AI Automation Strategy: An Operator's Guide

How I think about AI automation strategy after 25 years running companies: the maturity ladder, why pilots fail, agentic AI, build vs. buy, and what to measure.

Key takeaways

The one-sentence version

The maturity ladder

Why most AI pilots die

Agentic AI, for operators specifically

Build vs. buy, without the religion

Governance is not optional, and it's not hard

What I actually measure

Contrarian takes I've earned the hard way

If I were starting in your chair: the first 90 days

How to use this page

Most of what's written about AI automation strategy is written by people who have never met a payroll. It reads like it, too — frameworks stacked on frameworks, none of them dirtied by an actual deployment that had to survive contact with a front office, a skeptical ops manager, and a budget meeting.

I've been on the other side of that for 25 years. I run an MSP, a business phone company, and an AI automation agency, which means I've watched hundreds of small and mid-market companies from the inside — their file servers, their phone queues, their half-finished CRM rollouts. I've deployed automation that paid for itself in six weeks, and I've personally killed AI pilots that were never going to work no matter how good the model was. This page is the strategy I actually use, plus links into the deeper pieces I've written on each part of it.

One disclosure, up front, so you can weigh my bias honestly: I own companies that sell some of what I'm about to describe. When that matters to a specific recommendation, I'll say so. The upside of that bias is that everything here comes from deployments I was financially accountable for — not from a survey of other people's press releases.

Here's the whole strategy, compressed: AI succeeds or fails on the boring foundation underneath it — your processes, your data, your security — and the companies that win treat AI as the last mile of an operations discipline, not the first step of a transformation.

Everything else on this page is elaboration.

I evaluate every company against the same ladder, whether it's a 12-person HVAC shop or a 400-person healthcare group. Where you sit on it dictates what you should do next — and skipping rungs is where most of the wreckage comes from.

Rung 1 — Tribal. The process lives in someone's head. If Brenda quits, the process quits with her. You cannot automate what you cannot describe.

Rung 2 — Documented. The process exists on paper (or in a checklist, or a wiki). It's still done by hand, but two different people can do it the same way. This rung looks bureaucratic and unsexy. It's also where roughly half the ROI of "AI" actually lives, because documenting a process is the first time most companies discover the process doesn't make sense.

Rung 3 — Automated. Deterministic workflows: when X happens, do Y. Zapier, Make, n8n, Power Automate — no intelligence required, just plumbing. Most companies I meet think they need AI when what they actually need is six months of living on this rung. My piece on what to automate first is essentially a field guide to rung 3.

Rung 4 — AI-assisted. A human still owns the outcome, but a model does the heavy lifting inside the workflow — drafting the response, classifying the ticket, extracting the invoice data. This is where I put most SMBs today, and honestly, it's a great place to be. The examples I've collected from real deployments are overwhelmingly rung-4 stories.

Rung 5 — Agentic. Software that pursues a goal across multiple steps, uses tools, and decides its own next action — with guardrails you designed. Real, valuable, and dangerous to attempt from rung 1. I wrote a plain-English explainer on what agentic AI actually is because the term is being applied to everything with a chat window.

The strategic question is never "how do we get AI?" It's "what rung are we on, per process?" — because a company is never on one rung. Your invoicing might be rung 3 while your sales follow-up is rung 1. If you want the fuller version of this with a sequenced plan attached, that's my SMB automation roadmap.

I've now seen enough failed pilots — my clients' and, early on, a couple of my own — that the pattern is boring. Pilots don't fail because the AI wasn't smart enough. They fail for foundation reasons that were visible before the pilot started:

1. The process was never defined. You point AI at a rung-1 process and it faithfully automates the confusion. The model gets blamed; the missing SOP was the culprit.

2. The data wasn't there. The pilot assumed clean customer records, categorized tickets, or a searchable knowledge base — and the company had none of those. AI is a compounding return on data hygiene you already did. It is a terrible substitute for it.

