The MIT NANDA project reviewed over 300 public AI deployments and concluded that 95% of generative AI pilots produce no measurable impact on the P&L (Pebblous 2025 aggregation of IDC, MIT, Gartner, S&P, RAND; IntuitionLabs synthesis). RAND interviewed 65 enterprise practitioners and put the broader AI failure rate above 80% (IntuitionLabs synthesis). S&P Global counted the share of companies abandoning AI initiatives at 42% in 2025, up from 17% the year before (Pebblous aggregation). Five independent research organizations now converge on the same range: roughly 70% to 85% of enterprise AI initiatives fail to deliver their expected value.
This is not a model-quality problem. The models get better every year. Inference costs have cratered by 280-fold in 18 months (Stanford HAI AI Index 2025). SWE-bench performance jumped from 4.4% to 71.7% in a single year. The bottleneck sits outside the model — inside the organization that wants to use it. Most companies answer the wrong readiness question. They ask “what AI should we buy?” before they answer “are we ready to deploy what we already have?” This article is the second question.
You will get a seven-pillar readiness model, a 35-question scorecard that synthesizes the work of MIT CISR, Cisco, Microsoft, NIST, and EU regulators, and three concrete actions to take in the next 90 days. Read it, score your company honestly, and pick one pillar to fix before you sign another AI vendor contract.

Why most companies are not AI-ready (and do not know it)
Stanford HAI’s 2025 AI Index reports that 78% of organizations now use AI in at least one business function, up from 55% in 2023. McKinsey’s 2026 State of AI survey puts the figure at 88%, while only 1% of C-suite executives describe their GenAI rollouts as ‘mature.’ Adoption is not the bottleneck. Readiness is.
The numbers from five research organizations make the gap concrete. Gartner’s 2024 prediction said at least 30% of generative AI projects would be abandoned after proof of concept by the end of 2025; the 2025 follow-up moved the goalposts for agentic AI specifically: more than 40% of agentic AI projects will be canceled by the end of 2027. IDC’s enterprise survey (sponsored by Lenovo) found that of every 33 PoCs launched by a company, only 4 reach production — an 88% failure rate. BCG’s 2024 global research concluded that 74% of companies struggle to achieve and scale AI value, and only 26% have the capabilities to move beyond proofs of concept.
Five different methodologies, five different sample sizes, the same range. If you are mapping the deployment architecture decisions behind these failures, the breakdown in AI Agents Explained: The Architecture Behind the Hype covers the underlying mechanism choices that drive the success-failure split. The signal is not the headline percentage; it is that the percentages all cluster in the 70%-85% failure band regardless of how each study measures success. When independent research converges this way, the conclusion is structural, not methodological.
Most companies are not bad at AI. They are bad at the preconditions for AI. The MIT NANDA team attributed 80% of pilot-to-production work to data engineering, governance, and integration — not modeling. Gartner put the root-cause figure for failures even higher: 85% of failed AI projects trace to data quality. The “magic demo problem” is structural: clean data in a controlled environment, dirty data in production. A financial services company built a fraud-detection POC with six months of cleaned transaction data, hit 94% accuracy, then collapsed to 67% accuracy in production and generated 3,200 false positives per day. Same model, no production readiness.
The collapse is not silent. S&P Global’s 2025 survey measured it: large enterprises scrapped an average of 2.3 initiatives each, with a sunk cost of $7.2M per cancellation. The 42% abandonment rate in 2025 was nearly double the 17% measured in 2024. AI readiness is no longer a strategic question; it is a financial-control question.
The seven-pillar readiness model: what to score
Four published frameworks anchor this article. MIT CISR’s 2025 update defines four stages of enterprise AI maturity, with the largest financial lift at the transition from Stage 2 (build pilots) to Stage 3 (industrialize AI). Cisco’s 2025 AI Readiness Index weights six pillars — Strategy, Infrastructure, Data, Governance, Talent, Culture — and identifies the 13% of “Pacesetters” who outperform on every measure. Microsoft’s AI Readiness Assessment scores seven pillars, adding Model Management and AI Strategy & Experience. The Umbrex AI Transformation Readiness Diagnostic expands to ten domains, adding Financials & Investment and Ecosystem & Partnerships. NIST’s AI Risk Management Framework layers governance on top as a cross-cutting function (Govern-Map-Measure-Manage).
