Schedule a meeting

AI Readiness Assessment

Two weeks to find out whether your organisation is ready for AI, what stops it, and what to do first.

In short

An AI readiness assessment checks whether an organisation can use AI safely and profitably. Lindstead's takes ten working days, costs a fixed fee and ends with a five-page board memo.

It covers the usual ground of strategy, data and skills. It also checks what most assessments skip: where the AI runs, which law can reach the data, and what the AI Act asks of each system. Lindstead runs it as the AI Sovereignty Scan.

What does an AI readiness assessment check?

Seven dimensions, each scored on evidence from documents and interviews.

Dimension Question it answers Evidence
Strategy and use cases Which three uses pay off first? Interviews, cost and benefit per use case
Data Is the data good enough and allowed? Sources, quality, legal basis
Infrastructure Where does the AI run? Providers, regions, owners
Jurisdiction Which foreign law can reach the data? Contracts, CLOUD Act exposure
Regulation Which AI Act, GDPR, DORA and NIS2 duties apply? AI register, risk classes, dates
Security and vendors Who can access prompts, logs and models? Access rights, retention, sub-processors
People and skills Who builds, runs and checks it? Roles, AI literacy under Article 4

Why do European organisations stall on AI?

In 2025, 20 percent of EU enterprises with ten or more staff used AI. Eurostat also asks firms that considered AI and held back why they did. Missing expertise tops the list. Legal uncertainty and data protection follow, each cited by more than half.

Most firms that hold back lack skills or legal clarity

Three of the top four reasons are about knowledge and rules, the things an assessment settles.

Of EU firms that considered AI but did not use it, 70% cited a lack of expertise and more than half cited legal uncertainty or data protection.

Reasons for not using AI, share of enterprises that considered AI but did not use it, EU27, 2025, %

Skills, data, systems and cost Law, privacy and ethics
0 20 40 60 80 Lack of expertise 70.3% Legal uncertainty¹ 53.6% Data protection² 52.7% Data quality or access 43.5% Incompatible systems 41.6% Costs too high 38.4% Ethical concerns 24.6%

¹ Full wording: lack of clarity about the legal consequences. ² Full wording: concerns regarding violation of data protection and privacy. Base: enterprises with 10 or more persons employed that ever considered using AI but did not use any AI technology in 2025. All activities except agriculture, mining and the financial sector. Multiple answers possible.

Source: Eurostat, Artificial intelligence by NACE Rev. 2 activity (isoc_eb_ain2), EU survey on ICT usage in enterprises, updated 15 June 2026

What does the board get?

Uncertainty ends up as a list of decisions. Each deliverable answers a question the board will be asked by a supervisor, an auditor or a client.

  • Readiness score A score per dimension with the evidence behind it, so the board sees where the gaps are.
  • AI register Every AI system in use or planned, with owner, data, provider and where it runs.
  • Regulatory map The AI Act, GDPR, DORA and NIS2 duties per system, with the dates they apply.
  • Hosting advice Which workloads stay with a provider, which move to a European cloud and which belong in-house.
  • Board memo Five pages: one recommendation, a first use case, a cost range and the next 90 days.

How does the assessment run?

  1. Day 1: Kick-off. Interviews with IT, risk, privacy and one business owner. Scope and document access agreed.
  2. Days 2 to 5: Inventory. Lindstead lists every AI system, scores the seven dimensions and traces where data goes.
  3. Days 6 to 8: Options. Rules are checked per system. Use cases are ranked and hosting options priced in euro.
  4. Days 9 to 10: Board memo. Lindstead writes the memo and walks the board or executive team through it.

AI readiness checklist

Ten statements a ready organisation can confirm. Each "no" is a gap the assessment closes.

  1. A register lists every AI tool staff use, including free ones.
  2. Each tool has an owner who answers for its output.
  3. The organisation knows which country and which company processes its prompts.
  4. Contracts say whether providers keep or train on its data.
  5. Each AI system has an AI Act risk class and a date by which duties apply.
  6. Staff who use AI have had training, as Article 4 has required since February 2025.
  7. The first use case has a business owner, a budget and a success measure.
  8. Data for that use case is clean, available and lawful to use.
  9. IT can run or monitor the model, or a partner does it under contract.
  10. The board has decided what may leave the EU and what may not.

The AI Act timeline lists every date, and the CLOUD Act guide explains which providers foreign law can reach. For sector rules, see the briefings for financial services, healthcare and the public sector.

What comes after the assessment?

The organisation owns the memo and can act on it alone. Lindstead can also take the next step: an AI strategy built on the findings, governance and compliance for the systems in the register, or a first use case in production on infrastructure the organisation controls.

Frequently asked questions

  • A structured check of whether an organisation can use AI safely and profitably. It scores strategy, data, infrastructure, regulation, security and skills, and ends with a ranked plan. Lindstead adds where the AI runs and which law can reach the data.

  • Lindstead's takes ten working days. The organisation spends about six hours on it: a kick-off, four short interviews and the final discussion.

  • Lindstead charges a fixed fee, agreed before the start and set by the size of the organisation. There are no follow-up obligations and no commissions from vendors.

  • A maturity model scores how far AI use has progressed. A readiness assessment asks what must change before the next step, and ends with decisions. Lindstead's version produces a board memo with one recommendation.

  • No law requires one by name. The AI Act does require AI literacy for staff since February 2025, and deployers of high-risk systems face duties from December 2027. An assessment shows which duties apply and when.

Start with a 30-minute intake call.

Scope, timing and the fixed fee are settled in one conversation.