AI is already in the room. Readiness is what keeps it useful, safe, trusted, and real.
Move from AI curiosity, scattered use, and unclear risk into practical, trusted, responsible adoption. Sixteen tools and seven premium appendices — inventory current use, prioritize real use cases, tier risk, set guardrails, prepare for agents, pilot responsibly, and build your 30/60/90-day path.
AI doesn't improve work on its own. People do. Systems do. Decisions do. Trust does. Readiness is what allows all of it to work together.
This toolkit is built to be used, not filed away. Work through it in order, or jump straight to the tool that matches where you're stuck — a Start Here map is below. Every tool ends in a tiny, usable output.
Start Here — Match Your Situation
| If This Is Your Situation | Start With |
|---|---|
| Just finished the AI Readiness Assessment | Tool 1 · AI Readiness Debrief |
| You suspect people are already using AI quietly | Tool 2 · Current-State Inventory, Tool 5 · Risk Tiering |
| Leadership wants AI use cases | Tool 3 · Use-Case Map, Tool 4 · Prioritizer |
| Teams have AI tools but don't know how to use them well | Tool 7 · Rules of the Road, Tool 9 · Verification |
| Considering AI agents or automation | Tool 8 · Agentic Boundary Map, Appendix D · Security |
Tool 1 — AI Readiness Debrief
Use this after completing the AI Readiness Assessment. The goal isn't to defend the result — it's to use it as a mirror, together.
| Result Area | Response |
|---|---|
| AI Readiness Zone | |
| AI Readiness Score | |
| Strongest Area | |
| Biggest Readiness Gap | |
| Primary Pattern Flag |
Tool 2 — AI Current-State Inventory
Identify what AI use already exists before creating new plans. Most organizations start as if nothing is happening yet — that's rarely true.
| Tool / Platform | Who Uses It? | For What Work? | Approved? |
|---|---|---|---|
| ChatGPT | |||
| Claude | |||
| Copilot | |||
| Embedded AI (CRM, HRIS, helpdesk...) | |||
| Other |
Tool 3 — AI Use-Case Map
Find where AI could create meaningful value. A good use case starts with work friction, not tool excitement.
| Friction Type | Where does this show up? |
|---|---|
| Time Drag | |
| Rework | |
| Search Burden | |
| Decision Delay | |
| Communication Load |
Tool 4 — AI Use-Case Prioritizer
Score each use case 1–5 across eight criteria. Total 34–40 is a strong pilot candidate; below 20, don't prioritize now.
| Use Case | Value | Feasibility | Risk (reversed) | Readiness | Total |
|---|---|---|---|---|---|
Tool 5 — AI Risk Tiering Matrix
Not every AI idea needs the same review. When everything is treated as high risk, adoption slows. When everything is treated as low risk, trust breaks.
| Risk Tier | Description | Review Path |
|---|---|---|
| Tier 1 — Low Risk | Brainstorming, generic drafting, non-sensitive summaries | Team-level guidance |
| Tier 2 — Moderate Risk | Internal data summaries, customer response drafts | Manager or SME review |
| Tier 3 — High Risk | Employee, financial, legal, clinical, regulated use | Formal review |
| Tier 4 — Prohibited | Sensitive data in public tools, high-impact automation without approval | Not allowed |
| Our Use Case | Tier (1–4) | Why |
|---|---|---|
Tool 6 — Responsible AI Guardrails Builder
Build allowed, cautious, and prohibited use boundaries — plus transparency rules for when AI use should be disclosed.
Draft the Guardrail Statement
Tool 7 — Everyday AI Rules of the Road
Practical team-level rules for the daily stuff: drafting, summarizing, brainstorming, research support, meeting notes.
- Rule 1 — Use AI to support thinking, not replace it.
- Rule 2 — Don't paste sensitive information into unapproved tools.
- Rule 3 — Check before you trust.
- Rule 4 — Use AI where it reduces drag, not to avoid accountability.
- Rule 5 — Be transparent when it matters.
- Rule 6 — Escalate the weird stuff.
| We Can Use AI For… | We Won't Use AI For… | We Need Approval Before… |
|---|---|---|
Tool 8 — Agentic Workflow Boundary Map
Agents may take action, update records, trigger tasks, or escalate issues. Define what AI can assist, recommend, prepare, or do — and where human approval must remain.
| Level | AI Role | Human Role |
|---|---|---|
| 1 — Assist | Drafts, summarizes, searches, organizes | Reviews and uses judgment |
| 2 — Recommend | Suggests a next step | Decides |
| 3 — Prepare | Prepares an action | Approves before execution |
| 4 — Act Within Guardrails | Completes low-risk actions within defined limits | Monitors |
| 5 — Escalate Exceptions | Stops or escalates when unclear or risky | Resolves exception |
Tool 9 — Human Judgment + Verification Checklist
AI confidence is not the same as accuracy. This turns "be careful" into a practical review habit.
