TL;DR
AI readiness in 2026 is governance-led, not technology-led. With EU AI Act high-risk obligations enforceable 2 August 2026, Article 4 AI literacy in force since 2 February 2025, ISO/IEC 42001 certifiable since late 2023, and Fed/OCC/FDIC SR 26-02 (April 2026) explicitly carving GenAI/agentic AI out of model risk management while still assigning organizations responsibility for governing them, a concrete four-dimension rubric with 0–5 maturity levels is essential. This guide provides scoring questions, red flags, disqualifiers, and a roadmap, cross-referenced to NIST AI RMF, ISO 42001, CSA AICM, OWASP Agentic Top 10, and the Gartner / MIT CISR / McKinsey / Deloitte / IBM / Microsoft / Capgemini / Forrester models.
1. The maturity scale
- L0 Absent — No capability or awareness; ad-hoc only.
- L1 Initial — Reactive; siloed pilots; tribal knowledge.
- L2 Repeatable — Documented but inconsistent; some standards; project-level.
- L3 Defined — Enterprise-wide policy; standard tooling; cross-functional.
- L4 Managed — KPIs, SLAs, audits; quantitatively managed; integrated risk.
- L5 Optimizing — Continuous improvement; benchmark setter; embedded in operating model.
Score each dimension 0–5; aggregate via weighted average. Default weights: Data 30%, Talent 20%, Governance 25%, Infrastructure 25% — adjust by industry (e.g., financial services boosts Governance to 35%).
2. Data readiness
Maturity
- L0: No catalog; PII unmapped; data silos; no embeddings.
- L1: Some critical-system catalogs; ad-hoc PII tagging.
- L2: Enterprise data catalog; data lineage for top-50 datasets; basic classification.
- L3: Data products with owners; lakehouse/fabric/mesh; automated PII detection; embeddings governed.
- L4: Data contracts with SLAs; near-real-time CDC; vector indices versioned; RTBF automated.
- L5: Self-serve data products; synthetic data programs; embedding lineage; continuous quality scoring.
Sample scoring questions
- % of business-critical datasets with documented owners and SLAs.
- PII detection automation: manual / spot-check / rule-based / ML-based / continuous.
- Architecture: silos / lakehouse / fabric / mesh / interoperable mesh.
- Real-time capability: batch only / micro-batch / CDC / streaming / event-driven enterprise.
- Vector readiness: none / pilot / governed embedding service / production index / multi-modal multi-model.
- RTBF SLA achievable today: cannot do / >30 days / 7–30 / 1–7 / hours.
- Data contracts between source systems and AI applications.
Red flags
- No PII inventory before deploying customer-facing AI.
- "Shadow" data lakes outside governance (data-layer analog of the McDonald's/Paradox.ai dormant-test-account pattern).
- Embeddings stored without source-document lineage.
- Cannot delete a customer's data within GDPR SLAs.
Quick wins
- Stand up a unified data catalog (DataHub OSS / Atlan / Collibra / Alation).
- Deploy automated PII detection (Microsoft Purview, BigID, Immuta, Securiti).
- Document the top-20 datasets feeding AI use cases with owners and freshness SLAs.
- Implement an embedding registry tied to source-document hashes.
3. Talent readiness
Maturity
- L0: No dedicated AI roles; ad-hoc external help.
- L1: A few data scientists; no platform engineers; no AI governance roles.
- L2: ML/AI engineers exist; SI partner relationship.
- L3: Defined CoE (or federated equivalent); AI governance, risk, ethics roles named; AI literacy training rolled out.
- L4: Red-team, model-risk, prompt/context-engineering as named disciplines; AI literacy measured.
- L5: Talent acts as a competitive moat; in-house research; published contributions.
Sample questions
- AI/ML engineering FTEs per 1,000 employees: <0.5 / 0.5–1 / 1–2 / 2–5 / >5.
- Domain-expert (SME) integration into AI projects: never / sometimes / standard / embedded / co-owners.
- AI governance/ethics/risk roles named with budget.
- AI literacy program (EU AI Act Article 4, in force 2 February 2025): none / informal / role-based mandatory / measured / continuous.
- Operating model: ad-hoc / CoE / federated / hybrid hub-and-spoke / product-led embedded.
Red flags
- Operating in or selling into the EU without an AI literacy program (Article 4 in force since 2 February 2025; enforcement powers begin 2 August 2026).
- "1 data scientist + 5 contractors" attempting production deployment.
- No designated red-teaming function before customer-facing AI.
