The Enterprise AI Maturity Model
Five levels from isolated pilots to independently verifiable, owned infrastructure, with the unlock test for each.
The Enterprise AI Maturity Model places an organisation on one of five levels: Experimentation, Automation, Governance, Private AI, and Sovereign Intelligence. Each level is defined by what is actually running in production, not by ambition, and each has a specific, checkable condition that must be true before an organisation can honestly claim the next one. The framework extends the established maturity literature past the point where most of it stops, treating data residency, model ownership and end to end verifiability as a distinct, sequential stage.
What are the five levels of enterprise AI maturity?
Existing frameworks from Gartner, Deloitte and MIT CISR describe the early stages of AI adoption well: scattered pilots, workflow automation, then governance. Where they stop short is the move from "governed" to "owned." This model keeps the first three levels consistent with that literature, then splits the top into two distinct stages, because owning infrastructure and proving what it did are different achievements.
| Level | Name | One-line definition |
|---|---|---|
| 1 | Experimentation | Isolated pilots and individual tool use, no shared standards, no inventory of what is running where. |
| 2 | Automation | AI is embedded into repeatable workflows and produces measurable efficiency gains, but oversight is still manual and ad hoc. |
| 3 | Governance | AI use is inventoried, risk-classified, and subject to continuous oversight, typically aligned to a recognised framework such as NIST AI RMF or ISO/IEC 42001. |
| 4 | Private AI | AI infrastructure and models run on infrastructure the organisation owns or exclusively controls, with data never leaving the organisation's boundary by default. |
| 5 | Sovereign Intelligence | AI is owned, verifiable, and auditable end to end, meaning every material action a model takes can be independently checked, without having to trust the vendor's word for it. |
These levels are gated, not averaged. An organisation with excellent Level 3 governance on paper but no inventory of what tools staff actually use is still at Level 1, because the weakest link sets the level, not the strongest one. Section five below sets out the specific gate questions.
What does Level 1: Experimentation look like?
Definition: isolated pilots and individual tool use, no shared standards, no inventory of what is running where.
A handful of teams or individuals try AI tools, chat assistants, copilots, point solutions, without a central mandate. Usage is opportunistic rather than strategic, with no consistent measurement of value delivered.
Capabilities present
- Basic prompting skill in pockets of the business.
- Procurement of one or two SaaS AI tools by individual teams, not IT.
- Early wins, but no supporting infrastructure.
The risk of staying here
Shadow AI: unsanctioned tools handling company or customer data with no oversight. Output quality is inconsistent, learning does not transfer between teams, spend duplicates across tools, and there is no audit trail if a regulator later asks what AI touched customer data.
What unlocks Level 2
A named executive sponsor, a first shared use case with a measurable outcome, and a basic inventory of every AI tool actually in use. That inventory is the precondition for every governance step that follows.
What does Level 2: Automation look like?
Definition: AI is embedded into repeatable workflows and produces measurable efficiency gains, but oversight is still manual and ad hoc.
AI moves from a tool someone opens to a step inside a process: document processing, customer-service triage, code generation, report drafting. Return on investment is tracked for the flagship use cases, and IT and data teams are involved, not only individual users.
Capabilities present
- Workflow integration through APIs, automation platforms with an AI step, or embedded copilots.
- A small platform or model-selection layer, and basic prompt and output logging for the highest-value workflows.
- Early data-quality investment, because automation exposes bad data fast.
The risk of staying here
Automation outpaces governance. Model outputs feed real decisions with no consistent design for human oversight, no incident process for AI failures, and no policy on which data can be sent to which model. A single bad automated decision, a wrongful denial, a leaked prompt, a hallucinated figure, becomes a serious incident because nothing was structurally watching for it.
What unlocks Level 3
A written AI use policy, a named accountable owner for AI risk distinct from whoever owns AI delivery, and a first formal risk classification separating low-stakes use cases from ones touching regulated, safety-critical or high-impact decisions.
What does Level 3: Governance look like?
