AI Academy · Book
Executives & Directors · Module 09 · Chapter 001

Assessing Enterprise AI Readiness

"Are we AI-ready?" has no useful answer. Readiness only means something against a specific ambition: the capabilities that ambition needs, the evidence that you have them, and the one gap that will hold everything else back. A good assessment produces that gap and the order in which to close it, not a percentage.

≈ 16 min read

After this chapter you can

  • Define enterprise AI readiness as the ability to execute a specific AI ambition, not a general state.
  • Assess readiness across eight dimensions, each asked what the ambition needs and what evidence proves it.
  • Explain why readiness behaves like a chain, and why an average score hides the binding gap.
  • Record readiness as score, evidence, gap and action, and prioritize gaps by impact and dependency.
  • Distinguish the readiness bars for experiment, production and scale, avoiding both overbuilding and freezing.

In October 2025, Cisco published the third edition of its AI Readiness Index, a survey of 8,000 senior IT and business leaders in 30 markets. It classed about 13 percent of organizations as fully ready for AI, and that share had barely moved in the three years Cisco had been asking. The ready few were four times more likely than the rest to move pilots into production1.

About 13 percent of organizations were classed as fully ready for AI for three years running, and they were four times more likely to move pilots into production.13%Classed as fully readyAbout the same share for three years4xMore likely to reach productionReady firms versus the restSource: Cisco AI Readiness Index · Oct 2025
Figure 9.1.1 The ready share has barely moved in three years, and the ready firms are the ones whose pilots become production systems.

Treat the number with care. It is self-reported, and it comes from a company that sells the networks AI runs on. But the pattern it describes is one many executives will recognize: tools bought, pilots launched, enthusiasm high, and very little reaching the daily work of the business. The useful response is not to ask whether your organization sits in the top 13 percent. It is to ask a sharper question, one that a survey cannot answer for you.

Ready for what?

Enterprise AI readiness is the organization’s ability to turn a specific AI ambition into repeatable, governed and economically sustainable work. The key word is specific. Running a dozen controlled experiments, putting assistants in the hands of every analyst, and letting software agents settle supplier invoices are three different ambitions. They ask for different data, different engineering, different controls and different amounts of change in how people work. An organization can be ready for the first and nowhere near ready for the third. Both statements are true at once, and a single yes-or-no answer hides that.

Two sentences are often treated as if they meant the same thing: our IT department has AI tools and our enterprise is ready for AI. The first describes a purchase. The second describes a capability that stretches across strategy, data, people, controls and money. Even data readiness, the dimension that sounds most technical, turns out to depend on the use. Gartner defines AI-ready data as data aligned to specific use cases, and reported that 63 percent of organizations either lacked or were unsure they had the data management practices AI needs2. There is no such thing as data that is ready in general.

So the executive question changes. Do not ask whether you are AI-ready. Ask whether you are ready for the AI outcomes you intend to pursue, and which capabilities are missing.

The ambition sets the bar, and so does the law

How much AI should change the business is a strategic choice, and Defining AI Ambition in Module 04 showed how to set it and how to read it against readiness at a high level. This chapter takes the next step: once the ambition is set, it defines the bar every capability has to clear.

Ten controlled experiments need basic data and a small team; AI that screens job applicants is a high-risk use with legal duties of oversight and logging.AMBITION ATen controlled experiments inback-office workBasic data, a small team, a sandboxAMBITION BAI screens job applicantsacross EuropeHigh-risk use with legal dutiesvs
Figure 9.1.2 Illustrative: one company, two ambitions, two very different bars. The ambition decides what readiness has to mean.

Take an illustrative company weighing the two ambitions in the figure. A small experimental program can run on modest data, a handful of skilled people and a controlled environment. AI that helps decide who gets hired, or who gets credit, sits in a different world. In the European Union it is a high-risk use, and the organization deploying it carries legal duties that a sandbox experiment does not. Ambition B is not simply “more” of Ambition A. It needs capabilities that Ambition A never touches.

Eight dimensions, one question each

A practical assessment looks across a handful of dimensions. Lists vary: Cisco’s index uses six pillars, and many consultancies use more. The exact list matters less than covering the whole system, and asking each dimension the same question: what does this ambition need from you, and what is the evidence that you have it?

