AI strategy for business: where to start and what it should contain
An AI strategy should answer three questions: where in the business AI does the most good, in what order you tackle it, and who owns each piece. Everything else is background. Yet a lot of AI strategies end up as a thirty-page document that describes the technology in detail and changes nothing about how the work gets done.
This guide covers what an AI strategy for business looks like when people actually use it: where the value tends to be, what the strategy should contain, how to prioritise, where AI agents and automation belong, the governance minimum for a UK company, and the mistakes that leave it on the shelf. The short answer: a good strategy is a prioritised work list with owners, not a vision statement.
The UK's AI strategy gap: plenty of usage, less of it at work
Most UK companies do not have an adoption problem in the usual sense. Their people already use AI, many of them daily. What is missing is a decision about where that usage should go. Anthropic's Economic Index gives a useful snapshot. In May 2026 the UK scored 3.35 on the Anthropic AI Usage Index, which compares a country's share of Claude usage with its share of the working-age population (1.0 is proportional). That put the UK 16th of 121 countries.
Yet only 39.0% of UK usage in that snapshot was work, against 43.4% globally. Personal use (43.5% against 40.2%) and coursework (17.5% against 16.5%) were both above the global figures. UK users also leaned more towards collaborating with the AI than handing tasks over to it: 55.2% of usage was augmentation against 51.4% globally, and 44.8% was automation against 48.6%.
The index covers one product at one point in time and does not explain the numbers. But the shape matches what we see inside companies: individuals are fluent, and the organisation has not decided what to do with that fluency. Sweden shows the same pattern (an index of 2.98, 22nd, with 38.1% of usage at work), which we wrote up in the Nordic AI usage gap. Turning personal habit into how the company works is what an AI strategy is for, and every quarter of delay adds up; we have set out what not deploying AI costs in 2026.
AI for business: where the value actually is
When people talk about AI for business they tend to picture big projects: a custom model, a customer-service chatbot, a new product. In a company of 20 to 200 people the value is usually somewhere less glamorous, in the everyday work that many people do every week.
Take a 70-person engineering consultancy in Bristol. The partners assume AI means a bid-writing tool. The bigger win usually sits with the project managers: weekly client updates, meeting notes turned into actions, the first draft of every change request. None of it is exciting, and together it is where most of the recoverable hours are.
Firms that sell expertise have their own patterns, and we have gone deeper on AI for professional services firms, AI for law firms and AI for accounting firms. Whatever the sector, when we map an organisation we look for three things.
- Time sinks
- Work done again and again without much judgement. A shared inbox where most messages are copies, the same details keyed into the CRM and the finance system, a monthly board pack assembled by hand from five spreadsheets.
- Uneven quality
- Work that gets done, but differently depending on who does it. Proposals that look different from one account manager to the next, client emails whose tone depends on who is having a busy day.
- Work that never gets done
- The analysis nobody has time for, the lapsed clients nobody calls, the tender documents nobody reads properly. This is often where AI adds the most, because it makes room for work that never fitted into the week.
Why your AI strategy should come after the first hands-on test
Most leadership teams make decisions about AI from a picture of the technology that is a year or two out of date. Someone tried a chatbot, got a mediocre answer and drew a conclusion. Since then the tools have become far more capable. They read long documents, work inside your systems and carry out tasks in several steps.
A strategy built on the old picture is wrong in both directions. It underestimates what is possible in everyday work and overestimates how much needs a large project. So we almost always start by having the team build something on their own real work, and set the strategy from what they see. It takes half a day and often saves months of wrong priorities. That is the idea behind a half-day Deployed Kickstart, and it is also why AI training for staff should be built around the work people actually do.
What an AI strategy should contain (and what it shouldn't)
An AI strategy is a decision about order: which use cases you start with, which wait and why, who makes each one happen, and the ground rules for tools and data.
It is not a technology review, a shopping list of software or an essay on what AI can do in general. Those documents are easy to commission and hard to use, because they say nothing about what anyone should do on Monday. A good test: can every person named in the strategy say what they are doing about it in the next fortnight? If not, you have written a report. Five parts are enough.
- A prioritised list of use cases
- Ranked on two things at once: how much value each creates and how ready you are to do it. The most valuable item is often not the one you can start with, because it needs access, data or a decision first.