- Reliance on a single SI for both build and assurance (separation-of-duties violation).
4. Governance readiness
Maturity
- L0: No AI policy; no inventory.
- L1: Draft AI policy; partial AI inventory.
- L2: Approved AI policy; AI register; ethics board chartered.
- L3: NIST AI RMF / ISO 42001 alignment; model risk management; vendor risk integrated; bias/fairness assessed.
- L4: ISO 42001 certified or in active certification; EU AI Act conformity assessment workflow; AIBOM in production; incident response drills.
- L5: Continuous AI risk attestation; transparency reports; STAR-for-AI or sectoral certification.
Sample questions
- AI inventory/catalog completeness (% of AI systems registered).
- Model risk management process alignment: none / informal / SR 11-7 era / SR 26-02 era (17 April 2026) / SR 26-02 + a documented agentic/GenAI overlay.
- ISO/IEC 42001 alignment: not aware / gap-assessed / aligned / pre-certification / certified.
- NIST AI RMF + GenAI Profile alignment by function (Govern/Map/Measure/Manage).
- EU AI Act readiness: risk classification done; deployer obligations met; Article 4 literacy in place; Article 14 human oversight implemented; conformity assessment + CE marking + EU database registration ready for 2 August 2026.
- AI incident response runbook tested: none / drafted / tabletop / live drill / integrated into SOC.
- AIBOM capability: none / manual model cards / structured AIBOM / continuous AIBOM / AIBOM integrated with SBOM.
Red flags
- AI deployed in production without inventory registration (Air Canada chatbot pattern).
- Banks above $30B in assets without an explicit governance overlay for GenAI/agentic AI excluded from SR 26-02.
- No incident-response plan for AI (a Replit-class destruction event would mean ad-hoc response).
- Vendor AI clauses not addressing data residency, training-data exclusion, indemnification.
Quick wins
- Build an AI inventory in 30 days (even spreadsheet) and assign owners.
- Adopt CSA AI Trustworthy Pledge → AICM self-assessment → STAR for AI roadmap.
- Map existing controls to NIST AI RMF Govern/Map/Measure/Manage.
- For EU: appoint an AI literacy owner; deploy role-based training using the European Commission's Living Repository.
Need a defensible AI readiness baseline?
We run the full four-dimension assessment in two weeks.
Implement Agentic delivers a fixed-fee Closed-Loop AI Readiness Assessment with stakeholder interviews, scored rubrics, ranked use-case backlog, ROI model, and a 0–36 month roadmap. See our AI Readiness Assessment service.
5. Infrastructure readiness
Maturity
- L0: No GPU access; no MLOps; no AI-specific networking.
- L1: Cloud GPU on-demand; some Jupyter notebooks; no model registry.
- L2: Hyperscaler relationship; CI/CD for ML; basic observability.
- L3: Multi-cloud or sovereign-cloud option; LLMOps platform; OpenTelemetry tracing; vector DB in production.
- L4: Agent identity and zero-trust segmentation; FinOps for AI; benchmarking; sustainability metrics; DR.
- L5: Edge inference, custom silicon, federated learning, sovereign-cloud + sovereign-model option.
Sample questions
- MLOps/LLMOps maturity (experiment tracking / model registry / CI/CD / online evaluation / automated rollback on quality regression).
- Observability stack depth (OpenTelemetry, OpenInference, traces, evals).
- Network/security: flat / segmented / zero trust / zero trust + microsegmentation for agents / agent-aware policy with continuous authorization.
- Agent identity & NHI program: none / static API keys / OAuth 2.1 + PKCE / MCP authorization + ephemeral tokens + central NHI inventory / agent-as-first-class identity with delegation chains and audit (cf. Okta MCP Bridge GA April 30, 2026; OWASP NHI Top 10).
- FinOps for AI: token tracking by use case / cost per outcome / chargeback by team / forecasting / FOCUS-aligned billing data.
- Sovereign cloud / data residency capability.
- DR / BCP for model endpoints and vector indices.
Red flags
- Long-lived static API keys to OpenAI/Anthropic shared across teams.
- Production agents with database write privileges and no IAM permission boundaries.
- No FinOps visibility into token spend (PTU and on-demand commingled).
- Shadow AI: developers using personal accounts to call frontier APIs.
- No segmentation between agents and sensitive systems (MCP servers reachable by any agent).
Quick wins
- Deploy an AI gateway (LiteLLM, Portkey, Helicone, Mosaic AI Gateway, AgentCore Gateway, Azure AI Foundry, Vertex AI Gateway).
