AskAjay.ai

Reference

10 min read · ·

Your AI Readiness Equals Your Weakest Pillar

Five scored pillars: strategy, data, talent, process and governance. Your readiness is the lowest of the five scores, because an average lets four strong pillars hide a weak one.

Ajay Pundhir
Ajay PundhirAI Strategist & Speaker
Share
Five carets climb from lower left to upper right on a cream ground. The second from the left, low on the climb, is drawn large in deep blue with a gold caret nested inside it. The other four are thin and grey.
Art: AskAjay.ai house pattern, 'Caret Ascent' variant

Key Takeaways

  • →The assessment scores five pillars from 1 to 5: strategic alignment, data infrastructure, talent and culture, operational processes, and ethics and governance.
  • →Overall readiness is the lowest pillar score. An organisation that scores 5, 4, 4, 4 and 2 averages 3.8 and is at Level 2.
  • →Every pillar has a calibration check that tests the self-assessment against evidence. Three of the five cap the pillar at 2 when the evidence is missing.
  • →Gartner's survey of 644 respondents found that on average only 48% of AI projects make it into production, and that the move from prototype to production takes 8 months.
  • →Fix the weakest pillar first. A 90-day cycle spends weeks 1 to 6 on that one pillar and rescores all five in weeks 11 and 12.

AI readiness is the lowest of five scores: strategic alignment, data infrastructure, talent and culture, operational processes, and ethics and governance. Budget, a data science team and a vendor shortlist feel like readiness. They are inputs. Readiness is whether the organisation can put an AI system into daily work and keep it there, and the weakest of the five decides that.

Updated 4 October 2026. Rebuilt as a reference. The pillars and calibration checks are unchanged in substance. Figures that could not be traced to a source were removed. The changes are listed at the end.

What Is the Five-Pillar AI Readiness Assessment?

The Five-Pillar AI Readiness Assessment is a scored diagnostic of whether an organisation can take AI into production. It rates five pillars from 1 to 5 and sets overall readiness at the lowest of the five scores.

Each pillar has assessment questions, which record what the organisation believes about itself, and a calibration check, which asks for evidence and lowers the score when there is none.

The five pillars

Each is scored from 1 to 5. The lowest score is the overall score.

PillarThe question it answersCalibration check
1. Strategic alignment

Is AI tied to business results, or is it a technology programme looking for a problem?

Fewer than two of the last three funded initiatives have a documented metric, target and date: no higher than 2.

2. Data infrastructure

Can the data feed an AI system at the speed and quality it needs?

A new dataset takes more than two weeks to provision and clean: no higher than 2.

3. Talent and culture

Are the right people in place, and will the organisation use what they build?

Data scientists spend more than 60% of their time preparing data: lower the score for the data engineering gap.

4. Operational processes

Can workflows, decisions and change management absorb an AI system?

The last major technology change took more than six months to reach 80% of its users: lower the score to match.

5. Ethics and governance

Does governance shape real decisions, or does it live in a policy document?

Fewer than two of three engineers on the AI team can name the governance framework: no higher than 2.

The pillars cover familiar ground. The 1-to-5 scale follows CMMI maturity levels 1 to 5, from Initial to Optimizing. Two rules do the work here: the floor rule and the calibration checks.

Why Does the Weakest Pillar Set the Score?

Because an AI system fails at its weakest point. A model with clean data and a clear business case still stalls if nobody has redesigned the work around it. It is also exposed if nobody has the authority to stop it when it goes wrong. An average lets four strong pillars hide the fifth.

Take the organisation in the chart. Its scores average 3.8, which reads as nearly ready. The floor rule puts it at Level 2, and it names governance as the pillar to fix this quarter.

The distance between investing in AI and running it is wide. In a survey of 644 respondents from organisations in the US, Germany and the UK, run in the fourth quarter of 2023, Gartner found that "only 48% of AI projects make it into production" on average, and that the move from prototype to production takes 8 months.

McKinsey's 2026 State of AI survey points the same way. AI high performers, the 6% of respondents who attribute at least 5% of EBIT to AI and call its value significant, stand apart by how they deploy it. McKinsey writes that their advantage "cannot be reduced to budget". Nearly three-quarters of them report fundamentally redesigning workflows because of their AI use. Among other respondents the share is one-quarter. Redesigning the work is the subject of Pillar 4.

How Do You Score Each Pillar?

Score each pillar from 1 to 5 against the maturity levels in the next section. Answer the questions first, then run the calibration check. Where the two disagree, the check wins.

Pillar 1: Strategic alignment

This is where AI programmes fade without anyone noticing. A familiar pattern: the sponsor describes the strategy as using AI "across customer touchpoints", and nobody can say which touchpoints, which outcomes, or how success will be measured. That is an ambition; a strategy would name the touchpoints and the result. Why pilots stall before production traces where this leads.