Synthesizing all four, with EU AI Act and NIST AI RMF as governance anchors, the seven pillars worth scoring are:
- Strategy — does your AI plan actually exist, in writing, with measurable goals and a named executive owner?
- Data — is your data foundation clean, centralized, accessible, and documented enough to train or query against?
- Infrastructure — can your compute, network, and storage run AI workloads at scale without breaking under agent load?
- Talent — do you have people who can build, deploy, govern, and explain AI systems across the full lifecycle?
- Governance — can you trust what your AI does in production, including shadow AI, agent autonomy, and regulatory compliance?
- Culture — will the organization actually adopt AI outputs, or will middle managers route around them?
- Value Capture — can you measure ROI in dollars, not demos?
Seven pillars. Five questions each. Total possible score: 175. Below 70 means you are not ready. Between 70 and 105 means you are in the pilot stage — scale carefully. Between 105 and 140 means you can industrialize. Above 140 means you are AI-ready; your job is to lead and learn, not to buy another platform.
Pillar 1: Strategy — does your AI plan actually exist?
Cisco’s 2025 data is the cleanest single signal: 99% of Pacesetters have a well-defined AI strategy versus 58% of all companies. The 41-point gap is not a tech gap. It is a written-document gap.
A real AI strategy answers five questions in writing:
- What business outcomes does this AI investment target, expressed as a measurable metric (call center handle time reduced from 8.2 to 6.5 minutes, not “improve customer service”)?
- Who is the executive owner — by name, by title, with budget authority and quarterly review obligations?
- What is the in-or-out scope — which business units, which geographies, which use cases are explicitly approved and which are explicitly prohibited?
- What is the funding model — capital expenditure, operating expenditure, or a hybrid — and over what time horizon does ROI need to be demonstrated?
- What is the kill criterion — under what measured outcome do we stop a project, and who has the authority to make that call?
If you cannot answer all five, you do not have an AI strategy. You have an AI mood board. The good news is that 42% of failed AI projects had no agreed definition of success before they started (per S&P Global 2025). You can avoid the 42% by writing down what success means before you spend the money.
Pillar 2: Data — is your data foundation AI-ready?
The Cloudera and Harvard Business Review Analytic Services survey, fielded in October 2025, found that only 7% of enterprises describe their data as “completely ready” for AI. Twenty-seven percent describe it as “not very” or “not at all” ready. Seventy-three percent say their organization should prioritize AI data quality more than it currently does.
The top obstacles, in order: siloed data and difficulty integrating data sources (56%); no clear data strategy (44%); data quality and bias issues (41%); regulatory constraints on data use (34%). These are not advanced topics. They are the same problems enterprise data teams have been working on since the Hadoop era. The difference in 2026 is that AI makes the consequences visible: a stale customer record that was acceptable for monthly reporting now corrupts a real-time recommendation engine.
The Cisco data shows what readiness looks like in practice. Seventy-six percent of Pacesetters have fully centralized data; only 19% of all companies do. Eighty-four percent of Pacesetters have end-to-end encryption with continuous monitoring; 30% of all companies do. The readiness gap is not a tooling gap; it is a data-architecture gap that most companies have not yet closed.
The “clean sandbox fallacy” — the assumption that production data will look like POC data — kills more AI projects than any model limitation. If your data is siloed across 47 formats in 23 legacy systems, the integration cost will eat the model cost. A Fortune 500 manufacturer spent $12M on AI quality control, then $8M more on integration after discovering the production-data sprawl, then abandoned the project at $20M. Fix the data before you fix the model. For teams considering where that data physically lives — on your own hardware versus a provider — the analysis in Local AI Models in 2026 covers the deployment trade-offs.
Pillar 3: Infrastructure — can your systems run AI at scale?
