A new Chief AI Officer can easily spend the first 100 days becoming the organisation’s most senior AI evangelist. That is rarely the highest-value use of the role.
By the end of the first three months, the organisation should be able to answer a more important set of questions. Which AI systems do we operate? Who can approve a new one? Which uses create material risk? Which pilots deserve to scale? Who owns failures? What evidence reaches the board? And where does the CAIO’s authority stop?
The first 100 days should therefore build an operating model, not a collection of presentations. The plan below is designed for a senior leader entering an organisation where AI activity already exists but accountability is fragmented.
Days 1-30: establish the mandate and see the real system
The first job is not strategy writing. It is finding the gap between the formal organisation and the way AI is actually being used.
Clarify the CAIO mandate
Write a one-page mandate that identifies what the CAIO owns, what the CAIO influences and what remains with existing executives. At minimum, settle authority over enterprise AI policy, high-risk approvals, portfolio coordination, standards, assurance, incident escalation and board reporting.
The mandate should also state what the CAIO does not own. Cybersecurity remains a security leadership responsibility even when AI changes the threat. Data protection does not disappear into an AI office. Business units remain accountable for the outcomes of processes they operate.
This is why the role needs strong interfaces rather than a large central empire. The Certified Chief AI Officer course is designed for leaders developing this enterprise-level combination of strategy, governance and implementation judgement.
Build a working AI inventory
Do not wait for a perfect register. Create a usable version quickly.
For each system or material use, capture the business owner, user group, purpose, vendor or model, data categories, decisions influenced, external exposure, degree of autonomy, human review, current controls and material dependencies.
Then add one field that many inventories miss: what would have to be true for this use to cause significant harm? That question turns the register from a procurement list into a risk map.
Listen for shadow workflows
Interview operational teams, not only executives. Ask where people already use generative AI to draft, analyse, classify, translate, summarise, code or make recommendations. Shadow use is often rational behaviour filling a workflow gap. Treat it as evidence about unmet needs as well as a control problem.
At day 30, the CAIO should have a mandate, an initial system inventory, a stakeholder map and a list of the ten most consequential unanswered questions.
Days 31-60: turn principles into decision rights
The second month is where governance must become operational.
NIST’s AI RMF uses Govern, Map, Measure and Manage to structure AI risk activity. The “Govern” function is especially relevant to the CAIO because it calls attention to policies, accountability, roles, culture and processes rather than treating risk as a technical test performed at the end.
Create a tiered intake gate
Not every AI use deserves the same review. A team using an approved tool to reformat internal text should not face the same process as a system screening job applicants or making safety-relevant recommendations.
Create three or four risk tiers using factors such as:
- the consequence of an incorrect output;
- personal or sensitive data involved;
- whether people are materially affected;
- autonomy and ability to take action;
- regulatory or contractual exposure;
- external publication or customer interaction; and
- reversibility of the outcome.
Low-risk uses can follow standard controls. Higher-risk uses require defined evidence and specialist review.
Define who decides
For each tier, specify who can approve the use, what evidence they must see and when approval expires. Use named roles, not phrases such as “the AI committee”.
The Certified AI Business Steward can support a federated model in which business functions retain local ownership while trained stewards connect daily decisions to enterprise policy.
Publish minimum evidence requirements
Ask for a small set of evidence consistently: intended purpose, data sources, known limitations, evaluation method, human oversight, vendor dependencies, security/privacy review where relevant, incident route and monitoring metrics.
The goal is to make good decisions repeatable. A governance process that depends on who happens to attend the meeting is not yet an operating model.
By day 60, the CAIO should be able to show how a proposed AI use enters the organisation, how its risk is triaged, who approves it and what evidence survives the decision.
Days 61-100: rationalise the portfolio and prove value
The third phase shifts from control design to portfolio discipline.
Classify every significant initiative
Place initiatives into four groups: scale, continue learning, redesign or stop.
“Scale” should require more than a successful demo. Evidence should show a repeatable benefit, acceptable failure behaviour, ownership, supportability, cost visibility and controls that still work outside the pilot team.
“Continue learning” is appropriate when value is plausible but evidence remains incomplete. “Redesign” applies when the problem is worth solving but the current workflow, model or control is weak. “Stop” is a legitimate outcome where economics, risk or adoption do not justify more investment.
This is the practical link between the CAIO and an AI business strategist: the portfolio must connect technology choices to business outcomes rather than measuring activity.
Build a balanced AI scorecard
Avoid a dashboard built only from the number of pilots and hours “saved”. Track four dimensions:
Value: measurable outcome achieved, adoption in the intended workflow and benefit after operating costs.
Reliability: quality against defined acceptance criteria, exception rate and drift or degradation indicators.
Risk: control exceptions, incidents, unresolved high-severity findings and vendor changes.
Capability: availability of trained owners, reviewer competence and dependency on scarce specialists.
The scorecard should make uncomfortable information visible. If every indicator is green, it may be measuring advocacy rather than governance.
Establish board reporting
Boards do not need model-level telemetry. They need decision-useful information: material uses, aggregate exposure, major incidents, significant vendor dependencies, investment versus realised value, regulatory changes and decisions that need board attention.
The OECD’s 2026 Due Diligence Guidance for Responsible AI reinforces the importance of senior-management oversight and, where appropriate, board responsibilities for AI-related responsible business conduct. The precise governance structure will vary by organisation, but accountability should not evaporate into technical teams.
The 100-day deliverables
At the end of the period, a credible CAIO should be able to place eight things on the table:
- A written mandate and decision-rights map.
- A material AI system and use-case inventory.
- A risk-tiered intake and approval process.
- Minimum evidence requirements for significant uses.
- A portfolio decision for each major initiative.
- An AI scorecard covering value, reliability, risk and capability.
- A board reporting structure and escalation route.
- A twelve-month roadmap focused on the largest capability and control gaps.
These deliverables are more valuable than a 100-slide AI strategy because they change how decisions are made on day 101.
What not to do in the first 100 days
Do not centralise every AI decision in the CAIO office. The queue will become a bottleneck and business accountability will weaken.
Do not make the inventory a six-month data-collection project. Start with material uses and improve it iteratively.
Do not allow “innovation” to become a permanent pilot category. Every experiment needs an exit decision.
Do not report only good news. The CAIO earns credibility by revealing uncertainty early enough for leaders to act.
Do not treat training as a substitute for workflow controls. People need capability, but they also need approved tools, clear authority and escalation routes.
Leaders who want a broader route across governance, strategy and operational capability can review The Case HQ’s strategy and management courses.
Final takeaway
The first 100 days of a Chief AI Officer are successful when AI becomes easier to govern and easier to evaluate. The organisation should know what it uses, why it uses it, who decides, what evidence is required and what happens when the evidence is weak.
That is the foundation for responsible scale. Everything else – new tools, agents, models and ambitious programmes – becomes easier to judge once the operating model exists.

Responses