-
Notifications
You must be signed in to change notification settings - Fork 0
2026 04 26 ai lowcode governance maturity model
What maturity model best describes the evolution of governance capabilities for Artificial Intelligence (AI) and low-code in enterprises?
What maturity model best describes the evolution of governance capabilities for AI and low-code in enterprises, specifically, what are the clearly defined maturity stages, capability benchmarks, and progression pathways that allow an organisation to assess its current governance capability state and plan incremental improvements across all governance dimensions?
In scope:
- Maturity model design: definition of maturity stages (for example, initial, developing, defined, managed, optimising) with clear stage boundary criteria across all governance dimensions identified in Q1-Q12 and Q15
- Stage definitions: what capabilities, practices, evidence artefacts, and outcomes characterise each maturity level for each governance dimension
- Progression pathways: what sequence of improvements is recommended for progressing from one maturity level to the next, and what investment or effort is required at each step
- Benchmarking: how organisations can assess their current maturity level using observable evidence, not just self-assessment, and what common assessment mechanisms exist
- Existing maturity models: assessment of whether existing maturity frameworks, such as Capability Maturity Model Integration (CMMI), National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) maturity guidance, and AI governance maturity models from industry bodies, are applicable or require adaptation
- Relationship between governance maturity and risk profile: what the evidence says about the relationship between governance maturity level and operational risk, incident rate, and regulatory compliance
- The role of culture and behaviour (Q14) in maturity progression, including whether maturity models that focus only on structural capabilities without addressing behavioural conditions overstate an organisation's actual governance capability
Out of scope:
- Detailed design of individual governance dimensions, covered by Q1-Q12
- Economic modelling of the cost of maturity improvement, covered by Q8
- Specific AI or technology maturity models unrelated to governance, because the focus is governance capability maturity
Constraints:
- This item depends on the findings of Q1-Q12 and Q14-Q15 to define what governance capabilities exist and therefore what maturity stages can be meaningfully defined
- Existing maturity frameworks must be assessed for adequacy before constructing a new one, because a new maturity model is only warranted if existing frameworks are materially insufficient
- The model must address the gap between capability possession, having a tool or policy, and capability exercise, using it effectively and consistently, because a model based only on possession will overstate maturity
[fact; source: https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Public AI governance guidance already distinguishes between early experimentation, defined controls, managed scale, and continuous improvement, which means organisations need a maturity model to translate abstract governance principles into sequenced capability-building and assessable evidence.
[inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] This item is the synthesis capstone for the governance research program because the companion items show that enterprise AI and low-code governance spans identity, enforcement, lifecycle, behavioural, and regulatory surfaces, and a useful maturity model must integrate those surfaces rather than score policies in isolation.
Cross-references:
- Q1: Decision rights, accountability, and liability
- Q2: Identity and access management
- Q3: Governance enforcement architecture
- Q4: Observability and telemetry governance
- Q5: Risk-tier classification controls
- Q6: Data governance enforcement
- Q7: Lifecycle management
- Q8: Cost, performance, and delivery impact
- Q9: Human-in-the-loop design
- Q10: Software development lifecycle (SDLC) and platform engineering integration
- Q12: Failure modes and governance mitigation
- Q14: Culture, incentives, and behaviour
- Q15: Regulatory compliance alignment
- Q16: AI agent control-plane architecture
- Existing maturity model survey: Review existing AI and Information Technology (IT) governance maturity models, including CMMI, NIST AI RMF maturity guidance, AI governance maturity models from industry bodies, and sector-adjacent models. Assess each for dimensional completeness against the Q1-Q12 governance dimensions, stage definition clarity, assessment mechanism quality, and evidence of use in practice.
- Dimensional gap analysis: Identify which governance dimensions from Q1-Q12 and Q14-Q15 are absent or inadequately covered by existing maturity models, particularly machine identity management, vendor constraint management, and behavioural governance.
- Maturity model design: Based on the survey and gap analysis, either select and extend an existing model or define a new one. Define three to five maturity stages with explicit, observable stage boundary criteria for each governance dimension.
- Capability progression pathways: For each governance dimension, define the progression pathway from initial to optimising maturity, including which capabilities must be developed, in what sequence, and which evidence artefacts demonstrate progression.
- Behavioural maturity integration: Integrate the findings from Q14, culture and behaviour, into the maturity model by defining a behavioural maturity dimension that captures the gap between formal governance capability and actual practice.
- Assessment mechanism: Design a self-assessment instrument that allows organisations to rate their current maturity level against observable evidence criteria, moving beyond questionnaire-only self-assessment toward evidence-based assessment.
- Synthesis: Produce a governance maturity model, including stage definitions, capability matrix, progression pathways, and self-assessment instrument, suitable for adoption as an enterprise governance artefact.
Starting points, papers, articles, standards, and guidance. Every source includes a Uniform Resource Locator (URL).
