TL;DR
- AI governance maturity describes how deliberately (or accidentally) an organisation controls the way it builds, buys, and uses AI - from complete chaos to a fully embedded, board-level discipline.
- Most SMEs and mid-market businesses sit lower on the curve than they think. Using ChatGPT in the marketing team doesn’t count as “governed.”
- Maturity is usually mapped across four or five stages: ad hoc, aware, defined, managed, and optimised.
- Governance ownership is shared - legal, IT, and operations all have a stake, but someone senior needs to be accountable, not just “AI-curious.”
- The right time to start is before the first AI tool touches customer or employee data, not after an incident forces the conversation.
Table of Contents
- Why “we’re using AI” isn’t the same as “we govern AI”
- What is the AI governance maturity model?
- The five stages of AI governance maturity
- How to actually assess where you sit
- Who is responsible for AI governance in a company?
- Where should AI sit in an organisation?
- At what point should AI governance actually begin?
- Moving up the curve without grinding the business to a halt
- FAQs
- Key takeaways
Why “we’re using AI” isn’t the same as “we govern AI”
Walk into most SME leadership meetings in 2026, and someone will confidently say the business “has an AI policy.” Push a little further, and the policy usually turns out to be a single paragraph in the employee handbook, last touched a year ago, that nobody in sales or finance has actually read. Meanwhile, that same sales team is pasting client contracts into a free AI tool to summarise them, and finance is using an AI plugin inside a spreadsheet that nobody in IT approved.
This gap - between what leadership believes is happening and what’s actually happening on the ground - is the entire reason AI governance maturity models exist. A recent look at how invisible workplace AI adoption tends to be makes the same point: the problem for most organisations isn’t a lack of AI strategy, it’s a lack of AI visibility. You can’t govern what you can’t see, and you can’t measure maturity if you don’t know your actual starting point.
AI governance maturity gives that starting point a name. It’s a structured way of answering an uncomfortable question honestly: are we managing AI risk on purpose, or are we managing it by accident, one awkward incident at a time?
What is the AI governance maturity model?
An AI governance maturity model is a framework that places an organisation somewhere on a spectrum - from having no formal control over AI use at all, through to having AI governance so embedded that it’s simply part of how decisions get made, alongside financial controls or health and safety.
Different consultancies and vendors describe the spectrum with slightly different labels. Sapient’s model frames it as a progression from reactive to strategic; Data Sentinel talks about a governance “curve”; Databricks and Modulos both describe roughly four-to-five stage journeys that move from informal, siloed AI use toward centralised, continuously monitored governance. The number of stages varies by source, but the underlying logic doesn’t: maturity tracks how much of AI governance is designed versus how much is improvised.
What all of these models agree on is that maturity isn’t really about how much AI you use. A business running a handful of carefully vetted AI tools with clear ownership can be more mature than a business running dozens of ungoverned tools across every department. Maturity is about control, not volume - which is a distinction worth sitting with, because it’s the one most leadership teams get backwards.
It’s also worth separating “AI governance maturity” from plain old “AI readiness,” even though the two get used interchangeably. A breakdown of what AI readiness actually involves is really about foundational capability - data quality, infrastructure, skills. Governance maturity is about control and accountability once that capability exists. A business can be technically ready to deploy AI and still be governance-immature, and that combination is where a lot of the real risk sits.
