Business AI Readiness: Find Out What You Already Have
IT Club provides general technology information and guidance. Content relating to regulation, compliance, cybersecurity or AI governance is provided for general information and should not be treated as legal, regulatory or certification advice. Requirements vary by organisation and jurisdiction. Obtain appropriate professional advice where necessary.
Your company does not need to have launched an AI project to be using AI. Employees may already be using ChatGPT, Copilot, Gemini, Claude and AI features built into everyday software. The sensible first step is not buying more AI. It is finding out what you already have.
Your business may already have an AI estate
An AI estate is simply the collection of AI tools, features, accounts and workflows connected to the business. It can include a paid Copilot licence, a free personal chatbot account, an AI meeting feature switched on in a collaboration platform, a browser extension, a supplier's automated service and a team experiment that quietly became part of the daily process.
That creates two related questions. Are people using AI in ways the business has not governed? And is the business paying for tools or licences that nobody uses, that overlap, or that solve a problem nobody defined? A business can take AI risk while missing useful opportunities at the same time.
KNOW: build a useful picture before buying anything else
- 1Ask each team what AI tools and features it uses, what work each one supports and which account owns it.
- 2Check company-card payments, expenses, software renewals and identity-provider application records for subscriptions people may not mention.
- 3Review AI features already included in Microsoft 365, CRM, accounting, recruitment, meeting and customer-service platforms.
- 4Record what information enters each tool: public information, internal information, personal data, customer material, confidential business information or security secrets.
- 5Name a business owner and record whether the tool is approved, being assessed, or not approved for business use.
A simple AI register
For each tool or AI-enabled feature, record its name, account type, owner, purpose, users, data, supplier, cost, approval status, human review requirement and next review date. A rough register that exposes unknowns is more useful than a perfect-looking document nobody maintains.
GOVERN: reduce risk without stopping useful work
Good governance does not mean banning AI. It means making the safe and useful route obvious. Set approved tools and account rules, keep passwords and security secrets out of prompts, define what personal or confidential information needs extra care, and make someone responsible for each important use.
- Use a proportionate AI policy in plain English.
- Require human checking for factual, customer-facing, financial, employment, legal, health, safety and security outputs.
- Check supplier retention, training, access, transfers, subprocessors and exit arrangements for the plan actually being used.
- Train people on limitations, hallucination, verification, bias, data protection, cybersecurity, approved tools and escalation — not only on prompting.
- Keep enough evidence to explain what the system does, who approved it and how mistakes are handled.
VALUE: separate useful AI from AI waste
| Ask | Look for |
|---|---|
| What does it cost? | Licences, subscriptions, usage charges, staff time and supplier extras |
| Is anybody using it? | Active users, repeat use, completed work and whether the tool is still a pilot |
| Does it improve a process? | Time saved, quality improved, fewer errors or a better customer/staff outcome |
| Are we paying twice? | Overlapping tools, duplicate team solutions and AI already included elsewhere |
| Could the risk outweigh the value? | Sensitive data, weak controls, unreliable output or consequences nobody owns |
Do not measure value only by the number of prompts or licences assigned. A small, well-controlled use that removes a real bottleneck may be worthwhile. A widely available tool that produces no measurable benefit may not be. Consolidating, cancelling or delaying a purchase is a valid recommendation.
IMPROVE: choose the next sensible action
- 1Stop a use that creates unacceptable exposure or has no accountable owner.
- 2Consolidate overlapping tools or remove unused licences.
- 3Train people where the tool is useful but the risks or limitations are not understood.
- 4Adopt a controlled pilot where a real business process has a clear owner and measurable outcome.
- 5Automate only after the underlying process is understood and worth keeping.
- 6Ask an existing IT or software supplier what AI is already enabled, how permissions work and what evidence they can provide.
- 7Obtain a formal technical, data-protection, legal or specialist review when the consequences or regulatory position justify it.
The best outcome may be to buy something, change something, train someone, review something, ask a better question or do nothing for now. Readiness is not a race to deploy more AI. It is the ability to make that decision knowingly.
Keep the picture current
Tools, terms, staff, permissions and use cases change. Review the register, policy, spending and outcomes periodically, and after a material incident or supplier change. If an EU customer, regulator or procurement team asks how AI is governed, the useful evidence is the picture you actually maintain — not a generic claim that the business is “AI compliant”.
Plain-English Takeaway
Before buying more AI, find out what your business already uses, what information enters it, what it costs, who owns it and whether it helps. Then govern, consolidate or improve from evidence.
Related intelligence
A Technology Intelligence article that goes deeper on this topic
The EU AI Act Is Now Being Enforced — Does Your Business Know What AI It Is Using?
Read the articleSources and further reading
- ICO — Guidance on AI and data protection
- NCSC — AI and cyber security: what you need to know
- GOV.UK — Introduction to AI assurance
External guidance changes. Check the source itself for the current position before acting on it.