  • Can you name three specific business outcomes (revenue, cost, risk or customer experience) that each AI initiative is meant to deliver, with measurable targets?
  • Does an executive sponsor carry the result in their own P&L?
  • Are initiatives ranked by business impact, or by which team has the loudest champion?
  • Can the organisation say what it will not use AI for, and why?

Calibration check. Pull up the last three AI initiatives the organisation funded. For each one, find the document that ties it to a business metric with a target number and a date. If fewer than two of the three have one, the pillar scores no higher than 2.

Pillar 2: Data infrastructure

Having a lot of data is different from having data an AI system can use. Organisations with decades of systems, departments and acquisitions often hold their data in silos with no shared schema. A new data platform does not fix that. Governance, quality measurement and pipeline engineering do. Only Seven Percent Say Their Data Is Completely Ready for AI covers that groundwork.

  • Can a data scientist get the data for a new use case within a week, without filing tickets with three teams?
  • Is data quality measured (completeness, accuracy, freshness, consistency), with a fix process when it drops?
  • Can the infrastructure handle model training and real-time inference, or does it all run on the systems behind the dashboards?
  • Are pipelines automated and monitored, or manual and liable to break silently?

Calibration check. Ask the data science team, rather than IT leadership, how long it takes to get a new dataset provisioned, cleaned and ready for model work. If the honest answer is more than two weeks, the pillar scores no higher than 2.

Pillar 3: Talent and culture

Most organisations frame the talent question as hiring data scientists. In my work, the role most often missing is the translator: someone who understands the business problem and the technical options well enough to explain each side to the other, and to carry a model's output into the workflow of the person who makes the decision. Data engineers come next. Without pipelines, data scientists spend their days preparing data.

Culture takes longer to build than talent takes to hire. Five behaviours show where it stands:

  • Tolerance for experiments. When the last pilot disappointed, was the team asked to iterate or told to stop?
  • Shared work. Do data and business teams build AI initiatives together, or swap requirement documents?
  • Leaders who use it. Do executives use AI-generated analysis in their own decisions?
  • Data sharing. Will departments share data across their boundaries?
  • Curiosity against fear. When AI comes up, is the first question what it could do, or whose job it takes?

Calibration check. Ask the data scientists what share of their time goes to preparing data rather than building models and analysing results. Above 60%, lower the pillar score. The gap is data engineering capacity, and more data scientists will not close it.

Pillar 4: Operational processes

This pillar catches organisations that have done everything else right. The model works, the data is sound, the case is clear, and then the people who are meant to use its output don't trust it, because nobody involved them, explained it, or changed their workflow to make room for it.

  • Decision design. For each use case, is it explicit whether AI informs a human decision, decides under human oversight, or acts alone?
  • Change management. Is there a plan to help people understand, trust and work with the system, or only a technical rollout plan?
  • Monitoring. Once a model is live, who watches it for drift in accuracy and fairness? Is that a named owner?
  • Incidents. When the system produces a wrong or harmful output, is there a written escalation path?

Calibration check. Find the last significant technology change the organisation absorbed, meaning its users changed how they work, as opposed to the day it was switched on. How long did it take for 80% of the intended users to work the new way? If it took more than six months, score this pillar to match that record.

Pillar 5: Ethics and governance

For organisations within reach of the EU AI Act, governance is now partly a legal duty. Under the Act, the original prohibited-practice rules have applied since 2 February 2025, the two prohibitions the Digital Omnibus added apply from 2 December 2026, and the obligations for high-risk systems listed in Annex III apply from 2 December 2027 after the Omnibus moved them. In the US, the NIST AI Risk Management Framework, released in January 2023, is intended for voluntary use. The EU AI Act guide sets out the dates in full.

A policy document by itself does not score. I have seen AI principles that never touched a development decision, because the engineers had not read them.

  • Review by risk tier. Do a product recommender and an automated lending decision get different levels of scrutiny?
  • Bias testing in the pipeline. Is fairness testing part of development and deployment, or a one-off check before launch?
  • Authority to stop. When someone raises a concern, can a named person stop or change the deployment?
  • Regulatory watch. Does someone track AI rules in each market you operate in and turn them into requirements before they apply?

Calibration check. Ask three engineers on the AI team to name the organisation's AI principles or governance framework. If fewer than two can, the pillar scores no higher than 2, whatever the policy documents say. The Governance Playbook shows how to turn principles into processes people follow.

What Do the Five Maturity Levels Mean?

