Assessing Enterprise AI Readiness
"Are we AI-ready?" has no useful answer. Readiness only means something against a specific ambition: the capabilities that ambition needs, the evidence that you have them, and the one gap that will hold everything else back. A good assessment produces that gap and the order in which to close it, not a percentage.
After this chapter you can
- Define enterprise AI readiness as the ability to execute a specific AI ambition, not a general state.
- Assess readiness across eight dimensions, each asked what the ambition needs and what evidence proves it.
- Explain why readiness behaves like a chain, and why an average score hides the binding gap.
- Record readiness as score, evidence, gap and action, and prioritize gaps by impact and dependency.
- Distinguish the readiness bars for experiment, production and scale, avoiding both overbuilding and freezing.
In October 2025, Cisco published the third edition of its AI Readiness Index, a survey of 8,000 senior IT and business leaders in 30 markets. It classed about 13 percent of organizations as fully ready for AI, and that share had barely moved in the three years Cisco had been asking. The ready few were four times more likely than the rest to move pilots into production1.
Treat the number with care. It is self-reported, and it comes from a company that sells the networks AI runs on. But the pattern it describes is one many executives will recognize: tools bought, pilots launched, enthusiasm high, and very little reaching the daily work of the business. The useful response is not to ask whether your organization sits in the top 13 percent. It is to ask a sharper question, one that a survey cannot answer for you.
Ready for what?
Enterprise AI readiness is the organization’s ability to turn a specific AI ambition into repeatable, governed and economically sustainable work. The key word is specific. Running a dozen controlled experiments, putting assistants in the hands of every analyst, and letting software agents settle supplier invoices are three different ambitions. They ask for different data, different engineering, different controls and different amounts of change in how people work. An organization can be ready for the first and nowhere near ready for the third. Both statements are true at once, and a single yes-or-no answer hides that.
Two sentences are often treated as if they meant the same thing: our IT department has AI tools and our enterprise is ready for AI. The first describes a purchase. The second describes a capability that stretches across strategy, data, people, controls and money. Even data readiness, the dimension that sounds most technical, turns out to depend on the use. Gartner defines AI-ready data as data aligned to specific use cases, and reported that 63 percent of organizations either lacked or were unsure they had the data management practices AI needs2. There is no such thing as data that is ready in general.
So the executive question changes. Do not ask whether you are AI-ready. Ask whether you are ready for the AI outcomes you intend to pursue, and which capabilities are missing.
The ambition sets the bar, and so does the law
How much AI should change the business is a strategic choice, and Defining AI Ambition in Module 04 showed how to set it and how to read it against readiness at a high level. This chapter takes the next step: once the ambition is set, it defines the bar every capability has to clear.
Take an illustrative company weighing the two ambitions in the figure. A small experimental program can run on modest data, a handful of skilled people and a controlled environment. AI that helps decide who gets hired, or who gets credit, sits in a different world. In the European Union it is a high-risk use, and the organization deploying it carries legal duties that a sandbox experiment does not. Ambition B is not simply “more” of Ambition A. It needs capabilities that Ambition A never touches.
Eight dimensions, one question each
A practical assessment looks across a handful of dimensions. Lists vary: Cisco’s index uses six pillars, and many consultancies use more. The exact list matters less than covering the whole system, and asking each dimension the same question: what does this ambition need from you, and what is the evidence that you have it?
Three dimensions are easy to underweight. Leadership is not enthusiasm; it is a sponsor who funds the work, takes decisions and removes blockers, because AI that lives as an IT side project struggles to reach the core business. People does not mean turning everyone into an engineer. It means users and managers who understand what the system can and cannot do and when a person must check it. And the operating model, which is really a question of ownership, is a dimension that often surprises leadership teams: if you cannot say who owns an AI system, who builds it, who approves it, who runs it and who measures its value, you will struggle to run more than a few.
The questions are deliberately concrete. Is our data good? invites a shrug. Can the forecasting system reach three years of promotion history, with an owner who will fix it when it breaks? has an answer. For governance, a recognized reference such as the NIST AI Risk Management Framework, with its four functions of govern, map, measure and manage, gives the assessment a common vocabulary4.
