Most organizations can’t say where they stand on AI governance because the question is too abstract. Stages make it concrete. Find yourself below — the test for each stage is a question you can answer today.
Stage 1 · Blind
AI is in use; nobody can list where. Spend is scattered, policies are aspirational. Test: “How many AI systems do we run?” produces an argument, not a number. Exit: one gateway, first traffic flowing, first real count.
Stage 2 · Visible
The estate is mapped: systems, owners, spend, shadow AI surfaced. Nothing is enforced yet, but surprises stop. Test: you can produce the inventory in one click and defend how it’s built. Exit: data classes defined; first usage policies in alert-only mode.
Stage 3 · Protected
Sensitive data is masked inline, injections are blocked, budgets have hard stops. Governance stops being a document. Test: paste a customer record into a chatbot — does anything happen? Exit: policies tuned per team; findings flowing to the SIEM; evidence accumulating.
Stage 4 · Controlled
Autonomy is tiered and earned. Material actions route through approval queues; every system has a kill switch someone has tested. Test: name the human who approved your most autonomous agent’s current tier. Exit: promotion/demotion working as routine events, not crises.
Stage 5 · Provable
Any material decision reconstructs in minutes. Exams are exports. Supervision is continuous, and interventions are themselves evidenced. Test: an auditor picks a decision at random — how long until they hold the full story? The honest benchmark: almost nobody is here yet. The advantage goes to whoever arrives first.