3. Nobody owned the outcome. A pilot run by "the IT guy plus whoever's curious" has no executive owner, no success metric, and no budget line. It dies quietly at renewal time.

4. Security and access were an afterthought. The moment an AI system can read your files or send email on your behalf, it inherits every access-control sin you've been deferring. I've written a full automation security guide on this, and I'll be blunt about my bias here: my MSP sells security remediation, so I'm the guy who profits when you take this seriously. I'd still tell you the same thing if I didn't — an automated process is a process that executes your mistakes at machine speed. When the gap is bigger than a checklist can fix, that's foundation work for an IT partner — the kind of security groundwork my team at TEXMG does before we let any agent near production systems.

5. Expectations were set by demos. A demo is a best case with the failure modes edited out. Production is failure modes with occasional best cases. Budget your enthusiasm accordingly.

Before I let any client spend real money on AI, I make them walk through my AI readiness checklist. It's deliberately unglamorous. Companies that pass it rarely have failed pilots; companies that fail it and proceed anyway keep me supplied with cautionary tales.

The agentic wave is real — I use agents daily in my own companies — but the framing around it is upside down. Vendors pitch agents as digital employees. Operators should think of them as extremely fast, extremely literal new hires with no judgment and no fear of consequences.

That framing gets the strategy right automatically:

The difference between an agent and a chatbot matters more than most buyers realize — a chatbot answers, an agent acts, and the risk profiles are completely different. I've broken that down in AI agents vs. chatbots, which I'd call required reading before any vendor meeting where the word "agent" appears on a slide.

Where agents genuinely shine for SMBs right now, in my direct experience: internal-facing work with a human at the end of the pipe. Research and briefing, drafting, data entry across systems that don't integrate, triage and routing, first-pass QA. Where I still keep humans firmly in the loop: anything customer-facing that commits the company to something, anything touching money, and anything where a 2% error rate creates a liability rather than a redo.

I build automation for a living and I still tell clients to buy more often than you'd expect. The decision is not about capability — almost anything can be built. It's about maintenance gravity: every workflow you build is a small system you now operate forever, with monitoring, error handling, credential rotation, and a bus-factor problem.

And a disclosure-flavored note on the third path: some companies shouldn't build or assemble — they should hand the whole thing to someone accountable for the outcome. That's literally what my agency sells, so discount accordingly. If you want the done-for-you version of everything on this page, my team wrote its own implementation-side guide to AI strategy for SMBs, which covers the delivery half I'm deliberately not selling you here.

"AI governance" sounds like something that requires a committee and a consultant. For a small or mid-market company it's mostly one document and three habits:

The document: an AI use policy that says what tools are approved, what data can and cannot be pasted into them, who approves new tools, and what happens with AI-generated work product. I wrote a practical AI policy guide for small businesses with a template, because the alternative — shadow AI — is already happening in your company whether you've blessed it or not. Your people are pasting things into free chatbots today. The policy's job is to make the safe path the easy path.

That's it. Governance at this scale is less about compliance theater and more about making sure the company knows what it deployed.

The fastest way to tell whether an AI initiative is real is to ask what number it moves. If the answer is "engagement" or "innovation," it's a hobby. Hobbies are fine — I have several — but they shouldn't be in the operating budget.

The measures I hold my own deployments to:

One number I deliberately do not lead with: percent of tasks automated. It optimizes for automating easy trivia instead of valuable work.

These are positions I hold from deployments, not from theory. Some of them annoy vendors, including occasionally my own sales team.

1. Most companies should spend their first "AI budget" on documentation and data cleanup. Unsexy, unfundable at a conference, and the highest-ROI move available from rung 1 or 2. The AI gets dramatically better later because of it.

2. "We're waiting for AI to mature" is usually cover for "our operations are a mess." The models are not the bottleneck for the median SMB. They haven't been for a while.

