AI is already influencing management decisions in many businesses before the board or leadership team has agreed which decisions it is allowed to touch.
That is the real governance gap for many SMEs and mid-market companies. It is not whether people are using AI. They are. It is not whether AI can save time. It can. The more important question is whether AI is being allowed to shape decisions without a clear owner, a clear evidence standard or a clear point at which human judgement must intervene.
For founders, CEOs and leadership teams, this is becoming a practical management issue. AI is appearing inside CRM platforms, finance tools, recruitment systems, customer service software, marketing platforms and productivity applications. It may recommend which leads to prioritise, which candidates to shortlist, which customers to retain, which invoices to chase, which prices to adjust or which operational risks deserve attention.
None of those decisions are purely technical. They affect margin, reputation, customer trust, cash, people and strategic direction.
The businesses that get value from AI will not be the ones that simply use it most. They will be the ones that decide, deliberately, where AI should inform a choice, where it should recommend an action, where it can operate within boundaries, and where a human leader must remain clearly accountable.
The next AI problem is not adoption. It is accountability.
The first phase of AI adoption was driven by access. Staff were given tools. Teams tested use cases. Functions found ways to speed up emails, analysis, presentations, customer responses, coding, research and reporting.
That phase is useful, but it creates a misleading sense of progress. Faster work is not the same as better decisions. More analysis is not the same as clearer judgement. A polished recommendation is not the same as a decision the business can defend.
In many leadership teams, the AI conversation still starts with:
- Which tools should we buy?
- Which use cases should we test?
- How much productivity can we gain?
- How do we stop people using unsafe tools?
Those are valid questions. They are not enough.
The better leadership question is:
Which business decisions are now being influenced by AI, and who remains accountable for the quality and consequences of those decisions?
That question changes the conversation. It moves AI from a technology initiative to a management discipline.
What the AI decision rights gap looks like
The decision rights gap appears when AI has influence but no clearly defined role.
It often shows up quietly. A sales manager uses an AI-assisted CRM tool to prioritise opportunities, but nobody has agreed whether the model is optimising for conversion, revenue quality, margin or strategic customer fit. A finance team uses AI to identify cash-flow risks, but there is no agreed threshold for when the CFO must review the output. A recruitment workflow uses AI to screen CVs, but hiring managers cannot clearly explain which criteria were used or how bias is being checked.
The problem is not that AI is present. The problem is that the business has not made the decision architecture explicit.
In practical terms, the gap usually has five symptoms.
1. AI recommendations are treated as neutral
AI outputs can look objective because they are structured, confident and data-rich. That does not mean they are neutral. Every recommendation is shaped by data, prompts, assumptions, model design, tool configuration and user behaviour.
If a leadership team does not define what good evidence looks like, AI can amplify weak assumptions at speed.
2. Human review is present but vague
Many organisations say a human is "in the loop". That phrase is too loose to be useful. Does the human check for errors? Approve the decision? Challenge the recommendation? Own the outcome? Override the system? Report exceptions?
Human involvement only creates control when the role is specific.
3. The accountable owner is unclear
If an AI-enabled pricing recommendation damages margin, is the owner the commercial director, the data team, the vendor, the tool administrator or the person who accepted the recommendation?
The answer should be clear before the system goes live.
4. Reversible and irreversible decisions are treated alike
Some AI-assisted decisions can be tested quickly because the downside is limited. Others deserve slower scrutiny because the cost of error is high. A marketing subject line, a customer credit decision and a senior hiring recommendation should not carry the same review process.
5. The business measures AI usage, not decision quality
Adoption dashboards can show how many people are using AI, how many outputs are generated or how much time is saved. They rarely show whether decisions are better, faster, fairer, more profitable or easier to defend.
That is where leadership discipline matters.
The leadership question: what role should AI play in each decision?
A practical AI governance model should not treat every decision in the same way. Some decisions can safely use AI heavily. Some should only use AI as an input. Some should remain firmly human-led.
Allington Advisors recommends classifying AI's role using five levels.
Level 1: AI informs
AI gathers, summarises, compares or analyses information. A human makes the decision.
Typical examples include:
- summarising customer feedback;
- comparing supplier proposals;
- gathering competitor information;
- preparing a briefing note;
- highlighting anomalies in operational data.
This is usually the lowest-risk starting point, provided the evidence is checked and the source limitations are understood.
Level 2: AI recommends
AI suggests an option, ranking, priority or next best action. A human accepts, rejects or modifies the recommendation.
Typical examples include:
- prioritising sales leads;
- identifying customers at risk of churn;
- recommending stock replenishment actions;
- flagging invoices for credit control focus;
- shortlisting operational improvement opportunities.
At this level, the leadership team needs to define the outcome being optimised. If the system is recommending sales leads, is it prioritising volume, margin, speed, strategic fit or likelihood to close? If that is not explicit, the AI may optimise the wrong thing.
Level 3: AI drafts
AI prepares a document, response, plan, analysis or action for human review.
Typical examples include:
- drafting customer communications;
- preparing first-pass board reports;
- creating job descriptions;
- producing scenario summaries;
- drafting policy or process documents.
Here, the human reviewer must be more than a proof-reader. They must own accuracy, tone, commercial judgement, legal sensitivity and fit with the company's position.
Level 4: AI executes within limits
AI takes an action automatically, but only within defined thresholds and escalation rules.
Typical examples include:
- routing customer enquiries;
- sending standard follow-ups;
- adjusting low-risk stock replenishment quantities;
- triggering routine workflow tasks;
- flagging standard compliance checks.
This level requires tighter design. Leaders should define financial limits, customer impact limits, risk categories, exception rules, audit logs and named owners.
Level 5: AI escalates
AI monitors information and raises issues that need human attention.
Typical examples include:
- identifying a potential cash-flow issue;
- surfacing a pattern of customer complaints;
- flagging supplier performance deterioration;
- detecting unusual margin movement;
- warning of project slippage.
Escalation can be valuable because it helps leaders see weak signals earlier. But escalation only works when somebody has the authority and time to act on the signal.
The decisions AI should not own
For most SMEs and mid-market firms, there are decisions AI should not own outright.
These include:
- strategic choices about market entry, acquisition, divestment or business model change;
- senior leadership appointments;
- material pricing decisions that could reset customer expectations or margin structure;
- decisions with significant legal, ethical, regulatory or reputational implications;
- employee dismissal, redundancy or disciplinary decisions;
- customer decisions where fairness, vulnerability or long-term relationship value is material;
- major supplier, funding or capital allocation decisions.
AI may support these decisions by providing analysis, options, challenge or scenarios. It should not become the accountable decision-maker.
The reason is simple. Senior leaders are paid to exercise judgement under uncertainty. AI can strengthen that judgement when it is used well. It can also weaken it when leaders outsource the hard part of deciding.
A practical framework for AI decision rights
Leadership teams do not need a heavy governance structure to manage this well. They need a clear decision inventory and a small number of rules that can be applied consistently.
The following framework is designed for founders, CEOs and leadership teams that want control without bureaucracy.
Step 1: Build a decision inventory
Start by listing the decisions AI is already influencing or likely to influence in the next 12 months.
Focus on decisions in five areas:
- Commercial: pricing, lead prioritisation, proposals, customer segmentation, retention and marketing spend.
- Finance: forecasting, cash collection, credit risk, budget variance and management reporting.
- Operations: scheduling, stock, procurement, supplier performance, quality, service levels and workflow routing.
- People: recruitment, performance insights, workforce planning, learning and employee communications.
- Strategy: market analysis, scenario planning, competitor intelligence, resource allocation and investment cases.
For each decision, capture:
- what the decision is;
- how often it is made;
- who currently owns it;
- which data informs it;
- whether AI is already involved;
- what could go wrong;
- whether the decision is reversible;
- how material the impact could be;
- who should approve or challenge it.
Step 2: Classify the risk and reversibility
Not all decisions need the same level of control.
A simple two-part test is useful.
First, ask how material the decision is. Would a poor decision materially affect cash, profit, customers, employees, compliance, reputation or strategic direction?
Second, ask how reversible it is. If the decision proves wrong, can the business correct it quickly and at acceptable cost?
This creates four categories.
This is where many businesses make mistakes. They apply the same AI enthusiasm to every type of decision. A leadership team needs the discipline to move quickly where risk is low and slow down where the consequences justify it.
Step 3: Assign the AI role
For each decision, define whether AI will:
- inform;
- recommend;
- draft;
- execute within limits;
- escalate;
- or remain outside the decision.
This should be written in plain English.
For example:
- "AI may recommend which overdue accounts to prioritise, but the finance manager owns collection strategy and any customer relationship escalation."
- "AI may draft candidate summaries, but the hiring manager owns shortlisting and must record the evidence for each decision."
- "AI may identify margin anomalies, but the commercial director owns pricing decisions above agreed thresholds."
- "AI may draft a customer response, but no AI-generated commitment may be sent without human approval where pricing, liability, refund or service failure is involved."
The aim is not to slow every decision. It is to make ownership visible.
Step 4: Define the human gate
"Human review" is not enough. The leadership team should specify what the human gate is for.
There are five common gate types.
A good AI operating model makes these gates explicit. A weak one assumes that somebody will notice if something looks wrong.
Step 5: Set an evidence standard
AI-supported decisions should have a defined evidence standard. This does not need to be complex, but it should be clear.
For material decisions, leaders should ask:
- What data was used?
- Is the data current, complete and relevant?
- What assumptions shaped the recommendation?
- What alternatives were considered?
- What would change our mind?
- What are we too ready to believe?
- What is the downside if the recommendation is wrong?
- Who has challenged the answer?
This is especially important because AI can make weak evidence look polished. The discipline is to separate presentation quality from decision quality.
Step 6: Create a decision log
For high-risk or high-value decisions, keep a short decision log.
It should capture:
- the decision made;
- the AI role;
- the human owner;
- the evidence used;
- the challenge or review completed;
- the agreed action;
- the result after review.
This is not bureaucracy for its own sake. It creates a learning loop. Over time, the business can see where AI recommendations are improving decisions, where they are adding noise and where human judgement is still correcting the system.
Where AI decision rights matter most in mid-market businesses
The AI decision rights gap is most dangerous where decisions are frequent, commercially important and already supported by software.
Pricing and discounting
AI can help sales teams identify price sensitivity, competitor movement, customer behaviour and margin patterns. But pricing decisions carry strategic weight. A discounting recommendation can affect customer expectations, sales behaviour and profit quality.
Leadership teams should define:
- who owns pricing rules;
- where AI may recommend price or discount actions;
- what margin thresholds require approval;
- how exceptions are recorded;
- how pricing impact is reviewed.
This is especially important for growth companies where revenue momentum can hide margin leakage.
Recruitment and talent decisions
AI can improve speed in recruitment by summarising CVs, drafting interview questions and matching skills to requirements. It can also introduce bias, over-rank familiar profiles or hide weak role definition behind efficient screening.
For recruitment, leaders should define:
- which criteria AI may use;
- which criteria are prohibited;
- who owns shortlisting;
- how candidates can be compared fairly;
- how hiring decisions are documented;
- when senior review is required.
This connects naturally to executive search and leadership advisory work. Senior hires should never be reduced to pattern matching.
Customer service and complaints
AI can route enquiries, draft responses and identify recurring issues. The risk is that it optimises for speed while weakening customer trust.
Leadership teams should define:
- which customer responses can be automated;
- which categories require human approval;
- where vulnerability, refunds, service failure or legal sensitivity trigger escalation;
- how customer sentiment and complaint outcomes are reviewed;
- who owns the customer promise.
The key point is that customer experience is not just response time. It is also judgement, tone and reliability.
Finance, forecasting and cash control
AI can help identify variance, forecast scenarios and prioritise collections. But cash and forecast decisions shape confidence, investment timing and stakeholder trust.
Finance leaders should define:
- which AI outputs can be used in forecasts;
- what evidence is needed before revising assumptions;
- who owns forecast judgement;
- which cash risks require immediate escalation;
- how AI-generated scenarios are challenged.
In a distressed or margin-pressured business, this discipline matters even more. Speed is valuable, but false confidence can be costly.
Operations and supplier performance
AI can identify supply issues, recommend scheduling changes and flag performance patterns. In operations, the challenge is often the hand-off between recommendation and action.
Leadership teams should define:
- who owns each operational decision;
- which actions AI can trigger automatically;
- what service, quality or cost thresholds require review;
- how supplier exceptions are escalated;
- how operational learning is captured.
Done well, AI helps the business see operational friction earlier. Done badly, it simply creates another stream of alerts that nobody owns.
The CEO's checklist for AI decision rights
Founders and CEOs do not need to personally approve every AI use case. They do need to ensure the business has a simple, consistent discipline for decisions that matter.
Use this checklist with your leadership team.
- Do we know which business decisions AI is already influencing?
- Have we classified those decisions by materiality and reversibility?
- Is there a named human owner for each material AI-supported decision?
- Have we defined whether AI informs, recommends, drafts, executes or escalates?
- Are the human review gates specific enough to be useful?
- Do managers know when they are allowed to override AI?
- Do we have evidence standards for material decisions?
- Are high-risk decisions logged and reviewed?
- Do we measure decision quality, not just AI usage?
- Are board and leadership discussions focused on value, risk and accountability rather than tool novelty?
If the answer to more than three of these questions is "no", the organisation is probably moving faster than its governance.
A 30-day action plan
The aim is not to write a lengthy AI policy and hope people read it. The aim is to clarify the decisions that matter and put light but effective controls around them.
Week 1: Map the decisions
Ask each function to list the decisions AI is already influencing or expected to influence. Keep the first version practical. Focus on the top 20 to 30 decisions across the business, not every possible use case.
Output:
- decision inventory;
- current AI involvement;
- accountable owner;
- known risks;
- priority areas for review.
Week 2: Classify decision risk
Score each decision by materiality and reversibility. Identify which decisions can move quickly and which need stronger human gates.
Output:
- decision risk map;
- list of high-materiality decisions;
- list of decisions suitable for controlled automation;
- list of decisions that should remain human-led.
Week 3: Define AI roles and human gates
For each priority decision, agree the AI role and the human gate. Keep the language plain enough for managers to use.
Output:
- AI decision role for each priority decision;
- named owner;
- review gate;
- escalation rule;
- decision-log requirement.
Week 4: Set the management cadence
Add AI decision quality to the relevant management rhythm. This may be part of the monthly finance review, commercial meeting, operations review, people review or board pack.
Output:
- decision quality measures;
- AI exception review;
- lessons learned;
- changes to thresholds or gates;
- next 30-day improvement actions.
What good looks like
A well-managed AI decision rights model should feel practical, not performative.
You should see:
- clear ownership for material decisions;
- fewer vague references to "the system recommended";
- faster decisions where risk is low;
- stronger challenge where consequences are high;
- better evidence in leadership discussions;
- clearer escalation from frontline teams to managers;
- improved visibility of where AI is creating value;
- a more confident board conversation about AI risk and performance.
You should also see managers becoming better decision-makers. That matters. AI should not weaken judgement by making leaders passive recipients of recommendations. It should sharpen judgement by improving evidence, widening options, surfacing risks and reducing low-value manual work.
The mistake to avoid
The most common mistake is to put AI governance in a policy document while leaving decision-making unchanged.
Policies matter, but they rarely change behaviour on their own. If AI is influencing pricing, hiring, customer service, cash, procurement or operations, governance must be embedded where those decisions actually happen.
That means:
- decision owners know their responsibilities;
- review points are built into workflows;
- escalation thresholds are visible;
- performance is reviewed through management meetings;
- the board sees value, risk and accountability in the same conversation.
AI governance should not sit beside the operating model. It should be part of it.
How Allington Advisors can help
Allington Advisors works with founders, CEOs and leadership teams who need practical AI implementation without losing control of the business fundamentals.
An AI decision rights review can help a leadership team:
- identify where AI is already influencing decisions;
- classify decisions by risk, reversibility and commercial impact;
- define appropriate human gates;
- clarify accountability across functions;
- design a simple AI governance rhythm;
- connect AI use to operating performance and measurable value.
This sits at the intersection of AI implementation, management consulting, operations improvement and transformation. The goal is not to slow the business down. It is to help leaders move faster where they can, apply judgement where they must and keep accountability where it belongs.
Final thought
AI will increasingly sit inside the everyday systems that run the business. That makes the leadership challenge more immediate, not less.
The question is no longer simply whether your business is using AI. It is whether your leadership team has decided where AI may influence decisions, where people must remain accountable and how the organisation will learn from the results.
For many SMEs and mid-market firms, that is the next practical step in making AI useful, controlled and commercially valuable.
If your leadership team is adopting AI across the business, Allington Advisors can help you review your decision rights, operating model and governance before informal habits become embedded.
