AI Readiness Assessment | Does AI Scale | Business Technology Solutions | GBQ

 Why do some companies get returns while others stay stuck in pilots?

Most mid-market artificial intelligence (AI) programs stall for reasons that have nothing to do with the technology. They stall because the organization was not ready to absorb it. The distance between companies seeing measurable returns and companies cycling through pilots or endless desktop innovations is a readiness gap, and readiness is diagnosable before the spending starts.

The U.S. Census Bureau's Business Trends and Outlook Survey (BTOS) found that in the collection period ending May 3, 2026, 37% of firms with 250 or more employees reported using AI in their business operations, against a national rate of 19.8%. Across the December 2025 to May 2026 period, national reported use ranged from 17% to 20%. Use rose measurably among firms with 20 or more employees and did not change significantly among firms with fewer than 20. BTOS is a biweekly, nationally representative survey of roughly 1.2 million U.S. employer businesses, excluding farms.

The survey asks whether a business used AI in any business function during the prior two weeks, which captures drafting, research, and internal administrative work alongside anything actually running in production. It measures exposure rather than maturity. It does not tell you, however,  whether those firms have governance, approved use cases, reliable data foundations, or any return they can point to. Adoption figures show the pace of exposure; governance and operating model evidence show maturity.

Larger firms carry an advantage in that data, but it is not the advantage most executives assume. It is not that enterprises can outspend the mid-market on technology. It is that by the time AI showed up, they already had mature data infrastructure, dedicated technology staff, and governance processes running. Governance here means the rules and ownership that decide who may use AI for what, whose data it may touch, who checks its output before anyone relies on it, and who answers for it when it is wrong. AI had something solid to sit on. For a $25 million to $500 million revenue company, closing the gap is a question of operational discipline, and it starts with an honest read on where the foundation is thin.

Before You Ask The Tool Question

Leaders who ask “which AI tool should we buy” before asking “can our data and operating model support it” end up funding pilots that never leave the sandbox. The cost is rarely the pilot itself. It is the time spent proving that AI does not work here, which makes the next initiative harder to fund and staff. The failure is rarely the tool, and it is seldom the creativity of the people using it. What is missing is underneath: data and processes that stop at department boundaries, data hygiene that will not survive contact with a production system, and the project and change management discipline required to carry a working idea from one desk to the whole company.

A readiness assessment inverts the sequence. It produces a scored maturity profile across the five dimensions that actually determine whether an AI use case can move from concept to production, and it tells you which use cases you can pursue now versus which require investment first.

Most Pilots Are Not Pilots

The word pilot implies something formal: defined scope, an executive sponsor, success criteria, and a decision at the end. Very little of what is happening inside mid-market companies right now looks like that. What is actually happening is innovation on the desktop. A controller has built a genuinely good variance analysis workflow. An analyst produces in an afternoon what used to take most of a week. Project estimators have built an app that speeds up costing client work. Someone in marketing has quietly rebuilt half a content process and told no one.

That work is real, and almost none of it reaches production across the firm. The company gets the benefit of one person's augmented output instead of the benefit of an improved process, and when that person changes roles, the capability leaves with them. It is also invisible to governance. Nobody has reviewed what data it touches, verified how its outputs are checked, or asked what happens when it is wrong in front of a client. The security exposure it creates has not been examined, and no one has worked out which regulatory obligations apply to it or whether it meets them. No one has defined how it is tracked as a company asset, or who keeps it up to date.

None of this is an argument for shutting desktop innovation down. Instead, it tells you which parts of the business are slow enough, or painful enough, that someone bothered to fix them on their own time, and which of your people are ready to lead the work. However, counting it as evidence of AI adoption is how companies conclude they are further along than they are.

 Dimension    The question it answers    What a gap costs you  
 Strategy & Governance    Do we have a clear AI vision with named outcomes, and the governance to pursue  it responsibly?    Competing departmental efforts with no shared success criteria, and AI use spreading faster than anyone can account for it  
 Data Enablement    Is our data architecture accessible, well managed, and governed securely enough to support AI workloads?    Competing departmental efforts with no shared success criteria, and AI use spreading faster than anyone can account for it  
 Technology & Tools    Do we have infrastructure capacity for AI workloads, and experience with the tooling to build and run them?    Capable infrastructure that never gets activated, because nobody has deployment or tooling experience  
 Operating Model    Can we move an AI solution into production, and keep it running once it is there?    Solutions that work once and then degrade, with no one accountable for maintaining them  
 People & Skillsets    Do we have AI skills internally or through partners, and the capacity to keep building them?    A hard ceiling on ambition that training alone will not lift  

 

AI governance is not AI strategy

The two get used interchangeably in board conversations, and they answer different questions.

Strategy decides what you are trying to accomplish: which business problems are worth solving with AI, in what order, at what cost, and what a win looks like when you get there. It is a set of choices about where to spend.

