Business transformation. Built to work.
+381 21 472 03 88office@positive.rs
Artificial intelligence

You Have AI, But Do You Have a Strategy?

Many companies already use AI but cannot measure its value. Learn how to review tools, align them with business goals and create a sustainable plan.

Illustration of artificial intelligence and business AI strategy planning.
In this article13 sections

Many businesses already use artificial intelligence. Employees work with AI assistants, departments experiment with chatbots, and some workflows use automated document analysis or data processing. Yet buying and activating tools does not tell us whether the organisation is more productive, reliable or profitable.

In its article “You Have AI, But Do You Have a Strategy?”, first published on 6 February 2026, Positive highlighted the difference between owning technology and building a system that produces measurable business value. That original perspective guides this expanded edition: if you already use AI, a strategy helps you identify what works, what needs to change and which experiments are no longer worth funding.

What does an AI strategy mean when AI is already in use?

An AI strategy connects specific uses of artificial intelligence with business objectives, accountable people, available data, acceptable risks and measurable outcomes. It is not a subscription inventory or a list of the newest models.

When the organisation has already adopted AI, planning starts with an honest review. Which teams use which products, who pays for them, why were they introduced, who verifies the results and how is sensitive information handled? Only when those questions are answered should the company decide on additional integrations.

The useful question is not “Which AI tool should we buy next?” but “Which business problem are we solving, and how will we recognise success?” That distinction changes how decisions are made.

When AI becomes a cost rather than an operational advantage

AI subscriptions can gradually become disconnected expenses. One team pays for drafting assistance, another for a separate analytics platform, and a third develops a chatbot that cannot access the same approved information. The company acquires technology but does not create a connected way of working.

This does not always mean the tools are bad. Often the sequence of decisions was wrong: products were selected before processes were understood, and adoption was measured in logins or generated messages rather than verified outcomes.

Assess licence costs, integration and maintenance, employee time and the value of completed, approved work separately. A few minutes saved during drafting may be outweighed by hours spent correcting an inaccurate result. That total picture matters more than vendor demonstrations.

First, create an inventory of current AI tools

Keep the inventory practical. For each product record the service name, team using it, purpose, owner, recurring price, type of data processed and how the output is checked.

Distinguish centrally approved business accounts from privately opened services that staff have started to use for work. Informal adoption can reveal genuine unmet needs, but it may also create uncertainty about confidentiality and security.

Once the list is assembled, ask: are two platforms solving the same task? Are paid seats rarely used? Is a useful workflow dependent on one employee? Are outputs checked before customers receive them? These answers are more valuable than the total number of AI initiatives on a slide.

Start from a business problem, not a product demo

A promising AI project begins with a problem that can be described clearly. Preparing a quotation may involve excessive copying; employees may struggle to find current instructions; or enquiries may arrive through disconnected channels without a shared record.

Each problem needs a baseline. How long does the process take? How frequently does it occur? How many errors arise, and what is the impact on customers or employees? Without baseline information, claims of improvement remain speculative.

Sometimes the best first move is to simplify the process, consolidate knowledge or clarify responsibilities. AI should support a well-defined workflow rather than automate confusion.

How to prioritise AI use cases

Evaluate potential use cases against four criteria: expected business value, frequency of the task, readiness of the required data and the consequences of error. A high-impact concept is not automatically the best initial pilot if the input information cannot be trusted.

Tasks such as drafting standard reports or finding approved internal procedures are often easier to test than allowing a model to make autonomous legal or financial decisions. The difference is how well the outputs can be checked and what happens if they are wrong.

Select a small number of priorities. For each one define the conditions under which you would expand, redesign or stop it. A credible strategy includes decisions not to invest.

KPIs and ROI: measuring AI without inventing benefits

A key performance indicator (KPI) reflects progress towards an agreed goal. Relevant measures might include time to resolve an enquiry, accuracy of a categorisation task, the percentage of answers with verified sources or the time from request to approved output.

Return on investment (ROI) should account for more than licence fees. Include data preparation, integration, training, human review, operational maintenance and safeguards. Benefits should be based on measured changes that can reasonably be associated with the pilot.

Avoid promises of a guaranteed productivity improvement. Compare equivalent tasks before and after implementation, explain the test conditions, record failures and identify what the evidence does not prove.

Who owns the AI programme?

A strategy without accountability quickly becomes a presentation rather than a management tool. Every use case needs a business owner, a data owner, a technical or security reviewer, a person approving important outputs and someone responsible for measuring results.

Smaller companies do not need a large dedicated AI department. Several responsibilities can be carried by a small cross-functional group, provided the decision-making is clear and someone has authority to pause a risky system.

