The AI Governance Maturity Model: From Ad Hoc to Optimized

Five ascending shield-shaped platforms like steps, representing stages of AI governance maturity

AI governance isn’t something an organization either “has” or “doesn’t have” — it develops in stages, the same way IT governance and cybersecurity programs matured over years, not overnight. This post lays out an original Shielded Networks maturity model for AI governance, plus a dedicated track specifically for AI cybersecurity maturity, since security capability tends to develop on its own timeline within the broader program.

This model is our own framing, informed by common maturity-model conventions used across IT and security disciplines — it is not a reproduction of any single published standard. For the frameworks referenced at each level, see our companion post, AI Governance Frameworks Compared.

The Five Levels of AI Governance Maturity

Level 1 — Ad Hoc

Characteristics: AI is in use somewhere in the organization, but without formal governance. There’s no clear ownership, no inventory, and no policy. Decisions about AI use are made independently by whichever team or individual adopts a tool.

Typical risks: Shadow AI, unreviewed data exposure through AI tools, no visibility into what AI is actually running.

Focus: Simply becoming aware of the scope of the problem — this is not a stage to stay in for long.

What “good” looks like at this stage: Leadership acknowledges AI governance needs attention and assigns someone to start.

Before moving on: Basic ownership is assigned and a first-pass AI inventory begins.

Level 2 — Aware

Characteristics: Basic ownership exists. An initial AI inventory is underway. A simple acceptable-use policy has been drafted, even if not yet fully enforced. Awareness of AI risk exists among IT and security teams, though not necessarily across the business.

Typical controls: A written (if basic) AI policy; an inventory that’s incomplete but growing; informal risk discussions.

Typical risks: Policy exists but isn’t consistently followed; inventory misses shadow AI and embedded SaaS AI features.

Focus: Completing the inventory, socializing the policy, and starting to classify AI use cases by risk.

What “good” looks like: Most known AI systems are in the inventory, and employees are aware a policy exists.

Before moving on: A formal governance structure (roles, a committee, or clear individual accountability) and risk classification approach are defined.

Level 3 — Defined

Characteristics: A formal AI governance structure exists — defined roles, a governance committee or clear owner, documented policies, and a repeatable risk assessment process. AI use cases are classified by risk level, and higher-risk systems get more scrutiny.

Typical controls: Documented AI risk assessment methodology; a defined approval process for new AI use cases; a maintained inventory with risk classifications; basic security controls applied consistently.

Typical risks: Governance exists on paper but isn’t yet well-integrated with cybersecurity, privacy, and vendor management — creating gaps between teams.

Focus: Integrating AI governance with existing IT risk, cybersecurity, privacy, and vendor management programs rather than running it as a standalone function.

What “good” looks like: New AI use cases go through a defined approval process, and that process actually gets used.

Before moving on: AI governance is formally integrated with cybersecurity, compliance, and vendor risk management, with clear handoffs between teams.

Level 4 — Managed

Characteristics: AI governance operates as an integrated part of the organization’s broader IT governance, cybersecurity, privacy, compliance, and enterprise risk management programs — not a parallel structure. Metrics exist to track program effectiveness. Vendor and third-party AI risk is systematically managed.

Typical controls: AI risk tracked in the enterprise risk register; vendor AI review built into standard procurement; lifecycle governance (approval through retirement) consistently applied; regular reporting to leadership.

Typical risks: Without continuous attention, controls can become checkbox exercises; new risks (like AI agents) can outpace existing processes if governance isn’t actively watching for them.

Focus: Building continuous monitoring and treating governance as an ongoing lifecycle activity rather than a periodic review.

What “good” looks like: Leadership receives regular, meaningful reporting on AI risk, and governance processes adapt as new types of AI use emerge.

Before moving on: Continuous monitoring, automated controls where feasible, and explicit governance for autonomous AI/agents are in place.

Level 5 — Optimized

Characteristics: Continuous monitoring of AI systems, automated policy enforcement where feasible, regular AI security testing (including red teaming), and governance extended explicitly to autonomous AI and AI agents. AI governance metrics feed into broader enterprise risk analytics. The program improves continuously based on incidents, near-misses, and changing regulation.

Typical controls: Automated AI inventory discovery; continuous monitoring and alerting on AI system behavior; scheduled AI red-team exercises; governance processes specifically designed for agentic AI autonomy levels.

Typical risks: Even at this level, new categories of AI risk (increasingly autonomous agents, novel attack techniques) require ongoing attention — optimization is a continuous process, not an end state.

Focus: Continuous improvement, advanced risk analytics, and staying ahead of emerging AI risk categories.

What “good” looks like: The organization can confidently answer “what AI do we have, what risk does it carry, and how do we know” at any given moment.

The Dedicated AI Cybersecurity Maturity Track

General AI governance maturity and AI cybersecurity maturity often develop at different speeds — an organization can have strong general AI governance while its AI-specific security controls lag, or vice versa. This track focuses specifically on the security dimension.

Basic AI Security

AI systems exist without AI-specific security controls — general IT security controls apply, but nothing addresses AI-unique risks like prompt injection or model manipulation. Focus: Establish an AI asset inventory and apply baseline identity and data protection controls to AI systems, the same as any other sensitive system.

Controlled AI Security

Baseline controls are consistently applied: identity and access management covers AI systems and their administrative interfaces, sensitive data flows into AI tools are reviewed, and AI systems are included in existing vulnerability management. Focus: Extending application security practices to cover AI and LLM-specific risks, using resources like OWASP’s LLM and GenAI guidance.

Managed AI Security

AI-specific threat modeling is standard practice, informed by resources like MITRE ATLAS. API security and AI supply-chain risk (including vendor and third-party models) are actively managed. Logging and monitoring extend to AI system usage and outputs, not just infrastructure. Focus: Building detection capability specific to AI misuse and anomalous behavior, not just traditional security events.

Advanced AI Security

Regular security testing of AI applications is standard, including scenario-based testing for AI-specific attack techniques. Incident response plans explicitly address AI-related incidents, with clear roles and a defined process for taking an AI system offline quickly. Focus: AI red teaming — proactively simulating attacks against AI systems rather than waiting to detect them reactively.

Continuous AI Security

AI red teaming happens on a regular cadence, not as a one-time exercise. Detection and monitoring are tuned specifically to AI behavior patterns, with automated alerting. Recovery processes for AI-related incidents are tested, not just documented. Security posture for AI systems is tracked with the same rigor as traditional infrastructure. Focus: Sustaining this level as AI usage — including increasingly autonomous agents — continues to expand and change.

Using This Model

Most organizations will find they sit at different maturity levels for different parts of their AI governance program — further along on policy than on security, for example, or ahead on inventory but behind on vendor management. That’s normal. Use this model to identify where the biggest gaps are relative to your actual AI risk profile, and prioritize closing those first rather than trying to advance every dimension at once. For a structured way to close bootstrap gaps, our main guide’s starting roadmap and our AI Governance Checklist are good next steps.

Share this article