Generative AI: A Manager’s Guide
How to Cite This Book
If you use this book in your work, please cite it as:
APA: Chaudhri, A. (2026). Generative AI: A Manager’s Guide. Self-published. https://gen-ai-managers-guide.github.io/
BibTeX:
@online{chaudhri2026generativeai,
author = {Chaudhri, Akmal},
title = {Generative AI: A Manager's Guide},
year = {2026},
url = {https://gen-ai-managers-guide.github.io/},
urldate = {2026-07-21}
}
Cover

License
Copyright
Copyright © 2026 Akmal Chaudhri. All rights reserved.
Publication Information
First published: July 2026
The latest version of this book, together with updates, errata and additional resources, is available at:
gen-ai-managers-guide.github.io
Book License
Generative AI: A Manager’s Guide is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (CC BY-NC-ND 4.0).
You are free to copy and redistribute this book in any medium or format under the following conditions:
- Attribution - You must give appropriate credit, provide a link to the license and indicate if changes were made.
- NonCommercial - You may not use the material for commercial purposes.
- NoDerivatives - If you remix, transform or build upon the material, you may not distribute the modified material.
The full license text is available at:
creativecommons.org/licenses/by-nc-nd/4.0
Code License
Unless otherwise stated, all code samples, notebooks, scripts and source files accompanying this book are licensed under the Apache License 2.0.
You are free to use, modify and redistribute this code, including for commercial purposes, subject to the terms of the Apache License 2.0.
The full license text is available at:
apache.org/licenses/LICENSE-2.0
This distinction means that the book’s written content is protected under the Creative Commons license, while the accompanying code remains freely available for use, modification and integration into your own projects.
Trademarks
Product names, company names and logos mentioned in this book may be trademarks or registered trademarks of their respective owners.
Their inclusion is for identification and educational purposes only and does not imply any affiliation with, sponsorship by or endorsement from the respective trademark holders. All trademarks remain the property of their respective owners.
Disclaimer
The information in this book, including all code samples, scripts and notebooks, is provided “as is” without warranty of any kind, express or implied.
The author makes no representations or warranties regarding the accuracy, completeness, reliability or suitability of the information contained herein for any particular purpose.
Examples are provided solely to illustrate technical concepts, patterns and software architectures.
Readers are responsible for independently validating all code, configurations and recommendations before using them in production environments.
To the fullest extent permitted by law, the author shall not be liable for any direct, indirect, incidental, special, consequential or other damages arising from the use of or inability to use, the information, code or techniques described in this book.
About the Author
Akmal Chaudhri is a technical leader, educator and author with extensive experience in databases, AI and developer relations. He specializes in technical writing, developer education and community building, helping engineers and organizations understand and adopt complex technologies through clear, practical and engaging content. He is a frequent international speaker, a published author and a contributor to industry discussions on data platforms, AI and software development.
Today, Akmal works in developer education at Neo4j, where he focuses on technical content, workshops and community initiatives. While his professional role has evolved, this book represents an independent exploration of Generative AI.
Based in the United Kingdom, Akmal continues to work at the intersection of databases, AI and developer tooling, helping developers build modern data-driven applications.
For book updates, code samples and additional resources, visit the Book website.
To connect professionally or follow his latest work, visit LinkedIn.
Introduction
Something unusual is happening in organizations right now. A technology has arrived that is immediately useful to almost everyone, requires no training to try and produces results that are good enough to be genuinely surprising. And unlike most enterprise technology, it did not arrive through the IT department. It arrived through the front door - through individuals using it at their desks, on their phones, in their own time - before most organizations had formed a view about it.
The result is a peculiar situation. Executives are approving AI budgets, signing off on AI strategies and fielding questions from boards about AI governance - while privately uncertain whether they understand the thing they are being asked to govern. Managers are being handed responsibility for AI initiatives without a clear framework for thinking about what those initiatives require. Teams are using AI tools daily, in ways their organizations may or may not be aware of, with results that range from genuinely impressive to quietly problematic.
This book is written for the people in the middle of that situation: the managers, directors and executives who are responsible for making AI work well in their organizations - not the engineers building the technology and not the theorists debating its long-term implications, but the people who need to make a decision about it on Monday morning.
What This Book Is Not
This book does not explain how large language models work at a technical level. It does not rank AI tools or recommend specific vendors. It does not make predictions about which jobs will be automated or what the world will look like in twenty years. And it does not assume that AI is either the transformative force its most enthusiastic advocates claim or the overhyped disappointment its skeptics suggest.
What it assumes is that AI is a real and consequential technology that is already present in your organization, that it has genuine strengths and genuine limitations and that managing it well is a management challenge - one that draws on skills you already have, applied to a context that is genuinely new.
The Central Argument
The central argument of this book is simple: managing AI is, at its core, a management challenge, not a technical one.
The technology behind modern AI is sophisticated. But the questions that determine whether AI creates value in your organization are not technical questions. They are management questions. How do you direct AI to produce useful output? How much oversight is appropriate? Who is accountable when something goes wrong? How do you build a business case that will survive scrutiny? How do you redesign work so that AI and people each do what they do best? How do you explain your organization’s AI posture to a board?
These questions have management answers. They require clarity of thinking, appropriate governance, honest evaluation and the judgment to know what decisions require human accountability and what can be safely delegated. They do not require you to understand transformer architectures or training data pipelines.
The Digital Intern
Throughout this book, we use a single metaphor to carry the argument: your Digital Intern.
Imagine you have hired an intern. Before their first day, this intern spent several years reading - comprehensively, not casually. Books, articles, research papers, contracts, instruction manuals, court judgments, recipes, technical specifications and an enormous quantity of text from the internet. By the time they arrive, they have encountered more written material than any human being could absorb in a lifetime.
They are genuinely capable. They draft well, summarize accurately, explain complex ideas clearly and apply the same consistent approach to the hundredth task that they applied to the first. They are available at any hour, never tired and never in a bad mood.
They are also unlike anyone you have managed before. They produce confident answers regardless of whether those answers are correct. They have no memory of previous conversations. They know nothing about your organization, your clients or your specific situation unless you tell them. And they cannot be given a consequential decision to make on your behalf - the accountability is yours.
This intern needs managing. Not technically - but in exactly the ways that good managers have always managed capable people: clear direction, appropriate oversight, honest assessment of strengths and limitations and a clear sense of what decisions require the manager’s judgment rather than the intern’s output.
That is what this book teaches you to do.
How This Book Is Structured
The book is organized in four parts, each addressing a different dimension of managing AI well.
Part I: Meeting Your Intern covers the mental model you need to work with AI effectively. Chapter 1 explains what AI actually knows, why it produces confident wrong answers and what it means that it has no memory between sessions. Chapter 2 covers the craft of briefing the intern well - the management skill that determines the quality of everything that follows.
Part II: Trust, Risk and Accountability is the heart of the book. Chapter 3 provides a framework for supervision - how much oversight is appropriate and under what conditions. Chapter 4 maps the seven risks that AI adoption introduces and the mitigations for each. Chapter 5 prepares you for the board conversation about AI: the questions you will be asked, the governance structures that make the answers credible and the accountability framework that makes them honest.
Part III: Putting the Intern to Work addresses the practical economics and implementation of AI adoption. Chapter 6 covers where to start and how to build a business case that will survive scrutiny. Chapter 7 provides sector-specific briefings for eight industries, covering use cases, risks and regulatory context. Chapter 8 maps the roadmap from pilot to embedded capability, including the failure points where most initiatives stall.
Part IV: The Adaptive Enterprise looks at the broader organizational challenge. Chapter 9 addresses augmentation in practice - how to redesign work, manage the human dimension of change and develop the skills the augmented role requires. Chapter 10 addresses the strategic challenge of leading an organization where AI is everywhere: the maturity model, the executive questions that define genuine AI leadership and the case for building organizational capability rather than tool dependency.
The book closes with a Conclusions chapter that returns to the Digital Intern metaphor one final time and three appendices: decision framework templates for direct use, a glossary of thirty essential terms and an annotated further reading list.
A Note on Pace
The AI landscape is moving quickly. Capabilities that seemed remarkable at the start of 2024 were table stakes by the end of it. The specific tools available to managers in 2026 are more capable than those available in 2023 and the tools available in 2028 will be more capable still.
This book is written to remain useful as the technology changes. The governance frameworks, the risk structures, the business case discipline and the management principles it describes do not become obsolete when a new model is released. The specific examples and sector details reflect the landscape at the time of writing; the underlying argument is designed to hold.
The intern is getting better. The management challenge is not going away. This book is your guide to meeting it.
Chapter 1: What Your Digital Intern Actually Knows
MARGIN - The Briefing Room A consistent thread runs through every margin in this book. You have just hired a Digital Intern. Brilliant, tireless, eager to help - and in need of careful management. Each margin note translates the chapter’s ideas into what they mean for you, the manager, on your first week with a new member of staff.
Something unusual happened in the last few years. A technology arrived that was immediately useful to almost everyone, required no training to try and produced results good enough to be surprising. Managers who had spent careers carefully avoiding the technical details of the systems they oversaw found themselves using one directly, often before their IT departments had formed a policy about it.
The result is a peculiar situation. Executives are approving AI budgets, signing off on AI initiatives and fielding questions from boards about AI strategy - while privately unsure whether they understand the thing they are being asked to govern. This is uncomfortable and it need not be.
You do not need to know how a large language model works to manage one effectively. You do need to know what it is like to work with one - its habits, its tendencies, its characteristic strengths and its equally characteristic failures. That is what this chapter is for.
The Intern Who Read Everything
Imagine you have hired an intern. Before their first day, this intern spent several years reading. Not casually - comprehensively. They read books, articles, research papers, contracts, instruction manuals, court judgments, recipes, technical specifications and an enormous quantity of text from the internet. By the time they arrive at your desk, they have encountered more written material than any human being could absorb in a lifetime.
The result is genuinely impressive. Ask them to draft a client email and they will produce something polished. Ask them to summarise a long document and they will pull out the key points accurately. Ask them to explain a technical concept in plain language and they will often do so better than the expert who knows the topic directly.
They are also, in ways that are important to understand, not quite like anyone you have managed before.
What the Intern Learned - and How
The intern’s knowledge came entirely from text. This sounds obvious but has consequences that are easy to miss.
They know what people have written about the world, which is an extraordinarily rich source of information. They do not know the world directly. They have never attended a meeting, visited a factory floor, read a room or noticed that a client seemed uncomfortable with a proposal. Everything they know arrived as language and language is how they think.
This makes them remarkably fluent. Language is their native medium in a way that it is not for most people. They produce clear, well-structured prose almost automatically. They can match the register and tone of whatever they are asked to write. They have encountered enough examples of almost any kind of document to produce a plausible version of it on request.
It also means their knowledge has edges that can be hard to detect. The intern learned from what was written and what was written is not a perfect representation of reality. It over-represents some things - popular topics, English-language sources, material published on the internet - and under-represents others. They may be confident about subjects where the written record is thin or skewed and appropriately hesitant about subjects where their reading was comprehensive. You cannot always tell from the outside which is which.

Figure 1-1. The Knowledge Map.
MARGIN - First Week Observation Your new intern is extraordinarily well-read. They will rarely say they don’t know something - and that confidence is not always earned. In the first week, check their work more carefully than their fluency suggests you need to.
The Confidence Problem
The most important thing to understand about your Digital Intern is that they do not experience uncertainty the way people do.
When a human expert is unsure of something, they usually know they are unsure. They hedge their answers, say “I think” or “I believe,” suggest you check with someone else. The feeling of uncertainty is a signal that the person registers and communicates.
A large language model does not have that signal. It produces the most plausible continuation of whatever conversation it is in, based on patterns in its training. Whether that continuation is correct or confidently wrong, the prose is equally fluent, the tone equally assured. The model does not know the difference between a well-supported answer and a plausible-sounding one. It does not have a feeling of certainty or doubt - it has a next word.
This is the origin of what is called hallucination - the production of confident, well-formed statements that are simply untrue. It is not deception. The intern is not trying to mislead you. They are doing what they were trained to do, which is produce fluent, contextually appropriate text. When that text happens to contain a made-up figure, a misattributed quote or a fictitious case reference, the intern does not notice, because they have no mechanism for noticing.
The managerial implication is direct. You would not send a new hire’s first draft of a client document out without reading it. You would not accept their summary of a legal agreement as a substitute for reading the agreement. The same instincts apply here and they apply consistently - not just in the first week, but as a permanent feature of working with this kind of system.

Figure 1-2. Confidence vs. Accuracy.
MARGIN - The Confident Wrong Answer The intern will occasionally give you a wrong answer delivered with total confidence. This is not dishonesty - they genuinely cannot tell the difference. Your job is to build checking into the workflow, not to hope the intern will flag it.
No Memory Between Tasks
There is another characteristic that managers find counterintuitive until they encounter it directly: your Digital Intern does not remember previous conversations.
Each time you open a new session - each time you start a fresh conversation - the intern arrives with no recollection of anything you have discussed before. The rapport you built yesterday, the context you established last week, the preferences you explained at length - none of it is there. You are meeting for the first time again.
Within a single session, the intern does have working memory. They can refer to something said earlier in the same conversation, build on a previous answer, maintain a consistent thread. But the moment the session ends, it is gone.
This is not a bug that will eventually be fixed, though memory capabilities are evolving. It is a consequence of how these systems work and it shapes how you should use them. Any context that matters needs to be provided at the start of each task. Any established way of working needs to be included in the instructions you give, every time.
For managers accustomed to working with teams who accumulate shared context over months and years, this is a genuine adjustment. The intern is not growing in their understanding of your organization, your clients, your preferences or your standards. They are reset, completely, at the start of each session.