- Stand up an LLM observability tool (Langfuse OSS or Galileo/Arize/Helicone managed).
- Enforce OAuth 2.1 + PKCE for MCP per Anthropic's authorization spec.
- Establish FinOps tagging on day 1 of any new use case.
6. How to use the assessment
Cadence
- Initial baseline: 6–8 week cross-functional assessment for first run.
- Periodic: annual full re-assessment; quarterly delta on Governance + Talent.
- Gate-based: lightweight version applied at each new AI use-case approval stage.
Scoring methodology
- Each question scored 1–5; computed dimension score = weighted average; overall readiness = weighted average across dimensions per industry profile.
- Disqualifiers (binary): cannot perform RTBF; no AI inventory; no Article 4 program (EU); SR 26-02 applicability without coverage; no incident response plan. A single disqualifier caps overall maturity at L2.
- Combine self-assessment with audit evidence — sample 5 AI systems and verify policy adherence.
Roadmap derivation
- 0–90 days: catalog, gateway, AI literacy, inventory, observability.
- 3–9 months: NIST AI RMF mapping, ISO 42001 gap assessment, AICM self-assessment via AI-CAIQ.
- 9–18 months: ISO 42001 certification, conformity assessment for high-risk EU systems, agent identity rollout, FinOps maturity.
- 18–36 months: continuous attestation, transparency reporting, selective sectoral certification (FedRAMP, FDA).
7. Common patterns by industry (April 2026 observed positioning)
- Banking (SIFIs): strongest in Governance; weakest in Talent. SR 26-02 gives strong MRM; agentic gap explicit.
- Insurance: strong Data; weak Infrastructure. NAIC AI Bulletin alignment.
- Pharma/Life sciences: strong Data + Governance; weak Infrastructure. FDA AI-DSF; clinical-trial provenance strong.
- Healthcare providers: strong Governance; weak Data + Infrastructure. HIPAA strong; data fragmentation chronic.
- Retail/CPG: strong Infrastructure; weak Governance. Hallucination risk in customer-facing.
- Manufacturing: strong OT Infrastructure; weak Data integration. OT/IT gap.
- Public sector / Defense: strong Governance + Sovereign infra; weak Talent. FedRAMP, DoD IL5/IL6.
- Tech / SaaS: strong Infrastructure + Talent; Governance maturation lagging speed.
- Energy & utilities: strong Infrastructure; weak Talent + Governance. NERC CIP overlap.
8. Comparison to existing frameworks
- NIST AI RMF + GenAI Profile — functions (Govern/Map/Measure/Manage), authoritative, voluntary, cross-sector. Not a maturity model per se; needs the CSA Agentic Profile for agents.
- ISO/IEC 42001 — PDCA management system; certifiable; aligned with EU AI Act. Doesn't score capabilities directly.
- Gartner AI Maturity Model — 5 stages; widely used; light on data/infrastructure specifics; misses agentic governance.
- Gartner AI TRiSM — 4 levels; strong on agent risk; narrow scope.
- McKinsey AIQ — composite; benchmarking; proprietary.
- Deloitte State of AI — survey-based; industry depth; not a self-assessment instrument.
- MIT Sloan / CISR — stages of data monetization; excellent data foundations; pre-GenAI.
- Microsoft AI Maturity Model — 4 stages; vendor-leaning.
- Capgemini AI Readiness, Forrester AI Maturity Model, IBM AI Maturity Framework.
This rubric's differentiation: explicit four-dimension structure, industry weights, disqualifiers, and 2025–2026 anchors (EU AI Act timeline, Article 4, SR 26-02, ISO 42001, AICM, NIST AI 600-1) plus 2025–2026 incident learnings (EchoLeak, Replit, Asana MCP, McDonald's, mcp-remote, Anthropic emergent misalignment) — see AI Agent Failure Modes.
9. Failure modes of the assessment itself
- Box-checking — scoring becomes the goal rather than improvement.
- Self-attestation without audit — combine with sampling.
- Stale baselines — re-baseline annually at minimum (Article 4, SR 26-02, AICM, OWASP Agentic Top 10 are all inside an 18-month window).
- Misweighted dimensions — a tech company over-weighting Infrastructure can pass while being uninsurable on Governance.
An AI readiness assessment scores four dimensions — data, talent, governance, and infrastructure — against the workflows you actually want to automate. The output is a concrete sequencing plan, not a maturity badge.
