Contents
- The AI maturity models you’ll find measure infrastructure
- In HR, maturity is trust earned
- Four stages, by what people let AI near
- In private hands
- One thing, one name on it
- Inside the process
- Answerable
- Three questions that place your function in ten minutes
- What the next stage costs in months and attention
- Write the paragraph you’d have to say
- Frequently asked questions
Somebody on your board asks where HR is on AI.
It’s the fourth item on a crowded agenda, you have about ninety seconds, and you say the team is using it, there’s a pilot running, and it’s going well. Everyone nods. The meeting moves on. You spend the drive home knowing that answer wouldn’t have survived one more question.
The follow-up is always some version of the same three. What decisions does it touch. Where does the data sit. Who signed off. The third one is the one that stings, because in most functions nobody signed off on anything. Nobody was asked to.
The question arrives cold, too. A Protiviti and BoardProspects survey of 772 board members and C-suite executives in late 2025 found that only 26% of corporate boards discuss AI at every board meeting. The rest get to it less often, so no shared vocabulary has built up and whatever you say has to stand on its own.
Here’s a way to describe where your function sits that holds up when somebody pulls the thread.
The AI maturity models you’ll find measure infrastructure
Search for an AI maturity model and you’ll find five levels of infrastructure. Ad hoc, then repeatable, then defined, then managed, then optimized. Data platforms, model governance, a center of excellence, a target state. Gartner, MIT Sloan, Microsoft and the big consultancies each publish something in that shape, and each one serves the reader it was written for: a technology leader with a platform budget and a three-year architecture plan.
The axes give that away. Those frameworks measure systems deployed and infrastructure built, because that’s what a technology function can move. Your board wants something else from you. They want to know whether the people side of the company is doing something reckless with the most personal data it holds.
Which is why the same question keeps landing on your desk in different clothes. Are we screening candidates with it. Is it reading performance reviews. Did anyone tell the works council.
In HR, maturity is trust earned
One axis carries most of it. What decisions do people let AI near, and who still signs?
The first half tracks how far AI has been allowed into the work: summarizing a document nobody minds it reading, shaping a shortlist, drafting the first version of something that ends up in an employment file. The second tracks whether a named person owns each of those calls and can be found afterwards.
That’s also the shape the law already takes. Under the EU AI Act, AI used to screen candidates, allocate tasks based on personal traits, or evaluate performance sits in the high-risk category in Annex III, and Article 26(7) requires an employer to inform workers’ representatives and the affected workers before such a system is put into use at the workplace. “Who decided” and “who did you tell” are questions with a paper trail attached, whether or not your board thinks to ask them.
And there’s real distance to cover. SHRM’s State of AI in HR 2026 research, drawing on 1,908 HR professionals across 138 distinct HR tasks, found that “just 39% of organizations are currently using AI in their HR functions” and that “less than half of HR functions are involved in AI strategy and vision in any way.”
Four stages, by what people let AI near
The four stages run from AI in private hands to a function that can be asked about any of it. There’s no score here and no pass mark. Trust doesn’t survive being averaged, so a stage is a name and a description, and the description either sounds like your function or it doesn’t.
| Stage | What the function owns | What AI is allowed near |
|---|---|---|
| In private hands | Nothing | Whatever individuals decide, unobserved |
| One thing, one name on it | One live system | Questions, drafts and volume. No decision about a person |
| Inside the process | Two or three HR processes | Work that reaches a decision, with the decision on a person’s desk |
| Answerable | A register of what’s live | Anything you can trace, with the trace on the record |
In private hands
From the inside. Your recruiters are drafting job ads in a chat window. Somebody in HR ops is pasting a policy question into a tool the company doesn’t license. A business partner rewrote a performance review with help and told nobody, because there was no rule to tell anyone about. Every bit of it saves real time. None of it belongs to the function, so none of it can be pointed at, improved or defended.
What to say out loud.