Figure 1-3. Memory and the Session Reset.
MARGIN - Brief Them Every Time You cannot assume your Digital Intern remembers anything from yesterday. Include the relevant context in every task you give them. This is not inefficient - it is the price of a colleague who never leaves, never tires and never brings yesterday’s bad mood to today’s work.
What the Intern Is Actually Good At
Given these limitations, it is worth being specific about where the Digital Intern genuinely excels - because the list is substantial.
First drafts. The intern is exceptional at producing a first draft of almost any kind of document. The draft will need reviewing and refining, but starting with a competent draft is faster than starting from a blank page. Emails, reports, proposals, summaries, presentations, meeting agendas, job descriptions - the intern can produce a working version of any of these quickly.
Transformation. Give the intern a document in one form and ask for it in another: long to short, formal to conversational, technical to plain English, English to a different structure entirely. This is where the fluency with language pays particular dividends. The intern moves between registers and formats with ease.
Exploration. Ask the intern to give you five different framings of a problem, three possible responses to a client objection or two ways to structure an argument. The ability to produce multiple plausible variations quickly is genuinely useful for the kind of thinking that precedes a decision.
Consistency at volume. For tasks that involve doing the same thing many times - reviewing many documents against a checklist, summarising a large set of responses, formatting a large quantity of data - the intern applies the same approach to the hundredth item that it applied to the first. There is no fatigue, no drift, no tendency to rush at the end.
Explanation. The intern can explain concepts at multiple levels, adjust the explanation based on the audience and generate examples on request. For managers who need to get up to speed on an unfamiliar topic or who need to communicate a technical idea to a non-technical audience, this is valuable.
MARGIN - Where to Start Give your Digital Intern the tasks that involve producing a first version of something, transforming content from one form to another or doing the same thing reliably at scale. These are their strongest contributions in the first few weeks.
What the Intern Cannot Do
There are things the intern will attempt that they should not be given unsupervised. Understanding these is as important as understanding their strengths.
Anything requiring current information. The intern’s knowledge has a cutoff date. Events after that date simply did not make it into their reading. They may not know this or may not know exactly where their knowledge ends. Asking the intern about today’s market conditions, a recent regulatory change or the latest version of a software platform is asking them to work beyond their reliable territory. Some AI systems can search the web to supplement their knowledge - even then, the quality of what they retrieve needs checking.
Anything requiring verified facts. Figures, dates, statistics, legal references, specific attributions - anything that will appear in a document as a verified fact should be checked against a primary source. The intern will produce plausible figures. Plausible is not the same as accurate.
Reasoning from your organization’s private context. Unless you tell them, the intern knows nothing about your company, your clients, your internal processes or your specific situation. They will produce generic answers to specific questions unless given the specific context. The answer you get without context may look relevant without being so.
Judgement calls. The intern can lay out the considerations, describe precedents and suggest options. They cannot weigh your organization’s particular values, your specific risk appetite or the human factors that a decision actually turns on. The judgement is yours. The intern is an input to that judgement, not a replacement for it.
MARGIN - What to Keep The final decision, the verified fact, the judgment call, the thing that will go out under your name or your organization’s name - keep these. The intern prepares the ground. You make the call.
The Right Mental Model
There is a temptation, when encountering AI for the first time, to reach for either extreme. Either it is a remarkable oracle that knows everything and can be trusted implicitly or it is an unreliable gimmick that produces confident nonsense and cannot be trusted at all. Both views lead to poor management.
The Digital Intern is neither. It is a capable, tireless, well-read colleague who produces high-quality first drafts, handles volume tasks without complaint and communicates fluently in any register you require - but who needs clear instructions, works without memory of previous conversations and cannot reliably distinguish what they know from what they have confidently guessed.
That description maps directly onto something most managers already know how to handle: a talented new hire who needs supervision, context and checking. The tools for managing the intern well are not technical tools. They are management tools - clarity of instruction, appropriate oversight, sensible verification and a clear sense of what decisions require human judgement.
The rest of this book works through what that looks like in practice. How much autonomy is appropriate and when? What can go wrong and how do you mitigate it? How do you talk about this to a board? How do you calculate whether it is worth the investment? What does your organization look like when you have embedded AI thoughtfully rather than hastily?
Those are managerial questions. They have managerial answers.
MARGIN - The Governing Principle Your Digital Intern is capable and worth managing well. The skills you already have - setting clear expectations, checking outputs, defining what requires your sign-off - are exactly the skills this requires. The technology is new. The management is not.
Chapter Summary
- A large language model learns from text. Its knowledge is broad, fluent and uneven - comprehensive in some areas, thin or skewed in others.
- It produces confident answers regardless of whether those answers are correct. The fluency is not a signal of accuracy.
- It has no memory between sessions. Any context that matters must be provided with each task.
- It excels at first drafts, document transformation, generating multiple options and applying a consistent approach at volume.
- It should not be used unsupervised for current information, verified facts, organization-specific judgements or final decisions.
- The right mental model is a talented, well-read new hire who needs clear instructions, appropriate oversight and a manager who knows what to keep.
Next: Chapter 2 - The Briefing Room: Prompts, Context and Instructions
Chapter 2: The Briefing Room
Most managers discover quickly that their Digital Intern is capable of producing very different quality work depending on how they are asked. The same intern who delivers a sharp, well-structured analysis in one conversation produces something vague and generic in another. The task was similar. The intern was the same. What changed was the quality of the brief.
This is not a coincidence. It is the central mechanic of working with generative AI and understanding it puts a manager in control of the output in a way that feels, at first, almost surprising. The intern does not improve with time and experience the way a human employee does. What improves and what you can deliberately improve is how clearly you tell them what you need.
That is what this chapter is about. Not the technology behind the brief - but the craft of writing one well.
The Brief Is the Work
In most management contexts, the brief is the thing you do before the work. You write the brief, hand it off and then the work begins. With your Digital Intern, the relationship is different. The brief does not precede the work - it largely determines it. A vague brief produces vague output. A brief that specifies the audience, the purpose, the format and the constraints produces output that is useful from the first attempt.
This shifts something important. Managers who approach AI as a time-saving tool - type a quick request, get an answer - often find the output disappointing and conclude that the technology is overhyped. Managers who treat the brief as the primary investment of their attention find something closer to the opposite. The intern handles the volume. The manager handles the direction. And the quality of the direction is almost entirely within the manager’s control.
The good news is that briefing a Digital Intern draws on skills most managers already have. Clarity. Specificity. An understanding of the audience. A clear sense of what success looks like. These are not new skills. What is new is applying them to a conversation with a piece of software.

Figure 2-1. Brief Investment vs Output Quality.
MARGIN - The Investment With your Digital Intern, the brief is where your attention goes. A two-minute brief produces two-minute output. A ten-minute brief that clearly specifies the task, the audience, the format and what good looks like will return that investment many times over.
Role, Task, Context, Constraints
A useful brief has four components. Not all four are needed for every task - a simple request can be simple - but when the output disappoints, the missing element is almost always one of these.
Role. Tell the intern who they are for this task. Not their general identity, but their role in this specific conversation. You are a communications advisor helping a senior manager prepare for a difficult team meeting. This does two things: it narrows the scope of the intern’s knowledge to what is relevant and it sets a register - the tone and style appropriate to that role. An intern asked to respond as a communications advisor will write differently from one asked to respond as a legal analyst, even to an identical underlying question.
Task. State what you need, specifically. Not help me with the report but write a one-page executive summary of the attached report, in plain English, for a board audience with no technical background. The more specific the task, the more precisely the intern can direct their considerable fluency at the right target.
Context. Provide the information the intern does not have. This is the information that lives inside your organization - your company’s situation, your client’s preferences, the history of the project, the audience’s particular sensitivities. The intern’s general knowledge is broad. What it lacks is your specific knowledge. Context is how you supply it.
Constraints. Tell the intern what not to do or what the limits are. No longer than 300 words. Avoid technical jargon. Do not recommend a specific vendor. Constraints save rounds of revision. Without them, the intern will make plausible choices about format and scope - and plausible is not always right.

Figure 2-2. The Four-Part Brief.
MARGIN - The Four-Part Brief Role, Task, Context, Constraints. For routine tasks, one or two of these will do. For anything important, use all four. The brief takes five minutes. The revision it saves you takes much longer.
Talking to the Intern Like a Manager
There is a temptation, when writing instructions to an AI system, to become either too formal - as though writing a specification document - or too casual, as though sending a text message. Neither works especially well.
The register that works best is the one a good manager uses when briefing a capable person: direct, specific and respectful of the recipient’s intelligence. You do not need to explain the obvious. You do not need to soften the request. You do not need to say please, though it does no harm. What you need to do is say clearly what you want, give the intern the information they need to produce it and specify the form you want it in.
A useful test: read the brief back and ask whether a capable, well-intentioned person with no prior knowledge of your organization or the situation could produce what you need from it. If not, something is missing.
MARGIN - The Capable Stranger Test Before sending a brief, ask: could a capable stranger, given only this instruction and nothing else, produce what I need? If the answer is no, the brief is incomplete. Add the missing context before sending.
Iteration Is Not Failure
Most managers find that their first attempt at a brief does not produce exactly what they wanted. This is not a sign that the technology does not work or that they are doing it wrong. It is the normal pattern of working with any capable collaborator on a complex task.
The intern does not take corrections personally. They do not remember the previous attempt in a new session. They do not become defensive when asked to try again with different parameters. This makes iteration genuinely cheap - cheaper, in many respects, than iterating with a human colleague who has invested effort in the first version.
When the output is not right, the question to ask is not what did the intern do wrong but what did the brief not specify. In most cases, the second brief - which adds the missing element, narrows the scope or corrects a misunderstood constraint - produces something substantially better. The quality of output improves not because the intern learns, but because the manager’s brief gets more precise.

Figure 2-3. The Iteration Loop.
MARGIN - Why It Missed When the output is not what you needed, read the brief rather than the output. The gap between what you asked for and what you got is almost always in the brief. Add the missing element and try again.
Giving the Intern a Persona
One of the more powerful techniques available in a brief is asking the intern to take on a specific perspective or expertise for the task. This goes beyond role - it asks the intern to filter their response through a particular viewpoint.
Respond as a sceptical CFO reviewing this business case for the first time. The intern will apply what they know about how CFOs think, what they prioritize and what objections they tend to raise. The result is a stress test of the business case - not a perfect one, but a useful one, produced in seconds.
Review this proposal as if you were a procurement manager from a regulated financial services firm. The intern will flag the kinds of concerns that procurement in that sector tends to raise: compliance questions, vendor risk, data handling, contractual protections. Again, not a substitute for real procurement review - but a useful first pass that surfaces questions worth thinking about before the real review happens.
The technique works because the intern has encountered a great deal of text written by, about and for a wide range of professional roles and perspectives. Asking them to adopt a perspective is asking them to draw on a relevant portion of that reading.
MARGIN - The Devil’s Advocate Ask the intern to argue against your proposal before you present it. Give them the brief, then ask: what would a sceptical board member say? What has been missed? What would concern a cautious CFO? The objections are worth having before the meeting, not during it.
What Belongs in the Brief and What Does Not
There are things that should always go into a brief and things that are a waste of space.
Include: the audience for the output, the purpose it will serve, the form you want it in, the length or scope, any specific information the intern needs that they would not otherwise have and any constraints on what the output should or should not contain.
Exclude: background about how AI works, assurances that the intern is capable of the task, lengthy explanations of why you are asking and social pleasantries that would not appear in a well-written internal memo. The intern does not need encouragement. They need information.
One thing that catches managers out: asking for too many things in a single brief. A brief that asks the intern to summarise a document, identify the three key risks, draft a response and suggest a meeting agenda is four tasks presented as one. The intern will attempt all four and the result will be adequate across all of them rather than excellent on any one. Better to sequence the tasks, treating each as a separate brief that builds on what came before.
MARGIN - One Task at a Time A brief that contains four tasks produces four adequate outputs. Four briefs, each with one task, produce four good ones. Sequence your requests. The intern has no problem with the extra work - and neither will you, once you see the difference in quality.
The Brief as an Organizational Asset
Individual managers who learn to brief their Digital Intern well get better output. Organizations that treat good briefs as an asset - documenting them, sharing them, refining them over time - get something more valuable: consistency.
A well-crafted brief for a recurring task is reusable. The brief that produces a good first draft of a board paper is the same brief, with different context plugged in, next quarter. The brief that produces useful competitor summaries can be shared across a team. The brief that generates useful risk checklists for a particular type of project can become a standard part of the project toolkit.
This is an organizational skill, not just an individual one. Teams that develop a shared library of effective briefs find that the quality of AI output across the team rises - not because the intern has improved, but because the organization has become better at directing it.
MARGIN - The Reusable Brief A brief that works once can work every time. When a brief produces genuinely useful output, save it. Strip out the specific context, leave the structure and the constraints and you have a template. That template is an asset.
Chapter Summary
- The quality of your Digital Intern’s output is largely determined by the quality of the brief. This is within your control.
- A useful brief has four components: role, task, context and constraints. For complex tasks, use all four.
- Write the brief as you would instruct a capable person with no prior knowledge of the situation - specific, direct, complete.
- When output disappoints, the problem is almost always in the brief, not the intern. Add the missing element and try again.
- Asking the intern to adopt a specific perspective or persona is a powerful way to generate useful challenges and stress tests.
- Keep briefs focused on a single task. Sequence multiple requests rather than bundling them.
- Effective briefs are reusable. A brief that works once can become a team asset.
Next: Chapter 3 - Supervising the Intern: Trust, Safety and Governance
Chapter 3: Supervising the Intern
Every manager who has hired a capable but inexperienced person has faced the same question: how much rope do you give them? Too little and you waste their potential, spend your own time doing work they could handle and signal that you do not trust them to deliver. Too much and you expose your organization to avoidable mistakes, find yourself fixing errors that should have been caught and lose the confidence of clients or colleagues who expected more control.
The same question applies to your Digital Intern and the stakes are higher than most managers initially realize. The intern is fast, tireless and available at any hour. Left unsupervised, they can produce and act on a great deal of output in a short time. Some of that output will be excellent. Some will be subtly wrong. A small amount may be seriously problematic. The question is not whether to supervise, but how much and under what conditions.
This chapter gives you a framework for answering that question consistently.
The Supervision Spectrum
It helps to think of supervision not as a binary choice between full control and full autonomy, but as a spectrum with several distinct positions. Most organizations, once they understand the spectrum, find that different tasks belong at different points on it.
At one end is full supervision: the intern produces output, a human reads and approves every piece before it acts on anything or reaches anyone. At the other end is full autonomy: the intern produces output and acts on it directly, with no human review. Between these extremes sit several intermediate positions, each appropriate for a different combination of task type, output stakes and intern reliability.
The right position on this spectrum is not fixed. It changes as you learn more about how your intern performs on specific types of tasks, as the stakes of particular outputs change and as your organization builds the verification processes needed to operate safely at lower supervision levels.
MARGIN - The Supervision Spectrum Full supervision at one end. Full autonomy at the other. Most tasks belong somewhere in the middle and the right position depends on the stakes of getting it wrong. Start closer to full supervision. Move toward autonomy only when you have evidence it is safe to do so.
Four Supervision Levels
Four positions on the spectrum are worth naming precisely, because they correspond to four distinct management postures.
Level 1: Review everything. Every piece of output is read by a human before it is used, sent or acted upon. This is appropriate for high-stakes outputs, unfamiliar task types, the early period of working with a new AI system and any situation where an error would be costly or embarrassing. It is not efficient for high-volume, low-stakes tasks, but efficiency is not the primary concern at this level.
Level 2: Spot check. The intern operates with light oversight. A human reviews a sample of outputs rather than every one and checks for patterns of error rather than individual mistakes. This is appropriate for tasks the intern has demonstrated reliability on, where volume makes full review impractical and where an individual error is correctable before it causes significant harm.
Level 3: Exception-based review. The intern operates largely independently, flagging outputs that fall outside defined parameters for human review. The human attention goes where the intern has identified uncertainty or where the output meets pre-defined criteria for escalation. This requires clear escalation rules and some confidence in the intern’s ability to recognize the edges of its own competence.
Level 4: Autonomous operation. The intern produces and acts on output without routine human review. This is appropriate only for low-stakes, well-defined, highly repeatable tasks where the cost of an error is low and the error is easily detected and corrected. Very few tasks that involve external-facing output or consequential decisions belong here.

Figure 3-1. Supervision Spectrum.
MARGIN - Which Level? Ask two questions for any task: what is the cost if the output is wrong and how detectable is an error before it causes harm? High cost or low detectability means a higher supervision level. Low cost and high detectability allows you to move down the spectrum.
What Makes a Task Safe to Delegate
Not all tasks are equal candidates for reduced supervision. Four factors determine how safely a task can be delegated to the intern with less oversight.
Reversibility. Can the output be corrected after the fact if it turns out to be wrong? A draft document that will be reviewed before sending is highly reversible. An automated email sent directly to a thousand customers is not. Tasks with reversible outputs can tolerate lower supervision levels.
Verifiability. Can a human quickly and reliably check whether the output is correct? A summary of a document can be checked against the document. A claim about a competitor’s pricing requires external verification and is harder to spot-check quickly. Easily verifiable outputs are safer at lower supervision levels.
Stakes. What is the consequence of an error reaching its destination uncorrected? An internal draft has different stakes from a regulatory submission. A formatting task has different stakes from a decision recommendation. Higher stakes demand higher supervision regardless of the intern’s track record.
Familiarity. How well do you know how the intern performs on this specific type of task? An intern who has produced a hundred reliable summaries of a particular document type has a track record. An intern being asked to do something new does not. Familiarity reduces but does not eliminate the need for oversight.

