TL;DR: AI compliance programs fall into five maturity levels. Level 3 satisfies most US state safe harbors. Level 4 is the minimum for EU AI Act high-risk deployments. This guide defines each level, gives you a 25-question self-assessment to find your score, and shows the specific next steps to advance from wherever you are.
Auditors and regulators do not grade AI governance on pass/fail. When an enforcement authority reviews your program, they assess it on a spectrum: do you have basic controls, are you following them, are you measuring whether they work, and are you improving over time? The same logic applies when a large enterprise customer asks for your AI governance documentation as a condition of signing a contract.
A maturity model makes this spectrum explicit. Instead of asking "do we have AI governance," you ask "what level are we at and what does the next level require." That framing converts an abstract compliance goal into a concrete project plan.
This guide defines five maturity levels in detail, maps each level to specific regulatory requirements, and provides a 25-question self-assessment so you can place your program accurately and identify the next actions.
Why maturity models matter for AI governance
Regulators in the US and Europe increasingly use maturity frameworks to assess AI programs. The NIST AI Risk Management Framework uses a tiered approach. EU AI Act Annex IV documentation requirements implicitly assume a Level 4 program for high-risk AI systems: you cannot produce conformity assessment documentation if you have not maintained records throughout the development and deployment lifecycle.
Auditors use the same framing. A SOC 2 Type II audit for an AI-adjacent product will assess whether controls are defined, implemented, monitored, and improved. Each of those verbs maps directly to maturity levels.
There is a commercial reason too. Enterprise procurement teams are increasingly asking suppliers for AI governance documentation. A vendor that can demonstrate Level 3 or Level 4 governance wins deals that a Level 1 or Level 2 vendor loses on risk grounds alone.
The five maturity levels
Level 1: Ad Hoc
What it looks like: Employees use AI tools without any formal process. There is no AI register, no acceptable use policy, and no one person accountable for AI governance. Decisions about which tools to use are made by individual contributors or small teams without review. No contracts with AI vendors have been reviewed for data processing terms.
Documentation: None, or scattered informal notes.
Processes: None defined.
Roles: No AI governance owner.
Typical example: A 12-person SaaS company where engineering uses GitHub Copilot, sales uses an AI email tool, and the customer success team uses a different AI assistant, all adopted independently and without any procurement or legal review.
Risk profile: High. Any one of these tools could be processing customer personal data without a DPA, training on your proprietary information, or creating IP ownership questions.
Level 2: Defined
What it looks like: An AI policy exists on paper. Someone has started an AI tool register, though it may be incomplete. The policy is not consistently followed because there is no enforcement mechanism and no one checking. Vendor contracts may have been reviewed for the top one or two tools but not systematically.
Documentation: Acceptable use policy (draft or adopted), partial AI tool register.
Processes: Informal review before adding major new tools. No risk assessment process.
Roles: One person informally responsible, no formal charter or dedicated time.
Typical example: A 20-person startup that wrote an AI policy after a customer asked for it, has a spreadsheet with the five main AI tools, but has never done a formal risk assessment and does not track whether employees are following the policy.
Risk profile: Moderate. The documentation exists but provides limited actual protection because it is not operationalized.
Level 3: Managed
What it looks like: The AI register is complete and maintained. Every material AI tool in use has a completed risk assessment and a signed DPA or vendor data processing agreement. There is an acceptable use policy that employees have acknowledged. Vendor due diligence is a defined step in the procurement process. Someone owns AI governance with a defined scope of responsibility.
Documentation: Complete AI tool register, risk assessments for all material tools, signed DPAs, acceptable use policy with acknowledgment records, vendor evaluation records.
Processes: Procurement review for new AI tools, periodic register updates (quarterly or semi-annually), incident escalation path.
Roles: Named AI governance owner with defined responsibilities, possibly part-time.
Typical example: A 30-person professional services firm where the COO owns AI governance, every AI tool above a cost threshold goes through a short review process, the tool register is reviewed quarterly, and new employees complete an AI policy acknowledgment during onboarding.
Regulatory correlation: Level 3 is sufficient for most US state-level safe harbors and general GDPR Article 5 accountability requirements. It satisfies the FTC's basic expectations for AI program governance for non-high-risk applications.
For EU AI Act purposes, Level 3 covers general-purpose AI use and low-risk AI systems. It is not sufficient for high-risk AI system deployment.
Level 4: Measured
What it looks like: The program has defined metrics: how many tools are in the register, what percentage have current risk assessments, incident counts and response times, policy acknowledgment rates, vendor due diligence completion rates. These metrics are reviewed on a schedule and reported to leadership or the board. Audits happen on a defined cadence. Policy review cycles are documented and followed.
Documentation: All Level 3 documentation plus: metrics definitions, audit reports, board or leadership reporting records, policy review logs.
Processes: Periodic compliance audits, board or leadership AI reporting, metrics review cadence, formal policy update cycle.
Roles: AI governance owner with dedicated time, audit function (internal or external).
Typical example: A 50-person financial technology company where the General Counsel prepares a quarterly AI governance report for the board, compliance audits happen twice a year, and the program has a documented scorecard that tracks five key metrics.
Regulatory correlation: Level 4 is the practical minimum for EU AI Act high-risk AI system deployers. It is also what OCC model risk guidance implies for bank-supervised entities and what the CFPB expects for AI-based credit decisioning tools.
Level 5: Optimized
What it looks like: The program includes continuous improvement loops: audit findings generate corrective action plans that are tracked to closure. Regulatory monitoring is proactive, with someone responsible for tracking developments in AI law and updating the program before deadlines. Compliance checks are automated where possible: vendor attestation renewals are tracked in a system, the AI register is integrated with procurement workflows, and incident detection uses automated monitoring.
Documentation: All Level 4 documentation plus: corrective action tracking, regulatory monitoring log, automation documentation.
Processes: Continuous improvement cycle, proactive regulatory monitoring, automated compliance checks, integration with enterprise risk management.
Roles: Dedicated AI governance function, possibly with a formal AI ethics or responsibility team.
Regulatory correlation: Level 5 is expected in regulated industries regardless of company size: financial services (OCC, FDIC, Federal Reserve model risk guidance), healthcare (FDA Software as a Medical Device requirements for AI/ML), and legal services (ABA ethics rules on competence and supervision). For companies operating at scale in multiple jurisdictions, Level 5 is also the standard expected by enterprise customers.
25-question self-assessment
Answer each question Yes (1 point), Partial (0.5 points), or No (0 points). Your total score maps to a maturity level:
- 0 to 5: Level 1 (Ad Hoc)
- 6 to 10: Level 2 (Defined)
- 11 to 16: Level 3 (Managed)
- 17 to 21: Level 4 (Measured)
- 22 to 25: Level 5 (Optimized)
Foundation
- Does your organization have a written AI acceptable use policy?
- Has the AI policy been acknowledged by all employees who use AI tools?
- Is there a named person responsible for AI governance with a defined scope?
- Does your organization maintain an AI tool register?
- Is the AI tool register complete (all material tools listed)?
Risk assessment and vendor management
- Has each AI tool in the register been assessed for data processing risk?
- Does your organization have signed DPAs or vendor data processing agreements for all AI tools that process personal data?
- Is vendor due diligence a defined step in the procurement process for new AI tools?
- Has your organization reviewed AI vendor terms for training data rights?
- Are vendor DPA renewal dates tracked and monitored?
Process maturity
- Is there a defined process for employees to request approval for a new AI tool?
- Is there a defined process for reporting an AI incident or concern?
- Has at least one tabletop exercise or review of your incident response process been completed in the past 12 months?
- Are AI governance activities included in employee onboarding?
- Does your organization have a process for reviewing AI policy when regulations change?
Documentation depth
- Does your AI risk assessment documentation include the specific data types each tool processes?
- Does your documentation include which AI tools are used in customer-facing products or services?
- Does your organization maintain records of AI governance decisions (e.g., tool approvals, risk acceptances)?
- If applicable: does your GDPR Record of Processing Activities (ROPA) include AI tool data processing?
- If applicable: does your EU AI Act documentation include post-market monitoring procedures?
Measurement and reporting
- Does your organization track defined metrics for AI compliance program performance?
- Are AI governance metrics reported to leadership or the board on a schedule?
- Has an internal or external AI governance audit been completed in the past 12 months?
- Are audit findings tracked to resolution with defined owners and timelines?
Continuous improvement
- Does your organization actively monitor regulatory developments in AI law and update the program proactively?
How to advance from each level
Advancing from Level 1 to Level 2
The two tasks that will have the greatest impact are writing an acceptable use policy and starting an AI tool register. Neither requires legal counsel: a one-page policy covering which tools are approved, what data can be used with each tool, and how to request access to a new tool is sufficient to establish Level 2.
Estimated time: Three to four weeks. Estimated cost: $0 to $3,000 (internal staff time or a template).
Advancing from Level 2 to Level 3
Level 3 requires operationalizing what Level 2 defined. The specific actions are: completing the AI tool register for all tools (not just the obvious ones), running risk assessments for each material tool, signing or updating DPAs with vendors, ensuring policy acknowledgment records exist, and putting a quarterly register review on the calendar.
Estimated time: Six to ten weeks. Estimated cost: $5,000 to $15,000 (legal review of vendor contracts, staff time for risk assessments).
Advancing from Level 3 to Level 4
Level 4 requires moving from governance that exists to governance you can demonstrate is working. Define five to eight metrics for your program, establish a reporting cadence to leadership, schedule a compliance audit (even an internal one is valuable), and document the policy review cycle.
Estimated time: Four to eight weeks to establish. Three to six months to have meaningful data to report. Estimated cost: $3,000 to $10,000 (audit facilitation, reporting template development).
Advancing from Level 4 to Level 5
Level 5 requires building systems, not just processes. This means integrating AI governance into procurement workflows (so new tool approvals happen automatically at the right step), setting up automated monitoring of vendor compliance attestations, and assigning someone to track regulatory developments. In regulated industries, this also means connecting AI governance to the enterprise risk management framework.
Estimated time: Three to six months for the automation and integration work. Estimated cost: $10,000 to $40,000 depending on the level of automation and whether dedicated headcount is added.
Regulatory mapping by maturity level
| Level | US state safe harbors | EU AI Act (general use) | EU AI Act (high-risk) | Regulated industries |
|---|---|---|---|---|
| 1 | No | No | No | No |
| 2 | Partial | Partial | No | No |
| 3 | Yes | Yes | Partial | No |
| 4 | Yes | Yes | Yes | Partial |
| 5 | Yes | Yes | Yes | Yes |
Most US state AI laws (including Colorado SB 205, Texas HB 4480, and Illinois AIEA) include safe harbor language that protects organizations from certain enforcement actions if they have documented governance programs. Level 3 is typically the threshold for these safe harbors. Colorado's specific language references "reasonable policies and programs" for managing algorithmic discrimination.
Time and cost estimates for a 10-person team
| Level transition | Elapsed time | Cost estimate |
|---|---|---|
| Level 1 to Level 2 | 3 to 4 weeks | $0 to $3,000 |
| Level 2 to Level 3 | 6 to 10 weeks | $5,000 to $15,000 |
| Level 3 to Level 4 | 4 to 8 weeks | $3,000 to $10,000 |
| Level 4 to Level 5 | 3 to 6 months | $10,000 to $40,000 |
| Level 1 to Level 3 (combined) | 2 to 4 months | $8,000 to $20,000 |
The largest variable in these estimates is whether you engage external legal counsel for vendor contract review and risk assessment documentation. For teams in regulated industries or with substantial personal data processing, legal review is not optional. For teams with limited personal data exposure and no regulated industry obligations, you can reach Level 3 using well-designed templates and internal staff time at the lower end of the cost range.
Related reading
- AI governance for small teams: complete guide
- AI tool register template
- AI compliance cost for small teams in 2026
- AI governance metrics dashboard for small teams
- AI regulatory readiness scorecard for software and biotech
- AI governance checklist 2026
- EU AI Act Article 9 risk management system: step-by-step implementation gui