A table of eight readiness dimensions - strategy, leadership, data, technology, people, governance, operating model and economics - each with its question and the evidence that counts.DimensionThe question for this ambitionEvidence that countsStrategyWhere will value be created, and what will wenot do?Named outcomes with owners and targetsLeadershipWho sponsors it, funds it and removes blockers?A sponsor with budget and decision rightsDataCan authorized systems reach data fit for this use?Owners, access rights, quality checksTechnologyCan we integrate, secure and observe it?Working integration and monitoringPeopleDo users and managers know how and when to relyon it?Role-specific training, adoption dataGovernanceCan we classify, approve, monitor and stop it?A risk tier and an approval recordOperating model(ownership)Who owns, builds, approves, runs and measures it?Named roles across the life cycleEconomicsWhat will it cost at scale, and who holds the budget?Unit cost and a value baseline
Figure 9.1.3 Eight dimensions, each asked the same thing: what does this ambition need, and what proves we have it?

Three dimensions are easy to underweight. Leadership is not enthusiasm; it is a sponsor who funds the work, takes decisions and removes blockers, because AI that lives as an IT side project struggles to reach the core business. People does not mean turning everyone into an engineer. It means users and managers who understand what the system can and cannot do and when a person must check it. And the operating model, which is really a question of ownership, is a dimension that often surprises leadership teams: if you cannot say who owns an AI system, who builds it, who approves it, who runs it and who measures its value, you will struggle to run more than a few.

The questions are deliberately concrete. Is our data good? invites a shrug. Can the forecasting system reach three years of promotion history, with an owner who will fix it when it breaks? has an answer. For governance, a recognized reference such as the NIST AI Risk Management Framework, with its four functions of govern, map, measure and manage, gives the assessment a common vocabulary4.

Failed projects point to missing dimensions

The case for assessing all eight comes from the way AI projects actually fail. RAND researchers interviewed 65 experienced data scientists and engineers about why AI projects go wrong. Their report cites estimates that more than 80 percent of AI projects fail, about twice the rate of IT projects without AI, and it finds five root causes5. Gartner, explaining why it expected at least 30 percent of generative AI projects to be abandoned after the proof of concept, named four reasons: poor data quality, inadequate risk controls, escalating costs and unclear business value6. The two figures measure different things and should not be compared: RAND’s 80 percent is an estimate, cited from others, of AI projects of all kinds that fail; Gartner’s 30 percent is a forecast of generative AI projects dropped after the proof-of-concept stage.

Misunderstood problems, missing data, technology-first choices, weak infrastructure, weak risk controls and unclear value each map to a readiness dimension.Why projects failReadiness dimension it exposesThe problem was misunderstoodor miscommunicatedStrategy, leadershipThe organization lacked the dataDataTechnology chosen before theusers' problemStrategyInadequate infrastructure to deployand runTechnology, operating modelInadequate risk controlsGovernanceEscalating costs or unclearbusiness valueEconomics, strategy
Figure 9.1.4 In RAND’s and Gartner’s lists, most causes of AI failure are organizational. Each one is a readiness dimension nobody assessed.

Read the left column again and notice what is missing: the model. RAND does list one technical cause, problems too difficult for current AI, but most of the causes sit in strategy, data, infrastructure, controls and money. That is the practical argument for a readiness assessment. It is a way of finding these failures on paper, before they are found in production.

The dimensions are not independent checkboxes. They behave like a chain: the value of the whole depends on its weakest link. The economist Michael Kremer formalized this idea in 1993 and named it after the space shuttle Challenger, lost in 1986 because one small seal, an O-ring, failed. In his O-ring theory, production consists of many tasks that must all be done well; a mistake in any one of them can destroy most of the value of the rest7.

AI systems are O-ring systems. Consider an illustrative agent that resolves supplier invoice disputes on its own.

An invoice agent depends on data, system integration, controls and operational support; any one missing link stops it.DataInvoices,contracts,receiptsSystemsReads and writesthe ERPControlsAccess rights,payment limits,escalationSupportMonitoring,rollback, anamed ownerAny missing link stalls the whole agent
Figure 9.1.5 Illustrative: an agent needs every link at once. Strength in three cannot make up for absence in the fourth.

Excellent data and a strong platform do not help if nobody has defined what the agent may pay without approval. Mature governance does not help if the agent cannot read the contract system. This is why the limiting capability matters more than the overall picture, and why the most important output of an assessment is often a single sentence: this is the gap that holds everything else back.

Averages hide exactly that sentence. Suppose, as an illustration, that an assessment scores five dimensions for one ambition.

Four dimensions score 4 and governance scores 1; the average of 3.4 looks healthy while governance blocks the ambition.Technology4Data4People4Leadership4Governance1ILLUSTRATIVE NUMBERS
Figure 9.1.6 Illustrative scores: an average of 3.4 out of 5 reads as nearly ready. The single score of 1 is the one that decides the outcome.

The average is 3.4 out of 5, which a board slide would present as nearly ready. For an ambition in a high-risk use, the governance score of 1 means the organization cannot launch at all. Report the weakest link first, and the average, if at all, second.