- Ground rules
- Which tools are approved, which data must never go in, and who to ask when unsure. This is often what gives people the confidence to use AI on real work. If you are still choosing, our overview of AI tools for business sets out the main categories.
- One owner per initiative
- A named person who drives it forward, though not necessarily the one doing the work. An initiative without an owner does not happen, however good it looks on paper.
- One measure per initiative
- What it looks like today and what it should look like afterwards, in hours, pounds or quality. Without a baseline you cannot tell whether anything improved.
- A sequence
- What starts now, what runs in parallel and what waits. Some initiatives only become possible once another is in place, so the order is itself a strategic decision. Written down with dates, this is your AI roadmap.
How to prioritise use cases and build an AI roadmap
Score each candidate on value and readiness. Value is hours saved, revenue protected or quality raised; rough estimates are fine. Readiness asks whether the data is reachable, the process is clear, someone wants to own it and the risk is acceptable. Start where both scores are high. High-value, low-readiness items become phase two, with the blocker named.
Keep the AI roadmap short. Ninety days in detail and a rough view of the two quarters after that is enough, because the tools change faster than a three-year plan can be revised. Review it monthly: what shipped, what people actually use, what you learned and what moves up. For the practical side of rolling it out team by team, see our guide to deploying AI across a company. If you want outside help, start with what a good AI consultant does.
Take a 45-person lettings and property management firm in Manchester. Top of the list might be drafting replies to routine tenant queries, with a person approving each one: high volume, clear rules, low risk. Second, summarising inspection reports for landlords. Further down, an agent that chases contractors and updates the maintenance system, which waits until the first two have shown where the process is unclear.
Where AI agents and AI automation fit in the strategy
AI automation takes over a defined step that needs some judgement: reading an email and deciding what it is about, summarising a long document, drafting a reply in the right tone. Classic automation follows fixed rules; AI automation handles the messier steps in between. Start where the work already follows rules but eats time, and where a person still reviews the output. You get the time back straight away and learn where the boundary is before you move it.
AI agents go further. An agent carries out tasks in several steps: it fetches information, makes simple decisions and acts in your systems. That makes agents powerful, and riskier than a chat window. They suit processes that recur, where the data is accessible and a mistake is cheap to correct, such as triaging incoming requests, preparing case files or chasing follow-ups that would otherwise slip. They suit less well where every case is different or an error does damage before anyone notices.
When agent projects fail, it is usually because nobody owns the result or the process was never clear. The model is rarely the problem; we have written about why AI agents fail in production. The Economic Index snapshot showed UK usage leaning towards collaboration over delegation, and teams tend to start the same way, using AI as a colleague long before they hand it a process. Plan the move to automation deliberately.
A rule of thumb from our projects: if the same person does the same thing more than once a week and can explain how, it is a candidate. If nobody can explain how it is done, it is a process problem first and an AI project second. Reporting is a classic first candidate: at tm:rw, around 15 hours of it a week were eliminated.
How to build one, step by step and role by role, is in our guide to AI agents.
The governance minimum for a UK company
Governance is where smaller companies either overdo it or skip it. A 40-person firm does not need an AI ethics board. It does need a page of rules people have read, because the alternative is staff pasting client data into whichever free tool they found last week.
For most UK companies the rules that apply first are data protection rules. UK GDPR applies as soon as personal data goes into an AI tool, and the ICO publishes guidance on AI and data protection worth reading before you approve anything touching customer or employee data. Where processing is likely to be high risk, UK GDPR expects a data protection impact assessment. Regulated firms also have their sector regulator to consider, such as the SRA for solicitors or the FCA for financial services.
If you sell into the EU, the EU AI Act can apply to you even though the UK is outside the EU, because it covers AI systems placed on the EU market and, in some cases, AI output used there. For organisations in its scope it also expects staff to have a sufficient level of AI literacy. Check your own position with a legal adviser. For most companies of this size, the practical minimum looks like this.
- Approved tools on business accounts
- A short list of tools people may use for work, on business or enterprise plans whose data terms you have actually read, so nobody is running client work through a personal account.
