Only 8% of organizations globally maintain a comprehensive AI governance framework. Sixty percent are already deploying AI across multiple departments — but only 4% are governing it at scale. That gap between doing and governing is where budget gets wasted, data gets exposed, and boards start asking questions leaders can't answer with a number.
This is a four-dimension, scorable AI readiness checklist for business leaders — not another maturity-model diagram, an actual audit you can run this week and bring a score to your next leadership conversation. If you want the broader strategic context first, start with AI for business leaders: what actually matters in 2026; this post is the instrument, that one is the map.
TL;DR — the four dimensions, scored
| Dimension | The real question | Weak signal | Strong signal |
|---|---|---|---|
| 1. Data & Rights | Do you actually control what would feed an AI system? | Customer data, content, and IP rights scattered across vendor contracts nobody's re-read | Data inventory exists, usage rights are explicit, contracts checked for AI clauses |
| 2. Production | Can you build, customize, or evaluate AI — or are you 100% vendor-dependent? | No one in-house can sanity-check a vendor's benchmark claim | Small in-house capability to prototype, fine-tune, or rigorously evaluate |
| 3. Distribution | Do you own the customer relationship, or rent the shelf? | 100% dependent on a platform (marketplace, app store, aggregator) that could disintermediate you with an AI feature | Direct channel, owned data on your own customers, platform dependency is a minority of revenue |
| 4. Policy | Are AI rules written down, or improvised deal by deal? | Every AI tool request gets a one-off Slack decision from whoever's free | Written policy: approved tools, data classification, an actual approval workflow |
Score each dimension 0-3 below. Total out of 12.
Why a score beats a feeling
Ask ten executives if their company is "ready for AI" and you'll get ten different answers built on ten different mental models — one is thinking about ChatGPT usage among staff, another about a stalled pilot, another about a board deck from last quarter. None of them are comparable, and none of them survive a follow-up question like "ready compared to what?"
The numbers back up the vague-answer problem. McKinsey's 2026 research found that 88% of organizations regularly use AI in at least one business function and 72% report using generative AI — up from 33% in 2024. Adoption is not the bottleneck anymore. But 86% of leaders believe their own organization was not prepared to integrate AI into day-to-day operations, and fewer than 20% of organizations that attempted AI adoption have seen significant, tangible business impact. Two-thirds of enterprises have experimented with AI agents specifically — fewer than 10% have scaled them to deliver measurable value.
That's not an adoption gap. It's a readiness gap, and it's invisible until you measure it on purpose. A score forces the conversation past "are we behind" into "behind on what, specifically, and by how much" — which is the only version of that question a leadership team can actually act on.
Dimension 1: Data & Rights
The question: if you wanted to build or buy an AI system tomorrow, do you actually know what data and content you're legally and practically allowed to feed it?
This is the dimension most leaders skip because it feels like a legal problem, not a strategy problem. It isn't. Every AI initiative — a support copilot trained on ticket history, a marketing tool trained on your content archive, an internal search tool over your knowledge base — runs into the same wall eventually: do we actually own the right to use this data this way?
Checklist — Data & Rights
- We have an inventory of the data, content, and documents that would realistically feed an AI system (customer records, support transcripts, internal docs, proprietary content)
- We know which of that data has contractual, regulatory, or third-party restrictions on AI use (vendor contracts, licensing agreements, employee/contractor IP clauses)
- Customer-facing terms of service and privacy policy have been reviewed for whether they permit AI training or processing on customer data
- We've identified which data is sensitive enough that it should never leave an approved, vetted environment
- Someone with actual authority — not just "IT" by default — owns this inventory and updates it
Score: 0 = no inventory exists · 1 = informal awareness, nothing documented · 2 = partial inventory, gaps known · 3 = documented inventory, rights reviewed, an owner is accountable
Dimension 2: Production — in-house build capability
The question: when a vendor tells you their AI does X, can anyone on your team independently check that claim — or are you taking it entirely on faith?
This isn't about becoming an AI lab. It's about having enough in-house capability that "build vs. buy" is a real decision instead of a foregone conclusion, and that vendor claims get a sanity check before they become a line item. Leaders without this checkbox report the same failure mode repeatedly: a vendor's benchmark looked great, the pilot underperformed on real data, and nobody in the room could explain why until months in.