Evidence, not false precision

Scores are useful only when they are consistent and backed by evidence. A figure such as 3.27 out of 5 suggests a precision that no readiness assessment has; the score is less important than the gap behind it. For each dimension, record four things: the current score, the evidence for it, the level this ambition requires, and the action that would close the gap. The record below is an illustration, for an ambition to forecast demand with AI.

An illustrative readiness record in which each dimension shows its current and required score, the evidence and the action that closes the gap.DimensionNowNeededEvidenceGap and actionData24Promotion plans held inpersonal spreadsheetsName an owner; build aweekly feedGovernance13No risk tier; noapproval routeClassify; agree anapproval pathEconomics33Baseline forecasterror measuredNone for now
Figure 9.1.7 Illustrative record. Score, evidence, gap, action. A score without evidence is opinion; a gap without an action is a complaint.

Data = 4 says nothing. Data = 4, because there is a catalog, every critical dataset has a named owner and quality is checked weekly can be challenged, checked and improved. The evidence column is what turns the assessment from a self-portrait into a management tool. It is also why the assessment should be done by a cross-functional team, covering business, technology, data, security, risk, finance and change leadership, rather than by the technology function alone. Each of them sees gaps the others will miss. Resist false precision, too. A readiness score quoted to two decimals, such as 3.27 out of 5, looks rigorous but rests on judgments that are not that exact; the evidence behind a whole-number score is worth more.

Not every gap deserves immediate money. Prioritize where the gap is large and the business importance is high, then weigh urgency, dependency, risk and effort. A gap that blocks five initiatives at once, such as missing data ownership in a shared domain, is usually worth more than a larger gap that blocks only one.

Different bars for experiment, production and scale

The bar also rises with the stage. What an experiment needs is not what a production system needs, and neither is what a portfolio of systems running across the enterprise needs.

Experiments need basic data and a small team; production needs reliable data, security and an owner; scale adds a shared platform, portfolio governance and change at scale.ScaleShared platform, portfolio governance, costmanagement, change at scaleMany systemsProductionReliable data, integration, security, anowner, monitoringOne system in daily useExperimentBasic data, a small team, acontrolled environmentLearningTHEBARRISES
Figure 9.1.8 Readiness is not one threshold. Clear the bar for the stage you are in, and prepare the one you are about to enter.

The gap between the bottom two tiers is where many initiatives stall. Gartner’s 2024 forecast of abandoned generative AI projects is a forecast about exactly this boundary6, and the readiness gap in Cisco’s survey shows up most clearly in who manages to cross it1. How to move a particular system across the boundary is the subject of From AI Pilot to Production to Scale, later in this module.

Two opposite mistakes follow from ignoring the tiers. The first is to build everything before starting: a full platform, a complete data program and an enterprise governance office before a single use case has proved its value. That delays learning and often builds the wrong foundation. The second is to scale a successful pilot as if production and scale had the same bar as the experiment, without security, operations or ownership. The discipline that avoids both is minimum required readiness: build what the current stage needs and what the next stage will need, and let readiness grow with the roadmap. For the same reason, reassess at each major stage of the roadmap, and whenever strategy, technology, regulation or risk changes materially, not as an annual ritual.

Story: ready for care, not for testing

In 2015 the Royal Free London NHS Foundation Trust, a London hospital trust, began working with DeepMind, Google’s AI company, on Streams, a mobile app that alerts clinicians when a patient shows signs of acute kidney injury8. The clinical aim was not what the regulator later questioned. When it ruled on the project, the Information Commissioner began by acknowledging the potential of creative uses of data for patient care9.

The difficulty lay in one dimension, at one stage. To test the app’s clinical safety, the trust gave DeepMind the records of about 1.6 million patients. The Information Commissioner’s Office opened an investigation in May 201610, and in July 2017 it ruled that the trust had failed to comply with the Data Protection Act 1998, the UK law then in force. Patients had not been adequately informed, and would not reasonably have expected their records to be used in this way. The ICO rejected the argument that the processing was direct care, which the trust had relied on for patients’ implied consent: testing a new system is a different purpose from treating a patient. The trust had not shown that 1.6 million records were necessary and proportionate for the test, and no privacy impact assessment had been done before the project began9.

Testing the Streams app needed a lawful basis for that purpose, only the data required, an impact assessment before data moved and informed patients; the regulator found each missing.What testing the app neededWhat the regulator foundA lawful basis forthis purposeTesting was not direct care, so implied consent did not cover itOnly the data thetest required1.6 million records not shown to be necessary and proportionateAn assessment beforedata movedNo privacy impact assessment before the project beganPatients who knewPatients not adequately informed
Figure 9.1.9 Every gap sat in one dimension, data governance, at one stage, testing. None needed new technology to find.