Definition: AI use is inventoried, risk-classified, and subject to continuous oversight, typically aligned to a recognised framework such as NIST AI RMF or ISO/IEC 42001.
This is the threshold level. Governance becomes an operating capability, not a policy binder nobody reads: a standing AI governance committee, a continuous rather than one-off system inventory, mandatory pre-deployment testing for bias, safety and security, documented human-oversight design for consequential decisions, and an incident-response runbook that explicitly covers AI failure modes rather than only generic IT incidents.
Capabilities present
- Alignment to a recognised external framework: NIST AI RMF's Govern, Map, Measure and Manage functions, and/or ISO/IEC 42001's clauses.
- Provenance and audit logging of model decisions, and risk-tiering of use cases mapped to external categories such as the EU AI Act's.
- Vendor and third-party model oversight, not only internal use.
The risk of staying here
Governance without ownership. An organisation can be fully compliant on paper, with policies, committees and risk registers in place, while every model call still leaves the building to a third-party API. It can prove what happened but not control where the data went, what happens if the vendor changes terms or is acquired, or what happens if connectivity is cut. Governance alone caps out at "trust and verify"; it cannot deliver "verify without trusting," because the substrate is not owned. Cost compounds this, since usage-based pricing scales with adoption.
What unlocks Level 4
A board-level decision to bring model infrastructure in-house or under direct control, usually triggered by one or more of: data residency or sovereignty, cost predictability (fixed capital versus metered operating cost), continuity for a regulator or critical-infrastructure operator that will not accept an external dependency, or a competitive need to keep proprietary data and model tuning off a third party's servers.
What does Level 4: Private AI look like?
Definition: AI infrastructure and models run on infrastructure the organisation owns or exclusively controls, with data never leaving the organisation's boundary by default.
The organisation has moved from renting inference from a third party to running models on owned or dedicated infrastructure, whether on-premises, air-gapped, or a dedicated private cloud tenancy it fully controls. This is an architectural shift, not a procurement change.
Capabilities present
- Model deployment and fine-tuning within the organisation's own boundary.
- A predictable, capital-based cost structure instead of per-token metering.
- The technical ability to prove a specific dataset never left the organisation's control.
- Continuity independent of a third party's uptime, pricing changes, or willingness to keep serving the account.
The risk of staying here
Private is not automatically sovereign. An organisation can own the hardware and still depend on a foreign-controlled base model, a foreign cloud provider's management plane, or a supply chain it cannot independently verify end to end. "Private" answers where the data sits. It does not answer whether every action can be independently verified after the fact, whether the system survives loss of external connectivity or a vendor relationship, or whether the cryptographic chain of custody will survive the post-quantum transition. Staying "private but unverifiable" leaves an audit gap: the organisation can show data did not leave, but often cannot show, action by action, what the model did and why.
What unlocks Level 5
A requirement, regulatory, procurement-driven or self-imposed, for independently verifiable, auditable AI action, not just private hosting: a procurement clause, a national-security requirement, or a board decision that "owned" must extend to "provably accountable."
What does Level 5: Sovereign Intelligence look like?
Definition: AI is owned, verifiable, and auditable end to end, meaning every material action a model takes can be independently checked, without having to trust the vendor's word for it.
The organisation controls not just where the infrastructure sits but the full chain of accountability: what model made a decision, on what basis, with what data, and whether that can be reconstructed and verified after the fact by an internal auditor, an external regulator or a court, without relying on the good faith of a third-party operator.
Capabilities present
- A verifiable audit trail: cryptographically signed, tamper-evident records, not application logs that could be edited after the fact.
- Governance and technical control unified, so an ISO 42001 or NIST AI RMF style policy layer is backed by a technical layer that enforces it.
- Resilience to the loss of any single external dependency: the system stays operating and auditable if a vendor, cloud region or connectivity path fails.
- A security posture built against long-horizon threats, including signing designed to remain valid through the post-quantum transition.
