Engineering Operating Model
- Legacy
- Engineers write code, triage incidents, and close tickets by hand with no AI assistance.
- Autonomous
- Self-improving agents code, remediate, and resolve requests, with humans setting intent and guardrails.
AIR places your IT function on a six-tier readiness ladder, overall and per pillar, so you see where AI is an asset and where it is exposure.
Shadow AI, agentic tooling, and AI-assisted code are already inside your environment, and the gap between teams that govern them and teams that hope is widening every quarter.
The same five pillars of AI readiness, framed in the work, systems, and stakes that CIOs, CISOs, and IT leaders actually face.
AI is built into how IT actually runs work, from triage to resolution to provisioning, as documented systems rather than tricks a few engineers keep in their heads.
AI changes what IT produces and the value it returns, measured in resolution time, self-service deflection, and delivery throughput rather than ticket volume alone.
AI fluency is broad and owned across the help desk, operations, security, and engineering, with roles redefined and sentiment actually measured.
AI use is bound by a written policy, data-loss controls, access governance, and output QC, with the standards an audit will ask for already in place.
The AI stack and its spend are a deliberate, owned, defensible system instead of a sprawl of shadow subscriptions nobody approved.
AIR places IT on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.
AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.
Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.
AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.
Pockets, not a system. Real use in places, uneven and undocumented.
Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.
Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.
One score tells you that you are behind; five tiers tell you exactly where to start.
The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.
How IT's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.
| Regime | Pillar | What AI readiness requires |
|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | P4 | Govern, map, measure, and manage AI risk through a documented IT AI policy and named ownership. |
| ISO/IEC 42001 (AI Management System) | P1 | Operate AI through a managed system with defined processes, roles, and continual improvement, not ad hoc use. |
| SOC 2 (Trust Services Criteria) | P4 | Evidence logical access, change-management, and monitoring controls that extend to AI tools and their output. |
| Data-loss prevention and access control | P4 | Enforce DLP and least-privilege so confidential data and credentials never reach unsanctioned AI tools. |
| Shadow-AI governance | P5 | Inventory and gate every AI tool and license so unsanctioned subscriptions are visible and controlled. |
| ISO/IEC 42001 (AI Management System) | P3 | Assign competence and awareness obligations so staff operating AI are trained and accountable. |
Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current regulation and standards with qualified counsel.
Engineers and staff route confidential tickets, logs, and source into consumer AI tools no one sanctioned. The first honest discovery surface in an incident, not a review.
Credentials, customer PII, and access tokens reach external models through prompts and connected agents. Without DLP and enterprise tooling, the data is gone the moment it is pasted.
AI-assisted code and infrastructure changes merge without a checkpoint that catches confidently wrong output, insecure patterns, or hallucinated dependencies before they reach production.
AI agents hold broad, long-lived credentials and act across systems with no least-privilege scoping or audit trail, turning one compromised tool into lateral movement.
When a customer, auditor, or regulator asks how IT governs AI, there is no policy, inventory, or evidence to produce, stalling deals and renewals that depend on demonstrable controls.
Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.
Inventory every AI tool, agent, and license touching IT systems, who owns each, what data it can reach, and what it costs, then name one stack owner.
Publish a one-page policy naming sanctioned tools, prohibited data classes, and the rule that secrets and customer data never reach unsanctioned AI, and require everyone to acknowledge it.
Require a defined review gate so AI-assisted code and infrastructure changes are scanned and approved before merge, catching insecure or hallucinated output early.
Pick one high-volume workflow like incident triage or access provisioning and document the exact step where AI plugs in as a shared, versioned SOP.
Stand up an approved enterprise AI tool with data-retention and access controls, then block consumer endpoints for any work involving sensitive systems or data.
Give AI capability a named owner with protected time and run one role-specific session for the function with the weakest fluency, usually the help desk or operations.
The old transformation is finished. The new one is scored.