Most guidance on AI readiness is written for organizations with dedicated technical staff and a governance committee. If you have twenty people and no CIO, that guidance is not wrong so much as unusable.
The questions below are the ones that matter at that scale. They are deliberately answerable in an afternoon. If you cannot answer one, that is the work to do before adopting anything, not a reason to avoid adopting at all.
Data and Access
Assistants built into productivity suites inherit the permissions of the account using them. If a staff member has access to a shared drive they should not, the assistant will surface that content when asked a related question. Before enabling anything, audit what the average user can already reach.
Consumer tiers of most AI products carry different data handling terms than business tiers. This is the single most common gap in small organizations: staff using a free account for work that is subject to a confidentiality obligation. Check the tier, not the brand.
You do not need a detailed technical answer. You need a documented one you can produce if a client, insurer, or agency asks. If nobody can point to it, that is the gap.
- Confirm which account tier staff are actually using, not which one you purchased
- Review what a typical user account can reach before enabling any assistant
- Write down the answer to "where does our data go" in one paragraph
Governance and Ownership
Not a committee. A person. At small scale, governance fails through diffusion rather than disagreement. Someone has to be able to answer whether a proposed use is acceptable without convening a meeting.
In the absence of a stated policy, people apply their own judgment, and that judgment is usually more permissive than leadership expects. A single page covering what may and may not be put into an AI tool is sufficient. The failure is having nothing, not having something imperfect.
Decide in advance which categories of work require disclosure, internal review, or attribution. Client deliverables, regulatory submissions, and anything going on the record deserve an explicit answer before the situation arises rather than after.
Shadow adoption. In most small organizations, staff are already using AI tools the organization has not evaluated. A policy written as though adoption has not started will be ignored by people who started six months ago. Ask what is already in use before writing anything.
Operational Fit
AI applied to an unclear workflow produces faster ambiguity. If the steps, owners, and definition of a correct outcome are not written down, that is the prerequisite work.
A verification step assigned to someone already at capacity is not a control. It is a formality that will be skipped in the first busy week. If nobody has the time, either make it or narrow the use case until review is realistic.
Reading Your Results
If you answered all eight comfortably, you are ready to adopt deliberately, starting with one use case rather than a broad rollout.
If the gaps were in access and data handling, resolve those first. They are the ones that create exposure rather than disappointment, and they are also the ones that get harder to fix once tools are in use.
If the gaps were in governance and ownership, you can proceed on a narrow use case while you close them, provided the named owner exists before the tool does.
Answer questions one and two this week. They take under an hour between them and they surface the two problems most likely to matter: tools reaching more than they should, and staff working on a consumer account under a confidentiality obligation.