- CMMI Institute overview — - public overview of CMMI as a staged capability-improvement and benchmarking model
- CMMI model overview — - public description of CMMI domains, business-performance framing, and benchmarking logic
- CMMI appraisal method — - public description of appraisal, benchmark maturity levels, and capability-level assessment
- National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) 1.0 publication page — - primary framework publication record and citation
- NIST AI RMF overview — - official NIST page covering framework purpose, profiles, and companion assets
- NIST AI RMF Playbook — - official playbook page showing voluntary guidance and implementation support
- International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview — - official overview of the Artificial Intelligence Management System standard and continual-improvement framing
- Responsible AI Toolkit — - current United Kingdom government toolkit collection for safe and responsible AI development and deployment
- British Standards Institution (BSI) AI Foundation Framework — - official BSI page describing modular, stepwise AI trust and capability building
- Microsoft agentic AI adoption maturity model overview — - current public five-level AI maturity model with five pillars
- Microsoft governance, security, and operations maturity pillar — - detailed public stage descriptions for governance and lifecycle evolution
- Microsoft technology and data maturity pillar — - public stage descriptions for technology, data, and Application Lifecycle Management (ALM) evolution
- Microsoft organisation and culture maturity pillar — - public stage descriptions for behaviour, enablement, and cultural maturity
- Microsoft business strategy maturity pillar — - public stage descriptions for business-process redesign and value realisation
- MIT Sloan article on enterprise AI maturity — - practitioner summary of the MIT Center for Information Systems Research (MIT CISR) maturity model
- MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model — - research briefing linking four maturity stages to enterprise performance
- DevOps Research and Assessment (DORA) 2025 report announcement — - public summary of foundational-capability findings
- DORA AI capabilities model report page — - public summary of the seven foundational capabilities and platform findings
- Gartner documents portal — - seeded analyst source, access-gated in this session and not used for downstream factual support
- Business-led low-code agent governance
- Enterprise AI capability model for use-case maturity decisions
- Governance enforcement architecture for AI and low-code
(Full output from running the research skill - retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)
- [fact; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html] Research question restated: what maturity model best explains and benchmarks the evolution of enterprise AI and low-code governance, including clearly defined stages, observable evidence, and incremental progression pathways across the governance dimensions identified by the companion items?
- [fact; source: https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Scope confirmed: the investigation covers public maturity ladders, governance-system standards, assurance guidance, and evidence on capability progression, and then maps them against the AI and low-code governance surfaces already established in companion items.
- [fact; source: https://cmmiinstitute.com/; https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/; https://www.gov.uk/government/collections/responsible-ai-toolkit] Constraint handling: public and accessible sources were weighted most heavily, the paywalled Gartner portal was recorded but not used for core claims, and updated official pages replaced obsolete seed links.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Prior work cross-reference: adjacent completed items already established that enterprise governance depends on decision rights, identity, enforcement, observability, data controls, lifecycle gates, human oversight, culture, and regulatory alignment, so this item translates those governance surfaces into staged capability thresholds rather than re-deriving the surfaces themselves.
- [fact; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.iso.org/standard/81230.html] Output format confirmed: knowledge, specifically a five-stage governance maturity model with stage definitions, capability matrix, progression pathways, and an evidence-based assessment method.
- Root question: Which maturity model best supports staged, evidence-based improvement of AI and low-code governance in enterprises?
-
A. Existing maturity models
- A1. What does CMMI contribute on staged progression and benchmarking?
- A2. What does the Microsoft agentic AI maturity model contribute on AI-specific staging?
- A3. What do MIT Center for Information Systems Research (MIT CISR) and DevOps Research and Assessment (DORA) contribute on cumulative capability building and outcomes?
- A4. What do the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF), International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC) 42001, the Responsible AI Toolkit, and the British Standards Institution (BSI) AI Foundation Framework contribute on governance baselines and assurance?
-
B. Gap analysis
- B1. Which required governance surfaces are absent or only weakly specified in each external model?
- B2. Which gaps matter most for regulated, multi-vendor AI and low-code environments?
-
C. Stage design
- C1. How many stages are useful without collapsing meaningful distinctions?
- C2. What boundary criteria distinguish one stage from the next?
- C3. Which dimensions must gate maturity instead of being averaged away?
-
D. Progression pathways
- D1. What sequence of improvements is supported by the evidence?
- D2. Which artefacts and operating signals prove progression?
-
E. Assessment
- E1. How should organisations evidence maturity objectively?
- E2. How should behavioural maturity affect structural maturity claims?
- [fact; source: https://www.gartner.com/en/documents] Access note: the seeded Gartner portal was access-gated and was not used for downstream factual support.
- [fact; source: https://www.gov.uk/government/collections/responsible-ai-toolkit] Access note: the seeded United Kingdom Department for Science, Innovation and Technology (DSIT)
responsible-aicollection URL no longer resolved cleanly, so the current Responsible AI Toolkit collection page was used instead. - [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview] Access note: the seeded Microsoft
our-approach/ai-maturity-modelpage returned 404, so the current official Microsoft Copilot Studio maturity-model guidance was used instead. - [fact; source: https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] Access note: the seeded BSI assurance-standards brochure URL no longer exposed the intended material, so the current BSI AI Foundation Framework page was used instead.
- [fact; source: https://cmmiinstitute.com/; https://cmmiinstitute.com/learning/appraisals] CMMI is a staged capability-improvement model with benchmark maturity levels and a formal appraisal method designed to identify strengths, weaknesses, and capability or maturity achievements against defined best practices.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Microsoft's public model is an AI-specific five-level maturity ladder with five capability pillars, and its detailed governance, technology, business-process, and organisational-readiness pages describe level-specific anti-patterns and progression actions.
- [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.nist.gov/itl/ai-risk-management-framework; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] NIST AI RMF 1.0 is a voluntary, use-case-agnostic governance framework organised around Govern, Map, Measure, and Manage, and its Playbook provides actions and references for implementation rather than a public stage ladder.
- [fact; source: https://www.iso.org/standard/81230.html] ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System, using a management-system logic rather than a public maturity-stage benchmark.
- [fact; source: https://www.gov.uk/government/collections/responsible-ai-toolkit] The Responsible AI Toolkit is a collection of guidance, including assurance and transparency resources, intended to support safe and responsible AI development and deployment, but it does not itself publish a public staged maturity ladder.
- [fact; source: https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] BSI describes its AI Foundation Framework as a modular, standards-based, step-by-step approach to building control, confidence, and trust in AI adoption, but the public page does not disclose a detailed enterprise governance maturity matrix.
- [fact; source: https://mitsloan.mit.edu/ideas-made-to-matter/whats-your-companys-ai-maturity-level; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] MIT CISR identifies four stages of enterprise AI maturity, links higher stages to above-industry-average financial performance, and emphasises cumulative capability building, including policies, data access, process simplification, architecture for reuse, dashboards, and new AI-enabled services.
- [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cloud.google.com/resources/content/2025-dora-ai-capabilities-model-report] DORA reports that AI amplifies existing capability, that returns come from foundational systems and platform quality rather than from tools alone, and that internal platforms, clear policies, internal context, and safety nets are crucial for scaling AI value.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The external sources fall into three different classes: staged benchmark models, governance-system baselines, and assurance toolkits or frameworks.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://cmmiinstitute.com/cmmi] CMMI contributes a clear public discipline for staged benchmarking and evidence-backed appraisal, but its public material remains generic and does not specify AI-specific governance surfaces such as model access, agent autonomy, or low-code maker lanes.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Microsoft contributes a detailed current public AI-specific ladder, especially on governance, lifecycle, organisational readiness, and anti-patterns, but it is vendor-shaped and does not by itself define a multi-vendor enterprise control taxonomy.
- [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] NIST AI RMF and ISO/IEC 42001 are essential baselines for what a governed AI system must include, but they are not sufficient as public maturity models because they define functions and management-system requirements rather than explicit stage thresholds.
- [inference; source: https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The United Kingdom toolkit and BSI framework improve assurance practice and implementation support, but the public material is too high-level to serve alone as a full enterprise maturity benchmark.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] MIT CISR and DORA reinforce the progression logic that capabilities are cumulative and that performance upside appears only after organisations build shared foundations, but they do not specify the full control-surface detail needed for governance assessment.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-data-governance-ai-lowcode-enterprise-enforcement.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-human-in-the-loop-ai-automated-workflows.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The companion items collectively define a broader governance surface than any single public maturity framework, covering decision rights, machine identity, enforcement layers, observability, risk tiering, data boundaries, lifecycle gates, human oversight, software-delivery controls, failure handling, behavioural adherence, and regulatory alignment.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Adjacent evidence in the repository and in DORA also indicates that weak shared systems, not just missing policies, drive shadow adoption, governance fragmentation, and unstable scaling.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Behavioural maturity must be modelled explicitly because structural controls can exist on paper while incentives, legitimacy gaps, or governance friction keep actual practice at a lower effective level.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The best model should use five stages rather than four because a distinct stage is needed between basic repeatability and managed enterprise scale, and that distinction is visible in both CMMI-style staged logic and Microsoft's public AI ladder.
- [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cmmiinstitute.com/learning/appraisals] Stage boundaries should be defined by observable artefacts and operating evidence, not by self-description alone, because governance baselines and appraisal methods both emphasise documented controls, implemented processes, and continual review.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Maturity should be gated by the weakest mandatory control surfaces, especially identity and access, enforcement, lifecycle, and regulatory alignment, because high maturity on optional or cosmetic dimensions does not compensate for failure on control-critical dimensions.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Behaviour should act as a maturity cap, not as a side score, because governance that is routinely bypassed is not genuinely mature even if the control design is formally strong.
- [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The completed companion items are treated as a sufficiently comprehensive inventory of required governance dimensions for this capstone model. Justification: this item was explicitly sequenced after those companion items and its value depends on synthesising their already-completed control surfaces rather than independently rediscovering them.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html] If the model is chosen only for appraisal structure, CMMI is the clearest fit but too generic; if chosen only for current public AI-specific stage descriptions, Microsoft's model is the clearest fit but too vendor-shaped; and if chosen only for governance completeness, NIST AI RMF and ISO/IEC 42001 are the clearest fits but not staged enough for benchmarking.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] The strongest evidence supports a cumulative progression model in which organisations move from experimentation to repeatability, then to defined shared controls, then to measured risk-tiered scaling, and finally to adaptive assurance.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Structural capability without behavioural adoption is not a valid basis for rating maturity because both the behavioural companion item and Microsoft's readiness pillar treat incentives, enablement, and actual operating habits as part of maturity, not as optional change-management decoration.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] The assessment mechanism must therefore rely on objective artefacts, operating metrics, and assurance records, with questionnaires used only as prompts for evidence collection rather than as the scoring mechanism itself.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://cmmiinstitute.com/learning/appraisals] A four-stage model was considered but rejected because it collapses the distinction between basic repeatability and measured enterprise scale that Microsoft's five-level ladder and CMMI-style staged benchmarking keep separate.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Weighted-dimension scoring was considered but rejected because it would let strong scores on non-critical dimensions mask failure on identity, enforcement, or regulatory controls.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Separate structural and behavioural scores were considered, but a behavioural cap was chosen for the headline maturity rating because publishing a high structural score beside a low behavioural score would still overstate effective maturity in practice.