Checklist — Production
- At least one person can prototype or evaluate an AI tool against your own data, not just read the vendor's benchmark slide
- You have a standard eval process for new AI tools/vendors — same test set, same rubric, every time
- You know your actual cost structure for AI use (inference cost, token cost, fine-tuning cost) well enough to catch an inflated vendor quote
- There's a documented build-vs-buy decision process, not an assumption that buying is always faster
- Someone owns AI literacy for the leadership team itself, not just for frontline staff — see AI for business leaders for what that literacy actually needs to cover
Score: 0 = fully vendor-dependent, no internal capability · 1 = one person dabbles, no process · 2 = small team, informal eval process · 3 = real in-house capability, documented eval process, cost structure understood
Dimension 3: Distribution — do you own the channel?
The question: if an AI platform decided to disintermediate you tomorrow — answer your customers' questions directly, summarize your content without a click-through, recommend a competitor inside the same interface — how much of your business would that actually touch?
This dimension gets missed most often because it doesn't feel like an "AI decision" at all. But AI is actively reshaping which businesses sit between a customer and what they want. Publishers who rent 100% of their audience from a search engine or an aggregator are living this now; the same exposure exists for any business that doesn't own its customer relationship — marketplace sellers, SaaS companies distributed entirely through a single platform's app store, agencies whose entire pipeline runs through one referral partner.
Checklist — Distribution
- We know what percentage of revenue or customer relationships run through a channel we don't control
- We have a direct relationship (email list, owned app, direct contract) with our highest-value customers, independent of any platform
- We've modeled what happens to revenue if our largest distribution partner adds an AI feature that reduces our visibility or click-through
- We have at least one growing channel we fully own
- Leadership has actually discussed platform dependency risk in the last two quarters, not just at the last strategy offsite
Score: 0 = fully platform-dependent, never discussed · 1 = dependent, discussed once, no action · 2 = partial owned channel, actively growing it · 3 = owned channel is the majority of the relationship, platform risk is modeled and monitored
Dimension 4: Policy — written rules or improvisation?
The question: if an employee asked "can I paste this customer email into ChatGPT," is there an actual answer — or does it depend on who they ask?
This is the dimension the data backs up most starkly. Only 38% of US companies have published an AI policy. Just 8% of organizations globally maintain a comprehensive AI governance framework. And in a 2026 survey of creative professionals, 96% of organizations had formal AI usage restrictions in place — and 96% of employees at those same organizations admitted using unapproved AI tools anyway. A policy that exists on paper but isn't enforced, communicated, or realistic scores the same as no policy at all: staff route around it.
Separately, 78% of business executives in a 2026 Grant Thornton survey said they lack strong confidence they could pass an independent AI governance audit within 90 days — even though 90% of organizations have allocated funding for AI governance. Money isn't the blocker. A written, working policy is.
Checklist — Policy
- There's a written document (not tribal knowledge) listing which AI tools are approved for which data classifications
- New AI tool requests go through an actual approval step, not a Slack DM to whoever's online
- The policy has been communicated to staff in a way people can find later, not just announced once
- There's a process for what happens when someone breaks the policy — not punitive theater, an actual review
- The policy gets revisited on a schedule (quarterly is reasonable), not only after an incident
Score: 0 = no policy, fully improvised · 1 = informal norms, nothing written · 2 = written policy exists, enforcement is weak · 3 = written, communicated, enforced, and reviewed on a schedule
Your total score
| Score | Tier | What it means |
|---|---|---|
| 0-3 | Reactive | No plan. Every AI decision is a one-off. Highest exposure to data, legal, and platform risk. |
| 4-6 | Aware | Leadership knows the gaps but hasn't formalized a response. Common tier in 2026 — matches McKinsey's finding that 86% of leaders feel unprepared. |
| 7-9 | Operational | Written policy exists, some in-house capability, channel risk is at least modeled. Ahead of most peers. |
| 10-12 | Advanced | Formal governance, real build capability, owned distribution. Rare — most organizations are still deploying faster than they're governing. |
Most leadership teams land in Reactive or Aware — that tracks with the wider data: two-thirds of enterprises have experimented with AI agents but fewer than 10% have scaled them, and only 39% report any measurable EBIT impact from AI at all. A low score isn't an indictment. It's the first honest number most teams have had.
