Getting started
AI strategy for mid-size companies: start with the records you already have
By SourceX Editorial · Updated
Short answer
An AI strategy for mid-size companies should start with the records you already have, not with a tool purchase. It has three moves: use AI on your own records, protect those records from flowing into other companies' models, and decide deliberately whether to license them. All three begin with the same first step: an inventory of systems and history.
Key takeaways
- Tools are available to every competitor; your records of quotes, jobs, tickets and decisions are what make AI specific to your business.
- Use, protect and license are separate decisions, but they share one inventory of systems and history.
- Software vendors adding AI features can change what happens to your data at renewal, so terms review belongs in the plan.
- Licensing records is an option to evaluate, not a default; the company keeps ownership and can still use the records internally.
Why start with records instead of tools?#
An AI strategy that starts with records beats one that starts with tools because tools are available to every competitor on the same terms. What competitors cannot buy is your history: the quotes you won and lost, the jobs that came back, the tickets that escalated and the fixes that worked.
Records also decide whether any tool will work. A model asked to draft estimates is only as good as the past estimates and job outcomes it can see, and a support assistant is only as good as the resolved tickets and knowledge articles behind it. Companies that skip this step often end up with pilots that impress in a demo and stall in daily use. In RSM's 2026 middle-market survey, data quality and availability issues were the top reported inhibitor to AI deployment, ahead of security and privacy concerns and legacy systems integration.
Starting with records keeps the plan grounded in the business rather than in vendor roadmaps. The leadership team discusses concrete workflows instead of abstract capabilities.
The three-move framework on one page#
The three-move framework turns AI from a technology project into three business decisions about the same asset. Each move has its own owner and first actions, and each depends on knowing which systems hold which records.
The moves run in parallel, not in strict order. A company can pilot an internal use case while counsel reviews vendor terms and the CFO looks at licensing, as long as all three work from one shared inventory.
| Move | Question it answers | First actions | Usual owner |
|---|---|---|---|
| Use | Where can AI make our own work faster or better? | Pick one workflow with a clear record trail and measure its current baseline | COO or a business unit leader |
| Protect | Who else can see or train on our records today? | Review AI clauses in vendor contracts and set a policy for staff use of public AI tools | CTO or IT lead, with counsel |
| License | Would an AI developer license some of our history? | Run a metadata-only fit check on the strongest record families | CEO with the CFO |
Move one: use AI on your own records#
Using AI on your own records works best in a workflow where inputs, decisions and outcomes are already captured in a system. Good candidates share three traits: a repeated task, a record trail that shows what good work looks like, and a person who can judge whether the output is right.
Measure before you start. Capture how long the task takes and how often it needs rework today, so you can tell whether the pilot helped. Avoid starting with a general chatbot over unreviewed shared drives; it tends to surface outdated documents and erode trust in the whole program.
- Drafting estimates or quotes from similar past jobs in the CRM or field service system.
- Triage and suggested replies for support tickets, grounded in resolved tickets and the knowledge base.
- Summarizing service history before a technician or account manager visits a customer.
- Flagging order exceptions in the ERP or WMS that resemble past problems.
- Searching project archives for earlier RFI responses, submittal comments or proposal language.
Move two: protect the records you rely on#
Protecting your records means knowing where they can flow beyond the company, through software vendors, staff habits and contracts. Many SaaS platforms have added AI features, and some vendor terms now address using customer content to improve or train their models. Wording matters: in August 2023, after backlash over earlier changes, Zoom added a sentence to its terms stating it would not use audio, video or chat customer content to train its AI models without consent.
Three actions cover most of the exposure. Review the data and AI clauses in your main system contracts and note which renew soon. Write a short policy on what staff may paste into public AI tools, with customer details and confidential pricing as clear exclusions. Confirm who can export large volumes of records and whether those exports are logged.
Protection is not only defensive. A company that knows its rights in its own records is far better placed to use them internally or to license them later.
