Insights
Is my data ready for AI?
It depends on what you want AI to do with it. Using an off-the-shelf assistant to draft an email needs almost nothing from your data. The question changes once you ground AI in your own systems, so it answers from your contracts, your tickets and your numbers rather than the open internet. That is where data readiness starts to matter, and where most of the value for a business lives. Confuse the two and you will over-prepare for a trivial use, or under-prepare for a serious one.
Data is one dimension of wider AI readiness. This is a readiness check for the second case: the point at which you connect AI to your own data.
Ready for what?
There is no single bar for "AI-ready data." Each use sets its own.
A general assistant working from public knowledge needs no access to your data at all. A tool that summarises a document you paste in needs only that document. An assistant or agent that answers "what did we agree with this client on renewal terms" has to reach into your contracts, your CRM and your email, do it accurately, respect the right permissions, and not invent the parts it cannot find. That is a much higher bar, and it is the one worth planning for.
So start by naming the questions you want AI to answer, then check only the data those questions actually touch. Auditing your entire estate first is wasted motion.
The four things that actually matter
For grounding AI in your own systems, readiness comes down to four questions.
| Question | What you are checking | The failure it prevents |
|---|---|---|
| Access | Can the AI reach the data through a governed connection that respects each user's own permissions? | Data reaching people who should never see it |
| Quality | Is the data current, correct, and free of stale duplicates? | Confident answers built on wrong or out-of-date facts |
| Findability | Is it structured and labelled well enough to be retrieved, not buried? | The AI missing the right answer because it could not locate it |
| Governance | Do you know what is sensitive, and is that classification enforced? | Regulated or confidential data being surfaced without control |
Most organisations are stronger on quality than they fear, and weaker on access and governance than they hope. The gap on access is where the trouble usually starts.
The permissions trap
When connecting AI to internal data, the failure that catches most people is over-permissioned data meeting a tool that respects no boundaries. Bad data is rarely the culprit.
In most companies, far more people technically can open far more files than anyone intends. Years of broad shares, open folders, and "just give everyone read access" pile up quietly. That causes little harm while access depends on someone knowing a file exists. Point an AI assistant at the same store and it changes: ask the right question and the assistant will surface whatever it is allowed to reach, including the salary spreadsheet in the wrongly-shared folder.
You do not need to lock down the entire estate before you start. Connect AI through a governed layer that enforces each user's own permissions, and fix the worst oversharing on the data you are actually exposing first, rather than everywhere at once.
A pragmatic readiness check
You do not need a finished data lake, a governance programme, and a two-year cleanup before AI can return value. That counsel of perfection is how these efforts stall.
Start narrow. Take one high-value question, map the handful of systems it draws on, and check those four boxes for that slice only: access, quality, findability, governance. Fix what the slice needs, then ship it. Let the next use pull the next slice of data into shape. Readiness earned this way compounds, and it pays its way at each step rather than asking the business to fund a cleanup on faith.
Your data is readier than a big-bang project would suggest, and less ready than a careless connection assumes. The work is to connect the right slice, the right way, first.
Firestarter runs the data-and-technology readiness alongside your IT team: the questions named, the data behind them checked, and AI connected through a layer that respects each user's permissions.