3. Small companies have an AI advantage over enterprises right now. Fewer approval layers, faster iteration, blast radius small enough to try things. This window will not stay open forever — I've written about where I think AI automation is heading, and the short version is that the tooling advantage is temporary but the operating-discipline advantage compounds.

4. Headcount panic is aimed at the wrong decade. The near-term risk to your business isn't AI replacing your staff — it's a competitor whose staff use AI well. The skills gap is trainable, and I keep a running list of the AI skills that actually matter in 2026 — most of them are judgment skills, not tool skills.

5. The chat interface is a transitional form. The durable value is AI embedded invisibly inside workflows, where nobody "uses AI" any more than they "use electricity." If your strategy is "roll out a chatbot," you've strategized about the wrapper.

6. Pilot purgatory is a choice. Companies that run pilot after pilot without production deployments don't have a technology problem; they have a decision-rights problem. Someone has to own the yes.

Strategy pages have a way of ending without telling you what Monday looks like, so here's the sequence I actually run when I step into a company as a fractional CTO or when Talos takes on a new automation client. Adjust the calendar to your size; don't adjust the order.

Days 1–30: inventory and triage. List every recurring process the company runs — not the org chart, the processes. For each one, note its rung on the maturity ladder, who owns it, what breaks when it breaks, and roughly how many hours a month it eats. This exercise is tedious and it is the whole ballgame; every bad AI decision I've watched started with someone skipping it. While that's underway, run the readiness checklist and get the AI policy drafted, because your team is already using AI and the policy can't wait for the strategy to be finished.

Days 31–60: one boring win. Pick a single rung-3 candidate from the inventory — documented, repetitive, low-stakes — and automate it end to end, with an owner, an error alert, and a before/after measurement. Resist the temptation to pick something impressive. The purpose of the first project isn't ROI; it's teaching the organization what "done" looks like: monitored, owned, measured. The ROI shows up anyway.

Days 61–90: the first AI-assisted workflow. Now — and only now — introduce a model into a workflow, rung-4 style, human firmly at the end of the pipe. Draft-and-review beats full autonomy for the first deployment every single time; you're building the organization's calibration for when the AI is trustworthy and when it isn't, and that calibration is the asset that makes rung 5 possible later.

After 90 days you'll have something most companies chasing AI never get: an honest inventory, one production automation with a heartbeat, one AI deployment with a track record, and a team that's learned the shape of the work. From there the SMB roadmap covers the scaling half of the journey.

This pillar sits on top of everything I've written on strategy. If you're deciding where to start, my honest routing:

And if you'd rather have a person than a reading list, this is the thinking I bring to fractional CTO engagements — same strategy, applied to your specific company.

I write these from the operator's seat — I run an MSP, a phone company, and an AI automation agency, and everything above comes from deployments I was accountable for. More on the blog or get in touch.

Frequently Asked Questions

What is an AI automation strategy?

A plan for where AI and automation will change how a company operates — which processes, in what order, with what guardrails, measured by what numbers. The strategy matters more than the AI: outcomes depend on documented processes, clean data, and clear ownership.

Why do so many AI pilots fail?

Rarely because the technology was insufficient. Pilots fail for foundation reasons: undocumented processes, missing or dirty data, no executive owner, no success metric, and security handled as an afterthought.

Should a small business build or buy AI automation?

Buy when the problem is generic and a vendor's whole business is maintaining it. Build when the workflow is specific to how you win — and only what you are willing to monitor forever. Most SMBs should buy more and build less than their enthusiasm suggests.

What should we automate first?

The process that is documented, repetitive, high-volume, and low-stakes when it errs — the boring one you understand completely. Early wins build political capital for harder projects.

Do small businesses really need an AI policy?

Yes. Teams are already using unapproved AI tools with company data. A one-page policy naming approved tools, forbidden data, and an approval path addresses most of the risk.

How do I measure whether AI automation is working?

Use numbers the business already tracks: hours returned at loaded labor cost, cycle time on customer-visible processes, error and rework rates, and hires deferred. An initiative that cannot name its number is a hobby.