- A clear data line
- What may never go in: for example special category data, client material you are contractually bound to protect, or anything covered by legal privilege, unless a specific tool has been cleared for it.
- Human review where it matters
- A person checks anything that goes to a client, a regulator or into a decision about an individual. AI drafts; people sign off.
- A simple register
- A list of where AI is used, on what data and who owns it. It makes any later impact assessment, client security questionnaire or audit far easier.
- A named person to ask
- Someone people can check with before they act, so grey areas get answered instead of avoided.
Four mistakes that leave an AI strategy on the shelf
Most failed AI strategies fail quietly. Nobody cancels them; usage tails off and the document stops being opened. The gap between using AI and getting results from it is mostly made of the same few errors, covered in more depth in why so few companies see results from AI.
Each of these is cheap to avoid at the start and expensive to fix later.
- Writing the strategy before anyone has tested the tools
- Decisions rest on an outdated picture of what AI can do, so the priorities are wrong from day one.
- Pilots with no owner
- A pilot nobody owns afterwards dies when the consultant leaves. Name the owner before the pilot starts.
- Choosing the tool before the problem
- Licences go to everyone, nobody knows what they are for, usage drops after a few weeks and the conclusion is that AI does not work here.
- No baseline
- Without a before, you cannot show an after, and the next budget decision becomes a matter of belief instead of results.
Frequently asked questions
What is an AI strategy?
An AI strategy is a decision about where AI should create value in the business, in what order you tackle it and who owns each part. In practice it is a short, prioritised work list with owners and measures, plus ground rules for which tools and data may be used.
Does a small business need an AI strategy?
Yes, though not necessarily before you start. Without one, AI use spreads unevenly and nobody knows what is working. But a strategy written before anyone has tried the tools tends to get the priorities wrong, so test the tools on real work first, then write a short strategy based on what the team saw.
What should an AI strategy for business include?
Five parts are enough for most companies: a list of use cases ranked on value and readiness, ground rules for tools and data, a named owner per initiative, a measure per initiative with a clear baseline, and a sequence for what starts now and what waits. Anything beyond that is rarely read.
How long does it take to build an AI strategy?
Weeks rather than months. Interviews with key people and a short survey of the wider team are enough to produce a prioritised list. The slow part is usually the decisions, such as who owns what. A strategy that takes six months to write is often out of date by the time it is finished.
What is the difference between AI agents and AI automation?
AI automation takes over a defined step that needs some judgement, such as sorting incoming email, usually with a person reviewing the result. An AI agent works in several steps and acts in your systems: it fetches information, makes simple decisions and carries them out. Agents are more powerful and riskier, so they fit where the process is clear and mistakes are cheap to correct.
Who should own the AI strategy?
Leadership owns the decisions, and each initiative needs its own named owner in the business. AI strategy is not mainly an IT matter, because the value appears when ways of working change in sales, finance, marketing and operations. IT owns identity, access and integrations; the business owns the use cases.
How do you measure whether an AI strategy is working?
Measure before and after for each initiative, in hours, pounds or quality, starting with a clear baseline. Then track how many people actually use the solution each week, because access to a tool says nothing about whether anyone uses it.
Does the EU AI Act apply to UK companies?
It can. The EU AI Act covers AI systems placed on the EU market and, in some cases, AI output used in the EU, wherever the company is based, so UK firms that sell into the EU should check their position with a legal adviser. For purely domestic use, UK GDPR and the ICO's guidance on AI and data protection are usually the first rules to get right.
- How to Deploy AI in Your Organization — A Practical Guide
- 88% of Companies Use AI. 5% See Results. Here's What Separates Them.
- The Real Cost of Not Deploying AI in 2026
- Why AI Agents Fail in Production — And What That Means for Your Business
- The Nordic AI Gap: High Usage, Low Work Share
- AI for Professional Services Firms: Where the Time Goes and How to Get It Back
- AI for Law Firms: Less Document Time, More Client Time
- AI for Accounting Firms: From Compliance Work to Advisory — Faster
- What Is Shadow AI? The Risks, Why Bans Fail and What to Do Instead
Proof from the field
All casesLet's Kickstart.
Tell us where you are and what you're aiming for. We'll get back to you within 24 hours, usually sooner.
You'll get a first step you can act on, whether or not you hire us.