Figure 3-2. Delegation Matrix.
MARGIN - The Delegation Test Before reducing supervision on any task, ask: is this reversible, verifiable, low-stakes and familiar? If the answer to all four is yes, reduced supervision is reasonable. If the answer to any one is no, think carefully before stepping back.
The Autonomy Trap
There is a predictable pattern in how organizations adopt AI tools. In the early period, supervision is high. Over time, as the intern produces consistently good output on familiar tasks, supervision naturally relaxes. This is rational. What is less rational is the tendency for relaxed supervision to drift into absent supervision and for the scope of tasks delegated to the intern to expand without the supervision level being reset for the new task types.
The result is an organization that is applying spot-check oversight to tasks that warrant full review or no oversight at all to tasks that were never evaluated for autonomous operation. This is the autonomy trap: not a deliberate choice to operate without supervision, but a gradual slide that happens because the intern keeps producing output that looks good and nobody resets the defaults.
The defense against the autonomy trap is simple but requires discipline. Supervision levels should be set explicitly for each task type, reviewed periodically and reset to a higher level whenever the scope of the task changes. The fact that the intern has performed well on task A does not mean it will perform equally well on task B, even if A and B look similar from the outside.
MARGIN - Reset the Defaults When a task changes scope, treat it as a new task. The intern’s track record on the old version does not transfer automatically. Supervision levels should be set deliberately, not inherited.
Safety and the Limits of Intern Judgment
There are categories of output where supervision is not merely good practice but a hard requirement, regardless of how reliably the intern has performed in the past.
The first is outputs that affect individuals in consequential ways. Decisions about hiring, performance assessment, credit, access to services or any outcome that affects a person’s rights or opportunities require human judgment and human accountability. The intern can inform these decisions. It cannot make them.
The second is outputs that carry legal or regulatory exposure. Any output that will be used in a legal, compliance or regulatory context should be reviewed by someone with appropriate expertise before it is relied upon. The intern’s fluency in legal language does not make it a lawyer and its confidence is not a substitute for professional judgment.
The third is outputs in novel or ambiguous situations. The intern performs best on tasks it has seen many variations of. Novel situations, where the right approach is genuinely uncertain, are exactly where the intern’s tendency to produce confident, plausible-sounding output is most dangerous. Human judgment is most valuable precisely where the intern seems most sure.
MARGIN - The Non-Negotiables Decisions that affect individuals, outputs with legal or regulatory exposure and novel situations where the right answer is genuinely uncertain - these require human review regardless of supervision level. They are not candidates for delegation.
Building a Supervision Framework
A supervision framework does not need to be complex. What it needs to do is make supervision levels explicit, assign responsibility clearly and provide a mechanism for review.
A practical framework has three components. First, a task register: a list of the tasks your organization uses the intern for, with a supervision level assigned to each and the rationale for that level recorded. Second, a review trigger: a defined set of conditions that cause a supervision level to be reconsidered. A task moving to a new audience, a change in the regulatory environment, a cluster of errors on a previously reliable task type - any of these should trigger a review. Third, accountability: a named person responsible for each task category, who owns the supervision level and the decision to change it.
This does not require a large governance structure. For most organizations starting out with AI, a single document maintained by whoever owns the AI program is sufficient. What matters is that supervision levels are recorded rather than assumed and revisited rather than set once and forgotten.

Figure 3-3. Supervision Framework.
MARGIN - Write It Down A supervision framework that exists only in people’s heads is not a framework. Write down which tasks your intern handles, at what supervision level and who is responsible. Review it quarterly. The document is evidence that you are managing this thoughtfully - which matters when someone asks.
Chapter Summary
- Supervision is a spectrum, not a binary choice. Different tasks belong at different points on it.
- Four supervision levels cover most situations: review everything, spot check, exception-based review and autonomous operation.
- Four factors determine how safely a task can be delegated: reversibility, verifiability, stakes and familiarity.
- Supervision levels tend to drift downward over time without active management. Reset defaults whenever task scope changes.
- Some categories of output require human review regardless of supervision level: decisions affecting individuals, outputs with legal or regulatory exposure and novel situations.
- A practical supervision framework records task types, supervision levels, review triggers and named accountability.
Next: Chapter 4 - What Can Go Wrong: The Seven Risks of Generative AI
Chapter 4: What Can Go Wrong
Every technology that enters organizational life brings new failure modes. Some are obvious before they arrive. Most are not. Generative AI has been in widespread organizational use long enough that the failure modes are now reasonably well understood - which puts managers in the unusual position of being able to prepare for them before encountering them firsthand.
This chapter maps seven risks that any organization using generative AI needs to manage. They are not theoretical. Each has been observed in real organizations and in some cases has caused real harm. Understanding them does not guarantee they will be avoided, but it makes avoidance considerably more likely.

Figure 4-1. The Seven Risks.
Risk 1: Confident Wrong Answers
The intern produces confident, fluent, well-structured output regardless of whether that output is accurate. This is not a design flaw that will be corrected in a future version. It is a consequence of how large language models work: they predict plausible continuations of text rather than retrieving verified facts. The confidence is a property of the prose, not a signal of accuracy.
The risk this creates is specific. A manager who receives a plausible-sounding briefing document, a confident market analysis or a detailed competitive summary may act on it without checking. The document looks authoritative. The figures are specific. The argument is coherent. Only on investigation does it become clear that some of the figures were invented, that the case law cited does not exist or that the competitor described never launched the product in question.
The mitigation is not to distrust everything the intern produces. It is to distinguish between outputs that require verification and those that do not and to build verification into the workflow for the former. Factual claims, specific figures, legal references and any assertion that will be relied upon by someone who has not also checked it independently belong in the first category.
MARGIN - Verify Before You Rely The intern’s confidence is a property of the prose, not a signal of accuracy. Any specific claim that will be acted upon or passed to someone else needs to be checked against a primary source. Build verification into the workflow, not the review process.
Risk 2: Data Leakage
When a manager or employee pastes information into an AI system, that information leaves the organization’s controlled environment. What happens to it depends entirely on the policies of the AI provider - which vary considerably and change over time. In some configurations, inputs are used to train future models. In others, they are logged and retained. In still others, they are discarded immediately.
The risk is that sensitive information - client data, commercial terms, unreleased financial results, personal data covered by privacy regulation, strategic plans - is shared with an external system whose data handling practices may not meet the organization’s obligations. The fact that the output was useful does not mean the input was safe to provide.
The mitigation has two parts. The first is policy: establishing clear organizational guidance on what categories of information may and may not be pasted into AI systems and ensuring that guidance is understood and followed. The second is procurement: selecting AI tools based on their data handling commitments and ensuring those commitments are reflected in contracts.
MARGIN - What Stays In Not everything belongs in a brief to your Digital Intern. Client data, unreleased financials, personal data and strategic plans require clear policy guidance before they go anywhere near an external AI system. Set the policy before the incident, not after.
Risk 3: Regulatory and Legal Exposure
Generative AI intersects with a growing body of regulation in ways that are still being mapped. The areas of current concern include data protection and privacy, intellectual property, financial advice and product regulations, employment law and sector-specific requirements in areas including healthcare, legal services and financial services.
The exposure is not hypothetical. Organizations that use AI-generated content in customer communications may have obligations around disclosure. Those that use AI in hiring or performance management may face employment law questions. Those that use AI to generate advice in regulated sectors may find that the advice attracts regulatory scrutiny regardless of whether a human signed off on it.
The mitigation is not to avoid AI in regulated contexts - its usefulness in those contexts is real. The mitigation is to map the regulatory intersections before deploying AI in a new context and to involve legal counsel in that mapping. The question to ask is not “is this output useful?” but “what obligations does producing this output in this context create?”
MARGIN - Map Before You Deploy Before using AI in a new context - customer communications, hiring, advice, regulated sectors - ask what regulatory obligations that context creates. Involve legal counsel. The question is not whether the output is useful but whether producing it creates exposure.
Risk 4: Bias in Decisions
Large language models learn from text and text reflects the biases present in the society that produced it. This means that AI outputs can carry and amplify biases related to gender, ethnicity, age, geography and other characteristics - often without those biases being visible in the output itself.
The risk is highest when AI is used to support decisions that affect individuals: screening resumes, assessing performance, approving credit, allocating opportunities. An AI system that systematically produces outputs that disadvantage members of a particular group is causing harm even if no individual act of discrimination was intended. In many jurisdictions it is also illegal, regardless of intent.
The mitigation requires deliberate intervention. Organizations using AI in decisions that affect individuals need to audit those outputs for bias, to design processes that include human review of individual decisions and to maintain records that allow patterns to be identified and corrected. The intern does not know it is being biased. The manager does not always know either. The only reliable check is systematic monitoring.
MARGIN - Audit What Affects People Any AI output used in a decision that affects an individual - hiring, performance, credit, access - needs systematic monitoring for bias. The intern does not know it is producing biased output. The manager cannot assume it is not.
Risk 5: Reputational Harm
AI systems can produce output that is embarrassing, offensive, factually wrong or legally problematic - and they can produce it at scale, faster than human review can catch it. The reputational risk is not from the one document that gets checked before it goes out. It is from the thousand that do not.
The risk compounds when AI is used in external-facing contexts: customer communications, public statements, marketing materials, social media. A single widely-shared example of AI-produced content that is offensive or inaccurate can cause reputational damage disproportionate to the incident that produced it.
The mitigation is to maintain proportionate oversight for the stakes involved. Customer-facing content generated by AI requires human review before publication. High-volume, low-stakes internal content can tolerate lighter oversight. The supervision level should reflect the reputational consequence of a mistake reaching its destination.
MARGIN - Stakes Scale with Audience The reputational stakes of AI output are proportional to how many people see it and who they are. Customer-facing content needs human review. Internal drafts have more tolerance for error. Set supervision accordingly.
Risk 6: Dependency and Skill Atrophy
Organizations that delegate too much to AI too quickly risk losing the human skills that gave the AI outputs their value. A team that has stopped drafting documents from scratch gradually loses its ability to recognize when a draft is poor. A manager who has stopped analyzing data independently gradually loses the judgment needed to know when an analysis is wrong.
This is not an argument against AI adoption. It is an argument for managed adoption. The value of AI output depends partly on the human judgment applied to it. If that judgment atrophies because it is no longer exercised, the value of the output declines with it - while the confidence in the output may not.
The mitigation is to treat certain skills as deliberate practice rather than optional overhead. Teams that use AI to draft should still occasionally draft independently. Managers who use AI to analyze should still occasionally analyze the underlying data. The intern should augment the team’s capability, not replace the capability with dependence.
MARGIN - Keep the Skill The judgment that makes AI output valuable is yours, not the intern’s. If you stop exercising it, you lose it - and the output quality declines with it, even if you do not notice immediately. Deliberate practice is not inefficiency; it is maintenance.
Risk 7: Cost Overrun
AI tools are not free and the costs are not always obvious at the point of adoption. Direct costs include API usage fees that scale with volume, subscription costs for tools and platforms and the cost of storage and infrastructure. Indirect costs include the management time spent on oversight, the cost of errors that reach their destination and the cost of building and maintaining the organizational processes that AI requires.
The risk is that organizations adopt AI on the basis of the productivity gains it promises, without adequately accounting for the costs it introduces. A team that uses AI to produce ten times as much output is not necessarily ten times as productive if the cost of oversight, correction and quality management rises in proportion.
The mitigation is to build realistic cost models before scaling AI use, to monitor actual costs against projections and to evaluate AI initiatives on net value rather than gross output. The intern’s productivity is genuine. So is the cost of supervising them.
MARGIN - Net Value, Not Gross Output The value of AI adoption is the net gain after costs - including oversight, correction and management time. Measure it that way. A tool that produces ten times the output at ten times the oversight cost has broken even, not transformed the business.
Managing the Seven Risks Together
The seven risks are not independent. An organization with inadequate supervision (Risk 1) is also more exposed to reputational harm (Risk 5). An organization that has not set data policy (Risk 2) may also face regulatory exposure (Risk 3). A team that has allowed skill atrophy (Risk 6) is less able to detect confident wrong answers (Risk 1).
Managing these risks well requires treating them as a system rather than a checklist. A risk register that documents each risk, its likelihood in your specific context, its potential impact and the mitigations in place gives an organization a basis for prioritization. It also gives a board the evidence that AI adoption is being managed thoughtfully - which is increasingly what boards want to see.
The goal is not to eliminate risk. AI adoption involves genuine uncertainty and some level of risk is unavoidable. The goal is to take risk deliberately, with awareness of what you are accepting and why, rather than by default.

Figure 4-2. Risk Register.
MARGIN - The Risk Register Document the seven risks, their likelihood in your context, their potential impact and your mitigations. Review it quarterly. It is not just good governance - it is the evidence that you are making deliberate choices rather than hoping for the best.

Figure 4-3. Risk and Mitigation Pairs.
Chapter Summary
- Generative AI introduces seven manageable risks: confident wrong answers, data leakage, regulatory exposure, bias in decisions, reputational harm, skill atrophy and cost overrun.
- Each risk has a specific mitigation. None requires abandoning AI adoption - they require managing it deliberately.
- The risks interact. Weak supervision increases reputational exposure. Poor data policy increases regulatory risk. Skill atrophy reduces the value of AI output over time.
- A risk register that documents likelihood, impact and mitigation gives organizations a basis for prioritization and gives boards evidence of thoughtful governance.
- The goal is deliberate risk-taking, not risk elimination.
Next: Chapter 5 - The Accountability Conversation: When the Board Asks Why
Chapter 5: The Accountability Conversation
At some point, someone senior will ask why. Why did the AI produce that output? Who authorized it? Who checked it? What would have happened if it had been wrong? These questions arrive in different forms - a board presentation, a regulatory inquiry, an internal audit, a client complaint - but they share a common thread. They are questions about accountability and the answers need to exist before the questions are asked.
This chapter prepares you for that conversation. Not by offering defensive scripts, but by helping you build the governance structures that make the answers straightforward. An organization that has managed AI thoughtfully can answer board questions confidently, because the decisions it made are documented and the rationale behind them is clear. An organization that has not finds itself constructing answers under pressure - which is a poor position to be in.
The good news is that the accountability conversation is not technically demanding. It does not require the board to understand how large language models work. It requires them to understand how the organization is managing the risks. That is a management conversation and managers are well placed to lead it.
Why Boards Are Asking
Boards are asking about AI for three reasons and understanding which reason is driving a particular conversation shapes how you respond.
The first is fiduciary duty. Directors have a legal obligation to understand material risks to the organization. AI adoption, depending on how it is used, can create material risk in areas including data protection, employment law, intellectual property and reputational exposure. A board that has not asked about these risks is not doing its job. A management team that cannot answer the questions is creating board-level anxiety.
The second is stakeholder pressure. Investors, regulators, customers and employees are all increasingly interested in how organizations use AI. Boards are relaying that interest inward. A question that arrives from the board may have originated with an institutional investor’s ESG questionnaire, a regulator’s thematic review or a customer’s supplier due diligence process.
The third is genuine uncertainty. Many board members are personally uncertain about AI - what it can do, what it cannot do and what the right level of organizational engagement with it looks like. Questions that appear to be scrutiny are sometimes requests for help understanding a fast-moving area. The manager who can give a clear, confident, non-technical briefing on the organization’s AI posture is providing real value.
MARGIN - Know Which Question They Are Asking A board question about AI may be fiduciary duty, stakeholder relay or genuine curiosity. The answer is broadly the same - clear, confident and evidence-based - but knowing which is driving the conversation helps you pitch the level and tone correctly.
The Ten Questions a Board Will Ask
Experience across organizations that have had formal board-level AI discussions produces a consistent set of questions. They cluster into four themes: risk, governance, value and strategy.
These are not trick questions. They are the questions a thoughtful non-executive director would ask about any significant operational change. The manager who can answer all ten confidently is in a strong position.

