Before you sign off on AI: the questions every leader should ask

This informal CPD article, ‘Before you sign off on AI: the questions every leader should ask’, was provided by Heather Baker, founder of The AI Edit, a B2B AI training, coaching, and consulting business.

A significant proportion of AI projects fail to deliver their intended benefits. Annual industry research has consistently found that the majority of organisations have not yet achieved measurable financial returns from AI initiatives at scale (1).

The reasons cluster around the same issue. AI projects are routinely approved as technical decisions when they are, in fact, leadership decisions about risk, accountability, governance, and culture.

A technical question is "does this work?" A leadership question is "should this be done, who is accountable when it goes wrong, and what happens to clients, staff, and reputation if it does?"

The reasonable response is not to slow every AI decision down. It is to ask sharper questions before sign-off. Once an initiative is funded and announced, the political cost of pulling it climbs steeply.

The questions below offer a structured approach to that decision-making. They can be used as a checklist before approving, funding, or endorsing any AI initiative, whether vendor-led, internal, or partner-driven.

1. Clarity of purpose

Before anything else: what specific problem is the initiative trying to solve?

If the answer is "we want to be more AI-enabled" or "we should be using AI by now," that is not a problem statement. That is a press release.

A useful clarity test is to remove the word AI from the proposal entirely. If the initiative still makes sense as a sensible thing to do for the business, a real problem is being solved. If it collapses, what remains is AI for AI's sake, dressed as strategy.

What decision, task, or outcome will change if the project succeeds? How is the work currently being done? What does success look like in plain business terms?

Vague benefits and impressive demonstrations are red flags. Specific, measurable outcomes are not.

2. Leadership, ownership, and accountability

The next question is about people, not tools.

Who is accountable for the outcomes of the project? When something goes wrong, who answers for it? Possible failures include a fabricated client communication, a flawed recommendation, a data breach, or a regulatory complaint. A senior leader's name needs to be on the line, not the vendor's. Frameworks such as the United States National Institute of Standards and Technology AI Risk Management Framework explicitly identify clear lines of human responsibility as a foundational requirement for trustworthy AI (2).

If responsibility is being pushed to IT, to the vendor, or to "the model," a governance problem exists before an AI one. A named leader needs to own the initiative end to end, with sign-off authority and the willingness to stop it.

AI should be treated as a strategic decision, not a technical procurement.

3. Decision-making and human oversight

Is the AI assisting humans, or making decisions on their behalf?

In most professional contexts, AI that assists a human is generally defensible. AI that makes decisions unsupervised is rarely defensible, and almost never advisable in regulated work. The European Union's AI Act establishes mandatory human oversight obligations for AI systems classified as high-risk, including those used in employment, credit, law enforcement, and access to essential services (3).

For each use case, the lines need to be clear. Which decisions are automated? Which require human review? Which require a second human? What happens if the AI is wrong, and who can intervene, override, or stop the system?

Higher-risk decisions warrant higher-touch oversight. A spelling suggestion does not need a partner-level review. A client recommendation might. A compliance call almost certainly does. The level of oversight should track the level of risk.

4. Data and privacy

What data does the system use, and where does it come from? Is any personal, sensitive, or proprietary information involved? Is consent in place where it is required? Where is the data stored, and who has access?

A significant proportion of AI failures in professional settings begin here. Either the underlying data was richer than people realised, or the consent did not cover the planned use, or the storage location triggered a regulatory issue nobody had checked. Guidance from data protection authorities, including the United Kingdom Information Commissioner's Office, sets out specific obligations for the use of personal data in AI systems (4).

If the team is unsure what data the system is actually using, the answer is not yet. And if the vendor's terms allow client data to be used for model training, that is a difficult question for any regulated profession, and a meaningful one for everyone else.

cpd-The-AI-Edit-Generative-AI-produces-fluent-output
Generative AI produces fluent output

5. Accuracy, bias, and reliability

Where does accuracy really matter for this use case, and how will errors be detected when they happen?

Generative AI produces fluent output, which makes its mistakes hard to spot. Something that sounds right is not the same as something that is right. Without a system for catching errors, teams become more confident in AI output over time, not more sceptical. That is the opposite of what sound professional judgment requires.

The questions to ask: what assumptions are baked into the system, how will bias be monitored over time rather than only at launch, and has the system been tested in real operating conditions rather than only in sales demonstrations. Honest answers of "we don't know yet" indicate work to be done before sign-off, not after.

6. Transparency and explainability

Can the use of AI in the project be explained in plain language? Could it be explained to a regulator, a client, or a member of staff?

Are there logs, audit trails, or documentation that would allow the team to reconstruct what happened, after the fact, if something went wrong? International standards on AI management systems set out specific requirements for transparency and traceability in AI deployments (5).

External disclosure also matters. AI used quietly, without disclosure to those affected, is a trust risk in waiting. The first time clients learn of it is rarely the first time they should have known.

A system too complex to explain is itself a reason for caution.

7. The vendor and AI-washing check

A significant amount of what is currently marketed as AI is not AI. Much of it is rules-based automation, a wrapper around a publicly available model, or an existing feature renamed for the moment. Financial regulators in several jurisdictions have begun enforcement action against "AI washing," where products or services are misrepresented as containing artificial intelligence (6).

What is the AI actually doing in this product? Which components are AI, which are rules-based, and which are conventional automation? What would the product look like without AI involved at all?

What evidence supports the vendor's claims, and will they provide customer references? What happens to data, workflows, and continuity if the vendor fails or changes direction?

Heavy marketing language with light substance is a red flag. So is a vendor unwilling to provide references to existing customers.

8. Organisational readiness

A substantial share of AI projects fail not because of the technology, but because of the people around it.

Are employees already using similar tools informally, outside of policy? Do staff know what is permitted and what is not? Is training in place, or are people being expected to figure it out as they go?

Will this initiative create fear, resistance, or confusion in the team? If so, what is the plan to address it?

Silence internally combined with excitement externally is a pattern worth watching for. It usually indicates that the leadership team is convinced, the front line is anxious, and nobody has built the bridge between them.

9. Ethics and red lines

Where will AI not be permitted, in this project or elsewhere? What decisions must always involve a human, regardless of model capability? What would cause the initiative to be paused or stopped entirely? How will mistakes be handled when they occur, both internally and publicly?

These questions require answers in advance, in writing. Not because AI is uniquely dangerous, but because once a project is live, the pressure to continue is significant. Red lines drawn after a problem has emerged are rarely red lines. They are negotiations.

Final review questions

Three questions to ask in the room, before any sign-off.

  • Is this being approved because it is exciting, or because it is sound?
  • Are the risks as clear as the upside?
  • Are decision-makers comfortable owning the consequences if it goes wrong?

Uncertainty on any of those means the project is not ready for approval. It is ready for more work.

What this means for CPD

These nine questions are not really about AI. They are about leadership in a context where the technology is moving faster than most governance frameworks. That is now part of the role in every profession that involves judgment.

For CPD purposes, AI decision-making belongs alongside other core areas of leadership development. Ethics, governance, risk management, and accountability are all familiar professional territory. AI brings them together into a single, sharper test. Treating it as a continuous development area produces better decisions than treating it as a one-off briefing.

We hope this article was helpful. For more information from The AI Edit, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.

References: 

(1) MIT Sloan Management Review and Boston Consulting Group. Annual AI Global Executive Study and Research Report series. MIT Sloan Management Review, 2019 to present. https://sloanreview.mit.edu/big-ideas/artificial-intelligence-business-strategy/

(2) National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, US Department of Commerce, 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf

(3) European Parliament and Council of the European Union. Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj

(4) UK Information Commissioner's Office. Guidance on AI and Data Protection. ICO, 2023. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

(5) International Organization for Standardization and International Electrotechnical Commission. ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system. ISO, 2023. https://www.iso.org/standard/81230.html

(6) US Securities and Exchange Commission. SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence. Press release, 18 March 2024. https://www.sec.gov/news/press-release/2024-36