• AI ADOPTION
From One Workflow to Org-Wide: What AI Maturity Actually Looks Like Two Years In
The first two years of enterprise AI have produced a strange corporate theatre. Every company seems to have an AI story. Very few have an AI operating model.
Scattered Activity
Tools · pilots · licences
Prompting · experimentation
Local productivity
Dashboard adoption

Organisational Capability
Redesigned workflows
Clear accountability
Practical guardrails
Measurable outcomes
By Suchetana Bauri · Published 10 September 2026 · 20 Min Read
Key takeaway
AI maturity is not the point at which everyone has a licence. It is the point at which people can no longer sensibly describe AI as a side project.
What you’ll learn
01
Why rollout dashboards mislead
02
What genuine adoption requires
03
The five shifts from adoption to capability

• 01 / The maturity myth
The maturity myth
Corporate technology programmes have long had a fondness for maturity models: neat ladders promising a clean ascent from “initial” to “optimised”. They are useful right up to the point where they become decorative.
AI maturity is not a score awarded for having a steering committee, a model inventory or a colourful dashboard. Nor is it the number of pilots completed, prompts written, employees trained or vendors contracted. It is a lived organisational condition.
You can see it in ordinary work. A frontline employee knows which AI tool they are allowed to use, what information they may put into it, when an answer must be checked and how to report a failure. A manager can explain who owns an automated decision and what happens when the system is wrong.
Most importantly, the organisation has made choices. It has decided where AI should not be used, where human judgement remains non-negotiable and where automation is genuinely worth the operational and governance cost.
A thousand employees using a chatbot independently may create a lot of activity. They do not necessarily create a more capable organisation. The real test is not, “Can people use AI?” It is, “Can the organisation reliably produce better work with it?”
“Use AI everywhere” is not a strategy; it is an abdication of strategy.
AI IS WIDESPREAD. MATURITY IS NOT.
88%
Use AI regularly in at least one function. Only around a third have scaled it across the enterprise.
Source: McKinsey, 2025
• 02 / The shift from tool to workflow
The shift from tool to workflow
A workflow is simply how work gets done: who starts it, what information they need, what decisions they make, what they hand off, which systems they use, where it stalls and how anyone knows the result is good.
Take a communications team producing a briefing for senior leaders. The immature use case is familiar: an individual uses a general-purpose assistant to turn notes into a draft. It may save 20 minutes. It may also create a polished generic document with invented details, unclear sources and the same old approval bottleneck at the end.
The more mature workflow begins with an approved source pack. AI classifies feedback, retrieves prior material and assembles a first draft. A named editor remains accountable; claims link to sources; uncertain material is flagged; and the reviewer sees a concise decision log.
The difference is not a better prompt. It is a redesigned system of work. Faster production is valuable only if it creates better service, lower risk, higher quality or more capacity for important work. Workflow redesign is not a nice-to-have change-management addition. It is the work.
Begin with approved sources and clearly labelled evidence.
Keep a named editor accountable for accuracy, argument and voice.
Link claims to sources and flag uncertainty.
Measure revision cycles, factual corrections and decision speed.
Use-case type
Optimise for
Demand before scaling
Personal productivity
Time saved and first-draft quality
Clear data rules and basic training
Team workflow
Cycle time, rework and hand-offs
Process owner, metrics and integration plan
Decision support
Accuracy, fairness and oversight
Performance evidence and auditability
Automated action
Reliability, safety and recovery
Permissions, monitoring and reversal
• 03 / What maturity looks like
Five observable shifts
Stop picturing an upward staircase. Look for five shifts. They do not happen neatly or in the same order, but without them a company is probably scaling access rather than scaling capability.
AI MATURITY — Work changes, not just tool use
01 REPEATABLE WORK
Move from individual cleverness to shared methods.
02 MANAGED PORTFOLIO
Give every use case an owner, baseline and scaling decision.
03 WORKING GUARDRAILS
Put permissions, review and escalation inside the workflow.
04 SITUATED LITERACY
Build role-specific judgement through real tasks.