The five stages of AI governance maturity
Most maturity models compress into a five-level structure, even if the exact naming differs between Sapient, Data Sentinel, and Databricks. Here’s a practical version that maps closely to what those frameworks describe.
| Stage | What it looks like | Typical risk profile |
|---|---|---|
| 1. Ad hoc / Unmanaged | AI tools are adopted by individuals or teams with no central visibility, no policy, and no approval process | High - data leakage, no accountability, no idea what’s actually running |
| 2. Aware / Reactive | Leadership knows AI is being used, a basic acceptable-use policy exists, but enforcement is inconsistent | Moderate-high - policy exists on paper but isn’t operational |
| 3. Defined / Developing | Formal AI policy, an approvals process for new tools, some role clarity, but governance is still largely manual | Moderate - gaps in coverage, especially for tools introduced outside procurement |
| 4. Managed / Integrated | AI governance is built into procurement, HR onboarding, and vendor contracts; there’s a named owner and regular review cycles | Low-moderate - occasional gaps, but caught quickly |
| 5. Optimised / Strategic | AI governance is continuously monitored, tied to business strategy, and treated as a competitive differentiator, not just a compliance cost | Low - proactive, adaptive, audited |
A couple of things worth noting about this table. First, jumping straight from Stage 1 to Stage 4 rarely works - organisations that try to bolt on a full governance framework overnight tend to create so much friction that staff quietly route around it, which just pushes AI use back underground. Second, very few SMEs sit above Stage 3, and that’s not a criticism - it’s simply where most mid-market businesses realistically are, especially if they’ve adopted AI tools organically rather than through a planned rollout.
Where this becomes genuinely risky is the space between Stage 1 and Stage 2, which is exactly where shadow AI tends to flourish. Employees reach for whatever gets the job done fastest, and the scale of unapproved AI tool use inside ordinary workplaces is consistently higher than leadership expects. It’s less a rebellion and more a symptom: people will always fill a governance vacuum with whatever’s convenient.
A quick self-check
Ask three questions in your next leadership meeting and see how confidently people answer:
- Can we list every AI tool currently touching company or customer data?
- Is there a named person accountable if one of those tools causes a data protection issue?
- Would we know within a week if a new AI tool started being used across a department?
If the honest answer to any of these is “not really,” that’s a strong signal the business sits closer to Stage 1 or 2 than leadership assumed.
How to actually assess where you sit
Maturity assessments don’t need to be a six-month consulting engagement to be useful. A working self-assessment usually covers four dimensions:
Visibility - Do you actually know which AI tools are in use, by whom, and on what data? This is the foundation everything else builds on. Without it, every other governance measure is guesswork.
Policy and process - Is there a documented, current AI use policy, and does it cover procurement, data handling, and third-party AI embedded in existing software (which is often the biggest blind spot)?
Accountability - Is there a named owner for AI governance decisions, with real authority to say no to a tool or flag a risk, rather than governance being everyone’s job and therefore nobody’s?
Monitoring and review - Is governance a one-off policy document, or does it get revisited as new tools, regulations, and use cases appear? Static governance ages badly in a field that moves this fast.
Scoring each dimension honestly - even informally, on a simple low/medium/high scale - tends to be more revealing than any external audit, mostly because internal teams already know where the gaps are; they just haven’t been asked directly. Businesses that have gone through a structured AI readiness assessment often find governance gaps surface as a side effect, even when readiness was the original focus.
Who is responsible for AI governance in a company?
There’s no single universally correct answer here, and that’s part of why so many businesses end up with nobody clearly holding the brief. In practice, responsibility usually spans four groups, each owning a different slice:
- Legal and compliance typically own regulatory alignment - data protection, contractual risk, and sector-specific rules.
- IT and security own the technical controls - what tools are approved, how data flows, and how access is managed.
- Operations or a COO-level function often owns the day-to-day enforcement - making sure the policy is actually followed, not just written.
- The board or senior leadership team owns overall accountability - because when an AI-related incident happens, it’s leadership that answers for it, not the analyst who used the wrong tool.
The mistake most businesses make is treating AI governance as purely an IT problem or purely a legal problem. It’s neither in isolation. A policy that legal writes, but IT can’t enforce, is decorative. A technical control IT builds without legal input on data protection obligations can create compliance exposure that nobody flagged. The businesses that get this right tend to appoint a single accountable owner - sometimes called an AI governance lead, sometimes just given to an existing COO or Head of Legal Ops - who pulls the other functions together rather than trying to own every technical or legal detail personally.
