# How AI-Ready Is Your Company? The Road.MAP for AI Maturity Model

> An AI maturity model with 8 dimensions and 5 stages: where your company stands with AI, why a profile beats a single score and what comes next.

- URL: https://seiler.it/themen/ki-reifegrad/en.html
- Author: Dr. Sven Seiler (https://seiler.it/)
- Type: Pillar / Topic Hub
- Language: en
- Updated: 2026-09-27

TL;DR

- Road.MAP for AI is a maturity model for adopting AI in companies: 8 dimensions × 5 stages, from Experiment to Agentic Organization.

- Developed by Dr. Sven Seiler at Storm Reply, together with colleagues. Current release: version 2.0 (August 2026).

- The result is a profile, not a single score: the weakest dimension sets the pace for all the others.

- Only two of the eight dimensions are technology (Infrastructure & Permissions, Security & Risk). The rest is steering, value and people.

- From stage 3 on, only evidence counts: without a nameable artefact, the rating is capped at stage 2.

## What is an AI maturity model?

**An AI maturity model answers the question “Where do we stand with AI?” with a finding instead of a gut feeling.** It breaks AI adoption into dimensions, describes observable stages for each one and so shows where a company stands and what the next step is.

Road.MAP for AI is the maturity model I developed at Storm Reply together with colleagues. It started from a detailed analysis of six existing maturity models. Three findings surprised us: none of the six sources has a cost dimension, none has an agentic target stage, and none separates organisational maturity from process suitability.

> AI amplifies what is already there. If you are at stage 4 in five dimensions and at stage 1 in one, you don’t get the average – you get the stage 1 problem at five times the speed.

That is the reading rule the whole model revolves around.

## The five stages of AI maturity

1. Experiment – private accounts, copy and paste, no list of what is even running.

1. Pilot – policy, budget and use-case list exist, but none of it is enforced.

1. Controlled Rollout – gateway, SSO, limits: the rules take effect in the system, not in a document.

1. Scaled Operations – measured and charged back, audit as daily business.

1. Agentic Organization – agents take over workflows, people lead through goals and guardrails.

The hardest line runs between stage 2 and stage 3, between “decided” and “enforced”. Everything is decided, nothing is enforced: that is stage 2 in one sentence. Stages apply per dimension. A company is not at one stage but at eight, and rarely at the same one. Stage 5 is not the goal everywhere either; the target depends on the business.

## The eight dimensions

Each dimension has a guiding question and, for each stage, a short anchor that lets you recognise your own stage:

| Dimension | Stage 1 Experiment | Stage 2 Pilot | Stage 3 Controlled Rollout | Stage 4 Scaled Operations | Stage 5 Agentic Organization |
| --- | --- | --- | --- | --- | --- |
| Governance & Legal — Who may do what, with which model, under which rule? | No binding rule in place. | Use policy adopted and communicated. | Only approved models are technically reachable. | Every production use case is classified and auditable. | Rules exist as code, evidence is produced automatically. |
| Cost & Steering — What does AI cost, who is accountable for it, how is it capped? | Costs are unknown. | Budget is set but not steered. | Cost per use case is visible, limits bite technically. | Costs are charged back per use case and user. | Cost-benefit steering runs automatically at runtime. |
| Infrastructure & Permissions — How does AI run – technically, securely and across the whole company? | Use through SaaS front ends only, no integration. | First integration built, key model unresolved. | Central platform with SSO and server-side authentication. | The agent acts on behalf of the user and inherits their rights. | Agent-to-agent with an unbroken permission chain. |
| Security & Risk — What happens when things go wrong – and would anyone notice? | No risk view; inputs reach third parties unchecked. | Risks are named, controls are missing. | Injection and leakage controls take effect technically. | Agent runs logged, incident process rehearsed. | Red teaming and attack detection run in production. |
| Knowledge & Data — What does the AI draw on – and at what quality? | Context arrives by copy and paste. | Retrieval on a single source. | Several sources via connectors, permission-aware. | Company-wide knowledge hub, quality is measured. | Knowledge is available as a service to people and agents. |
| Organization & Enablement — Who can handle it – and who owns running it? | Lone enthusiasts, nobody is accountable. | Voluntary sessions, accountability unsettled. | Learning paths per role, owners per use case. | Binding curriculum, operating model in place. | Learning and ownership sustain themselves in operations. |
| Culture & Change — Are people taking up AI – and who clears the resistance out of the way? | Mood unknown, worries circulate unmanaged. | Worries are known, support is sporadic. | Change support per rollout, leaders visibly use AI. | Standing change programme, adoption measured and steered. | Change carries itself, the workforce asks for AI. |
| Use Cases & Value Contribution — What is AI working on – and how does anyone know it pays off? | Isolated experiments, value merely asserted. | Use-case list without a value criterion. | Prioritised by value and feasibility, targets per case. | Benefit measured per case, portfolio actively steered. | Cases arise from process data, benefit tracked continuously. |

_Road.MAP for AI: eight dimensions × five stages, each cell showing the stage anchor._

Organization & Enablement and Culture & Change started out as one topic. We split them because they answer two different questions: whether people *can* work with AI, and whether they *want* to. A team can be perfectly trained and still work around the tool.

## Why a profile instead of a single score?

An example from the self-check: 3.4 out of 5 sounds like solid AI maturity. The profile behind it shows four of eight dimensions in scaled operations, but Governance & Legal stuck at stage 2. The policy is adopted, but it lives in a document, not in the technology. Every new use case waits at the same brake.

The average smooths away exactly the imbalance that matters. The profile shows it, and the bottleneck tells you where to start. That is why the model also caps a dimension: it cannot be at stage 4 if one of its core questions is at stage 2.

## How is maturity assessed?

- Self-check: 16 questions, about five minutes – for a first orientation.

- Assessment: 128 questions, role-based. Each role only answers what it can judge.

- Behaviourally anchored answers: every core question has five observable state descriptions instead of a number scale. The chosen option is the stage.

- Evidence requirement: from stage 3, a rating only counts if a nameable artefact exists – a policy, a dashboard, a log, a role description. Without evidence, the rating is capped at stage 2. Conversations are not evidence.

- Several voices: if answers to the same question differ by two stages or more, that is a finding in its own right: a perception gap.

## The methodological foundation

The model is not made up. Its central design decisions rest on established frameworks:

- Dimensions along the Technology–Organization–Environment framework[^1].

- Stage logic following CMMI[^2] and ISO/IEC 15504[^3] (SPICE, now ISO/IEC 330xx): a stage only counts once its characteristics are met.

- Answer scales as Behaviourally Anchored Rating Scales[^4].

- Acceptance and culture via UTAUT/TAM (Venkatesh et al., 2003[^5]; Davis, 1989[^6]) and psychological safety[^7].

- Governance and security cut against the EU AI Act[^8], ISO/IEC 42001[^9] and the NIST AI RMF[^10] – so that stages 3 to 5 are designed to connect to audits.

The limits are part of it: the question batteries lean on validated scales but are not validated in this combination themselves. And stage 5 is hard to evidence in practice because too few organisations are there. Its anchors are constructed, not observed.

## And software development?

Software development has its own map: how far may AI agents work autonomously in each step, and how far does verification carry? The guiding principle there: autonomy only as far as verification carries. More on the [Agentic Engineering](/themen/agentic-engineering/en.html) topic page.

## Further reading

### Agentic Engineering

Using AI agents in software development production-ready: specification, guardrails, new roles.

### Agentic AI

What sets autonomous AI agents apart from chatbots and how they work in companies.

### AI-Powered Software Development: 2025 to 2030

Status, research and outlook – tools, agents, governance.

## Frequently asked questions about AI maturity

What is Road.MAP for AI?