“Our people are already using AI, on tools we license and on some we don’t. HR owns none of it yet, and nothing we’ve built goes anywhere near a decision about an employee. This quarter we’re finding out what’s actually in use, writing down where it can’t go, and picking one thing worth owning. I’ll bring you that one thing and the name of the person who owns it.”
The evidence to bring. The license list. A one-page rule on what employee data can leave the building, with a date on it. A shortlist of candidate use cases and who wrote it.
The claim to leave out. That you have an AI program. Activity is a fine place to start from, and calling it a program turns awkward nine months later when the board asks how the program is going.
One thing, one name on it
From the inside. One system is live and being used by people who don’t work in HR. It answers policy questions from your approved handbook and shows the clause it used. Claire in HR operations owns it, and she can tell you how many questions it took last month and which ones it got wrong. Everything else on the list is still a conversation.
One live system with an owner puts you ahead of most functions. It’s also the point where the second and third ideas start queuing behind a team of one.
What to say out loud.
“One AI system is live in HR. Claire owns it and reports the number it moves. It answers policy questions from our approved handbook, cites the clause it used, and hands anything personal to a person without attempting an answer. Here’s what it’s handled since March, here’s what it got wrong and how we caught it, and here’s the single thing we’d need in place before a second one.”
The evidence to bring. Volume over a named period. The error log, plus how errors surfaced, because a clean log usually means nobody’s looking. The owner’s name. Where the data sits and what’s retained.
The claim to leave out. That you’re scaling AI across HR. One system’s numbers describe one system. If that system has been live for six months without changing, it may have stalled somewhere specific, and that’s worth knowing before you describe it as a foundation.
Inside the process
From the inside. AI is doing work that reaches a decision. It reads applications against your published criteria and orders the pool, then a recruiter decides who advances. It drafts the first version of a manager’s review, then the manager writes the real one. It summarizes exit interviews into themes your leadership team reads.
The decision sits on somebody’s desk in every case, and the record shows whose. Your business partners have started asking for the next one before you’ve offered it. The questions get heavier here too: your CISO wants the retention table and your works council wants the conversation, and both of them are right to.
What to say out loud.
“AI now sits inside three HR processes: how we answer policy questions, how we prepare a shortlist, and how we draft the first version of a review. In each one a person makes the call and the record shows who. We can tell you where the data sits, what’s kept and for how long, and what the vendor does with it. Since January, time-to-shortlist is down by a week and our operations team has hours back each month. Our employee representatives were told before anything was connected.”
The evidence to bring. A process map with the decision point marked on it. The sign-off record for one real decision, start to finish. The data-flow and retention page your security team already reviewed. One before-and-after number with the name of the person who reports it.
The claim to leave out. That AI moved a people outcome you haven’t isolated. Attrition fell for eleven reasons this year and your board knows it. Claim the operational number you can defend, and let the people outcome build its own evidence.
Answerable
From the inside. Somebody names any AI in HR and you can say where the data sits, who decided, and what it moved, without leaving the room to check. There’s a register, it’s current, and it has a column for the last time each system’s output was reviewed by a person. Something on it has been switched off, and you can say why.
Nothing about this stage means finished. It means the function can be asked.
What to say out loud.
“Pick any AI system in HR and I’ll tell you where the data sits, who decides, and what it moved. Here’s the register. Here’s the one we turned off in May, and here’s what we learned from it. Two things we won’t do: nothing we run decides anything about a person on its own, and we don’t keep anything live that we can’t audit in a morning. The number all of this answers to is employee lifetime value, how well people perform and how long they stay.”
The evidence to bring. The register itself: system, owner, decision point, data location, retention, last output review. The decommission log. The eLTV story, with the operational numbers underneath it and the assumptions visible.
The claim to leave out. That the register makes you compliant. A register is how you answer questions, and answering questions well is a different thing from having no exposure.
Three questions that place your function in ten minutes
Stage descriptions are easy to read generously. These three are harder to argue with.
The review test. In the last 90 days, has a person sat down with a sample of what a live system produced and marked what was wrong? A real sample, read by somebody, with the corrections written down. Usage dashboards don’t count for this one. If the answer is no, that system is running unobserved, whatever the roadmap calls it.
The pull test. Are your HR business partners asking for the next one, or are you offering it? Pull means somebody outside the AI conversation wants a specific thing for a specific reason and has said so in writing. Offering is a perfectly reasonable place to be, and it describes an earlier stage than pull does.
The calendar test. Open the calendar of whoever owns your live systems and count the recurring events that exist to review the output those systems produced. Project status meetings don’t qualify. In private hands, the count is zero, because there’s nothing to review. One thing, one name on it, and you’d expect one. Inside the process, one per live system per month. It’s the fastest straight read available, and it takes about forty seconds.
A function often sits one stage behind where its own deck puts it, and the drift is easy to explain. A deck gets written at launch, when the pilot is new and the sponsor is in the room, and the language from that week carries forward into every update after it. Nobody edits it downward. The calendar test is what catches the gap, and catching it yourself is much cheaper than having a board member catch it for you.
Two things this doesn’t answer. Whether your data can carry a specific build is a separate question about your HR systems, and HR data readiness is the one that asks it. Readiness answers “can we start”, looks at the data, and points inward. Maturity answers “where are we and what do I say”, moves in stages, and points outward at the board. And whether a particular idea is worth building is a question about one idea at a time, which is what the 10X HR-AI Framework is for.
What the next stage costs in months and attention
Nobody skips one, and the price is mostly attention.
In private hands to one thing, one name on it. Six to twelve weeks. Most of it goes on choosing, and choosing needs a defensible order across the ideas on your list. Three real ideas taken through that end to end shows what falls out. The attention cost is one person with a few hours a week and the standing to say no.
One thing to inside the process. Two to three quarters, and three conversations set the pace: the sign-off with security, the works council meeting, and the process owner who has to agree that their process is changing. Book all three in month one and the timeline holds.
Inside the process to answerable. A quarter, and almost none of it’s building. Somebody writes the register, somebody schedules the reviews, somebody decides what gets switched off. The reason this stage arrives late is that it looks like admin, and admin loses to the next build every time it’s put to a vote.
One habit moves a function faster than any of the above: write the board paragraph before you build. A use case whose paragraph sounds thin now will sound thinner in six months, and the ones that read well tend to be the ones with a named owner already attached.
Write the paragraph you’d have to say
Take the stage that sounds most like your function, read its board paragraph out loud, and mark every sentence you couldn’t currently support with a document. That list is your next quarter.
Placing the stage, costing the next one, and working out what your function’s AI adds up to in employee lifetime value is a strategy month. Here’s how ours runs. It ends with the paragraph, the register and the order, written down.
Frequently asked questions
How is this different from Gartner’s or MIT’s AI maturity models?
Those models measure what’s been built: platforms, pipelines, governance bodies, a center of excellence. They work well for the technology leader they’re written for. This one measures what people let AI near and who still signs, because that’s the constraint in a function holding the company’s most personal records. If your CIO is running a maturity model too, both readings can be true at once.
Our deck says we’re further along than the calendar test suggests. How do I raise that?
Bring the test result and let it do the talking. Count the recurring output reviews, put the number on a slide next to the claim, and ask what it would take to close the gap by the next board meeting. Functions drift this way, since decks get written at launch and updated forward. Nobody has to be wrong for the number to be worth fixing.
Who should own HR AI maturity internally?
You, with your CIO or CISO reading the same document. The stage descriptions are yours to place. The data location, retention and vendor answers live with them, and both sets end up in the same board paragraph, so write them together the first time.
What if our board never asks?
Then you have time, which is the good version of this problem. Write the paragraph anyway. It’s the fastest way to find out which parts of your AI work you can currently defend, and it takes an afternoon.