The Question Isn't "Do You Have AI Governance," It's "What Level Are You At"
When asked about AI governance, most companies produce a PDF of "AI usage principles" and consider the matter closed. The data tells a different story. The World Economic Forum found that 81% of organizations remain in the first two stages of responsible-AI maturity, with fewer than 1% reaching the top stage. Meanwhile, according to McKinsey, the share of organizations regularly using generative AI grew from 65% in early 2024 to 71% in 2025. In other words, most companies are already using AI while governance lags far behind deployment.
That gap carries a price tag. IBM's 2025 Cost of a Data Breach Report found that breaches involving Shadow AI—employees quietly using unapproved AI tools—cost an average of USD 4.63 million, USD 670,000 more than a standard incident. Such breaches now account for 20% of all incidents, and among the victims, 63% either had no AI governance policy or were still developing one, and 97% lacked proper access controls. Governance is not a compliance-department ornament; it is an operating variable that maps directly to dollars lost. So the real question is not "do you do it" but "what level are you at, and what does the next level require"—which is precisely what a maturity self-assessment is for.
A Five-Level Maturity Model: From Ad Hoc to Governance-as-Throughput
Drawing on NIST's capability-maturity concept and the tiered models from firms such as WitnessAI and Credo AI, AI governance can be distilled into five levels. Each level is not an abstract adjective but corresponds to three observable facts: who is accountable, whether enforcement exists, and whether it can be audited.
| Level | Name | Characteristics | Typical reality |
| L1 | Ad hoc | AI managed under generic IT policy, no dedicated inventory, handled only when something breaks | About 14% of orgs |
| L2 | Defined (on paper) | Policies and committees exist, but enforcement is manual, inconsistent, or nominal | Most orgs stuck in L1–L2 (81% combined) |
| L3 | Operationalized | Formal risk taxonomy (aligned to NIST/EU AI Act), pre-deployment validation and red-teaming | Only 16% do red-teaming |
| L4 | Embedded/automated | Governance enforced by runtime technical controls, continuous monitoring, full audit trails | About 11% fully implemented |
| L5 | Governance-as-throughput | Enterprise-wide visibility, risk updates dynamically with drift and regulation, governance accelerates deployment | Very few |
The key insight: the difference between L1 and L2 is "whether it's written down," while the difference between L2 and L3 is "whether what's written down is actually enforced." Most companies mistake producing policy documents for leveling up; in fact that only moves them from L1 to L2. The real chasm comes after.
A Seven-Element Scorecard: Breaking Governance Into Scorable Dimensions
A single "overall maturity" number carries no action. You must break it into dimensions to know what to fix. Split governance into seven elements, self-scoring each on a 1–5 scale (1 = no process, 3 = organization-wide, 5 = continuously monitored with audit-grade evidence), and you get an actionable radar chart.
| Element | What to check | NIST function |
| 1. Strategy & accountability | Is there a clear owner, decision cadence, and escalation path | Govern |
| 2. Policy & principles | Are principles turned into enforceable rules, not declarations | Govern |
| 3. Risk & impact assessment | Is risk assessed with a formal taxonomy before go-live | Map |
| 4. Data governance | Are the source, permissions, and retention of data controlled | Map / Measure |
| 5. Technical controls & monitoring | Are there runtime guardrails, identity checks, drift detection | Measure / Manage |
| 6. Incident response & audit | Kill switches, response playbooks, complete trails | Manage |
| 7. Literacy & culture | Are users trained and able to recognize risk | Govern |
Field data reveals a consistent shape: policy-type elements (1, 2, 7) generally score 3–4, because most firms wrote policy documents in 2024–2025; but runtime technical controls (5, 6) sit at a median of just 1–2, for lack of platform infrastructure. This explains why so many companies "look governed" yet remain at L2—their scores cluster on the easiest dimensions while the hardest and most critical runtime controls stay blank.
Align to International Frameworks; Don't Reinvent the Wheel
The five-level model and seven elements are not invented from scratch; they deliberately align to two authoritative frameworks so your self-assessment plugs straight into compliance.
- NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is the current core framework, extended by the Generative AI Profile (AI 600-1) in July 2024. It comprises four functions: Govern (the cross-cutting culture of accountability), Map (frame the system and its context), Measure (assess and benchmark risk), and Manage (allocate risk-treatment resources); the latter three form a continuous loop. Every element in the scorecard above maps to these functions rather than a separate vocabulary.
- ISO/IEC 42001:2023 is the world's first AI management system standard and, by 2026, the de facto gate for selling into the EU and regulated markets. Implementing it covers roughly 70% of the EU AI Act's high-risk documentation requirements, and organizations already holding ISO 27001 can achieve 42001 up to 40% faster.
For companies in Taiwan, the takeaway is: you don't need to invent a standard for self-assessment. Use these two as the skeleton—it saves effort, and when you later export or face an international customer audit, you won't have to redo the work.
The Upgrade Path: Getting Over the L2-to-L3 Wall
Maturity doesn't rise from meetings and declarations. Industry data shows moving from L1 to L2 typically takes 2–3 months, and reaching L3 (operationalized) takes 4–6 months; the bottleneck is almost always the same—turning paper policy into enforced controls. Here are the priority moves to clear that wall:
- Fix the three weakest, highest-leverage items first: data shows kill switches, incident response, and red-teaming correlate most strongly with audit success, yet are most often missing. Fixing these three yields the highest return.
- Translate principles into rules: every governance principle must map to a technical control or approval gate that can actually block a violation, or you stay at L2 forever.
- Bring in Shadow AI and legacy systems: a common L3 blind spot is governing only new projects while missing employee-used tools and old systems.
- Build an auditable trail: the ticket from L3 to L4 is "every AI interaction leaves a verifiable record," which is also the precondition for automated monitoring.
The External Clock of 2026: Staying at Level Two Is Becoming a Risk
Staying at L2 may once have been harmless, but the external regulatory clock is ticking. Although the EU AI Act's May 2026 "Digital Omnibus" postponed Annex III high-risk obligations from August 2026 to December 2027, most transparency obligations (Article 50, covering public-facing chatbots, synthetic media, and AI-generated content labeling) still take effect on 2 August 2026. For Taiwanese companies with EU business or customers, this means the "write policy now, enforce later" strategy has hit its deadline. The value of a maturity self-assessment is exactly this: it lets you see, before the deadline, which piece you're missing and how much time is left to fix it.
Nerdtechnic has long helped Taiwan's small and medium enterprises adopt AI, and we find the governance gap is rarely "not wanting to do it" but "not knowing what level you're at or what to fix next." We offer AI governance maturity assessment and advisory services: we score your organization's current state against the five-level model and seven-element scorecard above, align it to NIST AI RMF and ISO/IEC 42001, identify the highest-leverage gaps, and help turn governance principles into enforceable, auditable technical controls. If you're preparing to cross the L2-to-L3 wall or need to get ready for EU compliance, talk to us—let governance become the force that advances your AI adoption rather than the friction that holds it back.
References
- World Economic Forum, "Advancing Responsible AI Innovation: A Playbook" (2025) — reports.weforum.org
- McKinsey, "The state of AI: How organizations are rewiring to capture value" (2025) — mckinsey.com
- IBM, "Cost of a Data Breach Report 2025" — ibm.com/reports/data-breach
- WitnessAI, "AI Governance Maturity Model" — witness.ai
- NIST, "AI Risk Management Framework (AI RMF 1.0)" — nist.gov
- NIST, "AI RMF: Generative Artificial Intelligence Profile (NIST AI 600-1)" — nist.gov
- ISO, "ISO/IEC 42001 explained" — iso.org
- ExamCert, "ISO 42001 AI Management Certification Guide 2026" (ISO 42001 covers ~70% of EU AI Act high-risk documentation requirements) — examcert.app
- Protecht, "AI governance: Why ISO 42001 is the natural next certification step" (ISO 27001 organizations can achieve 42001 up to ~40% faster) — protechtgroup.com
- Credo AI, "The Six Levels of AI Maturity" — credo.ai
- European Commission, "Timeline for the Implementation of the EU AI Act" — ai-act-service-desk.ec.europa.eu
- European Commission, "Guidelines on Transparency of AI-Generated Content" — digital-strategy.ec.europa.eu