An AI maturity model is a five-level scale that shows how ready an organization is to use AI, scored separately for data, people, processes, systems, governance and culture. It tells you where you stand and what to fix first.
Readiness is several conditions at once. Organizations that are strong on some dimensions and weak on others make predictable mistakes. They buy platforms before the data can feed them, or write policies nobody follows. A maturity model gives technology, operations, legal and the board one shared language for "ready".
What is an AI maturity model?
An AI maturity model is a structured way to assess AI readiness and measure progress over time. It has two parts: a set of levels that describe how AI is used, and a set of dimensions scored against those levels.
Several analysts and vendors publish their own five-stage models. Level names differ between them, and the logic is similar. The version below is a practical composite for Canadian organizations. You can take a first reading with the AI Readiness Quiz before a structured assessment.
What are the five levels of AI maturity?
The five levels run from individual, unmanaged use to AI built into how the organization competes. Many organizations sit at Level 1 or 2 on at least one dimension.
| Level | What you see | Main risk | Priority next step |
|---|---|---|---|
| 1. Ad Hoc | Staff use ChatGPT, Copilot or Claude on their own; no policy, no inventory | Personal or client data sent to unapproved tools | Inventory current use, approve tools, publish a short use policy |
| 2. Aware | Leadership engaged, a working group, pilots with no path to production | Pilot fatigue; spend without results | Take one use case through the full lifecycle to production |
| 3. Structured | Approved strategy, governance that is followed, at least one system in production | Growth outpaces controls | Build measurement and a deployment pipeline for more use cases |
| 4. Managed | AI run as a portfolio with metrics, incident handling and regular review | Complacency as rules and models change | Portfolio decisions based on performance data |
| 5. Optimizing | AI built into products, services and operating models | Dependence on a few vendors or people | Continuous investment in talent and design |
Level 1 is often invisible to management. The official position may be "we have not adopted AI yet" while staff use it daily. The risk sits in the data being pasted into tools and in AI-drafted content presented as reviewed.
Level 2 has a strategy in draft, a committee and a few pilots. Awareness has not yet become capability. The most useful move is to take one system all the way through design, privacy review, build, testing, training and production.
Level 3 is a stable platform. There is a defined path from idea to production, data is catalogued, and at least one AI system produces value in a real process.
Levels 4 and 5 add measurement, portfolio management and design of new services around AI. Few organizations reach Level 5 across all dimensions.
Which dimensions does an AI maturity assessment score?
An AI maturity assessment scores six dimensions, each on the same five-level scale. The profile across dimensions matters more than the average.
| Dimension | Key questions | Common gap |
|---|---|---|
| Data | Is data catalogued, trusted and reachable by the systems that need it? | Data exists but sits in inboxes, PDFs and old systems |
| People | Who can design, run and check AI outputs? Do teams have time to learn? | A few enthusiasts, no trained owners |
| Process | Is the work documented and repeatable? Are metrics tracked today? | Processes live in people's heads |
| Infrastructure | Are access, integrations and security controls in place? | Tools that work for a pilot and fail at scale |
| Governance | Is there a use policy, an inventory and a named owner for each system? Are privacy duties mapped? | Policy documents without enforcement |
| Culture | Does leadership sponsor change? Do staff trust the approved tools? | Technology rollout with no change management |
How do you score your organization and measure progress?
Score each dimension from 1 to 5 with evidence, then re-score on a fixed schedule. Honest scoring needs the budget owner, someone from operations and someone who knows the systems in the same room.
Look for the lowest dimension relative to the others. That is the binding constraint. Four profiles come up often:
- High infrastructure, low data. Platforms bought before the data could feed them.
- High governance, low culture. Policy exists; staff do not know it or work around it.
- High data, low people. Good data, too few people who can use it with AI.
- Many pilots, little production. Process ideas at Level 3, infrastructure and governance at Level 1–2.
To measure progress, keep the same questions and evidence at each re-score, every six to twelve months. Track a short list of indicators alongside the levels:
| Indicator | Why it matters |
|---|---|
| Share of AI use covered by an approved tool and policy | Shows whether Level 1 risk is shrinking |
| AI systems in production with a named owner | Separates pilots from operations |
| Systems with a measured baseline and a review date | Makes results provable |
| Staff trained on approved tools, by team | Tracks the people and culture dimensions |
| Privacy impact assessments completed for systems using personal data | Tracks governance under PIPEDA and Quebec Law 25 |
How does the model apply to knowledge work and HR?
The same levels apply to knowledge management and HR, two areas where AI use often starts informally. The signals per level are specific.
- Knowledge management. Level 1 means staff paste internal documents into public chat tools. Level 3 means an approved assistant answers from a curated, access-controlled document set, with sources shown and an owner who keeps content current.
- HR and recruitment. Level 1 means recruiters use AI to screen or rank applicants without a record. Level 3 means every AI step in hiring is listed, reviewed by a person and disclosed where the law requires it.
Canadian rules make the HR case concrete. Since January 1, 2026, Ontario employers with 25 or more employees must state in publicly advertised job postings whether they use AI to "screen, assess or select applicants". Quebec Law 25, section 12.1, requires an enterprise to inform a person when a decision about them is based exclusively on automated processing. A governance score of 3 or higher in HR means these duties are mapped and met.
What should you do at each level?
Each level has one priority. Trying to fix every dimension at once spreads the budget too thin.
- Level 1: find out which tools staff use and what data goes into them. Approve a short list of tools and publish an AI use policy for staff.
- Level 2: build governance, a strategy and the first production system in parallel. One system in production teaches more than five pilots.
- Level 3: widen the pipeline to more use cases and put measurement in place for each.
- Level 4: manage AI as a portfolio and retire systems that do not meet their targets.
- Level 5: invest in talent and service design, and review vendor concentration.
How do you start an AI maturity assessment?
Start with a structured self-assessment, then bring in an outside view where functions disagree. A well-run executive session takes two to four hours. Disagreement between functions about the current level is itself a finding.
For an outside view, Remolda's AI readiness assessment scores six dimensions (data, process, people, leadership, infrastructure and culture) in one week and lists the three gaps to close first. It costs $490 CAD + HST. The two-week AI Opportunity Audit, at $2,900 CAD + HST, adds interviews and a 12-month roadmap. Both are described on the pricing page. Related reading: How to Build an AI Strategy.