← Research
Research

Rules before tools

An AI strategy in four layers and ten rules, first published 17 August 2025, kept here as written with dated notes on what has moved.

Last reviewed: 15 September 2026

Rules before tools is Rahim Hirji's principle that an organisation writes its rules for AI, which decisions it may inform, recommend or execute, who is accountable, what is measured and what people must stay capable of, before it buys another tool. This is the essay of 17 August 2025 that set it out, republished unchanged apart from house style, with a dated note at the top on what has moved since. The original is at Box of Amazing. See the glossary.

Question this page answersAll 811 questions this research covers

People ask for an AI strategy and want a quick answer, and there is not one. To do it properly you have to get under the skin of a business: its workflows, data, incentives and culture. Without that, all you have is doing AI things for show. This is the essay sent to everyone who asks, first published in Box of Amazing on 17 August 2025 and republished here unchanged apart from house style, so that the argument has a dated home on the record. Four layers, ten rules, a governance charter, the human shift, and what to do this quarter. The rules come before the tools, and the tools are easier to choose once they are written.

The answer, in one line

That an organisation writes its rules for AI before it buys another tool: which decisions a machine may inform, recommend or execute, who is accountable for each, what is measured, and what its people must stay capable of doing.

Share as a card

Definition#

Rules before tools: the principle that an organisation writes its rules for AI, meaning which decisions it may inform, recommend or execute, who is accountable, what is measured and what people must stay capable of, before it buys another tool, because the tools slot into a system that has been designed and fall out of one that has not. Rahim Hirji's phrase and framework, first published 17 August 2025, and the name of the leadership decision session that applies the ten rules to one organisation.

Share this definition as a card

Read this first, 15 September 2026. Thirteen months is a long time in this subject and three things in the essay have moved. The Klarna figures in the section on trust are the company's own from 2024; in May 2025 its chief executive said cost had been too dominant a factor in that decision and that the result was lower quality, and the company began recruiting people again. The figures stand and the lesson has changed, which is graded in the evidence base. The tenth rule defines capability debt as a skills gap; the term has since been narrowed on this site to the accumulated loss of judgement that builds when an organisation automates the doing without redesigning the learning, and the fuller treatment is at capability debt. And the model named in the third paragraph dates the piece; keeping the date on it is why it is here. Everything else has held, and the ten rules are now the spine of the AI leadership page.

The essay, as first published#

People ask me for an AI strategy all the time, sometimes in the oddest of moment. They want a quick answer. Sorry to tell you this, but there isn’t one. To do it properly, you have to get under the skin of a business, its workflows, data, incentives, and culture. Without that, all you’ve got is doing AI things for show.

So what I tell them is this: read this first - and I send them what you are receiving today. It’s the closest thing I can give you to a starting point without sitting inside your organisation. Consider it free consultancy for 2025. It’s longer than a LinkedIn post, but it will help consolidate your thinking. Bookmark it, send it to your AI team leads, take your time with it. However you skew whether it is AI-first, AI-driven, or AI-supported, you’ll find something here you can use to survive what’s already happening.

This is the reality of 2025. If you’re working, you’re already in one of those categories, whether you admit it or not. Most of my current feed and email is noise. It’s the same pattern. Last week GPT-5. Previously Veo-3, but it’s always the same. New model. New product. New demo. Crowds rush in like magpies chasing the shiniest thing. Screenshots. Hype videos. Hot takes. Likes, comments, reposts, restacks. Then nothing changes in their business. Dabbling is fine if you have time, but most do not. Watching every new tool feels like standing in a stadium with 50,000 people shouting while someone tells a joke. You miss the punchline. So, choose one or two voices you trust and ignore the rest or you will drown in the hype.

The part most people don’t want to hear? The boring work is the valuable work. Data that doesn’t rot. Workflows that match the speed of the tools. Guardrails that stop you from blowing yourself up in production. Skills that compound so your team and colleagues get better as the tech does. That’s the difference between AI hype theatre and results. AI will improve your processes first. Then it will change your people’s jobs. If you get it right, it will open doors you didn’t know were there. But that only happens if you think strategically.

Bill Gates calls AI “the most important advance in technology since the graphical user interface.” Kai-Fu Lee says the winners will be “those who pair human strengths with AI speed.” Scott Galloway says, “AI will not take your job. Someone using AI will.” I don’t love that line. AI unbundles jobs task by task until the role is smaller or gone. The point still stands, though. AI is an opportunity if you choose to use it.

In my SuperSkills research, I’ve spoken with hundreds of people from CEOs, operators, technologists, teachers, shop owners. I’ve seen who’s getting sharper, who’s being replaced, and who’s still waiting for AI to arrive in their city. If you want to be in the first group, you need principles that outlast the tools.

On my recent holiday to Thailand, I met Sugar. She assures me that is her real name. She runs a beach bar, a restaurant, a Thai beachfront spa as well as an ice cream stand and a sundries shop. Two years ago her restaurant was failing. Today she dominates a busy stretch on Chawengmon beach. Her secret was multiple overnight play arounds with ChatGPT where she learned to track every competitor’s prices and menus within a twenty-minute walk. She tailored offers for niche audiences (Gluten-free, Halal etc). She struck deals with other businesses. On the surface, it looks like the same simple operation. Behind the scenes, she is running AI agents to manage suppliers, pay bills, and spot new opportunities. She is 25. It is not about looking like a tech company. It is about using tools to make faster, better decisions than anyone else.

That’s why I say: don’t be a magpie. Be more like Sugar.

The strategy stack that compounds#

To keep things super simple, think about AI in layers:

Get these layers right, and the tools you choose will slot in instead of falling out.

Ten rules that outlast the tools#

There are probably other technical areas worth considering, but strategically, I think they are the core of how you should think.

Rule 1. Start with tasks

Map work to the smallest useful units and kill zombie work: repetitive, low-value tasks that burn time without creating useful output. Duolingo’s Birdbrain personalises every exercise and now drafts new content faster than before because they rebuilt the workflow around it. Siemens fixed factory defects at the step level, not by chasing full automation. Kobo360 in Nigeria cut freight coordination hours with AI-driven load matching. This is one of my 7 SuperSkills in action: Curiosity applied to real work.

What to actually do: list 20 high-volume tasks, mark low-value ones, remove 3 with narrow automations.

Rule 2. Redesign the system

Pouring AI into yesterday’s process just scales yesterday’s problems. Shopify’s Magic feature can write product copy in seconds, but the real gain came when they overhauled catalogue and approvals. Maersk’s routing AI still worked under Red Sea and port congestion because they designed for resilience, not perfection. Etisalat in Abu Dhabi rebuilt service triage with AI and cut resolution times by 35 percent.

What to actually do: sketch the current process, circle delays, rebuild 1 flow with fewer handoffs and smarter checkpoints.

Rule 3. Put a human in command

Every winning AI programme has one accountable owner. DBS Bank put AI at the executive table, so credit, fraud, and service changes could move fast. Canva put AI inside product teams so launches solve real user problems.

What to actually do: name the owner, publish a one-page approval path, set clear risk appetite. This is the SuperSkill Big Picture Thinking in action.

Rule 4. Make it legible

People act on what they understand. Microsoft gives teams error analysis and explanations. Ant Group shows merchants why transactions were flagged, which cuts disputes and builds trust. mBank in Poland uses real-time fraud blocks without locking out genuine customers.

What to actually do: attach plain-language explanations where money or people are affected, set confidence thresholds for human review, keep a short purpose-and-limits note.

Rule 5. Measure impact and harm

“Feels fair” is not a metric. LinkedIn improved representation in search without hurting business outcomes by building fairness into ranking. Spotify measures how recommendations balance accuracy with discovery because it shapes who gets heard. Safaricom’s M-Pesa uses AI to flag SIM-swap scams before they hit customers, cutting incidents.

What to actually do: pilot with 5 to 10 per cent of users or one region, track one business metric and one safety metric, and know when to roll back.

Rule 6. Strengthen your data backbone

Consent scarcity is real. The most valuable data is both up-to-date and gathered with explicit permission. Ping An protects financial and health data with firm access rules. Estonia’s national ID works because people trust it and it’s useful every day. Aadhaar in India handles hundreds of millions of authentications a month because the controls are clear.

What to actually do: assign data owners, document what is collected and why, delete what you don’t need.

Rule 7. Build guardrails in by default

Guardrails aren’t brakes, they’re speed. Apple processes most AI work on-device and uses Private Cloud Compute with zero retention when it can’t. Salesforce masks sensitive data fields and routes them through safe paths.

What to actually do: keep an allow-list of actions, log behaviour, red-team monthly for failure modes like prompt injection.

Rule 8. Treat capacity as a strategy

Processing power is the new supply chain. Anthropic locked in GPU supply with AWS to guarantee uptime. TCS in India balances workloads across hybrid compute so they never stall. Jensen Huang says accelerated computing is cost-effective, but only if you lock in capacity before you need it. Listen to Jensen!

What to actually do: document where each system runs, how fast it must respond, and move simple jobs to lighter options.

Rule 9. Protect dignity by design

Privacy is a growth driver. Bumble deletes verification images after checks. Estonia’s ID adoption sits near 98% because trust was designed in.

What to actually do: publish how data is used, set expiry by default, and remove anything that feels like a trick. This is Principled Innovation. Another of my SuperSkills.

Rule 10. Educate for leverage

Capability debt is the gap between the skills people have and the ones they now need. It kills more AI projects than tech failures. PwC invested big in upskilling. M-KOPA in Kenya trains teams to use handset AI to extend microloans and solar power. This is the Augmented Mindset, the most topical of my SuperSkills. It helps you and your team prepare for the future.

What to actually do: run monthly challenges on real tasks, teach managers to read simple dashboards, share before-and-after examples.

The AI governance and risk charter#

If you want your teams to move fast without fear, give them rules they can remember and use. This isn’t about creating a binder no one reads. It’s about making sure people know what’s allowed, what isn’t, and who decides.

Clear guardrails speed you up. Unclear guardrails slow you down.

Managing the human shift#

AI changes your workflows and it changes how people feel at work. If you ignore that, you’ll kill adoption.

People feel excited, anxious, tired, and proud, sometimes in the same week. Many haven’t noticed AI in their city or country yet. They will when back-office work shrinks, answers arrive faster, and certain jobs disappear. You have to make this a people change, not a tool rollout.

One of my SuperSkills, Empathetic Communication, is this: connecting the change to what people actually care about.

A few extra moves that separate the winners#

These are the habits that make your AI systems last longer than the launch party buzz.

Capacity, cost, and cadence#

Processing power is now a strategy. Decide what must be instant, what can be batched, what runs on-device, and what needs dedicated clusters. Plan this before you need it.

Price the full journey, not just the pilot. The integration tax (the hidden cost of going from a cool demo to something you can trust in production) is real. You’ll pay for data preparation, consent, safety checks, audits, human checkpoints, monitoring, bandwidth, and compute. The cost of doing nothing is real too: losing market share, slowing down cycle time, and lowering quality.

How to fund, run, and measure:

Where to start this quarter#

The next wave without the buzzwords#

Agents will act, not just answer. Keep their scope tight, log every step, and have a stop button. Multimodal systems will read text, tables, images, and video, which changes how you design training, support, and safety reviews. More will run on-device for speed and privacy. Smaller models will do 80% of the jobs for a fraction of the cost.

Yuval Harari warns that AI can “hack the operating system of human civilisation” by producing persuasive stories at scale. That’s why provenance, identity, and dignity aren’t nice-to-haves. They’re survival strategies.

Sugar, not Magpie#

I’ve met hundreds of people in this space. Some feel stretched, some feel left behind, others feel newly powerful. If you’ve already started down the AI path, pass this to your lead and make it the standard. If you’re thinking about AI, use this as your checklist to start.

If you’ve read this far, you’re looking at the next three years, not the next three weeks. Good.

Don’t be a magpie. Be more like Sugar. Make AI part of your operating system. Rethink what you do, how you do it, and how it will affect your team and customers. Do a clean sweep, decide what you need, and get someone accountable to deliver it.

If you’re not doing this now, you’ll be playing catch-up just to stay in the game.

The next model won’t save you. A better system will. Control the change before it controls you.

Key sources

The rules are the practical half of AI leadership, defined there as the allocation of judgement. Rule 3 is human at the start in operational form; rule 10 became capability debt; the whole is the design side of drift versus design. The evidence on why programmes fail when the rules are unwritten is on the AI leadership page and in the evidence base.

About this research#

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. This essay was written from twenty years building technology businesses and seven years of research across more than 200 organisations, and is kept here as first published, with dated notes where the world has moved. The company examples are as reported at the time of writing and were not independently verified for this republication; treat them as illustrations, not findings.

How this research works  ·  Reviewed quarterly  ·  Found an error? Tell me and it is corrected on the page.

Evidence review · SS-2025-003 · Graded against the published rubric

Cite this page

Hirji, R. (2025). Rules before tools. The SuperSkills evidence base, SS-2025-003. https://thesuperskills.com/research/rules-before-tools. Last reviewed 15 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

What does rules before tools mean?

That an organisation writes its rules for AI before it buys another tool: which decisions a machine may inform, recommend or execute, who is accountable for each, what is measured, and what its people must stay capable of doing. The tools slot into a system that has been designed and fall out of one that has not. Rahim Hirji set the principle out in ten rules in August 2025.

What are the ten rules?

Start with tasks. Redesign the system. Put a human in command. Make it legible. Measure impact and harm. Strengthen your data backbone. Build guardrails in by default. Treat capacity as a strategy. Protect dignity by design. Educate for leverage. Each comes with a what-to-actually-do line and company examples as reported at the time of writing.

What are the four layers of the strategy stack?

Redesign process and transformation, so quality rises and waste falls. Rewire the organisation, setting ownership, incentives and routines so people and AI work in sync. Rework the nature of jobs, breaking them into tasks and moving people toward judgement, service and creativity. Find new growth, using AI to open markets, improve unit economics and launch products that were not possible before.

Has anything in the essay changed since it was written?

Three things, noted on the page with dates. Klarna's 2024 customer service figures are quoted; in May 2025 its chief executive said cost had been too dominant a factor and the company began recruiting people again. Capability debt, defined in rule ten as a skills gap, has since been narrowed on this site to the accumulated loss of judgement from automating the doing without redesigning the learning. And the model named in the opening dates the piece. The ten rules themselves have held.

In this hub

Definitions

The terms this field uses, defined against their primary sources.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Ten rules, free to use. Applying them to one organisation, with the chief executive and the executive team in the room and the rules written by the end of the day, is the engagement. Board advisory.

This argument is one a board usually meets for the first time in the room. There is the boards and leadership version, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.