Insights

How AI-ready is my organisation, really?

For chief operating officersVerified July 2026

Readier than a technologist would tell you on some dimensions, and far less ready on others. The gap between them is what actually determines whether AI works for you. "AI readiness" usually gets measured as a data-and-tools question, because that is the part technologists can see. Most AI efforts stall on the parts they can't: whether leaders can decide, whether people will adopt, whether the process was redesigned, whether the risk is governed. Readiness is uneven across those, and knowing where you are lopsided is more useful than a single score.

Readiness is more than technology

The failure mode is to grade yourself on infrastructure, the data and the tools, decide you are "80% ready," then watch adoption collapse on the human side. Or the reverse: a culture eager to use AI, blocked by data nobody can safely connect. Real readiness sits at the weakest of several dimensions, because AI value has to pass through all of them. A brilliant model on ungoverned data returns nothing, and so does a governed pilot no one adopts.

The five dimensions

Score yourself honestly on each, and pay most attention to your lowest.

Dimension What "ready" looks like The warning sign
Leadership & literacy Leaders can tell value from hype and model the behaviour AI is delegated wholesale, or blocked out of discomfort
People & change appetite Teams are curious and change is handled well Change fatigue; a graveyard of half-adopted tools
Data & technology The data behind priority uses is accessible and governed Over-permissioned stores; no one can safely connect AI to systems
Process Willingness to redesign work, not just bolt AI on "Automate what we already do" thinking
Governance Clear ownership, policy, and a handle on EU AI Act exposure AI risk owned by no one; no policy people follow

Most organisations are strong on two or three of these and quietly weak on the rest. The weak ones are where your first effort will fail if you ignore them.

The honest self-assessment

Run each dimension past a simple question: if you launched a serious AI use tomorrow, would this dimension help it or sink it? Leadership that cannot decide sinks it. A workforce braced against another tool sinks it. Data no one can safely connect sinks it. The dimensions where your honest answer is "sink it" are your real readiness level, not the ones where you are already strong.

The discipline is to resist grading yourself on your best dimension, and to plan around your worst.

Readiness is uneven, and that is fine

Being lopsided is normal and not a reason to wait. The assessment is meant to produce a map rather than a verdict of "ready" or "not ready": start where you are strong enough to succeed, and shore up the weak dimensions in parallel rather than treating the whole organisation as one undifferentiated "not yet." A firm strong on data but weak on change should pair its first use with real adoption support. One strong on culture but weak on governance should get an owner and a policy in place before it scales.

From assessment to action

The value of scoring yourself is that it turns "are you ready," a question with no useful answer, into "which dimension do you fix first," which has one. Take the lowest dimension, make it the condition on your first AI use, and let each use pull the next weak spot into shape. Readiness earned that way compounds, and it beats waiting for a readiness that never arrives all at once.

An honest read across all five dimensions, benchmarked against your peers and turned into a plan that starts where you are ready. That is where Firestarter's accelerator begins.

Sources and verification. This guide offers a general framework for assessing organisational AI readiness as of July 2026. It is a lens rather than a certification; weight the dimensions to your own context, and validate any governance or data conclusions against your specific obligations before acting on them.

  • Risk & security lead

    How is shadow AI affecting my company?

    Shadow AI, the use of unapproved AI tools by employees, has become one of the fastest-growing data-governance risks for mid-market firms. A risk manager's guide to detecting it and protecting the business.

    Read the guide

  • Risk & security lead

    Does AI train on my business data?

    Whether an AI provider trains on your business data depends almost entirely on which plan you buy. A risk manager's guide to the safe tiers across Anthropic, OpenAI, Google, and Microsoft.

    Read the guide

  • Risk & security lead

    Which AI is right for my company?

    A cost and risk comparison of AI from Anthropic, OpenAI, Google, and Microsoft for business: API and per-seat pricing, plus which fits a manufacturing, financial services, or software company.

    Read the guide

  • Risk & compliance lead

    Does the EU AI Act apply to my company?

    The EU AI Act reaches companies well beyond the EU, and several of its obligations are already live. A risk lead's guide to whether you are in scope, which tier your AI use falls into, and the deadlines that matter.

    Read the guide

  • Risk & compliance lead

    What does an AI policy need to say?

    A good AI policy fits on a page and gets followed. A risk lead's guide to the essentials: approved tools, the data line that matters most, disclosure, and accountability, without the forty pages nobody reads.

    Read the guide

  • Chief financial officer

    Why do AI pilots fail to pay back?

    Most AI pilots never reach production, and fewer still return value the board can see. A CFO's guide to why AI pilots stall short of payback, and the four things the ones that pay back do differently.

    Read the guide

  • Chief executive

    How do I build a board-ready business case for AI?

    A board funds a decision it can vote on. A chief executive's guide to the four things an AI business case must contain (value, cost, risk, and the ask) and how to size it so the board can act.

    Read the guide

  • Change & people lead

    Why do employees resist AI?

    AI adoption stalls on people rather than technology. A change lead's guide to the four real reasons employees resist AI, why training alone doesn't move them, and what actually changes behaviour.

    Read the guide

  • Chief executive

    How AI-literate does my leadership team need to be?

    Leaders need enough AI literacy to make good decisions, without learning to build. A chief executive's guide to what a leadership team actually has to understand, why it's now a legal duty too, and how to get there.

    Read the guide

  • Board & executive

    Who owns AI risk in a mid-market company?

    In most mid-market firms, AI risk falls between IT, legal, and the business, so it belongs to everyone and no one. An executive's guide to assigning ownership without hiring a Chief AI Officer.

    Read the guide

  • Chief financial officer

    What should AI cost my business in year one?

    The licence fee is the small part. A CFO's guide to the four real cost lines of AI in year one (tools, enablement, integration, and governance) and why the biggest one is the one most budgets forget.

    Read the guide

  • IT & data lead

    Is my data ready for AI?

    Whether your data is ready for AI depends entirely on what you ask AI to do with it. An IT lead's guide to the four things that actually matter, the permissions trap that catches everyone, and where to start.

    Read the guide

  • Operations lead

    What is an AI agent, and what should we automate first?

    An AI agent does more than answer: it takes actions across steps and systems. An operations lead's guide to what agents actually are, where they help and where they don't, and how to choose what to automate first.

    Read the guide

  • Technology lead

    Should we build or buy AI agents?

    For most mid-market companies, building AI agents from scratch is the wrong instinct. A technology lead's guide to the build-buy-configure spectrum, the hidden cost of building, and a pragmatic default.

    Read the guide