Figure 5-1. Ten Board Questions.
On risk:
- What risks does our use of AI create and how are we managing them?
- What data are we putting into AI systems and what happens to it?
- What would happen if an AI output caused harm to a customer, employee or third party?
On governance: 4. Who is responsible for AI decisions in this organization? 5. How do we know when AI output has been checked before it was acted upon? 6. What would we do if something went wrong?
On value: 7. What is AI actually delivering for us and how do we know? 8. What is it costing us, including the costs we do not see directly?
On strategy: 9. Are we ahead of, behind or in line with our peers on AI adoption? 10. What decisions do we need to make at board level about AI in the next twelve months?
MARGIN - Prepare All Ten These ten questions will come, in some form, from any engaged board. Prepare written answers to all of them before the conversation. The act of writing the answers surfaces gaps in governance that are better discovered internally than by a non-executive director in a meeting.
Who Is Responsible for What
Accountability for AI in an organization is not a single point. It is a stack, with different responsibilities sitting at different levels. Confusion about where accountability sits is one of the most common causes of poor AI governance - and one of the most damaging when something goes wrong.
At the board level, accountability is for strategy and oversight: setting the appetite for AI risk, ensuring that management has the governance structures in place and receiving regular reporting on how AI is being used and what risks it is creating. The board does not operate AI systems. It ensures that those who do are doing so responsibly.
At the executive level, accountability is for policy and resources: establishing the organizational policies that govern AI use, allocating the resources needed for proper oversight and ensuring that accountability is clearly assigned below. An executive who has not assigned clear AI accountability to a named manager has a governance gap.
At the manager level, accountability is for implementation and supervision: ensuring that the organization’s AI policies are followed in their area, that supervision levels are appropriate for the tasks being performed and that errors are identified, corrected and reported. The manager is the person the board’s governance actually depends on.
At the operational level, accountability is for individual outputs: following the guidelines set by management, flagging uncertainty or error and not representing AI-generated content as independently verified when it has not been. The intern produces the output. The person who acts on it is accountable for having checked it appropriately.

Figure 5-2. Accountability Stack.
MARGIN - Name the Owner For every significant AI application in your organization, there should be a named person accountable for its governance. Not a team, not a function - a person. If you cannot name them, the accountability does not exist in practice.
Building an Audit Trail
One of the most practical things a manager can do to prepare for the accountability conversation is to ensure that AI-assisted decisions leave a trail. Not an elaborate one - a proportionate one. The question the audit trail needs to answer is: if this output caused harm, could we show what happened, who was involved and what checks were made?
A minimal audit trail for AI-assisted decisions has four elements. First, a record that AI was used: what system, for what purpose, on what date. Second, a record of what the output was or at least what it was used for. Third, a record of what human review was applied before the output was acted upon. Fourth, a record of who made the final decision.
For high-volume, low-stakes applications this can be lightweight - a log file, a workflow record or a process note. For high-stakes applications it needs to be more deliberate. A regulated decision supported by AI output that has no audit trail is a compliance risk, regardless of whether the output was correct.
The audit trail serves two purposes. The first is accountability: it allows the organization to demonstrate, after the fact, that AI was used responsibly. The second is learning: patterns of error that would not be visible in individual decisions become visible in aggregate when records exist.
MARGIN - Leave a Trail For any AI-assisted decision that could later be questioned, record that AI was used, what the output was, what review was applied and who decided. This does not need to be complex. It needs to exist.
The Sign-Off Protocol
A sign-off protocol is a defined set of rules about what level of human authorization is required before an AI output is acted upon, published or sent. It is the operational expression of the supervision levels discussed in Chapter 3, applied to the specific outputs that matter most in your organization.
A practical sign-off protocol specifies three things. First, the categories of output that require sign-off before use - customer communications, regulatory submissions, decisions affecting individuals and public statements are common candidates. Second, the level of seniority required to sign off - which varies by the stakes of the output. Third, what sign-off means in practice - not just “someone read it” but “someone with appropriate expertise reviewed it for accuracy and appropriateness.”
The sign-off protocol does not need to cover every AI output. It needs to cover the outputs where a failure to check would be consequential. Calibrating that scope is itself a governance decision that belongs at the manager or executive level.

Figure 5-3. Sign-Off Protocol.
MARGIN - Define What Sign-Off Means A sign-off protocol is only useful if sign-off means something. Specify what the reviewer is checking for, not just that a review occurred. “Reviewed for factual accuracy against primary sources” is a meaningful standard. “Reviewed” is not.
Having the Conversation
When the board conversation arrives, the manager who has built genuine governance has nothing to fear from it. The answers exist because the decisions were made and documented. The risks are known because they were assessed. The mitigations are in place because they were designed, not improvised.
The tone to aim for is confident and specific. Confident because you have done the work. Specific because vague reassurances do not satisfy a board that is asking on behalf of fiduciary duty or regulatory pressure. “We have policies in place” is less reassuring than “we have a data classification policy that prohibits client data from being entered into external AI systems, it was published in March and compliance is monitored through our quarterly audit process.”
Three things to avoid in the conversation: overconfidence about what AI can do, understatement of the risks and the claim that AI governance is someone else’s problem. The first damages credibility when the limitations become apparent. The second invites scrutiny. The third is almost never true - AI governance is always partly a management problem and boards know it.
MARGIN - Specific Beats Vague In a board conversation about AI, specific evidence of governance is far more reassuring than general claims about having policies. Know the date the policy was published, the name of the person who owns it and the last time it was reviewed. That specificity signals that the governance is real.
Chapter Summary
- Boards ask about AI for three reasons: fiduciary duty, stakeholder pressure and genuine uncertainty. The answer is broadly the same - clear, confident and evidence-based.
- Ten questions cover the terrain boards explore: three on risk, three on governance, two on value and two on strategy. Prepare written answers to all ten before the conversation.
- Accountability is a stack: board sets appetite and oversees, executives set policy and resources, managers implement and supervise, operational staff are responsible for individual outputs.
- A minimal audit trail records that AI was used, what the output was, what review was applied and who decided. It serves both accountability and learning.
- A sign-off protocol specifies which outputs require human authorization before use, what level of seniority is required and what sign-off means in practice.
- The manager who has built genuine governance has nothing to fear from the board conversation. Specific evidence of governance is more reassuring than general claims about having policies.
Next: Chapter 6 - The First Week: Where to Start Without Wasting Money
Chapter 6: The First Week
The most common mistake organizations make when adopting AI is starting with the wrong question. The question they ask is: what can AI do? The question they should ask is: what do we spend time on that AI could handle and what would we do with the time we got back?
These are different questions. The first leads to experiments. The second leads to results.
This chapter is about finding the results quickly, without the expensive detour through experiments that consume budget, generate enthusiasm and produce nothing durable. The “first week” in the title is a mindset rather than a timeline. It means the period before your organization has developed habits, assumptions or sunk costs around AI - the window when clear thinking is easiest and the cost of changing direction is lowest. That window closes quickly. Use it well.
The Quick Win Trap
There is a category of AI adoption that looks like success but is not. A team tries AI for drafting emails and finds it saves fifteen minutes a day. They report this upward. The initiative is declared a success. Budget is allocated. A center of excellence is formed. Eighteen months later, the organization has spent considerably more than the value of those fifteen-minute savings and the underlying work has not changed in any meaningful way.
This is the quick win trap: a genuine but modest improvement, elevated into a justification for investment that the improvement cannot support. It happens because the quick win is easy to measure, easy to communicate and emotionally satisfying - and because the harder question of where AI actually transforms something has not been asked.
The antidote is not to ignore quick wins. Some quick wins are genuinely valuable and a good place to start. The antidote is to distinguish between quick wins that are also scalable wins and quick wins that are only quick wins.
A scalable win has three properties. It applies to a large enough volume of work to produce meaningful aggregate savings. It improves in value as it is refined - the second month is better than the first because the team has learned how to brief the intern effectively. And it addresses a task that was genuinely constraining the team before - freeing time that was previously unavailable for higher-value work rather than simply making an existing task slightly faster.
MARGIN - Quick Win or Scalable Win? Before calling something a success, ask: does this apply at volume, does it improve with use and does it free time that was genuinely constrained? A quick win that fails all three is a demonstration, not a result.
Finding the Right Starting Points
The right starting points for AI adoption share a common profile. They are tasks that are high in volume, low in irreversibility and currently handled by people whose time is more valuable than the task deserves.
High volume matters because AI’s economics are different from human labor economics. A person who is ten percent faster at a task saves ten percent of the time they spend on it. An AI system that handles a task reliably at scale saves all of the time previously spent on it, for every instance. The leverage is in volume.
Low irreversibility matters because starting points are learning opportunities. The first wave of AI adoption will produce errors. The question is whether those errors are catchable and correctable before they cause harm. Tasks where the output goes through human review before acting on anything are safe learning environments. Tasks where the output acts directly on something consequential are not.
The people mismatch matters because time is the scarce resource the organization is trying to recover. Automating a task that was costing ten hours a week of a junior administrator’s time produces modest value. Automating the same task that was costing ten hours a week of a senior professional’s time produces considerably more - because the recovered time is worth more and because the senior professional will put that time to better use.
MARGIN - The Profile High volume, low irreversibility, done by people whose time is too valuable for it. If a task fits all three, it is a genuine starting point. If it fits one or two, it may still be worth doing - but manage expectations accordingly.
The Quick Win Filter
Before committing resources to any AI initiative, run it through a simple filter. The filter has two dimensions: the value of getting it right and the effort required to implement it responsibly.
High value, low effort: start here. These are the initiatives that produce results quickly without large investment in process change or infrastructure. Drafting routine documents, summarizing reports, generating first-pass analysis of structured data - tasks where the output is easily reviewed and the volume is high.
High value, high effort: plan carefully. These initiatives are worth pursuing but need proper scoping, clear governance and realistic timelines. Replacing a significant manual process, building AI into a customer-facing workflow or integrating AI with proprietary data sources belong here.
Low value, low effort: do selectively. These are the experiments - low stakes, low cost, potentially useful for building capability and confidence even if the direct value is modest. Useful in small doses, dangerous in large ones.
Low value, high effort: do not start. These are the initiatives that emerge from enthusiasm rather than analysis. They consume budget and attention without producing proportionate value and they crowd out the high-value work.

Figure 6-1. Quick Win Filter.
MARGIN - Filter First Apply the filter before the pilot. A pilot that was always going to be low value and high effort is not a learning opportunity - it is an expensive way to confirm something that clear thinking would have revealed in advance.
The Real Cost of an AI Initiative
The business case for an AI initiative almost always underestimates cost. This is not dishonesty - it is the result of making the visible costs the basis for the calculation while leaving the invisible costs out of the model.
The visible costs are straightforward: the subscription or API fees for the AI tools, any infrastructure required to support them and any direct professional fees for implementation. These are real costs and they belong in the model.
The invisible costs are where business cases typically fall short. The first is oversight: someone needs to check the outputs, manage the exceptions and handle the cases where the intern produces something that needs correction. This is not a one-time cost - it is an ongoing operational cost that scales with usage. Organizations that plan for the tool cost but not the oversight cost consistently find that their actual cost of operation is higher than projected.
The second invisible cost is process change. Introducing AI into an existing workflow almost always requires changing the workflow. People need to learn new habits, new checkpoints need to be introduced and old processes need to be retired. This takes time - more time than it appears to - and the productivity dip during transition is real.
The third invisible cost is error correction. Some proportion of AI outputs will be wrong and correcting them takes time. In a well-designed workflow this proportion is small and the correction is fast. In a poorly designed one it is neither. The error correction cost is genuinely difficult to estimate in advance, but ignoring it is a mistake.

Figure 6-2. Real Cost Model.
MARGIN - Model the Full Cost Tool fees plus oversight plus process change plus error correction. That is the full cost model. A business case that only includes tool fees is not a business case - it is an optimistic estimate masquerading as one.
Building a Business Case That Will Survive Scrutiny
A business case for an AI initiative that survives scrutiny has four components: a clear statement of the problem being solved, a realistic estimate of costs including the invisible ones, a credible estimate of benefits including the assumptions behind them and a set of success metrics that will allow the organization to know whether the initiative has delivered what was promised.
The problem statement matters more than it appears to. The clearest sign that a business case will not survive scrutiny is a problem statement that begins with “AI can now…” rather than “we currently spend…” The first is a technology looking for a problem. The second is a problem looking for a solution. Boards and CFOs are experienced at telling the difference.
The cost estimate has been covered above. What matters on the benefit side is being explicit about the assumptions. How much time will be saved per task? How many tasks does that apply to? What will the recovered time be used for? What is the value of that use? Each of these is an assumption that can be challenged. Having explicit, defensible answers to each challenge is what separates a credible business case from one that does not hold up in the room.
The success metrics close the loop. They allow the organization to know, at a defined point in the future, whether the initiative delivered what was promised - and to make an informed decision about whether to continue, expand or stop. A business case without success metrics is a commitment without accountability.

Figure 6-3. Intern ROI Calculation.
MARGIN - The Survivor Test Read the business case as a skeptical CFO would. Is the problem real and specific? Are the costs complete? Are the benefit assumptions explicit and defensible? Are there success metrics with a date? If the answer to any of these is no, the case is not ready.
Starting Small and Learning Fast
The right approach to the first wave of AI adoption is a portfolio of small, focused initiatives rather than a single large transformation. Small initiatives are faster to start, easier to evaluate and cheaper to stop if they do not deliver. They also produce learning - about how the intern performs on specific task types in your organization’s specific context - that cannot be obtained any other way.
The portfolio should be deliberately diverse. Different task types, different parts of the organization, different levels of output stakes. The goal is not to find the one AI use case that transforms everything - it is to build a map of where AI creates genuine value in your specific context and where it does not.
That map is the most valuable output of the first wave. It tells you what to expand, what to refine and what to stop. It also tells you something about your organization’s readiness - its capacity for oversight, its ability to change processes and its appetite for the kind of disciplined management that AI requires to deliver its potential.
MARGIN - Build the Map The goal of the first wave is not transformation. It is a map of where AI creates genuine value in your context. That map, built through small focused initiatives and honest evaluation, is worth more than any single large initiative that has not been tested.
Chapter Summary
- The right question is not what AI can do but what the organization spends time on that AI could handle and what the recovered time would be used for.
- Distinguish scalable wins from quick wins: scalable wins apply at volume, improve with use and free genuinely constrained time.
- The right starting points are high-volume, low-irreversibility tasks currently handled by people whose time is worth more than the task deserves.
- Filter initiatives by value and effort before piloting. Low value and high effort is not a learning opportunity - it is an expensive confirmation of something clear thinking would have revealed.
- The real cost of an AI initiative includes tool fees, oversight, process change and error correction. A business case that omits the invisible costs is not credible.
- A business case that survives scrutiny has a specific problem statement, complete costs, explicit benefit assumptions and defined success metrics.
- The goal of the first wave is a map of where AI creates genuine value in your context, not a single transformative initiative.
Next: Chapter 7 - Sector Briefings: AI Across Industries
Chapter 7: Sector Briefings
AI adoption does not look the same across industries. The use cases that generate most value in financial services are different from those in healthcare. The regulatory constraints facing a law firm are different from those facing a retailer. The risks that matter most in manufacturing are different from those in media.
This chapter provides eight self-contained briefings, one for each of the sectors where AI adoption is most active. Each briefing covers the same ground: the highest-value use cases, the risks specific to that sector and the regulatory context a manager needs to be aware of. The briefings are designed to be read independently - a manager in healthcare does not need to read the financial services section and vice versa.
One caveat applies to all eight. AI capabilities and the regulatory environment are both moving quickly. The briefings reflect the landscape as of mid-2026. The broad patterns are durable; specific regulatory details should be verified against current guidance before being relied upon.

