AI Readiness Assessment Results
Microsoft's AI Readiness Assessment is the one many people find first, so I completed it in as a composite of the firms I've spent the last few months talking to. It came back 2 out of 5. The vision is there, but the execution is often lacking, with some very obvious knowledge gaps.
AI Readiness Assessment: Where I Think Most Companies Are At
Most knowledge-intensive firms are considerably more ready for AI on paper than they are in the room.
Microsoftās AI Readiness Assessment seems genuinely thought provoking
The Microsoft AI Readiness Assessment is a thought-provoking quiz. Its free, structured, extremely specific, and it takes about half an hour. It's also one of the most popular assessments out there (according to search traffic), which makes sense given how many organisations are living inside Copilot and the M365 stack more broadly.
You can do the quiz yourself here.
It covers seven pillars, including:
- Business Strategy
- Organization & Culture
- AI strategy & Experience
- Data Foundations
- AI Governance & Security
- Infrastructure for AI
- Model Management
At Monboard, we tend to focus heavily on the behavioural side and prefer to be vendor-agnostic, but Iāll get to critique later.
Score wise, you get several options from 1 (āInitialā) to 5 (āOptimizedā). Most of the time I ticked 2 (āEvolving.ā)
Overall score is 2 out of 5
I answered as the average of scores of companies I've spoken with over the past six months, particularly:
- Law & legal services
- ESG and sustainability
- Medicine and life sciences
- Insurance and FSI in general
Most of the firms I spoke to had 50 to 300 employees, with a handful of outliers at the large (>10,000) or very small (<20) end.
Its better than anec-data, but its obviously somewhat biased, especially since there was a fair amount of best-guess-based-on-inferred answers. Notwithstanding, the answers aligned with what Iāve seen elsewhere.
Our overall score was 2 out of 5, which isnāt exactly encouraging. Microsoft puts 2 in both the āCriticalā and āModerateā category. Perhaps they were being diplomatic?
Six of the seven categories came back yellow, one red. I'm going to focus on the yellow zone because I think it's where most of the market genuinely sits and the āred zoneā (Model Management) seems to be more advanced stuff that most folks arenāt ready for (IMO).
Business Strategy and Organisational / Cultural AI Readiness
Iāve merged these sections together, in part because theyāre brief.
Topline is usually OK. Vision & communication; strong advocacy from leadership; company-wide understanding that AI matters. Everybody knows its a Big Deal. 3-4 / 5.
When you start on the details, it gets murkier.
- Investment Plan: 2 out of 5. Many companies have been thoughtful about what AI they buy and which team gets what capability, but ROI (a critical part of any business case) is often mixed or poor.
- Use Cases. Lets say 2.5. I do see this in some scenarios, but it tends to be quite basic. Some companies have a āchampionā or ācoordinatorā who comes up with practical use cases. For many it depends on the team and the manager.
- AI Skilling: this hovers between 2 and 3 (see above). Thereās definitely some efforts here.
- Decision Agility (for evaluating AI advancements): 2 out of 5. I almost never see formal process here.
- Vision & communication: Iād give this a 4. Strong advocacy from leadership; company-wide understanding that AI matters. Everyone gets that AI Is a Big Deal. Do they actually execute on that? Thatās another matter.
- AI Expertise: Moderate. The company gets that AI matters
I keep coming back to MIT's NANDA project finding from last year, something like 95% of enterprise generative AI pilots showing no measurable impact on the P&L. I donāt think the high-level stuff is an issue.
Data foundations are strong - until you get to the AI-specific stuff
The things firms did before AI arrived scored fine. A lot of it dates back to the Cloud era.
- Data Governance: acceptable. Lets say 3 out of 5.
- Data Privacy: acceptable, with automated access controls and regular audits.
- Data Access: acceptable. Almost all of that is GDPR residue: eight years of compliance work that happened to leave useful infrastructure behind.
The things that now matter because of AI scored badly:
- Data Engineering: 1 out of 5.
- Data Quality Management: 1 or 2 out of 5.
- Data Integration: maybe a 2 at best.
- Structured Data Feeds: 1 out of 5 (in a lot of firms this genuinely just means spreadsheets).
- Real-time processing: 1 out of 5, and mostly manual.
- Data Representativeness: mixed bag. Iāll give this a 3 out of 5 for science-based fields (ESG & Sustainability; Life Sciences). 1 or 2 out of 5 for other fields (though its less relevant, arguably).
