The right AI question is not:
“What AI tool should we buy?”
The better question is:
“Which defined workflow could benefit from assistance, what information would the system use, and who remains responsible for the result?”
Start with the workflow—not the tool.
A useful workflow should define:
What a useful workflow defines
- Input
- Context
- Task
- Expected output
- User
- Review standard
- Approval authority
- Error handling
- Measurement
- Data boundary
Good early candidates for AI assistance
1. Summarization
Examples:
- Meeting notes
- Long internal documents
- Public research
- Project updates
Boundary: Someone must verify accuracy and omitted context.
2. First-Draft Preparation
Examples:
- Internal outlines
- Email drafts
- Process drafts
- FAQ drafts
- Content structures
Boundary: AI output is a starting point, not automatic publication.
3. Classification and Organization
Examples:
- Categorizing inquiries
- Grouping notes
- Tagging approved content
- Organizing project information
Boundary: Exceptions and sensitive categories require review.
4. Structured Information Extraction
Examples:
- Pulling fields from approved documents
- Converting notes into a consistent structure
- Preparing a review table
Boundary: Source documents and extracted values must remain available for validation.
5. Knowledge Retrieval
Examples:
- Finding approved SOPs
- Locating templates
- Answering internal questions from controlled sources
Boundary: The system should distinguish retrieved sources from generated interpretation.
6. Repetitive Preparation Work
Examples:
- Preparing meeting briefs
- Creating first-pass project summaries
- Drafting checklists
- Preparing comparison structures
Boundary: Final decisions remain human.
7. Decision Support
Examples:
- Organizing factors
- Highlighting missing information
- Comparing options
- Preparing questions
Boundary: AI supports the decision-maker but does not become the accountable decision-maker.
Poor early candidates
- Final legal advice
- Final tax or accounting determinations
- Medical diagnosis
- Hiring or termination decisions without expert controls
- Housing, credit, or eligibility decisions
- Safety-critical instructions
- Automatic financial transfers
- Unsupervised public communications
- Automatic deletion of business data
- Final contract approval
- Unreviewed factual publication
- Tasks using sensitive information without an approved data process
- Workflows with no method to identify or correct errors
These categories are not ones AI can never touch. They require stronger governance, expertise, controls, and often legal review.
Use a practical risk screen
| Question | Lower-Risk Signal | Higher-Risk Signal |
|---|---|---|
| What happens if output is wrong? | ||
| Can a person review it? | ||
| Does it use sensitive data? | ||
| Does it affect someone’s rights? | ||
| Can the result be reversed? | ||
| Is the source information available? | ||
| Is quality measurable? | ||
| Does the vendor retain data? | ||
| Can the workflow operate without AI? | ||
| Who is accountable? |
Four levels of human review
Level 1: Draft Assistance
A person reviews everything before use.
Level 2: Structured Recommendation
AI organizes or recommends; a person approves.
Level 3: Limited Automation
AI may complete a low-risk action under defined rules with monitoring and reversal.
Level 4: High-Impact Decision
Do not deploy without specialized governance, testing, professional review, and appropriate authority.
A focused pilot framework
Define one workflow
Choose a single, well-scoped workflow to pilot.
Establish the current baseline
Understand how the workflow performs today.
Define approved information
Decide what information the system is allowed to use.
Create the prompt or system instructions
Write the reusable instructions that guide the system.
Define human review
Specify who reviews and approves the output.
Measure the pilot
Track the workflow against your chosen measures.
Decide whether to stop, revise, or scale
Use the results to make a deliberate decision.
Suggested measures:
- Time required
- Rework
- Error rate
- Completeness
- User adoption
- Cost
- Escalations
- Quality-review result
Do not promise savings.
Data rules before implementation
Approved
Examples:
- Public information
- Approved templates
- Non-sensitive internal procedures
- Sanitized test data
Restricted
Examples:
- Client-confidential information
- Internal financial information
- Employee records
- Nonpublic strategy
- Credentials
Prohibited Without Specific Approval and Controls
Examples:
- Passwords
- Authentication codes
- Highly sensitive personal information
- Protected health information
- Payment-card data
- Bank credentials
- Legal-privileged information
- Regulated records
Actual classifications depend on the business and professional advice.
Questions to ask an AI vendor
Questions to ask an AI vendor
- What information is collected?
- Is submitted information used for model training?
- How long is information retained?
- Can retention be configured?
- Where is data processed?
- Who can access it?
- What security controls are offered?
- What administrative logs exist?
- Can users be removed centrally?
- Can the system use named accounts and SSO?
- How are model and product changes communicated?
- What happens when the service is unavailable?
- Can data be exported or deleted?
- What contractual terms apply?
- What does the system explicitly not guarantee?
Do not answer these questions for any vendor unless verified.
Govern, map, measure, and manage
Govern: Define responsibilities, policies, approved uses, and accountability.
Map: Understand the workflow, people, information, context, and risks.
Measure: Test quality, errors, consistency, and business value.
Manage: Prioritize and address risks, improve the system, or stop the use case.
This article is not an official NIST implementation guide.
What practical AI implementation looks like
What practical AI implementation looks like
- One defined workflow
- Clear owner
- Approved data
- Reusable instructions
- Source visibility
- Human review
- Error escalation
- Usage documentation
- Measurement
- Periodic review
- Ability to stop or operate manually
A small-business AI checklist
A small-business AI checklist
- We have defined the workflow
- We know the current baseline
- We know what data is approved
- We know what data is prohibited
- We know who reviews output
- We know who approves final action
- We can identify errors
- We can reverse or correct the result
- We understand vendor terms
- We have tested with non-sensitive information
- We have documented the process
- We know how success will be measured
- We have a manual fallback
- We have a decision date for continuing or stopping
Professional Boundaries
This resource provides general business and operational information. It does not constitute legal, tax, accounting, financial, medical, security, or other licensed-professional advice. Requirements and platform rules can change. Consult the appropriate qualified professional for decisions affecting legal rights, regulated information, taxes, contracts, employment, or other specialized matters.
Regulated and high-impact uses require specialized legal, compliance, security, and subject-matter review.
Sources and Official References
- National Institute of Standards and Technology — AI Risk Management Framework (https://www.nist.gov/itl/ai-risk-management-framework)
- NIST AI Resource Center — AI RMF Core (https://airc.nist.gov/airmf-resources/airmf/5-sec-core/)
- National Institute of Standards and Technology — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)
- Federal Trade Commission — Artificial Intelligence Business Guidance (https://www.ftc.gov/business-guidance/blog/topics/artificial-intelligence)
About the Author
Marty Clarke
Founder and Principal Consultant
Marty Clarke founded MCC to help growing businesses connect strategy, operations, digital ownership, websites, marketing systems, and practical AI implementation.
About Marty Clarke