When organisations ask whether they are ready for AI, they usually mean their technology. Do we have the right licences? Is our data in the cloud? Does our IT team know how to set it up?
Those questions matter. But in my experience they are rarely what holds an organisation back. The tools are easy to get. What is hard is everything around them.
AI readiness is mostly an organisational question.
Your staff are already using it
Start with an uncomfortable fact. In most organisations, AI is already in use. Someone is drafting emails with it. Someone is summarising meeting notes. Someone has pasted a spreadsheet into a chatbot to make sense of it.
None of this waited for a strategy. So the real readiness question is not "should we start?" It is "do we know what is already happening, and are we comfortable with it?"
Most organisations can't answer that. Not because people are hiding anything, but because nobody has asked. The first step in any readiness work is simply finding out.
Four things that decide whether AI will help
When I look at whether an organisation is ready to use AI well, I look at four things. Only one of them is mostly technical.
1. Do you know who owns your information?
AI is only as useful as the information it can work with, and only as safe as the rules around that information. If nobody can say who owns the client records, which version of the policy manual is current or what staff are allowed to share externally, AI will amplify that confusion.
This is not a data engineering problem. It is a question of ownership and accountability. It usually needs a conversation between leadership, operations and whoever manages your systems, not a new platform.
2. Are your processes clear enough to improve?
AI is good at speeding up work that is well understood. It is poor at fixing work that nobody has defined. If a process runs differently depending on who does it, adding AI will produce different results depending on who uses it.
Before asking where AI could help, it is worth asking which processes are stable and understood well enough to improve. Those are your candidates. The others need attention first, and that attention often delivers more value than AI would have.
3. Who is allowed to decide?
Every AI use involves decisions. Can this tool be used with client information? Who approves a new use case? What happens when the output is wrong?
In organisations without clear decision rights, one of two things happens. Either everything waits for a committee that meets quarterly, or people make their own calls and hope for the best. Neither is readiness. Good governance is not about saying no. It is about making sure someone can say yes, with confidence, in a reasonable time.
4. Do people trust it, and should they?
The final question is cultural. Some staff will over-trust AI output and stop checking it. Others will refuse to touch it. Both reactions are reasonable responses to uncertainty, and both are risks.
Readiness here means building a shared understanding of what AI does well, where it fails and what your organisation expects of people who use it. That is a capability question, not a technical one.
What readiness work actually looks like
A useful readiness review is not a long audit. It usually covers a few things:
- Current use. How AI is being used today, formally and informally, and what people want from it.
- Information and risk. Where sensitive information lives, who owns it and what could go wrong.
- Process fit. Which workflows are stable enough for AI to improve, and which need fixing first.
- Governance. Who decides, on what basis and how quickly.
- Capability. What leaders and staff understand, and what they need to learn.
The output should be short and practical: a clear position on AI, a simple set of rules people can follow and a small number of use cases worth doing properly.
The technical part still matters
None of this means the technology is irrelevant. You still need the right tools, sensible security settings and someone who understands how they work. But those are the parts of the problem that are easiest to buy.
The organisations that get real value from AI are rarely the ones with the most advanced tools. They are the ones that know what they are trying to improve, who is responsible and how they will know if it is working.
A better first question
If your board is asking about your AI strategy, resist the urge to answer with a list of tools. Answer with the organisational questions instead. What are we trying to improve? What information can we safely use? Who decides? What do our people need?
Those answers will tell you far more about your readiness than any technology assessment. And they will make every AI decision that follows easier to make and easier to defend.