The CEO’s AI Mandate: What Leaders Must Own, and What They Can Hand Off

McKinsey says some AI decisions can only be made by the CEO. Here’s what leaders must own, what to delegate, and how to keep AI governed and secure.
Security technology professional reviewing an AI systems checkup for existing business security systems

Most executives we talk with have already said yes to AI. Copilot licenses are rolling out, a department head is piloting an assistant, the contact center has a virtual agent on the roadmap, and the security vendor keeps mentioning analytics. What’s harder to find is someone who can explain who actually decided where AI should go, what data it is allowed to touch, and how anyone will know whether it worked.

A recent McKinsey article, “The CEO’s singular impact on the success—or failure—of AI in organizations” (September 2026), puts numbers to what we see in the field: “89 percent of organizations are reporting regular use of AI in at least one business function,” yet the share of true AI high performers “has remained flat at about 6 percent.” The authors argue that the gap is as much about leadership as technology, and that some of the decisions involved “can only be made by the CEO.”

We agree, and we’d go a step further. We’ve written before about why most organizations aren’t agentic yet, focusing on workflows and change management. Here we want to answer a more practical question from our own client work: if the CEO has to own AI, what exactly should they own, and what can they confidently delegate to IT and a trusted partner?

Why AI Can’t Be Treated as Just Another IT Project

We understand the temptation to hand AI to IT. In most mid-market organizations we support, IT already runs Microsoft 365, the phone system, the network, and often the cameras and access control. Adding AI to that list feels natural.

But in our experience the hardest AI questions aren’t technical. Which areas of the business deserve real investment? Which customer, patient, or case data is off-limits for outside models? Who is accountable when an AI agent takes an action? Those are business and risk decisions. In the regulated and high-security environments we work in, such as healthcare, logistics, legal, financial services, and critical facilities, they’re also compliance decisions. A capable IT team or managed service provider can execute them well, but it shouldn’t be making them alone.

When leadership stays out of these calls, we usually find the same pattern: a dozen disconnected pilots, inconsistent data rules from one site to the next, and no clear way to measure return. When an executive sets direction, the same tools start producing results.

Decision 1: Pick the Few Places Where AI Will Really Matter

We push every client to narrow their focus. McKinsey makes a similar case, describing the CEO’s most critical role as “selecting the two or three domains where AI-native redesign will have the greatest impact on the business.” Spreading small experiments everywhere builds familiarity but rarely moves the numbers.

For the multi-site organizations we serve, the highest-impact domains usually sit where communication, data, and security already meet:

  • Customer and patient communications. Contact center AI agents that answer routine calls, authenticate callers, and route complex issues with full context, connected to your phone system and Microsoft Teams contact center rather than bolted on beside them.
  • Security operations. AI enablement for video, access control, and alarm platforms, so operators spend time on real events instead of sorting through noise across dozens of sites.
  • Revenue and service workflows. AI that drafts quotes, summarizes customer history, and flags at-risk accounts using data already in your CRM and Microsoft 365.

Broad access to tools like Copilot still matters for building fluency. But we recommend leadership name the few domains where it expects measurable results and fund them deliberately.

Decision 2: Decide What Can Leave the Building

This is the decision we see mid-market leaders underestimate most. Every AI feature that gets switched on, whether a meeting summarizer, an email assistant, or a camera analytics add-on, is a decision about where your data goes and who can see it. If no one has set a policy, each vendor’s default settings quietly become your policy.

McKinsey frames this as a CEO responsibility: working with technology leaders to set explicit controls “denoting what can leave the building and under what conditions.” The article also cautions that sending proprietary data and workflows through outside model providers can hand valuable know-how to vendors who may later compete with you.

Turning executive intent into working controls is the core of our AI security, governance, and risk work:

  • Classifying data so sensitive records stay out of unapproved AI tools.
  • Tightening Microsoft 365 permissions and sharing before Copilot surfaces files people were never supposed to see.
  • Defining approved tools, acceptable use, and logging, so “shadow AI” doesn’t become your real AI strategy.
  • Aligning AI use with your existing governance, risk, and compliance program instead of creating a parallel one.

BTI operates as an ISO 27001 compliant organization, and we bring the same information security discipline to AI deployments that we apply to the networks and systems we manage for clients.

Decision 3: Keep Models Interchangeable and Own Your Data

We advise clients to treat their data, workflows, and integrations as long-term assets and to treat any particular AI model as replaceable. Models, pricing, and capabilities are changing every few months, and AI costs can vary widely depending on how a workflow is designed. McKinsey reaches the same conclusion, saying proprietary data and decision logic should be permanent assets, “while the underlying models should become increasingly interchangeable.”

In practice, that argues against locking critical workflows into one vendor’s closed AI feature. It argues for AI connected to the systems you already run, including Microsoft Teams and 365, your phone and contact center platform, your CRM, and your security systems, through integrations you control. When a better or cheaper model shows up, you should be able to switch without rebuilding your contact center or re-cabling a building.

It also depends on unglamorous foundations. AI agents that answer calls, analyze video, or act in business systems need reliable bandwidth, segmented networks, and monitored endpoints. In our view, sound network design and strong cybersecurity are part of AI strategy, not separate from it.