Only 15% of organizations have networks fully ready for AI workloads, according to Cisco — versus 71% of Pacesetters. AI workloads are bursty, bandwidth-heavy, and latency-sensitive in ways that traditional enterprise networks were not designed for. A spreadsheet model can survive a 200ms request delay. A real-time agent loop making twenty sequential API calls cannot.
The 2025 infrastructure readiness question is no longer “do we have GPUs?” Every large enterprise has GPUs or has signed a cloud contract for them. The question is whether the rest of the stack is ready for the workload pattern. Cisco’s data points to four infrastructure readiness checks:
- Compute: do you have enough dedicated capacity for AI inference and training, separate from the contention pool that serves general business workloads?
- Network: can your internal network carry sustained AI traffic without degrading for other users, or does a model rollout slow down everyone else?
- Storage: do you have a vector store and a feature store in production, or are you running embeddings from a notebook?
- Security: do you have agent action controls (allowlists, rate limits, kill switches) wired into the production stack, or only in a policy document?
Agentic AI raises the infrastructure bar again. Only 31% of organizations say they are fully equipped to control and secure agentic AI systems; 72% are at least moderately prepared. Cisco reports that 24% of organizations can control agent actions with proper guardrails and live monitoring, versus 84% of Pacesetters. The remaining 76% are running agents in production without the observability to detect when one goes off-script. That is a Category 5 hurricane in slow motion.
Pillar 4: Talent — do you have people who can build, deploy, and govern?
Thirty-eight percent of AI project failures are caused by skill gaps, according to a 2025 multi-source analysis by Beri. The breakdown matters more than the headline. The skill gap is not “we cannot find data scientists.” It is that the role mix is wrong. Companies hire 90% for AI/ML fundamentals and 10% for domain expertise and change management. The actual job breakdown for production AI is closer to 20% AI/ML fundamentals, 40% domain expertise, and 40% change management. You cannot deploy AI into a hospital without hospital operations people on the team.
Real readiness on this pillar means having these roles staffed, not just described in a JD:
- AI/ML engineers who can deploy models to production, not just train them in notebooks
- Domain experts who can translate the business problem into the right model specification
- Platform engineers who own the inference stack, the vector store, and the agent runtime
- Evaluators and prompt engineers who own quality measurement and safety filters
- Data stewards who own data quality, access controls, and lineage documentation
- Model risk partners who own governance review, pre-launch approval, and rollback authority
- Change managers who own adoption, training, and the social process of getting humans to actually use the system
If you have only data scientists, you have a research team. You do not have a deployment team. For the prompt-engineering layer that bridges AI/ML fundamentals and domain expertise, the 2026 reality check in Prompt Engineering Isn’t Dead in 2026 covers what the role actually looks like in production.
Pillar 5: Governance — can you trust what your AI does in production?
NIST’s AI Risk Management Framework 1.0, released in January 2023 and updated through 2024, defines four functions for trustworthy AI: Govern (the cross-cutting function that infuses the other three), Map (establish context and identify risks), Measure (quantify and benchmark), and Manage (allocate risk resources and respond to incidents). It is voluntary, sector-agnostic, and the most adopted governance framework in the U.S. If your AI governance does not map to Govern-Map-Measure-Manage, you do not have AI governance; you have an AI policy document.
The regulatory layer is now binding. The EU AI Act’s high-risk obligations — Articles 9-17 for providers, Article 26 for deployers — become enforceable on August 2, 2026. The Cloud Security Alliance’s research note on the readiness gap confirms that over half of organizations lack systematic AI inventories, and the harmonized technical standards that should guide compliance arrived eight months late. If your AI system output touches anyone in the EU, you need: conformity assessments for high-risk systems, registration in the EU AI database, a quality management system, post-market monitoring, human oversight mechanisms, automated log retention for at least six months, and Fundamental Rights Impact Assessments where applicable.