- Metadata Management I marked 2 out of 5, though it varies heavily by sector. Sustainability and life sciences teams tend to be OK at it. Law firms, in my experience, less so.
One might think āwhy do I need any of these anyway, I got on fine so far without them?ā
Because all these things get really important once you start scaling your AI efforts (or doing advanced stuff e.g. agentic workflows).
Understanding of more advanced concepts including compliance, security and ethics is very poor
- AI Security: weak. Prompt injection is the clearest example. Many people have heard about it, few had done anything. Nobody knew about search poisoning.
- Regulatory Compliance: weak to medium. As an example: the volume of firms with who don't know the EU AI Act exists (and have exposure to it) is shocking. Its fair that the Act isnāt being aggressively enforced, but Article 4's AI literacy obligation has applied since February 2025. I wonder if the reason theyāve watered down the Act is because an insane amount of companies would become immediately liable?**
- AI Ethics: weak.
- Human-Centred Design: weak.
- Model Interpretability: weak.
Where governance does exist, it's usually a policy that says check your work, which as a control is roughly as effective as a sign asking people to be careful.
Model Management came back Critical, though Iām not concerned
Only one category went red, and it's hard to say whether it even applies to a lot of companies at this stage.
- Model Deployment; ML Pipelines; Feature Management; Model Flighting - all 1 or 2 out of 5. I doubt most people even know what this is (some of these are unnecessary industry jargon IMO).
- Some of the questions here are a bit niche. Synthetic Data is controversial.
- Prompt flow Automation - maybe 2 out of 5, possibly 3. I see sporadic usage of LLM plugins and custom workflows - even vibe coding.
There's a view in tech that you should own this stack yourself rather than outsource it, and maybe that view ages well as things mature. Unfortunately, most of these firms haven't sorted out the basics further up this list yet: skilling, incentives, verification. Whether they can do model engineering feels like a much later problem than whether their people know when to trust the output in front of them. So I'll flag the red score and move on, rather than tell you what to do about it.
What this AI Readiness assessment doesn't measure
- Verification behaviour: there's no question about what a person actually does when the output looks plausible and is wrong. This is, IMO, one of the biggest problems with AI use for regulated industries with very real consequences.
- General risk mitigation: Thereās no stuff about hallucinations, homogeneity, cognitive atrophy or similar. To be fair, maybe Microsoft puts this under āAI Ethics.ā Points for their mentioning Bias detection and Abuse prevention at least.
- Incentives: The organisational / culture stuff focuses mostly on training. Thereās no mention of incentives, which is a real blocker in fields like law.
- Vendor shape: PTU provisioning, PAYGO management, Azure OpenAI stuff. Reasonable questions if you're building on Azure, meaningless otherwise, and they drag your score around based on a path you may never take.
How can I evaluate my companyās AI readiness?
A few things I would add from change management land to Microsoftās aassessment. You can fairly accuse me of bias here, though the research suggests it strongly improves your chances of success - by about 6-fold if done right:
- What people actually know and do - Observed rather than measured via tickbox. Shadow usage, workarounds, the tools nobody declared. Microsoft's own Work Trend Index put self-supplied AI tools at around three-quarters of users, though that survey's from 2024 now, and I'd want a fresher number before leaning on it too hard.
- Where verification sits - Which specific step, done by which named role, at what cost. Put a cheap filter before the expensive human. Even a basic red-teaming prompt is better than nothing. And staff should be clear on what must never be wrong (eg case citations).
- Getting a grasp on your incentives (and disincentives): Do the employees have good reasons to use the tools? Is there anything that would discourage them from doing so?
- What reinforcement exists after initial introduction - Training decays. If there's no refresher, no measurement (or incentive - see above), and no manager conversation⦠where do you think itāll land?
None of the above requires a data engineering function, by the way. If you've run the Microsoft assessment and came out low like almost everyone else - especially on the people stuff - weāre building something to help. Drop us a ping if you want to be an early guinea pig.
*Note on the EU AI Act
The EUAIA continues to be a moving target:
- The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July, days before this piece went up.
- It defers stand-alone Annex III high-risk obligations to 2 December 2027
- Article 50 transparency obligations largely still apply from 2 August 2026, though the Article 50(2) rules for systems already on the market before that date were pushed to December 2026.
- The Article 4 literacy obligation is still there - but instead of being required to enforce AI literacy firms have to support it. Functionally, I think this is kind of the same - you still have to offer training
ā All posts