AIR FOR IT

AI runs through your stack whether you govern it or not

AIR places your IT function on a six-tier readiness ladder, overall and per pillar, so you see where AI is an asset and where it is exposure.

Shadow AI, agentic tooling, and AI-assisted code are already inside your environment, and the gap between teams that govern them and teams that hope is widening every quarter.

What AIR measures

Five pillars, read for IT.

The same five pillars of AI readiness, framed in the work, systems, and stakes that CIOs, CISOs, and IT leaders actually face.

P1Operating Model

AI is built into how IT actually runs work, from triage to resolution to provisioning, as documented systems rather than tricks a few engineers keep in their heads.

P2Service & Delivery Model

AI changes what IT produces and the value it returns, measured in resolution time, self-service deflection, and delivery throughput rather than ticket volume alone.

P3Talent & Capability

AI fluency is broad and owned across the help desk, operations, security, and engineering, with roles redefined and sentiment actually measured.

P4Governance & Risk

AI use is bound by a written policy, data-loss controls, access governance, and output QC, with the standards an audit will ask for already in place.

P5Tool Standardization

The AI stack and its spend are a deliberate, owned, defensible system instead of a sprawl of shadow subscriptions nobody approved.

The AIR rating

Six tiers, Legacy to Autonomous.

AIR places IT on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.

6

Autonomous

85–100

AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.

5

Integrated

68–84

Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.

4

Operational

51–67

AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.

3

Adopting

34–50

Pockets, not a system. Real use in places, uneven and undocumented.

2

Reactive

17–33

Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.

1

Legacy

0–16

Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.

The point

One score tells you that you are behind; five tiers tell you exactly where to start.

The deep diagnostic

Every pillar, climbed for IT.

The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.

P1

Engineering Operating Model

AI in the SDLCOps & Incident ResponseReusable AssetsProcess InstrumentationKnowledge & RunbooksService Desk & Internal Support
LegacyAutonomous
Legacy
Engineers write code, triage incidents, and close tickets by hand with no AI assistance.
Autonomous
Self-improving agents code, remediate, and resolve requests, with humans setting intent and guardrails.
P2

Platform, Security Posture & Business Enablement

Platform & ReliabilitySecurity PostureBusiness EnablementCost & CapacitySelf-Service & Internal Products
LegacyAutonomous
Legacy
Platform, security, and delivery run on manual effort, with AI contributing nothing to outcomes.
Autonomous
An AI-native platform defends, scales, and enables the business with a compounding, defensible edge.
P3

Talent & AI Capability

AI Fluency BreadthOwnership & RolesReskilling & EnablementPrompt & Agent SkillsSentiment & Culture
LegacyAutonomous
Legacy
The team has no AI fluency, no AI roles, and treats the tools with suspicion.
Autonomous
The team is an AI-native talent magnet whose capability compounds and redefines its roles.
P4

Governance, Security & AI Risk

AI Policy & StandardsData Protection & DLPOutput QC & ValidationShadow-AI GovernanceAccess & Identity ControlFramework Alignment
LegacyAutonomous
Legacy
There is no AI policy, no DLP for AI, and unmanaged shadow-AI across the team.
Autonomous
Risk controls are AI-native and self-adapting, turning governance into a competitive and trust advantage.
P5

AI Tool Standardization & Stack

Stack CoherenceOwnership & ProcurementSpend & ROI VisibilityIntegration & InteroperabilityStack Defensibility
LegacyAutonomous
Legacy
There is no AI stack, no budget line, and no owner for AI tooling.
Autonomous
A proprietary, defensible AI platform built on the stack creates a compounding moat.
Governance and compliance

Where the rules bite.

How IT's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.

RegimePillarWhat AI readiness requires
NIST AI Risk Management Framework (AI RMF 1.0)P4Govern, map, measure, and manage AI risk through a documented IT AI policy and named ownership.
ISO/IEC 42001 (AI Management System)P1Operate AI through a managed system with defined processes, roles, and continual improvement, not ad hoc use.
SOC 2 (Trust Services Criteria)P4Evidence logical access, change-management, and monitoring controls that extend to AI tools and their output.
Data-loss prevention and access controlP4Enforce DLP and least-privilege so confidential data and credentials never reach unsanctioned AI tools.
Shadow-AI governanceP5Inventory and gate every AI tool and license so unsanctioned subscriptions are visible and controlled.
ISO/IEC 42001 (AI Management System)P3Assign competence and awareness obligations so staff operating AI are trained and accountable.

Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current regulation and standards with qualified counsel.

The stakes

What stalling looks like.

Shadow AI in the environment

Engineers and staff route confidential tickets, logs, and source into consumer AI tools no one sanctioned. The first honest discovery surface in an incident, not a review.

Secrets and confidential data leaking to models

Credentials, customer PII, and access tokens reach external models through prompts and connected agents. Without DLP and enterprise tooling, the data is gone the moment it is pasted.

AI-generated code and changes ship unvetted

AI-assisted code and infrastructure changes merge without a checkpoint that catches confidently wrong output, insecure patterns, or hallucinated dependencies before they reach production.

Agentic tools with standing access

AI agents hold broad, long-lived credentials and act across systems with no least-privilege scoping or audit trail, turning one compromised tool into lateral movement.

No audit-ready AI governance

When a customer, auditor, or regulator asks how IT governs AI, there is no policy, inventory, or evidence to produce, stalling deals and renewals that depend on demonstrable controls.

Start now

Signature quick wins for IT.

Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.

P5

Run an AI tool and access audit

Inventory every AI tool, agent, and license touching IT systems, who owns each, what data it can reach, and what it costs, then name one stack owner.

Days
P4

Ship a one-page AI usage policy

Publish a one-page policy naming sanctioned tools, prohibited data classes, and the rule that secrets and customer data never reach unsanctioned AI, and require everyone to acknowledge it.

Days
P4

Add a checkpoint on AI-generated changes

Require a defined review gate so AI-assisted code and infrastructure changes are scanned and approved before merge, catching insecure or hallucinated output early.

Weeks
P1

Turn one runbook into an AI-embedded SOP

Pick one high-volume workflow like incident triage or access provisioning and document the exact step where AI plugs in as a shared, versioned SOP.

Weeks
P5

Route confidential work to enterprise tooling

Stand up an approved enterprise AI tool with data-retention and access controls, then block consumer endpoints for any work involving sensitive systems or data.

Weeks
P3

Name an owner and lift the lowest-fluency team

Give AI capability a named owner with protected time and run one role-specific session for the function with the weakest fluency, usually the help desk or operations.

Days

Find out where your team stands.

The old transformation is finished. The new one is scored.