The shadow AI problem is the governance emergency nobody planned for. Gartner’s 2025 survey of 302 cybersecurity leaders found that 69% of organizations either suspect or have direct evidence that employees are using prohibited public GenAI tools. Microsoft and LinkedIn’s 2024 Work Trend Index put the bring-your-own-AI number at 78% of employees. Teramind found that 68% of workers using AI tools at work intentionally hide that usage from employers. The risk is not abstract: 33% of employees have shared research data sets, 27% have shared employee data, and 23% have shared financial statements on unsanctioned AI tools (BlackFog 2025). Governance is no longer a question of what your official AI systems do; it is a question of what your employees’ unofficial AI systems are doing with your data. For a forensic look at what consumer AI tools actually retain from your prompts, see Your AI Tool Is Logging Everything You Type.
Pillar 6: Culture — will your organization actually adopt it?
McKinsey’s 2026 research found that 67% of AI project failures cite organizational resistance as the #1 barrier. BCG put a number on it earlier: AI success rests 10% on algorithms, 20% on data and technology, and 70% on people, processes, and cultural transformation. The model is the smallest variable. The culture is the largest.
The adoption failure modes are well-documented. Operations teams bypass the AI system and use manual processes. Middle managers do not enforce usage (“make it optional for now”). End users find workarounds to avoid the new system. Cisco’s data shows what readiness looks like: 91% of Pacesetters have comprehensive change management plans versus 35% of all companies. A 56-point gap, and almost entirely about humans, not technology.
Culture readiness answers five questions:
- Has the executive team publicly committed to using AI outputs in their own work, not just sponsoring AI for the rank and file?
- Do middle managers have skin in the game — bonuses or KPIs tied to adoption, not just deployment?
- Is there a sanctioned alternative for every common employee AI use case, so the path of least resistance is the approved tool?
- Is there a clear process for employees to request new AI tools, with a defined approval timeline?
- Is there a feedback loop where employee AI failures get escalated to the AI team instead of buried in the help desk?
If you cannot answer yes to all five, your culture will route around your AI strategy. The shadow AI problem is partly a symptom of culture failure: employees use unsanctioned tools because the sanctioned tool is harder, slower, or missing entirely.
Pillar 7: Value Capture — can you measure ROI?
McKinsey’s 2026 survey found only 23% of respondents see AI delivering any favorable change in costs. BCG’s 2024 report put the median expected ROI at twice as high for AI leaders versus laggards — but only 26% of companies are in a position to realize any ROI at all. The Varonis 2025 State of Data Security Report observed that 96% of organizations say data pipeline performance issues affect AI objectives, led by delays and reduced AI accuracy. The value capture problem is upstream of value capture: you cannot measure ROI if the system does not work reliably enough to produce measurable outcomes.
The “vague goal” pattern is the most common value-capture failure. Failed projects have goals like “improve customer service with AI” or “reduce costs through automation.” Successful projects have goals like “reduce average handle time from 8.2 minutes to 6.5 minutes by Q3 2026” or “cut cloud infrastructure spend by 15% ($2.3M annually) within 6 months.” The difference is specificity, not aspiration. If you cannot answer four questions — what metric improves, by how much, by when, and who owns the outcome — you are not ready to start.
Value-capture readiness means:
- A specific, measurable baseline metric before any AI investment
- A documented cost model — inference, integration, change management, retraining — for the full lifecycle
- A pre-registered kill criterion — under what measured outcome do we stop the project, and who makes that call
- A dashboard that surfaces the metric to the executive sponsor at least weekly
- A backfill plan — what manual process or alternative tool fills the gap if the AI project is killed
The kill-criterion point is the most uncomfortable and most valuable. Organizations that cannot kill failing projects burn resources, damage morale, and prevent budget reallocation. S&P Global’s data shows that the 46% of projects scrapped between proof of concept and broad adoption represent not a technology failure but a budget-discipline failure. Write the kill criterion down before you start. It will save your organization millions.
The readiness scorecard: 35 questions to ask this quarter
Five questions per pillar. Score each on a 1-5 scale, where 1 = no, we have not even started, and 5 = yes, this is documented, owned, and verified.
Strategy (out of 25)
- Is there a written AI strategy that names specific business outcomes, not aspirational goals?
