Playbooks

Structured playbooks for AI adoption

Step-by-step playbooks for SMB operators putting AI into real workflows — the 30/60/90-day adoption sprint, the governance and risk layer that keeps it from becoming a liability, the people-side work that makes it stick, and the EU AI Act and ISO 42001 obligations in plain terms.

The AI Adoption Sprint

A practical 30/60/90-day sequence for SMB and mid-market leaders — three phases, three deliverables, three honest go/no-go moments.

The whole series

Read end to end, the sprint is one argument: adoption fails without a sequence, so fix the sequence before touching the tool. Thirty days to name one workflow, one owner, and one number; thirty to run a single protected pilot and count the hours it saves; thirty to decide scale, fix, or stop and put just enough governance around what survives. The checklists matter less than the order — each phase only works if the one before it produced something real.

AI Governance Playbook Series

Seven short playbooks that put a workable governance layer around AI — triage, vendors, data, rollout, roles, documentation, and generative content.

Start here — Playbook 1

The whole series

The seven playbooks are one system, not a menu. Playbook 1 decides how much governance a use case needs; 2 through 4 control what you buy, what data it touches, and how it goes live; 5 through 7 assign the owners, keep the record, and govern everyday generative use. The thread running through all of them is documentation — every playbook produces a decision, and a decision only protects you once it is written down in the register.

AI Risk Management

Identify, assess, and control the risks that derail AI projects — seven risk categories, a scoring framework, per-category mitigations, and the governance cadence that keeps it running.

Start here — Part 1

The whole series

The five parts move from naming risk to controlling it. Start with the seven categories, score each risk on likelihood and impact, then apply the mitigation that fits the category rather than a generic one. Governance and cadence keep it running; the templates keep it honest. The aim is not a complete risk register — it is noticing the early warning sign while it is still cheap to fix.

Use Case Analysis

Choose the right use case before you build anything: gather six to ten real candidates, score them on value and feasibility, and rule out the four patterns that burn pilot budgets.

Start here — Part 1

The whole series

Three steps, in order. Gather more than one candidate so the winner actually beats something. Score them on value and feasibility rather than enthusiasm. Then rule out the four patterns that should never reach the matrix. What comes out is a use case worth building a business case for — not the idea that happened to walk in the door.

Measure Value, Risk, Costs & KPIs

Five parts on the question that decides whether any of it mattered: did the AI project pay for itself? Screen the idea, translate the metrics, do the numbers, get it approved, then measure what actually happened.

Start here — Part 1

The whole series

Five parts take an AI idea from hunch to measured result: screen it, translate the technical metric into a business number, build the ROI across three scenarios, put the conservative case into a one-page business case, then track it against a fixed dashboard. The last part is the one almost everyone skips — and it is the only one that proves the projection was real.

EU AI Regulation for SMBs

What the EU AI Act and the digital rules around it actually ask of a small or mid-sized company — by role and risk tier, not by headline.

Start here — Part 1

The whole series

The AI Act is the rule everyone has heard of, but it rarely stands alone. Part 1 sorts out what the Act actually asks of a company by size and role now that the Digital Omnibus has moved the deadlines and introduced the Small Mid-Cap path. Part 2 maps the rules that arrive beside it — GDPR, NIS2, the CRA, the Data Act, DORA — and, just as usefully, which ones a typical SMB can leave to the enterprises. The point in both is the same: compliance starts with one inventory and one vendor-onboarding checklist, not a project per regulation.

Change Management & Adoption Enablement Series

Six short playbooks that turn buy-in from a hope into a sequence — awareness, desire, training, coaching, and the reinforcement that keeps adoption from sliding back.

Start here — Playbook 1

The whole series

Awareness and desire earn the right to train; training and coaching build the skill; reinforcement is what makes the first ninety days outlast the rollout’s own momentum. Without it, the sprint’s scale-or-stop decision has no adoption data to decide with.

EU AI Act & ISO 42001 Compliance Series

Five short playbooks that connect the existing governance work to the two names an SMB owner will actually be asked about: the EU AI Act and ISO 42001.

Start here — Playbook 1

The whole series

Classify what you have built, know which obligations are already enforceable versus still ahead, map what you have already written to ISO 42001’s clauses, close the transparency gap that is live today, and keep one file that proves all of it — an extension of the governance work, not a parallel project.