This connects to a broader theme worth being honest about: governance and ethics aren’t the same conversation, but they overlap constantly. A practical framework for balancing AI-driven growth with responsibility is a useful companion piece here, because “who’s accountable” is as much an ethical question as an operational one - it’s about who’s answerable when an AI system produces a biased, wrong, or harmful outcome.
Where should AI sit in an organisation?
This question comes up constantly, and the honest answer is: it depends on company size, but the wrong placement is more common than the right one.
In larger enterprises, AI governance often sits within a dedicated function - a Chief AI Officer, an AI Centre of Excellence, or a cross-functional AI council reporting into the board. For SMEs and mid-market businesses, that level of structure is usually overkill, and building it is a good way to spend money on a title rather than an outcome.
What tends to work better at the SME scale is treating AI governance as a shared responsibility with a single point of accountability, rather than an entirely new department. That accountable person - often already sitting in Legal, Operations, or IT - needs enough seniority to make decisions, enough visibility to see across departments, and a direct line to leadership. Burying AI governance three layers down in IT, where it never reaches board discussion, is one of the most common structural mistakes.
It also shouldn’t sit in a silo separate from how the business already governs risk. Just as contract operations increasingly rely on AI-assisted workflows that still need a human keeping oversight, AI governance works best when it’s woven into existing risk, procurement, and compliance structures rather than treated as a brand-new, parallel system that competes for attention.
At what point should AI governance actually begin?
The honest answer: before the first AI tool goes anywhere near customer data, employee data, or a decision that affects a real person - not after.
In practice, most businesses don’t get that luxury, because AI adoption has usually already happened informally by the time anyone asks the governance question. If that’s the case for your business, the right moment to start is now, not once a “proper AI strategy” is finalised. Waiting for a perfect governance framework before addressing an already-ungoverned environment just extends the exposure window.
There are a few concrete trigger points worth treating as non-negotiable start lines if governance hasn’t begun yet:
- Before procuring any new AI tool that will touch customer, employee, or financial data.
- Before integrating AI into any process that produces a decision affecting a person, such as hiring, credit, pricing, or performance review.
- The moment you discover (and you likely will) that AI tools are already in use without approval.
- Before any AI vendor contract is signed, the vendor terms often quietly shift data processing responsibilities onto the buyer.
The UK’s regulatory backdrop makes early action more relevant than it might seem for an SME. The Information Commissioner’s Office has published detailed guidance on how UK GDPR principles apply to AI systems, covering everything from lawful basis for processing to fairness and bias mitigation - and it applies regardless of company size, the moment personal data is involved. Separately, the government’s pro-innovation approach to AI regulation puts the responsibility for interpreting AI risk on individual sectors and organisations rather than a single AI regulator, which in practice means businesses can’t simply wait for a rulebook to arrive - the expectation is that governance is already being worked out internally.
Moving up the curve without grinding the business to a halt
The instinct, once a maturity gap becomes obvious, is to over-correct - freeze all AI use, demand sign-off for every tool, route every request through legal. That response usually backfires, because it recreates the exact conditions that caused shadow AI in the first place: frustrated employees find workarounds, and visibility gets worse, not better.
A more workable path tends to follow this rough sequence:
- Get visibility first. Before writing a new policy, find out what’s actually in use. This is uncomfortable but essential - you can’t govern an unknown.
- Fix the highest-risk gaps, not all of them at once. A tool handling customer personal data unapproved is a different priority than a team using AI to draft internal meeting notes.
- Write a policy that people can actually follow. A ten-page AI policy nobody reads is worse than a one-page policy that’s actually enforced.
- Assign real ownership, with the authority to say no.
- Build review into the calendar, not just the policy document - quarterly is realistic for most SMEs; annual is usually too slow given how fast the tools change.