Figure 7-1. Sector Map.
Financial Services
Where AI creates most value
Financial services organizations have found genuine productivity gains in three areas. The first is research and analysis: AI handles the initial synthesis of large volumes of market data, analyst reports and regulatory filings, freeing investment professionals for interpretation and judgment. The second is customer communications: AI drafts responses to routine queries, flags complex cases for human handling and maintains consistency across high-volume client correspondence. The third is compliance documentation: AI generates first drafts of regulatory reports, compliance submissions and policy documents, significantly reducing the time senior compliance staff spend on drafting.
The risks that matter most
The confidence problem is acute in financial services. An AI-generated market analysis that contains a plausible but incorrect figure can feed a decision with real financial consequences. Verification workflows are not optional - they are the price of using AI in any context where a number will be acted upon.
Data leakage is a particular concern because of the sensitivity of client financial data and the volume of material non-public information that financial services organizations routinely handle. The data classification questions discussed in Chapter 4 apply with additional force here.
The regulatory context
Financial services is one of the most heavily regulated AI environments. Regulators in most jurisdictions have issued guidance on AI use in financial services, with particular attention to model risk management, explainability and bias in credit and insurance decisions. The use of AI in advice-giving contexts is subject to suitability and fiduciary requirements that do not disappear because a machine generated the initial recommendation. Any AI deployment in a regulated advice context requires legal review before implementation.
MARGIN - Financial Services The confidence problem and data sensitivity both require active management. Verification workflows and clear data classification policies are the minimum. Anything touching advice, credit or insurance needs legal review before going live.
Healthcare
Where AI creates most value
Healthcare organizations have found AI most useful in three areas that do not directly touch clinical decisions. Administrative documentation - clinical notes, discharge summaries, referral letters - is the largest single source of productivity gain, with clinicians reporting meaningful reductions in documentation time. Patient communication - appointment reminders, pre-procedure information, follow-up instructions - is a high-volume, lower-stakes context where AI can operate with appropriate oversight. Operational analysis - bed utilization, staffing patterns, supply chain - is a third area where AI handles data synthesis that was previously done manually.
The risks that matter most
The stakes of error in clinical contexts are higher than in almost any other sector, which means that the non-negotiable categories from Chapter 3 apply in force. AI does not make clinical decisions. It supports the people who do. Any deployment that blurs this boundary - that presents AI output as clinical guidance rather than a tool for clinicians - is a governance failure, not just a risk.
Patient data is protected by stringent privacy regulation in most jurisdictions and the regulatory requirements for handling health data are more demanding than those for most other data categories. The data leakage risk discussed in Chapter 4 applies with particular severity.
The regulatory context
Healthcare AI operates in a complex regulatory environment that varies considerably by jurisdiction and by the nature of the AI application. Software that constitutes a medical device is subject to device regulation in most jurisdictions; the boundary between administrative AI and clinical AI is not always obvious and requires careful legal assessment. Patient data regulation - HIPAA in the US, the Data Protection Act and NHS-specific guidance in the UK and equivalent frameworks elsewhere - applies to any AI system that processes patient information.
MARGIN - Healthcare AI supports clinicians; it does not replace clinical judgment. Administrative and operational applications are the lowest-risk starting points. Any application that touches clinical decision-making requires careful regulatory assessment before deployment.
Legal Services
Where AI creates most value
Legal AI adoption has been faster and deeper than many observers expected. Document review - reading and summarizing large volumes of contracts, correspondence and evidence - was the first area where AI produced clear value and the gains are substantial. Contract drafting has followed: AI produces first drafts of standard agreements, non-disclosure agreements and routine commercial documents at a fraction of the time previously required. Legal research - synthesizing case law, statute and commentary - is a third area where AI can accelerate work that was previously time-intensive.
The risks that matter most
The hallucination problem is particularly dangerous in legal contexts. A legal brief that cites a case that does not exist is not just unhelpful - it exposes the lawyer and the firm to professional sanctions. Several high-profile examples of AI-generated legal documents containing fictitious citations have made this risk visible and real. Verification of every legal reference against a primary source is not optional in legal AI use - it is the basic minimum.
Client confidentiality creates data handling constraints that go beyond standard data protection requirements. The professional obligation of confidentiality may be compromised by inputting client matter information into external AI systems, depending on the system’s data handling practices. This requires careful assessment at the firm level before any external AI tool is used for client work.
The regulatory context
Legal AI is subject to professional regulation as well as data protection law. Bar associations and law societies in most jurisdictions are actively developing guidance on AI use in legal practice, with particular attention to supervision obligations, confidentiality and the duty of competence. The regulatory environment is developing rapidly and current guidance from the relevant professional body should be checked before implementing AI in any client-facing context.
MARGIN - Legal Services Verify every legal reference. No exceptions. Treat client matter data as confidential even when using AI tools with strong data commitments. Check current professional guidance from your bar association or law society before deploying AI in client work.
Retail and Consumer
Where AI creates most value
Retail has found AI most useful in three areas: personalization, operations and customer service. Product description generation - producing accurate, engaging descriptions for large catalogs - is a high-volume, relatively low-risk application where AI delivers clear productivity gains. Customer service: AI handles routine inquiries, order tracking questions and returns processing at scale, with human escalation for complex cases. Demand forecasting synthesis: AI assists in analyzing sales data patterns and generating first-pass forecast analyses for merchandising teams.
The risks that matter most
Customer-facing AI content carries reputational risk that internal applications do not. A product description that is inaccurate, a customer service response that is inappropriate or a promotional communication that contains a factual error reaches customers directly. The supervision levels discussed in Chapter 3 apply to customer-facing output regardless of how confident the intern appears.
Personalization at scale raises regulatory questions in jurisdictions with strong consumer protection frameworks, particularly where personalization involves pricing or where AI-driven recommendations could exploit vulnerabilities. These questions are worth examining before personalization initiatives scale.
The regulatory context
Retail AI intersects with consumer protection law, advertising standards and, increasingly, AI-specific regulation. The EU AI Act classifies certain retail AI applications - particularly those involving manipulation or subliminal techniques - as prohibited or high-risk, depending on their nature. Personalization that affects pricing is subject to price transparency requirements in many jurisdictions. Customer data used in AI applications is subject to data protection law.
MARGIN - Retail Customer-facing content needs human review before publication - the reputational stakes of a mistake are proportional to how many customers see it. Personalization initiatives that touch pricing should be reviewed for regulatory compliance before scaling.

Figure 7-2. Regulatory Watchlist.
Manufacturing
Where AI creates most value
Manufacturing AI adoption has concentrated in three areas. Maintenance documentation: AI generates and maintains technical documentation, work instructions and maintenance procedures, reducing the time engineers spend on documentation and improving consistency. Quality analysis: AI assists in analyzing quality data, identifying patterns in defect rates and generating reports for quality management teams. Supply chain intelligence: AI synthesizes supplier data, lead time information and inventory patterns to support procurement decision-making.
The risks that matter most
Manufacturing involves physical processes where errors can have safety consequences. AI-generated work instructions or maintenance procedures that contain errors are not just productivity problems - they can contribute to accidents. The verification requirements for any AI output that will be followed in a physical process are correspondingly higher than for purely administrative applications.
Integration with operational technology systems - production control, SCADA, industrial IoT - raises cybersecurity and reliability requirements that go beyond standard IT risk management. AI systems that interact with operational technology require specialist risk assessment.
The regulatory context
Manufacturing AI intersects with health and safety regulation, product liability law and, in regulated industries (pharmaceuticals, aerospace, food production), sector-specific quality and documentation requirements. The documentation requirements for AI-assisted processes in regulated manufacturing are particularly demanding - regulatory bodies expect evidence that human oversight was maintained at appropriate points, regardless of how much AI was involved.
MARGIN - Manufacturing AI-generated work instructions and maintenance procedures require higher verification standards than administrative output - they can affect physical safety. Anything touching operational technology needs specialist risk assessment.
Media and Communications
Where AI creates most value
Media organizations have adopted AI extensively in content production, with results that range from genuinely transformative to problematic. The areas of clearest value are: first-draft generation for structured content (earnings reports, sports results, weather summaries) where the output follows a predictable template and factual accuracy can be verified quickly; research and background synthesis for journalists and content teams; and translation and localization of content across languages and markets.
The risks that matter most
Accuracy is the core value of journalism and the core risk of AI adoption in media. An AI system that produces confident, well-written content that is factually wrong undermines the organization’s fundamental asset. The verification requirements for any factual claim in AI-assisted content are not lower than for human-written content - they are the same, because the reputational consequences of publishing inaccurate content are the same regardless of how it was produced.
Intellectual property questions are particularly active in media. The training data for most large language models includes published content, raising questions about copyright and originality that are being actively litigated in multiple jurisdictions. The legal landscape around AI-generated content and copyright is genuinely unsettled and media organizations should seek current legal advice.
The regulatory context
Media AI intersects with copyright law, advertising standards, defamation law and, increasingly, AI transparency requirements. Several jurisdictions require disclosure when AI is used to generate content in certain contexts. The EU AI Act’s provisions on AI-generated content and the obligations around synthetic media (deepfakes) apply to media organizations operating in European markets.
MARGIN - Media Accuracy standards for AI-assisted content are the same as for human-written content. Intellectual property questions around AI-generated content are unsettled - seek current legal advice before publishing AI-generated content at scale.
Professional Services
Where AI creates most value
Professional services firms - consulting, accounting, architecture, engineering - have found AI most productive in knowledge work that involves synthesizing large amounts of information into structured output. Research synthesis: AI reviews and summarizes relevant literature, case studies, precedents and data to support consulting and advisory work. Report drafting: AI produces first drafts of client deliverables - strategy documents, audit reports, feasibility studies - from structured inputs. Proposal development: AI generates first drafts of new business proposals, adapting standard frameworks to specific client contexts.
The risks that matter most
Client confidentiality and data sensitivity apply in professional services as they do in legal services. The professional obligation to maintain client confidence may be affected by the use of external AI tools for client work and the data classification questions discussed in Chapter 4 apply with force.
The quality of professional services output is the primary commercial differentiator and AI-generated content that is generic, inaccurate or poorly calibrated to a client’s specific context can damage client relationships and firm reputation. The checking and refinement process for AI-assisted client deliverables needs to be proportionate to the stakes.
The regulatory context
Professional services AI is subject to the regulatory frameworks of the specific profession - accounting standards bodies, engineering institutes, architectural professional bodies - as well as general data protection law. Audit in particular is subject to specific regulatory requirements around the use of technology in the audit process and AI use in audit contexts requires careful assessment against current regulatory guidance.
MARGIN - Professional Services Client data requires the same confidentiality protections whether or not AI is involved in the work. AI-generated client deliverables need checking calibrated to the stakes - a board-level strategy document has different requirements from an internal briefing note.
Public Sector
Where AI creates most value
Public sector AI adoption has been more cautious than in the private sector, reflecting the specific accountability obligations of government and public bodies. The areas where AI is being deployed most actively are: correspondence management - drafting responses to public inquiries and ministerial correspondence; policy research - synthesizing research, evidence and stakeholder feedback to support policy development; and internal knowledge management - making existing policy documents, guidance and precedents more accessible to staff.
The risks that matter most
Public sector AI carries accountability obligations that private sector organizations do not face in the same form. Decisions made by or with the assistance of AI in a public sector context are subject to public law principles - fairness, rationality, consistency, the right to reasons - that require the decision-making process to be explicable and defensible. AI that generates a recommendation but cannot explain its basis is not compatible with public law obligations in most jurisdictions.
The use of AI in decisions that affect individuals - benefit entitlements, planning applications, licensing decisions - is subject to particularly stringent requirements, including in many jurisdictions an obligation to provide human review on request.
The regulatory context
Public sector AI is subject to general data protection law, human rights obligations, public law principles and, in many jurisdictions, specific AI governance frameworks developed for government use. The UK government’s AI governance framework, the US executive orders on AI in government and the EU AI Act’s specific provisions for AI in public administration all apply depending on jurisdiction. Most public sector organizations are also subject to freedom of information obligations that may affect how AI-assisted decision-making is documented.
MARGIN - Public Sector AI-assisted decisions must be explicable and defensible against public law principles. Any application that affects individuals’ rights or entitlements requires human review capability. Check current government AI governance guidance for your jurisdiction.

Figure 7-3. Adoption Maturity.
Chapter Summary
- AI adoption looks different across sectors. Use cases, risks and regulatory contexts vary significantly and require sector-specific thinking.
- Financial services: strong gains in research, communications and compliance; acute data sensitivity and heavy regulatory oversight.
- Healthcare: administrative and operational applications are lowest-risk; clinical applications require careful regulatory assessment.
- Legal services: document review and drafting deliver clear value; verify every legal reference and treat client data as strictly confidential.
- Retail: customer-facing content needs human review; personalization initiatives touching pricing require regulatory assessment.
- Manufacturing: verification standards for AI output that affects physical processes are higher; operational technology integration needs specialist assessment.
- Media: accuracy standards are unchanged from human-written content; intellectual property questions are unsettled.
- Professional services: client confidentiality applies regardless of AI involvement; checking standards should be proportionate to stakes.
- Public sector: AI-assisted decisions must be explicable and defensible; individual-affecting decisions require human review capability.
Next: Chapter 8 - The Roadmap: From Pilot to Production
Chapter 8: The Roadmap
Most AI initiatives start well. A pilot is run, results are promising, enthusiasm is high. Then something happens. The pilot does not become a production system. The production system does not scale. The scaling effort consumes more resources than anticipated and delivers less value than projected. Eighteen months after a confident announcement, the organization is roughly where it started, with a smaller budget and more skepticism.
This failure pattern is common enough to have a name in some organizations: the pilot trap. It is not caused by bad technology or bad people. It is caused by the absence of a roadmap - a clear model of what the journey from initial experiment to embedded capability looks like and what decisions are required at each stage.
This chapter provides that roadmap. Four stages, each with a different focus and a different set of decisions. Understanding where you are and what the next stage requires is the most reliable way to avoid the trap.

