The Best AI Use Cases Start Where The Business Process Breaks

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
For organizations without a pilot or that haven't sunk a lot of money into their project, a good starting point is finding where the process breaks and how AI can help.

John Bruggeman, CISSP, consulting (CISO) for CBTS and OnX, both are MSPs and MSSPs.

getty​Two big problems are showing up in AI projects right now. First, companies are rushing to launch AI pilots before they have clearly defined the business problem they want or need to solve. Second, they can get pretty far into a pilot before realizing they don’t have the security framework in place to support it. ​

For organizations without a pilot yet, or ones that haven’t sunk a lot of money into their project, a good starting point is finding where the process breaks and how AI can help. Folks call this the breakpoint, and every process has one. It’s probably familiar. It is the spot where a decision stalls, data vanishes or the process stops being valuable. ​

Find that breakpoint, put a number on the cost, and identify the risk. When you do that, you get a much clearer idea of what job AI is being asked to do. ​

A programmer knows the systems inside and out and is the one person who patches the system. The cybersecurity risk is a single point of failure compounded by a lack of documentation, sometimes referred to as a “key person” risk. Operationally, the risk is: What happens when that person takes a vacation or leaves? With nothing written down, there is nothing reliable for an AI tool to work from to help automate.

A security operations center (SOC) analyst escalates alerts based on years of pattern recognition, but none of that was written down. The cybersecurity risk is inconsistent triage and incomplete data. Feed an AI model incomplete data and it will produce incomplete results really fast. The operational risk is throughput. It is hard to scale and take advantage of AI to triage alerts when the process isn’t documented.

A managed service provider (MSP) is granted access and nobody owns the task of revoking or recertifying it once the project or contract ends. The cybersecurity risk is access nobody’s watching. Operationally, the risk is accountability. When access reviews come up in an audit, there is no clear answer for who approved it, why or whether it’s needed. Without a good process, there isn’t anything for AI to do. ​

One of the best ways to start is to talk to people doing the work. I call it a reference interview. ​

Imagine you’re at a mechanic trying to figure out what’s wrong with your car. I know it’s vague, but most of us have been there. So, you stop at the service desk and say your car is making noise.

The mechanic, who’s been trained to narrow down the problem, asks a few follow-up questions. Does it happen when you brake or when you accelerate? Does it happen every time or only at low speeds? Those two questions narrow the scope of possible problems tremendously. The same thing needs to happen with a business process. ​

1. Where do you spend most of your time?

2. What do you dread doing every day?

3. What would you like to give to an intern if you had one?

4. What would you like to simplify in your day?

5. What breaks when someone is on vacation? ​​

You can find the pain point in an internal workshop. The goal is to make sure the projects that come out of the brainstorming session have good ROI. Being able to quantify the cost savings is key to getting the funding to invest in employees and AI systems that are going to drive growth and revenue. ​

Now that the breakpoint has been identified, the next step is to refine the task or tasks involved. Teams need to identify what data is required for the task, whether the data is reliable, who owns that data, etc. They also need to make sure the infrastructure is ready for the AI project. The platform needs to work in the organization’s environment and not break when the project moves from the test environment to production. ​

Once the data is ready and the platform is solid and can support the load, the next step is to map out the deployment strategy, keeping security in mind. AI models can be trained on custom data, and that newly trained model can drift from the expected process or, in more malicious cases, be poisoned by a competitor or malicious actor. Teams need to build safeguards for the AI tool. The specific safeguards will depend on the scope and risk of the project.​

Organizations also have governance and potential regulations to address before an AI project goes live with client data. The governance element can move forward while pilot projects are being built, but it has to happen. With U.S. state regulators enacting laws, as well as regulators in the EU, China, Asia and the Middle East addressing what can be done with AI, organizations need to include that as part of the project. Regulation and governance will be an ongoing project, so budget appropriately for that. ​​

​Find your breakpoint, identify the tasks that can be automated, and determine what data those tasks require and who owns it. Make sure the data is reliable enough to use and that your infrastructure can support the AI workload. Once those pieces are in place, involve your security team so the appropriate controls are established before deployment. You also need to account for privacy and data regulations, since a compliance issue can cost more than the project saves. ​

I hope that these steps help you and your team successfully launch your first AI project.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/05/the-best-ai-use-cases-start-where-the-business-process-breaks/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business