RH Consulting · Fractional Chief AI Officer
Most small businesses use AI. Almost none run on it.
Seventy-six percent of small businesses now use AI somewhere. Fourteen percent have it built into how the business actually operates. That gap is the difference between buying a tool and installing a system.
I build and run a fleet of AI agents for my own consulting practice. I install the same thing in yours.
76%
of small businesses use AI
14%
have it embedded in core operations
Goldman Sachs 10,000 Small Businesses Voices, n=1,256, fielded January 2026
It was never about the price of the software.
When small business owners are asked what actually stops them going further with AI, cost comes fourth. What comes first is not being able to trust it.
- Privacy and security concerns36%
- Not knowing what AI can actually do28%
- Accuracy, bias, and errors26%
- Cost12%
Intuit QuickBooks AI Impact Report, January 2026. Cost ranking from SBE Council / TechnoMetrica, February 2026.
Owners are not holding back because agents are expensive. They are holding back because nobody has given them a reason to trust an automated system with work that matters, and they are right to want one.
Trust comes from monitoring, permissions, audit trails and a tested rollback path, designed in from the first build. The tools do not ship with any of that. I build it.
I run my own practice on this.
There's no wall of testimonials here, and there doesn't need to be. The system I'd put in your business is the one already running mine, on my own revenue, for months. It works.
The same governance, permissions, monitoring, and rollback path are live in production and proven under real load. I've hit the failure modes myself and closed them, so what reaches you is the hardened version. When I put something on this page, it's because I already run it, every day.
Nineteen agents, five executive functions, one post still vacant.
This is the staffing chart of the system that runs this practice. It is organised the way you would organise people: by the executive function each role covers, and the kind of time it gives back.
19
Reasoning agents on live schedules
5
Executive functions covered
1
Posts named and not yet filled
- Daily strategic frame: sets the day's three priorities and, just as importantly, names what not to touch.
- Weekly portfolio review: a retrospective across every venture, what moved, what stalled, what compounded.
- Cross-venture synthesis: reads ideas captured across separate businesses and finds the connections between them.
- Gap analysis briefing: a daily read on goals versus reality, including the cost of anything slipping.
The remaining vacant post is on this chart deliberately. A system that claims to be finished is either small or not being honest about its edges.
The operating layer is wired to the revenue layer.
Most AI deployments bolt an assistant onto one department. The value is in the seam: intelligence gathered overnight is scored, routed, and lands as account groundwork by morning, without anyone asking for it.
Stage one, Intake.
Overnight sweeps of market, competitor and funding signal. Every finding carries a source.
Stage two, Judgement.
Findings scored against a defined ideal-customer profile. Most are discarded. The ones that survive get a named reason and a deadline.
Stage three, Groundwork.
What survives is routed into account research and outreach material, so the first human touch starts from evidence rather than a blank page.
The most recent example is three days old. On 28 July I raised a token limit to suit a newer model. The change looked clean and the test suite passed. It had crossed a threshold that rejects a certain kind of request, and ten of my thirteen agents were on the affected path. They would have failed on their next scheduled run, overnight, with nobody watching.
It surfaced because I ran one agent for real instead of trusting the tests, and it failed instantly with the vendor's own error: "Streaming is required for operations that may take longer than 10 minutes." All ten were converted and redeployed the same day, before a single scheduled run failed.
That monitoring layer is not something I add at the end of a project. It is the first thing I build, and it is the reason I can put my name on a system that runs when you are not looking at it.
Your AI Operating System, in three phases.
The same sequence I used on my own fleet, scoped to your business, ordered so each phase pays for the next.
- 1
Stabilize. Get the recurring work off your desk
The load-bearing work that happens every day and currently depends entirely on you being available to do it.
- Inbox and Lead Triage: sorts, tags, and drafts replies to the routine majority of what lands in your inbox
- Scheduling: finds times, confirms, and reschedules without a reply-all thread
- Weekly Ops Brief: one message each Monday, what needs you and what was already handled
- Research Scout: watches your market and flags only what actually matters
- 2
Systemize. Multiply your capacity
Turn your own past work into a working library, then layer on agents that draft and decide from it, in your voice.
- Pipeline and Account Intelligence: researches prospects and drafts account plans, the same engine behind my own territory system
- Proposal and Quote Writer: drafts from your past work and your pricing, and when something is not in the file it asks rather than inventing
- Financial Health Monitor: tracks cash and flags anomalies early
- 3
Operate. Keep it alive
The phase most projects skip, and the reason most of them are dead within a year.
- Health and Security Watchdog: catches a failing agent before it becomes a customer-facing problem
- Chief of Staff: routes one request across the whole team of agents and hands back a single coherent answer
- Quarterly Review: a working session with me, what the system caught, what it missed, what changes next
Why not just build it yourself?
You can. The tools are good, they are cheap, and most of them need no code. Building an agent is the easy part, and it is not what you would be paying me for. Here is what the first version does not tell you.