Failed projects point to missing dimensions
The case for assessing all eight comes from the way AI projects actually fail. RAND researchers interviewed 65 experienced data scientists and engineers about why AI projects go wrong. Their report cites estimates that more than 80 percent of AI projects fail, about twice the rate of IT projects without AI, and it finds five root causes5. Gartner, explaining why it expected at least 30 percent of generative AI projects to be abandoned after the proof of concept, named four reasons: poor data quality, inadequate risk controls, escalating costs and unclear business value6. The two figures measure different things and should not be compared: RAND’s 80 percent is an estimate, cited from others, of AI projects of all kinds that fail; Gartner’s 30 percent is a forecast of generative AI projects dropped after the proof-of-concept stage.
Read the left column again and notice what is missing: the model. RAND does list one technical cause, problems too difficult for current AI, but most of the causes sit in strategy, data, infrastructure, controls and money. That is the practical argument for a readiness assessment. It is a way of finding these failures on paper, before they are found in production.
Readiness is a chain, not an average
The dimensions are not independent checkboxes. They behave like a chain: the value of the whole depends on its weakest link. The economist Michael Kremer formalized this idea in 1993 and named it after the space shuttle Challenger, lost in 1986 because one small seal, an O-ring, failed. In his O-ring theory, production consists of many tasks that must all be done well; a mistake in any one of them can destroy most of the value of the rest7.
AI systems are O-ring systems. Consider an illustrative agent that resolves supplier invoice disputes on its own.
Excellent data and a strong platform do not help if nobody has defined what the agent may pay without approval. Mature governance does not help if the agent cannot read the contract system. This is why the limiting capability matters more than the overall picture, and why the most important output of an assessment is often a single sentence: this is the gap that holds everything else back.
Averages hide exactly that sentence. Suppose, as an illustration, that an assessment scores five dimensions for one ambition.
The average is 3.4 out of 5, which a board slide would present as nearly ready. For an ambition in a high-risk use, the governance score of 1 means the organization cannot launch at all. Report the weakest link first, and the average, if at all, second.
Evidence, not false precision
Scores are useful only when they are consistent and backed by evidence. A figure such as 3.27 out of 5 suggests a precision that no readiness assessment has; the score is less important than the gap behind it. For each dimension, record four things: the current score, the evidence for it, the level this ambition requires, and the action that would close the gap. The record below is an illustration, for an ambition to forecast demand with AI.
Data = 4 says nothing. Data = 4, because there is a catalog, every critical dataset has a named owner and quality is checked weekly can be challenged, checked and improved. The evidence column is what turns the assessment from a self-portrait into a management tool. It is also why the assessment should be done by a cross-functional team, covering business, technology, data, security, risk, finance and change leadership, rather than by the technology function alone. Each of them sees gaps the others will miss. Resist false precision, too. A readiness score quoted to two decimals, such as 3.27 out of 5, looks rigorous but rests on judgments that are not that exact; the evidence behind a whole-number score is worth more.
Not every gap deserves immediate money. Prioritize where the gap is large and the business importance is high, then weigh urgency, dependency, risk and effort. A gap that blocks five initiatives at once, such as missing data ownership in a shared domain, is usually worth more than a larger gap that blocks only one.
Different bars for experiment, production and scale
The bar also rises with the stage. What an experiment needs is not what a production system needs, and neither is what a portfolio of systems running across the enterprise needs.
The gap between the bottom two tiers is where many initiatives stall. Gartner’s 2024 forecast of abandoned generative AI projects is a forecast about exactly this boundary6, and the readiness gap in Cisco’s survey shows up most clearly in who manages to cross it1. How to move a particular system across the boundary is the subject of From AI Pilot to Production to Scale, later in this module.
Two opposite mistakes follow from ignoring the tiers. The first is to build everything before starting: a full platform, a complete data program and an enterprise governance office before a single use case has proved its value. That delays learning and often builds the wrong foundation. The second is to scale a successful pilot as if production and scale had the same bar as the experiment, without security, operations or ownership. The discipline that avoids both is minimum required readiness: build what the current stage needs and what the next stage will need, and let readiness grow with the roadmap. For the same reason, reassess at each major stage of the roadmap, and whenever strategy, technology, regulation or risk changes materially, not as an annual ritual.
Story: ready for care, not for testing
In 2015 the Royal Free London NHS Foundation Trust, a London hospital trust, began working with DeepMind, Google’s AI company, on Streams, a mobile app that alerts clinicians when a patient shows signs of acute kidney injury8. The clinical aim was not what the regulator later questioned. When it ruled on the project, the Information Commissioner began by acknowledging the potential of creative uses of data for patient care9.
