The GDS AI Readiness Assessment: What It Measures and Why It's the First Step

Copilot is arriving in Microsoft 365 tenants through the update cycle. In June and July 2026, Microsoft resumed automatically installing the Microsoft 365 Copilot app on Windows devices running the Microsoft 365 desktop apps, unless an administrator opted out. If your board or your largest customer has asked what your AI exposure is, the honest answer depends on what Copilot can reach once it's running. An AI readiness assessment is built to give you that answer before someone else asks for it, and what it measures (identity, data, workflow value, people, and governance) decides how complete that answer is.

Cisco's research suggests that a lot of leadership teams are in the same position. Its 2025 AI Readiness Index surveyed 8,000 senior IT and business leaders at organizations with more than 500 employees across 30 markets and found that about 13 percent qualify as fully AI-ready, a share that has held for the three years Cisco has run the study. The same survey found 83 percent of organizations plan to deploy AI agents, yet only 31 percent say they are fully equipped to control and secure them. Cisco calls the gap between those plans and the foundations underneath them "AI infrastructure debt." The GDS AI Readiness Assessment is built to tell you whether your Microsoft 365 environment can support AI safely today and what has to change before it can.

 

What does an AI readiness assessment measure? The five dimensions GDS scores

Executives often use these three terms interchangeably, and each one answers a different question and produces a different document.

 

AI readiness assessment

AI audit

AI maturity model

Question it answers

Is our environment capable of adopting AI safely, and what has to change first?

Does the AI we already run comply with our policies and regulations?

Where are we on a defined scale, and how are we progressing over time?

When you use it

Before deploying or expanding AI

After deployment, on a schedule or after an incident

Repeatedly, as a benchmark across years

What it produces

Scores, gaps, and a sequenced plan

Findings against a control set

A level or stage


The GDS assessment borrows the maturity model's measuring stick, since you receive a maturity score for each dimension, and applies it to the readiness question. You come away with a baseline you can re-measure later and a plan for what to fix first.

The Five Dimensions the GDS assessment measures 

Many published readiness frameworks start with data. The GDS assessment starts with identity, because Copilot works through the identity of the person using it.
The five dimensions below appear in the order the assessment presents them,
and each one answers a plain question your leadership team can put to IT.

  1. Can your environment safely support AI? Identity and endpoint security

This dimension evaluates your identity and endpoint environments against what safe AI deployment requires. The review covers conditional access policies, multifactor authentication, endpoint protection, and device compliance, along with how your Microsoft Defender configuration supports those controls.

Identity comes first because of how Copilot handles access. Microsoft's documentation states that Copilot only surfaces organizational data to which the individual user has at least view permissions, so Copilot inherits every permission the user already holds and the identity layer decides what AI can reach. Least privilege, applied to user and administrator accounts, sets the limit on what Copilot can surface.

Low scores here and a stolen password or an unmanaged laptop carries the same Copilot reach as the employee it belongs to. Anyone who signs in with that account can ask Copilot to summarize every file the account can open. GDS identifies a weak identity posture as the most common barrier to safe AI deployment and the one that creates the most direct financial and regulatory exposure.

  1. Is your data ready to fuel AI accurately and safely?

This dimension examines your data structure, sensitivity classification, SharePoint and Teams governance, and access boundaries. In practice that
means finding where your sensitive files live, whether they carry sensitivity labels
in Microsoft Purview, and who can open the SharePoint sites and Teams channels that hold them.

Oversharing usually builds up over years. A SharePoint site opened to the whole company for a one-week project in 2019 stays open until someone closes it, and Copilot will draw on it for any employee whose question matches its contents. Classification also determines what your safeguards can do. Microsoft Purview data loss prevention policies can stop Copilot from summarizing files and emails that carry specific sensitivity labels, and those policies have nothing to act on when the files were never labeled. A weak data score costs you twice: Copilot gives poorer answers because it grounds them in duplicate, outdated, or disorganized content, and it can reach sensitive content that was never meant to be broadly shared.