What people are asking
Is this the same as an "AI maturity model"?
No, and the difference matters. Most AI maturity models — including the ones vendors hand you before a sales call — score technical sophistication: how advanced your models are, how many pipelines you've shipped, how much of your stack is "AI-native." This checklist scores something more foundational: control and exposure. A technically unsophisticated company that owns its data, its distribution, and has a written policy scores well here even with zero custom models. A technically advanced company that's fully platform-dependent with no written rules scores poorly, correctly.
We're a small company — do we really need all four dimensions?
Yes, proportionally. A five-person startup doesn't need a compliance department, but it needs a one-page answer to "what data can go into what tool," a sense of whether it's renting 100% of its customers from one platform, and at least one person who can push back on a vendor's claims. The dimensions scale down in process weight, not in relevance — a small company with zero written AI rules is exposed the same way a large one is, just with a smaller blast radius.
What's the fastest dimension to fix?
Policy, almost always. Data & Rights and Production require real work — an inventory, a hire, a process. A written AI policy can be a genuinely useful one-pager drafted in an afternoon: which tools are approved, which data classifications can and can't go into them, who approves exceptions. It won't be perfect, but per the numbers above, any written policy outperforms the improvised default most organizations are running today.
How often should we re-score?
Quarterly is reasonable for most organizations — AI vendor landscape, tool approval lists, and platform dependency risk all shift faster than an annual review can track. Re-score after any material event too: a new vendor contract, a platform policy change from a distribution partner, or an incident that exposed a gap the checklist should have caught.
Building the capability, not just the score
A score tells you where the gaps are. Closing them is a literacy problem as much as a policy one — the leaders who score well on Production and Policy are usually the ones who've put real time into understanding AI agents, cost structure, and evaluation, not just delegated it. If that's the gap for your team, our live Claude for Work workshop is built for exactly this: managers, founders, and consultants who need working AI fluency, not another slide deck. Role-specific reading: AI for consultants and analysts, AI for HR professionals.
Honest limitations
- This checklist scores organizational exposure and control, not technical AI capability — a company can score well here and still ship mediocre AI products, or vice versa.
- Self-scored checklists are only as honest as the person filling them out — have more than one leader score independently and compare, don't let one optimistic self-assessment stand in for an audit.
- Regulatory requirements (EU AI Act, sector-specific rules) add obligations beyond this checklist depending on your industry and geography — this is a readiness instrument, not legal advice.
- The statistics cited are from 2026 surveys with different methodologies and sample sizes (McKinsey, Grant Thornton, Retool/Credo AI, industry governance reports) — directional evidence of a real gap, not a single unified study.
Closing
The gap in 2026 was never "are we behind on AI." It's "behind on what, exactly, and by how much" — and almost nobody can answer that with a number. Run this checklist with your leadership team this week, score independently, compare notes, and you'll have a sharper conversation than the one built on a feeling.
Follow @explainx_ai for more frameworks like this one.
Related on explainx.ai
- AI for business leaders: what actually matters in 2026
- AI for consultants and analysts
- AI for HR professionals
- AI for personal finance: budgeting and investing
- Claude for Work workshop — reserve a seat
- Top Claude live workshops in 2026
- How to learn AI: beginner to expert roadmap
- All workshops catalog
Sources
- Retool / Credo AI — State of AI Governance in 2026
- Grant Thornton — 2026 AI Impact Survey Report
- McKinsey — State of AI trust in 2026: shifting to the agentic era
- Digital Applied — Creative teams AI policy compliance gap 2026
Statistics cited are from 2026 industry surveys and are accurate as of August 12, 2026 — verify current figures against the linked primary sources before citing them in a board deck. This checklist is a self-assessment tool, not a substitute for legal, compliance, or security review specific to your industry and jurisdiction.
