- Of AI projects without AI-ready data predicted to be abandoned through 2026
- 60%Of AI projects without AI-ready data predicted to be abandoned through 2026
- Of organisations attribute any EBIT impact at all to AI, and most of those put it below 5%
- 39%Of organisations attribute any EBIT impact at all to AI, and most of those put it below 5%
- EU AI Act high-risk obligations apply, including data governance and logging
- 2 Dec 2027EU AI Act high-risk obligations apply, including data governance and logging
The model is rarely the problem
AI readiness is whether your information is in a state where a system can produce results you would actually act on. It is a property of the records and the rules around them, not of the model. The pattern is consistent:
The pilot works
Production meets the estate
The model gets the blame
Where you stand, in thirty questions
AI Readiness Pulse
How ready is your organisation for AI at scale?
Thirty questions across eight pillars: strategy, processes, information, technology, governance, people, scaling and value. About ten minutes. Your result appears at once, and nothing you answer leaves your browser.
- 30
- 8
- 5
- 10
Before you start
What it is costing you now
Two costs, and the second is larger. Not because it is bigger each time, but because it is paid again every time.
The visible one-time spending
The failed pilot: budget spent proving something that could not have worked on this estate. It is the one that gets written up, it is paid once, and it is the smaller of the two.
The recurring invisible one
The clean-up tax. Every project that touches the same estate rediscovers the same problems from scratch and pays to solve them from scratch, which is what makes it the larger figure: not more per occurrence, more occurrences. Nobody has measured how many that turns out to be, and we are not going to be the first to guess.
And underneath both
Storage and compute spent on data nobody has classified. The figure in circulation is around half of a typical estate being redundant, obsolete or trivial, and it comes from vendor surveys of what managers estimate about their own storage. We would rather tell you that than repeat it.
What is not in doubt is the mechanism. Unclassified content is backed up, indexed, searched, secured and paid for exactly like the content that matters, because no rule distinguishes them. That does not need a survey behind it.
A question passes four gates before the model is the variable.
Take one question you would want a system to answer. It stops at the first of these that fails, and where it stops is your readiness, for that question, today.
Completeness
Does the record exist, and is the current version identifiable as current?
Where it stops Four versions of the same contract in three places, and nothing that says which one is in force.
Governance
Is there a rule for what may be used, and is it applied rather than assumed?
Where it stops Retention and access were never written down, so nobody can say what the system is allowed to read.
Accessibility
Can a system reach the content without a person opening a file?
Where it stops The answer is in a scanned attachment on a shared drive: reachable by a colleague, and by nothing else.
Accountability
Afterwards, can you show what was used and on what basis?
Where it stops The output is defensible only as far as the trail behind it, and there is no trail.
Swiss and EU data sovereignty
Where a model runs is a contractual question at least as often as a technical one. Processing can be pinned inside Switzerland, or inside the EU, and the two are not the same commitment.
Where the data is processed
Pinned to Switzerland, or to the EU, per engagement. Switzerland is not an EU Member State, so those are two separate undertakings rather than one with two names, and which one you need is usually decided by your own customers rather than by you.
Where the model comes from
A second and independent question. A Swiss-hosted deployment of an American model is a legitimate arrangement and is not the same claim as a European model. We choose the origin per engagement to match what your clients will accept, and we say which is which.
Who enforces it
The routing, not a policy document and not somebody remembering on a Friday. Requests that would leave the agreed area do not leave it, and every action is logged, so the answer to "where did this run?" is a record rather than an assurance.
What you get
Four pieces of work, not four feelings. Each one names the work and where it connects to the rest of what the group runs.
A written answer before the budget, not after it
We take the records a proposed use case would actually consume and walk them through the four gates: how much is current, how much has a rule attached, how much a system can reach without a person, and whether use can be traced afterwards. A few hundred real documents is usually enough to know.
What comes back is a gap list with an order of work, not a score out of a hundred. A score is something to put in a steering pack. A gap list is something the next three months can be planned against, and it says which gate to fix first because fixing them out of order wastes the earlier work.
It costs a fraction of the pilot it either redirects or prevents, and that is the entire commercial case for doing it first.
The rules a system needs, written once for the whole estate
Classification, retention and access, defined and then actually applied: what a record is, how long it is kept, who and what may read it, and what happens when it should go. Until that exists, every question about what an AI system is permitted to consume is answered by whoever is in the room.
This is the same work the group does for contracts, personnel files and invoice archives, and it is deliberately not a second, AI-shaped copy of it. An organisation that has set retention and access rules for its records has already done most of what an AI deployment needs from it; what is usually missing is that the rules were never applied to the places the content actually sits.
It is also what turns shadow AI from a security incident waiting to happen into a governed one. You cannot police tools you have not defined boundaries for.
Content a system can reach, and a trail behind what it used
Reachable means a system gets to the content without a person opening a file: scanned material read, formats normalised, the record identified rather than the folder it happens to sit in. That is integration and document work, and it is the group’s standing capability rather than anything invented for this page.
The trail is the other half and it is usually forgotten until an auditor asks. Retrieval that returns the source document rather than a paraphrase, and a log of what was consulted and on what basis, is what makes an output defensible after the fact.
Those two together are what the EU AI Act asks of most enterprise deployments, which is why AI readiness and information governance keep turning out to be the same programme approached from two directions.
The same work pays for itself twice
Everything above, from classification and retention through disposal to reachable content, is exactly what reduces the storage, search and security cost of an estate nobody has sorted. Unclassified content is backed up, indexed, searched, secured and paid for identically to the content that matters, because no rule distinguishes them.
That means the readiness work has a business case that does not depend on any AI project succeeding. If the use case is dropped, the estate is still cheaper to run and easier to govern than it was. Very little of what gets sold as AI preparation can say that.
It is why we would rather assess than pitch. If the honest answer is that your gap is small and your use case is weak, that is cheaper to find out from us than from a pilot.
We walk one of your own questions through the four gates on your actual estate and give you a written answer on where the gap is. It is a short piece of work and it stops a large one being spent in the wrong place.
AI readiness, asked plainly
What is AI readiness?
AI readiness is whether your information is in a state where AI can produce results you would act on. It is a property of the data and the governance around it, not of the model. An organisation with a capable model and ungoverned records is not AI-ready; one with ordinary tooling and complete, current, traceable records usually is.
What are the pillars of AI readiness?
Four, and they behave as gates rather than as columns: a question stops at the first one that fails and never reaches the rest. Completeness, meaning the records exist and the current one is identifiable as current. Governance, meaning retention and access are defined and applied rather than assumed. Accessibility, meaning a system can reach the content without a person opening a document. And accountability, meaning you can evidence what was used and why, which is what an EU AI Act obligation actually asks of you.
How do you assess AI readiness?
By sampling the estate rather than surveying opinion about it. Take the records a proposed use case would actually consume, and check each pillar against them: how much is current, how much has a retention rule, how much is machine-reachable, and whether use can be traced. The result is a gap list with an order of work attached. Most organisations pass completeness and fail governance and accessibility.
Is my data ready for AI?
The honest test is smaller than it sounds. Pick one question you would want a system to answer, find the records that would answer it, and see how many of them a system could reach without a human. That number is your readiness for that use case, and it is usually what nobody has measured before the pilot is funded.
What does the EU AI Act require in practice?
For most enterprise uses, it requires you to know what the system does, on what basis, and to be able to show it. That is a records and governance obligation more than a technical one, which is why AI readiness and information governance are the same programme approached from two directions.