Road.MAP for AI is a maturity model for adopting AI in companies. It rates eight dimensions – Governance & Legal, Cost & Steering, Infrastructure & Permissions, Security & Risk, Knowledge & Data, Organization & Enablement, Culture & Change, and Use Cases & Value Contribution – on five stages each. It was developed by Dr. Sven Seiler at Storm Reply, together with colleagues.

What are the stages of AI maturity?

Five: Experiment, Pilot, Controlled Rollout, Scaled Operations and Agentic Organization. Stages apply per dimension, so a company has eight stages, not one. The biggest hurdle lies between stages 2 and 3, where decided rules become technically enforced ones.

Why is there no overall score?

Because an average hides exactly the imbalance that is the problem. AI amplifies what is already there: the weakest dimension slows down all the others. The result is therefore a profile across eight dimensions, and the weakest one is the bottleneck to start with.

Does every company need to reach stage 5?

No. Stage 5, the Agentic Organization, is not the goal everywhere. Which target stage makes sense per dimension depends on the business. That is why the assessment captures the target state as well as the current one.

How does Road.MAP for AI differ from other AI maturity models?

Three things were missing from all six models we analysed: a dimension of its own for cost and steering, an agentic target stage, and the separation of organisational maturity from process suitability. On top come the evidence requirement from stage 3 and the absence of an overall score.

How is AI maturity assessed?

For orientation with a 16-question self-check (about five minutes), in full with a role-based assessment of 128 questions. From stage 3, a rating only counts with evidence, meaning a nameable artefact such as a policy or a dashboard.

## Sources

[^1]: Tornatzky, Louis G.; Fleischer, Mitchell: “The Processes of Technological Innovation”, Lexington Books, Lexington (MA), 1990. ISBN 0-669-20348-3. [openlibrary.org](https://openlibrary.org/books/OL2207473M/The_processes_of_technological_innovation)

[^2]: CMMI Product Team: “CMMI for Development, Version 1.3” (CMU/SEI-2010-TR-033), technical report, Software Engineering Institute, Carnegie Mellon University, 2010. DOI: 10.1184/R1/6572342.v1. [doi.org](https://doi.org/10.1184/R1/6572342.v1)

[^3]: ISO/IEC: “ISO/IEC 15504-2:2003 Information technology — Process assessment — Part 2: Performing an assessment”, standard, 2003 (withdrawn; superseded by the ISO/IEC 330xx series). [iso.org](https://www.iso.org/standard/37458.html)

[^4]: Smith, Patricia C.; Kendall, Lorne M.: “Retranslation of expectations: An approach to the construction of unambiguous anchors for rating scales”, Journal of Applied Psychology 47(2), pp. 149–155, 1963. DOI: 10.1037/h0047060. [doi.org](https://doi.org/10.1037/h0047060)

[^5]: Venkatesh, Viswanath; Morris, Michael G.; Davis, Gordon B.; Davis, Fred D.: “User Acceptance of Information Technology: Toward a Unified View”, MIS Quarterly 27(3), pp. 425–478, 2003. DOI: 10.2307/30036540. [doi.org](https://doi.org/10.2307/30036540)

[^6]: Davis, Fred D.: “Perceived Usefulness, Perceived Ease of Use, and User Acceptance of Information Technology”, MIS Quarterly 13(3), pp. 319–340, 1989. DOI: 10.2307/249008. [doi.org](https://doi.org/10.2307/249008)

[^7]: Edmondson, Amy: “Psychological Safety and Learning Behavior in Work Teams”, Administrative Science Quarterly 44(2), pp. 350–383, 1999. DOI: 10.2307/2666999. [doi.org](https://doi.org/10.2307/2666999)

[^8]: European Parliament and Council: “Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)”, OJ L, 2024/1689, 12 July 2024. [eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)

[^9]: ISO/IEC: “ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system”, standard, 2023. [iso.org](https://www.iso.org/standard/42001)

[^10]: National Institute of Standards and Technology (Tabassi, Elham): “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”, NIST AI 100-1, 26 January 2023. DOI: 10.6028/NIST.AI.100-1. [doi.org](https://doi.org/10.6028/NIST.AI.100-1)