- [fact; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] The external sources are consistent on the core point that maturity is cumulative, stage-based, and linked to repeatable organisational capability rather than to isolated pilots.
- [fact; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://www.gov.uk/government/collections/responsible-ai-toolkit] The governance-baseline sources are consistent that responsible AI requires documented governance, risk management, implementation support, and continual review, even though they do not publish the same public stage ladders.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html] There is no contradiction between the software-delivery evidence and the governance evidence, because both indicate that scaling faster than shared controls and foundations produces instability and fragmentation.
- [inference; source: https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/; https://www.gov.uk/government/collections/responsible-ai-toolkit] The remaining uncertainty is not about whether staged governance maturity is needed, but about how much extra detail inaccessible analyst material or non-public assurance frameworks would add to the public hybrid model.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html] Technical lens: higher maturity depends on internal platforms, governed data access, source control, Application Programming Interface (API) reuse, deployment gates, and telemetry, because these are the shared systems that absorb faster AI and low-code change safely.
- [inference; source: https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Regulatory lens: the stage model must treat demonstrable governance, assurance, and reviewability as part of maturity because public governance baselines increasingly emphasise profiles, management systems, assurance, and auditable controls.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Economic lens: the strongest economic signal is not that every additional control raises value, but that value appears when organisations cross the threshold from isolated pilots to reusable enterprise foundations and managed scale.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html] Behavioural lens: behavioural readiness is not downstream of maturity but constitutive of it, because governance that is seen as slow, illegitimate, or optional will be bypassed.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://mitsloan.mit.edu/ideas-made-to-matter/whats-your-companys-ai-maturity-level] Historical lens: stage-based maturity logic remains useful because repeated capability-building still precedes optimisation, even though AI introduces new control surfaces compared with earlier software or process-maturity models.
Executive Summary
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] The best maturity model for enterprise AI and low-code governance is a five-stage hybrid that combines CMMI-style staged appraisal, Microsoft-style AI-specific capability pillars, and NIST AI RMF plus ISO/IEC 42001 governance baselines, because no single public model simultaneously provides benchmarkable stages, AI-specific governance detail, and full multi-surface enterprise control coverage.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] The model should be evidence-based rather than questionnaire-based, using artefacts, operating metrics, and assurance records to determine whether a capability is merely documented, consistently exercised, measured in production, or continuously improved.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Behavioural maturity must cap structural maturity, because organisations with policies, tools, and councils but with routine bypass behaviour are less mature in practice than their formal control inventory suggests.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Progression should move from ad hoc experimentation to guarded repeatability, then to defined federated governance, measured risk-tiered scale, and finally adaptive assurance, because the public evidence consistently shows that shared foundations and disciplined scaling precede durable value.
Key Findings
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] High confidence. Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external framework.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://cmmiinstitute.com/cmmi] Medium confidence. CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity model.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Medium confidence. Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shaped.
- [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] High confidence. NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholds.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Medium confidence. The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhere.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Medium confidence. Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally exist.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cloud.google.com/resources/content/2025-dora-ai-capabilities-model-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] High confidence. The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurable.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] High confidence. A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires alone.
Evidence Map
Assumptions
- [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The completed companion items are a sufficiently complete inventory of governance dimensions for this capstone model. Justification: the workflow intentionally sequenced this item after those companion items, and the remaining uncertainty is about staging and benchmarking, not about discovering wholly new governance surfaces.
- [assumption; source: https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The inaccessible Gartner material and non-public details behind BSI offerings would refine the model more than overturn it. Justification: the public sources already agree on staged progression and governance-system foundations, so the missing material is more likely to add benchmarking nuance than to reverse the core conclusion.
Analysis
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] The proposed model is a five-stage hybrid called the Enterprise AI and Low-Code Governance Maturity Model, and it uses CMMI-style appraisal logic, Microsoft's five-level AI-specific ladder, and NIST plus ISO governance baselines as its external backbone.