Figure 8-1. Adoption Stages.
Stage 1: Experiment
The experiment stage is the shortest and in some ways the easiest. A small team, a specific task type, a defined time period. The goal is not to prove that AI works in general - it is to find out whether AI works for this task, in this organization, with the people and processes currently in place.
The experiment stage has three outputs, not one. The first is evidence about the task: does AI produce useful output on this type of work, at the quality level required, with the brief investment the team can make? The second is evidence about the organization: can the team use the tool effectively, does the workflow accommodate AI output, are the oversight processes manageable? The third is evidence about the economics: what does the tool actually cost to run, including oversight time and what productivity is being recovered?
Most organizations treat only the first output as the measure of success. This is how pilots get declared successful on the basis of output quality alone, while the organizational and economic evidence is ignored or deferred. When the initiative scales, the organizational friction and economic costs that were not examined in the pilot stage emerge and derail the project.
A well-run experiment answers all three questions deliberately. It ends with a decision document - a brief, honest summary of what was learned - rather than an enthusiastic presentation of the best outputs the tool produced.
MARGIN - Three Questions, Not One A successful experiment answers: does the output meet the quality bar, can the organization use it effectively and does the economics work at scale? Answering only the first question and ignoring the other two is how enthusiastic pilots become stalled production projects.
Stage 2: Prove
The prove stage is where most initiatives stall. The experiment worked, the decision was made to go further and now the task is to demonstrate that the initiative can deliver reliable value at a larger scale and over a longer time period than the experiment covered.
The prove stage has a different character from the experiment stage. In an experiment, novelty is a feature - people are engaged, oversight is tight and the team is interested in the results. In the prove stage, the initiative has to work when it is no longer new. The team has moved on to other priorities. The oversight that was careful in the first week has become routine. The results need to hold up when nobody is paying special attention.
This is where the governance structures discussed in Chapters 3 and 4 become load-bearing. Supervision levels need to be set explicitly and maintained consistently. Error tracking needs to be in place so that quality drift is visible. The brief templates developed in Chapter 2 need to become part of the standard workflow rather than being reinvented each time.
The prove stage is complete when the initiative has produced consistent value over a period long enough to give confidence that the experimental results were not exceptional. For most initiatives, this means at least three months of production use with documented outcomes.
MARGIN - Survive the Loss of Novelty The prove stage is where the initiative has to work without the energy of a new experiment behind it. Governance structures, error tracking and standardized briefs are what hold quality up when the novelty has worn off.
Stage 3: Scale
Scaling an AI initiative means applying it to more volume, more users or more task types. Each of these is a different kind of scaling challenge and they should not be conflated.
Volume scaling - doing more of the same thing with the same team - is the most straightforward. If the initiative has proved itself on a hundred documents per week, scaling to a thousand requires checking that the quality holds at higher volume, that oversight processes remain manageable and that the economics still work when tool costs scale with usage.
User scaling - rolling out to more people - is a change management challenge as much as a technical one. People who were not part of the experiment have no direct experience of the tool’s strengths and limitations. They need training that covers not just how to use the tool but what not to trust it with. Supervision levels need to be reset for new users, who have no track record with the tool.
Task scaling - applying the initiative to new task types - is the most dangerous form of scaling. The evidence from the prove stage applies to the original task type. A different task type is a different experiment and should be treated as one. The temptation to assume that a tool that works well on task A will work equally well on task B is responsible for a significant proportion of AI initiative failures.
MARGIN - Three Kinds of Scaling Volume, user and task scaling are different challenges. Volume scaling is primarily operational. User scaling is primarily change management. Task scaling is primarily a new experiment. Treat each accordingly.
Stage 4: Embed
An embedded AI capability is one that has become part of how the organization works - not a separate initiative with its own governance structure, but a normal part of the workflow that happens to involve AI at certain points.
The transition from scale to embed is less a stage than a shift in how the organization relates to the capability. In the scale stage, the AI initiative is still a thing the organization is doing. In the embed stage, it is a way the organization works. The distinction matters because the management effort is different. An embedded capability needs maintenance and governance, not project management.
The embed stage has two requirements. The first is that the governance structures - supervision levels, audit trails, sign-off protocols, data classification - have been absorbed into standard operating procedure rather than sitting in a separate AI governance framework. They are just how the process works. The second is that the capability is being maintained as the technology and the organization’s needs evolve. An embedded capability that was set up two years ago and never reviewed is a liability - the tool may have changed, the regulatory environment may have changed and the organization’s risk appetite may have changed.
MARGIN - Governance Becomes Process An embedded capability has governance built into the workflow, not bolted on as an AI-specific framework. If the governance requires a separate document to explain, it has not yet been embedded.
Where Initiatives Fail
Most AI initiatives fail at the transition between stages rather than within a stage. Understanding where the common failure points are makes them avoidable.
Experiment to prove is the most common failure point. The experiment produces good results in the controlled conditions of a pilot. The prove stage requires those results to hold under normal operating conditions - with less oversight, more varied input quality and the ordinary friction of organizational life. Initiatives that were designed to succeed as experiments rather than as production systems fail here.
Prove to scale is the second common failure point. The initiative has produced reliable value in its original context. The decision is made to scale. But scaling was not designed into the initiative from the start - the tools, processes and oversight mechanisms that work for a team of three do not simply extend to a team of thirty. The prove stage needs to include explicit design work on how scaling will work before the scaling begins.
Scale to embed is the third failure point and the least visible. The initiative appears to be working. Volume is high, users are trained, results look good. But the governance is still being maintained by the project team that launched the initiative and when that team moves on to other things, the governance deteriorates. The capability persists but the quality assurance that made it reliable does not.

Figure 8-2. Failure Points.
MARGIN - Design for the Next Stage Each stage should be designed with the next stage in mind. An experiment that was not designed for a production environment will not survive the transition. A proof that was not designed for scaling will not scale.
The Build vs Buy Decision
At some point in the roadmap, most organizations face a build versus buy decision: do we use a general-purpose AI tool from a vendor or do we build something specific to our needs?
The decision depends on four factors. The first is differentiation: does a custom solution create competitive advantage or is the underlying task generic? Summarizing documents is generic. Applying your organization’s specific analytical framework to documents is less so. The more specific the task, the stronger the case for custom development.
The second is data: does the task require training or fine-tuning on your organization’s own data or does a general-purpose model work well enough with the right brief? Many tasks that appear to require custom development can be handled adequately by a well-briefed general-purpose model.
The third is cost: what is the total cost of custom development, including ongoing maintenance, compared to the ongoing cost of a vendor tool? Custom development costs are routinely underestimated and maintenance costs - which continue indefinitely - are routinely omitted from the comparison.
The fourth is speed: how quickly does the organization need the capability and how long would custom development take? A vendor tool that is available now and meets eighty percent of the need often delivers more value than a custom solution that meets a hundred percent of the need in eighteen months.
MARGIN - Eighty Percent Now A vendor tool that meets eighty percent of the need today usually delivers more value than a custom solution that meets a hundred percent of the need in eighteen months. The gap between eighty and a hundred percent narrows as you learn how to use the tool well.
The Stage-Gate Checklist
A stage-gate is a defined checkpoint at which the organization decides whether to proceed to the next stage, refine the current stage or stop. Stage-gates are the mechanism that prevents initiatives from drifting forward by momentum rather than by evidence.
Each stage-gate has a set of questions that must be answered satisfactorily before the initiative proceeds. The questions are not a bureaucratic hurdle - they are the evidence of learning that justifies the next investment.

Figure 8-3. Stage-Gate Checklist.
The stage-gate checklist should be completed by someone who was not responsible for running the current stage. Self-assessment of a stage you ran is not reliable - the person who managed the pilot is invested in its success and will tend to interpret ambiguous evidence optimistically. A brief external review - even by a colleague from another part of the organization - produces a more honest assessment.
MARGIN - Independent Review Stage-gate assessment should not be done by the person who ran the stage. Investment in a stage’s success makes objective assessment difficult. A brief review by someone independent, even a colleague, produces a more honest picture.
Chapter Summary
- Most AI initiatives fail at stage transitions rather than within a stage. The roadmap makes the transitions explicit and manageable.
- Stage 1 (Experiment): answer three questions - does the output meet the quality bar, can the organization use it effectively and does the economics work at scale?
- Stage 2 (Prove): demonstrate consistent value over time without the energy of novelty. Governance structures become load-bearing at this stage.
- Stage 3 (Scale): volume, user and task scaling are different challenges requiring different approaches. Task scaling is a new experiment.
- Stage 4 (Embed): governance moves from a separate framework into standard operating procedure. The capability requires maintenance not project management.
- The build vs buy decision depends on differentiation, data requirements, total cost and speed. Vendor tools that meet eighty percent of the need now often outperform custom solutions that meet a hundred percent later.
- Stage-gates prevent momentum from substituting for evidence. Independent review at each gate improves assessment quality.
Next: Chapter 9 - Redesigning Work: Augmentation in Practice
Chapter 9: Redesigning Work
Augmentation is a word that has been used so often in discussions of AI that it has started to lose its meaning. It has become a reassurance - a way of saying that AI will help rather than replace - without specifying what help actually looks like in practice or what changes when a capable AI system joins the workflow.
This chapter is about the practical reality of augmentation: what changes, what stays the same, how to design the change deliberately rather than letting it happen by default and how to have the conversations with your team that the change requires.
The central argument is simple. Augmentation does not mean adding AI to existing work. It means redesigning work around what AI can do well and what people do well, so that the combination produces better results than either could alone. Organizations that add AI without redesigning work get modest gains. Organizations that redesign work around AI get something more substantial.
What Augmentation Actually Means
The easiest way to understand augmentation is to contrast it with two alternatives that look similar but are not.
The first alternative is automation: AI replaces a task entirely, with no human involvement in the output. Automation is appropriate for well-defined, high-volume, low-stakes tasks where the output does not require human judgment. It is not augmentation - it is replacement of a task, which may or may not require redesigning the role that previously contained it.
The second alternative is assistance: a human does the work largely as before, with AI available as a tool that can be consulted occasionally. Assistance produces modest gains - the convenience of having the intern available - without changing the fundamental structure of how work gets done. Most organizations that have “adopted AI” are at the assistance stage.
Augmentation is the third option and the most demanding. It requires identifying which parts of a role or workflow are best handled by AI and which are best handled by people and redesigning the workflow so that each handles what it does best. This is a management task, not a technology task. The technology is available. The redesign requires judgment about work, people and organizational context that only the manager can provide.
MARGIN - Assistance Is Not Augmentation Adding AI as an available tool without changing how work is structured is assistance, not augmentation. Assistance produces modest gains. Augmentation requires deliberately redesigning which parts of the work go to the intern and which stay with the person.
The Augmentation Audit
The starting point for redesigning work is understanding the current work in enough detail to make deliberate decisions about it. The augmentation audit is a structured way of doing this.
The audit maps the tasks that make up a role or workflow against two dimensions. The first is AI suitability: how well does AI handle this type of task, given the intern’s known strengths (drafting, transformation, volume consistency, explanation) and limitations (verified facts, current information, organizational context, judgment calls)? The second is human value-add: how much does human involvement add to this task, beyond what AI can provide? Tasks that score high on human value-add are tasks where experience, judgment, relationships, accountability or tacit organizational knowledge make a material difference to the outcome.
The audit produces four categories of task. Tasks that are high on AI suitability and low on human value-add are candidates for delegation to the intern with light oversight. Tasks that are low on AI suitability and high on human value-add stay with people. Tasks that score high on both require a hybrid approach - AI handles the volume and first-pass work, people handle the judgment and refinement. Tasks that score low on both are worth questioning regardless of AI.

Figure 9-1. Augmentation Audit.
MARGIN - Map Before You Delegate The augmentation audit maps every significant task in the role before deciding what to delegate. Delegating without mapping is guessing. The map takes time once. The guessing costs time continuously.
How Roles Change
When augmentation is done well, roles do not disappear - they shift. The parts of the role that were high volume and low judgment move to the intern. The parts that were high judgment and low volume become more central. The person in the role spends less time on the former and more on the latter.
This sounds straightforwardly positive and often it is. A analyst who previously spent sixty percent of their time gathering and formatting data and forty percent interpreting it can, with well-designed augmentation, spend twenty percent on data handling and eighty percent on interpretation. The role has more of what made it interesting and less of what made it tedious.
But the shift creates real challenges that managers need to anticipate. The first is skill gap: if the high-judgment tasks now take up more of the day, the person needs to be able to do them well. If their capability was calibrated to spending sixty percent of their time on lower-skill work, the shift may expose gaps that were not previously visible. The role has been upgraded and the person may or may not be ready for the upgrade.
The second challenge is identity. People often have strong attachments to the parts of their work that are being delegated to AI - not because those parts were the most intellectually demanding, but because they were familiar, because they created a sense of productivity or because they were how the person learned the role in the first place. Telling someone that AI will now do the part of their job they have done for ten years requires careful handling regardless of how positive the intended outcome is.
The third challenge is measurement. If a role’s output was previously measured by volume - documents processed, calls handled, reports produced - and augmentation means the person now handles far fewer but higher-value tasks, the old metrics no longer reflect the contribution. Managers who redesign roles without redesigning how those roles are measured create people who are doing better work but appearing to do less.

Figure 9-2. Role Redesign Model.
MARGIN - Redesign the Metrics Too When the work changes, the way you measure it needs to change with it. A person handling fewer but higher-value tasks under augmentation should not be measured by the volume metrics designed for the pre-augmentation role.
The Change Conversation
The most important management skill in augmentation is not understanding the technology. It is having an honest conversation with the people whose work is changing.
The conversation has three parts and all three need to happen - not once, but as an ongoing dialogue as the change develops.
The first part is transparency about what is changing and why. People deserve to know that their role is being redesigned, what the redesign involves and what the rationale is. Vague reassurances that “AI will just help” while the work quietly changes around someone are a failure of management, not a kindness. The person finds out eventually. Finding out through transparency builds trust. Finding out through experience erodes it.
The second part is honest acknowledgment of what is uncertain. Not every redesign goes smoothly. Not every skill gap is filled quickly. Not every measurement system is updated in time. Acknowledging that the transition will have friction - and that you will work through it together - is more credible than promising a seamless transformation.
The third part is genuine attention to the person’s concerns. The concerns will vary: some people will worry about job security, some about their ability to perform in a changed role, some about the loss of work they valued. None of these concerns should be dismissed. Each deserves a real response, which may mean a real commitment to training, to adjusted timelines or to revised expectations.

Figure 9-3. Change Conversation Framework.
MARGIN - Three Parts, Not One The change conversation has three parts: transparency about what is changing and why, honest acknowledgment of uncertainty and genuine attention to the person’s specific concerns. Skipping any one of the three produces a conversation that feels complete but leaves the person unsatisfied.
Designing for Skill Development
Augmentation changes what skills are most valuable in a role. It does not eliminate the need for skill development - it redirects it.
The skills that become more valuable under augmentation are broadly the skills that AI cannot replicate: judgment, interpretation, relationship management, accountability, creativity in ambiguous situations and the organizational knowledge that comes from experience. These are the skills that the redesigned role increasingly depends on.
The skills that become less central are those the intern handles well: drafting, reformatting, summarizing, searching and volume consistency. These skills do not become worthless - the ability to evaluate AI output depends partly on being able to do the underlying task - but they are no longer the primary focus of development.
This has implications for how organizations design learning and development programs. A program built around the skills that AI now handles is a program that is training people for the pre-augmentation version of the role. The more useful investment is in the skills that the augmented role depends on most heavily - and in the meta-skill of working effectively with AI, which includes knowing how to brief it, how to evaluate its output and how to maintain the judgment that makes evaluation reliable.
MARGIN - Train for the Augmented Role Learning and development programs should reflect the skills the augmented role requires, not the skills the pre-augmentation role required. Training people to do what the intern now does is preparing them for a role that no longer exists in its original form.
Chapter Summary
- Augmentation means redesigning work around what AI and people each do best. Adding AI without redesigning work produces assistance, not augmentation.
- The augmentation audit maps tasks against AI suitability and human value-add to identify what to delegate, what to keep and what requires a hybrid approach.
- When augmentation is done well, roles shift toward higher-judgment work. This creates skill gaps, identity challenges and measurement problems that managers need to anticipate.
- The change conversation has three parts: transparency about what is changing and why, honest acknowledgment of uncertainty and genuine attention to the person’s specific concerns.
- Augmentation changes what skills are most valuable. Learning and development programs should reflect the skills the augmented role requires, not the pre-augmentation role.
Next: Chapter 10 - The Intelligent Enterprise: Leading When AI is Everywhere
Chapter 10: The Intelligent Enterprise
There is a difference between an organization that uses AI and an organization that has learned to use AI well. The first has tools. The second has capability. Tools can be switched off, replaced or rendered obsolete by the next generation of technology. Capability - the organizational knowledge of how to direct AI effectively, how to manage its risks and how to extract genuine value from it - persists and compounds.
This chapter is about what it takes to lead the second kind of organization. Not the early adopter excitement of the first experiments, nor the project management discipline of scaling a pilot - but the steady, strategic leadership required when AI is everywhere in the organization and the question is no longer whether to use it but how to keep using it well.
That is a different kind of challenge and it requires a different kind of leadership posture.
The Leadership Shift
In the early stages of AI adoption, the leadership challenge is primarily managerial: identify good use cases, run good experiments, build appropriate governance. These are the challenges this book has addressed in the chapters that came before. They require good judgment, organizational discipline and a willingness to invest in governance that does not always feel urgent.
In the later stages - when AI is embedded across the organization, when most workflows have some AI component, when the team members who joined in the last two years have never known the organization without it - the leadership challenge shifts.
The shift has three dimensions. The first is from project to policy: the question is no longer what each initiative should do but what the organization’s overall approach to AI should be and how that approach is maintained consistently as technology and regulatory environments evolve.
The second is from oversight to culture: individual supervision decisions matter less than whether the organization has developed the judgment, habits and norms that make good supervision happen naturally. An intelligent enterprise does not rely on managers checking every output - it relies on people who have learned what to check, why checking matters and how to recognize when something needs escalation.
The third is from adoption to adaptation: the AI landscape will continue to change and probably faster than it has so far. Leading an intelligent enterprise means building an organization that can absorb and evaluate new AI capabilities without either rushing to adopt everything or reflexively resisting change.
MARGIN - Project to Policy The transition from project to policy is the moment AI governance stops being a special initiative and becomes part of how the organization runs. It requires explicit management attention - it does not happen automatically when enough pilots succeed.
The AI Maturity Model
Most organizations are somewhere on a journey from ad hoc AI use to genuine organizational capability. Understanding where your organization is on that journey is the first step to leading it deliberately toward the next stage.