Workflows where this capability changes the unit economics of the process.
- Choosing the first 1–3 workflows to automate with agentic AI.
- Pre-budget diligence before signing a multi-year AI platform contract.
- Building the business case for a CFO or board AI investment review.
- M&A or vendor due diligence on AI-driven companies.
- You are considering more than $250K in AI investment in the next 12 months.
- You have multiple AI pilots and need to decide which to scale.
- Compliance, security, or audit needs a defensible baseline before agents ship.
- Leadership disagrees on whether the organization is 'ready' for agentic AI.
- You already have a clear, validated workflow and just need to build it.
- You are exploring a single low-risk proof-of-concept under $25K.
- AI Readiness AssessmentStructured 4-dimension scoring with a workflow sequencing plan.
- AI-Native Process ImplementationTranslate readiness findings into a redesigned, agentic process.
- Enterprise AI ImplementationEnd-to-end execution after readiness gaps are closed.
- AI Governance & LLM EvaluationClose the governance dimension before scaling.
Translate this into an AI-native business process
Apply this architecture to a real workflow. We map your highest-leverage business process to a closed-loop, governed agentic implementation plan.
Related reading
- AI Agent Failure Modes — the incident record that motivates the rubric.
- Enterprise AI Memory & Context Systems — the memory/context architecture you assess on the Data and Infrastructure dimensions.
- AI Governance for Agentic Systems.
- Enterprise LLM Evaluation Framework.
- FAQ: What is an AI readiness assessment?
- Services: AI Readiness Assessment · AI Governance & LLM Evaluation · Enterprise AI Implementation.
FAQs
What is an AI readiness assessment?
An AI readiness assessment is a scorable, four-dimension audit (Data, Talent, Governance, Infrastructure) using a uniform 0–5 maturity scale, with weighted scoring questions, red flags, and a roadmap. Default weights — Data 30%, Talent 20%, Governance 25%, Infrastructure 25% — are adjusted by industry (e.g., financial services boosts Governance to 35%).
Why is AI readiness now governance-led, not technology-led?
Because regulation has caught up. EU AI Act high-risk obligations are enforceable 2 August 2026, Article 4 AI literacy has been in force since 2 February 2025, ISO/IEC 42001 has been certifiable since late 2023, and the Fed/OCC/FDIC's SR 26-2 (April 2026) carves GenAI/agentic AI out of model risk management while assigning organizations responsibility for governing them anyway. Technology choice no longer determines whether you can deploy AI; governance posture does.
What are the maturity levels?
L0 Absent (no capability), L1 Initial (reactive, siloed pilots), L2 Repeatable (documented but inconsistent), L3 Defined (enterprise-wide policy and tooling), L4 Managed (KPIs, SLAs, audits, integrated risk), L5 Optimizing (continuous improvement, benchmark setter, embedded in operating model).
What are common disqualifiers that cap maturity at L2?
Inability to perform right-to-be-forgotten within GDPR SLAs; no AI inventory; no Article 4 AI literacy program for EU exposure; SR 26-02 applicability without an explicit governance overlay for GenAI/agentic AI; no AI incident response plan tested at minimum at tabletop level. A single disqualifier caps overall maturity at L2 regardless of other scores.
How does this rubric compare to NIST AI RMF, ISO 42001, Gartner, McKinsey, and others?
NIST AI RMF defines functions (Govern/Map/Measure/Manage) but is not a maturity model; ISO/IEC 42001 is a certifiable management system but doesn't score capabilities directly; Gartner's 5-stage AI Maturity Model is widely used but light on data/infrastructure specifics and misses agentic governance; McKinsey AIQ is proprietary; Microsoft, Capgemini, Forrester, IBM each have 4–5-stage models. This rubric's differentiation is the explicit four-dimension structure with weights, disqualifiers, and 2025–2026 regulatory anchors.
What is the recommended cadence?
Initial 6–8 week cross-functional baseline; annual full re-assessment; quarterly delta on Governance and Talent (which change fastest with regulation); a lightweight gate-based version applied at each new AI use-case approval — analogous to architecture review boards.
How does readiness map to safe use-case selection?
L0–L1: internal-only productivity copilots with low blast radius. L2: supervised customer-facing chat and structured RAG with no agent autonomy on transactions. L3: limited-autonomy agents with human-in-the-loop. L4: autonomous agents in production for medium-risk workflows; high-risk EU AI Act systems with conformity assessment. L5: mission-critical agentic workflows and cross-organization agent federations.