Technical decisions play into this, too. Businesses weighing up whether to build custom AI tools or buy off-the-shelf products often find that governance maturity should influence that decision, not the other way around - a business at Stage 1 or 2 maturity generally isn’t ready to safely build and maintain a custom AI system with all the additional oversight that requires. Off-the-shelf tools from vendors with established security and compliance credentials are usually the lower-risk starting point while governance catches up.
Security shouldn’t be treated as a separate workstream from governance, either - the two are deeply connected. The National Cyber Security Centre’s guidelines for secure AI system development are a useful reference point even for businesses that aren’t building AI systems from scratch, because the “secure by design” principles they set out - around supply chain security, monitoring, and incident response - apply equally to organisations deploying third-party AI tools, not just those developing models in-house.
One more thing worth flagging honestly: transparency about how AI systems reach decisions is becoming a governance expectation in its own right, not just a technical nicety. Anyone building or deploying AI that influences real decisions should be familiar with what explainable AI actually means in practice - because “the AI decided” is no longer a defensible answer to a customer, regulator, or employee asking why.
FAQs
What is the AI governance maturity model?
It’s a framework for assessing how deliberately an organisation manages AI risk, typically mapped across four or five stages - from ad hoc, ungoverned use through to fully embedded, continuously monitored governance tied to business strategy. It measures control and accountability, not how much AI a business uses.
You might also wonder: does every business need to reach the highest maturity level? Not necessarily. A small business with limited AI exposure may only need to reach a “defined” or “managed” stage to be adequately protected - the target level should match the actual risk the business carries, not an abstract ideal.
Who is responsible for AI governance in a company?
Responsibility is typically shared across legal/compliance, IT/security, and operations, but there should be one senior, named owner who’s accountable overall - otherwise governance tends to fall through the gaps between departments. In larger organisations, this might be a Chief AI Officer or AI council; in SMEs, it’s usually an existing COO, Head of Legal Ops, or similar role taking on the brief.
Another common question: should the board be involved? Yes - even if AI governance is operationally run by a mid-level owner, the board should receive regular visibility, because reputational and regulatory risk from AI incidents ultimately lands at the board level.
Where should AI sit in an organisation?
For SMEs, AI governance works best as a shared responsibility with a single accountable owner embedded within existing risk, legal, or operations structures - not as an isolated new department. Larger enterprises may justify a dedicated AI function, but bolting on unnecessary structure at the SME scale often creates more friction than protection.
At what point should AI governance actually begin?
Ideally, before any AI tool touches customer, employee, or financial data - but if AI adoption has already outpaced governance (which is the case for most businesses), the right time to start is now, focused on visibility first, then policy, then enforcement.
You might also wonder: Is it too late to introduce governance if AI has been used ungoverned for months? No - most organisations are in exactly this position. The priority is closing visibility gaps and addressing the highest-risk tools first, rather than treating the delay as a reason to wait for a perfect framework.
What are the 5 levels of the maturity model?
Most models describe five broad stages: ad hoc/unmanaged, aware/reactive, defined/developing, managed/integrated, and optimised/strategic. Organisations move from having no visibility or control over AI use, through documented policy and named ownership, to continuous, strategy-linked governance. Exact naming varies between frameworks (Sapient, Databricks, Data Sentinel, and Modulos each phrase the stages slightly differently), but the underlying progression - from accidental to intentional - is consistent across all of them.
Key takeaways
- AI governance maturity measures how intentional your control over AI is, not how much AI you use.
- Most SMEs sit lower on the curve than leadership assumes, largely because of ungoverned, informal AI adoption.
- Maturity typically spans five stages, from ad hoc to optimised - and the right target level depends on your actual risk exposure, not an abstract ideal.
- Responsibility is shared across legal, IT, and operations, but needs one senior, named, accountable owner.
- Governance should start now if it hasn’t already - visibility first, then policy, then enforcement, reviewed on a real cadence rather than left to age.