Figure 10-1. AI Maturity Model.
Level 1 - Experimental: AI is used by individuals and teams independently, without organizational coordination. Use cases are discovered opportunistically. There is no policy, no governance and no systematic evaluation of what is working. The risk at this level is that the organization has less visibility into how AI is being used than it thinks.
Level 2 - Coordinated: The organization has begun to coordinate AI use. There is a recognized list of approved tools, emerging policy on data handling and some cross-team learning about what works. Governance exists but is fragmented. The risk at this level is that coordination creates the appearance of control without the substance.
Level 3 - Governed: The organization has clear policies, supervision frameworks and accountability structures. AI use is documented, risk is actively managed and there is a process for evaluating new tools and use cases. The risk at this level is that governance becomes an end in itself - a compliance exercise rather than a genuine management tool.
Level 4 - Optimized: The organization has developed genuine expertise in using AI well. Briefing is skillful, oversight is calibrated, learning is systematic and governance is embedded in workflow rather than sitting alongside it. The risk at this level is complacency - the assumption that what works today will continue to work as the technology evolves.
Level 5 - Adaptive: The organization is genuinely capable of evaluating and absorbing new AI developments quickly and wisely. It has the internal expertise to assess new capabilities, the governance structures to deploy them safely and the culture to use them thoughtfully. This is the intelligent enterprise.
MARGIN - Know Your Level Honest assessment of where the organization currently sits is more useful than aspirational claims about where it wants to be. The level determines the right focus for leadership attention - governance at Level 2, optimization at Level 3, adaptability at Level 4.
The Ten Questions an Executive Should Be Able to Answer
Just as Chapter 5 prepared managers for board-level questions about AI, this chapter prepares executives for the questions that define genuine AI leadership. These are not the defensive questions a board asks - they are the strategic questions an executive should be asking themselves.

Figure 10-2. Ten Executive Questions.
- What is our organization’s AI risk appetite and who approved it?
- Which AI applications in our organization carry the most significant risk and what is being done to manage each?
- Who is accountable for AI governance overall and what does that accountability include in practice?
- How do we know when AI is being used in ways that fall outside our policies?
- What is the total cost of our AI program, including oversight, process change and error correction?
- What value has our AI program delivered and how do we know?
- How do our AI capabilities compare to our most capable competitors?
- What regulatory changes in the next twelve months are most likely to affect our AI program?
- What organizational capabilities - skills, processes, culture - are we building for the long term and which are we outsourcing to vendor tools?
- If our primary AI vendor disappeared tomorrow, what would be the impact and how quickly could we recover?
An executive who cannot answer these questions confidently does not have governance - they have activity. The difference matters when something goes wrong, when a regulator asks or when a competitor makes a move that requires a rapid strategic response.
MARGIN - Activity Is Not Governance An AI program that produces reports, runs pilots and holds governance committee meetings may or may not have genuine governance. The test is whether the executive can answer the ten questions. If not, the program has activity.
Building Organizational Capability
The most important strategic choice an executive makes about AI is not which tools to adopt. It is how much of the capability to build inside the organization versus how much to depend on vendors and consultants.
Tool dependency is the default. It is faster to set up, cheaper in the short term and requires less organizational investment. The organization acquires AI capability in the form of subscriptions and the capability grows as the vendor improves the tool.
Organizational capability is harder to build. It requires investment in people, in learning, in processes and in the organizational habits that make AI use effective. It takes time to develop and it does not appear on a vendor invoice.
The case for organizational capability is that it is genuinely durable. Vendors change their pricing. Tools become obsolete. Regulatory environments shift in ways that require rapid adaptation. An organization with genuine internal capability - people who know how to evaluate AI systems, how to brief them effectively, how to govern their use and how to adapt when the landscape changes - is resilient in ways that a tool-dependent organization is not.
The right answer is not to build everything internally. Vendor tools will remain the primary delivery mechanism for AI capability in most organizations. The right answer is to ensure that the organization’s understanding of what it is doing - its ability to direct, evaluate and govern its AI use - resides in the organization, not in the vendor relationship.

