Where to start with AI in your business
A four-step sequence you can run before buying anything: count the AI already in use, ask your staff, check your data, and agree the rules first.
If you’ve been asked to work out where AI fits in your business, the temptation is to start with a shortlist of tools. Don’t. The first month of useful work costs nothing but attention, and it starts with finding out what’s already true in your own building. In our experience the starting line is usually behind you, because your staff started without you.
Here is the sequence we’d run, in order, before a single purchase.
Count the AI already in use
Pull the card statements and expense claims and look for AI subscriptions. Ask each team lead which tools their people actually use in the browser, sanctioned or not. For every tool on the list, write down one more thing: what data goes into it.
The count matters because staff use of AI predated the policy at client after client of ours. The counted version of what those engagements kept finding is in what seven UK AI audits kept finding, and it’s the evidence behind every step on this page. A count usually pays for itself on the spot, because individual subscriptions bought on personal cards are the first saving, and consolidating them onto a managed tier puts the spend where finance can see it.
Ask ten people before you ask a vendor
Book half an hour each with ten people across departments, with no vendor in the room. One question does most of the work: what would you hand to a machine tomorrow?
Expect the answers to surprise you. The tools businesses get sold are mostly generators, but what staff ask for first is usually retrieval. The most common request we hear is to ask a question in plain English and have it answered from the company’s own documents. Whatever your ten people say, their requests are a better shortlist than any product demo, and the demo can wait until you know what you’re shopping for.
Find out where your data lives
Three questions settle most of it. Which systems hold the documents and records that matter? Can anything search across them today? Who controls access to each?
If the honest answer is that your company’s knowledge sits scattered across drives, inboxes and a legacy server, then tidying that up is your starting project, and it would be your starting project even if AI didn’t exist. Ask the sovereignty question at the same time: does any of your data have to stay in the UK, in the EU, or on your own machines? The answer decides which tools you’re even allowed to consider, and it’s the cheapest question to answer early and the most expensive one to answer late.
Agree the rules before you buy the tools
A first policy is short. Which tools are approved. What data must never go into them. Where you will not use AI at all, written down as its own list. Agreeing it before the purchase gives every later decision something to be measured against, and it’s far easier to write while nothing is embedded yet. We’ve set out the case in write the AI charter before you buy the AI.
What a month of this gets you
By the end you hold four things: a list of the tools in use and the data flowing into them, a shortlist your own staff wrote, a map of where your data lives, and agreed rules with an off-limits list. From that position, buying decisions are quick and hard to get badly wrong.
If you want a reading on where you stand before you talk to anyone, the free AI readiness check asks ten questions and gives you a score out of 100 with suggested next steps. And when you want the counted version, built from your own invoices, folders and interview transcripts, that’s the AI Audit and Transformation, which runs three to four weeks.
Where should a business start with AI?
Start before you spend. Count the AI your staff already use and what data goes into it, interview ten people about what they would hand to a machine, establish where your data lives and what condition it is in, and agree the rules before anything new is bought. That sequence costs attention rather than money, and it turns every later buying decision into a quick one.
Should we write an AI policy before buying AI tools?
Yes. A policy agreed before the purchase gives every later decision something to be measured against, and it is much harder to write once tools are already embedded in daily work. One of our clients, House of Hackney, agreed its Responsible AI Charter before the tools were bought, and we would recommend that order to anyone. A good first policy also says where you will not use AI, in writing.
Our staff already use ChatGPT on personal accounts. Is that a problem?
It is a demand signal as well as a risk. In the audits we have run, staff use of AI predated the policy in every engagement we have documented in full, and the people doing it are showing you where AI would help. The risk sits in the data going into those accounts, so the fix that works is consolidation onto a managed tier under agreed rules rather than a ban.
Take the question to an audit.
If this raised a question about your own operation, the AI Audit and Transformation is where we answer it. It runs three to four weeks, and your first automation is live before it ends. You leave with a written report your board can read in one sitting alongside a prioritised 12 month roadmap. Your fee is fixed and agreed before anything starts.