The EU AI Act Is Here. Most Are Guessing. Some Already Know Where They Stand.
A few elite organizations are already running dedicated tech-legal cross teams to govern their AI posture. The rest are still treating compliance as a checkbox. The distance between them is growing.
There is a moment, early in every AI Readiness Assessment, that tells you almost everything you need to know. Not the scores. Not the gap. The moment before any question is asked. When you look around and see who came.
In some organizations, one person arrives. A CFO sent to represent the company. A CTO dispatched to receive a verdict. They sit across from you, arms ready to take notes, minds already half-defending the decisions already made. The assessment will happen. The report will be delivered. And somewhere between the scorecard and the inbox, the truth will be quietly filed away.
In others, the room fills. Architects. Heads of engineering. The people who actually build the systems, alongside the people responsible for their direction. They don’t arrive to receive a verdict. They arrive to think together. And before a single dimension has been scored, you already know which path this organization is on.
What the assessment actually measures
The AI Readiness Assessment covers four dimensions. Each one probes a different layer of organizational capacity.
Focus and Time Management measures whether developers have the protected cognitive space to actually supervise AI output. Not whether they have access to tools, or whether they have the attention required to challenge them.
Technical Practices and Engineering Excellence assesses whether the team can verify what AI produces. Testing discipline, code quality, the capacity to catch what automated reviews miss.
Product and Backlog Health examines whether intent is clear enough for AI to work from. User stories that communicate, acceptance criteria that specify, a backlog that reflects product thinking rather than ticket accumulation.
Customer Obsession and Satisfaction measures the feedback loop. How fast does reality reach the team that built the feature? How tightly is what was shipped connected to what customers actually experienced?
Each dimension is scored 1 to 10, mapped against three states: Chaos, Plateau, Amplification. The gap between AI adoption percentage and organizational readiness percentage produces the risk metric. And the risk metric tells you one thing:
whether AI is amplifying your organization’s excellence, or its dysfunction.
Two organizations that faced the truth
A major European infrastructure operator and a large insurance company came to the assessment with something unusual: the right people in the room. Not one representative. Not a single point of contact. Architects, engineering leads, heads of product. Stakeholders with their skin in the game. The conversations were honest. The gaps surfaced quickly, not because the questions were clever, but because the people answering them had come to think, not to defend.
Both organizations showed high technical maturity. Years of software craftsmanship work had built strong engineering foundations. But both were running SAFe at scale, and both were experiencing the same friction that scaled frameworks tend to produce: interrupted focus on the ground, mechanical product management driven by Jira ceremonies rather than genuine product discovery, and feedback loops long enough to sever the connection between what shipped and what customers felt.
The AI adoption numbers were high. The readiness to supervise AI output was lagging behind.
What they chose to do with that information is what separates them from the next two stories.
Both organizations designed a three-cluster trial. One team continued working as before: the baseline. A second team that went through the Software Craftsmanship Dojo and was equipped with AI tooling, but without guidelines. A third team that also went through the Dojo, was equipped with AI tooling, and was trained to work within nWave.ai, a human-centered deterministic agentic AI software factory where humans remain in control at every step of the development process, or as Andrea Laforgia put it:
nWave goes beyond spec-driven development. It is expectation-driven development.
The results from the third cluster were unambiguous. Teams working with nWave were delivering a full sprint’s worth of work in three days. After gaining maturity with the tool, that compressed to a single day. A 300% performance boost at the start; growing toward something closer to 1000% as the team found its rhythm.
Beyond velocity, something structural had changed. Documentation lived inside the repository as living records. Fully correlated between what was developed, how it was developed, and how it reached production. Product, quality assurance, development, and ops were cooperating daily, sometimes multiple times a day. The feedback loop had closed. The disconnection that SAFe had been producing for years was gone.
Both organizations are now expanding toward a production pilot. That story will continue in the coming months.
Two organizations that looked away
The data from two other assessments tells a different story.
One company, a technology series B startup, came to the assessment with 85% of their development team using AI tools daily. Their organizational readiness measured at 42%. A 43% gap. Their Product dimension scored 2 out of 10: Chaos. Their Focus dimension scored 3 out of 10: Chaos. The most telling detail: despite 85% claimed adoption, actual observed usage was around 50%. A trust deficit, rooted in missing fundamentals. The tools were there. The capacity to use them well was not.
A second company, in logistics technology, showed 80% adoption against 45% readiness: a 35% gap. Their engineering foundations were stronger, but their Product dimension was also in Chaos at 3 out of 10. Agentic code reviews had been automated without guardrails. The pipeline was moving fast. Nobody was checking what it was producing.
Both received the same recommendation: NO-GO. Halt AI expansion. Build the foundations before resuming.
Both chose not to act.
What happened next was not a technology problem. The bottleneck didn’t disappear; it relocated. When technology is no longer the constraint and the human layer hasn’t moved, the friction surfaces exactly where behavioral science predicts it will: in communication breakdowns, in coordination failures, in the slow compounding of small misalignments that no tool can resolve because no tool was designed to resolve them. The dysfunction didn’t vanish. It found a new address.
What the room tells you before the scores do
Bob FlowChainSensei-Marshall, organizational psychotherapist, and a voice in the conversation that followed episode 88 of this series, recently wrote something precise on this. His argument:
the single greatest suppressor of collective thinking in an organization is not a lack of information, tools, or time. It is the absence of felt agency. The private conviction that what you think, say, or contribute will make no meaningful difference to what actually happens.
When people don’t believe their contribution changes anything, you don’t get collective insight. You get performative behavior. And when the moment of truth arrives (an assessment, a retrospective, a hard conversation about what the data is actually showing), you get one person sent to receive a verdict instead of a room full of people ready to face it together.
The four organizations above ran the same assessment. The scores were different. But the decisive variable wasn’t the scores. It was whether the organization had enough felt agency in the room to do something with what it found.
Bob’s full piece is worth reading: Agency
The path forward
The AI Readiness Assessment is not a verdict. It is a mirror. What it shows you is the distance between where you are and where your AI investment needs you to be. The last mile that most organizations don’t know they’re walking.
The four cases above ran the same assessment. They saw similar gaps. Two of them brought the right people into the room and built a framework to close the distance incrementally, measurably, sustainably. Two of them filed the report and moved on.
The mirror doesn’t change based on who looks into it. But what you choose to do next. That part is entirely yours.
If you’re ready to see clearly: ai-readiness.dev
Next week: why Google, Microsoft, and Anthropic are all converging on the same architecture, and what it tells us about the future of governed AI development.