| Check | Question | Finding |
|---|---|---|
| Accuracy | Is this factually correct? What needs verification? | |
| Context | Does this fit our situation? What might AI be missing? | |
| Judgment | Would I stand behind this if challenged? | |
| Bias + Fairness | Could this disadvantage anyone? | |
| Privacy | Does this include sensitive information? |
Tool 10 — Team Trust Conversation Guide
This conversation isn't about convincing everyone to love AI. It's about understanding what people need to use it responsibly.
| Leadership Follow-Up Action | Owner | Date |
|---|---|---|
Tool 11 — Workflow Redesign Canvas
The question isn't "where can we add AI?" It's: how should this work change if AI can support part of it?
| Step | Who Does It Today? | Pain Point | AI Role (Assist/Recommend/Prepare/Act) |
|---|---|---|---|
| 1 | |||
| 2 | |||
| 3 |
Tool 12 — AI Pilot Charter
A pilot shouldn't be "let's try AI and see what happens." Define scope, data boundaries, review, and success before launch.
| Charter Element | Response |
|---|---|
| Pilot Name / Use Case | |
| Problem We're Solving | |
| Pilot Owner / Sponsor / Users | |
| Data Allowed / Not Allowed | |
| Human Review Required | |
| Risk Tier | |
| Success Measures | |
| Stop / Continue / Scale Criteria |
Tool 13 — AI Learning Log
AI readiness improves through practice, not theory. Capture what worked, what didn't, and what risk appeared — every check-in.
| Check-In Date | What We Tried | What Worked | What Didn't / Risk Seen |
|---|---|---|---|
Tool 14 — 30/60/90-Day AI Readiness Plan
The goal isn't to do everything at once — it's to build enough readiness to move responsibly.
| Phase | Focus | Our Actions |
|---|---|---|
| First 30 Days — Clarify | Shared view of where AI can help and where risk exists | |
| Days 31–60 — Design | Basic structures for responsible adoption | |
| Days 61–90 — Enable | Move from planning to responsible testing |
Tool 15 — AI Leadership Operating Rhythm
A monthly dashboard for active use cases, risks, adoption, and value — so AI readiness stays a rhythm, not a one-time project.
| Area | Status (Green/Yellow/Red) | Decision Needed |
|---|---|---|
| Active Use Cases | ||
| Risks / Issues | ||
| Adoption / Trust | ||
| Value / Measurement |
Tool 16 — Final AI Readiness Action Plan
The synthesis page. Pull everything you've built into one clear plan you can share, revisit, and execute.
| Area | Decision |
|---|---|
| Our AI Readiness Zone & Primary Pattern Flag | |
| Our strongest area / biggest gap | |
| Our first AI use case & biggest risk | |
| Our first guardrail priority | |
| Our 30 / 60 / 90-day actions | |
| Owner / Sponsor / Next Review Date |
Appendix A — AI Governance Charter
Without visible governance, AI decisions drift. With too much governance, AI freezes. The goal is right-sized structure.
| Charter Area | Decision |
|---|---|
| Governance Group Name / Purpose | |
| Executive Sponsor / Chair | |
| Core Members | |
| Decision Rights | |
| Meeting Cadence / Escalation Path |
Appendix B — AI Governance RACI
AI work gets messy when everyone is interested but no one owns the hard parts. R = Responsible, A = Accountable, C = Consulted, I = Informed.
| Decision / Activity | Executive Sponsor | Business Owner | IT/Data | Security/Legal |
|---|---|---|---|---|
| Define AI priorities | ||||
| Identify use cases | ||||
| Approve pilots |
Appendix C — AI Tool / Vendor Intake Checklist
Use before approving a new AI tool, vendor, or embedded AI feature inside a platform you already use.
Appendix D — LLM + Agent Security Checklist
The practical question: could the AI system be manipulated, leak sensitive information, act beyond its authority, or produce output people trust too quickly?
| Risk Area | Question | Finding |
|---|---|---|
| Prompt Injection | Could a user or external content manipulate the AI's instructions? | |
| Sensitive Info Disclosure | Could sensitive information be exposed in prompts, outputs, or logs? | |
| Excessive Agency | Could the AI take actions beyond what it should be allowed? | |
| Auditability | Can we see what the AI did, changed, or recommended? |
Appendix E — AI Capability + Training Plan
Different audiences need different levels of AI understanding — executives, managers, employees, and technical teams all need something different.
| Audience | Capability Needed | Format & Owner |
|---|---|---|
| Executives | ||
| Managers | ||
| Employees | ||
| IT / Data / Security |
Appendix F — AI Adoption Communications Pack
Ready language for the questions people actually ask — and aren't sure it's safe to ask out loud.
Appendix G — AI Value + Measurement Scorecard
AI pilots shouldn't be evaluated only by enthusiasm. They should be evaluated by evidence.
| Measure | Baseline | Target | Actual | Evidence |
|---|---|---|---|---|
| Time saved | ||||
| Quality improved | ||||
| Trust improved |