Draft for Tamir's review. Not published.
Start from your problems, then pick tools
Vendors each propose their own product as the strategy. Start instead with your most expensive recurring problems, and ask where earlier warning or a faster decision would reduce them. That list is the strategy, and tools come after it.
Pick the first use case by measuring where work actually waits, using real cases rather than demos. Keep the first step advisory, so people stay the decision makers, and define the measure of success before you choose a vendor.
Name the owners and keep a register
Name the decisions each AI use would influence and an accountable owner for each, before procurement. Some approvals, such as clinical judgment or credit decisions, can't be delegated to the supplier. When two committees both claim oversight, assign decision rights by exposure and material change.
Keep a register of AI uses with purpose, data, owner and risk level. Write a short policy on what data may enter which tools and who is responsible for outputs used in work. Compare actual use with the approved scope, because departments switch on features beyond what was approved.
Depending on your seat
If you're on the board, ask for the first use cases with owners, measures and budgets, and release money as evidence arrives. Assign AI oversight to a committee or a named director, and decide which risk levels need its approval.
If you're the CEO facing a competitor's announcement, find out what it actually shipped. Announce only what you can show working within a quarter. If you run IT and employees already paste documents into public tools, roll out an approved tool with clear data terms first, then restrict the others.
What to check before you decide
- List your recurring losses with a cost for each, from operations and finance, and ask where better prediction would reduce them.
- Ask for the first use cases with owners, success measures, budgets and a date to report results.
- Name an accountable owner for each decision an AI use would influence, before approving procurement.
- Require a register of AI uses with purpose, data, owner and risk level, and decide which levels need board approval.
- Write a short policy on which data may enter which tools, with human responsibility for outputs used in work.
- Read each tool's terms on data retention, training on your data and where processing happens.
- Set a quarterly report on uses, results, incidents and regulatory matters, and compare it with approved scope.
Questions people ask
Hospital board receives AI proposals from departments, how should directors govern AI investments?
Set a short set of questions every AI proposal must answer: what it decides or advises, the evidence on patients like ours, data use and privacy approval, who is accountable for errors, and how results are measured. Approve proposals that answer them and monitor the measures. It depends on the hospital's clinical governance structure and on which proposals touch patient care directly.
Management presented an AI strategy to the bank's board, how do we approve direction without a blank check?
Approve the direction and attach a governance frame: which use cases come first and why, what each must show before the next is funded, who owns risk and model governance, and what the board hears quarterly. Spending follows evidence from the first use cases. It depends on the bank's model risk and data governance maturity and on which use cases touch customers.
Management announced an AI first strategy, how does the board oversee the risks without blocking it?
Ask for three things that let management run and the board see: a register of AI uses with risk levels, a policy on data and customer-facing use, and a quarterly report on results and incidents. Oversight of the register beats approval of every use. It depends on which uses touch customers, employees or regulated decisions.
Employees use AI tools with no policy, what should the board require management to put in place?
Require a short policy on what data may enter which tools, approved tools with proper terms, human responsibility for outputs used in work, and training; then a report on use and incidents. The policy should enable use with limits rather than ban it. It depends on which data the company handles and on which tools are already in use.
Should a hospital board intervene when departments deploy AI outside approved scope?
Require management to reconcile actual use with approved authority. The response depends on consequences, existing safeguards, and whether qualified governance owners can justify the expanded role.
Who should own AI oversight when financial risk committees overlap?
Assign decision rights by material change and exposure rather than by technology label. Oversight depends on clear ownership, escalation, and evidence shared across relevant risk disciplines.
Board wants an AI strategy for our plant, vendors each pitch their product, how do I build a strategy that's ours?
Start with the plant's three most expensive recurring problems, such as unplanned downtime, quality losses or energy use, and ask where better prediction or faster decisions would reduce them. That list is the strategy; tools come after. It depends on which problems have data behind them and on who in the plant would own a change.
A competitor announced an AI product and customers are asking what we have, how do I respond without rushing something fake?
Find out what the competitor shipped versus announced, because the two often differ, and ask your customers what they actually want from AI in your product. Then announce what you can show working within a quarter, even if small. It depends on whether the competitor's product is live with customers and on what your customers value.
Who should own an AI initiative that crosses clinical and operational decisions?
Name the decisions and accountable owners before choosing technology. Progress depends on separating clinical judgement, operational use, data responsibilities, and the authority to approve each boundary.
Employees already use public AI tools with company data, how do I choose and roll out an approved AI assistant quickly and safely?
Start with the data terms and the integration with your existing identity and document controls, because most tools do similar things and differ on what they do with your data. Roll out to a few teams with clear rules, measure use and then expand. It depends on where your sensitive data lives and on which tools your identity and compliance controls can cover.
Insurer wants AI in claims, where should we start among document reading, triage, fraud scoring and customer communication?
Start where the claims process actually waits, which you find by measuring time per step on real claims rather than by vendor demos. The safest first steps keep a human decision in the loop and have a measurable before and after. It depends on where your claims spend their time and on what data each step has.
Our low code program produced dozens of unmanaged business apps with customer data, how do we govern without killing it?
Inventory the apps, rank them by data sensitivity and business dependence, and bring only the top tier under IT controls such as ownership, access, backup and review. Set simple rules for new apps, with a fast path for low-risk ones. It depends on how many apps hold personal or financial data and on what the platform offers for central control.
How I can help with this decision
- Ask or talk (Free)
- I give my view on the oversight frame that lets management move and gives you what you need, and which first use case deserves the closest look.
- Review (Pay if it was worth it)
- I write an independent assessment of the strategy, its first use cases, the vendor proposals and the governance. I recommend what to approve, under which conditions, and the register, policy and reporting to adopt.
- Retain (When it makes sense)
- I stay available to review the periodic AI report, higher-risk uses and the next funding decisions as they come.