Back to blog

AI for Small Business: A 90-Day Implementation Guide

Where to start with AI at work: how to pick the first use case, the one-page policy, what to keep out of the tool, and why most pilots die in month two.

Straight answer: the obstacle to using AI in a small company is not price or technology — it is choosing the first use case and having a written rule about what may go into the tool. An AI subscription now costs less than a phone line, and most pilots die in month two for predictable reasons: a task without volume, scattered data, no metric defined before starting, and nobody responsible after the demo. This guide gives the method for picking the first task, the one-page policy that covers governance for a small business, and a 90-day plan to find out whether to scale — or kill it.

Picking the task: the quadrant that prevents a dead pilot

"Start small" is advice, not a method. The method fits in three questions about the candidate task:

  1. Does it happen often? Fewer than five times a week builds neither habit nor visible return.
  2. Is the right answer predictable? Is there a recognized correct way to do it, or does it hinge on judgment that shifts case by case?
  3. What does a mistake cost? Is the error caught before it reaches a customer, or does it become a real problem?
Task profileExamplesStart here?
High volume, predictable answer, cheap errorAnswering repeat questions, first drafts of commercial copy, meeting summaries, sorting inbound emailYes — start here
High volume, predictable answer, expensive errorIssuing documents, final customer replies without reviewOnly with mandatory human review
Low volume, heavy judgmentDecisions about people, contracts, strategic pricingNo
High volume, unpredictable answerNegotiation, collectionsNo

A first-quadrant task has a decisive advantage: it proves value in days, not quarters — and that is what carries the project once the initial enthusiasm fades.

The four traps that kill a pilot

Trap 1 — volume that isn't there. The company picks the most annoying task instead of the most frequent one. No repetition, no habit; no habit, and the tool becomes a closed tab.

Trap 2 — data nobody can find. AI needs company context (price list, return policy, customer history) and it lives in three places, two of them in someone's head. A pilot without organized data produces generic answers, and generic answers destroy the team's trust in week one.

Trap 3 — no metric before starting. Without a baseline, the result becomes opinion. "It felt faster" does not support a decision to scale and does not survive the first invoice.

Trap 4 — nobody owns it. After the demo, usage depends on each person remembering. With no one maintaining the standard prompt, onboarding new people and reviewing output, the pilot dissolves on its own.

None of these traps is technical. All are managerial — which is why switching tools almost never fixes them.

The one-page policy

AI governance in a small company needs no committee and no 40-page document. It needs four written answers, in a file anyone can read in two minutes:

1. What may be done with AI. List the approved tasks by name. A closed list avoids both bad extremes: shadow usage and paralysis.

2. What never goes into the tool. The short, non-negotiable list: customer personal data (name, ID, phone, address), identifiable financial data, information under NDA, access credentials. Without a minimal classification of what is sensitive in your business, the policy is dead letter — start with that list.

3. Who approves what reaches a customer. Any generated text that reaches a customer passes through a named person. AI writes; a human signs.

4. Who owns it. One person responsible: maintains the policy, chooses the tools, answers questions and reviews what went wrong.

One page with those four answers covers most of the real risk in a small company and, more importantly, makes usage discussable — the opposite of the scenario where half the team already uses AI without telling anyone.

Data protection, for companies without a legal team

The question in every meeting is whether customer data can go into the tool. The practical answer has three parts:

  • Responsibility stays with the company, not the vendor. If personal data was mishandled, your business answers for it.
  • Consumer plans typically train on your conversations. Data pasted there leaves your control and does not come back. Business plans generally do not — and that difference is what justifies paying.
  • Anonymizing solves nearly everything. "Customer who purchased three times this year, average order $80, complained about delivery time" gives enough context to be useful without identifying anyone.

The split that works day to day: text and reasoning in the assistant; personal data in your systems.

The 90-day plan

Weeks 1-2 — map and write. List the five most repeated tasks of the week and run each through the quadrant. Pick one. Write the one-page policy. Record the baseline of the metric that task affects (average time, weekly volume, rework).

Weeks 3-6 — pilot with one person. One person, one task, one written standard prompt. The goal is not adopting AI company-wide: it is finding out whether that specific task improves. Log what goes wrong — that becomes your review checklist.

Weeks 7-10 — the second person. If the metric moved, a second person joins using the same standard prompt. Here comes the real test: does the gain depend on the talent of the user or on the written process? If it depends on the person, you have a trick, not a process.

Weeks 11-12 — decide. Compare the metric against the baseline and make one of three calls, explicitly: scale (more tasks, more people, paid plan), hold (works at current size, does not scale yet) or kill (the number never moved — and admitting that early is the cheapest decision available).

Note that the plan asks for no new budget in the first weeks. It asks for the two things actually missing: task selection and a written rule.

The framing error: AI is not an IT project

A company that treats AI as a tool purchase measures adoption in logins. One that treats it as process redesign measures how long a quote takes to go out, how many proposals get sent, how much rework disappeared.

That changes who leads: not the person who understands technology, but the one who owns the process. And it changes what gets trained: not "how to use the tool", but "what our process looks like now that this step costs five minutes instead of an hour". Leadership training is not an accessory to the project — it is the part that turns individual gains into company results.

Where to learn this properly

This guide covers use-case selection, the policy and the decision cycle. Anyone who wants the full path — strategy, governance, process redesign and scale — will find it inside a business school built for owners and leaders. The featured schools on Tandria are on this page and the course catalog shows what each one covers.

If your company needs to train the whole team on its own process, that is a different path: the employee onboarding track and corporate university cover that side.

In one sentence

AI in a small company does not fail for lack of technology: it fails from a badly chosen task, scattered data, a missing metric and no owner — and all four are settled before you sign up for any tool.

Frequently asked questions

Where should a small business start with AI?

Start with a task that has three traits at once: it happens many times a week, the correct answer is predictable, and a mistake is cheap and caught before it reaches a customer. Answering repeat questions, drafting first versions of commercial copy and summarizing meetings all sit in that quadrant. Collections, decisions about people and anything shipped to a customer unreviewed do not.

Is it safe to paste customer data into a general AI assistant?

On consumer tiers, conversations are typically used to train the model, which means data you paste leaves your control and does not come back — and the responsibility stays with your company, not the vendor. The safe practice is to split it: text and reasoning go to the assistant; personal data stays in your systems. When context is needed, anonymize before pasting.

What is AI governance and when does a small company need it?

Governance is writing down who may use AI, for what, with which data, and who answers for the output. A small company needs it the day the second person starts using it — before that it is an individual habit, after that it is distributed risk. No committee required: one page with four answers covers most of it.

Why do most company AI projects fail?

Almost always for four reasons, none of them technical: a use case without real volume, data that is scattered or inaccessible, no metric defined before starting, and nobody owning the process after the pilot. The tool works in the demo and dies in week three, when enthusiasm fades and no routine sustains the use.

How do you measure the ROI of AI?

Measure the process, not the tool. Before starting, record a baseline for a metric the business already cares about: average time to send a quote, proposals sent per week, hours spent on month-end close. After 60 days, compare the same number. Individual productivity gains that never show up in a business metric are a feeling, not a return.