spent.
What the page contains
| Section | What it says | Example of a decision |
|---|---|---|
| Where we use AI | The processes and tasks where AI is allowed or encouraged | Drafting replies, summarising meetings, sorting inbound email |
| Where we do not | Tasks that stay fully human, with the reason | Hiring decisions, pricing, anything a customer would expect a person to have judged |
| Data rules | What may never leave the company through an AI tool | Customer records, contracts, health or financial data, source code |
| Approved tools | Which tools are in, with which accounts and settings | A company account with data training switched off, not personal logins |
| Who decides | One person who approves new tools and features | Named, with a simple request form |
| Review date | When the page is revisited | Every quarter |
From the page to the first project
The page is not the goal. It exists so the first project can be chosen with confidence and the second one can build on it. The first project should be a dull, frequent, measurable process. We wrote up five processes worth automating first for exactly that step.
What this means for you
Take the seven-question test. If you scored three or more, block an afternoon, use the table above as the outline, and write the page. Keep it to one page. Then pick one boring process and automate it. That is an AI strategy for a business your size, and it beats any document that starts with a vision statement.
Frequently asked questions
Is an AI strategy only for large companies?
Large companies need governance and committees. Small companies need clarity. The strategy for a twenty-person business is one page: where AI is used, where it is not, which data may never go into a public tool, and who says yes to new tools. That page prevents most of the expensive mistakes.
What is the most common mistake?
Having no position at all while staff already use AI tools with customer data, and vendors switch on AI features inside software you already pay for. The strategy is then written by accident, by other people. Writing it down yourself is the whole point.
Do I need a consultant for this?
For the first page, no. The seven questions below and an honest afternoon are enough. A partner helps when you move from the page to the first project, because that is where access, data and integration questions appear.
How does this relate to automation?
Automation is what you do; strategy is the list of what you will and will not do, and why. Many businesses start with one automation and write the page afterwards, once they see what questions it raises. That order is fine, as long as the page gets written.