What an AI strategy for a small business actually contains
Six decisions, one owner, three projects and a review date. What a small business AI strategy contains, and what belongs in procedures instead.
The short answer
An AI strategy for a business of ten to two hundred people is a small set of decisions that everyone can find and apply. It contains six things: where you use AI, where you do not, which data never leaves the company, which tools are approved, who decides, and what you will build next. It has an owner and a review date. Everything else is either a procedure behind the page or a document you do not need.
The six things, and why each is there
| Element | What it decides | Why it is on the page |
|---|---|---|
| Where we use AI | The tasks and processes where AI is allowed or encouraged | So people stop guessing and start using it where it helps |
| Where we do not | Tasks that stay fully human, with reasons | So nobody automates a decision that needed a person |
| Data rules | What may never go into an external tool | So the expensive incident does not happen |
| Approved tools | Which tools, on which accounts, with which settings | So company data is not scattered across personal logins |
| Who decides | One person and a way to ask | So new tools and uses get a fast, consistent answer |
| Next three projects | What will actually be built, with owners and months | So the strategy produces something instead of describing intent |
Plus two lines: the owner’s name and the next review date.
What does not belong on the page
- A vision statement. Nobody reads it and it decides nothing.
- A market analysis. Useful for a board deck, useless for daily choices.
- A technology roadmap. Models and tools change every few months; the page should say how you choose, not which model.
- Detailed procedures. How to request a tool, how to review an AI project, what to do after an incident. These matter, and they live behind the page, referenced by one line each.
The procedures behind it
Keep them short, keep them separate, reference them from the page:
- Requesting a tool or a new use. A two-line message to the owner, what and why, answer within a set number of days.
- Handling an AI incident. Wrong output reached a customer, data went where it should not, a tool behaved unexpectedly. Who is told, what is stopped, what is recorded.
- Reviewing a project. Before it starts: the question it answers and how success is measured. After a month: what the numbers say and whether it continues.
- The quarterly review. What changed in the tools, what changed in the business, which boxes on the page need updating.
What this means for you
If you have no AI strategy, write the six decisions on one page this month; we published the template we use. If you have a long one, extract the six decisions from it and put them on one page that people can actually find. The rest becomes procedures or gets archived. Either way, the test is the same: can anyone in the company answer the daily questions in five minutes.
Frequently asked questions
How is this different from an AI policy?
The policy is the rules part: what is allowed, what is not, which data stays inside. The strategy contains the policy and adds direction: where you intend to use AI, what you will build next, who owns it. For a small business they fit on the same page, with the policy as three of the six boxes.
Do we need a separate document for compliance?
The strategy records the decisions compliance later asks about: purposes, data, accountability, human oversight. Specific obligations, such as those for higher-risk uses under EU rules, add procedures rather than a new strategy. Keep the decisions on the page and the procedures behind it.
Who owns the strategy?
One named person with the authority to say yes and no, usually the owner or an operations manager. Not a committee, not IT alone, not an external party. The owner can delegate the work; the decision stays with them.