05 MEASURED CONSEQUENCES
Track workflow, human and business outcomes.
If one part is missing, you may be scaling access — not capability.
If results collapse when the star performer is on holiday, you do not have organisational maturity. You have a gifted user.
Make good practice repeatable: turn individual improvisation into shared, supported methods.
Manage use cases as a portfolio: give every experiment a named process owner, a baseline and an explicit decision to scale, adapt or stop.
Put guardrails into the flow of work: make permissions, review points and escalation routes clear enough to use under everyday pressure.
Teach for the role, not the tool: build AI literacy around the real tasks, risks and judgement calls people face.
Measure what changes: track workflow performance, human experience, business value and public outcomes — not activity alone.
• 04 / Governance & literacy
Disciplined permission, situated judgement
Working guardrails answer the questions people have on Tuesday afternoon: which tools are approved, what data must never enter a public system, when a person must review an output, which decisions AI may inform but not make, and who can pause an automated workflow.
The arrival of agents makes this more urgent. The risk moves from bad content to bad action. Mature governance defines permissions, spending limits, tool access, approval points, logging, monitoring, exception handling and liability.
Real literacy is contextual. A recruiter faces different risks from a finance analyst; a communications professional must assess sources, factual reliability, copyright and reputational harm. The best learning uses real tasks, seductive bad outputs, source checking and practised escalation.
CAPABILITY IS OUTPACING CONTROL
21 %
Of surveyed enterprises report mature governance for agentic AI, despite much wider plans to deploy it.
Source: Deloitte, 2026
Teach through real tasks, not abstract demonstrations.
Show both a good output and a seductive bad one.
Make escalation a sign of professional judgement.
Train managers to redesign work and assess outcomes.
• 05 / The awkward middle
The awkward middle
The hardest stage is not the first pilot. It is the awkward middle: after excitement, before institutional confidence. Different teams have bought different tools. Security has issued a restrictive memo that people work around. Employees are worried about jobs while leaders want returns but cannot agree how to measure them.
This phase is normal. The problem is pretending it is not happening. Leaders must say plainly what is changing and what is not. Change communication is not the email announcing that a tool is available. It is the continuing work of making change intelligible.
Why this use case, and why now?
Which parts of my day-to-day work will change — and in what way?
Where does my professional responsibility and judgement still apply?
What is the escalation route when the technology produces a wrong, harmful or uncertain result?
• 06 / A two-year test
A two-year test
Two years in, an organisation should know its priority workflows. Give every scaled use case a named business owner, rather than relying solely on a central AI team. Back it with an intelligible risk model and credible evidence: baseline measures, observed outcomes, user feedback and an honest account of where the intervention did not work.
It should also be changing skills and roles deliberately. AI maturity is not achieved when people become faster at performing the old job. It arrives when the organisation decides which parts should be automated, augmented, safeguarded or made more human.
THE TWO-YEAR TEST
Five diagnostic questions to assess your current state.
Have we identified the workflows where AI can materially improve outcomes?
Yes
No
Does each scaled use case have a named business owner and a baseline?
Yes
No
Can employees explain what tools, data and decisions are permitted?
Yes
No
Is AI learning specific to roles, risks and real tasks?
Yes
No
Are we measuring outcomes, including harms and failure modes — not merely usage?
Yes
No
0–2 You are experimenting.
3–4 You are building capability.
5 You are approaching an operating model.
• 07 / The work starts after deployment
The work starts after deployment
Organisations are not software interfaces. They are collections of habits, incentives, informal knowledge, power structures, legacy systems, professional standards and people trying to get through the day. AI enters all of that. It does not float above it.
The companies that pull ahead will do the less glamorous work: map the workflow, remove pointless steps, improve data and knowledge practices, clarify decisions, equip people to exercise judgement, measure consequences and build safeguards before something goes wrong.
The first two years were about discovering what the tools could do. The next two should be about deciding what work is worth changing – and building organisations capable of changing it well.
In other words, they will treat AI as organisational change.