  1. Where will AI deliver value first? Workflow and use-case mapping

This dimension maps your highest-value automation opportunities to the specific Copilot and AI capabilities best positioned to address them. The purpose is to make the productivity case visible before deployment, so leadership approves licenses against named workflows with an expected return.

For a hospital revenue-cycle team, that could mean summarizing payer correspondence and drafting appeal letters. For a community bank, it could mean first drafts of loan committee memos built from documents the bank already holds. Each candidate workflow gets weighed against the data it touches, so this dimension depends on the first two. When this dimension scores low, licenses tend to go out to a broad population with no workflow attached, and six months later the CFO asks what the spend produced and the best answer available is an anecdote.

  1. Are your people ready to adopt it?

This dimension assesses user training maturity, leadership alignment, and change management practices. It looks at questions like whether the leadership team agrees on which outcomes AI is supposed to improve, whether the organization has run a structured rollout of a new tool before (with training, communication, and a feedback loop), and whether managers know how their teams' work will change.

Adoption failure is a readiness failure, and it can be measured before a single license is assigned. A low people score predicts weak user adoption after launch, and you end up paying for licenses that go unused while employees keep working the old way.

  1. Does your governance framework meet the standard responsible AI requires?

This dimension evaluates your framework against what responsible deployment requires: acceptable use policies, data handling rules, privacy standards, and compliance alignment. For organizations in regulated industries, the assessment scores readiness directly against your specific obligations, so a HIPAA-covered entity and a public-sector agency are measured against different requirements.

Without a written acceptable use policy, employees decide for themselves which AI tools to use and what to paste into them. That is shadow AI, and it creates exposure your security tools may never see. If governance scores low, a board member, an examiner, or a customer can ask how AI is governed in your organization and you won't have a document to hand them.

How the scoring works and what your score tells you

The assessment produces an AI maturity score for each of the five dimensions. Read those five scores individually before you look at any overall average, because an average can look healthy while one dimension blocks deployment on its own.

An organization with strong leadership alignment and a clear set of high-value workflows can post an average that looks ready to go while gaps in conditional access mean Copilot should not reach production deployment yet, and in that case the identity score decides the timeline. A useful rule is to let your lowest-scoring dimension set the pace, treating identity and data gaps as blockers and people or workflow gaps as items to address during rollout.

A low score is a normal place to start. With about 13 percent of organizations fully AI-ready in Cisco's research, expect gaps, and expect each one to arrive with a recommendation and a place on the roadmap.

What you receive

Your assessment package includes four documents: 

Everything starts with the AI Readiness Survey, a few minutes of questions that begin your assessment and lead to your maturity score and roadmap.

Take the AI Readiness Survey. 
  1. AI maturity scores across all five dimensions, giving leadership and the board a baseline to re-measure.
  2. A gap analysis with specific recommendations, giving IT and security a working list tied to named controls.
  3. An AI Foundations Report aligned to Microsoft's AI governance guidance, giving compliance and audit stakeholders a reference point they recognize.
  4. A prioritized action roadmap split into short-term, mid-term, and long-term steps your organization can execute and budget against. 


Why the assessment is the first step

The same gap carries a different price depending on when you find it. Found before deployment, an overshared SharePoint site or a missing conditional access policy becomes a remediation item with an owner and a due date. Found after deployment, it becomes an incident with regulatory and financial consequences, and it lands after the productivity gains have been promised to the board.
The assessment moves discovery to the cheaper side of that line. It also gives your leadership team a documented record that the organization assessed its environment before it deployed.

Where the assessment takes you

The assessment starts a defined sequence:

  1. The AI Readiness Assessment scores your environment and produces the roadmap. 
  2. Secure Plus Premium, the GDS-managed Microsoft 365 environment, provides M365 E5 licensing, Microsoft Purview compliance configuration, and advanced identity and governance controls as the foundation for closing the gaps the assessment found.
  3. Copilot goes into the specific workflows your assessment scored as highest-value, so the first deployment is contained and tied to a result you can report.
  4. Ongoing AI operations management keeps the environment performing and accountable as your use of AI grows.