Move three: decide whether to license them#
Deciding whether to license records is a deliberate choice about whether some of your operating history should earn revenue from AI developers who need real workflows. Data is licensed, not sold outright: the company keeps ownership, sets permitted uses and approves every release.
The decision rests on a few questions. Do you have several years of connected records, such as tickets linked to fixes or estimates linked to jobs and invoices? Are they predominantly in English? Do your contracts and notices allow the use once personal and confidential details are removed? Typical fit is a company with 50+ full-time employees at peak and several years of operating history.
In the SourceX Enterprise Data Value Framework, eight drivers increase value (uniqueness, domain expertise, human-generated signal, scale, recency, data cleanliness, rights and AI utility), exclusivity increases price, reproducibility reduces value, and preparation cost and privacy burden reduce net value. Nobody can quote a figure before a buyer engages with your specific records.
A first 90-day plan#
A first 90-day plan gives the board something concrete without committing to large spend. The aim is one working pilot, one set of protections and one informed licensing decision.
Keep the plan short enough to fit on one page. Longer roadmaps tend to delay the inventory, which is the step everything else depends on.
- First month: build an inventory of systems, record families and years of history; review AI and data clauses in the top vendor contracts; publish a staff policy for public AI tools.
- Second month: launch one internal pilot on a workflow with a clear record trail; run a metadata-only licensing fit check; brief counsel on any rights questions that surfaced.
- Third month: measure the pilot against its baseline; decide whether to proceed to a rights review for licensing; present a one-page plan covering use, protect and license to the board.
Illustrative: a mechanical contractor writes its first AI plan#
Illustrative: a fictional HVAC and plumbing contractor running ServiceTitan has years of estimates, job notes, callbacks and maintenance agreements. Its board asks the CEO for an AI plan, and the CEO's first draft lists three software products.
The inventory changes the plan. For use, the company pilots drafting replacement estimates from similar past jobs, judged by its most experienced comfort advisors. For protect, it learns that some technicians were pasting customer addresses into a public chatbot to write job summaries, and it sets a policy. For license, it runs a metadata-only fit check on job and callback history.
The board receives a one-page plan with one pilot, two protections and a decision to proceed to a rights review. No records leave the company at any point.
Where SourceX fits in the plan#
SourceX fits only in move three. It manages licensing through the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery, beginning with a fit check built on system names, years of history and record families rather than files.
If a license proceeds, the SourceX Evidence Packet records what was licensed and on what basis. SourceX does not build internal AI tools, so moves one and two stay with your own team and vendors.
Frequently asked questions
Do we need a chief AI officer to get started?
Usually not at this stage. A mid-size company can assign each move to an existing leader: operations for use, IT with counsel for protection, and the CEO with the CFO for licensing. A dedicated role makes more sense once several pilots are running and need shared standards.
Should a mid-size company build its own AI model?
Rarely. Most mid-size companies get more from applying existing models to their own records, through vendor features or simple internal tools, than from training a model of their own. The records are the differentiator; the model can be bought or rented.
What if our records are messy or spread across old systems?
Messy records are normal. Start the inventory anyway, note where history sits and how complete it is, and pick a first pilot where records are cleanest. Old systems due for retirement deserve attention early, because their history can be lost in a migration.
Does licensing records stop us from using them ourselves?
No. Licensing grants a buyer defined rights to a prepared copy; the company keeps ownership and continues to use its records. Exclusivity terms, if any, can restrict licensing the same records to other buyers, so they deserve careful review, but they do not normally limit internal use.
How should we budget for an AI strategy?
Budget first for the inventory, one pilot and counsel's review of vendor terms, before committing to larger platforms. The inventory and protections cost mostly staff time. A licensing fit check works from metadata, so it can run alongside the pilot without a large commitment.
Sources
- In RSM's 2026 middle-market survey, data quality and availability issues were the top inhibitor to AI deployment, followed by security and privacy concerns and legacy systems integration. Source
- On August 7, 2023, after backlash over March 2023 changes to its terms, Zoom added to Section 10.4 of its Terms of Service that it will not use audio, video or chat Customer Content to train its AI models without consent. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.