| Stage | Name | Proposed threshold | Typical evidence | Basis |
|---|---|---|---|---|
| 1 | Ad hoc experimentation | [inference] Local pilots exist, but there is no enterprise inventory, no tiering, no AI-specific governance, and no repeatable maker or deployment path. | [inference] Pilot demos, informal approvals, personal workspaces, fragmented logs |
https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview |
| 2 | Guardrailed repeatability | [inference] Basic policy, ownership, environment separation, intake, and low-risk guardrails exist, but enforcement is still partial and manual. | [inference] Acceptable-use policy, named owners, dev-test-prod separation, simple intake form, first connector restrictions |
https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://www.gov.uk/government/collections/responsible-ai-toolkit https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian |
| 3 | Defined federated governance | [inference] Enterprise standards, role clarity, risk tiers, approved build paths, lifecycle gates, registry, telemetry, and delegated low-risk execution exist under shared guardrails. | [inference] Standard control library, risk-tier matrix, registry, approved reference architectures, lifecycle checklist, baseline dashboards |
https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html |
| 4 | Managed risk-tiered scale | [inference] Controls are measured in production, approvals and enforcement are increasingly automated, and value, risk, and reliability are reviewed by tier. | [inference] Automated policy checks, release gates, alerting, value dashboards, exception workflow, retirement reviews |
https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html |
| 5 | Adaptive assurance | [inference] Governance, assurance, and optimisation adapt continuously using telemetry, incident learning, regulatory change, and predictive risk signals. | [inference] Continuous compliance evidence, predictive risk analytics, automated remediation, cross-functional optimisation cadence, external assurance artefacts |
https://www.iso.org/standard/81230.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://www.nist.gov/itl/ai-risk-management-framework |
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-data-governance-ai-lowcode-enterprise-enforcement.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-human-in-the-loop-ai-automated-workflows.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The capability matrix below maps the companion governance dimensions to stage thresholds so organisations can see where maturity is constrained.
| Dimension | Stage 2 threshold | Stage 3 threshold | Stage 4 threshold | Stage 5 threshold | Basis |
|---|---|---|---|---|---|
| Decision rights and accountability | [inference] Named owner per use case | [inference] Responsibility-assignment matrix and escalation by agent class | [inference] Delegated approvals by risk tier | [inference] Dynamic decision rights reviewed by telemetry and incidents |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness |
| Identity and access | [inference] Basic role-based access control and approved identities | [inference] Machine and human identities governed with least privilege | [inference] Policy-driven identity enforcement and periodic access review | [inference] Continuous identity assurance and anomaly-driven remediation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html https://www.nist.gov/itl/ai-risk-management-framework |
| Enforcement architecture | [inference] Basic connector and action restrictions | [inference] Standard enforcement points defined across gateways, connectors, and runtimes | [inference] Automated multi-layer enforcement with exception workflow | [inference] Adaptive policy tuning and cross-layer consistency checks |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Observability and telemetry | [inference] Usage logs captured for shared systems | [inference] Standard dashboards, alerts, and audit trails by class | [inference] Production reliability, safety, and compliance metrics reviewed routinely | [inference] Predictive analytics and automated anomaly response |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Risk tiering | [inference] Initial low-medium-high use-case categorisation | [inference] Tier-specific controls, approvals, and deployment paths | [inference] Tier-specific service levels and automated policy selection | [inference] Dynamic re-tiering based on behaviour, incidents, and context |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook |
| Data governance | [inference] Approved data sources and basic separation | [inference] Data classification, approved retrieval patterns, and connector policy | [inference] Data lineage, sensitive-data controls, and monitored exceptions | [inference] Continuous data-policy verification and adaptive protection |
https://davidamitchell.github.io/Research/research/2026-04-26-data-governance-ai-lowcode-enterprise-enforcement.html https://www.iso.org/standard/81230.html |
| Lifecycle management | [inference] Manual review before production | [inference] Standard build-test-release-retire gates by class | [inference] Automated release gates, periodic recertification, retirement triggers | [inference] Continuous lifecycle optimisation with policy and model refresh |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Business value and cost governance | [inference] Basic success criteria and owner | [inference] Baselines, key metrics, and portfolio visibility | [inference] Value and cost reviewed by risk tier and lifecycle status | [inference] Real-time value-risk optimisation and retirement discipline |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-cost-performance-delivery-impact.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-business-process |
| Human oversight | [inference] Human approval for sensitive actions | [inference] Defined human-in-the-loop patterns by risk tier | [inference] Escalation logic and auditability for overrides | [inference] Dynamic oversight calibrated by confidence and incident learning |
https://davidamitchell.github.io/Research/research/2026-04-26-human-in-the-loop-ai-automated-workflows.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-business-process |
| SDLC and platform engineering | [inference] Shared repository and basic environment separation | [inference] Reference architectures, templates, and approved build paths | [inference] Automated testing, policy-as-code, and platform self-service with guardrails | [inference] Platform continuously evolves from telemetry and failure analysis |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report |
| Vendor and platform constraints | [inference] Known platform limits recorded for major tools | [inference] Compensating controls documented and approved | [inference] Constraint monitoring and standard fallback patterns | [inference] Constraint-aware routing and automatic policy adaptation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html https://www.iso.org/standard/81230.html |
| Failure-mode management | [inference] Incident logging and basic postmortems | [inference] Failure taxonomy and standard mitigations | [inference] Near-miss tracking, control testing, and scenario drills | [inference] Predictive prevention and closed-loop remediation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Culture and incentives | [inference] Basic training and sponsorship | [inference] Sanctioned-path norms, champions, and clear expectations | [inference] Incentives reinforce responsible use and escalation | [inference] Responsible autonomy is normalised and measured |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness |
| Regulatory alignment | [inference] Baseline legal and compliance review | [inference] Mapped obligations by use-case tier | [inference] Evidence pack and review cadence aligned to material regulations | [inference] Continuous compliance monitoring and external assurance readiness |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html https://www.nist.gov/itl/ai-risk-management-framework https://www.iso.org/standard/81230.html |
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] The recommended progression pathway is sequential rather than opportunistic.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10] Establish AI literacy, acceptable-use policy, ownership, and a minimum inventory before scaling pilots.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://www.gov.uk/government/collections/responsible-ai-toolkit] Introduce guardrails, intake, environment separation, basic risk tiers, and reviewable evidence for shared or production use cases.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Standardise the sanctioned build path with identity, data, lifecycle, and deployment controls embedded into reusable enterprise patterns.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html] Move to measured scale by automating policy checks, release gates, telemetry, exception handling, and value-risk reviews by tier.