- Is there a single executive owner by name and title with budget authority?
- Is there a documented in-or-out scope — which business units, which use cases, which geographies?
- Is the funding model documented, with a specific ROI time horizon?
- Is the kill criterion pre-registered — under what measured outcome do we stop a project?
Data (out of 25)
- Is the organization’s critical data catalogued with named owners, stewards, and SLAs?
- Is data lineage documented from source to AI consumption for the priority use cases?
- Are data quality metrics (completeness, accuracy, timeliness) measured and reported?
- Is sensitive data access controlled with column/row-level security and audit logging?
- Are bias and fairness audits run on training data before model deployment?
Infrastructure (out of 25)
- Is there dedicated compute capacity for AI workloads, separate from general business contention?
- Can the internal network carry sustained AI traffic without degrading other workloads?
- Is there a vector store and feature store in production, not in a notebook?
- Are agent actions controllable with allowlists, rate limits, and kill switches?
- Is end-to-end encryption with continuous monitoring in place for AI data flows?
Talent (out of 25)
- Are AI/ML engineers staffed who can deploy to production, not just train?
- Are domain experts embedded on every AI project team?
- Are platform engineers owning the inference stack and agent runtime?
- Are evaluators and prompt engineers measuring quality and safety?
- Are change managers driving adoption, training, and the human-side rollout?
Governance (out of 25)
- Is there an AI governance body with documented decision rights (RASCI) for approvals and funding?
- Are AI systems registered in an inventory with risk classification and data lineage?
- Is there a pre-launch model review process with rollback authority?
- Is there automated log retention (6+ months) for AI system decisions?
- Is there a process to detect and govern shadow AI tools across the organization?
Culture (out of 25)
- Has the executive team committed publicly to using AI outputs in their own work?
- Do middle managers have KPIs or bonuses tied to AI adoption, not just deployment?
- Is there a sanctioned alternative for every common employee AI use case?
- Is there a clear process for employees to request new AI tools with a defined timeline?
- Is there a feedback loop where employee AI failures escalate to the AI team?
Value Capture (out of 25)
- Is there a specific, measurable baseline metric before any AI investment?
- Is the cost model documented across the full lifecycle — inference, integration, change management, retraining?
- Is the kill criterion pre-registered with a named decision authority?
- Is the value metric surfaced to the executive sponsor at least weekly?
- Is there a backfill plan — what fills the gap if the AI project is killed?
Scoring bands
- Below 70 (below average per pillar): Foundations are missing. Do not start new AI investments. Fix the lowest-scoring pillars first.
- 70 to 105 (pilot-stage): You can run pilots but cannot reliably scale. Choose 1-2 use cases, instrument them carefully, and build the governance and data foundations before scaling.
- 105 to 140 (scaling-stage): You can industrialize AI across the organization. Focus on change management and value capture discipline.
- 140 to 175 (AI-ready): You are in the top 13-18% of organizations by most measurements. Your job is to lead, share learnings, and avoid the trap of over-investing in new tools when you should be deepening the ones you have.
What to do this week (the next 90 days)
Three actions, in order, before you sign another AI vendor contract.
1. Run the scorecard honestly. Pull a team of senior technical, data, and business leaders into a room for two hours. Score each of the 35 questions out of 5. Do not let anyone inflate scores. The point of the diagnostic is to find the gap, not to perform readiness. If your total is below 105, the next 90 days should be spent fixing the lowest-scoring pillar — not buying more AI.
2. Pick one pillar to fix first. The most common mistake is trying to fix all seven pillars at once. Pick the pillar with the lowest score AND the highest business impact. For most companies, that pillar is Data (Cloudera/HBR: only 7% are ready) or Governance (EU AI Act enforcement in 60 days, shadow AI everywhere). Pick one. Define a 90-day improvement goal. Get one thing measurably better.
3. Define the metric that proves ROI before you start. McKinsey’s 2026 data shows only 23% of organizations see AI delivering favorable cost change. BCG’s research shows the gap is mostly discipline, not capability. Write down, in one sentence, the metric that will prove or disprove the AI investment is working. If you cannot, you are not ready to invest.
