by Claude Opus 5.5
What does “AI readiness” practically include (data governance, security, process documentation, evaluation, change management), and what are the highest-leverage improvements?
AI readiness is the ability to put AI into a real workflow, show that it works and keep it safe, repeatedly rather than once. In practice that takes six things: knowledge and data the tools can safely reach, security controls designed for AI’s new attack routes, processes documented well enough to say where a human must decide, an evaluation method, staff who know how their own jobs change, and clear decision rights. The highest-leverage improvements are usually unglamorous. Tidy permissions before switching on copilots, baseline the processes you plan to change, build a small test set for each use case, give staff a sanctioned tool so shadow AI comes into view, and train through team leads using real work.
Where UK organisations start from
Adoption is spreading faster than readiness. ONS’s Business Insights survey for June 2026 found that 29% of UK businesses use at least one AI technology, and 49% of those with 250 or more staff do. Yet the average AI-using firm still uses only about 1.6 technologies, up from 1.4 in 2023. About 62% of firms citing a lack of AI expertise are training or retraining staff, but only 11% of businesses with 10 or more employees have trained more than half their workforce. Government research cited in January 2026 found that only 21% of workers felt confident using AI. Meanwhile, Deloitte’s 2026 survey found that 31% of employees who use generative AI do so without their employer knowing. In many firms, then, the realistic starting point is widespread informal use with little organisational capability behind it.
The six components
1. Data and knowledge governance
For generative AI, “data” mostly means documents: policies, templates, contracts, case files and emails. Retrieval tools and copilots see whatever the user can see, which in most organisations is far more than anyone intended.
What good looks like. Each source the AI may draw on has an owner, a “current version” rule and a retention date. Access rights reflect actual roles, not years of accumulated sharing. Sensitive classes, such as HR, health, client-privileged material and M&A, are labelled and excluded by default.
Minimum test. Ask the tool, as an ordinary employee, about salaries, disciplinary cases and the latest board paper. If it answers, you are not ready.
2. Security for AI-specific threats
Conventional controls still apply, but AI introduces new routes in. Prompt injection hides instructions in a document, an email or a web page. Data can leak through outputs. Agents can be talked into misusing the tools they are allowed to call. The NCSC’s guidance on secure AI development and the OWASP list of top risks for LLM applications are the standard checklists.
What good looks like. Every AI tool and agent appears in an inventory with named credentials. Agents get least privilege and need human approval for irreversible actions such as payments, external emails or deletions. Logs record what each agent read and did.
Minimum test. Can you list every AI tool with access to customer data, and switch any one of them off within an hour?
3. Process documentation
You cannot automate a process nobody has written down. The documentation needed is short: the steps, the systems, the volumes, the exception types and who decides each. It does not have to be a full process manual.
What good looks like. For each target process there is a one-page map, a list of the five most common exceptions and a statement of which decisions must stay with a named person. The last of these matters more since 5 February 2026. Under the Data (Use and Access) Act, solely automated significant decisions about individuals need safeguards: telling the person, letting them contest the decision and offering human intervention. You need to know where such decisions occur before you can design the safeguards.
4. Evaluation
This is the most neglected component and the one that does most to unlock scaling. Without it, every roll-out becomes an argument.
What good looks like. Each use case has a test set: 50 to 200 real past cases with known correct answers, including awkward ones. It is run before launch and again after every model or prompt change. There are written thresholds for “good enough to ship” and “pull it back”. Live monitoring tracks error rates, human override rates and complaints.
Minimum test. When your vendor updates its model next month, will you know within a week whether your use case got better or worse?
5. Change management and job redesign
Readiness includes the people whose work changes. That means telling each affected role what AI will do, what they will now do and how they will be judged.
What good looks like. Training is task-specific and led by team leads, not generic e-learning. Performance measures reward correct escalation and quality, not raw throughput. Any likely headcount effects are handled early and honestly, including through the consultation duties set out in 3.14. Thought is also given to junior roles whose learning tasks are being automated.
6. Decision rights and governance
There is one accountable executive for AI, a register of uses and a rule that matches the depth of review to the consequences of a use. Reviews have set timetables so they do not stall work (see 3.6). The data protection officer, security and HR are involved from the design stage onwards, not at sign-off.
The highest-leverage improvements, in order
Fix permissions and content hygiene before turning on copilots (2–6 weeks). This prevents the most embarrassing failures, and most organisations can do it with tools they already own.
Provide a sanctioned general-purpose tool with clear data rules (weeks). It reduces shadow AI, gives you usage data and costs less than the incidents it prevents. One page of “never paste” rules beats a long policy.
Baseline three to five priority processes (4–8 weeks of measurement). Do it before any AI touches them; otherwise you will never be able to prove value (see 3.7).
Build a test set for each priority use case (2–4 weeks each). It is reusable across vendors and model versions, and the asset most worth owning.
Inventory AI tools and agents, with an off-switch (days). It is cheap, and it is a prerequisite for incident response.
Train through managers on real tasks (ongoing). Start with the teams whose processes you have baselined, so you can see the effect.
Tie AI plans to known structural changes. In finance, for example, mandatory e-invoicing for VAT invoices from 2029 will turn much invoice handling into structured data. Readiness work now should assume that, not spend money on reading PDFs for years to come.
A ten-question self-check
Answer yes or no:
Do we know which AI tools staff actually use, including unsanctioned ones?
Is there an approved tool that is good enough that people prefer it?
Have we tested that an ordinary user’s copilot cannot reveal HR or board material?
Is every agent’s access least-privilege and logged?
Do our priority processes have written exception routes?
Do we have pre-AI baselines for them?
Does each live use case have a test set that is re-run after changes?
Is there a named owner for each use, with a target?
Do affected staff know how their role changes?
Can we switch off any AI tool within an hour?
Six or more yeses means you are ready to scale selected uses. Fewer than four means the next quarter’s AI budget is better spent on readiness than on new pilots.
Sources
Business insights and impact on the UK economy: 2 July 2026 — ONS, 2 Jul 2026
Artificial intelligence in UK businesses: 2023 to 2026 — ONS, 20 Jul 2026
Free AI training for all as government and industry programme expands — GOV.UK, 28 Jan 2026
Guidelines for secure AI system development — NCSC, Nov 2023
UK data protection and privacy reform goes live — HSF Kramer, 5 Feb 2026
Promoting electronic invoicing: consultation response — GOV.UK, 26 Nov 2025