- [inference; source: https://www.iso.org/standard/81230.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance] Reach adaptive assurance only after the organisation can continuously update controls, assurance, and operating patterns from incidents, telemetry, and regulatory change.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html] The assessment mechanism should use the following rules.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Score each dimension only when evidence is present in three forms: design evidence, operating evidence, and assurance evidence.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Determine overall maturity using the lowest common stage across mandatory control dimensions rather than the average of all dimensions.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Apply a behavioural cap so that if culture and incentives are more than one stage below structural controls, effective maturity is capped at the behavioural stage.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.iso.org/standard/81230.html] Reassess quarterly, after major incidents, and before materially increasing autonomy, because maturity is an operating condition rather than a one-time certification.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-cost-performance-delivery-impact.html] Treat a maturity claim as credible only when the organisation can show that higher control rigor is improving stability, delivery quality, or measurable governance outcomes rather than adding untracked friction.
Risks, Gaps, and Uncertainties
- [fact; source: https://www.gartner.com/en/documents] Paywalled Gartner material was unavailable, so the synthesis does not compare its analyst framing directly with the public hybrid model.
- [fact; source: https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The public DSIT and BSI materials are useful but high-level, which limits how much public evidence exists for externally benchmarked AI-governance maturity assessment mechanisms.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Some dimension-specific thresholds rely partly on same-repository companion syntheses, so those rows are medium confidence until more public cross-enterprise benchmarking studies become accessible.
Open Questions
- [inference; source: https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] How closely would analyst or proprietary assurance frameworks agree with the proposed gating rule and behavioural cap if their full scoring rubrics were accessible?
- [inference; source: https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html] Which sectors should require Stage 4 rather than Stage 3 as the minimum operating threshold for production generative or agentic use cases?
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Which telemetry and assurance signals are most predictive of a pending maturity downgrade before a major incident occurs?
- [fact; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] Review outcome: the synthesis is grounded in accessible public evidence spanning staged maturity models, governance baselines, and capability-foundation research.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Review outcome: adjacent completed items on identity, enforcement, lifecycle, behaviour, and regulatory alignment were re-checked so the maturity model cites the most relevant same-repository governance surfaces directly where they qualify stage thresholds.
- [inference; source: https://www.gartner.com/en/documents; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] Review outcome: the remaining uncertainty is confined to inaccessible analyst content and public high-level assurance materials rather than to the core conclusion that a hybrid, evidence-based maturity model is required.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html] The best maturity model for enterprise AI and low-code governance is a five-stage hybrid that combines CMMI-style staged appraisal, Microsoft-style AI-specific capability pillars, and NIST AI RMF plus ISO/IEC 42001 governance baselines, because no single public model simultaneously provides benchmarkable stages, AI-specific governance detail, and full multi-surface enterprise control coverage.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] The model should be evidence-based rather than questionnaire-based, using artefacts, operating metrics, and assurance records to determine whether a capability is merely documented, consistently exercised, measured in production, or continuously improved.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Behavioural maturity must cap structural maturity, because organisations with policies, tools, and councils but with routine bypass behaviour are less mature in practice than their formal control inventory suggests.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] Progression should move from ad hoc experimentation to guarded repeatability, then to defined federated governance, measured risk-tiered scale, and finally adaptive assurance, because the public evidence consistently shows that shared foundations and disciplined scaling precede durable value.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html; https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] High confidence. Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external framework.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://cmmiinstitute.com/cmmi] Medium confidence. CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity model.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Medium confidence. Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shaped.
- [inference; source: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html] High confidence. NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholds.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Medium confidence. The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhere.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Medium confidence. Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally exist.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cloud.google.com/resources/content/2025-dora-ai-capabilities-model-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] High confidence. The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurable.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] High confidence. A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires alone.
- [assumption; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The completed companion items are a sufficiently complete inventory of governance dimensions for this capstone model. Justification: the workflow intentionally sequenced this item after those companion items, and the remaining uncertainty is about staging and benchmarking, not about discovering wholly new governance surfaces.
