Field notes. John Arndt, Soxoa. Published .
The title needs a plain statement before anything else. A fractional Chief AI Officer is an outside advisor with delegated authority to make and record certain decisions. I am not an officer of your company and not an employee of it, and legal, security, and compliance sign-off stays with your own responsible people. What the arrangement supplies is a named person who does this work continually, has no vendor relationship to protect, and can be brought in or let go without restructuring a department.
With that said, here is what the first three months consist of, because the useful question is not what the role is called but what changes by the end of the quarter.
Month one: find out what is running and who decided it
Nearly every organization I start with is already using AI. Not in the way the strategy deck describes, but in the way people actually work: a licence somebody bought, a browser extension in one department, a spreadsheet with a formula calling a model in it, a vendor feature switched on by default in a tool you already had. Month one is finding all of that and writing it down.
Three questions per item. What is it doing, who decided to use it, and which kinds of information pass through it. The third question is the one that produces the interesting silences, because approved-tool decisions are usually made informally and nobody has matched tools to information types on purpose.
Alongside the inventory comes a short list of decisions that are being deferred because nobody owns them: which tools are approved for what, whether client information may go through a particular vendor, who signs off output that reaches a customer, what to do about the department that bought its own thing. I do not resolve all of those in a month. I make them visible, name who has the authority to decide each one, and get the first two or three actually decided.
The output at the end of month one is an inventory, a decision list with owners, and a ranked portfolio: what is worth doing, in what order, and what I am recommending against. The last part matters. A portfolio with nothing declined on it has not been prioritised.
Month two: one build, through a gate, with a review path
Month two is a build, and deliberately one build. The point is not the volume of work delivered; it is to run a single piece of work through the whole path so the organization can see what the path is.
That means a workflow chosen against the criteria I have written about in how to pick the first workflow, evaluated on real approved examples before anything is installed, with a named reviewer for whatever needs judgment, and a documented handoff. Gate means the thing does not go live because it demos well. It goes live because it cleared a bar that was agreed before anyone looked at the results, and if it does not clear the bar, the answer is to stop and say so in writing.
The reviewer is chosen before the build, not after. Review bolted on at the end becomes a queue nobody has time for, and a queue nobody has time for becomes a rubber stamp inside a month. Designing the review path first changes what gets built, because it determines what evidence is logged and what the reviewer needs on screen to decide quickly.
By the end of month two there is one workflow operating, one named internal owner, one written review path, and a worked precedent for how the next one will be handled. Where the work is larger than a month, it runs as an AI Build Sprint beside the advisory engagement rather than inside it.
Month three: a policy people will follow, and the first scorecard
Month three writes the policy, and it is written third on purpose. A policy drafted before anybody has built anything is a document about imagined risks, and it shows: too long, too cautious in the wrong places, silent on the things that actually came up. Written after one real build, it can name the cases that occurred.
What a policy people follow looks like: one page, maybe two. Which tools are approved for which kinds of information. What must never be pasted into a general tool. Who reviews output before it reaches a customer, a permanent record, a regulator, or a decision with money attached. What to do when someone wants a tool that is not on the list, with a named person to ask and a realistic answer time. If the route to asking is a committee that meets monthly, staff will not use it, and the policy becomes a document that describes something other than what happens.
Then the first monthly scorecard, which leadership should be able to read in five minutes. What is running and who owns it. What changed this month. What we declined and why. The one or two measures we agreed to check, with their numbers. Open decisions and who is holding them. The scorecard is the mechanism that keeps the engagement honest, because it puts the declines and the open items in front of the people paying for the work.
None of this makes the role an internal one. I bring a rhythm, a set of decisions, and accountability for the portfolio. Your people keep the authority that has to sit inside your company, and the policy says which those are.
What ninety days does not produce
It does not produce a fully governed organization, a trained workforce, or a portfolio of systems in production. It produces the parts that let those happen without starting over each time: a known inventory, decisions with owners, one worked example of the whole path, a policy grounded in something real, and a reporting habit.
It also does not produce a replacement for the judgment of your general counsel, your security lead, or whoever signs your regulatory filings. An outside lead who claims to absorb those responsibilities is describing something they are not able to do.
Where this fits
This is the Fractional Chief AI Officer engagement, and it is the right rung when the question is who owns AI here month after month rather than what should we build next. If you are not sure whether that is your question yet, the AI Readiness Assessment scores ownership and governance separately from workflows and will tell you which is actually trailing. When you want to talk it through, schedule a strategy call; scope and price are agreed before work begins.