AI in 2026 is not a question of which model to use. The models are good. The question is whether your organization is ready to deploy what the models need. Seven pillars. Thirty-five questions. One honest score. That is the readiness assessment. The rest is execution.
Frequently asked questions
What is a 7-pillar AI readiness assessment?
A structured diagnostic that scores a company’s AI maturity across seven dimensions: Strategy, Data, Infrastructure, Talent, Governance, Culture, and Value Capture. The model synthesizes MIT CISR’s four-stage framework, Cisco’s six-pillar readiness index, Microsoft’s seven-pillar assessment, NIST’s Govern-Map-Measure-Manage governance framework, and the Umbrex readiness diagnostic. Total possible score: 175 points across 35 questions. Bands: below 70 (not ready), 70-105 (pilot-stage), 105-140 (scaling-stage), 140+ (AI-ready).
How many companies are actually AI-ready in 2026?
By the most generous measurement, 18% (MIT CISR 2025 Stage 4 — “AI Future Ready”). By the strictest, only 1% of C-suite executives describe their GenAI rollouts as “mature” (Stanford HAI AI Index 2025). Cisco’s Pacesetter group is 13% of organizations worldwide. McKinsey’s 2026 survey shows 88% use AI in some function but only 44% report AI is scaling across the enterprise. The gap between adoption and readiness is the readiness story of 2026.
What is the most common AI readiness failure?
Data quality. Five independent studies converge: Gartner attributes 85% of failed AI projects to data quality problems. Cloudera and HBR Analytic Services report only 7% of enterprises say their data is completely ready for AI. Cisco’s 2025 readiness data shows 76% of Pacesetters have centralized data versus 19% of all companies. The MIT NANDA project attributes 80% of pilot-to-production work to data engineering, governance, and integration. Data readiness is the most common bottleneck and the most expensive one to fix late.
What is shadow AI and why does it matter for readiness?
Shadow AI is the use of unsanctioned AI tools (ChatGPT, Claude, Gemini, and others) by employees without IT or security approval. Gartner’s 2025 survey of 302 cybersecurity leaders found 69% of organizations suspect or have evidence that employees are using prohibited public GenAI tools. Microsoft and LinkedIn’s 2024 Work Trend Index reports 78% of employees bring their own AI tools to work; Teramind found 68% of those users intentionally hide that usage. The risk is data exposure: 33% of employees have shared research data, 27% have shared employee data, and 23% have shared financial statements on unsanctioned AI tools (BlackFog 2025). Shadow AI is a governance problem that compounds the readiness problem: even if your official AI is well-governed, your unofficial AI is leaking data.
Do we need to comply with the EU AI Act to use AI in our business?
Yes if your AI system output touches anyone in the EU, regardless of where your company is headquartered. Enforcement of high-risk obligations (Articles 9-17 for providers, Article 26 for deployers) begins August 2, 2026. The Cloud Security Alliance reports over half of organizations lack systematic AI inventories. Most companies do not need to register a general-purpose AI model, but anyone deploying AI in HR, lending, education, biometric identification, or critical infrastructure needs compliance: conformity assessments, EU AI database registration, quality management systems, human oversight mechanisms, automated log retention of at least six months, and Fundamental Rights Impact Assessments where applicable. The harmonized technical standards to guide compliance arrived eight months late, compressing timelines further.
Related reading
If you are working through the seven-pillar readiness model, these posts from AI Made cover the dimensions in depth:
- Which AI Tool Should I Use in 2026? An Honest Decision Guide — for the Strategy pillar, before you commit to a platform.
- How to Use AI for Your Business in 2026 (Practical Playbook) — for the use-case selection work that comes after the scorecard.
- Your AI Tool Is Logging Everything You Type — for the Governance pillar’s data-protection dimension.
- RLHF: The Plain-English Guide to How AI Models Learn — for the Talent pillar’s understanding of how models are trained.
- The 2026 AI Pricing Guide: What Every AI Tool Actually Costs — for the Value Capture pillar’s cost-modeling work.