| What breaks | Day one | Later | This has happened |
|---|---|---|---|
| Sustainability | The agent works. | The model it names gets retired on a date you never saw. | More than 30 OpenAI models retire on a single day this October, including the ones most tutorials tell you to use. A related shutdown in August turns off ChatGPT actions inside Zapier, and Zapier leaves the migrated ones switched off pending your review. |
| Governance | It does what you asked. | Months later nobody can explain a specific decision, including you. | The FTC banned Rite Aid from facial recognition for five years. The FTC did not rule the output was wrong. It ruled that because Rite Aid never monitored or tested the system, they had no reasonable basis to believe any alert was accurate. |
| Security | You connected your accounts. | A tool you connected becomes somebody else's way in. | Attackers stole the access tokens of a chatbot that companies had connected to Salesforce, then walked past logins and two-factor at more than 700 organizations in ten days. None of the victims were hacked directly. They had all just clicked approve. |
| Conflict | One agent, one system. | Two agents fight over the same record. | Two Amazon repricing bots, each set to price against the other, drove a used textbook to $23,698,655.93. Neither rule was wrong on its own. Monday.com now publishes a support article on avoiding automations that overwrite each other. |
| Rollback | It made a change. | It made the wrong change, and there is no undo. | An AI agent deleted a live customer database during an explicit freeze, generated thousands of fake records that hid the damage, then reported the data was unrecoverable. That last part was wrong. If the owner had believed it, he would have concluded his data was gone. |
The sum most people don't finish
The best public case study of doing this yourself is a full year of it, written up by someone happy with the result. He replaced his automation subscription with a six dollar a month server across eight workflows.
He reports saving between $320 and $500 over twelve months. In the same write-up, he reports spending one to two hours a month maintaining it.
Saved over 12 months: $320 to $500
Own time spent: 12 to 24 hours
At $50/hour, that time is worth $600 to $1,200
He never does that multiplication, and almost nobody does. It happens after the interesting work is over, which is the part I am selling.
A cloud cost analysis firm, with nothing to sell you either way, found that on one major platform the same agent can cost eight dollars a month or eight hundred, depending purely on how it was built. A hundredfold difference on identical work comes down to how it was built.
This is not for everyone, and I would rather say so now.
There is a real version of your business where hiring me is the wrong call. If you are in the left column, use a template and keep your money.
Do it yourself
- Fewer than five people. The tooling overhead will outweigh the benefit, and this is a learning problem rather than a build problem.
- The workflow touches two apps you already own, with no custom authentication.
- No patient data, no payment credentials, no customer records at scale.
- When it breaks, the consequence is that something runs slower, not that money moves or data leaks.
- You have someone technical with genuine spare capacity who will own it after launch. The vendor's own foundations course is nine to fourteen hours. That is a real, achievable path.
Bring in help
- The work spans most of your software stack rather than a corner of it.
- You are in a regulated field, or you handle data that carries a legal obligation if it leaks.
- An error can move money, miss a deadline, or reach a customer before you see it.
- Nobody in the business has time to notice something broke, let alone fix it.
- You have already tried, and the honest result was a handful of automations nobody fully trusts.
Every build holds to GUARD.
Five commitments, no exceptions. They exist because the failure modes above are predictable, and each one is somebody else's incident report.
G
Governed
Every agent has an owner, a decision log, and a kill switch. Nothing runs that nobody is accountable for.
U
Unlocked
Your accounts, your data, your keys, scoped to the narrowest permission the task needs. Never a blanket approval.
A
Auditable
Every claim traces to a real source and every action is logged. When it does not know, it asks.
R
Reversible
Every build ships with a documented rollback that has been tested, not assumed. I test mine in the direction I would actually use it. A rollback nobody has ever pulled has not been tested.
D
Durable
Monitored from day one, so a failure reaches me before it reaches your customer.
About Rick Hancock

Rick founded RH Consulting to help owner-operators stop buying strategy decks and start shipping governed AI. He serves as a Fractional Chief AI Officer for leaders in healthcare, insurance, and professional services who need execution, not experimentation.
He builds production systems himself, keeps client data out of every public example, and trains his team on HIPAA boundaries before any client work begins. The system described on this page is the one running his own practice. He installs the same thing, scoped to the business, and stays on to run it.
Credentials & Compliance
HIPAA Training Credential
Individual Training CredentialRick Hancock completed HIPAA training covering PHI handling, privacy standards, and compliance best practices.
Valid through Jun 05, 2027Verification available
Two ways to work together.
Fixed fees, not hourly. You own everything that gets built, at every tier.
Start with the AI Direction Workshop.
Ninety minutes, and you leave with a 30-day plan and a scored list of what is worth automating. Some clients take that plan and run it themselves, which is a good outcome. If you would rather it were built, your workshop fee comes off the build. See the workshop.
Most common
Build
$12,000
base · 4 to 6 weeks · regulated environments from $18,000
Includes the first 6 months of the operating retainer.
- Five agents built and installed, chosen in the workshop
- Connected to the accounts and tools you already use
- Monitoring and rollback built in from the first agent, not added later
- Regulated builds cost more because they are more work: tighter governance on every agent, stricter data handling, and approval cycles that add real calendar time
- Your team trained to run it and extend it
Ongoing
Operating Retainer
$5,000
per month · month to month after the first six
20 hours per month, one initiative at a time, shipped to production.
- Monthly health and security review of every agent
- Model and integration changes handled before they break something
- New agents added as the business changes
- Direct access for troubleshooting, not a ticket queue
- Quarterly working session with me
On the monthly figure
You already pay something close to this every month to have someone keep your laptops patched, your network monitored, and your backups running. Nobody argues about that line item, because everyone understands what happens without it. This is the same arrangement for the AI systems now doing real work inside your business.
Why regulated work costs more
If you handle patient data, the build is genuinely a bigger job, and I would rather explain that than bury it. Every agent needs a tighter governance boundary. Data handling has to hold up to an audit rather than just work. And approvals take the time they take, which is calendar time nobody can compress. The premium is the extra work, priced honestly. It is not a surcharge for the word HIPAA.
The questions worth answering.
The oxygen mask goes on you first.
I built this because I was the bottleneck in my own practice and I wanted the time back for the people who actually need it.
If you want to find out what your business looks like when you are no longer the single point of failure in it, let's talk.
Rick Hancock
Fractional Chief AI Officer, RH Consulting
