Skip to content
10Governance readiness

How mature is your AI governance — really?

Fourteen questions, two per layer, four maturity levels each. Five minutes with a customer produces a per-layer profile, the gaps to close first, and the topics to bring to their Google Cloud team. Nothing is stored or transmitted — answers live only in this browser.

1Ad hoc

AI adoption is running ahead of any structure: no reliable inventory, no named owner, controls are whatever individual teams chose. Most value at risk; most incidents found by surprise.

2Documented

Policies, an initial inventory, and a review process exist — on paper. Enforcement is manual and bypassable, which is where most enterprises sit today (average trust maturity was 2.3 in McKinsey's 2026 survey).

3Enforced

Policy compiles into the platform: allowlists, screening floors, eval gates, and DLP run in the request path; the governed road is faster than the shadow one.

4Continuous

Governance generates its own evidence: runtime enforcement everywhere including agents, continuous evals, automated compliance evidence, rehearsed kill switches — governance as an operating capability.

1 of 7 · 0/14 answered
1Enterprise Governance

Could you produce a complete inventory of AI in your enterprise — systems, agents, and AI embedded in SaaS?

Who is accountable for AI governance, and how fast does a new use case get a decision?