Back to blogAI Governance

    AI Rating: why you need an objective score before investing

    No CFO would approve an acquisition without due diligence, no bank would extend credit without a rating, no CISO would buy a security platform without an assessment of their own perimeter. Then the AI budget arrives, often the fastest-growing line of technology spending, and the discipline evapor...

    ZeroFive.AI January 27, 2026Updated on July 14, 2026 4 min

    No CFO would approve an acquisition without due diligence, no bank would extend credit without a rating, no CISO would buy a security platform without an assessment of their own perimeter. Then the AI budget arrives, often the fastest-growing line of technology spending, and the discipline evaporates: companies start from the vendor, from the fashionable use case, from the demo seen at an event, without anyone having measured whether the organisation can turn that investment into value.

    The AI Rating exists to bring back to AI the same discipline companies apply to every other significant capital allocation. The analogy with credit ratings is deliberate and worth taking seriously, because it inherits three properties: a synthetic, comparable score, a transparent and repeatable methodology, and gating rules whereby certain gaps cannot be offset by other strengths.

    How the score is built

    The evaluation crosses four dimensions, each scored from 0 to 5. AI Readiness photographs preparation, from strategy to data quality, from infrastructure to widespread skills. AI Delivery looks at execution capacity, meaning development processes, MLOps, integration with existing systems, monitoring of whatever reaches production. AI Risk covers governance, with compliance towards the EU AI Act and ISO/IEC 42001, plus the management of bias, security and privacy. AI Confidence measures actual adoption, from board commitment to the trust of the people who use the systems every day.

    The method matters as much as the model. Every score comes from crossing documentary evidence (architectures, policies, real project metrics) with interviews run at several levels, from the board to operational teams, because the distance between what is declared and what is experienced is itself a data point, often the most eloquent one. The result is summarised in four merit classes, from A for leaders (score above 4.0, no area below 3.5, gates satisfied) to D for those at the initial stage, with C in the middle collecting the most frequent case in Italy: real capabilities, pilots that never scaled, maturity under construction.

    Critical gates deserve an extra word, because they are what separates a rating from a survey. A company can excel at strategy and delivery, but if an AI systems register is missing, if personal data circulates unsupervised or if nobody has classified systems by risk as the European framework requires, the merit class stays capped. The message built into the mechanism is that certain foundations are non-negotiable.

    What changes in decisions, concretely

    The value of the score shows up at three precise decision points. The first is budget allocation: knowing you are a class C with Risk at 1.8 shifts spending from the third pilot to closing the gaps that sank the first two, and in our experience (34+ assessments delivered, ZeroFive.AI data, 2026) this single course correction is worth more than any technological quick win.

    The second moment is the conversation with the board. A board of directors cannot govern what it cannot compare, and the rating hands it exactly that: a number to place on the dashboard next to financial KPIs, to re-measure after twelve months, on which to hold management accountable with the same ease with which margins are discussed. An isolated snapshot ages, the comparison between two measurements governs.

    The third moment is the dialogue with the outside world, auditors, regulators, enterprise clients whose tenders are starting to require evidence of AI governance. A documented rating, with precise regulatory references for every recommendation, demonstrates that the topic was addressed with method, which is different from declaring compliance (certified compliance is a journey of its own, and we distrust anyone who promises it inside an assessment).

    When to do it, and when to do it again

    The right moment for the first measurement is before an investment cycle, never after. The typical occasions we see: an industrial plan that includes AI, a board demanding a strategy, a series of pilots with disappointing outcomes, a regulatory deadline on the horizon. The baseline takes four to six weeks and produces deliverables calibrated for each level, the strategic summary for the board, the analytical gap report for the teams, the roadmap with 30-day quick wins, the raw data for audit and governance.

    The single measurement, though, is only the start of the mechanism. The model works as a cycle, baseline, execution of corrective actions, re-assessment after twelve months, because the declared goal is to turn the rating into a structural KPI of the organisation, monitored over time like any other executive indicator.

    If you are about to approve an AI budget for 2026, the question to ask before signing is simple: what evidence is it based on? If the answer is a list of proposed projects and no measure of the capacity to deliver them, half an hour of conversation can save you months: calendly.com/fabiolalli/zerofive, or hello@zerofive.ai. Patient capital is not the capital that waits, it is the capital that measures before it moves.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI Rating#enterprise AI assessment#AI maturity evaluation#AI rating merit classes#AI investments
    Share

    Keep reading