AI STRATEGY
Your AI agent is only as useful as what your organisation knows
Learn why AI magnifies the value and weaknesses of company knowledge, what cannot simply be uploaded, and how management can build a useful knowledge system.
Imagine a customer has returned a faulty product. The service manager asks the company's AI agent whether the customer qualifies for a replacement.
The AI agent finds three documents:
- a current returns policy approved in June;
- an old PDF that nobody removed from the shared drive; and
- meeting notes describing an exception that was discussed but never approved.
Meanwhile, Ruth in customer service knows the practical detail that is missing from all three: the supplier changed the serial-number rule last month. She knows because she spent two days resolving the last disputed return.
The AI agent answers in six seconds. Unfortunately, it uses the old PDF.
We can call this an AI-agent failure, but the model is only the newest participant in a much older organisational habit: keeping several versions of the truth and asking experienced staff to remember which one counts.
My view is that AI makes knowledge management more important, not less. A fast reader is valuable when the library is organised. When the library contains outdated policies, missing context and documents called FINAL-v7-USE-THIS-ONE.pdf, speed mainly helps the confusion arrive earlier.
The executive answer
- An AI agent can make organisational knowledge easier to find, summarise and use.
- It does not decide which source is authoritative, current or appropriate for a decision.
- Company knowledge lives in people, documents and the way work is actually performed.
- Some expertise can be captured; some is learned through practice, relationships and judgement.
- Important knowledge needs an owner, audience, effective date, review date and superseded status.
- Existing permissions must still apply when staff access information through an AI agent.
- The useful measure is not how many documents were uploaded. It is whether people reach supported answers and better decisions with less avoidable effort.
- Start with one important knowledge area where delay, inconsistency or staff dependency is already visible.
The goal is not to document the entire organisation before lunch. It is to manage the knowledge that the business cannot afford to lose, misunderstand or apply out of date.
Organisational knowledge is not a folder of PDFs
When people hear knowledge management, they often picture a document repository: policies, manuals, presentations and perhaps a search box that everybody praised during launch and quietly stopped using by the following quarter.
Documents matter, but they are only one form of knowledge.
The current draft revision of ISO 30401, the international knowledge-management-system standard, describes knowledge held in people, codified in material and embedded in processes, services, products or tools. The published ISO 30401:2018 sets requirements for establishing, maintaining and improving a knowledge management system.
For a business, the three forms look like this:
| Where knowledge lives | Familiar example | What can go wrong |
|---|---|---|
| People | A sales manager knows which questions reveal a serious buyer | The method leaves when the manager leaves |
| Codified material | A credit policy, price list or repair guide | The document becomes outdated or loses its context |
| Work itself | An ERP approval rule, quality check or supplier-escalation process | The rule is changed without the reason being recorded |
There is also a difference between knowing the written procedure and knowing how to apply it when the situation is untidy.
A warehouse supervisor may notice from the packaging that a supplier delivery is likely to contain the wrong item before a box is opened. A relationship manager may know that “I will confirm tomorrow” means something different from one customer than it does from another. An experienced technician may hear a machine and know which check to perform first.
This is often called tacit knowledge: practical understanding that can be difficult to express completely. Ikujiro Nonaka's influential theory of organisational knowledge creation explains how knowledge develops through interaction between tacit and explicit forms. That theory has also been seriously debated, particularly when “conversion” sounds as if every form of expertise can be extracted from a person and stored.
The practical conclusion is more modest and more useful: capture what can be explained, preserve the context, and do not mistake the document for the whole skill.
What AI changes
An ordinary language model has broad knowledge from its training, but it does not automatically know your current prices, approved procedures, customer commitments or the reason management rejected an earlier policy.
An organisation can connect AI to approved internal material using retrieval. A common design is retrieval-augmented generation, usually shortened to RAG. When somebody asks a question, the system searches a separate knowledge source, gives relevant material to the model and asks it to answer using that material.
Think of a knowledge agent as an extremely quick research assistant. The agent can fetch a file and explain it. It still needs to know which cabinet it may open, which version applies and what to do when two files disagree.
The original RAG research combined a model with an external retrievable memory partly to improve access to factual and updateable information. Retrieval is valuable precisely because organisational facts change. It is not a certificate of truth.
AI raises the stakes in four ways.
1. Bad knowledge becomes easier to distribute
Before AI, an outdated policy might sit unread in a folder. After AI, that same policy can be discovered, summarised and delivered to every branch in friendly language.
A 2025 study on outdated information in RAG systems found that old material could damage answers even when newer information was also available. The study is a benchmark, not a prediction of your company's failure rate, but the management lesson is clear: keeping the old and new rule together without status is not harmless archival tidiness.
2. Conflicts need authority, not just relevance
Search systems usually look for material related to the question. Yet the most similar document is not necessarily the authorised one.
Google Research on conflicting retrieval sources found that sources disagree for different reasons and those conflicts need different treatment. A branch procedure may legitimately differ by country. A new policy may replace an old one. Meeting notes may record a proposal, not a decision.
The AI agent needs signals that semantic similarity cannot invent:
- who approved the source;
- when it became effective;
- which people, products or locations it covers;
- whether another source superseded it; and
- who resolves an unresolved conflict.
3. A citation can still be wrong
Source links are essential, but a blue link does not become evidence merely because it looks busy. Research on answer attribution in RAG shows that systems can cite sources that do not actually support the answer, or fail to reflect which context influenced it.
For low-risk questions, a reader may inspect the source when something looks odd. For credit, safety, employment, legal or major customer decisions, the organisation should test whether the evidence supports the answer before depending on the system.
4. Convenient access can quietly widen access
Suppose payroll records are correctly restricted in the document system. If a general internal AI agent retrieves them for anybody who asks nicely, the business has not created a knowledge advantage. It has created a very polite data leak.
Permissions should follow the information into the AI experience. Identity must be checked, retrieval should respect document- or record-level access, and the answer should not reveal restricted details through summaries.
For Kenyan organisations, the Data Protection Act includes principles such as explicit legitimate purpose, data minimisation, accuracy, security and limited retention. Existing information being “inside the company” does not automatically make every new AI use appropriate. The exact obligations depend on the data and use case; this article is not legal advice.
Work through one real knowledge failure
Let us return to the fictional returns example. Management wants staff in Nairobi, Mombasa and Eldoret to give customers consistent answers without waiting for Ruth.
The tempting project is: upload all customer-service documents and launch a chatbot.
I would take a different route.
1. Define the decision
The first use case is not “answer anything about customer service.” It is:
Help an authorised service employee determine the current return path for a product, show the supporting policy and identify cases that require a manager.
That boundary tells us which knowledge matters and what a useful answer must contain.
2. Find the authoritative sources
The policy owner and experienced service staff review the three documents. They mark the June policy as current, archive the old PDF as superseded and record that the meeting note was a proposal rather than approval.
They also add the current supplier serial-number requirement with evidence and an effective date. Ruth's experience becomes an input to review, not an unquestioned rule simply because she remembers the last case.
3. Capture context, not only the final sentence
“Serial number required” is incomplete. Useful context includes:
- which product lines it covers;
- what counts as a valid serial number;
- when the supplier rule changed;
- what evidence the customer should provide;
- known exceptions;
- who can approve an exception; and
- the source behind the rule.
Without context, the AI may repeat a technically correct sentence in the wrong situation.
4. Make disagreement visible
If two approved sources still conflict, the AI agent should say so and route the case to the policy owner. It should not hold a private election between the PDFs.
5. Test decisions, not demonstrations
Build a set of past and invented cases: an in-warranty product, an expired warranty, an unclear serial number, a product covered by another supplier and a case where the required source is unavailable.
For each case, check:
- whether the correct source was retrieved;
- whether the source supports the answer;
- whether the right exception was applied;
- whether restricted information stayed restricted; and
- whether uncertain cases reached a person.
The launch demo may ask one clean question. Real work has a talent for arriving with half the receipt, two spellings of the customer name and a promise somebody made on WhatsApp.
A practical knowledge lifecycle for AI
Knowledge management is not a one-off clean-up before an AI project. The material changes because the business changes.
I would use this seven-part lifecycle:
- Prioritise: identify knowledge that is consequential, frequently needed or vulnerable to loss.
- Capture: record the rule, decision, experience or process while the context is still available.
- Validate: have an accountable subject expert check it against evidence and current practice.
- Contextualise: add scope, authority, effective date, exceptions, related sources and the reason behind important choices.
- Protect: classify sensitivity and preserve the access rules of the original information.
- Use and observe: let people use it in real work, then collect unanswered questions, corrections and conflicts.
- Review or retire: update the source when the business changes and clearly mark what it replaced.
The metadata can be simple:
| Field | Question it answers |
|---|---|
| Owner | Who is accountable for keeping this useful? |
| Authority | Who approved it, or what source makes it official? |
| Audience | Who may use or see it? |
| Scope | Where, when and to whom does it apply? |
| Effective date | When did it become current? |
| Review date | When should somebody check it again? |
| Status | Draft, approved, superseded or archived? |
| Evidence | Which record supports the rule or decision? |
This is editorial guidance, not a mandatory ISO schema. The right fields depend on the risk and rate of change. A lunch-menu FAQ and a workplace-safety procedure should not share the same review burden merely because both are text.
Do not turn every expert into a documentation clerk
There is a legitimate reason knowledge projects fail: capturing knowledge can become additional work for the people already doing the difficult work.
AI can help reduce that burden. It can draft a handover from approved notes, extract decisions from a project review, group repeated customer questions, propose an FAQ update or compare a new procedure with the old one. A person still checks the draft, supplies missing context and approves the final source.
A field study of 5,179 customer-support workers found that an AI assistant improved issues resolved per hour by 14% on average in that setting, with larger gains for novice and lower-skilled workers. The researchers found suggestive evidence that stronger service patterns were reaching newer workers. That is promising, but it is one customer-support environment—not a universal productivity coupon that every executive may redeem at reception.
AI can help people reach useful organisational patterns faster. It does not replace mentoring, observation and practice. If a technician's judgement depends on sound, touch, safety awareness and years of diagnosing unusual failures, a transcript of an interview will not turn a new employee into that technician.
Use documentation to support the social system:
- let experienced staff explain decisions through real cases;
- preserve the reasoning behind important exceptions;
- pair newer staff with people who can correct application, not just recall;
- use after-action reviews while details are fresh; and
- treat unanswered agent questions as signals of a knowledge gap, not automatically as a request for a longer prompt.
What management must own
This work cannot be delegated entirely to IT because many of the hardest questions are management questions.
Who owns the returns policy? Which sales report is authoritative? May procurement see every supplier term? When should old project lessons be deleted? Whose approval changes a credit rule? What happens when the documented procedure and actual practice differ?
Technology can enforce an answer after the organisation has made it. It cannot conveniently settle the politics of two departments each believing their spreadsheet is the national anthem.
Management should establish:
- a named owner for each important knowledge domain;
- clear authority and escalation rules;
- time and incentives for capture, review and mentoring;
- permissions appropriate to the information;
- a route for staff to challenge an answer or source; and
- a review rhythm based on business change and consequence.
Kenya's own policy direction recognises this connection. The National Research Fund's knowledge-management guidance asks public institutions to identify, capture, store, protect, share and apply knowledge. Kenya's National AI Strategy Implementation Roadmap includes data-quality, metadata, security and continuously updated domain datasets. Private companies are not bound to copy a public-sector framework, but the underlying point travels well: governed knowledge and data are part of AI infrastructure.
The details will differ across countries, industries and businesses. Nairobi, Kigali and Lagos are not interchangeable operating environments, and neither are a bank, a logistics firm and a five-person agency. The knowledge system should fit the work, law, language, technology and risk of the organisation using it.
A 90-day starting point
Days 1–30: find one expensive knowledge gap
Look for repeated questions, inconsistent answers, slow onboarding, dependence on one employee, avoidable rework or decisions delayed while somebody searches for context. Choose one domain with a clear owner and a meaningful but controlled consequence.
Days 31–60: establish the trusted set
Review the relevant sources with the people who use them. Mark authority, scope, dates, status and access. Capture the important unwritten exceptions and identify what still requires human judgement. Do not upload the whole shared drive simply because storage is cheaper than deciding.
Days 61–90: test access and usefulness
Pilot retrieval with a small authorised group. Use normal, awkward and adversarial questions. Check sources, support, permissions, uncertainty and handover. Record every correction and unresolved question.
Measure outcomes such as:
- time taken to find a supported answer;
- repeated questions received by experienced staff;
- answer correction rate;
- unresolved knowledge gaps;
- onboarding time for the selected task;
- continuity when an owner is unavailable; and
- whether people use the answer in a real decision.
Document count is a poor headline measure. A hundred well-labelled pages that nobody trusts are still a hundred pages.
The advantage is not owning more documents
The organisations that benefit most from AI will not necessarily be those with the largest repositories. They will be those that can tell the difference between a source and an opinion, a current rule and its ancestor, recorded procedure and practical judgement.
AI can help capture, find and explain knowledge at a scale that was previously expensive. That is the opportunity. The responsibility is to make sure the system knows what it may use, why it should trust it, when it became true and who must decide when the situation no longer fits the page.
I would start by asking one uncomfortable but useful question:
Which important part of this business works today because one person remembers what the documents do not?
That answer is a better beginning for an AI strategy than “Which model should we buy?”
Next, read what makes AI agents special to see how instructions, tools, memory and permissions turn approved knowledge into useful work. For the wider management architecture, continue with why the chatbot is not the strategy.
Research and helpful links
- Review the published ISO 30401 knowledge-management-system standard
- Read the draft second edition's distinctions between people, codified and embedded knowledge
- Read the original retrieval-augmented generation paper
- Review NIST's Generative AI Profile on provenance, monitoring and human oversight
- Explore the 2025 research on outdated knowledge in RAG
- Read the customer-support field study on generative AI at work
- Review Kenya's Data Protection Act
Research checked on 28 August 2026. Standards, technology and legal obligations change, and the right controls depend on the organisation and use case. This article provides strategic and operational guidance, not legal advice.