Figure 10-3. Capability vs Dependency.
MARGIN - Own the Understanding The capability that matters is not the tool - it is the organizational understanding of how to use the tool well, evaluate its output honestly and govern its use safely. That understanding must live in the organization, not in a vendor relationship that can be ended.
Strategy at the Speed of AI
AI capabilities are developing faster than most organizations’ strategy cycles. A three-year technology strategy written in 2023 was already partially obsolete by 2024. An organization that sets its AI strategy and then executes against it for three years will find that the strategy no longer fits the environment it was designed for.
This is not an argument against strategy. It is an argument for a different kind of strategy - one that sets clear principles and direction while building the organizational capacity to adapt quickly to changed circumstances.
The principles that hold across technological change are the ones worth setting in strategy. What is the organization’s risk appetite for AI? What categories of decision will always require human judgment? What data will the organization never put into external AI systems? These principles do not become obsolete as the technology evolves.
The specific implementations - which tools, which use cases, which workflows - are better managed through shorter cycles: quarterly reviews of what is working, annual reviews of the broader program and ad hoc reviews whenever a significant new capability or regulatory development warrants one.
The organization that can think strategically about AI without being locked into a fixed implementation is the one that will navigate the next five years well.
MARGIN - Principles over Plans Set principles that hold across technological change: risk appetite, human judgment requirements, data policy. Manage specific implementations on shorter cycles. A three-year AI implementation plan is likely to be wrong. A clear set of principles is likely to remain useful.
The Manager’s Enduring Role
Throughout this book, the Digital Intern metaphor has carried the argument that managing AI is, at its core, a management challenge - not a technical one. The intern is capable, tireless and well-read. They need clear instructions, appropriate supervision, honest assessment of their limitations and a manager who knows what to keep.
That description does not change as the intern gets better. A more capable intern still needs clear instructions. The instructions just become more sophisticated, the supervision more nuanced and the assessment of limitations more demanding. As AI systems become more capable - and they will - the premium on good management judgment does not decrease. It increases.
The organizations that will use AI best over the next decade are not the ones that adopt the most tools or move the fastest. They are the ones that develop the most capable management of AI - the clearest direction, the most honest evaluation, the most thoughtful governance and the most deliberate approach to building capability that endures beyond any individual tool.
That is the intelligent enterprise. And building it is, first and last, a management job.
MARGIN - The Intern Gets Better As AI systems become more capable, the premium on good management judgment increases rather than decreasing. A more capable intern given poor direction produces more capable poor output. The management challenge scales with the technology.
Chapter Summary
- The leadership challenge shifts from project management to policy, from oversight to culture and from adoption to adaptation as AI becomes embedded across the organization.
- Five levels of AI maturity run from experimental to adaptive. Honest assessment of current level determines the right focus for leadership attention.
- Ten questions define genuine AI executive leadership. An executive who cannot answer them confidently has activity, not governance.
- The most important strategic choice is how much AI capability to build inside the organization versus depending on vendors. Organizational capability is more durable; tool dependency is faster to acquire.
- AI strategy should set clear principles that hold across technological change and manage specific implementations on shorter cycles.
- As AI systems become more capable, the premium on good management judgment increases. The organizations that use AI best are those with the most capable management of it.
Next: Conclusions - Managing the Intern Well
Conclusions
At the start of this book, we introduced a metaphor: your Digital Intern. Brilliant, tireless, extraordinarily well-read - and in need of careful management.
That metaphor has carried us through ten chapters, from the basics of what the intern actually knows to the strategic challenge of leading an organization where AI is everywhere. It is time to bring it home.
What You Have Learned
You have learned that the intern’s confidence is not a signal of accuracy and that the fluency of the output is no guarantee of the correctness of what it contains. You have learned to brief the intern well - to give clear instructions, relevant context and defined constraints - because the quality of what you get out is largely determined by the quality of what you put in.
You have learned that supervision is a spectrum, not a switch and that the right level of oversight depends on the stakes of the task, the reversibility of the output and the track record the intern has built on this specific type of work. You have learned the seven risks that AI adoption introduces and the mitigations that make each manageable. You have learned how to answer a board’s questions about AI with confidence, because the governance structures behind those answers are real rather than improvised.
You have learned where to start - with high-volume, low-reversibility tasks done by people whose time is worth more - and how to build a business case that will survive a skeptical CFO. You have learned that sector context matters, that the roadmap from pilot to embedded capability has predictable failure points and that avoiding them requires designing each stage with the next stage in mind.
And you have learned that augmentation is not addition. Adding AI to existing work produces modest gains. Redesigning work around what AI and people each do best produces something more substantial - if you manage the transition thoughtfully, redesign the metrics alongside the work and have the honest conversations with your team that the change requires.
What Has Not Changed
Through all of this, one thing has not changed: the management fundamentals.
Clear expectations. Appropriate oversight. Honest evaluation of what is working and what is not. The judgment to know which decisions require human accountability and which can be safely delegated. The courage to tell a board something it does not want to hear. The discipline to measure net value rather than gross output.
These are the skills this book has asked you to apply to a new kind of colleague. They are not new skills. They are the skills that good managers have always needed, applied to a context that is genuinely new.
The intern is not a replacement for management judgment. The intern is a reason to exercise it more deliberately.
What Comes Next
AI capabilities will continue to develop and probably faster than the pace of the last few years. The systems available to managers in 2028 will be more capable than the ones this book was written about, in ways that are not fully predictable today.
What is predictable is that the organizations that manage those systems well will be the ones that have developed genuine capability - not just familiarity with the current generation of tools, but the organizational knowledge of how to direct AI effectively, evaluate its output honestly and govern its use safely. That capability, built now, will compound.
The intelligent enterprise is not a destination. It is a practice - the ongoing, deliberate management of AI as it becomes more capable and more embedded in organizational life. It requires the same things it has always required: clear thinking, honest assessment and the willingness to keep improving.
A Final Word on the Intern
The intern will get better. The models that power the Digital Intern are improving continuously and the improvements will be significant. Tasks that currently require careful supervision will become more reliable. Tasks that currently require human judgment will begin to look like candidates for delegation.
This is a reason for optimism, not complacency. A more capable intern given poor direction produces more capable poor output. A more capable intern given good direction - clear briefs, appropriate oversight, honest feedback and a manager who knows what to keep - produces something genuinely valuable.
The technology will change. The management challenge will not.
Manage the intern well.
Appendix A: Decision Framework Templates
This appendix collects the key decision frameworks from across the book in a single reference. Each template is designed to be used directly - in a meeting, a governance review or a planning session. They are starting points, not fixed formats. Adapt them to your organization’s terminology and context.
A-1: The Augmentation Audit
Use this to map tasks in a role or workflow before deciding what to delegate to AI.
For each significant task, score it High / Medium / Low on two dimensions, then record your recommendation.
Task: _______________________________________________
AI suitability (High / Medium / Low): _______
High if the task involves drafting, summarizing, transforming, formatting or applying a consistent approach at volume. Low if it requires current information, verified facts, organizational context or judgment calls.
Human value-add (High / Medium / Low): _______
High if the task depends on experience, relationships, accountability, tacit organizational knowledge or consequential judgment. Low if it is primarily mechanical or templated.
Recommendation:
- High AI suitability + Low human value-add -> delegate to intern with light oversight
- High on both -> hybrid: AI handles volume and first pass, people handle judgment
- Low AI suitability + High human value-add -> keep with people
- Low on both -> question whether the task needs to be done at all
Copy this block for each task in the role or workflow.
A-2: The Four-Part Brief Template
Use this when briefing your Digital Intern on any task where output quality matters.
Role Who is the intern for this task? What perspective or expertise should they bring?
Example: You are a communications advisor helping a senior manager prepare for a difficult team meeting.
Task What specifically do you need? Be precise about format, length and purpose.
Example: Write a one-page briefing note summarizing the three main concerns likely to be raised and suggesting a response to each.
Context What does the intern not already know that is essential for this task?
Example: The meeting follows a restructure announcement last week. The team has concerns about role changes and reporting lines. The manager wants to acknowledge concerns without making commitments that have not yet been approved.
Constraints What should the output not include? What limits apply?
Example: Do not reference specific salary changes. Keep the tone calm and factual. No longer than one page.
A-3: The Supervision Level Decision
Use this to assign and record supervision levels for AI-assisted tasks.
Task description: _______________________________________________
Reversibility - can errors be corrected before they cause harm?
- High - output reviewed by human before acting
- Medium - errors detectable quickly after acting
- Low - errors may not surface until harm is done
Verifiability - can a human quickly check whether the output is correct?
- High - easily checked against a source
- Medium - requires some effort to verify
- Low - difficult or time-consuming to verify
Stakes - what is the consequence if the output is wrong?
- High - significant harm to individuals, organization or reputation
- Medium - correctable but costly
- Low - minor and easily fixed
Familiarity - how well do we know how the intern performs on this task type?
- High - strong track record on this specific task type
- Medium - some experience, some uncertainty
- Low - new task type, no track record
Recommended supervision level:
- Level 1 - review everything (any High stakes or Low familiarity)
- Level 2 - spot check (Medium stakes, Medium familiarity)
- Level 3 - exception-based (Low stakes, High familiarity, clear escalation rules)
- Level 4 - autonomous (Low stakes, High reversibility, High verifiability only)
Named owner: _______________________________________________
Review date: _______________________________________________
A-4: The Risk Register
Use this to document and manage the seven risks of AI adoption in your organization. Complete one row per risk. Review quarterly.
Risk 1 - Confident wrong answers
- Likelihood in our context (High / Medium / Low): _______
- Potential impact (High / Medium / Low): _______
- Mitigations in place: _______________________________________________
- Owner: _______________________________________________
Risk 2 - Data leakage
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Risk 3 - Regulatory exposure
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Risk 4 - Bias in decisions
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Risk 5 - Reputational harm
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Risk 6 - Skill atrophy
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Risk 7 - Cost overrun
- Likelihood: _______
- Impact: _______
- Mitigations: _______________________________________________
- Owner: _______________________________________________
Last reviewed: _______________________________________________
A-5: The Business Case Checklist
Use this before presenting a business case for an AI initiative.
Problem statement
- The problem is stated in terms of what the organization currently spends time or money on - not in terms of what AI can do
- The problem is specific and measurable
Costs
- Tool fees and subscriptions included
- Infrastructure costs included
- Oversight and checking time estimated and costed
- Process change and training costs estimated
- Error correction costs estimated
- Total cost model reviewed by someone independent of the initiative
Benefits
- Time saved per task specified
- Volume of tasks specified
- Value of recovered time specified and justified
- Assumptions listed explicitly and available for challenge
Success metrics
- Specific metrics defined
- Baseline measurement taken or planned
- Review date specified
- Named person responsible for reporting
A-6: The Stage-Gate Questions
Use these at each stage transition to decide whether to proceed, refine or stop.
Gate into Prove (experiment complete when…)
- Output quality meets the defined bar
- The organization can use it effectively without special support
- The economics work at the volume projected
- A decision document has been written and reviewed independently
Gate into Scale (prove complete when…)
- Consistent results over at least three months of production use
- Error tracking in place and reviewed
- Supervision levels explicit and maintained
- A scaling plan documented before scaling begins
Gate into Embed (scale complete when…)
- Volume, user and task scope all assessed separately
- New users trained and supervised as new starters
- Task scaling treated as a new experiment with its own gate
- Governance owner named and active
Ongoing gate (embed healthy when…)
- Governance absorbed into standard operating procedure
- Quality reviewed at least quarterly
- Named owner for each application still in role and engaged
- Regulatory context reviewed for changes since last review
All gates should be assessed by someone independent of the team that ran the current stage.
A-7: The Ten Board Questions - Prepared Answers Template
Use this to prepare for a board-level conversation about AI. Complete before the meeting.
On risk
-
What risks does our use of AI create and how are we managing them?
Your answer: _______________________________________________
-
What data are we putting into AI systems and what happens to it?
Your answer: _______________________________________________
-
What would happen if an AI output caused harm to a customer, employee or third party?
Your answer: _______________________________________________
On governance
-
Who is responsible for AI decisions in this organization?
Your answer: _______________________________________________
-
How do we know when AI output has been checked before it was acted upon?
Your answer: _______________________________________________
-
What would we do if something went wrong?
Your answer: _______________________________________________
On value
-
What is AI actually delivering for us and how do we know?
Your answer: _______________________________________________
-
What is it costing us, including the costs we do not see directly?
Your answer: _______________________________________________
On strategy
-
Are we ahead of, behind or in line with our peers on AI adoption?
Your answer: _______________________________________________
-
What decisions do we need to make at board level about AI in the next twelve months?
Your answer: _______________________________________________
Appendix B: A Manager’s Glossary
This glossary defines the thirty terms a manager is most likely to encounter in AI conversations. Definitions are written for the boardroom, not the machine room. Technical precision has been traded for useful clarity.
Agent / AI agent An AI system that can take actions in the world - browsing the web, running code, sending emails, interacting with other software - rather than just producing text. Agents can operate with more autonomy than standard AI assistants and require correspondingly more careful governance. The “Digital Intern” described in this book is a simple agent when it takes actions rather than just producing output.
Artificial general intelligence (AGI) A hypothetical AI system with human-level capability across all cognitive tasks. No current AI system qualifies. The term is often used in strategic discussions and investment contexts; when you encounter it, treat it as speculative rather than descriptive of anything that exists today.
Augmentation Using AI to enhance human capability rather than replace it. Augmentation means redesigning work so that AI handles the tasks it does best - volume, consistency, first drafts - while people focus on tasks requiring judgment, relationships and accountability. Contrast with automation.
Automation Using AI or software to replace a task entirely, without ongoing human involvement. Automation is appropriate for well-defined, repeatable, low-stakes tasks. It is distinct from augmentation, which involves ongoing human-AI collaboration.
Bias Systematic patterns in AI output that disadvantage certain groups or produce unfair outcomes. Bias in AI typically reflects bias in the training data, which reflects the biases present in the texts the system learned from. Particularly significant when AI is used in decisions affecting individuals.
Context window The amount of text an AI system can process at once - both what you give it and what it produces. Systems with larger context windows can handle longer documents and more complex conversations. Practically, this means that very long documents may need to be split for AI processing.
Data leakage The risk that sensitive information shared with an AI system leaves the organization’s controlled environment. Depending on the AI provider’s policies, inputs may be stored, logged or used to train future models. Requires clear organizational policy on what information may be shared with external AI systems.
Embedding A mathematical representation of text as a set of numbers, used to measure the similarity between pieces of text. Embeddings allow AI systems to find content that is similar in meaning rather than just in exact wording. Used in search, recommendation and document retrieval systems.
Fine-tuning Adapting a general-purpose AI model by training it further on a specific dataset - for example, training a general language model on your organization’s documents to make it more familiar with your terminology and style. More involved and expensive than prompting but can produce better results for specific applications.
Foundation model A large AI model trained on broad data that can be adapted to a wide range of tasks. The models that power most commercial AI applications - including the systems described in this book - are foundation models. Examples include GPT-4, Claude and Gemini.
Generative AI AI systems that produce new content - text, images, code, audio - rather than just classifying or analyzing existing content. The systems this book is primarily concerned with are generative AI systems that produce text.
Governance The policies, processes and accountability structures that determine how AI is used in an organization. Good AI governance specifies who is responsible for what, what oversight is required and how decisions are made and recorded. The absence of governance is not the absence of AI use - it is the absence of visibility and control over AI use.
Guardrails Technical or procedural constraints placed on an AI system to prevent it producing certain types of output. Guardrails may be built into the AI system itself by its developer or added by the organization deploying it. They reduce but do not eliminate risk.
Hallucination The production by an AI system of confident, well-formed statements that are factually incorrect. Hallucination is a consequence of how language models work - they predict plausible text rather than retrieve verified facts - and cannot be entirely eliminated. It requires systematic verification of factual claims.
Human in the loop A design principle for AI systems in which a human reviews and approves AI output before it is acted upon. The degree of human involvement can vary from reviewing everything to reviewing only flagged exceptions. Central to the supervision frameworks discussed in this book.
Inference The process of running an AI model to generate output. When you send a message to an AI system and receive a response, that response is generated through inference. Inference has a cost - in computing resources and often in money - which scales with usage volume.
Large language model (LLM) The type of AI model that underlies most current AI assistants and chatbots. LLMs are trained on large quantities of text and learn to predict what text should come next. Their capability to produce fluent, contextually appropriate text across a wide range of topics is the source of both their usefulness and their hallucination risk.
Model The AI system itself - the mathematical structure that has been trained to perform a task. When people refer to “the model,” they mean the underlying AI system, distinct from the interface through which you access it. Different models have different capabilities, costs and limitations.
Multimodal Capable of processing or producing multiple types of content - text, images, audio, video. Multimodal AI systems can, for example, analyze an image and describe it in text or generate an image from a text description. Increasingly common in commercial AI systems.
Prompt The instruction or input you give to an AI system. The quality of the prompt significantly affects the quality of the output. Prompt engineering is the practice of designing prompts to reliably produce good output - reframed in this book as the management skill of briefing your Digital Intern well.
Prompt engineering The practice of designing effective instructions for AI systems. Includes techniques for specifying role, task, context and constraints clearly and for iterating on prompts to improve output quality. The subject of Chapter 2 of this book.
RAG (retrieval-augmented generation) A technique for giving AI systems access to specific documents or data sources when generating responses. Rather than relying only on what the model learned during training, a RAG system retrieves relevant content from a defined set of documents and uses it to inform the response. Useful for applications requiring access to organizational knowledge.
Risk appetite The level of AI-related risk an organization is willing to accept in pursuit of its objectives. Risk appetite should be set explicitly at board or executive level, not left to emerge from individual project decisions. It determines what supervision levels are appropriate and what categories of AI use are permissible.
Supervision level The degree of human oversight applied to AI output before it is acted upon. This book defines four levels: review everything, spot check, exception-based review and autonomous operation. The appropriate level depends on the stakes, reversibility and verifiability of the output.
System prompt Instructions given to an AI system before the user’s input, typically by the organization or developer deploying the system rather than the end user. System prompts set the AI’s role, behavior and constraints for a given application. They are a primary governance tool for organizations building AI-powered products.
Temperature A setting that controls how predictable or varied an AI system’s output is. Low temperature produces more predictable, consistent output. High temperature produces more varied, creative output. Relevant when building AI applications where consistency or creativity is a priority.
Token The unit in which AI systems process text. A token is roughly equivalent to three-quarters of a word in English. AI systems have limits on how many tokens they can process at once (context window) and charge for usage based on tokens processed.
Training data The text, images or other content used to train an AI model. The model learns patterns from this data, which determines both its capabilities and its limitations. Training data that over-represents certain sources or perspectives will produce a model with corresponding biases.
Use case A specific application of AI to a defined task or problem. “Using AI to draft client emails” is a use case. “Using AI” is not. Identifying specific use cases before investing in AI tools is a prerequisite for sensible business case development and governance design.
Zero-shot Asking an AI system to perform a task without providing examples of what a good response looks like. Contrasted with few-shot prompting, which includes examples. Zero-shot works well for simple, well-defined tasks; few-shot is useful for tasks requiring a specific format or style.
Appendix C: Further Reading
This appendix points to the most useful books, papers and resources for managers who want to go deeper on specific topics. Each entry includes a brief note on what makes it worth reading and which chapter of this book it relates to most closely. Resources are organized by theme rather than chapter, since most span more than one area.
The AI landscape moves quickly. Online resources in particular may have changed since this list was compiled. Where possible, pointers are to primary sources or established publications that are likely to remain accessible.
Understanding AI: The Mental Model
For managers who want a deeper technical foundation without becoming engineers, these resources explain how large language models work at a level that is genuinely useful without being overwhelming.
“Attention Is All You Need” - Vaswani et al. (2017) The original research paper describing the transformer architecture that underlies most modern AI systems. Technically demanding, but reading the abstract and introduction gives a sense of the intellectual leap that made current AI possible. Available free online.
“A Jargon-Free Explanation of How AI Large Language Models Work” - Timothy B. Lee and Sean Trott, Ars Technica (2023) One of the clearest plain-language explanations of how LLMs work. Covers tokens, training, context windows and why hallucination happens. Available free online.
“What Is ChatGPT Doing… and Why Does It Work?” - Stephen Wolfram (2023) A long, careful walkthrough of how language models work, from someone who has thought deeply about computation. More demanding than the Ars Technica piece but more thorough. Available free on Wolfram’s website.
AI Strategy and Leadership
For the strategic and leadership dimensions covered in Chapters 9 and 10.
“Competing in the Age of AI” - Marco Iansiti and Karim Lakhani (Harvard Business Review Press, 2020) Written before the current generation of generative AI but prescient about the organizational transformation AI requires. Strongest on the economics of AI-native businesses and what they imply for incumbents.
“Power and Prediction: The Disruptive Economics of Artificial Intelligence” - Ajay Agrawal, Joshua Gans and Avi Goldfarb (Harvard Business Review Press, 2022) A rigorous treatment of AI as a technology that reduces the cost of prediction and what that means for organizational strategy. Useful for thinking through where AI creates competitive advantage and where it does not.
“The Age of Surveillance Capitalism” - Shoshana Zuboff (PublicAffairs, 2019) A challenging read, but essential context for managers thinking about data governance and the political economy of AI. Particularly relevant to Chapters 4 and 5.
Governance and Risk
For the governance frameworks and risk management covered in Chapters 3, 4 and 5.
“Algorithmic Accountability: A Primer” - Data and Society Research Institute A clear introduction to the governance challenges posed by algorithmic decision-making. Available free from the Data and Society website. Relevant to the bias and accountability discussions in Chapters 4 and 5.
“Responsible AI Practices” - Google AI Google’s published principles and practices for responsible AI development. Useful as a reference for organizations developing their own frameworks. Available free on Google’s AI website.
EU AI Act - European Parliament and Council (2024) The full text of the EU’s landmark AI regulation. Dense, but the risk classification framework in Articles 6–7 and Annex III is directly relevant to any organization assessing its AI governance obligations in European markets. Available free on the EUR-Lex database.
“NIST AI Risk Management Framework” - National Institute of Standards and Technology (2023) The US government’s framework for managing AI risk. Comprehensive and well-structured. Particularly useful for organizations in regulated sectors or those supplying to government. Available free on the NIST website.
Augmentation and the Future of Work
For the people and organizational dimensions covered in Chapters 9 and 10.
“The Technology Trap” - Carl Benedikt Frey (Princeton University Press, 2019) A historical perspective on how technology transitions affect labor markets. Sobering and rigorous. Useful context for managers navigating the augmentation conversation with their teams.
“Human Compatible: Artificial Intelligence and the Problem of Control” - Stuart Russell (Viking, 2019) Written by one of the leading AI researchers, this book argues for a fundamental rethink of how AI systems are designed to ensure they remain aligned with human values. More technical than most books in this list but highly readable.
“The Work of the Future: Building Better Jobs in an Age of Intelligent Machines” - David Autor, David Mindell and Elisabeth Reynolds (MIT Press, 2022) An empirically grounded examination of how AI and automation are reshaping labor markets, with policy implications. Useful for managers thinking about workforce strategy.
Sector-Specific Resources
For the sector context covered in Chapter 7. These are starting points rather than comprehensive guides - each sector has a substantial literature of its own.
Financial services: The Financial Stability Board’s reports on AI in financial services provide a regulatory perspective. The Bank of England’s AI Public-Private Forum published useful findings on AI governance in financial services.
Healthcare: The NHS AI Lab in the UK and the FDA’s Digital Health Center of Excellence in the US both publish guidance on AI in healthcare that is accessible to non-technical readers.
Legal services: The Law Society (UK) and the American Bar Association both publish guidance on AI in legal practice that is updated regularly and covers professional obligations as well as practical applications.
Public sector: The Government Digital Service (UK) and the US Government’s AI.gov both publish frameworks and case studies for AI in government that are relevant to public sector managers.
Practical Prompting and Briefing
For the practical skills covered in Chapter 2.
“The Art of Prompting” - Various authors, Anthropic documentation Anthropic publishes detailed guidance on effective prompting for Claude. Practical and frequently updated. Available free at docs.anthropic.com.
“Prompt Engineering Guide” - DAIR.AI A comprehensive open-source guide to prompt engineering techniques. More technical than Chapter 2 of this book but a useful reference for teams who want to systematize their briefing practices. Available free at promptingguide.ai.
Staying Current
The AI landscape changes faster than any book can track. These sources are worth following for ongoing developments.
The Gradient - A publication covering AI research and applications for informed non-specialists. Consistently high quality.
Import AI - Jack Clark’s weekly newsletter on AI developments. Technical but accessible to motivated non-specialists.
AI Snake Oil - Arvind Narayanan and Sayash Kapoor’s newsletter and book on AI limitations and hype. Essential counterweight to vendor claims and media coverage.
MIT Technology Review - Reliable, balanced coverage of AI developments with appropriate scepticism about hype.
This reading list reflects resources available at the time of writing. The AI field moves quickly - check for more recent editions and resources, particularly for regulatory and governance topics.
Free Books
The SingleStore Cookbook: Recipes for Multi-Model, Machine Learning and AI Data Engineering
A hands-on cookbook covering SingleStore’s multi-model capabilities, from time series and geospatial data through vector search, machine learning pipelines and AI-powered applications. The recipes draw on first-hand experience building applications with the platform and are organized into four parts:
- Multi-Model
- Streaming and Big Data Pipelines
- Machine Learning
- AI and Agentic Frameworks
Seven Vector Databases in Seven Days
A practical guide that takes one vector database per day and pairs each with a use case chosen to showcase that database’s strengths. Databases covered:
- PostgreSQL and pgvector - Semantic job search
- MongoDB Atlas - Recipe finder
- Pinecone - E-commerce search
- Weaviate - Research paper discovery
- Neo4j - Fraud detection
- Snowflake - Customer support analytics
- Databricks - RAG over internal documents
Each chapter is self-contained, comes with a Jupyter notebook and gives an assessment of when you’d look elsewhere.
Generative AI: A Manager’s Guide
A practical guide for managers, directors and executives who need to make decisions about AI in their organizations, not the engineers building it, but the people responsible for making it work well. The book uses a single central metaphor, the Digital Intern, to frame what AI is genuinely good at, where it falls short and what managing it actually requires. It covers governance, risk, board-level accountability, business case building and the organizational change of moving from pilot to embedded capability.
Seven Ways to Do Vector Search in Python
A practitioner’s guide that benchmarks seven Python libraries against the same dataset, measuring recall and latency consistently so you can compare like-for-like. Libraries covered:
- FAISS
- Voyager
- Scikit-learn NearestNeighbors
- PyNNDescent
- USearch
- Chroma
- LanceDB
Each chapter covers one library, explains what it’s genuinely good at and when you’d reach for something else.
Real-Time Vehicle Tracking with Neo4j, Databricks Lakebase and OpenStreetMap
A fleet operations demo that puts ten simulated vehicles onto real road networks loaded from OpenStreetMap. The architecture:
- Neo4j Aura holds the road network graph
- Databricks Lakebase stores live vehicle positions
- Databricks Lakehouse handles historical analytics
Two Streamlit dashboards display live positions and trend data. The primary demo uses the London Borough of Merton, with additional configurations for San Francisco and Singapore.
Real-Time Supply Chain Routing with Neo4j, Snowflake Postgres and Confluent Kafka
In progress.