"AI readiness" is the phrase of the moment. Every organisation wants it, every vendor sells it, and a whole cottage industry of assessments, maturity models, and consulting engagements has sprung up to tell you how ready you are and what you must buy to become readier. I've now sat through enough of these conversations to have a slightly deflating observation, which I offer in the spirit of saving people money: strip the branding off "AI readiness" and the checklist underneath is almost identical to the "data readiness" checklist we've been writing — and mostly ignoring — for a decade. The AI part is largely new marketing wrapped around old, unglamorous fundamentals. Whether that deflates you or liberates you depends entirely on how you choose to hear it, and I'd gently suggest liberating.
Let me make the case, because it's not a throwaway line. When you actually decompose what makes an organisation able to do something valuable with AI on its own data — the useful kind, not a generic chatbot — the ingredients are strikingly familiar.
The "AI readiness" checklist, decoded
- You need to know what data you have. Every AI-readiness assessment eventually asks whether you have a handle on your data estate — what exists, where it lives, what it means. That's a data catalogue. We've been saying you need one for years. The AI framing just finally got someone to fund it.
- The data has to be good, and you have to know how good. AI-readiness talks about "high-quality training data." That's data quality — completeness, accuracy, representativeness — the exact discipline that's been quietly essential and quietly neglected forever. A model on bad data is confidently wrong, which is the one thing worse than a report that's quietly wrong.
- You have to control who sees what. AI-readiness frets about models exposing sensitive data. That's access control and governance, the plumbing we've under-invested in because, until an AI could surface anything conversationally, the neglect was survivable.
- You have to trace where things came from. Readiness frameworks want "explainability" and "lineage." That's data lineage — knowing where a number originated and how it was transformed — the thing every governance programme has listed and few have delivered.
- You need the organisational habits to sustain it. Ownership, stewardship, a culture that keeps the above alive. That's data governance as a practice, and it was the hard part long before anyone said "AI."
Notice what's not on that list: nothing about GPUs, frontier models, or a particular vendor's platform. The genuinely AI-specific technology is the easy, rentable part. The hard, determinative part is the data foundation — and that foundation is the same one we've been describing under a less exciting name for a decade.
Why this is good news, not bad
The deflating reading is "so it's all just the boring stuff again." The liberating reading — the correct one — is that you already know exactly what to do, and you don't have to wait for a magic new capability to start. You don't need to crack some novel AI-readiness code. You need to do the data work you already knew you should be doing, and the AI wave has, mercifully, produced the executive urgency and the budget to finally fund it. For years those of us arguing for cataloguing, quality, and governance were asking for money to fix a problem nobody could see. Now the same work has a compelling why attached, a board that's paying attention, and a deadline. That's not a reason to be cynical. It's the best opening we've had in years to fix the foundations — the same argument I keep making that governance is the steering wheel, not the brake, finally landing because AI raised the stakes enough to make people listen.
The honest caveat
I'll grant the counter-view its due, because there is a genuinely AI-specific layer and I don't want to wave it away. There are new concerns that data readiness didn't fully cover: the particular ways models can be manipulated or leak training data, the specific evaluation of model behaviour, the new regulatory obligations arriving for high-risk AI, the questions of bias and oversight that models sharpen. Those are real, and they're additive. But they sit on top of the data foundation; they don't replace it, and they're worthless without it. You cannot govern an AI's outputs if you never governed its inputs. So the AI-specific work is real — it's just the top floor of a building whose foundation is ordinary data readiness, and you cannot start on the top floor.
What I'd actually do
If you want to be "AI-ready," here's my unglamorous, money-saving advice: don't buy the readiness product. Do the readiness work. Catalogue your data, measure and improve its quality, sort out access and lineage, and build the ownership to keep it all alive — scoped to a real use case so it ships rather than sprawls. Do that and you'll be genuinely ready for AI, and — this is the part I love — you'll also just have better data, which pays off in every dashboard, every decision, and every report whether the AI hype proves entirely justified or only half. It's the rare investment that's valuable in every possible future. The marketing says you need to become something new. The truth is you need to finally become good at something old. That's a much better deal than it sounds, and it's available to start on Monday, no frontier model required.