The risk at this level
The operational discipline required is real and ongoing. Sovereignty is a maintained state, not a one-off migration. An organisation that reaches Level 5 and then under-invests in the audit chain, key management or the governance function can regress in practice even while the infrastructure remains owned on paper. The risk at Level 5 is complacency, not the absence of a next level.
Where this level sits in the market today
Still rare. Most enterprises, including well-governed ones, sit at Level 2 or 3. Level 4 is where regulated and public-sector procurement conversations increasingly start, driven by data-residency requirements. Level 5 is what defence, critical infrastructure, financial regulators and the judiciary are starting to ask for explicitly, because "we promise we did not misuse the data" is no longer sufficient when a model's actions materially affect a citizen or a national system.
How is Private AI different from Sovereign Intelligence?
This is the most consequential distinction in the model, and the one most existing frameworks skip past. Private AI and Sovereign Intelligence answer two different questions, and an organisation can satisfy the first without coming close to the second.
| Level 4: Private AI | Level 5: Sovereign Intelligence | |
|---|---|---|
| Core question answered | Where does the data sit? | Can every action be proven after the fact? |
| The test | Can you show, technically, that a dataset never left your boundary? | Can you reconstruct exactly what a model did, on what basis, in a form that satisfies an external auditor without relying on the vendor's account? |
| What it protects against | Data leaving the organisation, exposure to a third party's servers | An unverifiable or unaccountable decision, inability to survive loss of a vendor or connectivity |
| What it does not guarantee | That the decision trail is tamper-evident or independently checkable | Nothing further; this is the top of the current framework |
An organisation that owns its infrastructure but cannot produce a tamper-evident, action-by-action record of what a model did is at Level 4, not Level 5, no matter how much hardware it owns. The move from Level 4 to Level 5 is not a hardware upgrade; it is a verifiable, cryptographic accountability layer added on top of infrastructure that is already owned.
How do you assess your own AI maturity?
Score honestly against the gate questions below. This is a gated model, so the correct method is not to average your answers: find the lowest level at which you answer "no," and that is your current level, regardless of how advanced your answers are further down the list.
| Gate | Question |
|---|---|
| Level 1 to 2 | Do you have a single list of every AI tool and model in active use across the organisation? |
| Level 2 to 3 | Is there a named individual accountable for AI risk at executive level, distinct from whoever is accountable for AI delivery? |
| Level 2 to 3 | Is bias, safety or security testing a mandatory step before any AI system goes live, or is it discretionary? |
| Level 3 marker | Is your AI governance mapped to a recognised external framework such as NIST AI RMF or ISO/IEC 42001, or is it bespoke and undocumented? |
| Level 3 marker | Does your incident-response plan explicitly cover AI failure modes such as hallucination in a customer-facing decision, model drift or data leakage via a prompt, or only generic IT and security incidents? |
| Level 3 to 4 | Can you state with certainty where every piece of data sent to an AI model physically resides, and who else can access it? |
| Level 3 to 4 | If your primary AI vendor changed its terms, was acquired, or withdrew service tomorrow, could your AI-dependent workflows continue operating? |
| Level 3/4 marker | Is your AI cost structure predictable and capital-based, or does it scale unpredictably with usage? |
| Level 4 to 5 | Can you reconstruct, after the fact, exactly what data and reasoning led to a specific AI-driven decision, in a form that would satisfy an external auditor or regulator, without relying on the vendor's own account of events? |
| Level 4/5 marker | Does your AI capability keep functioning, and remain auditable, if external connectivity is lost? |
The inventory question is the most common failure point: organisations that believe they are at Level 3 because they have a governance committee frequently discover, once asked directly, that no one can list every AI tool in live use. If that is true for you, the honest answer is Level 1, and the fix, a complete inventory, is also the fastest lever available.
How does this map to recognised standards and regulations?
The Enterprise AI Maturity Model is designed to sit alongside the standards an assessor will actually ask about, not replace them.