Governance decides how AI is allowed to operate once you start. Who may use it for what, whose data it may touch, who verifies its output before anyone acts on it, and who is accountable when it is wrong. It is a set of rules and owners.

They fail in opposite directions. Strategy without governance produces speed nobody can defend to a client, a regulator, or a board. Governance without strategy produces a rulebook for work nobody has decided to do. The readiness assessment scores them as a single dimension for that reason: an organization that has one without the other is not ready, and a score that averaged them separately would hide it.

 

The dimensions are interdependent, which is why assessing one in isolation misleads. Strong data with a weak operating model produces accurate outputs that never change a decision. A capable workforce with unreliable data produces confident use of the wrong answer. The scoring matters less than the pattern it exposes.  

Governance Is Cheaper Before Deployment Than After

The National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF), published in January 2023, offers a voluntary, sector-agnostic structure organized around four functions: govern, map, measure, and manage. That being said, mid-market companies do not need to adopt it in full to benefit from it.

Applying its basic questions closes most of what stalls AI projects.

  • Who owns this use case?

  • How are its outputs checked for accuracy?

  • What happens when it is wrong?

  • Where does the underlying data come from, and are we permitted to use it that way?

Addressing data quality and access controls before deployment costs less than remediating them after an output reaches a client, a regulator, or a board packet.

For companies in regulated industries, supply chain environments, or any context handling protected information, this is not optional discipline. It is the evidence you will be asked to produce.

Start Where The Results Are Measurable

Prioritize use cases that can demonstrate measurable results. Invoice and accounts payable automation, financial forecasting and variance analysis, client service triage, and preventive maintenance scheduling all clear that bar in most mid-market environments because the process is well defined and the baseline is measurable.

Early wins matter more for organizational trust than for the returns themselves. Each one makes the next, more ambitious use case easier to fund and staff.

Measure It Against The Numbers You Already Track

The common trap is measuring whether the pilot worked rather than whether it created value the business can see. Tie AI initiatives to outcomes already tracked elsewhere: margin, cycle time, forecast accuracy, customer experience. Initiatives that clear that bar are candidates to standardize and repeat. Those that do not should be retired without ceremony, and retiring them is a governance success rather than a failure.

Where To Start

AI implementation is a business planning decision before it is a technology decision. GBQ's Business Technology Solutions team runs an AI Foundation Readiness Assessment for mid-market organizations: a three-week engagement of practitioner-led interviews and evidence review producing a maturity score from 1 to 5 across the five dimensions and 15 sub-dimensions, a feasibility map showing which AI use cases your current readiness can actually support, a risk register, and a sequenced remediation roadmap. Contact a GBQ advisor to find out where your organization stands today.


Frequently Asked Questions

How do I know if my business is ready for AI?

Readiness is measured across five dimensions: strategy and governance, data enablement, technology and tools, operating model, and people and skillsets. A company is ready for a given use case when all five clear the threshold that use case requires. Many organizations are ready for some use cases and not others, which is why a single yes-or-no answer is rarely useful.

What is the NIST AI Risk Management Framework?

A voluntary framework from the National Institute of Standards and Technology that helps organizations identify, assess, and manage risks connected to AI systems across their lifecycle, organized around four functions: govern, map, measure, and manage.

How long does AI implementation take for a mid-market company?

That depends on what you mean by implementation, and the distinction is worth drawing before you budget. Establishing a scored readiness baseline is a three-week engagement: scoping and stakeholder identification, then fieldwork, then findings delivery. What follows is sequenced across three horizons, with the earliest initiatives being the prerequisites everything later depends on. Duration beyond that point is a function of which gaps the assessment surfaces rather than a standard schedule. An organization with clean, accessible data and no governance is on a very different clock than one with neither.

What is the most common AI implementation mistake?

Treating one successful pilot as proof of readiness to scale. A pilot tests whether the technology works. It does not test the data quality, governance, and change management that scaling requires.


About GBQ Business Technology Solutions

GBQ's Business Technology Solutions practice empowers the growth of our clients across six disciplines: risk management, cybersecurity, IT governance, AI and automation, data and analytics, and business systems.

If this article raised questions that you cannot yet answer about your own cybersecurity strategy, the first place to start is with a conversation. GBQ’s cybersecurity advisory services allow us to assess where your organization stands today, prioritize use cases worth your investment, and help build the governance that lets you prove what AI is returning.

To continue the conversation, schedule time with Doug Davidson, director of GBQ’s Business Technology Solutions practice. Or, contact him directly at ddavidson@gbq.com.

Net Effect is a biweekly column written by Doug Davidson, director of the firm's Business Technology Solutions, published in the firm's Bottomline newsletter. Email ddavidson@gbq.com to have your technology questions addressed in a future column.