How Mature Is Your AI Capability?
Organisations tend to overestimate their AI maturity because they judge it on the tools they have bought rather than on what they can reliably deliver. Fifteen questions across the five dimensions that determine whether AI initiatives succeed here.
Answer for the organisation as a whole rather than for its most advanced team. Maturity is what you can reliably repeat, not what you have achieved once.
AI Maturity Scorecard
Answer for the organisation, not for its most advanced team.
A practical self-assessment rather than a formal capability audit. It is not a substitute for external assurance where that is required. Nothing entered is recorded or transmitted.
What Maturity Actually Means
Maturity is not about how much AI you use. It is about whether you can take a business problem, choose the right approach, deliver it and know whether it worked, repeatedly.
Repeatability, not achievement
One successful pilot driven by an enthusiastic individual is not maturity. Maturity is being able to do it again, with a different team and a different problem, without depending on that person being available.
Measurement separates the levels
The clearest divide between organisations that progress and those that plateau is whether they measure outcomes. Without measurement, every discussion becomes an argument about impressions, and nothing compounds.
Governance enables rather than restricts
Organisations without AI governance move slowly, because every initiative renegotiates the same questions about data and risk from scratch. Settled ground rules make teams faster, not slower.
The Five Dimensions
Fifteen questions, three per dimension. Balanced maturity outperforms strength in one area and weakness elsewhere.
Strategy and use cases
Whether AI work connects to business objectives, and whether opportunities are identified systematically rather than opportunistically.
Data foundations
Whether data is accessible, of known quality, and governed well enough to build on.
Technology and delivery
Whether you can actually build, deploy and operate something, and whether it survives the person who built it.
People and adoption
Whether staff have the skills and the willingness, and whether change is managed deliberately.
Governance and measurement
Whether decisions have owners, risks have controls, and outcomes get measured.
The Four Maturity Levels
Most Australian organisations are at level one or two. Moving up a level takes six to eighteen months of deliberate work rather than a purchase.
Level 1: Experimenting
Individuals are using AI tools independently, usually without central awareness. There is enthusiasm and some genuine value, but nothing is coordinated, measured or repeatable, and the organisation could not say what it is getting from AI.
- Typical signs: shadow usage, no policy, no measurement, no ownership
- Main risk: data governance breaches nobody knows are occurring
- Next step: establish an acceptable use position and find out what is happening
- Do not start with a large platform purchase at this level
Level 2: Piloting
One or two initiatives are running deliberately with a named owner. Governance is emerging. The main risk is pilot purgatory, a series of interesting proofs of concept that never reach production because nobody owns the transition.
- Typical signs: a successful pilot, no path to production, growing interest
- Main risk: pilots accumulate without anything reaching operational use
- Next step: take one pilot fully to production, including support and measurement
- Establish who owns a system once the project team disbands
Level 3: Operating
AI is running in production with owners, monitoring and measured outcomes. The organisation can deliver reliably. The constraint shifts from capability to prioritisation, more good ideas than capacity to build them.
- Typical signs: production systems, defined owners, measured outcomes
- Main risk: initiatives accumulating faster than they can be maintained
- Next step: formal prioritisation and a shared platform to reduce duplication
- Watch maintenance burden. It compounds quietly
Level 4: Scaling
AI capability is embedded rather than exceptional. Teams build on shared foundations, governance is proportionate and understood, and the organisation reallocates effort based on measured results rather than enthusiasm.
- Typical signs: shared platform, embedded skills, evidence-based prioritisation
- Main risk: complacency as the technology landscape shifts underneath
- Next step: focus on differentiated capability rather than general adoption
- Retire initiatives that no longer earn their maintenance cost
Next Steps
AI Use Case Prioritisation Tool
Once you know your level, work out which initiative to do next.
Prioritise use cases →AI Governance Checklist
The decisions to settle so every initiative does not renegotiate them.
Open the checklist →Frequently Asked Questions
No: it is where most Australian organisations genuinely are, and pretending otherwise is more damaging than acknowledging it. What matters is whether you are at level one deliberately or by accident. Level one with an acceptable use position, some awareness of what staff are actually doing, and a clear first initiative is a perfectly reasonable place to be. Level one with unmanaged shadow usage, no policy and no idea what data is leaving the organisation is a risk position rather than a maturity position.
Six to eighteen months of deliberate effort per level for most organisations. Moving from experimenting to piloting can be quick, because it mainly requires deciding to be intentional. Moving from piloting to operating is the hardest transition and the one where most organisations stall, because it requires production support, monitoring, ownership and measurement, none of which are exciting, and all of which are the actual work. Buying a platform does not move you up a level; delivering something that runs reliably does.
Your lowest one, almost always, because maturity is limited by its weakest dimension rather than raised by its strongest. Excellent data foundations produce nothing if no one can deliver, and strong delivery capability creates risk if governance is absent. The exception is governance: if governance is your lowest score and you are actively using AI, address it first regardless, because the exposure is accumulating while you work on anything else.
Not at levels one and two, and creating one prematurely often backfires by separating AI capability from the business problems it should be solving. A named owner with allocated time is usually sufficient early on. At level three, some dedicated capability becomes valuable for maintaining shared foundations and avoiding duplicated effort. At level four, the aim is generally the reverse, embedding capability into business teams rather than concentrating it, with a small central group maintaining the platform and governance.
It covers similar dimensions to established capability maturity frameworks but is deliberately shorter and oriented towards practical next steps rather than certification. Formal models are valuable for organisations needing external assurance or benchmarking against an industry standard. This is intended for the more common situation: a leadership team wanting a clear, honest view of where they stand and what to do about it, in fifteen minutes rather than a consulting engagement.
No. Everything runs in your browser, nothing is transmitted, and there is no email gate. The questions ask only about organisational capability, so no confidential information is requested. Screenshot the result if you want it for a leadership discussion, and feel free to use the tool without ever contacting us.
Know Your Level?
Tell us your weakest dimension and what you are trying to achieve. We will tell you the shortest path to the next level, and what to avoid buying on the way.