NIST AI RMF
The NIST AI Risk Management Framework (AI RMF 1.0), published January 2023, is voluntary and US-originated but globally referenced. It defines four functions applied iteratively across the AI lifecycle, not as one-off steps: Govern, Map, Measure, Manage. Alignment to these four is one of the clearest markers of genuine Level 3 governance.
ISO/IEC 42001
ISO/IEC 42001:2023 is the first international AI management-system standard, structured like ISO 27001, across clauses covering context, leadership, planning, support, operation, performance evaluation and improvement. Unlike a self-declared policy, it is certifiable: an organisation can be independently audited against it, a stronger claim than "aligned to." It complements, rather than substitutes for, ISO 27001 (information security) or a SOC 2 report (an audit report, not a management-system standard).
EU AI Act
High-risk obligations under the EU AI Act were originally due to apply from 2 August 2026. Following the Digital Omnibus, that date has moved: stand-alone Annex III high-risk obligations are deferred to 2 December 2027, and high-risk AI embedded in regulated products under Annex I is deferred to 2 August 2028. Article 50 transparency obligations largely stay on the original schedule. Treat the deferral as a build window, not a reprieve: the underlying proof requirements survive the move intact, so the extra time is best used to build the audit and governance capability properly rather than to delay starting.
Where does Mickai fit into this model?
Mickai's Sovereign Intelligence Operating System is one credible route to Level 4 and Level 5, rather than building the private-and-verifiable stack from first principles. The model above is intentionally vendor-neutral: Level 5 is a standard other credible vendors and internal engineering teams can also aim for, and the test for reaching it, an independently verifiable, tamper-evident record of what a model did that survives loss of any single vendor relationship, is the same regardless of who builds the substrate.
The infrastructure that the top level of this model actually requires is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
What are the levels of AI maturity in an enterprise?
The Enterprise AI Maturity Model defines five levels: Experimentation (isolated pilots, no shared standards), Automation (AI embedded in workflows, oversight still manual), Governance (inventoried and risk-classified, aligned to a recognised framework), Private AI (infrastructure owned or exclusively controlled, data stays inside the boundary), and Sovereign Intelligence (owned and independently verifiable end to end).
What is the difference between private AI and sovereign AI?
Private AI answers where the data sits: infrastructure is owned or exclusively controlled, so data does not leave the organisation's boundary. Sovereign AI answers a harder question: can every material action a model took be independently reconstructed and verified after the fact, without relying on the vendor's word for it. An organisation can own its hardware and still be unable to answer the second question, which is why they sit as two separate, sequential levels.
How do I know what AI maturity level my organisation is at?
Work through the gate questions in order, starting with whether you have a single inventory of every AI tool in active use. The model is gated, not averaged: your level is set by the first gate you fail, regardless of how advanced your capabilities are elsewhere. Most organisations that assume they are further along fail the inventory or the auditability gate first.
Is ISO 42001 the same as an AI maturity model?
No. ISO/IEC 42001 is a certifiable management-system standard covering leadership, planning, support, operation and continual improvement of AI governance, similar in structure to ISO 27001. It is strong evidence an organisation has reached Level 3 governance, but it is not a five-stage maturity scale and does not address infrastructure ownership or end-to-end verifiability, which Levels 4 and 5 measure.
Does the EU AI Act deadline of 2 August 2026 still apply?
No. Following the Digital Omnibus, stand-alone high-risk obligations under Annex III were deferred to 2 December 2027, and high-risk AI embedded in regulated products under Annex I was deferred to 2 August 2028. Article 50 transparency obligations largely remain on the original schedule. Treat the deferral as extra time to build proper governance and audit capability, not as a reprieve.
What triggers a move from AI governance to private AI infrastructure?
Four requirements typically trigger the move from Level 3 to Level 4: data residency or sovereignty, predictable capital-based cost instead of unpredictable usage-based pricing, continuity for a regulator or critical-infrastructure customer that will not accept an external dependency, and a competitive need to keep proprietary data and model tuning off a third party's servers. Any one is usually sufficient to force a board-level decision.