- [assumption; source: https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The inaccessible Gartner material and non-public details behind BSI offerings would refine the model more than overturn it. Justification: the public sources already agree on staged progression and governance-system foundations, so the missing material is more likely to add benchmarking nuance than to reverse the core conclusion.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10; https://www.iso.org/standard/81230.html; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian] The proposed model is a five-stage hybrid called the Enterprise AI and Low-Code Governance Maturity Model, and it uses CMMI-style appraisal logic, Microsoft's five-level AI-specific ladder, and NIST plus ISO governance baselines as its external backbone.
| Stage | Name | Proposed threshold | Typical evidence | Basis |
|---|---|---|---|---|
| 1 | Ad hoc experimentation | [inference] Local pilots exist, but there is no enterprise inventory, no tiering, no AI-specific governance, and no repeatable maker or deployment path. | [inference] Pilot demos, informal approvals, personal workspaces, fragmented logs |
https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview |
| 2 | Guardrailed repeatability | [inference] Basic policy, ownership, environment separation, intake, and low-risk guardrails exist, but enforcement is still partial and manual. | [inference] Acceptable-use policy, named owners, dev-test-prod separation, simple intake form, first connector restrictions |
https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://www.gov.uk/government/collections/responsible-ai-toolkit https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian |
| 3 | Defined federated governance | [inference] Enterprise standards, role clarity, risk tiers, approved build paths, lifecycle gates, registry, telemetry, and delegated low-risk execution exist under shared guardrails. | [inference] Standard control library, risk-tier matrix, registry, approved reference architectures, lifecycle checklist, baseline dashboards |
https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html |
| 4 | Managed risk-tiered scale | [inference] Controls are measured in production, approvals and enforcement are increasingly automated, and value, risk, and reliability are reviewed by tier. | [inference] Automated policy checks, release gates, alerting, value dashboards, exception workflow, retirement reviews |
https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html |
| 5 | Adaptive assurance | [inference] Governance, assurance, and optimisation adapt continuously using telemetry, incident learning, regulatory change, and predictive risk signals. | [inference] Continuous compliance evidence, predictive risk analytics, automated remediation, cross-functional optimisation cadence, external assurance artefacts |
https://www.iso.org/standard/81230.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance https://www.nist.gov/itl/ai-risk-management-framework |
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html; https://davidamitchell.github.io/Research/research/2026-04-26-data-governance-ai-lowcode-enterprise-enforcement.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html; https://davidamitchell.github.io/Research/research/2026-04-26-human-in-the-loop-ai-automated-workflows.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] The capability matrix below maps the companion governance dimensions to stage thresholds so organisations can see where maturity is constrained.
| Dimension | Stage 2 threshold | Stage 3 threshold | Stage 4 threshold | Stage 5 threshold | Basis |
|---|---|---|---|---|---|
| Decision rights and accountability | [inference] Named owner per use case | [inference] Responsibility-assignment matrix and escalation by agent class | [inference] Delegated approvals by risk tier | [inference] Dynamic decision rights reviewed by telemetry and incidents |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness |
| Identity and access | [inference] Basic role-based access control and approved identities | [inference] Machine and human identities governed with least privilege | [inference] Policy-driven identity enforcement and periodic access review | [inference] Continuous identity assurance and anomaly-driven remediation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html https://www.nist.gov/itl/ai-risk-management-framework |
| Enforcement architecture | [inference] Basic connector and action restrictions | [inference] Standard enforcement points defined across gateways, connectors, and runtimes | [inference] Automated multi-layer enforcement with exception workflow | [inference] Adaptive policy tuning and cross-layer consistency checks |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Observability and telemetry | [inference] Usage logs captured for shared systems | [inference] Standard dashboards, alerts, and audit trails by class | [inference] Production reliability, safety, and compliance metrics reviewed routinely | [inference] Predictive analytics and automated anomaly response |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Risk tiering | [inference] Initial low-medium-high use-case categorisation | [inference] Tier-specific controls, approvals, and deployment paths | [inference] Tier-specific service levels and automated policy selection | [inference] Dynamic re-tiering based on behaviour, incidents, and context |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook |
| Data governance | [inference] Approved data sources and basic separation | [inference] Data classification, approved retrieval patterns, and connector policy | [inference] Data lineage, sensitive-data controls, and monitored exceptions | [inference] Continuous data-policy verification and adaptive protection |
https://davidamitchell.github.io/Research/research/2026-04-26-data-governance-ai-lowcode-enterprise-enforcement.html https://www.iso.org/standard/81230.html |
| Lifecycle management | [inference] Manual review before production | [inference] Standard build-test-release-retire gates by class | [inference] Automated release gates, periodic recertification, retirement triggers | [inference] Continuous lifecycle optimisation with policy and model refresh |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Business value and cost governance | [inference] Basic success criteria and owner | [inference] Baselines, key metrics, and portfolio visibility | [inference] Value and cost reviewed by risk tier and lifecycle status | [inference] Real-time value-risk optimisation and retirement discipline |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-cost-performance-delivery-impact.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-business-process |
| Human oversight | [inference] Human approval for sensitive actions | [inference] Defined human-in-the-loop patterns by risk tier | [inference] Escalation logic and auditability for overrides | [inference] Dynamic oversight calibrated by confidence and incident learning |
https://davidamitchell.github.io/Research/research/2026-04-26-human-in-the-loop-ai-automated-workflows.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-business-process |
| SDLC and platform engineering | [inference] Shared repository and basic environment separation | [inference] Reference architectures, templates, and approved build paths | [inference] Automated testing, policy-as-code, and platform self-service with guardrails | [inference] Platform continuously evolves from telemetry and failure analysis |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report |