  • Level 1, Ad hoc. No formal approach. Ask five people how AI decisions are made and you get five answers.
  • Level 2, Emerging. Work has started and some of it is written down, but teams apply it unevenly.
  • Level 3, Defined. Processes are documented and most teams follow them. Governance has real authority. Reach this level on every pillar before deploying AI at scale.
  • Level 4, Managed. Results are measured and the process is tuned against them. AI is part of the planning cycle.
  • Level 5, Optimized. Improvement is continuous and built into how the organisation works. Few organisations need to be here.

Why Do Self-Assessments Score Too High?

Everyone rounds up. Leaders fill in readiness surveys generously, conclude they are at Level 3, and deploy. In my experience, a first self-assessment almost always scores higher than the same organisation scores once the calibration checks are run. Three habits close the gap:

  1. Evidence for every score above 2. Point to a document or system that exists today. A plan to build data governance scores 1.
  2. Score across functions. The CTO does not score data alone, and HR does not score talent alone. Put someone who will challenge a generous answer in the room.
  3. The new-hire test. Picture a senior hire who takes over the AI programme next week. Score what they would find in their first two weeks, setting aside what they were told at interview.

The gap between the first score and the calibrated score is worth recording. It shows how much optimism to allow for when the organisation plans its AI timelines.

What Happens After You Score?

The scores are the input. The output is a plan that works on the weakest pillar first. A 90-day cycle:

  1. Weeks 1 and 2: name the constraint. The lowest pillar is the constraint. Other improvements wait until it reaches at least Level 2.
  2. Weeks 3 to 6: fix one thing. Inside that pillar, pick the single change that moves it most. Give it an owner and a weekly check.
  3. Weeks 7 to 10: start on the next pillar. Keep the first fix moving and begin on the next-lowest pillar.
  4. Weeks 11 and 12: rescore. Score all five pillars again, with the same checks. Set the targets for the next cycle.

For the weekly check in weeks 3 to 6, Agentic AI Transformation Is Not a Program sets out one practice per weakest pillar and explains how to watch the agents already running before the plan starts.

Aim to lift each pillar one full level within a year, and rescore every quarter. Capabilities change, and so do the rules. For Pillar 5, Minimum Viable Governance is a 90-day route to a working baseline.

The five pillars are the model the AI Readiness Canvas scores, with the same floor rule, from fifteen questions.

Subscriber Resource

Download: 5-Pillar AI Readiness Assessment Worksheet

Get the structured worksheet with all scoring sheets, calibration checks, maturity scale reference, and 90-day sprint planner, ready to print or save as PDF.

Enter your email to get instant access. You'll also receive the fortnightly newsletter.

Free. No spam. Unsubscribe anytime.

When Is This the Wrong Tool?

When the question is about one initiative. The assessment scores the organisation. To judge whether a single use case deserves funding, use the AI Use Case Blueprint. For AI agents that act on their own, the A7 framework applies a similar floor rule across seven dimensions of agentic readiness.

Before the next AI budget decision, ask: Which pillar is our lowest, scored with the calibration check? Who owns fixing it this quarter? What evidence would move it up one level?

Sources and Changes

All sources read on 4 October 2026.

Changes on 4 October 2026. The headline, summary and structure are new, and the piece is shorter. Two charts drawn from advisory work were removed because their figures could not be traced to a dataset. The client scenes and the figures that came with them were removed for the same reason: the $12 million budget, the seventeen systems, the eight-month delay, the 1.2-point gap between self-assessed and calibrated scores, and the 6 to 12 months added to timelines. The patterns they described remain, stated as patterns. The 2023 McKinsey economic projection and a Gartner link that did not support its claim were replaced by the Gartner survey above. The McKinsey figures now come from the 2026 survey. The EU AI Act passage now gives the dates set after the Digital Omnibus. A panel titled "five AI roles" that listed four was removed. The pillars, calibration checks and questions are unchanged in substance.

Questions readers ask

What is the difference between AI readiness and AI maturity?

Maturity describes how developed a capability is, on a scale such as the five levels used here. Readiness is a narrower question: can the organisation take its next AI system into production and keep it running? This assessment answers the readiness question with maturity scores. It scores each pillar on the maturity scale, then sets readiness at the lowest of the five, because one immature pillar is enough to stop a deployment.

Can a startup or small company use the five-pillar assessment?

Yes. With fewer systems and fewer people, the calibration checks are quicker to run. In a young company, look first at governance, the pillar most likely to have no owner yet. The Founder's Playbook for Responsible AI covers that stage, and Minimum Viable Governance sets out the smallest governance that still works.


Ajay Pundhir
Ajay Pundhir

Senior AI strategist helping leaders make AI real across four continents. Forbes Technology Council member, IEEE Senior Member.

Let's Talk

Ajay's views, from 15 years in the field. Not legal or compliance advice. See full disclaimers →
Published by AI Exponent LLC

Your AI Readiness Equals Your Weakest Pillar | AskAjay.ai