Decision 4: Build Trust Alongside Technology

The biggest obstacles we encounter in AI rollouts are rarely technical. They’re about trust, habits, and uncertainty about what AI means for people’s roles. McKinsey’s data shows the disconnect clearly: “70 percent of employees say they feel personally ready to use AI, but only 27 percent of leaders say their organization is ready” to make the changes required at scale. The best leaders, the authors write, “construct a trust architecture alongside a technology architecture.”

Here’s how we put that into practice for multi-site organizations:

  • Human-in-the-loop by design. Agents can draft, triage, and recommend. People approve anything that touches money, safety, access, or regulated records.
  • Visible audit trails. Staff, auditors, and regulators can see what an AI agent did, when, and with which data.
  • Leaders who use the tools. Senior teams are often less fluent in AI than frontline staff. Short executive sessions on Copilot and agent workflows close that gap quickly.
  • Consistency across sites. The same policies and controls in every location, rather than each site improvising.

What CEOs Can Confidently Delegate

Owning AI doesn’t mean the CEO configures tenants or tunes call flows. Once leadership has set the ambition, the priority domains, and the data boundaries, we’ve found execution works best when internal IT partners with a provider through managed IT or co-managed IT support that adds capacity without replacing your team. Delegated work typically includes:

  • AI readiness assessments of Microsoft 365, identity, network, and data.
  • Deploying and governing Copilot and other approved tools.
  • Integrating AI agents with phones, Teams, and contact center platforms.
  • Enabling AI analytics on video, access control, and alarm systems through security system integration.
  • Ongoing monitoring, cost tracking, and policy enforcement.

The key is that the partner executes leadership’s decisions rather than quietly making them.

Where BTI Fits

BTI Communications Group has served businesses since 1985. Over four decades we’ve grown from communications into IT and networking, and since the 2010s into cybersecurity and physical security. That combination is why our AI services and solutions focus on connecting AI to the systems organizations already depend on, with governance built in from the start. We work with high-security, regulated, multi-site organizations from offices in Los Angeles, Chicagoland, and Phoenix. Learn more about why organizations choose BTI for AI.

AI won’t stop changing, and there’s no finish line. The organizations we see succeeding are the ones where leadership sets clear direction now and pairs it with disciplined execution.

Ready to turn your AI intent into a governed, connected plan? Talk with a BTI business advisor about an AI readiness and governance review for your organization.

Frequently Asked Questions

Why should the CEO own AI strategy instead of IT?

The most important AI decisions, such as where to invest, what data can leave the organization, and who is accountable for AI actions, are business and risk decisions. IT and partners should execute them, but leadership needs to make them.

What does “deciding what can leave the building” mean for AI?

It means setting explicit policies on which data, documents, and workflows may be processed by outside AI models and under what conditions, then enforcing them with data classification, permissions, approved tools, and logging.

How can mid-market organizations avoid AI vendor lock-in?

Connect AI to your existing systems, such as Microsoft 365, Teams, phones, CRM, and security platforms, through integrations you control. Treat your data and workflows as permanent assets and the underlying models as replaceable.

Can AI be added to our existing phone and security systems?

Often, yes. Contact center AI agents can integrate with Teams and existing phone platforms, and many video, access control, and alarm systems support AI analytics when the network and integrations are designed properly.

How does BTI help with AI governance?

We help organizations assess AI readiness, set acceptable-use and data policies, secure Microsoft 365 before Copilot rollouts, and monitor AI tools over time, supported by our ISO 27001 compliant security practices.

Table of Contents

Book an AI readiness conversation

Talk with a BTI business advisor about where AI fits, how to govern it, and what your data and infrastructure need first.
Book now ›

Get a free IT & security review

A BTI business advisor reviews your network, cloud and security posture against ISO 27001 compliant practices and shares clear next steps. No obligation.
Book now ›

Get a free communications cost review

See how your phone, Teams calling and contact center spend compares, with a tailored recommendation from a BTI business advisor.
Book now ›

Free security assessment

Get a walk-through of your facility and a tailored recommendation from our team — no obligation.
Book now ›

Talk to a BTI advisor

Have a question about IT, security, communications or AI? A BTI business advisor will point you to the right solution.
Book now ›
Picture of Eric Brackett
Eric Brackett

Eric W. Brackett is the founder and president of BTI Communications Group, where he’s been helping businesses nationwide simplify communications, strengthen IT security, and unlock growth since 1985. Known for his client-first approach and “Yes! We Can” mindset, Eric transforms complex technology into reliable, cost-saving solutions that deliver long-term value.

Related articles

California’s Workplace AI Laws Will Become the Model for Other States

California’s No Robo Bosses Act and AI surveillance limits take

AI Is Everywhere, But Your Organization Isn’t Agentic Yet: How to Close the Gap

AI is everywhere, but few organizations are agentic. See why

Revenue Alignment Review: AI for Sales & Marketing

Point AI at your most profitable clients first, then automate

Ready to strengthen your security and IT infrastructure?

Book a free consultation with BTI Communications Group. We’ll assess your facility, walk you through your options, and recommend the solution that fits your operations — no obligation.
IT Services

Let's Start a Conversation

What's the best way for us to contact you?

Top quality brands, expert engineering, transparent cost, and maximum ROI.