The difficulty lay in one dimension, at one stage. To test the app’s clinical safety, the trust gave DeepMind the records of about 1.6 million patients. The Information Commissioner’s Office opened an investigation in May 201610, and in July 2017 it ruled that the trust had failed to comply with the Data Protection Act 1998, the UK law then in force. Patients had not been adequately informed, and would not reasonably have expected their records to be used in this way. The ICO rejected the argument that the processing was direct care, which the trust had relied on for patients’ implied consent: testing a new system is a different purpose from treating a patient. The trust had not shown that 1.6 million records were necessary and proportionate for the test, and no privacy impact assessment had been done before the project began9.
The ICO did not impose a fine. The trust signed an undertaking to establish a proper legal basis for the project and for future trials, set out how it would meet its duty of confidence to patients, complete a privacy impact assessment and commission an audit of the trial. It said publicly that it accepted the findings [@ico-royal-free-deepmind-2017; @techcrunch-royal-free-ico-2017]. The Commissioner’s own summary of the lessons was blunt: the shortcomings were avoidable, and trusts should not dive in too quickly8.
Read through this chapter, the case is a readiness question that was never asked in its specific form. Data that a hospital holds properly to treat patients is not, by that fact, ready to build and test software. What the project needed, before any data moved, was an answer to ready for what? asked of one dimension at one stage: may we use this data, in this volume, to test this system, and have we told the people it describes? A privacy impact assessment is the standard tool for producing that evidence, and its timing was the gap. No average across eight dimensions would have revealed it, because the weakness was one link, not a low overall score.
What this means for leaders
An honest readiness assessment changes the conversation in the leadership team. It replaces the mood question, are we ready?, with a set of specific ones: ready for which outcome, missing what, proven how, and fixed in what order. It also protects against both familiar failures: the enthusiastic launch of twenty initiatives on foundations that cannot carry them, and the cautious freeze that waits for the organization to become perfect. Readiness does not halt the portfolio. It sequences the investment.
Check yourself
- An organization with enterprise AI tools and a cloud platform is AI-ready.
- The same organization can be ready for AI experiments and not ready for AI agents in core operations.
- A high average readiness score means the organization can proceed.
- Most root causes of AI project failure identified by RAND are organizational rather than technical.
- The safest approach is to build every foundation before starting any AI work.
- Data an organization already holds lawfully is ready for any AI use of it.
Reflection: find your O-ring
What comes next
A readiness assessment answers whether the organization can pursue a particular ambition, and what it must close first. It does not say how far the organization has come overall, or what “better” looks like across the whole enterprise. Readiness asks whether we can pursue this ambition; maturity asks how systematically we operate AI today. The next chapter, The AI Maturity Model, provides that second view.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
EU Digital Omnibus on AI · EU
Regulation (EU) 2026/1744
First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.
- 2026-07-24 — Published in the Official Journal
- 2026-07-27 — Entered into force
- 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
- 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))
Last verified 2026-10-10 · official text
General Data Protection Regulation · EU
Regulation (EU) 2016/679
Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.
- 2018-05-25 — Applies
Last verified 2026-10-08 · official text
References
- Cisco. Cisco AI Readiness Index 2025: Realizing the Value of AI. Cisco. 2025.
- Gartner. Lack of AI-Ready Data Puts AI Projects at Risk. Gartner press release, 26 February 2025. 2025.
- European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
- James Ryseff, Brandon F. De Bruhl and Sydne J. Newberry. The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed: Avoiding the Anti-Patterns of AI. RAND Corporation, RR-A2680-1. 2024.
- Gartner. Gartner Predicts 30% of Generative AI Projects Will Be Abandoned After Proof of Concept By End of 2025. Gartner press release, 29 July 2024. 2024.
- Michael Kremer. The O-Ring Theory of Economic Development. Quarterly Journal of Economics 108(3), 551-575. 1993.
- Elizabeth Denham (Information Commissioner). Four lessons NHS Trusts can learn from the Royal Free case. ICO blog, 3 July 2017, as reported by PublicTechnology.net, 4 July 2017. 2017.
- Information Commissioner's Office (UK). Royal Free - Google DeepMind trial failed to comply with data protection law. ICO press release, 3 July 2017 (mirrored by Wired-Gov). 2017.
- TechCrunch. UK data regulator says DeepMind's initial deal with the NHS broke privacy law. TechCrunch, 3 July 2017. 2017.
Further reading
- James Ryseff, Brandon F. De Bruhl and Sydne J. Newberry. The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed: Avoiding the Anti-Patterns of AI. RAND Corporation, RR-A2680-1. 2024.
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
Sources last verified 2026-10-10.