AI Level 1
Some Guardrails, Some Users
Almost every organization starts here, and most do not recognize it as a stage of its own rather than a running start.
You have provisioned Copilot, Claude, or ChatGPT seats for a few curious teams — usually the ones who asked loudest. Logging is whatever your platform switched on by default, Purview or its equivalent, and nobody has yet checked what it actually captures. None of that is a failure. It is the normal shape of a first year with AI.
What defines Level 1 is what has not been decided yet. You do not distinguish between internal models running against your own data and external models that send prompts to a vendor, so one posture — or no posture — covers both. Access follows enthusiasm rather than use case, which means the people with the most to gain from AI may not have it, and some of the people who have it do not especially need it.
The other Level 1 pattern is the opposite one: you have banned AI outright. That call is usually defensible on the day it is made, and it reliably produces shadow AI — staff using personal accounts on personal devices with company data, entirely outside your logs. A ban does not reduce your exposure. It moves your exposure somewhere you cannot see it.
Either way, the constraint at Level 1 is not appetite or budget. It is that you have nothing concrete to say yes or no with. Governance is what unlocks the next level, and it is a smaller project than most teams expect.
AI Level 2
Good Governance, Limited Adoption
Level 2 is the most comfortable place to stall, because from the inside it looks like success.
The guardrails are real now. Internal and external models are separated, DLP and access rules are written against each, prompts are logged word for word, and someone owns the AI use policy. Risk has a name, an owner, and somewhere to look. If a security review was the thing holding up your rollout, that blocker is genuinely gone.
What you do not have yet is use. Most of your staff have access; only a handful open it in a given week, and the ones who do are mostly rewriting email and summarizing documents. Those are real conveniences, and they are close to impossible to attribute value to — which becomes a problem the first time someone asks what the licenses are returning.
Meanwhile your leadership team has started asking for progress in specific terms: a number, a workflow, a before and after. You probably have an adoption plan written down. It maps departments, names champions, and sketches a training cadence. It has not been executed, because executing it competes with everything else on the roadmap.
The move out of Level 2 is not more licenses and it is not more policy. It is finding a small number of use cases specific enough to measure, connected to data your models can actually reach, and owned by someone whose own job gets easier when they work.
AI Level 3
Discovering Real AI Use Cases
Level 3 is where AI stops being a tool your people have and starts being part of how the work gets done.
Your users have moved past general-purpose chat into repeatable workflows — the same task, the same shape of input, several times a week, by more than one person. That repetition is what makes something a use case rather than a clever afternoon: it can be written down, handed to a colleague, and improved instead of reinvented.
The valuable ones are connected to curated data. A model that can read your contracts, your tickets, your policies, or your product catalog answers questions no general model can. The curation work — deciding what goes in, what stays out, and how it stays current — is most of the effort here, and most of the value.
The numbers start moving in ways you can show. Power users and weekly actives roughly double quarter over quarter, and you can name the workflows driving it rather than pointing at a licensing report and hoping.
The honest caveat at Level 3 is that the wins are real but not yet widespread. They live with a set of individuals rather than in any department's standard practice, which makes them reversible: a reorganization or two departures can take the value with them.
Reaching Level 4 means taking what a few people proved and making it the default for everyone around them.
AI Level 4
Department-Level AI Fluency
At Level 4 one part of your organization has gone fluent, and it shows up on paper.
In a leading department — often support, finance, legal operations, or engineering — essentially every employee uses AI for key day-to-day tasks. Not the enthusiasts: everyone, including the people who were skeptical, because the workflow they are expected to follow now includes it and it is faster than the alternative.
You understand cost at the level of the individual use case. You know what each workflow consumes, what it returns, and which ones deserve to be expanded, and you have granular enough controls that no single team or runaway process can produce a surprise invoice. Cost stops being a reason to restrict access and becomes an ordinary input to decisions.
Your board has noticed. The process improvements are large enough to report and specific enough to attribute — cycle time, cost per case, throughput, quality — which changes the question being asked of you. It is no longer whether AI is worth investing in. It is how quickly the rest of the organization can follow.
That is the Level 4 problem: a proven pattern in one department, and four more that want it. Replication is its own discipline, and what actually transfers is the method, the training, and the governance — not the prompts.
AI Level 5
Industry Leadership in AI
Level 5 organizations are the ones everyone else in the industry cites.
The improvements are org-wide and material. You have changed how core work happens across departments rather than in a showcase team, and the results are large enough to appear in how you describe the business to the market.
Your organization has moved beyond the hype in a specific, testable sense: it can hold both sides at once. Teams know which tasks a model should own, which it should assist with, and which it should stay out of, and they make that call at scale without escalating every instance. Tradeoffs get balanced rather than argued.
Your people are asked to explain how. Leadership and practitioners alike collect invitations to forums, panels, and conferences, and increasingly to standards and regulatory conversations — because you are further along the curve than the bodies writing the rules.
And AI is a competitive advantage that shows up in growth. You win work, retain customers, or operate at margins your peers cannot match, and the reason traces back to capabilities you built deliberately rather than to a good quarter.
Level 5 is not a finish line. The frontier moves roughly twice a year, and holding position takes the same discipline that got you here.
Level 1 → Level 2
Governance Improvements
Governance is the one move on this model that reliably works, and it is the cheapest level change available to you. Five pieces, in roughly the order most organizations should build them.
AI Use Policy. Three to five pages, in plain language, that a new hire can read in ten minutes. The essential content is what is allowed, what is not, and which vendors are approved — listed by name, because “approved enterprise tools” is not a list anyone can act on. A short policy your staff actually read beats a thorough one they do not.
Data Loss Prevention. DLP and access rules established separately for internal and external models. The separation matters because the risk is not the same shape: an internal model working inside your perimeter is a permissions problem, while an external model is an egress problem. A single ruleset covering both is either too loose for the external case or too strict for the internal one, and usually both at once.
Data Management. A hardened data perimeter where inference, logs, and application data all remain inside your network. This is the control that lets you say yes to sensitive use cases later. Once the boundary is real, expanding what runs inside it is a review rather than a new project.
Logging. Word-for-word auditability across every AI interaction — not counts, not summaries, but the actual prompt and the actual response, retained and searchable. That is what you need on the day someone asks what a model was told. It is also the raw material for finding your best use cases and, just as usefully, your struggling users.
Automated Risk Scoring. Every prompt scored on a fixed scale, with real-time filtering and alerting at the high end. Scoring turns review from a sampling exercise into full coverage, and full coverage is what makes it safe to widen access rather than restrict it.
Together these take weeks rather than quarters, and they are what turns AI from an exception you approve case by case into a capability you can hand to everyone.