You work with one accountable partner across all four stages. That replaces the handoffs between a licensing reseller, a security vendor, a consultant, and an internal team, where gaps tend to open up between contracts.

What this looks like in a regulated environment

Take a mid-market healthcare organization with HIPAA exposure. Its governance dimension gets scored against the obligations it already carries, including the HIPAA Privacy Rule's minimum necessary standard (45 CFR 164.502(b)) and the Security Rule's technical safeguards for access control and audit controls (45 CFR 164.312(a)(1) and 164.312(b)).

Those rules translate directly into Copilot questions. If a SharePoint site holding patient billing records is open to clinical, finance, and HR staff, Copilot will draw on it for all of them, and the question becomes whether that access reflects what each role needs. If a nurse pastes a patient summary into a consumer chatbot, the question becomes whether a written policy prohibited it and whether anyone would find out. A generic checklist asks whether you have an AI policy, and a regulated assessment asks whether your policy and your permissions would hold up in an HHS Office for Civil Rights investigation.

Mid-market organizations can often move through this faster than large enterprises. A 400-person health system with a single Microsoft 365 tenant can approve an acceptable use policy in one leadership meeting and has fewer business units with competing SharePoint structures to untangle. An enterprise with multiple tenants and regional compliance teams has more parties to coordinate before the same decisions hold.

Frequently asked questions

What is the difference between AI readiness and AI maturity?

AI readiness asks whether your environment can adopt AI safely now and what has to change first. AI maturity describes where you are on a defined scale and how you progress over time. The GDS assessment uses maturity scores to measure readiness, so you get a baseline to track and a plan to act on.

Who needs to be involved in an AI readiness assessment?

Plan for an executive sponsor, usually the CEO, COO, or CFO, plus the CIO or IT director, whoever owns security, and your compliance or privacy officer. Include leaders from the business units whose workflows are candidates for Copilot, and someone from HR or training for the people and change readiness dimension.

What happens after the assessment?

You receive your scores, gap analysis, AI Foundations Report, and prioritized roadmap. For many organizations the next step is Secure Plus Premium, followed by Copilot deployed into the workflows the assessment scored highest, then ongoing AI operations management.

Do we still need an assessment if we already have Copilot licenses?

Yes. A license turns Copilot on for a user, and Copilot then works with every permission that user already has. The assessment shows what your licensed users' Copilot can reach today, which gaps need to close, and which workflows those licenses should be pointed at to show a return.

If you'd rather talk it through first, schedule a discovery call with the GDS team.

Schedule A Discovery Call 

Start with the AI Readiness Survey

Global Data Systems is a Managed Intelligence Provider that designs, implements, and operates the digital workplace on a single platform for regulated mid-market organizations, and the AI Readiness Assessment is where that work begins. Take the AI Readiness Survey by submitting the short form on the assessment page, and the survey arrives in your inbox. It takes a few minutes to complete. Whether or not anything follows, you finish it knowing where your organization stands on identity, data, workflow value, people, and governance.




Sources
• Cisco, "Cisco AI Research: The Most AI-ready Companies Outpace Peers in the Race to Value," October 14, 2025 (Cisco AI Readiness Index 2025).
• Microsoft Learn, "Data, Privacy, and Security for Microsoft Copilot." Microsoft Learn, Microsoft Purview considerations for Microsoft 365 Copilot (learn.microsoft.com/purview/ai-m365-copilot-considerations). Microsoft 365 Message Center, MC1152323, updated June 15, 2026. 45 CFR 164.502(b) and 45 CFR 164.312.

 

 

Get In Touch

310 Laser Lane
Lafayette, Louisiana 70507
Office Hours: Monday - Friday
8 a.m. - 5p.m.
Contact Us >

24 / 7 / 365 Support

Our dedicated support
staff are available by
phone 24 hours a day.

Phone: 888-435-7986

GDS Offices

Time to simplify your IT?