The ICO did not impose a fine. The trust signed an undertaking to establish a proper legal basis for the project and for future trials, set out how it would meet its duty of confidence to patients, complete a privacy impact assessment and commission an audit of the trial. It said publicly that it accepted the findings [@ico-royal-free-deepmind-2017; @techcrunch-royal-free-ico-2017]. The Commissioner’s own summary of the lessons was blunt: the shortcomings were avoidable, and trusts should not dive in too quickly8.

Read through this chapter, the case is a readiness question that was never asked in its specific form. Data that a hospital holds properly to treat patients is not, by that fact, ready to build and test software. What the project needed, before any data moved, was an answer to ready for what? asked of one dimension at one stage: may we use this data, in this volume, to test this system, and have we told the people it describes? A privacy impact assessment is the standard tool for producing that evidence, and its timing was the gap. No average across eight dimensions would have revealed it, because the weakness was one link, not a low overall score.

What this means for leaders

An honest readiness assessment changes the conversation in the leadership team. It replaces the mood question, are we ready?, with a set of specific ones: ready for which outcome, missing what, proven how, and fixed in what order. It also protects against both familiar failures: the enthusiastic launch of twenty initiatives on foundations that cannot carry them, and the cautious freeze that waits for the organization to become perfect. Readiness does not halt the portfolio. It sequences the investment.

Check yourself

  1. An organization with enterprise AI tools and a cloud platform is AI-ready.
  2. The same organization can be ready for AI experiments and not ready for AI agents in core operations.
  3. A high average readiness score means the organization can proceed.
  4. Most root causes of AI project failure identified by RAND are organizational rather than technical.
  5. The safest approach is to build every foundation before starting any AI work.
  6. Data an organization already holds lawfully is ready for any AI use of it.

Reflection: find your O-ring

What comes next

A readiness assessment answers whether the organization can pursue a particular ambition, and what it must close first. It does not say how far the organization has come overall, or what “better” looks like across the whole enterprise. Readiness asks whether we can pursue this ambition; maturity asks how systematically we operate AI today. The next chapter, The AI Maturity Model, provides that second view.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

EU Digital Omnibus on AI · EU

Regulation (EU) 2026/1744

First amendment to the AI Act. Defers high-risk obligations (Annex III to 2 Dec 2027, Annex I to 2 Aug 2028), adds two prohibited categories, softens the Art. 4 AI-literacy duty to "take measures to support", and simplifies some compliance duties. Art. 50 transparency duties still apply from 2 Aug 2026, with one transition (new Art. 111(4)): providers of generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) marking duty by 2 Dec 2026.

  • 2026-07-24 — Published in the Official Journal
  • 2026-07-27 — Entered into force
  • 2026-12-02 — Grace period ends for safeguards against two new prohibited uses (non-consensual intimate imagery, child sexual abuse material)
  • 2026-12-02 — Art. 50(2) marking duty applies to generative AI systems placed on the market before 2 Aug 2026 (Art. 111(4))

Last verified 2026-10-10 · official text

General Data Protection Regulation · EU

Regulation (EU) 2016/679

Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.

  • 2018-05-25 — Applies

Last verified 2026-10-08 · official text

References

  1. Cisco. Cisco AI Readiness Index 2025: Realizing the Value of AI. Cisco. 2025.
  2. Gartner. Lack of AI-Ready Data Puts AI Projects at Risk. Gartner press release, 26 February 2025. 2025.
  3. European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
  4. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
  5. James Ryseff, Brandon F. De Bruhl and Sydne J. Newberry. The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed: Avoiding the Anti-Patterns of AI. RAND Corporation, RR-A2680-1. 2024.
  6. Gartner. Gartner Predicts 30% of Generative AI Projects Will Be Abandoned After Proof of Concept By End of 2025. Gartner press release, 29 July 2024. 2024.
  7. Michael Kremer. The O-Ring Theory of Economic Development. Quarterly Journal of Economics 108(3), 551-575. 1993.
  8. Elizabeth Denham (Information Commissioner). Four lessons NHS Trusts can learn from the Royal Free case. ICO blog, 3 July 2017, as reported by PublicTechnology.net, 4 July 2017. 2017.
  9. Information Commissioner's Office (UK). Royal Free - Google DeepMind trial failed to comply with data protection law. ICO press release, 3 July 2017 (mirrored by Wired-Gov). 2017.
  10. TechCrunch. UK data regulator says DeepMind's initial deal with the NHS broke privacy law. TechCrunch, 3 July 2017. 2017.

Further reading

Sources last verified 2026-10-10.