The short answer
You are ready for a first AI project when leadership can name the problem it should solve, at least some staff are already using AI tools and you know which, the target process can be described on a page, the data it needs is digital and reachable, your core systems can be connected to, multi-factor authentication is on for everyone, and someone owns an AI policy, even a short one. You do not need all seven perfect. You need to know which ones are not, because those are the first jobs.
1. Leadership: can you say what for?
Ready looks like a leadership team that has discussed AI formally, agreed on one or two problems worth solving, and named an owner. Not ready looks like “we need an AI strategy” with no noun after it. The test is simple: ask three directors what the first AI project should do, and see whether the answers overlap. If they do not, a half-day workshop is cheaper than any tool.
2. People: who is already using it?
Somebody in your business used an AI tool this week. Ready looks like knowing who, on which tool, on which account, with a short policy that says what may go in. Not ready looks like not knowing, which usually means company information is already in a public tool. This is the fastest dimension to fix and the one most often skipped, because it feels like an HR problem rather than a technology one. It is both.
3. Process: can you describe it on a page?
The process you want AI to take on has to be describable: what arrives, what is done to it, what is produced, what the exceptions are. Ready looks like a page. Not ready looks like “Sarah knows how it works”. AI is not a way of discovering how your business works; it needs to be told, and the telling is where a surprising amount of the value appears, because the page usually shows three steps nobody needed.
4. Data: is it digital and findable?
The information the AI needs must exist in a form software can reach. Ready looks like documents in a structured shared drive or document system, records in systems with an export or an API, and a rough idea of where the truth lives when two systems disagree. Not ready looks like paper, personal inboxes and spreadsheets called final-v7. Most businesses are somewhere in between, and the readiness question is which projects the current data supports, not whether the data is perfect.
5. Technology: can your systems be connected to?
An AI system reads from somewhere and writes to somewhere. Ready looks like cloud systems with APIs, or at least exports and inboxes, and a platform (Microsoft 365 or equivalent) that can host the assistant. Not ready looks like a core system nobody can get data out of except by screen. The fix is rarely replacing the system; it is usually a small integration layer, but it must be planned and priced rather than discovered halfway through a build.
6. Security: is identity in order?
An AI agent acts with the permissions of the account it runs under, and an assistant connected to your files sees everything the person can see. Ready looks like multi-factor authentication for everyone, documented access to sensitive information, and permissions that have been reviewed in the last year. Not ready looks like shared logins and folders shared with everyone since 2019. Fix identity before any agent goes live, and check permissions before any assistant reads your documents; these are the two failures that stop rollouts.
7. Governance: does anyone own it?
Ready looks like a short, signed AI policy, a named owner, and a way of recording what AI did when something needs to be traced. Not ready looks like nothing written down and a plan to write it after the project. Governance sounds like the last dimension; it is the one that decides whether the first project can be trusted with anything that matters.
Scoring yourself honestly
Give each dimension a plain mark: in place, partly, or not. Three or more “not” marks means the first project is the readiness work itself, honestly labelled, and the AI project comes after. Mostly “partly” is normal and means choosing a first project that avoids the gaps: internal, low consequence, using data you already have. Mostly “in place” means you are past the readiness question and into strategy: which project, in what order, with what business case.
What readiness is not
It is not a budget, although you will need one. It is not enthusiasm, which most businesses have in surplus. It is not having hired a data scientist; the seven dimensions are mostly about ordinary operational discipline, and the businesses that score well are the ones that already run tidy systems, not the ones with a technical team. It is also not perfection. A business that knows exactly which three dimensions are weak is more ready than one that assumes all seven are fine.
The readiness work pays even if you never do AI
Every gap on the list is a gap for reasons that have nothing to do with AI. Undocumented processes cost you every time someone leaves. Scattered data costs you every report. Shared logins and stale permissions are an insurance question before they are an AI question. Fixing them to prepare for AI is a good reason; you would have been right to fix them anyway. That is why the honest first project is sometimes not an AI project at all, and why a consultant who tells you that is worth more than one who does not.
Where to go from here
The AI Readiness Assessment on this site is the two-week, evidence-based version of these seven checks: we look at the systems, the permissions and the data rather than asking, score each dimension, and hand you a ninety-day plan. The AI Opportunity Score below is the five-minute self-assessed version, and it is the right place to start if you want a signal before committing to anything.
Published 12 September 2026 · Be AI