Key AI Strategies for Business Leaders from the CIT Workshop

Summary

- A multimodal AI strategy, using tools like Copilot, Gemini, and Claude for their specific strengths, is more effective than relying on a single platform.
- Robust data governance and a security audit of platforms like SharePoint must be completed before deploying AI to prevent the exposure of sensitive information.
- It's crucial to distinguish between tasks suited for rules-based automation (Power Automate) and those requiring the judgment-based capabilities of AI.
- Building a security-aware culture through continuous employee training and engagement is just as important as the technology itself for successful AI adoption.

The question is no longer if you should adopt AI, but how to do it strategically, securely, and with a clear return on investment. The constant hype can be deafening, making it difficult to separate fleeting trends from foundational business strategy.

The recent CIT AI Leadership Workshop cut through the noise, bringing together experts and business leaders to tackle these very challenges. The core takeaway was clear: successful AI adoption isn’t about chasing every new tool. It’s about a deliberate, security-first approach that integrates the right AI for the right task, empowering your team to drive measurable growth and efficiency.

Key Takeaways

  • Not All AI Models Are Equal: Choosing the right model (like ChatGPT, Gemini, or Claude) for a specific business task is critical for getting quality results. A multimodal approach is often best.
  • Security is the Foundation: Before scaling AI with tools like Microsoft Copilot, you must address data governance. Over-shared permissions in systems like SharePoint are a significant risk that AI can quickly expose.
  • Automation vs. AI: Many repetitive, rules-based tasks are better suited for automation (like Power Automate) than a complex AI model. Knowing the difference saves time and resources.
  • People Are Your Best Defense: Technology can only go so far. Building a security-aware culture through continuous training is essential for preventing data leaks and ensuring responsible AI use.

Table of Contents

  • Choosing Your Tools: A Multimodal AI Strategy is Non-Negotiable
  • The Unseen Risk: Why Data Governance Must Precede AI Adoption
  • When to Use AI vs. When to Use Automation
  • The Human Element: Building a Culture of AI Readiness and Security
  • Measuring What Matters: Calculating the ROI of Your AI Initiatives

Choosing Your Tools: A Multimodal AI Strategy is Non-Negotiable

A common misconception is that a single AI tool, like Microsoft Copilot, is the be-all, end-all solution. While Copilot is incredibly powerful for organizations in the Microsoft 365 ecosystem due to its deep integration, the workshop stressed the importance of a “multimodal” strategy. This means understanding that different Large Language Models (LLMs) excel at different tasks.

As Kyle Etter, President and CEO of CIT, noted, “You want to think multimodal. Copilot is a great part of everybody’s AI initiative… but don’t ignore the other independent models just because of it.”

Here’s a simplified breakdown discussed during the session:

  • ChatGPT (via Copilot): Excellent for summarizing, creative thinking, and tasks that require a lot of context. It’s the foundational engine for many Microsoft Copilot features.
  • Google Gemini: A powerful competitor that is outperforming in many areas. Its key strength is being truly multimodal—it was trained from the ground up to understand text, images, audio, and video simultaneously. This makes it incredibly powerful for tasks like creating infographics from text or analyzing visual data.
  • Claude (Anthropic): Built with a focus on enterprise-level security, data privacy, and task processing. It excels at creating structured documents like spreadsheets and presentations. Microsoft has even integrated Claude into Copilot for certain tasks because of its superior performance in these areas.

The strategic takeaway for leaders is to equip different teams with the tools best suited for their roles. Your marketing team might achieve incredible results with Gemini’s visual capabilities, while your operations team might benefit more from Claude’s document generation within Copilot.

The Unseen Risk: Why Data Governance Must Precede AI Adoption

Perhaps the most critical warning from the workshop was about the danger of deploying AI in an unsecured environment. AI tools like Copilot have access to all the data you grant them. If your internal data permissions are a mess, AI will not only access that sensitive information—it will “expedite that exposure.”

The classic example is the old company file share, what one speaker called “the gray box in the closet.” Many organizations migrated this data to platforms like SharePoint and Teams without first auditing permissions. Now, years of “over-sharing” mean that sensitive documents—from financial reports to HR files—are accessible to far more employees than they should be.

Before you scale your Copilot adoption, you must:

  1. Run a Data Security Audit: Start with an audit of your Microsoft 365 environment to identify and remediate over-shared files and folders.
  2. Implement Data Classification: Use tools within Microsoft Purview to automatically and manually classify data as “Confidential,” “Internal,” or “Public.” This allows you to set rules on how different types of data can be handled by both humans and AI.
  3. Leverage SharePoint Controls: Your control over SharePoint is your primary defense. Ensure that your permissions structure is sound, as this governs what data Copilot can access and use.