| Vendor and platform constraints | [inference] Known platform limits recorded for major tools | [inference] Compensating controls documented and approved | [inference] Constraint monitoring and standard fallback patterns | [inference] Constraint-aware routing and automatic policy adaptation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-control-plane-architecture-enterprise.html https://www.iso.org/standard/81230.html |
| Failure-mode management | [inference] Incident logging and basic postmortems | [inference] Failure taxonomy and standard mitigations | [inference] Near-miss tracking, control testing, and scenario drills | [inference] Predictive prevention and closed-loop remediation |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-failure-modes-governance-mitigation.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance |
| Culture and incentives | [inference] Basic training and sponsorship | [inference] Sanctioned-path norms, champions, and clear expectations | [inference] Incentives reinforce responsible use and escalation | [inference] Responsible autonomy is normalised and measured |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness |
| Regulatory alignment | [inference] Baseline legal and compliance review | [inference] Mapped obligations by use-case tier | [inference] Evidence pack and review cadence aligned to material regulations | [inference] Continuous compliance monitoring and external assurance readiness |
https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html https://www.nist.gov/itl/ai-risk-management-framework https://www.iso.org/standard/81230.html |
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] The recommended progression pathway is sequential rather than opportunistic.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10] Establish AI literacy, acceptable-use policy, ownership, and a minimum inventory before scaling pilots.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://www.gov.uk/government/collections/responsible-ai-toolkit] Introduce guardrails, intake, environment separation, basic risk tiers, and reviewable evidence for shared or production use cases.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-technology; https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-lifecycle-management.html] Standardise the sanctioned build path with identity, data, lifecycle, and deployment controls embedded into reusable enterprise patterns.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-risk-tier-classification-controls.html] Move to measured scale by automating policy checks, release gates, telemetry, exception handling, and value-risk reviews by tier.
- [inference; source: https://www.iso.org/standard/81230.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance] Reach adaptive assurance only after the organisation can continuously update controls, assurance, and operating patterns from incidents, telemetry, and regulatory change.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook; https://www.iso.org/standard/81230.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html] The assessment mechanism should use the following rules.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook] Score each dimension only when evidence is present in three forms: design evidence, operating evidence, and assurance evidence.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Determine overall maturity using the lowest common stage across mandatory control dimensions rather than the average of all dimensions.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Apply a behavioural cap so that if culture and incentives are more than one stage below structural controls, effective maturity is capped at the behavioural stage.
- [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.iso.org/standard/81230.html] Reassess quarterly, after major incidents, and before materially increasing autonomy, because maturity is an operating condition rather than a one-time certification.
- [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-cost-performance-delivery-impact.html] Treat a maturity claim as credible only when the organisation can show that higher control rigor is improving stability, delivery quality, or measurable governance outcomes rather than adding untracked friction.
- [inference; source: https://cisr.mit.edu/publication/2024_1201_EnterpriseAIMaturityModel_WeillWoernerSebastian; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-overview; https://cmmiinstitute.com/learning/appraisals] A four-stage model was considered but rejected because it collapses the distinction between basic repeatability and measured enterprise scale that Microsoft's five-level ladder and CMMI-style staged benchmarking keep separate.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-agent-identity-access-management-enterprise.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-governance-enforcement-architecture.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Weighted-dimension scoring was considered but rejected because it would let strong scores on non-critical dimensions mask failure on identity, enforcement, or regulatory controls.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-governance-culture-incentives-behaviour.html; https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-readiness] Separate structural and behavioural scores were considered, but a behavioural cap was chosen for the headline maturity rating because publishing a high structural score beside a low behavioural score would still overstate effective maturity in practice.
- [fact; source: https://www.gartner.com/en/documents] Paywalled Gartner material was unavailable, so the synthesis does not compare its analyst framing directly with the public hybrid model.
- [fact; source: https://www.gov.uk/government/collections/responsible-ai-toolkit; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] The public DSIT and BSI materials are useful but high-level, which limits how much public evidence exists for externally benchmarked AI-governance maturity assessment mechanisms.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-decision-rights-accountability-liability.html; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-regulatory-compliance-alignment.html] Some dimension-specific thresholds rely partly on same-repository companion syntheses, so those rows are medium confidence until more public cross-enterprise benchmarking studies become accessible.
- [inference; source: https://www.gartner.com/en/documents; https://www.bsigroup.com/en-GB/products-and-services/modular-solutions/ai-foundation-framework/] How closely would analyst or proprietary assurance frameworks agree with the proposed gating rule and behavioural cap if their full scoring rubrics were accessible?
- [inference; source: https://www.nist.gov/itl/ai-risk-management-framework; https://www.iso.org/standard/81230.html] Which sectors should require Stage 4 rather than Stage 3 as the minimum operating threshold for production generative or agentic use cases?
- [inference; source: https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance; https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-observability-telemetry-governance.html] Which telemetry and assurance signals are most predictive of a pending maturity downgrade before a major incident occurs?
- Type: knowledge
- Description: A five-stage enterprise governance maturity model for AI and low-code that combines staged appraisal, governance baselines, capability matrices, progression pathways, and an evidence-based assessment method.
- Links:
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson