Site down, hacked, or disappearing from search? Call (754) 302-4631
sosSTEVIE Start with the Diagnostic

Run  · $2,495/month

Who Actually Owns AI Decisions in My Business?

Right now, nobody. Which means everybody. Which means your most enthusiastic employee, and you've never asked what they're pasting in.

An empty chair at the head of a meeting table, representing the absence of ownership over AI decisions
Here's the direct answer

In most small businesses, nobody owns AI decisions — which means everyone does, and the most enthusiastic employee's judgment becomes de facto policy. A fractional AI officer is someone senior who owns AI for your business a few days a month: what tools are approved, what data can go where, what gets automated, what stays human, and what's actually working. sosSTEVIE does this for $2,495 a month, for businesses too small for a full-time AI hire but too exposed to keep improvising.

Key takeaways

  • You don't have no AI strategy. You have as many as you have employees.
  • The risk isn't your staff being reckless. It's that nobody's ever told them what's allowed.
  • Shadow AI is already load-bearing in most businesses — critical work running in personal accounts.
  • A policy document isn't governance. Nobody reads it and it doesn't decide anything.
  • The people using nothing are as much of a problem as the ones using everything.


The story

I asked a managing director how his company used AI. He said they didn’t, really. Maybe a bit.

So I asked his eleven staff.

All eleven used it. Daily. Six different tools, all paid for personally on expenses under vague descriptions, none approved, none reviewed. One had built a genuinely brilliant thing that produced their weekly client reports and had quietly become load-bearing — the business now depended on a workflow that lived in one person’s personal account and existed nowhere in any documentation. Another was pasting client contracts into a free tool to summarize them, which was, depending on who you asked, a data breach in progress.

And two people were using nothing at all, doing everything the slow way, quietly falling behind — because nobody had ever told them it was allowed.

The MD wasn’t negligent. He’d have said, correctly, that he had no AI strategy. What he actually had was eleven AI strategies, all in conflict, none written down, and no way of knowing which of them was about to cost him a client.

That’s not an AI problem. It’s a governance vacuum. And in a vacuum, the loudest, keenest person’s judgment becomes company policy by default.


The vacuum

Three unconnected groups of cards representing enthusiasts, the quiet majority and refusers in an AI governance vacuum

Every business I look at has the same three groups, and nobody’s ever mapped them.

The enthusiasts. Fast, inventive, genuinely valuable — and building things nobody’s reviewed, in personal accounts, with company data. They’re not the problem. They’re your best asset with no guardrails, and when they leave, whatever they built leaves with them, undocumented.

The quiet majority. Using it a bit, unsure what’s allowed, so they don’t mention it. Which means you can’t see it. This is where the data exposure lives, and it’s not recklessness — it’s the entirely rational behavior of people who were never told the rules and don’t want to be the one who asks.

The refusers. Doing it the slow way, falling behind, sometimes on principle, more often because nobody told them it was permitted or showed them how. This is the group everyone ignores and it’s usually the biggest cost — not a risk problem, a productivity gap you’re paying for every day.

Three groups, no coordination. And here’s the part that should worry you: the enthusiast’s judgment has become your company policy, without a decision ever being made, by anyone, at any point.

How common is this? Microsoft and LinkedIn’s Work Trend Index found that 78% of people using AI at work are bringing their own tools, outside any IT approval. Note what that figure actually says — it’s 78% of AI users, not of all employees, and it’s enterprise-weighted. But your business isn’t more governed than a Fortune 500 with a compliance department. It’s less.


Why a policy document won’t fix it

The instinct is to write a policy. It feels like taking control. It’s a document, it’s a deliverable, it goes in a folder.

Nobody reads it. And even if they did, a policy answers “what are the rules” while the actual questions arriving every week are:

Can I use this new tool? · Is this data okay to paste in? · Should we automate this or is it too risky? · The thing Dave built is now critical — who maintains it? · Should we be worried our competitor is doing something we’re not? · Is any of this working?

Those are decisions, and decisions need an owner, not a document. A policy is a snapshot of a judgment made once, in a domain where the ground moves every quarter. Written in January, it’s wrong by April, and it’s still in the folder being wrong with great authority.

Governance isn’t a document. It’s someone answering the question when it arrives.


The risk and financial math

Let me make the case in numbers, because $2,495 a month deserves arithmetic rather than adjectives.

What a full-time hire costs. A senior technical leader who could own this — a CTO, a head of AI, whatever you’d call it — costs somewhere around $200,000 a year in total compensation in the US market, before recruitment, equity, benefits and the risk of hiring wrong for a role you can’t yet define. That’s the comparison most people are implicitly making, and for a business of ten to fifty people it’s obviously absurd.

$2,495 a month is roughly $30,000 a year. About 15% of the alternative, for the decisions rather than the seat.

What the exposure costs. IBM’s Cost of a Data Breach 2025 found that breaches involving shadow AI — unauthorized tools used without security oversight — added around $670,000 to the average cost of a breach, ran longer than typical breaches, and were more likely to involve customer personal data. The same report found 97% of AI-related breaches happened in organizations lacking proper AI access controls, and that a majority of organizations either have no AI governance policy or are still drafting one.

That’s enterprise data and your numbers would be smaller. But the shape transfers exactly: the cost isn’t the tool, it’s the absence of anyone deciding what data goes where. And the small business version has a specific edge to it — you don’t have a security team, a legal department, or a cyber insurance policy that’ll absorb the hit.

What the invisible dependency costs. Harder to price, and often the one that actually happens. Somebody’s personal account is running your weekly client reporting. They leave. Nobody can reconstruct it, nobody documented it, and the client notices before you do. That’s not a breach — it’s just a business that quietly stopped being able to do something it could do last month.

What the gap at the bottom costs. Your refusers and quiet majority, working at a fraction of the speed available to them, every day, forever, because nobody told them what was allowed. This never appears in any risk register and it’s usually the largest number on this page.

Set those four against $30,000 a year. The math isn’t close, and it isn’t really about the breach — it’s about the fact that nobody is currently deciding any of this.


What a fractional AI officer actually does

Not a strategy deck. A standing job, a few days a month.

Owns the decisions. Tools approved and paid for properly. Data rules specific enough to follow — “don’t put confidential data in AI” is useless, “client contracts go in this tool and nowhere else” is a rule. And a named person to ask, which is most of the value, because right now nobody knows who to ask so they don’t ask.

Finds the shadow AI. Maps what’s actually running. Takes the good stuff — Dave’s report workflow — and makes it a real, documented, owned company asset instead of a personal liability. Shuts down the genuinely dangerous. Usually the biggest single win in the first month, and it’s mostly just asking people.

Closes the gap at the bottom. Gets the refusers and the quiet majority to a competent baseline. Unglamorous. Nearly always the largest measurable return, because the distance from zero to competent is much bigger than from good to excellent.

Decides what stays human. Genuinely part of the job. There are things you shouldn’t automate, and someone needs the standing to say so and be listened to. Harder from inside than out.

Watches the outside. Models change quarterly. Most of it is noise. Part of the job is reading the noise so you don’t have to, and telling you the two things a year that actually matter to you specifically.

Reports honestly. Including “this isn’t working, stop paying for it.” An internal hire who championed a tool can’t easily say that. I can, and I will, and that’s most of what you’re buying.


Why fractional

You almost certainly can’t justify a full-time AI hire. The salary’s absurd for the volume of decisions, and the role’s too new to define well enough to recruit for — you’d be interviewing for a job you can’t yet describe.

But the decisions arrive whether or not someone owns them. So they get made badly, by default, by whoever’s most confident that week.

Fractional fits the shape of the actual work: a few days a month, someone senior, no empire-building, no budget to defend. And a genuine advantage you might not expect — I can tell you to stop. I’m not protecting a department or justifying my own headcount. When the answer is “you don’t need this, cancel it,” I’ve got no reason not to say so.

That’s the whole pitch. Someone senior, in the room, with no incentive to sell you anything.

Six-month minimum, because anything shorter is a consulting project wearing a retainer’s clothes. The first month is mapping what’s actually running. The value compounds after that.


Somebody has to be in charge

A personal laptop at a kitchen table beside a work lanyard, representing critical work running in unapproved personal accounts

The MD didn’t have no AI strategy. He had eleven, in conflict, none written down, and one of them was pasting client contracts into a free tool.

Nobody was reckless. Nobody was in charge. Those turn out to be the same thing.

Let’s find out what’s actually running — $997 Diagnostic → Or call (754) 302-4631.


About Stevie

I’ve been in the room for the version of this that goes wrong. My own business was taken apart by something running quietly, confidently, with nobody watching it — and by the time I understood what I was looking at, the decision had been made for me.

I do this work because “nobody’s in charge” and “everything’s fine” look identical right up until they don’t.

sosSTEVIE — for when your digital presence is broken, invisible, or about to be. (754) 302-4631


Frequently asked questions

What is a fractional AI officer?

Someone senior who owns AI decisions for your business a few days a month rather than full-time. They decide which tools are approved, what data can go where, what gets automated and what stays human, and they report honestly on what's actually working. Mine is $2,495 a month with a six-month minimum — for businesses too small to justify a full-time AI hire but too exposed to keep improvising.

Isn't it cheaper to just hire someone?

Not at this scale. A senior technical leader who could own this costs around $200,000 a year in total compensation before recruitment and benefits, for a role most small businesses can't yet define well enough to hire against. At roughly $30,000 a year, the fractional version is about 15% of that, and you're buying the decisions rather than the seat.

Is my team already using AI without telling me?

Almost certainly. Microsoft and LinkedIn's Work Trend Index found 78% of people using AI at work bring their own tools without IT approval, and when I survey staff directly the usage is consistently far higher than the owner believes. It's rarely recklessness — people weren't told what's allowed and don't want to be the one who asks. The more useful question is what they're pasting in.

What's the biggest AI risk to a small business?

Not the dramatic one. It's that critical work is quietly running in someone's personal account, undocumented, and leaves when they do. Data exposure matters too — IBM's 2025 research found shadow AI added around $670,000 to average breach costs — but shadow dependency is the one that actually bites. Second biggest is the people using nothing, costing you every day, invisibly.

How is this different from hiring a consultant?

A consultant delivers a project and leaves. This is a standing role — the decisions keep arriving, so someone has to keep answering them. Closer to a fractional CTO than a strategy engagement. The other difference is incentive: I'm not protecting a headcount or a department, so "cancel that, you don't need it" is an answer I can give freely, and it's the answer I give most.

Also in Run

Stop guessing.

Five days. One diagnosis. A ranked list of what's broken, what it's costing you, and what to do in what order — yours to keep whether you hire me or not.

The Backstory

Three years ago my own website was taken over. It looked completely normal in my browser while tens of thousands of spam pages ran underneath it. I found out when the calls stopped, and I had to take the whole thing down.

I diagnose before I quote, because I know exactly what it costs to be certain about the wrong thing. The whole story is here.