AI maturity model: what it is, how it is measured, and why the board should demand one
Try asking this question at your next executive committee: on a scale from 0 to 5, how mature is our company in AI adoption? In our experience the answers fall into three families, those who cite ongoing projects (which measure activity, not capability), those who cite budget spent (which measure...
Try asking this question at your next executive committee: on a scale from 0 to 5, how mature is our company in AI adoption? In our experience the answers fall into three families, those who cite ongoing projects (which measure activity, not capability), those who cite budget spent (which measures intention), and those who admit that a shared measure does not exist. The third answer is the most useful, because it is the starting point for building one.
An AI maturity model exists precisely for this: turning a perception ("we are behind", "we are doing fine") into a number that can be compared over time, across functions and against the market. Companies have measured financial solidity with credit ratings for decades, and cybersecurity with maturity frameworks, while on AI, where investments grow at double digits, most still decide by gut feeling.
What a maturity model actually measures
The word maturity is misleading, because it suggests a technology ranking, how many models we have, how sophisticated they are. A serious model measures something different: the organisation's capacity to turn AI into value in a repeatable, governed way. A company can run the most advanced language model on the market and still score low on maturity, because its data is fragmented, nobody owns the risks and the board has never approved a strategy.
Our AI Rating, the proprietary framework we use in ZeroFive assessments, breaks this capacity down into four dimensions. AI Readiness measures preparation: strategy, governance, data quality, infrastructure, skills and culture. AI Delivery measures execution: development processes, MLOps, systems integration, scalability and monitoring. AI Risk measures oversight: compliance with the EU AI Act and ISO/IEC 42001, ethics, bias, security, privacy. AI Confidence measures adoption: board commitment, user trust, perceived robustness of the solutions.
The fourth dimension is the one that surprises clients most, because it sounds soft and turns out to be predictive: a technically excellent system that users avoid, or that the board abandons at the first setback, has the same value as a system that does not exist.
Scales, classes and the logic of critical gates
The measurement produces a 0-5 score for each dimension and a global rating, summarised in four merit classes, from A (leader, score above 4.0 with no area below 3.5) to D (initial stage, score below 2.0, opportunistic approach, missing prerequisites). In between, class B for advanced organisations and class C for those with real capabilities but significant weaknesses, typically pilots that never scaled.
The mechanism that makes the model credible, and that most downloadable self-assessments lack, is the non-compensable critical gate. A high score on strategy and delivery cannot offset the absence of an AI systems register or personal data management that is out of control: certain gaps cap the merit class regardless of the average, exactly as in credit ratings a breached covenant outweighs ten healthy indicators. Without gating, the model rewards whoever tells the best story.
There is also a methodological requirement that applies to any framework you choose: the evaluation must combine quantitative evidence (documents, architectures, real metrics) with qualitative interviews across several levels of the organisation, because the gap between what management declares and what operational teams experience is, almost always, the single most informative data point of the entire assessment.
The number the board should demand
For a board of directors, an AI maturity rating solves three concrete problems. The first is comparability over time: repeating the measurement after twelve months turns a snapshot into a film, and allows the board to hold management accountable for progress with the same discipline applied to financial KPIs. Our declared goal, in the engagements we run, is to bring the AI rating into the executive dashboard as a structural indicator monitored by the board.
The second is external defensibility. With the EU AI Act in force since August 2024 and its application deadlines approaching, and with ISO/IEC 42001:2023 defining the standard for AI management systems, boards, risk committees and auditors need to demonstrate that they assessed the state of play with method. A documented rating, with evidence and precise regulatory references for each area, is the foundation of that demonstration (we are talking about preparation and gap analysis, not certified compliance, which is a different journey).
The third problem is capital allocation. Knowing that the company is a class C with Readiness at 3.1 and Risk at 1.8 changes the budget conversation: before funding a third pilot, you fund the closure of the gaps that blocked the first two. Low maturity is not a verdict, it is information, and whoever holds it wastes less.
Where to start, in practice
A first assessment typically takes four to six weeks and produces deliverables for every level: a strategic summary for the board, an analytical gap report for the teams, a roadmap with 30-day quick wins and prioritised projects, and the raw data for governance and audit. The cost is a fraction of an average pilot, and in our experience it prevents at least one wrong one.
If you want to understand how it would work on your organisation, book a call at calendly.com/fabiolalli/zerofive or write to hello@zerofive.ai. First, though, it is worth asking your committee the opening question again, the one about the 0-5 scale, and observing not so much the answers as how far they diverge from one another: that distance is the first measure of your maturity.