NIST's AI Risk Management Framework organises AI risk work around Govern, Map, Measure and Manage. That approach offers a way to link technical capability with responsible oversight instead of treating governance as a separate document.

Data protection and security belong in the strategy

When employees share documents, customer questions or internal information with an AI product, the company needs to understand how that information is processed, who can access it and which contractual and legal obligations apply.

Review data categories, retention rules, approved accounts, access logs, CRM permissions and the response to significant model errors. Sensitive actions should require human approval or a reliable independent authorisation step.

The OECD AI Principles emphasise accountability, transparency, robustness and respect for people. In practice these ideas should become instructions employees can follow: which services are approved, what data they may use, when outputs require review and where incidents are reported.

AI cannot magically repair poor processes

Automation is not useful for its own sake. If information is outdated, responsibilities are unclear and approvals disappear into message threads, adding AI may speed up inconsistent work rather than improve it.

Consider a sales team whose client information is stored in several disconnected systems. An AI assistant may draft a persuasive proposal, but without reliable records it could quote an incorrect price or promise an unavailable service.

The better sequence is to establish a trustworthy source, define who owns the information and then automate a task that can be verified. Strategy is not an obstacle to innovation; it protects investment from becoming a series of demonstrations that never enter daily operations.

Why strategy matters even after tools have been purchased

An existing AI deployment is precisely when a strategy can add value. It can reveal duplicated subscriptions, connect tools with actual workflows and establish priorities. Some products may remain, others may be replaced and a few initiatives may be discontinued.

A review may also show that a task does not need a generative AI model. Straightforward rule-based automation can sometimes be cheaper and more predictable. Selecting it is not a failure of AI strategy; it is evidence of a problem-led decision.

It also helps to distinguish an individual AI assistant, a workflow automation and an AI agent allowed to use external tools. Read How AI Agents Change Business for a practical overview.

An illustrative 90-day review plan

Days 1–30: inventory AI use, costs, access and data categories. Identify duplicated services, operational friction and the processes that could benefit most. Select two or three candidates for controlled evaluation.

Days 31–60: define baseline KPIs and testing conditions. Assign owners, approve permitted data, establish output checks and agree in advance what successful results would look like.

Days 61–90: compare outcomes and total costs. Decide what to expand, redesign or retire. Document how reference information, quality control and periodic risk reviews will be maintained.

The timeline illustrates one way to organise the work; it is not a promise that every company can complete an AI transformation in three months. Complexity depends on data, processes and the organisation's level of readiness.

Connecting management, employees and IT teams

Leadership should set the objectives, resources and risk boundaries. Employees describe real tasks and bottlenecks. IT and security teams assess integration, data access and safeguards. A useful plan combines these perspectives.

A better conversation with staff does not begin with fear about replacement. It starts by asking which activities repeat, which information is difficult to obtain and which tasks could be done with higher quality. That reveals opportunities a subscription report cannot show.

Policies should be understandable. Anyone expected to use AI should know which service is authorised, which tasks are appropriate, what information may be shared and who approves the final output.

Conclusion: you have AI, but does it work for your business?

AI strategy is not a luxury reserved for large enterprises. It helps connect existing tools with measurable outcomes, reduce unnecessary experiments and establish responsibility for the results.

The essential question from Positive's original article remains: is your AI doing the job it was introduced to do? If that question cannot be answered, begin with a review of current use, costs and outcomes rather than buying the next subscription.

To align AI opportunities with business goals, see Cybercompany's AI strategy for businesses or contact Positive.

Frequently asked questions

What is an AI strategy?

An AI strategy is a plan for connecting artificial intelligence to business objectives, workflows, data, accountability and performance measures.

Does a company already using AI need a strategy?

Yes. It is particularly useful when tools are fragmented, costs grow or outcomes are uncertain, because it helps review current use and define priorities.

Which AI KPIs should a company track?

Track workflow-specific measures such as time to approved output, accuracy, corrections, resolution time and total costs, using a baseline for comparison.

How should AI return on investment be estimated?

Compare measured benefits with licences, integration, data preparation, training, verification and maintenance costs. Without a baseline, the estimate is uncertain.

Should every workflow use generative AI?

No. Some problems are better solved by clearer processes, standard software or simpler automation. Choose AI when it addresses a justified need with suitable controls.

Where should an AI strategy begin?

Begin with an inventory of current tools, tasks, costs and data access. Then choose a few priorities, assign owners and measure results before expanding.

Sources

Only essential browser storage is currently used. Analytics and marketing tools are not enabled.

Remembers the theme and your privacy settings.

Read the cookie policy