AI maturity is shaped by the strength of an organisation’s data foundations and operating model.

Organisations need to understand which AI “animal” they are before deciding how to move forward. 

At Security Edge, Gabby Fredkin, Head of Analytics & Insights at ADAPT, highlights that most organisations are investing in AI, but few are converting that investment into sustained business value. 

Organisations need to assess architectural maturity alongside governance and people maturity, then ask questions that match the organisation’s current ability to adopt AI safely and productively. 

 

Key takeaways: 

  • Autonomous agents expand the control problem, making identity, permissions, monitoring and traceability central to safe scaling. 
  • The most useful next step is maturity-based: understand the current state, then build the governance or architecture capability needed for the next stage. 
  • AI maturity is shaped by data, architecture, governance and people, not by the number of AI tools an organisation can buy. 

AI maturity depends on two foundations 

The difference between experimentation and value is rarely the availability of tools.

Organisations progress when their data architecture, platforms and security practices are mature enough to support AI, and when governance, capability and control are embedded across the business. 

These foundations can be mapped across four “animals”: koalas are cautious and immature on both axes; greyhounds move quickly but lack consistency; turtles have strong governance but limited ability to scale; and tigers combine architectural and governance maturity. 

 

Autonomy turns AI governance into a scaling problem 

As AI has moved from public tools to enterprise applications, frontier models, agents and APIs, the control challenge has changed.

Security teams must now understand model visibility, shadow AI, token costs, non-human identities and the permissions agents have to access or change sensitive data. 

This is why 50% of tools in pilot or deployment are reportedly outside a formal governance framework: governance added after experimentation slows production, while governance built into architecture helps organisations move faster. 

 

Good data governance remains the non-negotiable starting point 

Every stage of AI adoption still depends on whether the organisation can trust, classify and observe its data.

More than half of organisations say they are not ready or only emerging in their data maturity, making data governance the practical constraint behind many AI ambitions. 

The operating model must evolve with adoption, bringing security, data, technology, finance and business leaders into decisions about sovereignty, compliance, monitoring and value; not just tool approval. 

The goal is not to become a “tiger” overnight. 

It’s to identify the organisation’s current position, ask the right maturity-based questions and build the next capability that will convert AI activity into measurable value. 

Contributors
Gabby Fredkin Head of Analytics & Insights at ADAPT
As the Head of Analytics and Insights at ADAPT, Gabby Fredkin’s primary role is managing analysis to produce ADAPT’s actionable insights to... More

As the Head of Analytics and Insights at ADAPT, Gabby Fredkin’s primary role is managing analysis to produce ADAPT’s actionable insights to identify trends supporting organisations in Australia.

With a passion for creating stories with data, Gabby is consistently rated as one of the top speakers at ADAPT’s events. In roundtable discussions, he specialises in using statistics to initiate thought-provoking discussions, enabling ADAPT’s customers to become more data-driven.​

Using modern data science techniques, he provides ADAPT and its customers with confidence in the accuracy and validity of the information used for ADAPT’s research, advisory and events.

Working across artificial intelligence, machine learning, AI ethics, DevSecOps, end-user behaviour, and human-centred design, Gabby’s vast experience continues to grow, supported in part by a Master of Business Analytics from Deakin University.

Less
security data compliance