When to Use AI vs. When to Use Automation

It’s tempting to apply AI to every problem, but it’s often overkill. The workshop provided a clear distinction to guide your strategy:

  • Use Automation for Logic-Based Tasks: If a process is repeatable and based on clear “if-this-then-that” logic, use an automation tool like Microsoft Power Automate. Examples include routing forms for approval, sending notifications based on a date, or creating a new board in a project management tool. Power Automate has over 1,000 connectors to existing systems, making it a robust choice for streamlining predictable workflows.
  • Use AI for Judgment-Based Tasks: Use AI when you need to generate unstructured data, understand intent, or make a judgment. For example, AI is perfect for summarizing customer feedback, generating creative marketing copy, or building a complex Power App from a plain-language prompt.

A powerful demonstration during the workshop showed how AI (Copilot) could be used to build an automation flow (in Power Automate). An employee could simply describe a desired workflow in plain English, and the AI would construct the technical automation, bridging the gap between human intent and machine logic.

The Human Element: Building a Culture of AI Readiness and Security

Technology and policies are only part of the solution. Your people are your first and last line of defense. “You want people to be managers of the AI,” a speaker emphasized. “Think of them as orchestrators, managers, supervisors… Everybody becomes, effectively, a manager of a digital worker.”

To foster this culture, leaders should focus on:

  • Continuous Training: Don’t just hold a one-time training session. At CIT, we hold bi-weekly “AI lunch chats”, which are an open forum for employees to share what’s working, ask questions, and learn from each other.
  • Education on “Why”: Help employees understand why data classification is important. Teach them how to manually mark an email in Outlook or a Word document as “Sensitive.” When people understand the rationale, they become active participants in the security process.
  • Empowering Champions: Identify your early adopters and power users. Involve them in an AI committee or power group to test new tools, develop use cases, and champion best practices throughout the organization.

Measuring What Matters: Calculating the ROI of Your AI Initiatives

Ultimately, any AI initiative must be tied to business value. While the “wow” factor of AI is high, C-suite leaders need to justify the investment. The workshop provided a simple but effective framework for calculating ROI, focusing on time savings as a primary metric.

The formula is straightforward:
(Time Saved per Employee per Month in Hours x Average Hourly Employee Cost) x Number of Employees = Monthly Savings

From there, you can subtract the monthly cost of the AI tools to find your net ROI.

Start by identifying small, high-frequency tasks. If AI can save 200 employees just 30 minutes a week on tasks like summarizing meetings, drafting emails, or finding information, the time savings quickly compound into a significant financial return, freeing up your team to focus on high-value, customer-facing work.

Glossary of Terms

  • Agent Mode: A feature in AI tools (like Microsoft Copilot for Excel) that allows the AI to perform actions directly within an application (e.g., creating a new spreadsheet), rather than just providing suggestions.
  • Context Window: The amount of information (measured in tokens) an AI model can “remember” within a single conversation. A larger context window allows for longer, more complex interactions without the AI losing track of earlier parts of the conversation.
  • Large Language Model (LLM): The underlying technology behind AI chatbots like ChatGPT and Google Gemini. It’s a massive neural network trained on vast amounts of text data to understand and generate human-like language.
  • Multimodal AI: An AI model that is trained to understand and process multiple types of data simultaneously, such as text, images, audio, and video. Google Gemini is a leading example.
  • Prompt Engineering: The practice of carefully crafting instructions (prompts) for an AI model to get the most accurate, relevant, and useful response.
  • Token: The basic unit of data that an LLM processes. A token can be a word, part of a word, or a punctuation mark. The cost of using AI models is often calculated based on the number of tokens processed.

Frequently Asked Questions

What is the best first step for a mid-market company starting with AI?
The best first step is to conduct a data security and readiness audit of your current environment, particularly within Microsoft 365. Before deploying powerful AI tools, you must ensure your sensitive data is properly secured and that permissions are not overly exposed.

How do I choose between Microsoft Copilot, Google Gemini, and other AI tools?
Start with your primary business ecosystem. If your company runs on Microsoft 365, Copilot is the logical starting point due to its seamless integration. However, for specific tasks like advanced image generation or multimodal analysis, you may want to provide tools like Google Gemini to specialized teams, such as marketing. A multimodal approach is often best.

What is a simple way to demonstrate the ROI of AI to my leadership team?
Focus on time savings. Identify a common, time-consuming task that AI can accelerate (e.g., writing email drafts, summarizing long documents). Calculate the hours saved per employee per month, multiply by the average employee cost, and present that as the initial value proposition.

How do we prevent employees from using personal AI accounts for business data?
The best way is to provide them with secure, company-approved AI tools. If you don’t give them a sanctioned way to leverage AI, they will inevitably turn to personal accounts, creating “Shadow AI” and significant security risks. Couple this with clear policies and training on why using company tools is critical for data protection.

Take the Next Step in Your AI Journey

Understanding AI strategy is the first step. Implementing it securely and effectively is the next. If you’re ready to move beyond the hype and build a practical, high-ROI AI roadmap for your organization, our experts can help.

Schedule a complimentary AI readiness consultation with a CIT strategist today.


Sign Up to Get Notified When the Next Session is Scheduled

Leave a Reply

Your email address will not be published. Required fields are marked *