AI can change what a business is capable of. The business still has to decide what is worth doing.
I've been to a lot of conferences lately and I keep seeing one trend. AI being presented as a company’s new strategy. I understand the appeal. It is a powerful technology, and its possibilities can make a familiar business feel suddenly full of opportunity.
But “we are going to use AI” or "Our product will have AI" leaves the most important questions unanswered. For whom? To solve what problem? To create what value? And what will we choose to do less of so we can do that well?
Those are the questions that give a strategy its substance. Buying access to a capability does not answer them.
A strategy makes choices
A business has limited time, money, and attention. Its strategy should explain where it will focus, how it intends to succeed, and which tradeoffs it is prepared to make.
Suppose a financial services business wants to make a difficult client process simpler and more dependable. AI might help staff find relevant information, prepare documents, or identify cases that need closer attention. Each could contribute to the strategy.
The starting point is still the client’s problem. If the largest obstacle is an unclear process or a decision nobody owns, adding AI may simply help the business move through the confusion faster.
AI can make us better at what we are doing. Strategy asks whether we are doing the right things.
Capability can change the choices available
I do not think AI should be treated as just another piece of software. Its capabilities may make a previously impractical service achievable, change the cost of delivering it, or allow a team to tackle work it could never meaningfully cover before.
That can justify revisiting a strategy. A new capability can reveal a better way to serve clients or a different business worth building.
But the opportunity still needs to become a business choice. We need to understand who benefits, why the outcome matters, what it takes to deliver, and whether the result is sustainable. “AI-powered” tells us something about the method. It tells us very little about the value.
The business case has to survive the demonstration
A demonstration shows what might be possible. Operating a service means accepting responsibility for what happens when people depend on it.
That responsibility includes the quality of the result, the information used, the actions the system can take, and what happens when it is wrong or unavailable. It also includes the cost of checking and correcting its work.
If a team produces an answer faster but someone else must spend longer verifying it, the benefit needs to account for both. If an automated process saves effort but makes recovery harder, that belongs in the decision too.
I would judge an AI investment by the outcome the business intended to improve: fewer errors, a simpler client experience, better decisions, or more capacity for valuable work. The number of people using a tool can help us understand adoption. It cannot tell us, by itself, whether the investment is succeeding.
Security should help make the opportunity usable
My role as a security leader is to help a business understand how it can use a capability responsibly. That starts with knowing what the business wants to accomplish.
When the purpose is clear, we can define appropriate access, protect the information involved, set limits on automated actions, and plan how to respond if something goes wrong. We can also distinguish a use that fits established controls from one that needs deeper scrutiny.
This is why I believe security needs to be involved while the work is being shaped. Early decisions about data, permissions, and recovery can make a useful idea easier to operate. Discovering those questions just before launch makes them harder to resolve.
The controls should be proportionate to the consequence. A system helping draft an internal note and a system authorized to change a client’s financial records need different boundaries. Clear requirements and reusable patterns give teams a route forward without asking them to invent every control themselves.
Keep ownership of the direction
There is a temptation to let the excitement around a technology decide where a business puts its attention. Leaders need to stay curious without surrendering their judgement.
We should experiment, learn, and change course when the evidence warrants it. We should also be able to stop an impressive project if it is solving a problem that does not matter enough.
AI can absolutely help a business get where its strategy is taking it. It may even reveal a better destination. The responsibility for choosing that destination remains ours.
Before we ask what AI can do, we need to be clear about what is worth doing.
References & further reading
Primary guidance for the concepts and controls discussed here.
- NIST AI Risk Management Framework ↗Purpose, context, accountability, measurement, and management of AI-related risk.
- OSFI Guideline B-13: Technology and Cyber Risk Management ↗Risk-based technology governance and resilience for federally regulated financial institutions.