How mature is your AI governance — really?
Fourteen questions, two per layer, four maturity levels each. Five minutes with a customer produces a per-layer profile, the gaps to close first, and the topics to bring to their Google Cloud team. Nothing is stored or transmitted — answers live only in this browser.
AI adoption is running ahead of any structure: no reliable inventory, no named owner, controls are whatever individual teams chose. Most value at risk; most incidents found by surprise.
Policies, an initial inventory, and a review process exist — on paper. Enforcement is manual and bypassable, which is where most enterprises sit today (average trust maturity was 2.3 in McKinsey's 2026 survey).
Policy compiles into the platform: allowlists, screening floors, eval gates, and DLP run in the request path; the governed road is faster than the shadow one.
Governance generates its own evidence: runtime enforcement everywhere including agents, continuous evals, automated compliance evidence, rehearsed kill switches — governance as an operating capability.