A practical sequence for turning an AI mandate into one owned, testable, and useful operating decision.
Adoption is not operating coherence
AI adoption is now material, but adoption alone says little about whether a company can make a recurring decision reliably. In May 2026, the U.S. Census Bureau reported that 17–20% of U.S. businesses were using AI, with use reaching 32% among businesses with 100–249 employees. A separate Census working paper found that 57% of adopting firms used AI in three or fewer business functions.
That pattern is understandable: experimentation begins at the edge of the organization. The risk appears when a local tool starts influencing staffing, pricing, forecasting, or customer commitments without shared definitions, traceable evidence, or an accountable reviewer.
Start with a decision contract
Before selecting a model or vendor, write a compact contract for the decision. It should make the operating consequence explicit enough that two people can disagree productively about the evidence or threshold.
- Who is accountable for the decision?
- What action can follow, and what action is prohibited?
- Which source records and definitions are authoritative?
- How current must the evidence be?
- Which exceptions require review or escalation?
- What baseline will show whether the intervention helped?
Separate calculation from interpretation
Reliable systems distinguish deterministic work from probabilistic work. Revenue arithmetic, eligibility rules, access checks, and reconciliations should remain explicit and reproducible. AI may help classify an exception, retrieve supporting context, or summarize a review packet—but it should not silently replace a calculation that can be tested exactly.
This separation makes the system easier to evaluate. A wrong total is a data or logic defect. An incomplete summary is a model-performance defect. Different failures need different owners, tests, and fallback behavior.
Govern the use case, not the slogan
The NIST AI Risk Management Framework organizes work through Govern, Map, Measure, and Manage. Applied to a small firm, this does not require a large governance office. It requires enough specificity to know the context, affected people, evidence boundary, performance threshold, reviewer, monitoring cadence, and response when the system fails.
Governance should scale with consequence. A draft internal summary and a staffing recommendation do not deserve the same control pattern. The useful unit of governance is the named use case.
The order of operations
A durable sequence is decision, definitions, data, workflow, interface, control, then AI when justified. Each step removes a different ambiguity. Skipping ahead makes the prototype look faster while moving the unresolved risk downstream.
The first deliverable should therefore be a reliable decision loop, not an AI feature. If AI improves the loop under a defined evaluation, keep it. If it does not, the underlying operating system should still work.