Insights

Is my data ready for AI?

For it & data leadsVerified July 2026

It depends on what you want AI to do with it. Using an off-the-shelf assistant to draft an email needs almost nothing from your data. Grounding AI in your own systems — so it answers from your contracts, your tickets, your numbers rather than the open internet — is where data readiness starts to matter, and where most of the value for a business lives. Confuse the two and you will either over-prepare for a trivial use or under-prepare for a serious one.

This is a readiness check for the second case: the point at which you connect AI to your own data.

Ready for what?

There is no single bar for "AI-ready data." There is a bar for each use.

A general assistant working from public knowledge needs no access to your data at all. A tool that summarises a document you paste in needs only that document. But an assistant that answers "what did we agree with this client on renewal terms" has to reach into your contracts, your CRM, and your email — accurately, with the right permissions, and without inventing the parts it cannot find. That is a materially higher bar, and it is the one worth planning for.

So the first move is not to audit all your data. It is to name the questions you want AI to answer, then check only the data those questions actually touch.

The four things that actually matter

For grounding AI in your own systems, readiness comes down to four questions.

Question What you are checking The failure it prevents
Access Can the AI reach the data through a governed connection that respects each user's own permissions? Data reaching people who should never see it
Quality Is the data current, correct, and free of stale duplicates? Confident answers built on wrong or out-of-date facts
Findability Is it structured and labelled well enough to be retrieved, not buried? The AI missing the right answer because it could not locate it
Governance Do you know what is sensitive, and is that classification enforced? Regulated or confidential data being surfaced without control

Most organisations are stronger on quality than they fear and weaker on access and governance than they hope. Which brings us to the trap.

The permissions trap

The single most common failure when connecting AI to internal data is not bad data. It is over-permissioned data meeting a tool that respects no boundaries.

In most companies, far more people technically can open far more files than anyone intends — years of broad shares, open folders, and "just give everyone read access" have piled up quietly. It causes little harm while access depends on someone knowing a file exists. Point an AI assistant at the same store and that changes: ask it the right question and it will happily surface whatever it is allowed to reach, including the salary spreadsheet in the wrongly-shared folder.

The fix is not to lock down the entire estate before you start. It is to connect AI through a governed layer that enforces each user's own permissions, and to fix the worst oversharing on the data you are actually exposing first, rather than everywhere at once.

A pragmatic readiness check

You do not need a finished data lake, a governance programme, and a two-year cleanup before AI can return value. That counsel of perfection is how these efforts stall.

Start narrow. Take one high-value question, map the handful of systems it draws on, and check those four boxes — access, quality, findability, governance — for that slice only. Fix what the slice needs. Ship it. Then let the next use pull the next slice of data into shape. Readiness earned this way compounds, and it pays its way at each step rather than asking the business to fund a cleanup on faith.

The honest headline: your data is readier than a big-bang project would suggest, and less ready than a careless connection assumes. The work is to connect the right slice, the right way, first.

Naming the questions worth answering, checking the data behind them, and connecting AI through a governed layer that respects your permissions is the data-and-technology readiness Firestarter runs in its six-week accelerator — with your IT team, not around it.

Sources and verification. This guide describes general patterns in preparing organisational data for AI grounding and retrieval as understood in July 2026. The specific controls you need depend on your systems and obligations; validate any approach against your own security, data-protection, and vendor requirements before you connect a live system.

  • Risk & security lead

    How is shadow AI affecting my company?

    Shadow AI, the use of unapproved AI tools by employees, has become one of the fastest-growing data-governance risks for mid-market firms. A risk manager's guide to detecting it and protecting the business.

    Read the guide

  • Risk & security lead

    Does AI train on my business data?

    Whether an AI provider trains on your business data depends almost entirely on which plan you buy. A risk manager's guide to the safe tiers across Anthropic, OpenAI, Google, and Microsoft.

    Read the guide

  • Risk & security lead

    Which AI is right for my company?

    A cost and risk comparison of AI from Anthropic, OpenAI, Google, and Microsoft for business: API and per-seat pricing, plus which fits a manufacturing, financial services, or software company.

    Read the guide

  • Risk & compliance lead

    Does the EU AI Act apply to my company?

    The EU AI Act reaches companies well beyond the EU, and several of its obligations are already live. A risk lead's guide to whether you are in scope, which tier your AI use falls into, and the deadlines that matter.

    Read the guide

  • Risk & compliance lead

    What does an AI policy need to say?

    A good AI policy fits on a page and gets followed. A risk lead's guide to the essentials — approved tools, the data line that matters most, disclosure, and accountability — without the forty pages nobody reads.

    Read the guide

  • Chief financial officer

    Why do AI pilots fail to pay back?

    Most AI pilots never reach production, and fewer still return value the board can see. A CFO's guide to why AI pilots stall short of payback, and the four things the ones that pay back do differently.

    Read the guide

  • Chief executive

    How do I build a board-ready business case for AI?

    A board funds a decision, not a demo. A chief executive's guide to the four things an AI business case must contain — value, cost, risk, and the ask — and how to size it so the board can act.

    Read the guide

  • Change & people lead

    Why do employees resist AI?

    AI adoption stalls on people, not technology. A change lead's guide to the four real reasons employees resist AI, why training alone doesn't move them, and what actually changes behaviour.

    Read the guide

  • Operations lead

    What is an AI agent, and what should we automate first?

    An AI agent does more than answer — it takes actions across steps and systems. An operations lead's guide to what agents actually are, where they help and where they don't, and how to choose what to automate first.

    Read the guide