AI maturity model

What is an AI maturity model?

An AI maturity model is a grid. Down one side sit the things a company needs before AI is more than a few people using a chatbot: strategy, data, skills, governance, the technical plumbing and the way the work is run. Across the top sit four or five stages, from experiments by enthusiasts to something the company runs on purpose. You put yourself in a box on every row.

The shape is borrowed from the Capability Maturity Model, published by Carnegie Mellon's Software Engineering Institute in 1993 after the American federal government asked for a way to judge the capability of its software contractors. Its five-level ladder is still what most AI versions run on.

Three published models, from three kinds of organisation:

  • MITRE's AI Maturity Model, August 2022, from the American research organisation. Six pillars, twenty dimensions, five levels from initial to optimised.

  • UNESCO's AI Maturity Framework, 2025, a self-positioning guide for public administrations. Six pillars, four levels: basic, ready, dynamic, advanced. It was written inside the AI-Ready Flemish Public Administration project, funded by the European Commission and built for the AI expertise centre at Digitaal Vlaanderen, which makes it the nearest thing to a local reference.

  • Microsoft's agentic AI adoption maturity model on Microsoft Learn, published in the spring of 2026. Five pillars, five levels numbered 100 to 500.

They disagree remarkably little. Different words, the same rows, roughly the same ladder. None of them is the standard, and you do not have to pick one.

What the model does well, and what it does not

It turns a vague conversation into a concrete one. "We should do something with AI" is not something anyone can act on. Six rows with a score on each, and an argument about where each score belongs, is.

It also shows a management team that the problem is not technical. People walk in expecting technology to be the weak row, and technology usually scores fine, because they already pay for a platform that would run this. The low rows are the ones about who owns what and whether anybody measured anything.

What it is not is a target. Going from level 2 to level 3 is not a business outcome, and no customer or bank cares what level you are. The models say so themselves, which is worth repeating because the vendors built on top of them do not. MITRE writes that the target level for an organisation follows from its mission and business practices, and that the highest level in all dimensions may not be practicable or relevant. UNESCO writes that its framework does not prescribe a specific target maturity level.

The four questions that predict whether you get value

The difference between a company getting something out of AI and a company with a folder full of pilots does not sit on the ladder. Four plain questions catch most of it, and not one of them is a stage.

  1. Does one person own a use case from end to end? Not a sponsor and not a steering group. One name, who decides what it does, whose team lives with the result, and who is allowed to stop it.

  2. Can you get at the data it needs? Reachable means somebody with the right permissions can pull it out this week, in a format a machine can read. Sitting inside a system you pay for does not count.

  3. Is anybody measuring the result? One number, looked at on a fixed day. Enthusiasm in the corridor is not a measurement, and neither is how often the tool gets opened.

  4. Is there a route from a working experiment to production? Who reviews it for security, whose budget pays the licence, who repairs it at eight in the morning. When nobody knows, everything ends as a pilot, which is what pilot purgatory looks like from the inside.

A company that answers yes to all four while scoring level 2 on every row will get more out of AI this year than a level 4 company that answers no to the second.

An AI maturity level versus a certificate

Put a maturity model next to ISO/IEC 42001, the AI management system standard published in December 2023, and they split on one dimension: whether anything about it can be checked from outside your company.

A maturity level is produced by the people being scored. No auditor, no accreditation, no scope written on the document, no expiry date. Two companies that both say level 3 may have used different models with different rows, and the honest one comes out lower. So a level is worth nothing in a tender and quite a lot in the room where you decide what to fix next.

A certificate runs the other way. An accredited body audits you, the certificate carries a written scope and a date, and somebody comes back to check. What it does not tell a customer is whether AI is doing anything useful for you, because you can hold it and get nothing out of the technology at all. The maturity model asks that question and cannot prove its answer. The certificate proves its answer and never asks the question.

Scoring yourself in an afternoon

Take one of the published models, keep its rows as they are, and get three people in a room who will disagree: whoever runs the company, whoever runs the work that would change, and whoever keeps the systems going. Read each row's descriptions out loud and score it. Where two people put the same row at different levels, the argument is worth more than the number.

Then one rule. Take the nearest use case you actually intend to build, and fix the single lowest-scoring row that blocks it. Not the lowest row overall, and not all of them.

An example. A company of 45 people services industrial cooling installations across Limburg and Antwerp. The use case is a draft quote for follow-up repairs, written from the report a technician fills in after a visit. On UNESCO's four levels:

  • Strategy and value: ready. The managing director wants it and said so on Monday. Nothing written down, no budget line.

  • People and culture: ready. Half the office uses a chatbot for mail already. Nobody trained, nobody sure what is allowed.

  • Data: basic. The service reports are free text inside the service app their supplier hosts. No export beyond one PDF per visit, and the API is not in their plan.

  • Governance, ethics and risk: basic. No policy, no list of what is in use, no owner.

  • Technology and AI operations: ready. Microsoft 365 across the company, an ERP with a working export, one supplier-built feature nobody asked for.

Two rows tie for lowest, and the reflex is to fix governance, because governance is the row you raise by writing something and there is always somebody ready to sell a framework for it. Governance is not what stops the quote assistant. The technician's reports being out of reach is. So the next six weeks are a phone call to the supplier about an export or an API, probably a change of plan, and a test on last quarter's reports to see whether what the technicians type is good enough to draft from at all.

Governance still needs an answer, and the answer is a page: what staff may put into which tool, who to ask when they are unsure, and a list of what is in use with a name beside each line. That is an AI usage policy, and it is an afternoon rather than a project.

What to watch out for with an AI maturity model

A low governance score turns into a governance project. Governance is the easiest row to raise on paper, and raising it changes nothing about whether the thing you want to build can reach its data.

The model you find first was usually published by somebody selling the remedy. That does not make it wrong, and it does explain which row always comes back low and why the rows line up so neatly with a product catalogue. Microsoft's model is careful and worth reading, and its rows are also environment structure, connectors and platform tooling. The two that sell you nothing, MITRE's and UNESCO's, are free to download and are the ones to score yourself against.

The rows assume a bigger company than yours. At 45 people, "organisational structure" is one line in somebody's job description and "workforce development" is two afternoons. Read those rows as questions instead of requirements, or you will score yourself at the bottom on things you do not need.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
ai maturity model maturity model ai adoption ai readiness ai strategy data governance data literacy ai literacy center of excellence iso 42001 pilot purgatory ai governance