AI Governance Maturity Model: Where Are You and Where Do You Need to Be?
AI governance maturity models provide a structured way to assess where an organisation currently sits and what the path to a more defensible governance posture looks like. Unlike generic capability maturity frameworks, a useful AI governance maturity model for regulated financial services needs to be anchored in regulatory evidence requirements, not just governance best practice.
This article presents a five-level AI governance maturity model calibrated to the evidence standards that FCA supervisors, ICO auditors, and EU AI Act compliance require. It describes what each level looks like operationally, what evidence it produces, and what moves an organisation from one level to the next.
Most regulated firms in 2026 are operating at Level 2. They have governance policies and a basic inventory. The regulatory evidence standard requires Level 3 as a minimum. Level 4 is where defensible compliance lives.
The Five-Level AI Governance Maturity Model
| Level | Name | Characteristics | Evidence Standard |
|---|---|---|---|
| Level 1 | Unaware | No AI governance programme. AI tools used without oversight, inventory, or policy. | None |
| Level 2 | Policy-aware | AI governance policy exists. Manual inventory maintained. No monitoring programme. No evidence packs. | Policy documents only |
| Level 3 | Operationalised | Programmatic discovery running. Classification applied. Monitoring cadence established. Evidence packs generated. | Signed evidence packs, monitoring records |
| Level 4 | Evidence-grade | Full cross-platform coverage. Deterministic classification. Monthly signed evidence chain. Board-level reporting. Regulatory examination ready. | Verifiable, reproducible evidence satisfying FCA/ICO/Article 26 standard |
| Level 5 | Predictive | Continuous monitoring with anomaly detection. Automated remediation triggers. Forward-looking risk assessment integrated with enterprise risk management. | Real-time evidence with predictive risk indicators |
Level 1: Unaware
At Level 1, the organisation has no structured AI governance programme. AI tools are being used across the organisation (by employees using personal accounts, by teams deploying low-code automations, by procurement decisions that include AI features without governance review). There is no inventory, no classification, no oversight framework, and no evidence.
Level 1 is more common than most organisations believe. Firms that have issued an acceptable use policy but have no inventory, no classification, and no monitoring programme are at Level 1 for governance purposes. The policy exists, but the programme does not.
The risk at Level 1: complete regulatory exposure. Under Article 26, SYSC 8, and the ICO framework, the absence of a governance programme is itself a compliance failure, independent of what the AI agents are actually doing.
The move to Level 2: issue a governance policy and produce an initial AI agent inventory (even a manually maintained one) that establishes the scope of what is being governed.
Level 2: Policy-Aware
At Level 2, the organisation has a governance policy and a basic inventory. The policy defines acceptable AI use, risk categories, and governance responsibilities. The inventory lists the AI tools the organisation knows about. Risk assessments may exist for some tools. There is a governance committee or function responsible for AI governance.
Level 2 describes the current state of most regulated financial services firms in 2026. It is the product of a governance design exercise (often a consultancy engagement or an internal compliance initiative) that produced documentation without establishing an operational programme.
The evidence gap at Level 2: none of the assets of Level 2 governance constitute regulatory evidence. The policy describes intent. The inventory reflects self-reporting. The risk assessments may not be current. There are no monitoring records, no signed evidence packs, no programmatic discovery. When a supervisor asks for evidence of active governance, Level 2 organisations cannot provide it.
The move to Level 3: deploy programmatic discovery and establish a monitoring cadence with signed evidence generation. This is the single most important step. It converts governance design into governance operations.
Level 3: Operationalised
At Level 3, the organisation has moved from governance design to governance operations. Programmatic discovery is running. The inventory is generated by querying workspace admin APIs, not by collecting self-reports. Classification is applied consistently using a documented methodology. A monitoring cadence is established. Signed evidence packs are generated at each cycle.
Level 3 is where the regulatory evidence standard begins to be met. Article 26's monitoring obligation requires evidence of active oversight. Level 3 produces it. FCA SYSC 8's oversight requirement needs monitoring records. Level 3 provides them. The ICO's Control 4 requires demonstrable awareness of AI systems processing personal data. Level 3 demonstrates it.
The gap at Level 3: coverage may not be complete, cross-platform patterns may not be detected, and board-level reporting may not yet be in place. The evidence quality is improving but may not yet meet the full standard for regulatory examination or board assurance.
The move to Level 4: expand platform coverage to ensure cross-platform toxic-combination detection, establish board-level reporting from the evidence programme, and ensure the signed evidence chain is continuous (no gaps in the monthly cycle).
Level 4: Evidence-Grade
At Level 4, the organisation's AI governance programme produces evidence that meets the full standard for regulatory examination, internal audit, and board assurance. The key characteristics:
- Full cross-platform coverage. All major platforms where AI agents operate are included in the discovery programme
- Deterministic classification. The same agent always produces the same classification, making findings reproducible under examination
- Continuous signed evidence chain. Monthly evidence packs without gaps, each verifiable as unaltered since generation
- Cross-platform toxic-combination detection. Compound risk patterns across platforms are identified, not just within-platform findings
- Board-level reporting. The evidence programme produces the information boards need to exercise meaningful AI oversight
- Regulatory examination readiness. A supervisor can be presented with signed evidence packs for any period in the last 24 months and verify their integrity
Level 4 is where defensible compliance lives. It does not require perfection. It requires evidence of an active, well-designed programme that is demonstrably operating. Most firms reaching Level 4 find that the regulatory, audit, and insurance conversations become significantly more manageable.
Level 5: Predictive
Level 5 is the aspirational state for mature AI governance programmes: real-time monitoring with anomaly detection, automated remediation triggers, and forward-looking risk assessment integrated with the enterprise risk management framework. At Level 5, governance is proactive: identifying emerging risks before they become findings, and integrating AI governance data into business decision-making.
Level 5 is not yet the regulatory minimum. It is the direction of travel for organisations that have established Level 4 evidence-grade governance and are extending it. For most regulated financial services firms in 2026, reaching Level 4 is the priority.
Where Most Regulated Firms Are Today
Based on the observable evidence from regulatory engagements and governance assessments, the distribution of regulated financial services firms across the maturity model in mid-2026 is approximately: Level 1 (5%), Level 2 (65%), Level 3 (25%), Level 4 (5%), Level 5 (under 1%). The majority of the regulated financial services sector is at Level 2: policy-aware but not operationalised.
The gap between Level 2 and Level 3 is the most important gap in the sector in 2026. It is the gap between governance that describes oversight and governance that evidences it. Closing this gap is the Article 26 enforcement problem, and the move from Level 2 to Level 3 requires programmatic discovery and signed evidence generation, not more policy documentation.
Further reading: Building an AI Governance Evidence Programme and AI Governance Platform vs Consultancy.
How AETHER Pulse Accelerates the Level 2 to Level 4 Journey
AETHER Pulse is designed for the Level 2 to Level 4 journey. Its programmatic discovery immediately moves an organisation from self-reported inventory (Level 2) to programmatic discovery (Level 3). Its monthly signed evidence generation establishes the evidence chain that Level 4 requires. Its cross-platform detection and board-level reporting outputs address the remaining Level 3 to Level 4 gaps.
For organisations at Level 2 facing Article 26 enforcement in August 2026, AETHER Pulse provides the fastest path to Level 3 compliance: operational within days, first signed evidence pack within the first month.
Frequently Asked Questions
How do we self-assess our current maturity level?
Apply the operational markers for each level: do we have programmatic discovery (Level 3 minimum)? Do we have a continuous signed evidence chain with no gaps (Level 4 minimum)? The absence of programmatic discovery means Level 2 at most, regardless of how comprehensive the governance framework is.
Is Level 3 sufficient for Article 26 compliance?
Level 3 meets the minimum Article 26 evidence standard: monitoring is occurring and evidence packs are generated. Level 4 provides greater regulatory resilience: full cross-platform coverage, continuous evidence chain, board-level reporting. For firms expecting intensive regulatory scrutiny, Level 4 is the target.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation